Privacy Policy

Last updated: May 17, 2026

Overview

MintPick (“we”, “our”, “the service”) is a card centering measurement tool available as a mobile app and a web app at mintpick.dev. We are committed to protecting your privacy. This policy explains what data we collect and how we use it across both surfaces.

Data We Collect

Web and mobile apps: To measure centering, your card images are sent to our machine learning service for corner detection and border analysis. After analysis, we may retain card images, centering measurements, and correction data so we can improve our detection models over time. If you sign in and save a scan to your Board, the image and measurements are linked to your account so you can access them across devices; otherwise they are treated as anonymous training data. We do not request location permission, and we do not use photo location metadata for the service.

Regional retention notice (web app): As of May 2026, we do not retain card images or measurement data from users in the European Economic Area (EEA), the United Kingdom, or Switzerland for training purposes. The retention practices described above apply only to users in other regions. Card analysis still works in these regions — only the post-analysis training-data retention is suppressed.

Mobile app — explicit consent: The mobile app uses a different model from the web app. Training-data retention is OFF by default and only activates when you explicitly tap “Allow” in the in-app consent prompt (or toggle “Help measure cards better” on in Settings › Privacy). Consent (GDPR Art. 6(1)(a)) is the legal basis on mobile, in place of the geo-gated “legitimate interest” approach used on the web; mobile users in the EEA, UK, and Switzerland may opt in like users in any other region.

Mobile app — signed-in vs anonymous capture: If you opt in while signed in, your contributed scans are linked to your account so they can be deleted on request (toggle “Help measure cards better” off in Settings › Privacy fires a server-side deletion of your historical training rows). If you opt in without signing in, your contributed scans are stored without any link to your identity — we cannot re-associate them with an account later, which also means we cannot delete a specific anonymous user’s rows on request because the data is not personally identifiable in our database. Toggling consent off at any time stops future anonymous uploads immediately. Anonymous mobile uploads are also subject to the same EEA / UK / Switzerland geo restriction as web anonymous capture.

Account & Storage

MintPick uses Supabase to provide authentication and cloud storage for your Board. When you create an account, we store:

  • Your email address (for authentication)
  • Your name or avatar if provided by a sign-in provider or account profile
  • Card images and measurements you choose to save
  • Board and Stack organization, including notes, listing URLs, and pick/pass labels you add
  • Subscription tier (free or Pro)

The mobile app may also keep a local cache of Board and Stack data on your device so the app can load recent saved scans quickly.

Third-Party Services

We use the following third-party services:

  • Supabase (web and signed-in mobile app) — provides authentication, database hosting, and Board storage. See Supabase's Privacy Policy.
  • Stripe (web app) — processes subscription payments. Stripe receives billing information; we never store card details on our servers. See Stripe's Privacy Policy.
  • Google AdMob (mobile app) — displays banner advertisements to free-tier users and may use device identifiers for advertising, subject to your iOS tracking permission choices. See Google's Privacy Policy.
  • RevenueCat (mobile app) — manages in-app subscriptions through Apple/Google and helps us determine whether your account has Pro access. See RevenueCat's Privacy Policy.
  • PostHog (mobile app) — collects product analytics such as app opens, scan completion, save, export, and paywall events so we can understand how the service is used. The current web app does not yet send PostHog events. See PostHog's Privacy Policy.
  • Sentry (both) — collects crash reports and error diagnostics to help us fix bugs. No card images or measurement data are included. See Sentry's Privacy Policy.

App Tracking Transparency (iOS)

On the iOS app, we request your permission before allowing third-party services to track your activity across other apps. You can change this setting at any time in your device's Settings > Privacy > Tracking.

Your Rights

  • Opt out of ad personalization — on iOS, deny tracking in the App Tracking Transparency prompt, or go to Settings > Privacy > Tracking at any time.
  • Delete your data — signed-in mobile users can delete their account from the in-app Settings screen. Deleting the app alone does not delete your account. On the web app, sign in and email privacy@mintpick.dev to request deletion of your account and associated data.
  • California residents (CCPA) — we do not sell your personal information. You have the right to know what data is collected and to request deletion.
  • EU residents (GDPR) — you have the right to access, correct, and delete your personal data. Contact us at privacy@mintpick.dev to exercise these rights.

Children's Privacy

The service is not directed at children under 13. We do not knowingly collect personal information from children.

Changes to This Policy

We may update this privacy policy from time to time. Changes will be posted on this page with an updated date.

Contact

If you have questions about this privacy policy, contact us at privacy@mintpick.dev.