Privacy Policy
Last updated: 11 August 2026
Applies to: the Cardient iPhone and iPad app, and this website.
Contact: help@lamigsoftware.com
Cardient is made by Lamig Software.
The short version
- Cardient has no accounts. There is no sign-up, no email, no password, and no profile. We do not know your name.
- When you scan a card, the photo of that card leaves your device. It is sent to our server, which passes it to an AI vision service to work out which card it is. We do not keep the image. It is used to answer that one request and nothing stores it afterwards.
- Your collection lives on your device. If you subscribe to Cardient Pro, a copy is also kept on our server so it can be restored to the same device after a reinstall. It is not shared between your devices, because without accounts that is not possible.
- We use analytics, crash reporting and advertising services. They see a pseudonymous device identifier, never a name or an email address.
The rest of this page is the detail.
1. What Cardient does
Cardient identifies Pokémon trading cards from a photo, shows their market value, tracks your collection as a portfolio, and measures card centering before grading. You point your camera at a card; the app sends an image of it to be identified, matches the result against our card catalogue, and shows you what it found.
2. Your install ID
Because Cardient has no accounts, we identify a device rather than a person. On first launch the app generates an install ID: a string of letters and numbers, unique to that installation, created on the device itself.
What that means in practice:
- It is not linked to your name, email address, phone number or any account, because none of those exist in Cardient.
- It is device-bound. It cannot be copied off the device or restored onto another one, so a second device gets a completely different install ID and sees none of the first device's data.
- It is stable across app updates, and it survives deleting and reinstalling the app, which is what allows a Pro subscriber's collection to come back after a reinstall.
- You can see it yourself in the app under Settings → About, and copy it. You will need it if you ask us to delete your server-side data.
The install ID is sent with every request the app makes to our server, and is used as the identifier for analytics and for your subscription.
3. Card photographs — what happens to them
This is the most sensitive thing the app does, so it gets its own section.
When you scan a card, a small image of the card is uploaded to our servers over an encrypted connection. It is a reduced-size copy — enough to read the card, and no more.
Our servers pass that image to Google's AI vision service, which reads the text printed on the card and returns it to us. We look that text up in our own card catalogue and send the matching cards back to your app.
We do not store the image. It exists only for the length of that one request and is never written to any of our databases, storage or logs. Google processes the image as our AI provider under the Google APIs Terms of Service and the Gemini API additional terms; their handling and retention of data sent to their API is governed by those terms and by Google's privacy policy.
Two consequences worth stating plainly:
- Scanning requires an internet connection. Identification happens on our servers, not on your device.
- Photograph anything other than the card and it is still uploaded. Only point the camera at the card you want identified.
You can also import a photo instead of using the camera. Both the scan screen and the centering tool let you pick a photo you already took.
Cardient never gets access to your photo library in order to do this. The picker is run by iOS, outside the app, and hands Cardient only the single image you chose — which is why the app never asks for photo-library permission, and why it cannot see anything else in your library.
What happens next depends on where you imported it:
- A photo imported on the scan screen is uploaded and handled exactly as a camera scan is, described above.
- A photo imported into the centering tool never leaves your device. That measurement runs entirely on your iPhone or iPad.
If we ever change this — if the image starts being retained — this page, the app's privacy manifest and the App Store privacy label will all change together, in the same release.
4. What else leaves your device
| What | Goes to | Why | Kept? |
|---|---|---|---|
| Card photograph — camera or imported (see §3) | Our server → Google's AI vision service | To identify the card | Not kept by us |
| Install ID | Our server | To authenticate the device's requests, count your free daily scans, and unlock Pro | Kept while you use the app |
| Card lookups and searches | Our server | To return card details and prices | Not stored against your install ID |
| Collection rows — card, quantity, condition, foil, and any purchase price you typed in | Our server (Pro only) | Same-device backup and restore | Kept until deleted |
| Purchase and subscription state | Apple → RevenueCat → our server | To know whether Pro is active | Kept while the subscription exists |
| App usage events | PostHog, Firebase Analytics | To understand which features are used | Per vendor (see §5) |
| Crash reports | Firebase Crashlytics | To diagnose crashes | Per vendor (see §5) |
| Advertising identifiers and ad interactions | Google AdMob | To serve ads (see §7) | Per Google |
We never collect your name, email address, contacts, precise location, health data, or the contents of your photo library beyond the single image you choose to import.
5. Analytics and crash reporting
| Service | What it receives |
|---|---|
| PostHog (product analytics, hosted in the United States) | Events describing what happened in the app — screens reached, scans attempted and their outcome, onboarding steps, paywall views and dismissals. The identifier attached is your install ID. Automatic capture of taps and screen views is switched off, and session replay is switched off. |
| Firebase Analytics (Google) | The same events, with the install ID set as the user ID. |
| Firebase Crashlytics (Google) | Crash reports: the stack trace, device model, iOS version and app version at the time of the crash. Crash reports are not tagged with your install ID. |
We also forward subscription events from RevenueCat to PostHog on the server side, keyed by install ID, so a purchase can be joined to the sequence of screens that preceded it.
This website
Everything above is about the app. This website — cardient.app — uses Google Analytics 4 to count visits and see which pages people read. It receives the pages you view, an approximate location (country or city level), and the browser and device type you are using. It sets cookies in your browser to recognise a returning visit.
