Datenschutzerklärung
Stand: September 2026. Die deutsche Fassung ist maßgeblich.
Diese Datenschutzerklärung informiert über die Verarbeitung personenbezogener Daten bei der Nutzung von Papergold – der Website papergold.app, der iOS-/Android-App und der Web-App (app.papergold.app). Die Kartenerkennung beim Scannen läuft vollständig auf deinem Gerät; Kamerabilder und Kartenfotos werden nicht hochgeladen. Ein Konto ist optional und nur für Synchronisierung, Freunde, Tausch, Freigabe-Links und Premium nötig. Wir setzen keine Analyse-, Tracking- oder Werbewerkzeuge ein.
1. Verantwortlicher
Jan Huhsmann
Wacholderweg 14a, 26188 Wildenloh, Deutschland
E-Mail: [email protected]
Einen Datenschutzbeauftragten haben wir nicht bestellt; die Voraussetzungen des § 38 BDSG liegen nicht vor.
2. Hosting und Auslieferung (Cloudflare)
Die Website, die Web-App sowie unsere Katalog-, Preis- und News-Dienste laufen bei Cloudflare (Pages, Workers, D1, R2). Beim Aufruf verarbeitet Cloudflare als Auftragsverarbeiter technisch notwendige Verbindungs- und Protokolldaten (u. a. IP-Adresse, Datum und Uhrzeit des Zugriffs, angeforderte Ressource, User-Agent), um Auslieferung, Stabilität und Sicherheit zu gewährleisten. Dazu gehört auch die Missbrauchsabwehr, etwa Anfragebegrenzungen pro IP-Adresse. Rechtsgrundlage ist Art. 6 Abs. 1 lit. f DSGVO (berechtigtes Interesse an einem sicheren, funktionsfähigen Angebot). Unsere eigenen Protokolle enthalten ausschließlich Betriebswerte (z. B. Anzahl verarbeiteter Datensätze oder Token-Zahlen) und Fehlermeldungen – nie den Text deiner Ask-Fragen und nie deine Nutzer-ID. Weitere Informationen: Cloudflare Datenschutzrichtlinie.
3. Nutzung ohne Konto: Katalog, Preise, News und Kartenbilder
Scannen, Sammlung, Decks, der Offline-Kartenkatalog, das Regelwerk und der Lebenspunkte-Zähler funktionieren ohne Konto. Deine Sammlung liegt dann ausschließlich auf deinem Gerät. Die App lädt dabei Kartendaten, Preise und News von unseren Cloudflare-Diensten herunter; übermittelt wird nur, was für den Abruf technisch nötig ist (siehe Abschnitt 2) – keine Kennung, kein Konto. Kartenbilder werden direkt vom Bild-CDN von Scryfall (Scryfall, LLC) geladen; dabei ist deine IP-Adresse für Scryfall technisch sichtbar, wie bei jedem Laden eines externen Bildes. Daten von EDHREC (Commander-Empfehlungen) ruft unser eigener Dienst für dich ab – deine IP-Adresse erreicht EDHREC dabei nicht. Rechtsgrundlage ist jeweils Art. 6 Abs. 1 lit. f DSGVO (Bereitstellung der angeforderten Inhalte). Preise sind Schätzwerte ohne Gewähr.
4. Konto und Synchronisierung
Legst du ein Konto an und meldest dich an, verarbeiten wir: deine E-Mail-Adresse (Registrierung und Login), deinen Benutzernamen (öffentlich – dient der Freunde-Suche), den Zeitpunkt der Registrierung sowie die von dir synchronisierten Sammlungs-, Sealed-, Listen-, Deck- und Tausch-Daten (Karten, Mengen, Zustand, Sprache, Foil sowie – wenn du sie erfasst – Kaufpreise, Notizen und Aufbewahrungsorte). Dein Passwort wird ausschließlich verschlüsselt (gehasht) gespeichert. Zweck ist die Bereitstellung des Kontos und der Sync-Funktion; Rechtsgrundlage ist Art. 6 Abs. 1 lit. b DSGVO (Vertrag/Nutzungsverhältnis). Die Speicherung erfolgt bei unserem Auftragsverarbeiter Supabase (Supabase Inc.); der Serverstandort des Projekts ist Nordeuropa (Stockholm).
Kaufpreise, Notizen und Aufbewahrungsorte sind technisch von allen Fremdzugriffen ausgeschlossen: Sie erscheinen weder in Freundes-Ansichten noch hinter Freigabe-Links und werden auch nicht an Ask übermittelt.
