Privacy Policy

Privacy Policy

Last updated: August 2, 2026

1. Who is responsible for your data

PoBinder (pobinder.com) is operated by Udviklr ApS (CVR no. 46466950), a company registered in Denmark. Udviklr ApS is the data controller for the personal data described in this policy under the EU General Data Protection Regulation (GDPR).

For any question or request about your data, contact us at [email protected].

2. What data we collect

  • Account data. Your name, email address and a hashed password. If you sign in with Google instead, we receive your name, email address, Google account ID and profile picture URL from Google. We never see your Google password.
  • Content you create. Your binders (names, descriptions, layout), which cards you track and whether you have collected them, personal notes, acquisition dates, and any cover images you upload.
  • Technical data. When you are logged in, our session records include your IP address and browser type (user agent). Our servers also keep standard, short-lived request logs for security and troubleshooting.
  • Local preferences. Display settings such as theme, zoom and layout are stored in your own browser (localStorage) and are not sent to us.
  • Card scanner camera data. If you choose to use the free card scanner, camera frames and selected photos are processed temporarily in your browser to find likely cards. During ordinary scanning, photos, visual fingerprints, OCR readings and reflectance measurements are not uploaded to PoBinder or stored on our servers. Before recognition, the browser downloads a fixed catalog containing matching descriptors, printing metadata and current prices; recognition does not request artifacts for the inferred candidates. Opening a full card page or using signed-in collection tools makes the ordinary request for that selected card. Cards you keep for review are saved as one private scan session in your browser's localStorage. That session contains catalog identifiers, card and set names, card number, catalog image and page URLs, your selected printing, condition and quantity, displayed or manually entered values, and session timestamps. It never contains camera frames, crops, fingerprints or OCR readings. The session is not tied to your account or synced between devices, and you can remove all of it with Clear session on the scanner review screen.
  • Optional failed-scan reports. If you are logged in and choose “Report failed scan,” we show the image and a separate consent prompt before anything is sent. If you accept, the report can contain up to three source frames, up to five cropped card or tilt images, scan diagnostics such as OCR and matching scores, the scanner's original suggestion, and any correction you already made. Source frames may include the area around the card. Reports are linked to your account only so we can prevent abuse and honour withdrawal or account deletion; the internal training feed does not include your name, email address, account ID, IP address or full browser user-agent.

We do not collect payment details (the service is free) and we do not ask for any sensitive categories of data.

3. Why we process it, and on what legal basis

  • To provide the service: creating your account, storing your binders and showing them back to you. The legal basis is performance of a contract (Art. 6(1)(b) GDPR).
  • To keep the service secure: session management, abuse prevention and server logs. The legal basis is our legitimate interest in running a safe, working service (Art. 6(1)(f) GDPR).
  • To respond to you when you email us. The legal basis is our legitimate interest in answering your request (Art. 6(1)(f) GDPR).
  • To improve and train the card scanner using a failed scan you expressly choose to report. The legal basis is your consent (Art. 6(1)(a) GDPR). Reporting is optional and has no effect on your ability to use the scanner.

4. What we don't do

  • No analytics or tracking scripts, and no advertising.
  • We never sell your data or share it for marketing.
  • No automated decision-making or profiling.
  • We do not receive or store the photos you check with the card scanner unless you separately report a failed scan and accept the contribution prompt.

5. Cookies

We only use strictly necessary cookies: a session cookie that keeps you logged in, a CSRF token that protects forms against forgery, and an optional “remember me” cookie. These are required for the site to function and are exempt from consent requirements, which is why you don’t see a cookie banner. We set no advertising or analytics cookies.

6. Public binders

Binders are private by default. If you make a binder public, anyone with the link can see your display name and the binder's contents. Those contents may include its name, description, cards, collection status and price estimates if you enable them. You can make the binder private again at any time.

7. Who processes data on our behalf

We use a small number of service providers to run PoBinder. They process data only on our instructions under data processing agreements:

  • Our hosting provider, which runs the application and database.
  • Cloudflare, Inc., for storage and delivery of uploaded images and mirrored card artwork.
  • Google Ireland Ltd., only if you choose to sign in with Google.
  • An email delivery provider, which sends account emails such as password resets.

Separately, your browser makes direct requests to third parties when pages load: fonts are served by Bunny Fonts (an EU-based, GDPR-friendly font CDN that does not track users), and some card images are loaded from the TCGdex and Pokémon TCG API image servers until we have mirrored them. Those services see your IP address as part of serving the request, as any web server does.

Where a provider processes data outside the EU/EEA (for example Cloudflare or Google in the United States), transfers are covered by the EU–U.S. Data Privacy Framework and/or EU Standard Contractual Clauses.

8. How long we keep your data

  • Account and binder data: for as long as you keep your account. Deleting your account removes it permanently.
  • Sessions: expire automatically after inactivity and are deleted when you delete your account.
  • Server logs: kept briefly for security purposes, then deleted.
  • Consented failed-scan reports: kept until you withdraw consent, delete your account, or we remove the report. Withdrawal deletes the server images and diagnostics and sends a deletion marker to managed local training copies.
  • Backups: routine backups are rotated on a fixed schedule, so deleted data also disappears from backups shortly after.

9. Your rights

Under the GDPR you can:

  • Access and correct your data. Your name and email can be edited directly in account settings.
  • Delete your account yourself under Settings → Profile → Delete account. This permanently erases your account, binders, notes and uploaded images.
  • Export your data. Each binder can be exported as a CSV file from the binder page for data portability.
  • Object to or restrict processing based on legitimate interests, by contacting us.
  • Withdraw scanner-training consent under Settings → Profile. This deletes all active failed-scan reports you contributed. Withdrawal does not affect processing that lawfully happened before it.
  • Complain to a supervisory authority. In Denmark this is Datatilsynet, www.datatilsynet.dk.

For anything you can’t do yourself in the app, email us and we will respond within one month as the GDPR requires.

10. Children

PoBinder is not directed at children under 13, and you must be at least 13 years old (or the minimum age for consenting to information services in your country) to create an account.

11. Changes to this policy

If we make material changes to this policy, such as adding a new processor or collecting new kinds of data, we will update this page and its “last updated” date. We will notify account holders by email or an in-app notice when the change meaningfully affects them.

See also our Terms of Service.