Privacy Policy
Last updated: 24 August 2026
Bindy is a trading-card binder organiser. This policy explains what we collect, why, who it is shared with, and how to delete it. If anything here is unclear, email bindy.design@gmail.com.
What you give us
| Data | Why | When |
|---|---|---|
| Email address | Account identity and sign-in | On sign-up |
| Password | Sign-in. Stored hashed by our auth provider; we never see it | On sign-up |
| Username | Shown publicly on shared binders and comments | Optional |
| Profile photo | Shown on your account | Optional |
| Games you collect | Tailors the app to your games | Optional |
If you sign in with Google we receive your email address, name and profile picture from Google. We never receive your Google password.
What you create
Binders — the cards you add, how they are arranged, which you mark as owned, page colours, and any images you upload.
Social activity — binders you choose to make public, plus comments, likes and follows. This is visible to other people by design.
What we collect automatically
How many card photos you have scanned, so we can apply the free scan allowance, and whether you have an active Bindy Pro plan.
We do not collect location, contacts, health data or advertising identifiers. Bindy has no analytics or tracking SDKs.
Camera and photos
Camera is used only when you scan a card. The photo is sent to our server, which forwards it to Google Cloud Vision to read the card name. It is used only for that recognition and is not stored by us.
Photos are accessed only when you pick an image for a binder cover, a card slot, or your profile photo. We see only the images you choose.
Where your data lives
Your account and binders are stored with Supabase, our database and authentication provider, on servers in Canada. A copy of your binders is cached on your device so the app works offline.
Who we share it with
We do not sell your data, and we do not share it for advertising. We rely on these processors:
| Processor | Purpose | What they receive |
|---|---|---|
| Supabase | Database, authentication, file storage | Account and binder data |
| Google Cloud Vision | Reading card names from photos | The scanned photo |
| Sign in with Google | Authentication only | |
| RevenueCat | App Store and Play Store subscriptions | A pseudonymous user id and purchase status |
| Stripe | Payments made on this website | Billing details, handled by Stripe |
Card databases such as TCGdex and Scryfall, and our currency-rate provider, receive only card or currency lookups — never anything about you.
We may disclose data where required by law.
What other people can see
Binders you mark public, including their cards and your username; comments you post on public binders; and your username and profile photo. Binders stay private until you choose to share them.
How long we keep it
We keep your data for as long as your account exists. Deleting your account removes it as described below. Data cached on your device is removed when you uninstall the app.
Deleting your account
In the app, open Settings → Delete Account. This permanently removes your account, binders, shared pages, comments, likes, follows and profile photo. It cannot be undone.
You can also request deletion without the app by emailing bindy.design@gmail.com from the address on your account. We action these within 30 days.
Your rights
You can change or remove your username, profile photo and binders at any time in the app, and make a shared binder private again whenever you like.
Depending on where you live you may also have the right to access, correct, export or restrict processing of your data, and to complain to a data protection authority. Email us to exercise any of these.
Children
Bindy is not directed at children under 13 and we do not knowingly collect their data. If you believe a child has given us data, email us and we will delete it.
Changes
We will update the date at the top when this policy changes, and tell you in the app if the change is significant.