It also records when you click a link that takes you off this site — most often the button that opens our App Store listing. What is recorded is the address of the link and the page you clicked it from, not anything about you. We use it to count how many people set off to download Cardient, and from which page.
That approximate location is derived from your IP address by Google. We never see your IP address, and Google does not retain it in Google Analytics — it is used to work out the rough location and then discarded.
It is not connected to the app in any way. The website does not know your install ID, and nothing you do on this site is joined to anything you do in Cardient. There is no account on either side to join them through.
Links to the App Store may carry a campaign label, which tells Apple which of our links you came from — our website, say, rather than a card handed out at an event. Apple reports those downloads back to us as totals only. We are never told that a particular person installed the app, and the label says nothing about you.
If you are in the EEA, the UK or Switzerland, Google Analytics does not run at all. We do not load it there, so nothing is requested from Google, no cookie is set, and no measurement of any kind takes place — rather than ask for your consent, we simply do not collect. To apply this we check which country your connection comes from; that check happens on our server, stores nothing and is not recorded against you. Everywhere else, Analytics runs as described above.
You can opt out anywhere by using Google's browser add-on, by blocking cookies for this site, or by using your browser's private mode.
These services are subject to their own policies: PostHog, Firebase, Google.
6. Your collection, and the Pro backup
Your collection is stored on your device. The copy on your device is always the authoritative one, and deleting the app deletes it.
If you subscribe to Cardient Pro, the app also mirrors your collection to our servers so it can be restored if you delete and reinstall. What is mirrored: the card identifier, quantity, condition, whether it is foil, the purchase price if you entered one, and a timestamp — plus your saved portfolio value history. Every row is keyed to your install ID.
This is a backup, not sync. Because the install ID is device-bound (§2), another device gets a different ID and a completely separate set of rows. Your iPad cannot see your iPhone's collection. We do not offer multi-device sync, and it is not something we can offer without introducing accounts.
Free users' collections are not sent to our servers at all.
7. Advertising
Cardient can display ads supplied by Google AdMob.
- Before any ad is requested, we present Google's User Messaging Platform consent form where it is required (for example in the EEA and the UK), and Apple's App Tracking Transparency prompt asking whether Cardient may track you across apps and websites.
- If you allow tracking, AdMob may use your device's advertising identifier (IDFA) to serve personalised ads. If you decline, you still see ads, but non-personalised ones.
- Every ad request Cardient makes is tagged as general audience and capped at Google's "General" maximum ad content rating, so ad categories intended for older audiences are not served in Cardient.
- You can change your tracking choice at any time in iOS Settings → Privacy & Security → Tracking.
Google's use of this data is governed by Google's privacy policy and how Google uses information from sites or apps that use its services.
8. Purchases and subscriptions
Cardient Pro is sold through Apple In-App Purchase and managed with RevenueCat.
Apple processes all payment information. We never see your card number or billing details. RevenueCat receives your purchase receipt and the install ID (used as its app user ID, so the subscription stays anonymous there too) and tells us whether Pro is active, what expires when, and whether a subscription came from a purchase or a promotional code. We store that entitlement state against your install ID on our server so Pro features work.
See RevenueCat's privacy policy and Apple's privacy policy.
9. Where data is processed
Cardient's own servers run on Cloudflare's global network; card data, entitlements and the Pro collection backup are stored in Cloudflare's database and storage services. Our analytics, advertising, crash reporting and subscription providers — PostHog, Google and RevenueCat — process data in the United States and elsewhere. If you use Cardient outside those countries, your data is transferred to them.
10. How long we keep things
- Card photographs: not kept (§3).
- Card lookups and scans: not stored against your install ID. We keep a count of how many scans an install has made in a day, purely to enforce the free daily limit; it is deleted automatically after two days.
- Install record, entitlement and Pro collection backup: kept while you use Cardient, until you ask us to delete them (§11).
- Analytics, crash and advertising data: retained by PostHog, Google and RevenueCat under their own policies.
11. Deleting your data
- On your device: deleting the Cardient app removes your collection and all local app data.
- On our servers: email help@lamigsoftware.com from any address with your install ID (Settings → About in the app, where you can copy it) and ask us to delete it. We will delete your install record, your entitlement record and any collection backup rows held against that ID. Because there is no account, the install ID is the only way we can find your data — without it we cannot identify which rows are yours.
- Analytics and advertising: we will pass on deletion requests to PostHog and Google to the extent they allow. You can reset your advertising identifier and turn off tracking in iOS Settings at any time.
If you are in a region with a legal right to access, correct, port or delete personal data, or to object to its processing, write to the same address and we will do our best to honour it — bearing in mind that a pseudonymous, device-bound identifier is genuinely all we hold.
12. Children
Cardient is a general-audience app for card collectors. It is rated 4+, it is not directed at children, and it is not enrolled in the App Store's Kids Category. It serves advertising and is not designed for a child-directed audience. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, contact us and we will delete it.
13. Security
Traffic between the app and our servers is encrypted in transit (HTTPS), and requests are authenticated so they cannot be forged or replayed on your behalf. The credential that does that is created on your device, stays on your device, and cannot be read or extracted — by anyone, including us.
14. Changes to this policy
We will update this page and the date at the top when anything material changes. If what leaves your device changes, this page, the app's bundled privacy manifest and the App Store privacy label are updated together.
15. Contact
Questions, or a deletion request: help@lamigsoftware.com.