5. Freunde, geteilte Sammlungen und Tausch
Fügst du Freunde hinzu, speichern wir die Freundschaftsbeziehung. Deine Freunde sehen deinen Benutzernamen, dein Profilbild und die Sammlungen und Listen, die du für sie sichtbar geschaltet hast (Karten und Mengen); die Sichtbarkeit steuerst du je Sammlung selbst. Erfasst du einen Tausch, speichern wir die beteiligten Konten, die Karten, den Status und den Zeitverlauf des Vorgangs – für beide Seiten einsehbar. Zweck ist die Bereitstellung der Freundes- und Tauschfunktion; Rechtsgrundlage ist Art. 6 Abs. 1 lit. b DSGVO.
6. Freigabe-Links
Schaltest du eine Sammlung, eine Liste oder ein Deck frei, entsteht eine unerratbare Adresse, unter der jede Person mit dem Link die Karten und Mengen ansehen kann – ohne Konto. Kaufpreise, Notizen und Aufbewahrungsorte sind davon technisch ausgeschlossen. Du kannst den Link jederzeit in der App wieder abschalten; er wird dabei ungültig. Die Freigabe erfolgt nur auf deine ausdrückliche Anweisung; Rechtsgrundlage ist Art. 6 Abs. 1 lit. b DSGVO.
7. Profilbild und Meldungen
Ein Profilbild ist freiwillig. Lädst du eines hoch, wird es auf deinem Gerät verkleinert und neu als JPEG gespeichert – Aufnahmedaten wie Ort oder Kameramodell (EXIF) gehen dabei verloren – und in einem öffentlich lesbaren Speicherbereich bei Supabase abgelegt. Wer die Adresse des Bildes kennt, kann es abrufen. Rechtsgrundlage ist deine Einwilligung nach Art. 6 Abs. 1 lit. a DSGVO, die du jederzeit mit Wirkung für die Zukunft widerrufen kannst, indem du das Bild in der App entfernst.
Andere Nutzerinnen und Nutzer können ein Profilbild melden. Wir speichern dann, wer wen gemeldet hat und wann, bis der Fall bearbeitet ist, und entfernen das Bild bei einem berechtigten Hinweis. Rechtsgrundlage ist Art. 6 Abs. 1 lit. f DSGVO (berechtigtes Interesse an einem missbrauchsfreien Dienst).
8. Wertverlauf deiner Sammlung
Einmal täglich berechnet ein Dienst von uns bei Cloudflare den Gesamtwert deiner Sammlungen zu den Tagespreisen; gespeichert werden Tag, Wert und Kartenzahl je Sammlung. Für die Bewertung übermitteln unsere Apps Kartenkennungen und Stückzahlen an diesen Dienst – ohne E-Mail-Adresse und ohne Nutzer-ID. Zweck ist die Wertverlaufs-Anzeige als Kernfunktion; Rechtsgrundlage ist Art. 6 Abs. 1 lit. b DSGVO.
9. Ask (Premium) – Google Gemini
Ask beantwortet Fragen zu deinen Karten. Dafür übermitteln wir an die Gemini API von Google (Google Ireland Limited / Google LLC) ausschließlich: die von dir getippte Frage, die bisherigen Nachrichten desselben Chats und die von unserer Suche gefundenen Karten (Name, Set, Typ, Preis) – höchstens 50 pro Suchvorgang. Nicht übermittelt werden deine E-Mail-Adresse, deine Nutzer-ID, deine vollständige Sammlung, deine Kaufpreise, deine Notizen oder Freundesdaten. Chats speichern wir nicht auf unserem Server. Zur Missbrauchsbegrenzung speichern wir in einer Datenbank bei Cloudflare (D1) je Tag nur die Anzahl deiner Fragen, verknüpft mit deiner Nutzer-ID; diese Zeile läuft innerhalb von zwei Tagen automatisch ab. Rechtsgrundlage für die Beantwortung ist Art. 6 Abs. 1 lit. b DSGVO (Erbringung der Premium-Funktion), für den Tageszähler Art. 6 Abs. 1 lit. f DSGVO (Missbrauchsabwehr).
Bitte gib in Ask keine Angaben ein, die du einem externen Anbieter nicht anvertrauen möchtest. Antworten eines Sprachmodells können falsch sein.
