Privacy Policy
Last updated: 6 October 2026
Leer esta página en españolIn short
- The scanner runs on your device. What the camera sees does not leave it.
- Only if you send a card to review do we upload a small crop of that card. It is deleted when you resolve it.
- We store your account and collection to give you the service.
- We measure usage with PostHog (EU), without cookies and without your name or email. Usage events are not linked to your account.
- You can export your collection and delete your account yourself, without asking us.
- There is no advertising and we do not sell your data. If that changed, this policy would be updated first.
The rest of this document gives the detail required by the General Data Protection Regulation (GDPR) and Spain's Organic Law 3/2018 (LOPDGDD).
1. Who is the controller
| Item | Value |
|---|---|
| Controller | Jesé Romero Arbelo, a natural person |
| Privacy contact | privacy@holovisor.app |
| Website | https://holovisor.app |
| Apps | Holovisor for iOS and Android (identifier com.holovisor.app) |
We have not appointed a data protection officer: the law does not require one for this processing.
The iOS and Android apps are a shell (Capacitor) that loads https://holovisor.app. This policy applies equally to the website and the apps.
2. What data we process, why, and on what legal basis
2.1 If you have no account
You can use the scanner and look up cards and prices without an account. In that case:
- The camera is processed on your device. We do not upload frames or captures.
- The list of scanned cards you have not saved yet stays on your device (browser storage).
- Our hosting providers see the technical data of any website visit: IP address, browser and pages requested (section 2.8).
- Usage measurement (section 2.6) also works without an account.
2.2 Your account
| Data | Purpose | Legal basis |
|---|---|---|
| Name and email address | Create and maintain your account, identify you, send you verification and password-recovery codes | Performance of a contract (art. 6.1.b GDPR) |
| Password | Sign in with email and password. The authentication service stores it as a cryptographic hash; we never see it | Performance of a contract |
| With «Continuar con Google» (Continue with Google) (web only; the iOS and Android apps do not offer it): name, email and the identifier of your Google account | Sign in without a password of your own | Performance of a contract |
| Internal user identifier, sign-up date, whether the email is verified | Running the account | Performance of a contract |
| Session data (session cookies, start and expiry date) | Keep you securely signed in | Performance of a contract; legitimate interest in security (art. 6.1.f) |
The authentication service (Neon Auth) may also store, with each session, the IP address and browser you signed in from, and, if you sign in with Google, the profile photo of your Google account. Holovisor uses neither.
2.3 Your collection
| Data | Purpose | Legal basis |
|---|---|---|
| The cards you add and, for each lot: language, variant, condition, quantity, and whatever you choose to note (purchase price and date, grading company and grade, certificate number, notes) | Store and show your collection, calculate its value, export it | Performance of a contract |
Notes are free text. Do not write third-party or sensitive data in them.
2.4 Cards sent to review
When you swipe a card left in the scanner, or send it from the list, we place it in a review queue (/review) for you to confirm or discard.
| Data | Purpose | Legal basis |
|---|---|---|
| The card crop (a small JPEG of about 20 KB and at most 320 pixels on its longest side; never the full frame) | Show you your photo next to the proposed card so you can decide | Performance of a contract |
| Which cards the identifier proposed and with what score, the detected language, the model version, the entry status (pending, confirmed, discarded) and the card you chose | Make the review work and let you remember what you decided | Performance of a contract |
The photo is not used to train models. If we ever asked to use crops to improve the identifier, it would be with your prior, optional permission, and this policy would be updated first.
2.5 Purchases and Pro subscription
Purchases are not yet available in production. This section describes what will be processed once they are offered; no payment data is processed today. Holovisor Pro will be optional, and what is processed will depend on where you buy it:
| Data | Who processes it | Purpose | Legal basis |
|---|---|---|---|
| Your plan (free or Pro), where it comes from (App Store, Google Play or web) and when it expires | Us, in our database | Grant or remove access to Pro features | Performance of a contract |
| User identifier (the same as your account), receipts or purchase tokens, product, dates, status (trial, active, cancelled, refunded) and country | RevenueCat | Validate purchases, sync the subscription status and notify us (by webhook) | Performance of a contract |
| The data Stripe needs to take payment, such as the payment method and billing details, for web purchases | Stripe, through RevenueCat Web Billing | Take payment | Performance of a contract |
| Payment, Apple ID or Google account for store purchases | Apple or Google | Take payment and manage the subscription | Performance of a contract (with Apple or Google) |
| Invoices and accounting records | Us, and Stripe / Apple / Google as the case may be | Meet tax and commercial obligations | Legal obligation (art. 6.1.c) |
We will never receive your card number or your Apple or Google credentials.
