Privacy Policy

Last updated: 29/08/2026

This policy informs you pursuant to Art. 13 and 14 GDPR about which personal data we process when you use the app VaultDex, for what purposes, and on what legal basis.

1. Controller

The controller responsible for data processing within the meaning of the GDPR is:

  • Leon Achteresch
  • Seippelstr. 2
  • 44803 Bochum
  • Deutschland
  • E-Mail: info@vaultdex.de

2. Account and sign-in

When you create an account, we process the email address you provide, your name or username, and an encrypted password. Optionally, you can sign in with "Sign in with Apple" or Google; in that case we receive a pseudonymous identifier and, where applicable, your email address from Apple or Google.

Purpose: provision of your account and personalized features. Legal basis: Art. 6(1)(b) GDPR (performance of contract).

3. Collection, profile, and social features

When you use the app, we store the content you create: your card collection, binders, wishlists, challenges, your profile (display name, bio, avatar, showcase), stories (time-limited posts), as well as friendships and comparisons.

If you make profile content, showcase items, or stories visible to friends, they can be accessed by your confirmed friends. Stories are automatically hidden after they expire; we store which users have viewed a story. Legal basis: Art. 6(1)(b) GDPR as well as Art. 6(1)(f) GDPR (provision of social features).

4. Card scan and use of artificial intelligence

When you scan a card, the captured photo is first transmitted to our own recognition service, where it is evaluated by automatic image matching against the card catalog; the photo is not permanently stored in this step. If the matching does not produce a definitive result, the photo is additionally transmitted to an external AI service: via the intermediary service OpenRouter, Inc., USA to AI models from Google LLC (Gemini-Modelle); depending on the feature, models from NVIDIA Corporation (Nemotron-Modelle) or Meta Platforms, Inc. (Llama models) may also be used. The image is evaluated there to determine the set and card number. Transmission occurs server-side through our service, subject to the requirement that the providers do not use the images for training purposes; no direct access key is stored in the app.

This transmission only occurs if you have previously given explicit consent. You will be asked for your consent before the first scan, and you can also use the app without the scan feature (e.g. through manual search).

Legal basis: Art. 6(1)(a) GDPR (consent). You can withdraw your consent at any time with effect for the future in the settings. Processing may involve transfer to the USA; we rely on appropriate safeguards (standard contractual clauses pursuant to Art. 46 GDPR).

5. Location and card shops

In the "Shops" section, you can view card shops near you on a map. For this, we access your approximate location only with your permission and only while in use. The location is used for display and is not permanently stored on our servers.

When you add a new shop, we use OpenStreetMap (Nominatim) and Google Search server-side for search and address resolution; your approximate location may be transmitted as the search area in the process.

Legal basis: Art. 6(1)(a) GDPR (consent via the system prompt). You can revoke the permission at any time in your device settings.

6. Photos and images

For scan captures and shop photos, we require access to the camera and photo library. Captures are only used for the respective purpose (card recognition or shop entry).

7. Optional scan test data

In the settings, you can voluntarily enable storage of captured scan images together with the associated card to improve recognition. This feature is disabled by default. Legal basis: Art. 6(1)(a) GDPR (consent), revocable at any time.

8. Price data from third-party sources

The market prices displayed in the app come from publicly accessible third-party sources (including Cardmarket, TCGplayer, tcggo, PriceCharting, eBay, Yuyutei, Collectory, Sisemon, pokewallet.io, pokedata.io). This data is retrieved server-side without transmitting your personal data to these sources.

9. Hosting and technical provision

App data is stored on server infrastructure operated by us (Supabase/PostgreSQL). To deliver app updates, we use Expo Application Services (EAS). Technical connection data (e.g. IP address, app version) may be processed in the process.

The app retrieves exchange rates for currency conversion from the service Frankfurter (frankfurter.dev, daily rates of the European Central Bank); card images may be delivered via the image proxy wsrv.nl. For technical reasons, your IP address is transmitted to the respective service during these requests; no further personal data is transmitted.

