Privacy Policy

Effective Date: March 11, 2026  ·  Last Updated: March 11, 2026

Cardex (“we,” “our,” or “us”) provides a Pokémon TCG price tracking and collection management application. This Privacy Policy describes how we handle your information when you use Cardex.

1. Information We Collect

Account Information: Email address and display name when you register.

Collection Data: Card names, sets, quantities, purchase prices, and condition grades that you enter or import. This data is yours and is stored securely on our servers.

TCGPlayer Integration: If you choose to connect your TCGPlayer account, you provide your TCGPlayer email and password. We use these credentials solely to read your collection data. We do not store your TCGPlayer password — it is used for a single authenticated session and immediately discarded. We store only the resulting session token, encrypted at rest.

Price Data: We fetch and store publicly available market prices from TCGPlayer and other sources to power price tracking.

Alert Preferences: Price alert targets and notification settings you configure.

Usage Data: Anonymized logs of feature usage for product improvement.

Device Information: Device type, OS version, and app version for crash reporting and compatibility.

2. How We Use Your Information

3. TCGPlayer Credentials — Important

When you connect TCGPlayer, your password is transmitted over HTTPS directly to our server, used to authenticate with TCGPlayer, and then permanently discarded. It is never logged, stored, or accessible to any employee. If you are uncomfortable with this, please use our CSV import option instead.

4. Data Sharing

We do not sell your data. We do not share your collection or pricing data with third parties, except:

5. Third-Party Data Sources

Card metadata (names, images, set information) comes from the Pokémon TCG API (pokemontcg.io). Price data is sourced from TCGPlayer's publicly available market data. We are not affiliated with or endorsed by The Pokémon Company, Nintendo, TCGPlayer, or eBay.

6. Data Retention

Your collection data is retained for as long as your account is active. You may delete your account and all associated data at any time from Settings. We will process deletion within 30 days.

7. Security

All data is transmitted over HTTPS. Session tokens and sensitive settings are encrypted at rest. We do not store payment information (handled by our payment processor).

8. Push Notifications

If you enable price alerts, we will send push notifications to your device when alerts trigger. You can disable notifications at any time in your device settings or within Cardex.

9. Children's Privacy

Cardex is not directed to children under 13. We do not knowingly collect data from children. If you believe a child has provided us information, contact us and we will delete it.

10. Your Rights

You may access, correct, export, or delete your data at any time through the app or by contacting us. For requests, email privacy@cardex.app.

11. Changes

We will notify you of material changes via push notification or email before they take effect.

12. Contact

privacy@cardex.app