Our database also stores the identifiers and types of RevenueCat notifications already processed, with no personal data, so the same notification is not processed twice.
2.6 Usage measurement
We use PostHog Cloud EU (servers in the European Union) to learn which parts of the product are used and to improve what does not work.
- Setup: no cookies, nothing stored on your device (memory only while the tab is open), no session recording, no automatic capture of clicks, forms or pages, no surveys.
- Events we send: app opened; scan started; card identified (whether the identifier was sure, language, time, model version); card confirmed or discarded in review; account created (by email or Google); collection reaching 50 cards; end of a scan session (number of images and cards, duration); price-history range chosen; approximate band of your collection's size and value (for example «50-199 cards»); collection export; bulk edit (which fields, not their values); when the Pro wall is shown and whether it is closed; clicks on subscribe; purchase started, completed, failed or restored (plan and platform).
- What we do not send: email, name, photos or captures, cookies, session identifiers, addresses with parameters, text you type, or exact figures of your collection.
- Every event goes through our own filter, before leaving your device, that drops any event or data not on the list.
- To tell visits apart without cookies, PostHog computes a temporary identifier on its server from your browser and IP address. PostHog discards the raw IP and browser before storing the event.
- Events are not linked to your account: they carry no user identifier, name or email.
Legal basis: legitimate interest (art. 6.1.f GDPR) in understanding usage and improving the product, with minimal data and without profiling anyone. You may object (section 7). There is currently no switch in settings to turn measurement off: if you object, write to privacy@holovisor.app.
2.7 Error logging
With the same provider (PostHog EU) we record failures of the application and of our automated processes: which part they come from, the route and the technical trace of the error. Error texts are discarded, except those of our own server processes, which are cleaned (emails, passwords, address parameters, local paths and long strings are removed) and cut to 300 characters. Legal basis: legitimate interest in the security and stability of the service.
2.8 Technical data on the servers
When you visit Holovisor, the servers that host it receive your IP address, your browser, the date and the address requested, and keep them in technical logs. We use them to deliver the site, protect the service against abuse and diagnose failures. We also limit attempts to send email codes by your IP and your email, in memory and temporarily. Legal basis: legitimate interest in security and operation (art. 6.1.f).
One detail: during email verification and password recovery, your email appears in the page address (for example /verify-email?email=…). For that reason it may stay in your browser history and in these logs.
2.9 Emails we send you
Only those needed for the service: email verification and password-recovery codes. The authentication service (Neon Auth) sends them from its own sender and with its own email provider. We send no advertising or newsletters.
2.10 If you write to us
If you send us an email, we process your address and what you tell us in order to reply and, where applicable, handle your request. Legal basis: your request (art. 6.1.b) or our legitimate interest in helping you (art. 6.1.f); if it is a complaint or the exercise of a right, a legal obligation (art. 6.1.c).
2.11 Card and price data
Card data and prices are not personal data. Our server requests them from TCGdex; we send no data about you to TCGdex. We serve card images from assets.holovisor.app (Cloudflare), which, like any web server, sees your IP address.
3. Where we get the data
From you (forms, use of the app, your collection), from your device (technical data), from Google if you sign in with Google and, once purchases are offered, from Apple, Google, Stripe and RevenueCat as regards the status of your subscription.
