Zum Inhalt springen

Privacy Policy

Last updated: 14 August 2026

RareBit (“RareBit”, “we”, “us”) is a trading-card-game collection tracker available at rarebit.app and as a mobile app for iOS and Android. This policy explains what personal data we collect, why, who we share it with, and the rights you have over it. We are the data controller for the data described here. RareBit is operated from the European Union and we apply the EU General Data Protection Regulation (GDPR) to everyone, wherever you are.

The controller is RareBit, reachable at privacy@rarebit.app. This policy covers the website, the iOS and Android apps and the developer API alike.

Data you give us

When you create an account and use RareBit, we store:

  • Account — your email address, a securely hashed password (we never store it in clear text), an optional display name, your interface language and your preferred display currency.
  • Sign-in with Apple or Google (optional) — if you sign in with one of these providers instead of a password, we receive from them the email address and (where you allow it) the name associated with that account, plus the provider’s stable user identifier, and we store them to create and recognise your RareBit account. If you use Sign in with Apple and choose to hide your email, we only ever see Apple’s relay address. We never receive your password with either provider.
  • Your collection — the cards, sealed products and video games you add to your portfolio and wishlist, with their quantity, language, condition/grade, optional purchase price, date and notes, plus the price alerts, binders and set-completion progress you create. This is the data that makes your collection persist across devices.
  • Public profile (optional) — if you choose to publish a public profile, the username (slug), short bio and avatar image you set become visible to anyone with the link. It is off by default and you can unpublish it at any time.
  • Developer API (optional) — if you create API keys, we store a hashed token, the scopes and usage/rate-limit counters for those keys.
  • Support & correspondence — any messages you send us.

Data we generate or receive

  • Authentication tokens — short-lived access tokens and refresh tokens kept in your browser’s local storage (web) or secure device storage (mobile) to keep you signed in. We also store hashed, expiring tokens for email verification and password resets.
  • Notifications — if you enable push notifications, we store your browser’s web-push subscription (endpoint and encryption keys) or, in the mobile apps, the push token issued by Expo’s notification service for your device, so we can deliver the alerts you asked for, plus your notification preferences.
  • Subscription and purchase data — if you subscribe to RareBit Pro, we store the status of that subscription (active, cancelled, expired), the plan and billing period, the renewal or expiry date, the store or processor that holds it (Apple App Store, Google Play, RevenueCat Web Billing or Stripe), the product identifier you bought, and the subscriber identifier our payment tooling associates with your account. See “Payments and subscriptions” below. We never receive or store your card number.
  • Technical logs — standard server and CDN logs (IP address, request time, user agent) generated when you use the service, kept for security, abuse-prevention and debugging. We also record the IP address last used by an API key, for the same reasons.
  • Crash and error diagnostics — when the app or our servers hit an error we collect a diagnostic report (the error and its stack trace, app version, device model and operating-system version). These reports are used only to fix faults; we configure our error-reporting tool not to attach personal data to them.
  • Product analytics — how RareBit is actually used: the pages and screens you open, the actions you take (a scan, adding a card to your portfolio, reaching a feature that needs a subscription, starting or completing a checkout), whether they succeeded or failed, your app or browser version, device type and operating system, and the country your IP address resolves to. Each event carries a random identifier for your browser or device and, once you are signed in, your RareBit user identifier. We use this to see where people get stuck and to fix it — never to build an advertising profile.
  • Session recordings — a replay of your own session: which screens you moved through, where you tapped or clicked, and where you stopped. It is a reconstruction of the interface, not a recording of your camera, microphone or screen outside RareBit. Everything you type is masked before it leaves your device, and so are the figures that say what your collection is worth. We use it only to understand where the product fails people. See “Analytics, advertising and your choices” below for how to switch it off.
  • Advertising measurement — if you reach RareBit by clicking one of our ads, the click identifier the ad platform adds to the link (Google’s gclid, TikTok’s ttclid) and, where present, the campaign parameters in the address. If you later subscribe, we tell that platform that the click led to a subscription, so we know which ads are worth paying for. This is measurement of our own advertising, described in its own section below.

Our card-scan feature processes images on your device and only sends an anonymous perceptual hash for recognition — the photo itself is not uploaded, and scan telemetry is not linked to your account.

Our grading feature — the one that measures how well a card is centred — works differently, and it is only fair to say so plainly: those photos are transmitted to our servers, because that is where the measurement happens. They are held in memory for the length of that single request, measured, and then dropped. They are never written to disk, never saved in our database or in object storage, and never passed to an AI provider or to any other third party — the only companies involved are the ones that carry and run the request (our content-delivery/security provider and our host, both listed below). What we keep is the result and not the picture: the measured centring, the sub-scores, how many photos backed them, and when. That result is deleted together with the card it belongs to, or with your account.