10. Premium-Abo (Apple / Google)
Schließt du ein Abo ab, wickeln Apple (Apple Distribution International Ltd.) bzw. Google (Google Commerce Limited) die Zahlung ab; wir erhalten keine Zahlungsdaten. Wir speichern ausschließlich, wie lange dein Premium läuft, über welchen Store es kam und eine undurchsichtige Kaufreferenz des Stores, die wir zur regelmäßigen Prüfung der Gültigkeit brauchen. Rechtsgrundlage ist Art. 6 Abs. 1 lit. b DSGVO. Steuerliche Aufbewahrungspflichten aus dem Kaufvorgang treffen den jeweiligen Store, nicht uns.
11. Cardmarket-Import (optional)
Nutzt du unsere Browser-Erweiterung, liest sie deine Cardmarket-Bestellungen in deinem eigenen Browser aus und übergibt sie der Web-App zur Übernahme. Wir speichern die von dir importierten Bestelldaten – insbesondere Bestellnummer, Zeitpunkt und die übernommenen Artikel mit ihren Kaufpreisen –, damit dieselbe Bestellung nicht doppelt importiert wird und deine Kaufpreise als Kostenbasis erhalten bleiben. Diese Angaben sind für andere Nutzerinnen und Nutzer nie sichtbar. Rechtsgrundlage ist Art. 6 Abs. 1 lit. b DSGVO. Wir haben keinen Zugriff auf dein Cardmarket-Konto; der Abruf findet in deinem Browser statt.
12. Lokale Speicherung
In der Web-App speichern wir technisch notwendige Daten in deinem Browser (localStorage): die Anmelde-Sitzung sowie Anzeige-Einstellungen (z. B. gewählte Sprache, Kartengröße, Preis-Ansicht, Tab-Anordnung). Alle diese Zugriffe sind für den von dir angeforderten Dienst unbedingt erforderlich im Sinne des § 25 Abs. 2 Nr. 2 TDDDG. Es werden keine Tracking- oder Werbe-Cookies gesetzt; ein Cookie-Banner ist daher nicht erforderlich. Schriften sind selbst gehostet – es findet keine Übermittlung an externe Schriftanbieter statt.
13. Keine Analyse, kein Tracking
Wir verwenden keine Analyse-, Tracking- oder Werbewerkzeuge, keine Absturzberichterstattung, keine Werbe-Kennungen und betreiben keine Profilbildung. Es findet keine Weitergabe an Datenhändler und kein Verkauf von Daten statt.
14. Empfänger und Auftragsverarbeiter
Über die genannten Zwecke hinaus geben wir personenbezogene Daten nicht weiter. Eingesetzt werden:
- Supabase Inc. – Datenbank, Anmeldung und Speicher für Profilbilder (Serverstandort Nordeuropa/Stockholm). Auftragsverarbeiter.
- Cloudflare, Inc. – Auslieferung von Website und Web-App sowie Katalog-, Preis-, News- und Ask-Dienste (Workers, D1, R2, Pages). Auftragsverarbeiter.
- Google Ireland Limited / Google LLC – Gemini API, ausschließlich zur Beantwortung deiner Ask-Fragen. Auftragsverarbeiter.
- Scryfall, LLC – Bild-CDN für Kartenbilder; dein Gerät ruft die Bilder selbst ab, dabei wird die IP-Adresse übermittelt.
- Apple Distribution International Ltd. bzw. Google Commerce Limited – Abwicklung von In-App-Käufen als eigene Verantwortliche.
- Andere Nutzerinnen und Nutzer, soweit du das auslöst: deine Freunde, deine Tauschpartner und jede Person, der du einen Freigabe-Link gibst.
Hinzu kommen gesetzlich vorgesehene Empfänger, etwa Behörden, wenn wir dazu verpflichtet sind.
15. Datenübermittlung in Drittländer
Deine Konto- und Sammlungsdaten liegen bei Supabase in der EU (Serverstandort Nordeuropa/Stockholm). Ein Zugriff aus den USA durch die Muttergesellschaft Supabase Inc. lässt sich jedoch nicht ausschließen. Cloudflare, Inc. und Scryfall, LLC verarbeiten Daten auch in den USA; für Ask werden Frage, Chatverlauf und die gefundenen Karten an Google übermittelt und können dort außerhalb der EU verarbeitet werden. Diese Übermittlungen erfolgen auf Grundlage geeigneter Garantien nach Art. 44 ff. DSGVO: auf das EU-U.S. Data Privacy Framework, soweit der jeweilige Anbieter dort zertifiziert ist, andernfalls auf die EU-Standardvertragsklauseln nach Art. 46 Abs. 2 lit. c DSGVO, jeweils ergänzt um Transportverschlüsselung. Eine Kopie der Garantien erhältst du auf Anfrage unter [email protected].
