Back to home

Legal

Privacy policy

Here we explain which data CardEntry processes, what it is needed for and which rights you have.

Last updated: 18 July 2026

This English text is a convenience translation. The German version is the legally binding one.

1. Controller

Matthew Mc Gregor
Eckertstraße 30m/17A
8020 Graz, Österreich
Email: [email protected]

2. Visiting the website and hosting

CardEntry runs in the Hetzner Cloud. The hosting provider is Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. When the website is accessed, server logs may in particular process the IP address, the time and target of the request, the volume of data transferred, browser and device details, and technical error and security information.

This processing serves the secure, stable and efficient provision of the service. The legal basis is our legitimate interest under Art. 6(1)(f) GDPR. Log data is only stored for as long as it is needed for operation, error analysis and security. Further information can be found in Hetzner’s privacy policy.

3. Registration and sign-in

We use Clerk for registration, sign-in and session management. This may process in particular your email address, name or profile details, user and session identifiers, IP address, and browser and device information. This processing is necessary to maintain the user account and provide the protected area. The legal basis is Art. 6(1)(b) GDPR; security measures are additionally based on Art. 6(1)(f) GDPR.

The service provider is Clerk, Inc. Data may be processed in the USA. Clerk cites in particular the EU-US Data Privacy Framework and standard contractual clauses as its transfer mechanisms. Further information: Clerk’s privacy policy and Clerk’s data processing agreement.

4. Processing of card images

When you upload card images, the image data is transmitted to the Google Gemini API in order to recognise the card name, set, card number, language and further card data. The provider is Google Ireland Limited; affiliated Google companies may technically be involved. The legal basis is Art. 6(1)(b) GDPR, because the processing is necessary to carry out the recognition you requested.

CardEntry processes the image file during the recognition run and does not store it as a card image in the CardEntry database. The card data and suggestions derived from the image, by contrast, are assigned to the scan session and stored. Please upload card images only — no images containing people, addresses or other confidential information.

Information on processing and on possible international data transfers can be found in the Gemini API terms and data processing conditions.

5. Scan sessions, results and credits

In the course of use we store in particular the identifier and name of a scan session, recognised or selected cards, set, card number, language, quantity, condition, timestamps and credit consumption. This data is needed so that you can check, edit and export results. The legal basis is Art. 6(1)(b) GDPR.

Scan sessions remain available until you remove them using the delete function. After that they are no longer accessible in the user account. Archiving merely hides a session and does not remove it. You can request final deletion of the associated data or of the account at any time by email. Account data is generally stored for the duration of the user account. Legally required records may be stored for longer under existing retention obligations.

6. Local storage and necessary cookies

Clerk uses technically necessary cookies or comparable storage techniques for sign-in. CardEntry also stores local settings in the browser, such as the check status within a scan session, your own export profiles, the selected interface language and the state of the side navigation. Your choice in the privacy settings is also stored locally so that it can be honoured on later visits. This information serves the function and usability of the application. No advertising cookies are used.

If you visit CardEntry through an affiliate link and expressly consent to attribution, we store the referral code, a random visitor identifier and the time of the visit in the browser for up to 30 days. This lets us attribute a later registration, and any purchases arising from it, to the referring partner. Without your consent this attribution does not take place. Consent is voluntary and can be withdrawn by clearing your browser data. The legal basis is Art. 6(1)(a) GDPR in conjunction with § 165(3) TKG 2021.

If a user account is enabled as an affiliate partner, we additionally process the associated referral code, name, email address, postal address, country and a voluntarily provided tax or VAT number. We also store referred registrations and purchases, the agreed commission rate, payout amounts and monthly affiliate statements. This data is necessary for performing the partner relationship, for payouts and for legally required documentation. The legal bases are Art. 6(1)(b) and (c) GDPR. Accounting records are stored under statutory retention obligations.

You can clear browser data in your browser settings. Blocking technically necessary storage may impair sign-in and functionality.

7. Product analytics with PostHog

If you expressly consent to product analytics, we use PostHog Cloud EU to understand how CardEntry is used and where users abandon a workflow. The provider is PostHog, Inc. According to the provider, the EU cloud used for CardEntry is operated in Frankfurt.

Processing may cover pages visited, the time and origin of the visit, browser and device information, and clearly defined usage events. These include, for example, creating a scan session, the number of images processed, successful or failed processing runs, checking and export operations, the TCG and CSV format used, and the start and successful completion of a credit purchase. After sign-in, only the internal user identifier is used. Email address, name, card images, file names and recognised card names are not transmitted to PostHog. Session recordings and automatic capture of page elements are disabled.

The legal basis is your consent under Art. 6(1)(a) GDPR in conjunction with § 165(3) TKG 2021. Without consent PostHog is not initialised. You can withdraw your consent at any time with future effect via “Privacy settings”. Analytics data is retained for no longer than twelve months. Further information can be found in PostHog’s privacy policy.

8. Contacting us

If you contact us by email, we process your contact details and the content of your message in order to handle your request. Depending on the request, the legal basis is Art. 6(1)(b) or (f) GDPR. The data is deleted once the matter is concluded and no legal obligations require further storage.

For messages sent through the feedback and bug form we additionally store the user identifier, the type and content of the report, the page it was sent from, processing status, internal notes and timestamps. We use this data solely for error analysis and the further development of CardEntry. Depending on the content, the legal basis is Art. 6(1)(b) or (f) GDPR.

9. Recipients and transfers to third countries

Only service providers necessary for operation and provision receive data: Hetzner for hosting, Clerk for authentication and Google for card image recognition. PostHog only receives the analytics data described in section 7 if you have consented to that processing. Where data is processed outside the European Economic Area, the providers state that they base the transfer on an adequacy decision, the EU-US Data Privacy Framework or EU standard contractual clauses.

10. Retention period

Personal data is stored only for as long as is necessary for the respective purpose. After that we delete or anonymise it, unless statutory retention periods, the assertion or defence of legal claims, or security reasons stand in the way. The specific duration depends on the type of data and the context of use.

11. Your rights

Under the GDPR you have in particular the right to access, rectification, erasure, restriction of processing, data portability and objection. You can withdraw consent you have given at any time with future effect. To exercise your rights, a message to [email protected].

You may also lodge a complaint with a data protection supervisory authority. In Austria this is the Austrian Data Protection Authority, Barichgasse 40–42, 1030 Vienna, email: [email protected]. Further information can be found on the website of the Data Protection Authority.

12. Automated decisions and security

Card recognition produces automated suggestions but makes no decision with legal or similarly significant effect within the meaning of Art. 22 GDPR. You can check and change recognised details yourself. We apply appropriate technical and organisational measures to protect data against loss, misuse and unauthorised access.

13. Changes to this policy

We adapt this privacy policy when features, service providers or legal requirements change. The version published on this page is the applicable one.