4. Who we share it with
We do not sell your data or hand it over for advertising. The following providers process data on our behalf, as processors (art. 28 GDPR), under a contract that governs it:
| Provider | Purpose | Data | Where |
|---|---|---|---|
| Neon (database and authentication) | Store accounts, collections and reviews; sign-in | Those in sections 2.2 to 2.5 | AWS eu-west-2 (London, United Kingdom) |
| Vercel (web hosting and functions) | Serve the website, run the server | Technical data of the visit; account data while a request is processed | Functions in lhr1 (London); global distribution network |
| Cloudflare (R2 storage and DNS) | Store review crops (private storage) and serve the public catalogue images | Card crops; IP of whoever requests images | Cloudflare's global network |
| Upstash QStash | Trigger scheduled jobs (daily prices, photo cleanup) | None about users: messages carry only set identifiers and dates | According to the service contracted with Upstash |
| PostHog (EU) | Usage and error measurement | Those in sections 2.6 and 2.7 | European Union (eu.i.posthog.com) |
| RevenueCat (once purchases are offered) | Manage purchases and subscriptions | User identifier, purchases, status, country | According to its policy; RevenueCat, Inc. is a US company |
| Stripe (once web purchases are offered) | Take payment for web purchases | Payment and billing data | According to its policy; Stripe has entities in the EU and the US |
They process data as controllers in their own right (we do not control what they do with it; their own policies apply):
- Apple and Google, as stores and payment providers, and Google as a sign-in provider if you choose «Continuar con Google» (Continue with Google).
- Authorities, when a law requires us to disclose data to them.
5. International transfers
- United Kingdom (database in London, Vercel functions in London): covered by a European Commission adequacy decision.
- United States and other countries (for example, the parent companies of Vercel, Cloudflare, Neon, RevenueCat, Stripe, PostHog and Upstash, plus Apple and Google): when a provider or its parent is outside the European Economic Area, we rely on the adequacy decision for the EU-US Data Privacy Framework if the provider is certified, or on the European Commission's standard contractual clauses, together with additional measures where appropriate.
- You can ask us for more information about these safeguards by writing to privacy@holovisor.app.
6. How long we keep the data
| Data | Period |
|---|---|
| Account (name, email, access, Google link) | While you have the account. When you delete it, it is erased (not anonymised) |
| Verification and recovery codes | Expire after 15 minutes; deleted with your account |
| Session | Until you sign out or the session expires |
| Collection | Until you delete it or delete your account |
| Review entries (without the photo) | Until you delete your account. Resolved ones are kept to remember which card you chose |
| Review photo | Until you confirm or discard the entry, or scan it again (it is replaced). It is also deleted when you delete your account. A daily cleanup (03:00 UTC) deletes those left without an entry |
| Scan list on the device | On your device, until you empty it, save it, clear the browser data or delete your account from that device |
| Pro plan (our database) | While you have the account |
| Usage and error events (PostHog) | The retention period of the plan we have contracted with PostHog |
| Technical server logs | The retention period of the plan we have contracted with Vercel and with Cloudflare |
| Invoices and payment records | The period required by tax and commercial law |
| Emails you send us | The time needed to help you and, afterwards, while liabilities may arise from handling it |
| Backups | Deleted data may remain in database backups for the restore window of the plan we have contracted with Neon |
The periods of RevenueCat, Stripe, Apple and Google follow their own policies.
Deleting your account in Holovisor does not cancel a subscription or delete your history in RevenueCat, Stripe, Apple or Google. Once purchases are offered: cancel the subscription first and, if you want us to ask RevenueCat to delete your history, write to privacy@holovisor.app.
7. Your rights and how to exercise them
You have the right to:
- Access: know what data of yours we process and receive a copy.
- Rectification: correct inaccurate data. Today «Tu cuenta» (your account page) shows your name and email without letting you edit them: ask us for the change by email.
- Erasure: have us delete your data.
- Restriction of processing in the cases the law provides.
- Objection to processing based on legitimate interest, such as usage measurement.
- Portability: receive your data in a structured, commonly used format.
- Withdraw your consent, where processing is based on it, without affecting what was done before. We do not currently process any data on the basis of your consent.
- Not be subject to automated decisions with legal effects. We make none: the card identifier is an automatic model, but it only proposes a card and the decision is always yours.