16. Speicherdauer und Kontolöschung
Wir speichern personenbezogene Daten nur so lange, wie es für den jeweiligen Zweck erforderlich ist:
- Konto-, Sammlungs-, Sealed-, Listen-, Deck-, Freundes- und Tauschdaten: bis zur Löschung deines Kontos.
- Nicht bestätigte Registrierungen: automatische Löschung nach 7 Tagen.
- Profilbild: bis du es entfernst, bis zur Entfernung nach einer berechtigten Meldung oder bis zur Kontolöschung.
- Freigabe-Links: bis du sie abschaltest, längstens bis zur Kontolöschung.
- Täglicher Wertverlauf und Premium-Berechtigung: bis zur Kontolöschung.
- Cardmarket-Importe: bis zur Kontolöschung.
- Ask: Chats speichern wir gar nicht; der Tageszähler läuft innerhalb von zwei Tagen ab.
- Server-Logdaten bei Cloudflare: kurze, technisch bedingte Aufbewahrung, danach automatische Löschung.
Du kannst dein Konto jederzeit selbst löschen: in der App unter Mehr → Profil → Konto löschen, in der Web-App an der entsprechenden Stelle im Profil oder per E-Mail an [email protected]. Gelöscht werden dabei alle serverseitig zu deinem Konto gespeicherten Daten – Sammlungen, Karten, Listen, Decks, Sealed-Produkte, Freundschaften, Tauschvorgänge, Wertverlauf, Importe, deine Premium-Berechtigung und dein Profil einschließlich der Bilddatei deines Profilbilds, deren Link damit sofort ins Leere läuft. Karten, die nur auf deinem Gerät liegen, bleiben dort. In Sicherungskopien der Datenbank können Daten für die Dauer des Backup-Zeitfensters noch vorhanden sein; sie werden nicht mehr genutzt und laufen automatisch aus.
17. Minderjährige
Der Dienst richtet sich nicht an Kinder unter 16 Jahren. Wir erheben nicht wissentlich personenbezogene Daten von Kindern. Soweit eine Verarbeitung ausnahmsweise auf einer Einwilligung beruht (Profilbild), ist diese nach Art. 8 DSGVO in Deutschland erst ab 16 Jahren wirksam; jüngere Personen benötigen die Zustimmung der Erziehungsberechtigten. Erfahren wir, dass ein Kind unter 16 Jahren ohne diese Zustimmung ein Konto angelegt hat, löschen wir es.
18. Deine Rechte
Du hast nach der DSGVO das Recht auf Auskunft (Art. 15), Berichtigung (Art. 16), Löschung (Art. 17), Einschränkung der Verarbeitung (Art. 18), Datenübertragbarkeit (Art. 20) und Widerspruch gegen Verarbeitungen, die auf Art. 6 Abs. 1 lit. f DSGVO beruhen (Art. 21). Eine erteilte Einwilligung kannst du jederzeit mit Wirkung für die Zukunft widerrufen. Benutzername, Profilbild und E-Mail-Adresse kannst du direkt in der App ändern; deine Karten kannst du jederzeit als CSV-Datei exportieren. Eine vollständige Kopie aller zu deinem Konto gespeicherten Daten erhältst du formlos per E-Mail an [email protected]. Außerdem hast du das Recht, dich bei einer Datenschutz-Aufsichtsbehörde zu beschweren (Art. 77 DSGVO) – zuständig ist die für uns zuständige Aufsichtsbehörde oder die Behörde an deinem Wohnsitz.
Privacy Policy
Last updated: September 2026. The German version is legally authoritative.
This privacy policy explains how personal data is processed when you use Papergold — the website papergold.app, the iOS/Android app and the web app (app.papergold.app). Card recognition while scanning runs entirely on your device; camera frames and card photos are never uploaded. An account is optional and only needed for sync, friends, trades, share links and Premium. We use no analytics, tracking or advertising tools.
1. Controller
Jan Huhsmann
Wacholderweg 14a, 26188 Wildenloh, Germany
Email: [email protected]
We have not appointed a data protection officer; the conditions of § 38 BDSG do not apply.
