Mintdex

Privacy policy

Last updated August 28, 2026

Mintdex collects the minimum needed to run scanning, collection sync and subscriptions. This page says what is processed, why, on what legal basis, how long it is kept, and how to take control of it.

Who processes your data

  • Mintdex is published by Foosha Studio, a French simplified joint stock company with share capital of 500 euros, registered with the Paris trade and companies register under number 105 865 331, with its registered office at 8B rue Abel, 75012 Paris, France. EU VAT number: FR60 105 865 331. President: Jean-Elie Lecuy.
  • Foosha Studio is the data controller under the GDPR. It decides what is collected and why, and it is the one you can hold to account for it.
  • The contact point for anything touching your data is hello@getmintdex.com, under the president’s responsibility.

What is collected, and why

  • Your account. When first opened, Mintdex creates an anonymous account with a technical identifier, without asking for your email address. You can later link it to Sign in with Apple on iOS or Google on Android. The email address or private relay supplied by the provider lets you retrieve your collection on compatible devices. Legal basis: performance of the contract.
  • Your collection and choices. The cards you declare owning, their conditions, languages, grades, your purchase prices, your binders, the cards you watch and the alert thresholds you set. This data exists to provide and sync the features you request. Legal basis: performance of the contract.
  • Your scan photos. The image you hold in front of the camera is used to identify the card. It stays on your phone when local OCR is enough; as a last resort, it is sent to Google Gemini under the conditions detailed in the next section.
  • Your notifications, only if you enable them. Mintdex records an Expo push token, the device platform and time zone, and your notification preferences. For a price alert, the chosen threshold is also kept. The time zone is used to avoid sending notifications between 8 pm and 10 am local time. Legal basis: performance of the service you request. You can disable notifications in the app or in your device settings.
  • The free scan pack attached to your restored account. On iOS, the anonymous session remains in the secure Keychain and Apple DeviceCheck indicates whether the device free pack has already been used. On Android, the session remains in secure app storage and may be copied to Google Block Store when encrypted Google Account backup is available, so a reinstall can recover the same account and allowance. Mintdex receives no serial number and no Apple or Google identifier, only the technical tokens needed for restoration and control. Legal basis: the legitimate interest in preventing repeated circumvention of the free allowance.
  • Your subscription. Whether your Mintdex+ subscription is active, its type, dates and purchase or renewal history, so the right features unlock and the offers can be measured. Legal bases: performance of the contract for access to Mintdex+, and the legitimate interest in analysing purchases, trials and renewals to improve the offers.
  • How the app behaves. Crash reports, performance measurements, other technical diagnostics and pseudonymous usage metrics, to fix bugs and understand which features are useful. These metrics cover viewed screens and a small set of product actions, never card identities, collection contents or scan photos. Server technical logs, for security and abuse prevention. Legal basis: Mintdex has a legitimate interest in shipping an app that works and is not abused.
  • Your support messages. What you write to hello@getmintdex.com and the attachments you choose to send, so we can answer. Legal basis: performance of the contract and the legitimate interest in providing support.
  • Mintdex never asks for your name, your postal address, your phone number or any payment details.

Scan photos

  • When you scan a card, Mintdex first tries to identify it on your device using OCR and the downloaded catalog. In the great majority of cases, the image does not leave your phone. If those clues are not enough, the image is sent once to Gemini API, Google’s artificial intelligence service, to extract visual and textual clues. Mintdex then checks those clues against the local catalog; Gemini never chooses the final card identity on its own.
  • Mintdex does not store the image it sends or add it to any dataset. Google may retain the image, the associated instructions and the response for up to 55 days to detect and prevent prohibited use and meet legal or regulatory obligations.
  • The paid Gemini API does not use your images or its responses to improve Google products or general-purpose models. Data retained for abuse monitoring is used only for policy enforcement and violation prevention; authorised Google personnel may review content when it is flagged.
  • Google may process or temporarily cache this data in any country where Google or its agents maintain facilities. Processing is governed by Google’s data processing addendum and, where required, the safeguards applicable to international transfers.
  • Legal basis: performance of the contract. Sending the image to Gemini happens only when local processing could not identify the card.
  • Aim at the card, not the room. A photo taken on the fly sometimes catches what sticks out: a hand, a face, a corner of a living room. Frame tight when you can, and keep other people out of shot. No facial recognition is performed on these images, by Mintdex or by the recognition service.
  • Mintdex keeps no scan photo. Google’s temporary security retention expires automatically and is not a Mintdex training dataset.
  • The Wrong card button records the correct answer so the catalog can be fixed; it does not send a new photo by itself. Only the correction data is kept.
  • Your photos are never published, never shared with other users, never sold, never used to profile you.