Legal basis: Art. 6(1)(f) GDPR (secure and stable provision of the service).

10. Analytics and usage statistics (PostHog)

To improve the app, we use the analytics service PostHog (PostHog Inc.). Processing takes place on servers in the European Union (EU cloud, eu.posthog.com). Usage events (e.g. sections accessed, features used), app version, and device information are collected. For signed-in users, a pseudonymous user identifier (your account ID) is transmitted to associate events with an account; the data is therefore not fully anonymous. An email address is not transmitted to PostHog. We use the data exclusively for internal statistics; no disclosure to third parties for advertising purposes takes place.

Collection only occurs if you have consented via an explicit, cross-platform consent dialog in the app (identical on iOS and Android) at first app launch. On iOS, Apple's App Tracking Transparency (ATT) is additionally requested; collection only takes place if both your in-app consent and ATT permission are granted. On Android, only in-app consent applies. No analytics data is collected until you actively consent. Legal basis: Art. 6(1)(a) GDPR (consent). The time and version of your consent are stored. You can withdraw your consent at any time with effect for the future in the app settings under "Usage statistics" (on iOS additionally in system settings).

11. Support requests

For questions and issues, you can submit support requests (tickets) in the app and chat with us. In doing so, we process the content you provide (subject, category, messages) as well as your account in order to respond to your request. Replies may additionally be delivered to you via push notification.

Legal basis: Art. 6(1)(b) GDPR (performance of contract). Support requests are stored with your account and removed when your account is deleted.

12. Recipients and transfers to third countries

Your data is only disclosed to the extent necessary to provide the app:

  • OpenRouter, Inc., USA, Google LLC (Gemini-Modelle), NVIDIA Corporation (Nemotron-Modelle), and, where applicable, Meta Platforms, Inc. – scan images transmitted exclusively for card recognition (USA).
  • Apple or Google – when using the respective sign-in as well as for app distribution.
  • Apple or Google – processing of in-app subscriptions (VaultDex Pro) via App Store or Google Play.
  • RevenueCat, Inc. (USA) – management and verification of subscription entitlements; processes a pseudonymous user ID and purchase information.
  • Apple Push Notification service or Google Firebase Cloud Messaging (mediated via Expo) – delivery of push notifications (e.g. price alerts, wishlist digests, weekly recaps, support replies), only when permission is enabled; processes a device push token.
  • Expo Application Services – for app updates.
  • PostHog Inc. – usage statistics, only with your consent; processing on servers in the EU.
  • wsrv.nl – image proxy for delivering card images; processes your IP address.
  • Frankfurter (frankfurter.dev) – retrieval of daily exchange rates; processes your IP address.
  • OpenStreetMap Foundation (Nominatim) and Google – server-side search and address resolution when adding card shops.

Where data is transferred to third countries (in particular the USA), we rely on appropriate safeguards pursuant to Art. 44 et seq. GDPR.

13. Storage period and deletion

We store your data for as long as your account exists. If you delete your account (in settings under "Delete account"), your profile and associated data are irrevocably removed, unless statutory retention obligations apply.

14. Your rights

Under the GDPR, you have the following rights:

  • Access to the data stored about you (Art. 15)
  • Rectification of inaccurate data (Art. 16)
  • Erasure (Art. 17)
  • Restriction of processing (Art. 18)
  • Data portability (Art. 20) – you can initiate an export of your data in the settings
  • Objection to processing based on legitimate interests (Art. 21)
  • Withdrawal of consent given with effect for the future (Art. 7(3))

To exercise your rights, a message to info@vaultdex.de is sufficient. You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR).

15. Minors

The app is not directed at children. Use is intended for persons aged 16 and above; younger persons require the consent of their legal guardians.

16. Changes to this policy

We update this privacy policy when features or the legal situation change. The current version is available in the app and at the website address stated above.