CARDCUE · LEGAL

Privacy Policy

What CardCue collects, why it is needed, and the choices you have.

Effective September 26, 2026

01

Who we are

CardCue is operated by Kevin Levesque. This policy covers the CardCue Chrome extension and its supporting account, card-recognition, card-information, and membership services. These services are for adults aged 18 or older.

Contact us at support@getcardcue.com with privacy questions or requests. This policy does not describe separate practices of Whatnot, card marketplaces, or other websites you choose to visit.

02

Images and scanning

Before scanning begins, CardCue explains image capture and asks you to choose Agree and start. While scanning a supported Whatnot stream, the Chrome extension captures video frames and passes them through Chrome Native Messaging to the separately installed CardCue Mac companion. CollectorVision identifies cards on your Mac. CardCue does not upload these stream frames to its cloud recognition service in this local-recognition release.

Screenshot fallback includes the whole visible tab.

If direct video capture is unavailable, CardCue can capture the entire visible stream tab and pass that image to the local companion. It may contain chat, usernames, and other visible information outside the card or video. The screenshot stays on your computer in this local-recognition path. Use Stop to end scanning.

Local recognition messages contain the captured image, crop dimensions, and a scan-session identifier. The companion uses temporary files on your Mac for text recognition and removes them when no longer needed; its temporary working directory is removed when the companion process exits normally. This release does not save a permanent stream-frame archive. Uninstalling the extension alone does not remove the Mac companion.

CardCue reads supported-tab URLs, titles, and auction information locally to find the stream and follow auction changes. The cloud scan-accounting request does not include captured images, page URLs, or page titles as separate fields. A locally processed screenshot can still contain visible page information.

After a card is identified locally, CardCue sends its card identifier, game, language, scan-session and occurrence identifiers, and account authorization to our cloud service to apply the free allowance or confirm Pro access. It also requests artwork, estimated values, and other card information from our catalog services. The free allowance counts accepted card recognitions, not locally processed frames. Unmatched frames can be processed on your Mac between accepted recognitions.

03

Accounts and local storage

Clerk provides sign-in. Account information can include identifiers, email, name or username, profile image, and CardCue profile details. Authentication cookies and local browser storage maintain and synchronize sign-in between the extension and account page. Session tokens authorize requests to CardCue services.

The extension saves a local consent receipt with your account and sign-in session identifiers, the disclosure version, and an approval identifier. Active approval belongs to that session. Stop withdraws it, as do detected sign-out, account, or session changes. A restart of the extension’s background service requires a new agreement, even if an old receipt remains in storage.

Your appearance preference uses Chrome’s synchronized storage. Google handles that synchronization according to your browser settings. The Mac companion checks CardCue’s release feed for updates and can download a signed replacement. That request may expose its version and your network address to our hosting provider; it does not send captured stream images.

04

Usage and payments

CardCue keeps account-linked usage dates, scan claims, recognized card identifiers, and timestamps to apply allowances and avoid duplicate accounting. The cloud does not receive the captured frame in this local-recognition path. Server and provider logs may contain request metadata, including IP addresses, as described below.

Stripe hosts checkout and billing management. CardCue receives customer and subscription identifiers, membership status, plan, billing-period and cancellation details, and related billing-event information. CardCue’s extension does not read payment-card numbers or security codes you enter into Stripe’s payment form.

If you email support, we use your message, email address, and attachments to respond. Please do not include card-payment details, identity documents, or unnecessary sensitive information.

05

How we use and share information

We use personal information only to provide CardCue, protect its security and reliability, respond to support requests, and meet legal obligations. We do not sell personal information, use it for targeted advertising, or use captured images to train AI models.

Providers receive information needed to perform their roles: Cloudflare hosts our account, scan-accounting and card-information services and databases, but does not receive stream frames for recognition in this local-recognition path; Clerk handles authentication; Stripe handles payments; and Google provides our support email and Chrome preference synchronization. Requests expose network information, including IP addresses, to the receiving services. Operational errors and request metadata may appear in provider logs.

We limit transfers of extension user data to what is needed for the disclosed CardCue service, security and abuse prevention, or compliance with law. We do not send it to advertising platforms, data brokers, or creditworthiness services.

Human access to extension user data is limited to your explicit consent to review specific information, necessary security investigations, legal obligations, or aggregated and anonymized internal operational information permitted by applicable rules. A support request does not authorize unrelated review of captured content.

Chrome Web Store Limited Use

CardCue’s use and transfer of extension user data complies with the Chrome Web Store User Data Policy, including the Limited Use requirements.

Providers also describe their own practices in their privacy notices: Cloudflare, Clerk, Stripe, and Google. Our commitments here describe CardCue’s use of information; they are not a blanket claim about every provider’s independent services.

06

Retention and security

We retain information for as long as needed for the purposes described here: maintaining accounts and access, applying allowances and preventing abuse, handling billing or support, and meeting applicable legal recordkeeping requirements. The appropriate period depends on the record, its purpose, and any outstanding request or obligation.

Local OCR working files are temporary and are removed after use or when the companion exits normally. The cloud retains scan claims and their recognized card identifiers for usage accounting; resetting the daily allowance does not erase those records. Account, billing, support, and provider records follow their own operational and legal retention needs.

We use Chrome Native Messaging for local image transfer, HTTPS for account and card-information requests, and access controls for service operations. No software or storage system can guarantee absolute security. We do not describe these services as end-to-end encrypted.

07

Your choices and requests

You can stop scanning, sign out, change Chrome’s site permissions, or uninstall the extension and Mac companion. These actions do not automatically erase server-side account, scan, billing, support, or provider records. Ending a subscription also requires cancellation through billing management; uninstalling alone does not cancel it.

To request access, correction, or deletion of your information, email support@getcardcue.com. We may need to verify your identity before acting. Some records may need to be retained for security, billing disputes, or legal obligations. Where a request cannot be fulfilled in full, we will explain the relevant limitation. Any additional privacy rights available under applicable law remain unaffected.

CardCue is intended for adults 18 or older. If you believe a child has provided personal information, contact us so we can investigate and address it.

08

Updates and contact

We will post changes to this policy on this page and update its effective date. Material changes to extension data collection or use will be disclosed before they take effect, with renewed consent where required.

Kevin Levesque · CardCue
support@getcardcue.com

Last updated September 26, 2026 · Applies to CardCue for Chrome and its supporting services.