If you are under 15

  • Mintdex is not directed at children and is neither listed in the App Store Kids Category nor targeted at children on Google Play. But we know exactly who collects Pokémon cards, so here are the rules.
  • In France, below the age of 15, anything that relies on your agreement also needs the agreement of one of your parents. In practice: you only create a Mintdex account with a parent’s approval.
  • The account, the collection and the scanner rely on the contract, not on your consent, so there is nothing extra to accept in order to use them, and nothing extra is collected because you are young.
  • No advertising, no advertising profile, no targeting, no cross app tracking. Not for minors, not for anyone.
  • Purchases go through the account for the installed store: Apple on iOS or Google Play on Android. Parents can require purchase approval through Ask to Buy or through Google Play and Family Link controls. Mintdex charges nothing directly and cannot bypass those settings.
  • A parent can write to hello@getmintdex.com to access, correct or delete their child’s data. These requests are handled first.

Your Mintdex+ subscription

  • Purchase and payment go through the App Store on iOS or Google Play on Android. No payment details pass through Mintdex, and nobody at Foosha Studio ever sees any.
  • To know whether your subscription is active, Mintdex uses RevenueCat. RevenueCat receives an app identifier tied to your account, the subscription type, its dates and status, and the history of purchases, trials and renewals. Not your name, not your payment card, not your collection.
  • This data unlocks the features you paid for and supports internal subscription analytics in RevenueCat customer history and dashboards. It is used neither for advertising nor for tracking across apps or websites. Legal bases: performance of the contract for access to Mintdex+, and the legitimate interest in improving the offers.
  • Cancellation happens in your Apple Account subscriptions on iOS, or in Google Play under Payments and subscriptions on Android. Refund requests go through the store that charged the purchase. Deleting your Mintdex account does not cancel your subscription: those are two separate actions.

What Mintdex never does

  • No sale of personal data, to anyone, ever.
  • No advertising profile built from your collection, no targeted advertising, no advertising trackers, no cross app tracking prompt.
  • No facial recognition, no biometric processing, no attempt to identify anyone in a scan photo.
  • No general-purpose model is trained or improved using your scan photos. Foosha Studio never uses them for that purpose; Google limits monitoring data to safety, abuse prevention and policy enforcement.
  • No access to your photo library. Scanning uses only the camera when you start it.
  • No automated decision producing legal effects on you. Card recognition is automated, but it decides nothing about you, and you can always correct the result.

