CARDINAL VISION.AI

Cardinal Privacy Policy

Effective Date: 2026-06-23 Last Updated: 2026-06-23

This Privacy Policy describes how Cardinal Inc. ("Cardinal," "we," "us," or "our") collects, uses, and shares information when you use the Cardinal mobile application (the "App").


1. Who We Are

Cardinal is operated by Cardinal Inc., located at Delaware, US. If you have questions about this policy, contact us at [email protected].


2. What Information We Collect

2.1 Card Photos and Images

When you scan a trading card, your device captures photos using the camera. These images are uploaded to our backend servers (hosted on AWS infrastructure, including S3) so our AI systems can grade the card. Card images are the core data that makes the App work. Images you capture are:

Card photos are not linked to your name, email address, or any other personally identifying information.

2.2 Anonymous Install Identifier

When you first install the App, a random identifier (a UUID — universally unique identifier) is generated and stored on your device. This identifier:

This identifier is an opaque pseudonymous token, not personally identifiable information.

2.3 Device and Technical Metadata

When images are uploaded for grading, we also send technical metadata that helps improve grading accuracy:

This metadata is attached to the grading job and stored alongside the uploaded images.

2.4 App Activity and Crash Reports (Phase B — Upcoming)

We plan to add Firebase Analytics and Firebase Crashlytics in a near-future release. Once added, we will collect:

Analytics and crash data will be keyed to the anonymous install identifier only. We do not collect advertising IDs, and we do not use analytics data for advertising.


3. How We Use Your Information

DataPurpose
Card photosAI-powered card grading (centering, corners, edges, surface defect analysis)
Card photosCard identification (name, set, number, market value)
Anonymous install IDSession consistency across API requests; tying analytics events to a single install
Device/sensor metadataImproving grading accuracy; quality filtering
App activity events (Phase B)Understanding how users use the App; improving features
Crash logs (Phase B)Detecting and fixing bugs and crashes

We do not use any data for advertising or sell any data to third parties.


4. How We Share Your Information

We do not sell your data. We share data only with service providers necessary to operate the App:

4.1 AWS (Amazon Web Services)

Card images and job metadata are stored in AWS S3 and processed on AWS compute infrastructure. AWS acts as a data processor for Cardinal. AWS's privacy information is available at https://aws.amazon.com/privacy/.

4.2 Card Identification: Server-Side Fallback Services

When our on-device identification system cannot confidently identify a card, we send the card image to one or more of these services for identification:

These services receive the card image and return card identity information (name, set, number). They do not receive your name, email, or anonymous install ID. The on-device identification system (which runs entirely on your device) does not transmit images for the identification match itself.

4.3 Market Pricing Data

Card market pricing is sourced from third-party pricing data providers (including Scrydex). Cardinal queries pricing data using the card's identity (game, set, card number). No card images or personal identifiers are sent to pricing providers.

4.4 Firebase (Google) — Phase B

Once added, Firebase Analytics and Crashlytics will process app activity and crash data on Google's infrastructure. Events are keyed to the anonymous install identifier. Firebase's privacy information is available at https://firebase.google.com/support/privacy.

4.5 Other Disclosures

We may disclose information if required by law, legal process, or to protect the rights and safety of Cardinal, our users, or the public.


5. Data Retention


6. Data Security

All data transmitted between the App and our servers is encrypted in transit using HTTPS/TLS. Card images are stored in AWS S3 with server-side encryption.


7. Your Choices and Data Deletion

Cardinal does not require you to create an account, so there is no account to delete. Because all data is associated with your anonymous install identifier rather than a name or email address:


8. Children's Privacy

The App is not directed to children under 13 (or under 16 in the European Economic Area). We do not knowingly collect personal information from children under these ages. If you believe a child has submitted information through the App, contact us at [email protected] and we will delete it.


9. International Users

Cardinal is operated from the United States, and your information is processed in the United States. If you are located in the European Economic Area, the United Kingdom, or California and wish to exercise applicable data-protection rights (such as access, correction, or deletion), contact us at [email protected] and we will respond as required by applicable law.


10. Changes to This Policy

We may update this policy from time to time. If we make material changes, we will update the "Last Updated" date above. Continued use of the App after the updated policy is posted constitutes acceptance of the updated terms.


11. Contact Us

For privacy questions or data deletion requests, contact:

Cardinal Inc. Delaware, USA. Email: [email protected]