Exchards

Privacy notice

Privacy policy

In force from 17 July 2026 · version 1.0

This notice explains which personal data Exchards (the Android app and the exchards.com site) processes, why, and what you can do about it. It is written under articles 13 and 14 of Regulation (EU) 2016/679 (GDPR).

It is written to be read. Wherever a technical detail changes the consequences for you, for example the photos no, but a thumbnail yes, we say so instead of hiding it behind “usage data”.

1. Who processes your data

The data controller is:

Tiber Valley Digital Hub
Via Trastevere 13, Città di Castello (PG), Italia
VAT no. 03192530545
info@tiber-valley.com

For anything about this notice or about your rights, write to that address. We answer, not a form.

2. What data we process

DataWhat it containsWhen we collect it
AccountEmail address, password (kept only as an Argon2 hash: it is not readable, not even by us), display name, profile picture, Google identifier if you sign in with Google, email verification date, last sign-in date.At registration
SessionsA fingerprint (SHA-256 hash) of the session token, not the token itself, its expiry, any revocation, and the description of the device or browser that obtained it.At every sign-in
CardTrader credentialYour CardTrader token, encrypted (AES-256-GCM); the last 4 digits in the clear, as a reminder; your CardTrader user identifier; the result of the last check.If you connect your CardTrader account
ScansResult, card name as read, collector number, expansion, properties, price, quantity, any error, processing cost, and a 220 pixel thumbnail of the image (see §3).At every scan
Processing countersModel used, number of tokens, cost, duration, result. No content: neither images nor the text of the requests.At every AI call
SettingsLanguage, default condition and origin, pricing rule, notifications, spending cap.When you change them

We do not process special categories of data (art. 9 GDPR) and we don’t want them. We don’t collect your location, your contacts, the list of apps you have installed, or advertising identifiers. There is no advertising, there is no profiling, and the data is neither sold nor handed to anyone for their own purposes.

3. The photos of your cards: what really happens

It’s the question that matters most in an app that lives on photographs, so here is the answer in detail.

The photo you take

It is cropped on your device and sent to Google Gemini to be read. Afterwards it is not kept: it doesn’t end up on disk, it doesn’t end up in our database. We don’t send Gemini your name, your email or any identifier of your account: the image goes, the text that was read comes back.

The thumbnail that stays

In the scan history we save a 220 pixel thumbnail (about 12 KB), because a list of scans without the image is unreadable. It lives in our database, in the backups for as long as the backups last, and it is visible only to you when you are signed in. You can delete it at any time by clearing the history from the app settings.

If a card is photographed together with something you don’t want to keep, a document on the desk, a person in the background, that something can end up in the thumbnail. Frame the card and nothing else: it also makes recognition work better.

4. Why we process it, and on what legal basis

PurposeLegal basis
Creating your account, signing you in, keeping the session alivePerformance of the contract — art. 6(1)(b)
Recognising the cards, suggesting prices, publishing on CardTrader on your behalfPerformance of the contract — art. 6(1)(b)
Keeping your CardTrader credential in encrypted formPerformance of the contract — art. 6(1)(b)
Scan historyPerformance of the contract — art. 6(1)(b)
Verifying your email and letting you reset your passwordPerformance of the contract — art. 6(1)(b); security obligation — art. 32
Spending counters and monthly cap, defence against abuse and fraudLegitimate interest — art. 6(1)(f): keeping a free service standing without a few people’s usage making it unsustainable for everyone
Complying with legal obligations (tax, requests from authorities)Legal obligation — art. 6(1)(c)

We do not process data for marketing purposes. If we ever did, it would need your consent, asked for separately and revocable.

5. Who we share the data with

Only with whoever is needed to make the app work, and only with what they need. They are our data processors (art. 28) or independent controllers, as indicated.

RecipientWhat they receiveWhy
Google (Gemini API)The images of the cards to be read. No identifier of you or of your account.Recognising the card
Google (sign in with Google)Only if you choose that method: the sign-in request. Google passes us your identifier, email, name and profile picture. We ask only for openid email profile: we have no access to your mail, your files or your contacts. Independent controller.Signing you in
CardTraderThe requests the app makes on your behalf, authenticated with your token: reading the catalogue, the prices, your inventory, creating or editing your listings. Independent controller for the relationship between you and them.Publishing and managing your listings
Resend (email delivery)Your email address, your display name and the verification or reset link.System emails
HostingHosts the server and the database, so technically everything above.Running the service

Beyond these, data may be disclosed to the judicial authority or to other authorities when the law requires it. If one day the company or the service were sold, the data would pass to the buyer: we would tell you first, and in time for you to delete your account.

