Bindr Privacy Policy
Draft — pending legal review before R1.
Version: 2026-09
This policy explains what personal data Bindr — an app for tracking a Pokémon TCG card collection — processes, why, on what legal basis and for how long, and which rights you have.
Controller
The controller of your personal data is: Bindr Sp. z o.o., ul. Uniwersytecka 13, 40-007 Katowice, Poland.
For any question about your personal data, write to: privacy@usebindr.com.
Data we process
- Account identifiers. On first launch the app creates an anonymous account without any personal data; it only receives a user identifier (Supabase user id). We process an email address only if you link your account to an email address, a Google account or an Apple account.
- Sign-in identity. If you choose Google Sign-In or, when available, Sign in with Apple, we receive an account identifier and email address from that provider.
- Collection data. Data you enter yourself: cards (copies), folders, condition, quantity, purchase date and price.
- Profile data. An optional display name and the dates of your premium entitlement.
- Consent records. Your consents with their history: kind of consent, decision, document version, source and timestamp.
- Card photos (scan crops). Uploaded only with the separate "scan_dataset" consent, to improve card recognition. Withdrawing that consent stops future uploads but does not delete crops already collected; we delete them if you ask for it separately.
- Analytics events. Events about how the app is used (PostHog, EU cloud), collected only with the "analytics" consent (opt-in). Session replay is off. Test and development accounts never send analytics.
- Technical logs. Backend (Edge Functions) logs. In the audit log, user ids appear only as SHA-256 hashes.
- Data export requests. The time and status of each request.
We do not collect location data today. If a future feature (such as trading or meet-ups) needs it, approximate location would be collected only from then on, and you would receive separate information at that time.
Purposes
- providing the service: running your account and collection, sign-in, sync, premium;
- sending transactional messages (sign-in codes, account deletion and data export emails);
- understanding how the app is used — only with consent;
- improving card recognition from photos — only with consent;
- marketing messages — only with consent;
- security, abuse prevention and accountability.
Legal bases
| Purpose |
Legal basis (GDPR) |
| Providing the app and the account |
Art. 6(1)(b) — performance of a contract |
| Product analytics |
Art. 6(1)(a) — consent |
| Photo dataset to improve recognition (scan_dataset) |
Art. 6(1)(a) — consent |
| Marketing messages |
Art. 6(1)(a) — consent |
| Security, rate limits, audit log of account operations |
Art. 6(1)(f) — legitimate interest |
| Keeping records of acceptance of the policy and terms |
Art. 6(1)(c) — legal obligation (accountability, Art. 5(2) GDPR) and Art. 6(1)(f) — legitimate interest |
You can withdraw any consent at any time in the app under "Privacy and data". Withdrawal does not affect the lawfulness of processing carried out before it.
Processors
We use the following providers, who process data on our behalf:
| Processor |
Role |
Region |
| Supabase |
database, authentication, Edge Functions |
EU — AWS eu-central-1 (Frankfurt) |
| Cloudflare R2 |
card images, private files, data exports |
EU jurisdiction buckets |
| Cloudflare CDN |
delivery of public card images |
global network |
| Cloudflare Pages |
hosting of these documents |
global network |
| PostHog |
product analytics, only with consent |
EU cloud (eu.i.posthog.com) |
| Resend |
transactional email: sign-in codes, deletion and export emails |
see below |
Where data is transferred outside the European Economic Area, the transfer relies on the Standard Contractual Clauses approved by the European Commission.
When you choose to sign in with Google or Apple, Google (Google Sign-In) and Apple (Sign in with Apple) act as identity providers; their own privacy policies govern their processing.
We do not sell your data and do not share it with advertisers.
Retention and deletion
- Account deletion. Deleting your account in the app (Settings → delete account) starts a 30-day grace period. During it you can sign in and restore the account. After 30 days all data is permanently deleted: database rows, files and exports.
- Anonymous accounts. An anonymous account (not linked to email, Google or Apple) that deletes itself is removed immediately. Anonymous accounts are also removed automatically, together with their data, after a long period of inactivity.
- Analytics. At permanent deletion we request deletion of the person and their events in PostHog; this can take up to 7 days.
- Backups. Database backups keep data for up to 7 days after deletion, after which it is gone.
- Audit log. The audit log keeps only a SHA-256 hash of the user id and is retained for accountability.
- Card photos. Crops collected with the "scan_dataset" consent are kept until the account is deleted or until you separately ask us to delete them.
- Data exports. An export link is valid for 24 hours.
Your rights
You have the right to:
- access your data;
- rectify your data;
- erasure of your data;
- restriction of processing;
- data portability (Art. 20 GDPR) — choose "Download my data" in the app; you receive an email with a link to a ZIP archive containing export.json and collection.csv; the link is valid for 24 hours and you can request at most one export per 24 hours;
- object to processing based on legitimate interest;
- withdraw consent at any time, without affecting the lawfulness of processing before withdrawal.
To exercise your rights, use the app settings or write to privacy@usebindr.com.
You also have the right to lodge a complaint with the Polish supervisory authority: Prezes Urzędu Ochrony Danych Osobowych (UODO), ul. Stawki 2, 00-193 Warszawa, uodo.gov.pl.
Security
Data is encrypted in transit (TLS). User data is accessed only through controlled backend functions, and requests are rate-limited to prevent abuse.
Children
The app is not directed at children under 16 without the consent of a parent or legal guardian.
Changes to this policy
New versions are published at a new versioned address. If you accepted an earlier version, the app asks you to accept the new one before you continue.
Contact
Bindr Sp. z o.o., ul. Uniwersytecka 13, 40-007 Katowice, Poland
Email: privacy@usebindr.com