Who else sees your data

  • Mintdex relies on a handful of providers and platform services. Processors only handle your data on Foosha Studio’s instructions, for the stated purpose, and are bound by an agreement compliant with Article 28 of the GDPR. Apple and Google instead act on their own behalf for their store, account and notification services, as explained below.
  • Supabase Pte. Ltd. (Singapore). Database, accounts and authentication, including Sign in with Apple on iOS and Google Sign-In on Android. It holds your account identifier, your email address and your whole collection. The Mintdex project runs in the eu-west-3 region, in Paris: your data is stored and primarily processed in France, even though the company operating the service is established in Singapore.
  • Google, through its paid Gemini API. Card-recognition fallback only when local OCR is not enough. Receives the scan photo and strictly necessary instructions, then returns visual and textual clues. May retain the input and output for up to 55 days for safety and abuse monitoring; does not use them to improve its products or general-purpose models.
  • Sentry. Crash reports, performance measurements and other technical diagnostics, to fix what breaks and improve stability. Receives information including the error type, the app version and the device model, without a Mintdex account identifier. The Mintdex project uses the European region of Sentry: these diagnostics are stored in Germany.
  • PostHog, Inc. (United States), through PostHog Cloud EU in Frankfurt. Measures app usage only. It receives the normalized screen or action name, a random session pseudonym and limited technical context about the device and app. It receives no Mintdex account identifier, card identity, collection content or photo. The pseudonym lives in memory only and is recreated when the app process is closed and relaunched. Autocapture, person profiles, session replay, IP geolocation and IP retention are disabled. This data is used neither for advertising nor to track you across apps or websites.
  • DataFast (Singapore). Measures traffic on getmintdex.com only. It receives viewed pages and limited technical browser context, without a Mintdex account identifier, card identity, collection content or photo. Like any server it sees the IP address; it derives approximate location and a pseudonymous identity that rotates about every 24 hours. Cookieless mode sets no cookie, and this data is used neither for advertising nor to track you across websites.
  • 650 Industries, Inc. (Expo, United States). Push notification delivery and app update distribution. For a notification, Expo receives the token and the content strictly needed, then forwards them to Apple’s service on iOS or Firebase Cloud Messaging on Android. To check for and download an update, Expo receives the operating system, a randomized installation-specific token and the necessary network metadata, including the IP address. That token is not tied to your account. Expo receives neither your collection nor your scan photos.
  • RevenueCat, Inc. (United States). Subscription management and internal analytics for purchases, trials and renewals. Receives an app identifier tied to your account, the subscription type, its status, dates and history. Sees neither your collection nor your photos, and does not use this data for advertising or tracking across apps or websites.
  • Vercel Inc. (United States). Hosting for the getmintdex.com site you are reading. Processes request logs, including your IP address. Sees neither your account, nor your collection, nor your photos.
  • Cloudflare. Delivery of the catalog card images, stored on its R2 service under European jurisdiction. Receives the IP address requesting an image. Sees neither your account, nor your collection, nor your scan photos.
  • Apple. The App Store charges the subscription, Sign in with Apple handles sign-in, DeviceCheck contributes to the free-pack check and APNs delivers notifications to your device. For those operations Apple acts on its own behalf, under its own privacy policy, not on Mintdex’s instructions.
  • Google Ireland Limited (Ireland) and Google Commerce Limited (Ireland). On Android, Google Play charges the subscription, Google Sign-In handles sign-in, Block Store may keep the encrypted session in your Google Account backup and Firebase Cloud Messaging delivers notifications to your device. For those operations Google acts on its own behalf, under its own privacy policy, not on Mintdex’s instructions.
  • Beyond these providers, your data may be disclosed to an authority where the law requires it. In that case Mintdex checks that the request is valid and tells you whenever it is allowed to.

Where your data lives

  • Your account, your email address and your whole collection are stored and primarily processed in France, in Paris.
  • When the Gemini fallback is needed, your photo may be processed or temporarily cached in any country where Google or its agents maintain facilities. It may therefore leave the European Union.
  • Your collection does not leave France: it is stored and processed in the Paris region. Supabase, the company operating that database, is established in Singapore, so administrative access from outside the Union remains possible. That specific point is what the safeguards cover, not a movement of your data.
  • Other providers are established outside the European Union: Google for the Gemini fallback, RevenueCat, Vercel, Expo and PostHog in the United States, even though the Mintdex PostHog project is hosted in Frankfurt, DataFast in Singapore, and Cloudflare, whose image storage used by Mintdex is restricted to European jurisdiction. Only Google receives a scan photo when the fallback is triggered; none of these providers receives your collection. Expo receives only what is needed for notifications and app updates.
  • Your Sentry diagnostics, including crash reports and performance measurements, stay inside the Union: Sentry processes them in its European region, in Germany.
  • These transfers are covered by the appropriate safeguards provided by each supplier, including the European Commission standard contractual clauses where applicable. Expo, Vercel and Cloudflare are also certified under the EU-US Data Privacy Framework.
  • You can ask for a copy of those safeguards by writing to hello@getmintdex.com.

How long it is kept

  • Your account and your collection: as long as your account exists. On deletion, data is erased from live systems within 30 days, then from backups as they rotate.
  • Your push tokens and notification preferences: while active or until the account is deleted. A pending notification remains in the queue only until it is sent, cancelled or expires.
  • On iOS, the DeviceCheck anti-abuse marker for the free pack remains associated with the device at Apple for as long as this control is needed. On Android, Block Store may keep the encrypted session in Google backup so the same account and allowance can be restored after a reinstall. These technical data may therefore remain after the app is removed locally.
  • Crash reports, performance measurements, other technical diagnostics and usage metrics: 12 months.
  • Technical and security logs: 12 months.
  • Your support conversations, including attachments: 3 years after the last message. A photo voluntarily emailed to support follows this period; it is not a scan photo retained by the app.

