🇫🇷Cette page existe aussi en français.

Lire en français
✦ pepita
  • 🇫🇷Français

Privacy policy

Last updated: 6 October 2026

Who we are

pepita is published by Mathis Grosjean, who is the data controller. For any question, email support@pepitacards.com.

Data we collect

When you use Sign in with Apple or Google, we receive and retain the account identifier supplied by that provider and, when shared, your email address. This data is used to manage your account and support conversations. The authentication token is kept in secure storage on your device.

When you scan a card, the photo is sent to our server and then to Ximilar, our image-recognition provider, to identify the card. We keep a resized copy of the photo, stripped of its metadata (no location, no device information), for up to 12 months. It is used only to fix recognition errors and to train our own card-recognition models; it is never sold, never used for advertising and never used to identify you. We also retain a digital fingerprint (hash), the identified card and technical scan metadata such as image size, outcome, confidence and processing times.

The app creates a persistent installation identifier to enforce anti-abuse limits. We also process the IP address and rate-limiting signals. This data is not used for advertising or tracking.

PostHog processes limited usage statistics: app opens, scans, cards added, features viewed, action outcomes and duration, an installation-specific identifier, app version, device model and type, operating system, language and time zone. IP-based geolocation, screen recording and session replay are disabled.

Your card collection is stored locally on your device. It is not stored in a server profile.

When you join the Pepita Market Weekly launch list, we retain the email address entered, language, signup surface and consent date. No newsletter is sent before a confirmation process is introduced.

On pepitacards.com, Vercel Web Analytics anonymously measures visits and pages viewed. It processes the URL, referring site, country, device type, browser and operating system. It does not use cookies and does not retain your IP address or an identifier that can recognise you.

Also on pepitacards.com, a measurement script we wrote ourselves sends two events to PostHog: a page view, and a tap on an App Store download button or its Google Play equivalent. It sends the page viewed without its query string, the referring site’s domain name, the campaign tags of a shared link (utm_source, utm_medium, utm_campaign), the language and the site section. Nothing else.

This measurement uses no cookie, no device fingerprint and no lasting identifier: every page load is given a random identifier that is thrown away immediately. PostHog therefore counts page views and taps, never unique visitors, and builds no profile. The campaign tags of the link that brought you here are kept in the tab’s session storage for the duration of your visit, so that a tap from another page is still credited to the right link; they contain campaign words only and disappear when the tab closes. If your browser sends the Do Not Track or Global Privacy Control signal, nothing is sent at all.

Two additions about AI assistants. Visits from AI assistants’ crawlers are counted server-side, with the bot name as it identifies itself and the page requested, without any IP address; no such event is recorded for a person’s visit. And when a visit arrives from an AI assistant, the page view and the tap described above also carry that assistant’s name, taken from a closed list (for example “chatgpt” or “perplexity”).

How we use data

We use this data to authenticate your account, identify a scanned card, display its card sheet, estimate its value and track its value in the app. An address submitted to Pepita Market Weekly is used only to prepare and later confirm that newsletter.

We do not use your data for advertising, sell it or track you across apps or websites. App statistics help us measure and improve usage. Anonymous website statistics are used only to understand site traffic and to learn which shared links lead to downloads. We use no advertising or analytics cookies.

Sharing with service providers

Apple and Google provide the corresponding sign-in services. Ximilar receives the card photo temporarily to perform image recognition. Cardmarket and PriceCharting provide card price data; they receive no personal data.

Supabase, Fly.io and Vercel provide database, file storage (including scan photos), API and website infrastructure. They receive only the data required to provide these services. PostHog processes the limited app statistics, the two website events described above and the count of AI crawler visits in the United States. Vercel provides anonymous website analytics. pepitacards.com loads no third-party script: the measurements are sent from our own domain.

Retention and deletion

Scan photos are deleted automatically after 12 months at most, and immediately when you delete your account. You can also ask us to delete them, or object to their use for model training, at support@pepitacards.com. Account data, digital fingerprints and scan metadata are kept while your account is active or for as long as necessary to provide the service.

A Pepita Market Weekly pre-registration is retained until it is confirmed, withdrawn or the project is abandoned. You can request deletion at support@pepitacards.com.

The anonymous identifier used by Vercel Web Analytics is renewed every day. Aggregated statistics are retained for the reporting period provided by our Vercel plan.

App statistics are retained only for the configured reporting period. The installation identifier is deleted from the device when the app is uninstalled.

The two website events and the count of AI crawler visits are retained for the reporting period provided by our PostHog plan. They are attached to no profile and to no lasting identifier, so there is nothing about you to delete.

You can delete your account and its scans at any time in the app through Réglages → Supprimer le compte. This also removes the local data for that account from the device. You may also revoke pepita in your Apple or Google account settings; the app does not retain a provider token that can revoke that authorization for you.

Your rights under the GDPR

You may request access to, correction or deletion of your data, or object to certain processing, within the limits provided by the GDPR.

To exercise these rights, email support@pepitacards.com.

Children

pepita is not intended for children under 15. If you believe a child has sent us data, contact us to request its deletion.

Changes and contact

If this policy changes, we will publish the new version on this page with an updated revision date.

For privacy or support questions, email support@pepitacards.com or visit Support.

pepita
Last updated: 6 October 2026 · © 2026 pepita
SupportPrivacy