6. Transfers outside the European Union

Google and Resend may also process data outside the European Economic Area, in particular in the United States. In that case the transfer takes place on the basis of the European Commission’s standard contractual clauses (art. 46(2)(c) GDPR) and, where applicable, of the provider’s adherence to the EU-US Data Privacy Framework (art. 45).

You can ask us for a copy of the safeguards in place by writing to info@tiber-valley.com.

7. How long we keep it

DataRetention
Account and settingsAs long as the account exists. Then see §8.
Photos sent for recognitionNot kept: the duration of the call
Thumbnails and scan historyUntil you clear the history, or as long as the account exists
CardTrader credentialUntil you disconnect it, or as long as the account exists
Session (access token)1 hour
Session (refresh)90 days. The fingerprint of the revoked session stays as evidence of a possible token theft.
Email verification link24 hours
Password reset link30 minutes
Processing and spending countersAs long as the account exists (they are needed for the monthly cap and for defence against abuse)
BackupsDeleted data disappears from the backups as they rotate, within 90 days

8. Your rights

The GDPR gives you rights that actually count, and exercising them costs nothing:

  • Access (art. 15) — knowing what data we have and getting a copy of it.
  • Rectification (art. 16) — correcting what is wrong.
  • Erasure (art. 17) — the “right to be forgotten”.
  • Restriction (art. 18) — freezing the processing.
  • Portability (art. 20) — getting your data back in a machine-readable format.
  • Objection (art. 21) — to processing based on legitimate interest.
  • Withdrawal of consent (art. 7) — where the processing is based on consent, without affecting what was done before.

What you can do yourself, right now

  • Delete the account from the app settings: it opens the grace period described below.
  • Clear the scan history, thumbnails included, from the app settings.
  • Disconnect the CardTrader account: the encrypted credential is deleted.
  • Revoke the token from your CardTrader panel, which is worth doing anyway when you stop using the app.

Deleting your account

In the app settings you’ll find Delete account. To go ahead we ask you to confirm it’s you: your password, or your email address if you signed in with Google. From that moment a 30-day grace period starts — the account is deactivated and the sessions closed, but the data isn’t deleted yet. If you sign back in with the same login within those 30 days the deletion is cancelled and you get everything back the way it was. Once the deadline passes, the account and everything connected to it — scans, thumbnails, CardTrader credential, sessions, counters — are permanently deleted, except the little that a law obliges us to keep, and in that case we tell you what and why.

If you prefer, or if you can’t sign in to the app, you can also ask for deletion by writing to info@tiber-valley.com from the address you signed up with: we do the same thing, within the same deadline.

Complaints

If you think we are processing your data unlawfully you can turn to the Italian data protection authority, the Garante per la protezione dei dati personali (Piazza Venezia 11, 00187 Rome — garanteprivacy.it), or to the supervisory authority of the country where you live. We’d be glad to hear from you first, but it’s your right and you don’t have to ask permission.

9. How we protect it

  • All traffic travels over HTTPS.
  • Passwords are not stored: we keep an Argon2 hash of them. If the database ended up in the wrong hands, the passwords wouldn’t be in it.
  • The CardTrader token is encrypted with AES-256-GCM, with the key outside the database: anyone stealing the database alone would find no usable tokens in it.
  • Of sessions we keep only the fingerprint, not the token.
  • The keys for external services live on the server, never inside the app: whatever sits inside an installed app, anyone can extract.
  • Access to the data is limited to the people who have to keep the service running.

No system is impregnable. If a breach occurred that involves a high risk to your rights, we would notify the Garante within 72 hours and tell you (arts. 33-34).

10. Permissions the app asks for

  • Camera — to take the photo of the card. That’s the only reason.
  • Images and photos — only to let you pick a screenshot to value, when you are the one opening the gallery. We don’t read your gallery.
  • Internet — to talk to our server.

You can deny them or revoke them from the Android settings: the feature that depends on that permission will stop working, the rest won’t.

11. Minors

The service is not intended for anyone under 16 and we do not knowingly collect their data. Using Exchards also requires a CardTrader account, with the age requirements CardTrader sets. If you notice that a minor has given us their data, write to us: we delete it.

12. Changes to this notice

If the way we process data changes, this document changes, and it changes first, not afterwards. The date at the top always says from when the version you are reading applies. If the change actually affects you (new data, a new purpose, a new recipient) we tell you by email or inside the app, and we don’t leave you to find out on your own by rereading a page.