HitLegend Privacy Policy
Effective date: September 29, 2026. Controller: Unobstructed, LLC ("Unobstructed", "we", "us"). Contact: privacy@hitlegend.com.
1. In one paragraph
You give us your email, a password or a sign-in from Google, Microsoft or Apple, and photos of your cards. We use the photos to identify the cards, we store your collection, and we estimate values from market data. We do not sell your data, share it for advertising, or show you ads. We use service providers to run the product, and they may use your data only to do that work for us. You can export or delete everything at any time.
2. What we collect and why
| Data | Why | Legal basis (where applicable) |
|---|---|---|
| Email, name, password hash, or a provider identity (Google/Microsoft/Apple subject id) | your account and sign-in | contract |
| Photos of cards you upload or capture (pages, crops, backs) | identifying and filing your cards; the record of your collection | contract |
| Card records: what you own, condition, grade, cert number, notes, tags, binders, lists, values, trades you save | the product | contract |
| Copies of your card photos, only if you turn on photo training (section 3a) | teaching our own models to recognise card condition and finish | consent — off unless you turn it on; withdraw any time |
| Device identifier, app version, platform, IP address | sessions per device, compatibility, security and abuse prevention | contract, legitimate interest |
| Usage events (which features are used; no content) | improving the product; measuring reliability | legitimate interest |
| Questions you type into the natural-language box | understanding what collectors ask so we can answer more; reviewed only by our staff | legitimate interest |
| Error reports (device model, OS, app version, the error) | stability | legitimate interest |
| Payment details | billing — held by Stripe or Apple, never by us; we store the subscription status and a customer id | contract |
| Support emails | helping you | contract |
We get this data from you, from your device, and — only if you choose to sign in with them — from Google, Microsoft or Apple (your name, email and an account id). We do not collect precise location, contacts, health data, biometric data or advertising identifiers, and we do not buy data about you.
3. How photos are processed
Card photos are stored privately (there is never a public URL for one) and read by automated systems: our own detection and matching, plus service providers that read the text on a card and match it to a catalogue of cards. They receive the image of the card and return an answer. We use providers whose terms do not allow them to use the images we send to train their models. Catalogue artwork shown beside your photo comes from public card databases and is not your data.
Every photo you upload is also checked automatically for content that is not allowed (nudity, graphic violence, self-harm) before the cards are read, using a service provider's moderation system. A photo it holds back is not read or filed, and our staff review it — without seeing whose it is — to release it or remove it.
Only the people you choose see your photos: members of your shelf, and anyone you give a showcase link to (section 5). Our staff look at a photo only to fix a problem you report, to review a photo the safety check held back, to investigate abuse, or when the law requires it.
3a. Training with your card photos (optional)
*Draft for counsel: consent wording version 2026-09-29.2.*
HitLegend can learn to judge a card's condition and finish from photos. This is off unless you turn it on. We ask once, after your first scan, and you can change your answer any time in Settings → Account (or You → Help improve HitLegend on the phone).
- What is used: copies of the card photos in your collection (front and back) — the ones there when you turn it on and the ones you add later. Never the whole page you photographed, never your notes, name, email or anything else about you.
- How: the copies go into a separate training store with nothing in them or their file names that identifies you. They are labelled with facts about the card (which card it is, the condition) and used only to develop and train HitLegend's own models for recognising condition and finish. We do not sell them and we do not give them to anyone to train their own models.
- Who sees them: our staff or contractors who label training images may see a card photo, never who it came from.
- Turning it off: we delete the copies taken from your collection, and none are added again. A model that has already been trained on them cannot unlearn them, but no new training uses them. Deleting your account does the same.
- Kid profiles: a child is never asked. If you, the parent, turn it on, it includes the card photos your kid profiles add to your shelves, the same as yours. Turning it off deletes every training copy taken from your shelves, theirs included.
- We keep a record of each time you turned it on or off (when, and which wording you saw), including after you delete your account, so we can show your choice was respected.
4. Who we share with
We share personal data only with:
- Service providers that work for us under contract and may use the data only to provide their service to us: cloud hosting, database and file storage; card identification and machine reading (including AI model providers); market-price data (they receive card identifiers, never your identity); email delivery; error monitoring (crash reports, with personal details removed); payments (Stripe, and Apple for App Store purchases); and sign-in (Google, Microsoft or Apple, if you choose them). Where required, they sign data-processing agreements. Business customers can ask us for the current list at privacy@hitlegend.com.
- People you choose: shelf members, trade-circle members and anyone with a showcase link (section 5).
- Authorities, when the law requires it or to protect someone's safety, rights or property.
- A successor, if Unobstructed or HitLegend is merged or acquired; this policy continues to apply and you will be told.
We may publish aggregated statistics that cannot identify you or your shelf (for example, how many cards of a set have been scanned).
We do not sell personal data. We do not "share" it for cross-context behavioural advertising, as California law uses those words, and we have not done so in the last 12 months.
