Privacy Policy
Last updated: August 5, 2026
My Card Inventory ("we", "us") provides a service that reads purchase emails to build an inventory of the sports cards you own. An email reaches us in exactly one way: you forward it to a private address we give you. We do not connect to, sign in to, or read your mailbox, and we never ask for your email password. This policy explains what we collect, how we use it, and your choices.
1. Information we access and collect
- Account: your email address and authentication details, via Google Sign-In or email/password.
- Emails you forward: when you send an email to your private forwarding address, we receive that message, read it to extract purchase details, and put the result in your import queue for you to approve or discard. We only ever see what you choose to send. We do not have, and do not ask for, any access to the mailbox it came from.
- What we take from a forwarded email:structured purchase details (card, price, shipping, fees, tax, date, seller/platform) and an identifier for the message so the same receipt isn't imported twice. We never store or log full email bodies. If you set up automatic forwarding in your own email account, that rule lives in your account and you can change or remove it at any time without involving us.
- Your forwarding address: a random, unguessable address issued to you. It is a credential — anyone who has it can send us email that lands in your import queue — so keep it to yourself. You can rotate it at any time from your account, which switches the old one off immediately.
- Inventory data you create: cards, groups, notes, sale records, and settings.
- Usage/diagnostics: limited technical logs to operate and secure the service.
2. How we use it
We use your data solely to provide and improve the inventory features you asked for. Consistent with Google's Limited Use requirements, we do not sell your data, use it for advertising, or allow humans to read your email except where necessary for security, to comply with law, or with your explicit consent. Corrections you make to a parsed card are used to improve your own future results; we do not share the content of your email with other users.
3. How forwarding works
Your forwarding address contains a long random token that identifies your account, and that token is the only thing that determines whose queue an email lands in — not the sender. That has two consequences worth stating plainly:
- You can forward from any mailbox you like. We never learn its password and never gain access to it.
- Treat the address like a password. Anyone who has it can send email to it, which would place suggested cards in your import queue. It cannot read your inventory or change anything you own, and nothing is added without your approval — but you should not publish it. You can replace it at any time from the app, which stops the old one working immediately.
Forwarded messages are processed and not kept: we store the structured purchase details, the subject line and sender so you can see what arrived, and an identifier used to avoid importing the same email twice. We do not retain the message body.
4. What we store
We store the minimum necessary: the structured purchase details we extract and an identifier of which messages were already processed (to avoid duplicates). We do not retain full email content. Card photos you upload are stored at random, unguessable URLs — they are not listed or indexed anywhere, but anyone you give such a URL to can view that image.
5. Sharing & subprocessors
We don't sell your data. We use trusted providers to run the service: Resend (receiving the email you forward, and sending our own account emails), Anthropic (AI parsing of email text), Supabase (database, auth, photo storage), Vercel (hosting), Stripe (payments, if you subscribe), Google (sign-in only, if you choose Google Sign-In), eBay (only if you connect an eBay account — see below), and PostHog (product analytics and session replay, with all text masked before it leaves your browser). Each processes data only to provide their function.
5a. If you connect eBay
Connecting eBay is entirely optional and nothing here applies unless you do it. When you connect, eBay asks you to approve two permissions: managing your inventory and offers, and reading your account settings. We use the first to create and publish listings you have reviewed, and the second only to check whether your account has the shipping, payment and return policies eBay requires before it will publish anything.
We never see your eBay password.We store the access token eBay issues, and nothing else about your eBay account. That token lives in a table the browser cannot read at all — every use of it happens on our server. Disconnecting from inside the app deletes it, and you can also revoke us from eBay's own third-party app settings at any time.
The card details, photos and price you choose to list are sent to eBay to become the listing. What you paid is never sent. When you set a ship-from postcode we pass it to eBay so it can work out shipping, and we do not keep it.
5b. How we measure the site
We use PostHog to understand how the product is used — how people arrive, which features they use, whether they come back, and where a page confuses them. This includes interaction analytics and session replay (a playback of the layout and clicks in a visit). All text and every input are masked before anything leaves your browser, so what PostHog receives is layout and interaction — not your cards, prices, email addresses, or anything you type. You are identified only by an internal account id, never your email. We chose it this way deliberately: knowing where a page confuses people does not require knowing what anyone paid for a card.
6. Security
Data is encrypted in transit and at rest. Each user's data is isolated with row-level security. Server-only keys never reach the browser. No system is perfectly secure, but we follow least-privilege practices and store as little as possible.
7. Your choices & rights
- Stop forwarding at any time, or replace your forwarding address so the old one no longer works.
- Disconnect any inbox at any time to stop all future access.
- Request deletion of your account and associated data.
- Revoke our access from your Google Account security settings.
- Depending on where you live (e.g., California/CCPA, EU/GDPR), you may have additional access, deletion, and portability rights.
8. Data retention
We keep your inventory while your account is active. When you delete your account or data, we remove it from our systems within a reasonable period, subject to legal obligations.
9. Children
The service is not directed to children under 13 (or the applicable age in your region).
10. Changes & contact
We'll post changes here and update the date above. Questions or requests: privacy@mycardinventory.com.