How we use your data

  • To provide the service — your account, collection, valuations and alerts (performance of our contract with you).
  • To send essential service email — verification, password resets and the price-alert notifications you set up.
  • To sell, provision and renew Pro and API subscriptions, to restore a purchase you already made on another device, and to prevent abuse (contract and our legitimate interest in a secure, sustainable service).
  • To keep RareBit secure, debug problems and comply with our legal obligations, including tax and accounting rules that apply to what you pay.
  • To understand how RareBit is used and make it better — which features people reach, where a flow breaks down, which screens people leave (your consent on the website; our legitimate interest in a product that works in the mobile apps, where you can turn it off in Settings).
  • To measure our own advertising — to know which campaign brought someone who went on to subscribe, so we stop paying for the ones that bring nobody (your consent).

We do not sell your personal data, and we do not buy profiles about you from anyone. There are no ads inside RareBit, and we never use your collection, your holdings or what they are worth to target advertising. RareBit does not access your device’s advertising identifier (IDFA on iOS, Advertising ID on Android) and therefore never asks for App Tracking Transparency permission. What we do measure, and how to switch it off, is the next section.

Analytics, advertising and your choices

RareBit is a small operation and we advertise it. That means two kinds of measurement, and they are worth keeping apart because the rules and the controls differ.

Product analytics and session recordings. We use PostHog, hosted on its European infrastructure, to record the events described above and to replay sessions with text and monetary values masked. It is first-party measurement: PostHog processes the data on our instructions and does not use it for its own purposes or for advertising. On the website this runs only if you accept it in the cookie banner, and you can change your mind at any time from the same banner. In the mobile apps it runs by default and you can turn it off in Settings; turning it off stops both the events and the recordings.

Advertising measurement. We run ads on Google and TikTok. When you click one, the platform adds a click identifier to the link; we keep it, and if you later subscribe we send that platform a conversion event — the click identifier, the fact that a subscription happened, its value, and your email address in hashed form so it can be matched without being readable. Google and TikTok are not mere processors here: they act as independent controllers for what they do with that event, under their own privacy policies (Google, TikTok). On the website their tags load only after you consent, and we pass your choice to Google through its consent-mode signals. We do not send them your collection, your portfolio value, or anything you have written in RareBit.

In the mobile apps we measure installs and subscriptions with Google Analytics for Firebase, configured without access to the device advertising identifier, so no App Tracking Transparency prompt is required and no cross-app profile is built. We do not embed a TikTok, Meta or third-party attribution SDK in the apps. A subscription bought inside the app is never reported to an ad platform as an individual conversion: what Apple and Google report back to the advertising platform about app installs is aggregated by the operating system, and we add nothing to it.

Withdrawing consent is as easy as giving it, and it takes effect from that moment on: it does not undo measurement that already happened. Declining changes nothing about what RareBit does for you — every feature keeps working exactly the same.

Who we share it with (processors)

We share data only with the service providers we need to run RareBit and to measure the advertising that pays for it. Each of them processes data on our instructions, with one exception noted at the end of the list:

  • RevenueCat — subscription infrastructure for RareBit Pro on all channels. It receives your RareBit user identifier, the purchase and renewal events reported by the store, the product and price, your country and device platform, so that a subscription bought on one device is recognised on the others.
  • Apple — when you subscribe inside the iOS app, Apple is the seller and processes the payment through your Apple Account, and it provides Sign in with Apple if you use it.
  • Google — when you subscribe inside the Android app, Google Play is the seller and processes the payment through your Google Account, and Google provides Sign in with Google if you use it. Separately, Google Analytics and Google Ads measure our advertising on the web, and Google Analytics for Firebase does the same in the mobile apps.
  • Stripe — card processing for subscriptions bought on the web and for the developer API plans (billing and subscription management).
  • Resend — sending transactional email (verification, password resets, alert notifications).
  • Expo — delivering push notifications to the mobile apps (and, from there, Apple Push Notification service and Google Firebase Cloud Messaging as the platform transport).
  • Sentry — crash and error reporting for the app and our servers, configured without personal data attached.
  • PostHog — product analytics and session recordings, on its European instance. It receives the usage events and recordings described above, tied to a random device identifier and, once you are signed in, your RareBit user identifier. It processes them only for us.
  • TikTok — measurement of the ads we run on TikTok, on the website only. It receives the click identifier from its own ad and, if you subscribe, that a subscription happened and its value, with your email address in hashed form.
  • Amazon Web Services (S3 & CloudFront) — storage and content delivery for images, including your avatar and catalogue artwork.
  • Cloudflare — DNS and content delivery / security in front of our website.
  • Hetzner — our hosting provider (servers and database), located in the European Union.

The exception is advertising measurement: for what they do with the conversion events we send them, Google and TikTok act as independent controllers, not as our processors. That part of the processing is governed by their own privacy policies, and on the web it happens only with your consent.

We may also disclose data where required by law, or to protect the rights, safety and security of RareBit and its users.