2. Hosting and delivery (Cloudflare)
The website, the web app and our catalog, price and news services run on Cloudflare (Pages, Workers, D1, R2). On access, Cloudflare, acting as a processor, handles technically necessary connection and log data (incl. IP address, date and time, resource requested, user agent) to ensure delivery, stability and security. This includes abuse protection such as per-IP rate limits. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in a secure, functional service). Our own logs contain only operational figures (e.g. number of records processed, or token counts) and error messages — never the text of your Ask questions and never your user id. More info: Cloudflare Privacy Policy.
3. Using Papergold without an account: catalog, prices, news and card images
Scanning, your collection, decks, the offline card catalog, the rulebook and the life tracker all work without an account. Your collection then stays on your device only. The app downloads card data, prices and news from our Cloudflare services; only what is technically required for the request is transmitted (see section 2) — no identifier, no account. Card images are loaded directly from Scryfall's image CDN (Scryfall, LLC); your IP address is technically visible to Scryfall during the load, as with any external image. Data from EDHREC (Commander recommendations) is fetched for you by our own service — your IP address never reaches EDHREC. Legal basis in each case: Art. 6(1)(f) GDPR (delivering the content you requested). Prices are estimates without warranty.
4. Account and sync
If you create an account and log in, we process: your email address (registration and login), your username (public — used for friend search), the time of registration, and the collection, sealed, list, deck and trade data you sync (cards, quantities, condition, language, foil and — if you record them — purchase prices, notes and storage locations). Your password is stored only in hashed form. The purpose is providing the account and the sync feature; legal basis: Art. 6(1)(b) GDPR (contract). Storage is with our processor Supabase (Supabase Inc.); the project's server region is North EU (Stockholm).
Purchase prices, notes and storage locations are structurally excluded from any third-party access: they appear neither in friend views nor behind share links, and they are never sent to Ask.
5. Friends, shared collections and trades
When you add friends, we store the friendship relationship. Your friends see your username, your avatar and the collections and lists you have made visible to them (cards and quantities); you control visibility per collection yourself. When you record a trade, we store the accounts involved, the cards, the status and the history of the process — visible to both sides. The purpose is providing the friends and trade features; legal basis: Art. 6(1)(b) GDPR.
6. Share links
If you share a collection, a list or a deck, an unguessable address is created under which anyone holding the link can view the cards and quantities — without an account. Purchase prices, notes and storage locations are technically excluded. You can switch the link off again at any time in the app, which invalidates it. Sharing only happens on your explicit instruction; legal basis: Art. 6(1)(b) GDPR.
7. Profile picture and reports
A profile picture is optional. If you upload one, it is downscaled and re-encoded as a JPEG on your device — capture data such as location or camera model (EXIF) does not survive that — and stored in a publicly readable storage area at Supabase. Anyone who knows the image address can retrieve it. Legal basis is your consent under Art. 6(1)(a) GDPR, which you can withdraw at any time with effect for the future by removing the picture in the app.
Other users can report a profile picture. We then store who reported whom and when, until the case is handled, and remove the picture where a report is justified. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in a service free of abuse).
8. Value history of your collection
Once a day a service of ours at Cloudflare calculates the total value of your collections at that day's prices; we store the day, the value and the card count per collection. For the valuation our apps transmit card identifiers and quantities to that service — without your email address and without your user id. The purpose is the value history as a core feature; legal basis: Art. 6(1)(b) GDPR.
9. Ask (Premium) — Google Gemini
Ask answers questions about your cards. To do so we send Google's Gemini API (Google Ireland Limited / Google LLC) only: the question you typed, the earlier messages of that same conversation and the cards our lookup matched (name, set, type, price) — at most 50 per lookup. We do not send your email address, your user id, your full collection, your purchase prices, your notes or friend data. Conversations are not stored on our server. To limit abuse we store, in a database at Cloudflare (D1), only the number of questions you asked per day, linked to your user id; that row expires automatically within two days. Legal basis for answering: Art. 6(1)(b) GDPR (providing the Premium feature); for the daily counter: Art. 6(1)(f) GDPR (abuse protection).
Please do not type anything into Ask that you would not want to entrust to an external provider. Answers from a language model can be wrong.
