Register

Privacy Policy

Version 1.0 · Effective September 2, 2026

What Cardium collects, why, who sees it, how long we keep it, and the choices you have. Written to match what the service actually does. Part of the Terms of Service.

See also: Terms of Service · Content Policy

1. Overview

Cardium is operated by UVstocks LLC (“we”, “us”), at cardium.gg. This policy covers the Cardium website, API and any app that links to it. It does not cover other UVstocks products, which have their own policies.

The short version: we collect what we need to run an account, identify and price cards, host what you choose to publish, and keep the service safe. We do not run advertising, do not use tracking scripts, and do not sell personal information. Details follow.

2. What we collect

Account

  • Email address, and a display name if you give one.
  • Your password, stored only as a salted hash (argon2id). We cannot read it. Verification and reset links are single-use tokens, also stored hashed.
  • The version of the Terms of Service you accepted and when.
  • Sign-in sessions: a hashed session identifier, when it was created, renewed and last used, and the IP address and browser (user agent) it came from, so you can recognise and revoke sessions and so we can spot account takeover.
  • A short-lived count of failed sign-in attempts per IP address, used only to slow password guessing.

Your profile and what you publish

  • Handle, display name, bio, showcase picks, badges and profile visibility setting. Profiles are private until you make them public.
  • Posts, replies, hashtags, likes, follows, custom feeds, and any images you attach to posts once image posting is available. Public posts are visible to anyone, including people without an account.
  • Business profiles (name, bio, location, hours, website, phone, email) if you run a shop on Cardium, and any custom domain you connect.
  • Blocks, mutes and reports you make, and moderation records about content you published (see section 4).

Scans and collections

  • When you scan a slab or card, the photo is processed to identify it. We do not keep the photo. We keep a fingerprint of it (a SHA-256 hash), the label or card details the identification produced, which model read it, and how much that read cost us, all tied to your account and the time of the scan.
  • Your collection, wishlist, master sets and the values we compute for them. These are private unless you choose to show them on a public profile.

Billing

  • If you subscribe, Stripe is our payment processor. We store the Stripe customer and subscription identifiers, your plan and its status and renewal date. Card numbers and billing addresses are collected and stored by Stripe, never by us.

Support and email

  • Messages you send us, and our replies.
  • Which optional notification channels you have turned on, and the notifications we have shown you.

Automatically

  • Server logs: the IP address, browser, pages or API routes requested, time, and any errors. Used for security, debugging and capacity, then discarded.
  • Usage counts that enforce plan limits (for example scans per day) and social rate limits.

We do not collect precise location, contacts, biometrics, or data from other companies about you. The only “location” we hold is whatever your IP address implies.

3. How we use it

  • To create and secure your account and sign you in.
  • To identify cards and slabs, compute prices and confidence, and show you your collection's value.
  • To publish what you choose to publish, to the audience you chose.
  • To keep the community safe: reviewing content against the Content Policy, handling reports and appeals, and acting on accounts that break the rules.
  • To bill subscriptions and apply plan limits.
  • To send you transactional email (verification, password reset) and, only if you turn them on, notification digests.
  • To answer support requests.
  • To operate, debug and improve the service, including measuring what our AI models cost and how accurate they are.
  • To comply with the law and enforce our Terms.

We do not use your data for advertising, do not build advertising profiles, and do not send marketing email unless you have asked for it.

4. AI processing: identification and moderation

Two parts of Cardium send your content to an AI model. In both cases the model provider is Anthropic, which processes the content as our service provider under its commercial terms and does not use it to train its models.

Identification. A scan photo is sent to the model to read the label or recognise the card. The photo is held in memory for the request and not stored; what we keep is described in section 2.