How your data is protected

  • Everything travelling between the app and the servers is encrypted in transit. Data is encrypted at rest at the hosting provider.
  • Database access is partitioned per user: your account only sees your collection. Administrative access is limited and protected by two factor authentication.
  • The image is sent to the Gemini fallback only after local processing fails, over an encrypted connection, and is not retained by Mintdex.
  • No system is bulletproof. In case of a data breach likely to create a risk for you, the CNIL is notified within 72 hours and you are told directly whenever the risk is high.

Your rights

  • You have the right to access your data, to have it corrected, to have it erased, to restrict its processing, to object to processing based on legitimate interest, and to withdraw at any time a consent you have given. Withdrawing consent does not undo what was lawfully done before.
  • You also have the right to data portability: getting back the data you provided, in a machine readable format. There is no export button in the app. That request is therefore handled manually: write to hello@getmintdex.com and you get your file.
  • Under French law you can also leave instructions about what happens to your data after your death, and name who may enforce them.
  • To exercise any of these rights, write to hello@getmintdex.com from the email address of your account. The answer comes within one month. If the request is complex, that deadline can be extended by two months, and you are told before it is.
  • Where there is serious doubt about who is asking, an additional confirmation may be requested. It is used only to verify the request and is not retained.

Deleting your account

  • Deletion happens in the app settings, without going through support and without having to justify yourself.
  • What is erased: your account, your email address, your collection, your binders, your purchase prices, your watched cards, your scan history and your alerts. Scan photos are never retained by the app, so there are none to erase.
  • If you use Sign in with Apple, Mintdex also tries to revoke the authorisation. If Apple does not confirm revocation, nothing is deleted at first: you can retry or explicitly choose to delete anyway. In the latter case the Mintdex account is deleted, but the authorisation may remain visible in your Apple Account settings until you remove it yourself.
  • If you use Google Sign-In, Mintdex also signs the Google session out inside the app. Deleting the Mintdex account does not delete your Google Account or data Google retains for its own services.
  • Deleting the account does not provide a new pack of 10 free scans. On iOS, the DeviceCheck marker used to prevent abusive quota resets remains with Apple. On Android, any Mintdex session still present in Block Store is cleared during deletion; the app then creates a new anonymous account so you can keep using it.
  • What may survive for a while: security logs, until they expire normally, and transaction records held by Apple or Google, which Mintdex does not control.
  • There is no way back and there is no export button in the app. Before confirming, you can ask for a copy of your data at hello@getmintdex.com.
  • Your Mintdex+ subscription does not cancel itself when the account goes. Go to your Apple Account or Google Play subscriptions, depending on which store charged it, or it keeps being charged.
  • If you can no longer reach the app, write to hello@getmintdex.com and the deletion is done for you.

Affiliate links

  • Some buy links to third party marketplaces are affiliate links. The price you pay stays the same, and a commission may go to Mintdex.
  • Opening one of these links sends no account or collection data to the marketplace. The link carries an affiliate identifier, not an identifier of you.
  • Once you are on the merchant’s site, their privacy policy applies, not this one.

The getmintdex.com website

  • This site sets no analytics cookie and no advertising tracker. There is no banner to click because there is nothing to accept.
  • Traffic on this site is measured by DataFast without a cookie or an identifier that follows you from one site to the next. The service groups page views under a pseudonymous identity that rotates about every 24 hours and derives approximate location from the IP address. Legal basis: the legitimate interest in knowing how this site is used.
  • Your light or dark theme choice is stored on your device. DataFast’s cookieless measurement also uses browser session storage for temporary technical identifiers and state: they are used neither for advertising nor to follow you across websites and disappear when the browser session ends.
  • The site host, Vercel, records technical logs containing your IP address, for security and for the site to work. Legal basis: legitimate interest. Retention: 24 hours, or 30 days if extended observability is enabled on the project.

Changes to this page

  • The date at the top of the page tells you when it was last updated.
  • If a change actually alters what is done with your data, you are told in the app or by email before it applies.

Contact and complaints

  • For anything about your data, write to me.
  • If the answer does not satisfy you, you can lodge a complaint with the French data protection authority, CNIL, 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, or online at cnil.fr. If you live in another EU country, you can also complain to your own national authority.
hello@getmintdex.com