10. Premium subscription (Apple / Google)
If you take out a subscription, Apple (Apple Distribution International Ltd.) or Google (Google Commerce Limited) handles the payment; we receive no payment data. We store only how long your Premium runs, which store it came from, and an opaque store transaction reference we need to re-check validity. Legal basis: Art. 6(1)(b) GDPR. Tax retention obligations arising from the purchase apply to the respective store, not to us.
11. Cardmarket import (optional)
If you use our browser extension, it reads your Cardmarket orders inside your own browser and hands them to the web app for import. We store the order data you import — in particular the order number, its date and the imported items with their purchase prices — so that the same order is not imported twice and your purchase prices are kept as a cost basis. This data is never visible to other users. Legal basis: Art. 6(1)(b) GDPR. We have no access to your Cardmarket account; the retrieval happens in your browser.
12. Local storage
In the web app we store technically necessary data in your browser (localStorage): your login session and display preferences (e.g. chosen language, card size, price view, tab order). All of these accesses are strictly necessary for the service you requested within the meaning of § 25(2) no. 2 TDDDG. No tracking or advertising cookies are set, so no cookie banner is required. Fonts are self-hosted — nothing is transmitted to an external font provider.
13. No analytics, no tracking
We use no analytics, tracking or advertising tools, no crash reporting and no advertising identifiers, and we perform no profiling. Nothing is passed to data brokers and no data is sold.
14. Recipients and processors
Beyond the purposes described here we do not pass personal data on. The providers we use are:
- Supabase Inc. — database, authentication and storage for profile pictures (server region North EU / Stockholm). Processor.
- Cloudflare, Inc. — delivery of the website and web app plus the catalog, price, news and Ask services (Workers, D1, R2, Pages). Processor.
- Google Ireland Limited / Google LLC — the Gemini API, solely to answer your Ask questions. Processor.
- Scryfall, LLC — image CDN for card images; your device fetches the images itself, which transmits your IP address.
- Apple Distribution International Ltd. and Google Commerce Limited — handling in-app purchases as controllers in their own right.
- Other users, where you trigger it: your friends, your trade partners, and anyone you give a share link to.
In addition there are recipients provided for by law, such as authorities where we are obliged to disclose.
15. International transfers
Your account and collection data is held by Supabase inside the EU (server region North EU / Stockholm). Access from the USA by the parent company Supabase Inc. cannot, however, be ruled out. Cloudflare, Inc. and Scryfall, LLC also process data in the USA; for Ask, your question, the conversation so far and the matched cards are transmitted to Google and may be processed outside the EU. These transfers rely on appropriate safeguards under Art. 44 et seq. GDPR: the EU-U.S. Data Privacy Framework where the provider concerned is certified under it, otherwise the EU Standard Contractual Clauses under Art. 46(2)(c) GDPR, in each case together with transport encryption. You can request a copy of the safeguards at [email protected].
16. Retention and account deletion
We keep personal data only as long as it is needed for the respective purpose:
- Account, collection, sealed, list, deck, friend and trade data: until you delete your account.
- Unconfirmed registrations: deleted automatically after 7 days.
- Profile picture: until you remove it, until removal following a justified report, or until account deletion.
- Share links: until you switch them off, at the latest until account deletion.
- Daily value history and Premium entitlement: until account deletion.
- Cardmarket imports: until account deletion.
- Ask: conversations are not stored at all; the daily counter expires within two days.
- Server log data at Cloudflare: kept briefly for technical reasons, then deleted automatically.
You can delete your account yourself at any time: in the app under More → Profile → Delete account, at the corresponding place in your profile in the web app, or by emailing [email protected]. This deletes everything stored on the server for your account — collections, cards, lists, decks, sealed products, friendships, trades, value history, imports, your Premium entitlement and your profile, including the image file of your profile picture, whose link stops working immediately. Cards stored only on your device stay there. Database backups may still contain data for the length of the backup window; it is no longer used and expires automatically.
17. Minors
The service is not directed at children under 16. We do not knowingly collect personal data from children. Where processing exceptionally rests on consent (the profile picture), that consent is only valid from the age of 16 in Germany under Art. 8 GDPR; younger people need their guardians' approval. If we learn that a child under 16 has created an account without that approval, we delete it.
18. Your rights
Under the GDPR you have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and to object to processing based on Art. 6(1)(f) GDPR (Art. 21). You may withdraw any given consent at any time with effect for the future. You can change your username, avatar and email address directly in the app, and you can export your cards as a CSV file at any time. For a complete copy of everything stored for your account, just email [email protected]. You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR) — either the authority responsible for us or the one where you live.