Content moderation. When you publish a post, its text and any attached images are sent to the model, along with the Content Policy categories, and the model returns a classification: clean, flag for review, or a category it believes applies, with a confidence score and a short reason. We store that verdict against the post, together with the model used and its cost. A person on the Cardium team reviews anything the model flags, and the decision they make is stored next to the model's verdict so we can measure how accurate the model is. For a small set of serious categories we may remove a post automatically when the model is highly confident; you are told the category and can appeal, and every appeal is decided by a person. The Content Policy explains the categories and the appeal process.

We do not use AI to make decisions about your account, your subscription, or your prices.

5. Who we share it with

Service providers that process data on our behalf, under contracts that restrict them to providing the service to us:

ProviderWhat forWhat they receive
Amazon Web ServicesHosting, database, file storage, email deliveryEverything we store; email addresses we send to
AnthropicCard identification and content moderation (section 4)Scan photos; post text and images
StripeSubscription billingEmail address and the plan you chose; card details you enter with Stripe
JustTCGReference prices for raw cardsCard identifiers only, nothing about you
UPCitemdbProduct lookup for dealer inventory barcodesBarcodes only, nothing about you
SquarePayments and inventory sync for dealers who connect itOnly what the dealer authorises; we store the connection tokens encrypted

Other users and the public. Anything you publish to a public profile, feed or business page is visible to anyone, and may be copied or indexed by others. Your handle and display name appear on your posts and on lists of who follows whom.

Legal and safety. We disclose information when the law requires it, in response to a valid legal request, or when we believe in good faith it is needed to prevent serious harm, investigate fraud or abuse, protect our rights, or enforce our Terms. Where the law requires us to report certain content, we do.

Business transfers. If Cardium or UVstocks LLC is involved in a merger, acquisition or sale of assets, your data may be transferred as part of it. We will tell you before it becomes subject to a different policy.

We do not sell personal information and do not share it for cross-context behavioural advertising. There are no advertising or analytics partners.

6. Cookies and browser storage

Cardium does not use cookies for tracking and loads no third-party analytics, advertising or social-media scripts. To keep you signed in, the app stores your session tokens and a few preferences (such as your theme) in your browser's local storage; signing out clears them. Because nothing here tracks you across sites, we do not show a cookie banner. We do not respond to browser Do Not Track signals, as there is no tracking to turn off.

7. How long we keep it

  • Account, profile, collection, posts: for as long as your account exists. Content you delete is removed from every public view immediately and from our systems after that, except as noted below.
  • Sessions: a session expires after 30 days without use and 90 days at most; revoked and expired sessions are cleaned up.
  • Scan records: the fingerprint, identification result and cost of each scan are kept for the life of your account and, in aggregate form, for our accounting. The photos themselves are never stored.
  • Moderation records: reports, model verdicts, staff decisions, appeals and the content they concern are kept while your account exists and afterwards for as long as we need them to handle disputes, meet legal obligations, or protect other users.
  • Billing records: subscription history is kept as long as tax and accounting rules require.
  • Server logs: a limited period for security and debugging, then discarded.

When you delete your account (section 9) we delete or anonymise your personal information within 30 days, keeping only what the exceptions above require.

8. Security

Passwords are hashed with argon2id; session tokens are stored only as SHA-256 digests; payment card data never touches our systems; dealer payment-provider tokens are encrypted at rest; all traffic uses TLS; access to production data is limited to the people who run the service. No system is perfectly secure. If we learn of a breach affecting your data we will notify you as the law requires.

9. Your choices and rights

  • Profile visibility: your profile, collection and posts are private until you choose otherwise, and you can make them private again at any time in settings.
  • Email: transactional email (verification, reset) is part of having an account; notification digests are off unless you turn them on, and can be turned off in settings.
  • Sessions: signing out ends the current session; changing your password ends all of them.
  • Access, correction, export, deletion: you can edit your profile and content in the app. To get a copy of your data, correct something you cannot edit yourself, or delete your account, email support@cardium.gg from the address on the account. We will verify the request, act on it within 30 days, and tell you what, if anything, we had to keep and why. Self-serve export and deletion are on our roadmap.
  • Not being discriminated against: exercising any of these rights never affects the price or quality of the service you get.