5. What other people can see
- Shelf members see the shelf's cards according to the role the owner gives them.
- Showcases are public to anyone who has the link. They show the shelf and binder name, the cards, your photos of their fronts and, only if you switch them on, values. We ask search engines not to index showcases and count views without recording who viewed. Turn a showcase off and its link stops working.
- Trade-circle members see the cards you mark for trade and the cards you need.
- Kid profiles cannot have showcases or join trade circles.
6. Cookies, tracking and Do Not Track
We use one kind of cookie: the first-party cookie that keeps you signed in, plus the storage the app needs to work. We use no advertising cookies, analytics cookies, tracking pixels, session recording or third-party ad or analytics SDKs, and we do not track you across other sites or apps. Because we do not track you, there is nothing for a Do Not Track or Global Privacy Control signal to switch off; we honour a GPC signal as an opt-out of sale and sharing, which we do not do anyway.
7. International transfers
We and our providers operate in the United States; if you are outside the U.S., your data is transferred there. Where EU/UK law applies we rely on standard contractual clauses with our providers.
8. Retention
- Your account data is kept as long as your account exists.
- A deleted card's photos are kept 30 days, so a mistake can be undone, and then removed.
- Scan records are hidden from you when you clear them. They stay as the audit of how a card was identified until the account is deleted.
- Usage events and typed questions are kept 13 months, then anonymised.
Deleting your account. When you delete your account:
- we take your shelves, cards, photos, scans, sign-ins and kid profiles out of the Service straight away;
- we remove them from our live systems within 30 days;
- copies in our backups age out within a further 30 days.
What we keep after deletion. We keep:
- an anonymised record of sales you logged (no identity, no photos), for accounting;
- invoices, as the law requires;
- other data only where it is needed to investigate fraud, abuse, a security incident or a legal claim, or where the law requires us to preserve it — and then only as long as needed.
9. Your rights and controls
You can do the following yourself:
- Export: Settings → Your data → Download shelf export gives you everything in one file, any time.
- Correct: every card is editable, and identifications and facets can be corrected in the product.
- Delete: Settings (web) or Profile (app) → Delete my account.
You can also ask us, at privacy@hitlegend.com, to exercise the rights your law gives you:
- Everyone, wherever you live: access, a copy in a portable format, correction and deletion.
- EU/UK (GDPR): also restriction, objection, and withdrawing consent where we rely on it.
- California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon and other US states with privacy laws: also to know what we collect, to opt out of sale, targeted advertising and profiling (we do none of these), and not to be treated differently for using your rights.
How requests are handled:
- We answer within 30 days (45 under US state laws, extendable where the law allows).
- We may need to confirm the request comes from you, usually by asking you to write from your account's email.
- You may use an authorised agent.
- If we decline a request, you may appeal by replying to our answer. If you are still not satisfied, you may contact your state attorney general or your data-protection authority.
Email. Transactional messages (verification, password reset, receipts, alerts you turned on) are part of the Service. There is no marketing list; if we start one, it will be opt-in with an unsubscribe link in every message.
10. Children
Children under 13 cannot create their own account. A parent or legal guardian with a HitLegend account can instead make a kid profile for their child:
- What we collect from the child: a nickname the parent chooses and a PIN (stored only as a one-way hash). No email address, phone number, postal address, birthday, real name or photo of the child. We record when the profile signs in, and which cards they add to the shelves they are on.
- Card photos: a child who can scan sends photos of cards to our identification providers (section 3), only to read the cards. We ask children to photograph cards, not people. If the parent has turned on photo training (section 3a), copies of the card photos the child adds to the parent's shelves are included, as the parent's own are; the parent can turn this off at any time, which deletes those copies.
- What we never do with a kid profile: advertising, selling or sharing their information, showcases, trading, trade circles, messages, notes, or email to the child.
- Consent: before a kid profile exists, the parent reads this notice and gives consent, which we keep as a record (who, when, which version of the notice) and send to the parent's email.
- Parents' rights: from Members, the parent can see what we keep about each kid profile, change what it can do on each shelf, reset its PIN, turn it into the child's own login once they are 13, or delete it. Deleting withdraws consent and removes the profile, its sign-ins and its memberships; cards the child added stay on the shelf, which belongs to the shelf's owner. You can also ask us at privacy@hitlegend.com.
If you believe a child under 13 has an account of their own, tell us and we will delete it.
11. Security
We protect your data with:
- encryption in transit (TLS) everywhere;
- passwords hashed with bcrypt;
- photos in private storage, reached only through short-lived signed links;
- every shelf kept separate from every other on the server;
- no secrets in the apps;
- logged staff access.
No system is perfectly secure. If a breach affects you, we will tell you as the law requires. Keep your password and devices secure.
12. Changes
We will post changes here with a new effective date and, for material changes, tell you in the product or by email at least 14 days in advance.
13. Contact
privacy@hitlegend.com · Unobstructed, LLC