Payments and subscriptions

RareBit is free to track your collection, and exporting your data is free. Payment applies only to RareBit Pro and to our developer/business API plans. Pro can be bought through three channels, and the channel decides who takes your money:

  • Inside the iOS app — the seller is Apple. The charge is made to your Apple Account and is governed by the Apple Media Services Terms and Apple’s Privacy Policy. We never see your payment method; we receive only the transaction and subscription status.
  • Inside the Android app — the seller is Google. The charge is made to your Google Account under the Google Play Terms of Service and Google’s Privacy Policy, with the same limits on what reaches us.
  • On the web — checkout is handled by RevenueCat Web Billing or by Stripe. Your card details are entered directly with the payment provider and never reach RareBit’s servers; we only receive the billing status needed to provision your plan, and the billing details the provider needs to invoice you are held by them.

In every case what we store is the minimum needed to know that you are entitled to Pro and until when: plan, period, status, renewal date, store, product identifier and subscriber identifier. Invoices and payment receipts are issued by the store or payment provider under its own privacy policy. What the stores tell you about the subscription itself — price, renewal, how to cancel — is in our Terms & Conditions.

Pricing data sources

The market prices shown in RareBit are aggregated from third-party marketplaces and data providers, including Cardmarket, TCGplayer, CardTrader and eBay. These are read-only reference prices — we send no personal data to them. Prices are indicative and are not financial or investment advice. Each source remains subject to its own terms and privacy practices.

Cookies & local storage

On the website we use three kinds of storage, and only the first is set without asking you.

  • Strictly necessary — the authentication tokens that keep you signed in (kept in your browser’s local storage, not in a cookie), your language, the cookies our content-delivery and security provider (Cloudflare) sets to keep the site up, and a small cookie remembering how you first arrived — a referral link, a campaign name — so that a signup can be credited to it. The separate RareBit CMS admin uses a session cookie for staff only. These do not need your consent and cannot be switched off without breaking the site.
  • Analytics — set by PostHog only if you accept them, to link the events and the session recording described above into one visit.
  • Advertising measurement — set by us, Google and TikTok only if you accept them, to remember the click identifier of the ad that brought you and to report a subscription back to the right campaign.

You choose between them in the banner shown on your first visit, and you can reopen it from the footer at any time. Declining leaves every feature of RareBit working.

The mobile apps do not use cookies. They keep local preferences and a cached copy of your collection on the device so it works offline, plus a random analytics identifier if you leave analytics on; uninstalling the app removes all of it.

International transfers

Our servers and database are hosted in the European Union (Hetzner), and we chose PostHog’s European instance so that analytics and session recordings stay in the EU too. Some recipients (RevenueCat, Stripe, Resend, Sentry, Expo, Apple, Google, TikTok and AWS CloudFront edge locations) may process data outside the EU, including in the United States. Where that happens, transfers are protected by appropriate safeguards such as the European Commission’s Standard Contractual Clauses or an adequacy decision (including the EU–US Data Privacy Framework where the recipient is certified).

How long we keep it

We keep your account and collection data for as long as your account is active. Verification and password-reset tokens expire automatically. Technical, security and crash-diagnostic logs are kept for a limited period. Session recordings are deleted after 30 days and usage events after 12 months; the click identifier of an ad is kept for 90 days from the click, which is the window in which a subscription can still be credited to it. If you delete your account, we delete or anonymise your personal data, except where we must retain certain records — in particular billing and tax records, which accounting law requires us to keep for up to ten years. Deleting your RareBit account does not cancel a subscription bought through the App Store or Google Play: cancel it in that store, otherwise it keeps renewing.

Your rights

Under the GDPR you can:

  • Access the personal data we hold about you and ask for a copy.
  • Correct inaccurate data — you can edit your account, email and profile in-app.
  • Export your collection at any time, for free, from your portfolio (CSV download) — your right to data portability is built into the product.
  • Delete your account and associated personal data — from Settings in the app or the website, or by following these instructions.
  • Restrict or object to certain processing, and withdraw consent where we rely on it — for analytics and advertising measurement you can do it yourself, from the cookie banner on the website (reopen it from the footer) or from Settings in the mobile apps.
  • Lodge a complaint with your local data-protection authority.

To exercise any of these rights, email privacy@rarebit.app. We will respond within the time limits the law requires. If you are in Italy, the supervisory authority is the Garante per la protezione dei dati personali; elsewhere in the EU/EEA it is the authority of your country of residence.

Security

We protect your data with industry-standard measures: encrypted connections (HTTPS), hashed passwords and tokens, scoped access for staff and providers, and an EU-hosted database. No system is perfectly secure, but we work to keep your data safe and to respond quickly if something goes wrong.

Children

RareBit is not directed at children under 16 and we do not knowingly collect their data; subscriptions can only be bought by someone old enough to hold the store account that pays for them. If you believe a child has given us personal data, contact us and we will remove it.

Changes to this policy

We may update this policy as RareBit evolves. We will change the “last updated” date above and, for material changes, give notice in the app.

Contact

For any question about this policy or your data, contact RareBit at privacy@rarebit.app. See also our Terms & Conditions and how to delete your account.