10. Dealer desk and customer records

Shops on Professional and Enterprise plans can keep customer records (name, email, phone, notes), inventory, deals and staff logins in the dealer desk. Those customer records are the dealer's data: the dealer decides what to collect and is responsible for telling its customers and honouring their requests. We process the records only to provide the dealer desk, do not use them for anything else, and delete them when the dealer deletes them or closes the account.

Staff logins created by a dealer hold a username and a password hash and are tied to the dealer's account; they are not Cardium accounts of their own. Actions taken by staff are attributed to the login that made them, so the dealer can see who did what.

If you are a dealer's customer and have a question about a record a dealer holds on Cardium, contact the dealer first; if you cannot, contact us and we will help route the request.

11. California privacy notice

This section supplements the rest of the policy for California residents under the California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA/CPRA”).

Categories of personal information collected in the last 12 months

CategoryCollectedExamples at Cardium
A. IdentifiersYesEmail, handle, display name, IP address, account and Stripe identifiers
B. Customer records (Cal. Civ. Code §1798.80(e))YesName and email; phone and business details for shops
C. Protected classificationsNo
D. Commercial informationYesSubscription history; cards you track, scan or list
E. Biometric informationNo
F. Internet or network activityYesServer logs, session records, usage counts
G. Geolocation dataNoOnly what an IP address implies
H. Sensory dataYesPhotos you scan (not retained) and images you attach to posts
I. Professional or employment informationNo
J. Education informationNo
K. InferencesNoWe infer things about cards, not about you
L. Sensitive personal informationYesAccount credentials (stored hashed)

Sources, purposes and disclosure

We obtain this information directly from you, automatically from your use of the service, and from our service providers (for example Stripe telling us a payment succeeded). We use it for the business purposes in section 3 and disclose it to the service providers in section 5. In the last 12 months we have not sold personal information and have not shared it for cross-context behavioural advertising, and we do not sell or share the personal information of anyone under 16. We use sensitive personal information only to provide the service, so there is no separate “limit use” choice to make.

Your rights

California residents have the right to know what personal information we collect, use and disclose; to access it and receive a portable copy; to correct inaccurate information; to delete it, subject to the exceptions the law allows (for example completing a transaction, security, legal obligations); and not to be discriminated against for exercising these rights. To exercise them, email support@cardium.gg from the address on your account, or have an authorised agent do so with proof of authority. We will verify the request and respond within 45 days, extendable once by 45 days with notice. Requests are free, and disclosures cover the 12 months before the request.

Do Not Track and Shine the Light

We do not respond to Do Not Track signals because we do not track users across sites. We do not share personal information with third parties for their own direct marketing, so there is nothing to report under California's Shine the Light law (Civil Code §1798.83).

Minors

Under California Business and Professions Code §22581, California residents under 18 who are registered users may request removal of content they posted publicly. Cardium requires users to be 18 or older, so we expect no such accounts; if one exists, contact us and we will remove the content.

12. Children

Cardium is for adults. We do not knowingly collect personal information from anyone under 18, and never from anyone under 13. If you believe a child has created an account, contact us and we will delete it.

13. Where your data is processed

Cardium is hosted in the United States on Amazon Web Services, and our service providers operate there. If you use Cardium from outside the United States, your information is transferred to and processed in the United States, where privacy law may differ from your own. By using the service you agree to that transfer.

14. Changes to this policy

This is version 1.0. When we change what we collect or how we use it, we publish a new version with a new effective date at /legal/privacy, note it in the changelog, and for material changes give notice in the service or by email before the change takes effect.

15. Contact

Privacy questions and requests: support@cardium.gg, or UVstocks LLC, 4639 Da Vinci St, San Diego, CA 92130, United States.