How, without writing to us:
- Delete your account: «Tu cuenta» → «Eliminar mi cuenta» (the app is in Spanish) → type ELIMINAR and confirm (more information at https://holovisor.app/delete-account). Your account, your collection, your cards pending review, their photos and the scan list of the device you do it from are deleted for good. If you have been signed in for more than a day, it will ask you to sign in again. Deleting the account does not cancel a store or web subscription: cancel it first.
- Export your collection (portability): «Tu cuenta» → «Exportar colección» (CSV).
How, by writing to us: at privacy@holovisor.app, saying which right you want to exercise and from which account email. We may ask you to confirm it to make sure it is you. We reply within one month at most (extendable in complex cases, with notice).
Usage events are not linked to your identity, so we cannot find «yours» to give you access or delete them (art. 11 GDPR). As there is no switch in settings, if you object to measurement write to privacy@holovisor.app and we will handle it by email.
Complaints
If you think we have not handled your data properly, you can complain to the Spanish Data Protection Agency (AEPD): https://www.aepd.es, electronic office https://sedeagpd.gob.es, C/ Jorge Juan, 6, 28001 Madrid. We would appreciate it if you wrote to us first so we can resolve it.
8. Cookies and local storage
We use no advertising, tracking or measurement cookies or storage. Usage measurement (PostHog) writes nothing to your device. What we do store is necessary for what you ask for to work, so we do not need to ask for consent (art. 22.2 LSSI):
| What | Where | Purpose | Duration |
|---|---|---|---|
Neon Auth session cookies (names starting with __Secure-neon-auth.: session, a signed 5-minute copy of the session, and a 10-minute verifier when signing in with Google) | Cookie (HTTPS only) | Keep you signed in and complete «Continuar con Google» (Continue with Google) | Until you sign out or they expire (the signed copy, 5 minutes; the verifier, 10) |
| Account deletion cookie | Cookie, 60 seconds | Empty the device's scan list after the account is deleted | 60 seconds |
| List of scanned cards not yet saved (with their crops) | IndexedDB | So you do not lose what you scanned when you reload or sign in | Until you empty it |
| Scanner models and their files | Browser cache storage | So the scanner works without downloading again | Until you clear the site data |
| Scanner settings (languages of your cards, switches, receipt of the last model version that loaded correctly, notices already seen) | localStorage | Remember your preferences on that device | Until you clear the site data |
| Navigation context between cards | sessionStorage | Move from one card to the next in the list | Until the tab is closed |
Once purchases are offered on the web, payment will be processed by Stripe, which may use its own cookies or storage for fraud prevention; its own policy describes them.
Fonts are bundled with the site itself; they are not requested from Google when the page loads.
In the iOS and Android apps, the camera is used only for the scanner. The system asks you for permission, you can withdraw it in the device settings, and what the camera sees is processed on the device. We do not access your photo library.
9. Minors
Holovisor may appeal to young collectors, but it is not aimed at children under 14, and we do not want their personal data. To create an account you must be at least 14 years old (the age from which the LOPDGDD allows a minor's data to be processed with their own consent); between 14 and 17, with the knowledge of a parent or guardian. Paid subscriptions are for people over 18 only (or those who buy through an adult). If we find an account belonging to someone under 14, we will delete it. If you are a parent or guardian and think your child has given us data, write to privacy@holovisor.app.
The scanner can be used without an account and sends no data to our servers, apart from the technical data and the measurement in section 2.6.
10. Security
We apply reasonable technical and organisational measures: encrypted connections (HTTPS), secure session cookies, passwords stored only as a cryptographic hash, a private photo store with one-hour signed links, a check that each photo belongs to its user, test environments separate from production, and attempt limits to prevent abuse. No system is infallible. If there were a breach that poses a risk to your rights, we will tell you and notify the AEPD where the law requires it.
11. Changes to this policy
If we change something important (for example, a new provider or a new use of your data), we will say so on the website and, where appropriate, by email, before the change applies, and we will change the date above. Earlier versions are available if you ask for them.
12. Contact
- Jesé Romero Arbelo
- Privacy: privacy@holovisor.app
- Support: support@holovisor.app