Legal
Privacy policy.
Effective July 15, 2026
Chasebook Labs LLC builds Chasebook to help collectors scan, organize, and understand their trading-card collections. We do not sell personal information, run third-party advertising in the app, or use card scans for advertising.
Who this policy covers
This policy describes how Chasebook Labs LLC ("Chasebook Labs," "we," "us," or "our") handles information when you use the Chasebook mobile app, chasebook.app, and related services. Chasebook Labs LLC is responsible for the information described here.
Information we process
Account information
If you sign in, we process an account identifier and information supplied by your sign-in provider, which can include your email address and name. Authentication is provided through Supabase and supported Apple, Google, or email sign-in methods.
Collection and preference data
When you use account sync, we store the collection information you choose to save, such as cards, variants, quantities, conditions, containers, wishlists, set preferences, alert settings, and related collection history. Guest data can remain only on your device until you choose to sign in or sync it.
Card scans
When you choose to scan a card, the app sends the image to our service so it can identify the card. Our service currently uses Google Gemini as a vision processor. Chasebook does not save the submitted scan image to its collection database or object storage. We retain limited usage records, such as token counts, request counts, cost estimates, and a pseudonymous device or account key, to enforce quotas, prevent abuse, and operate the feature. Google may process and temporarily retain request content under its paid Gemini API terms for abuse monitoring.
Purchases
Apple or Google processes your payment details. We and RevenueCat receive purchase and entitlement information, such as the product, transaction status, subscription dates, and a Chasebook account identifier, so we can provide and restore Chasebook Pro. We do not receive your complete payment-card number.
Notifications
If you enable push notifications, we process a push token, app and device metadata, your notification preferences, and delivery status so we can send the alerts you request. You can disable notifications in Chasebook or your device settings.
Diagnostics and beta logs
Release builds use Firebase Crashlytics to collect crash reports, stack traces, relevant app state, device metadata, and an installation identifier. Internal test builds can also send pseudonymous session logs containing app version, device model, operating-system version, navigation and feature events, an app-generated installation ID, and a hashed account ID. These logs are designed not to include raw emails, authentication tokens, collection contents, screenshots, or scan images.
Website information
Our hosting and security providers can process ordinary request data such as IP address, browser and device information, requested pages, timestamps, and security signals when you visit chasebook.app.
How we use information
- Provide sign-in, collection sync, scanning, alerts, purchases, restore, and support.
- Keep the service reliable, secure, and resistant to fraud or abuse.
- Diagnose crashes and technical problems and improve app performance.
- Comply with legal, accounting, tax, and platform obligations.
We do not use personal information for third-party targeted advertising and do not sell personal information.
Service providers
We use service providers to run Chasebook. They process information for us under their applicable terms and may include Cloudflare (networking, APIs, storage, and security), Supabase (authentication and account data), Google (Gemini vision, Firebase Crashlytics, Firebase Cloud Messaging, Google sign-in, and Google Play), Apple (Sign in with Apple, App Store, and push notifications), and RevenueCat (purchase and entitlement management). We may also disclose information when required by law or to protect users, our services, or our rights.
Retention and deletion
Account and synced collection data is generally kept while your account remains active. Internal beta log content is scheduled for deletion after 30 days, with its limited lookup index retained for up to 90 days. Other diagnostic, transaction, security, and backup records are kept only as long as reasonably needed for the purposes above, including legal, fraud-prevention, accounting, and dispute obligations.
You can initiate deletion inside the Chasebook app or use our account-deletion page for an off-device request. Store purchase records controlled by Apple or Google remain subject to their policies, and we may retain limited records when legally required.
Security and international processing
We use technical and organizational safeguards intended to protect information, including encrypted network connections and restricted access. No method of storage or transmission is completely secure. Our providers may process information in the United States and other countries where they operate, subject to applicable safeguards.
Children
Chasebook is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided personal information, contact us so we can investigate and delete it as appropriate.
Your choices and rights
Depending on where you live, you may have rights to access, correct, export, delete, or restrict certain processing of your information. You can also control camera and notification permissions in device settings. Contact us to make a request. We may need to verify your identity before acting on it.
Changes and contact
We may update this policy as Chasebook changes. We will post the new effective date here and provide additional notice when appropriate. Questions or privacy requests can be sent to contact@chasebooklabs.com.