TL;DR
Binder Boss is a local-first tracker. Your collection lives on your device in localStorage + IndexedDB, and once you sign in (on any plan, Free or Pro) your ownership rows also sync to Supabase under your user ID with row-level security, so only you can read them. Demo mode never leaves your browser. We never sell, share, or monetize your collection data.
What we collect
- Email address (any signed-in account): required to sign in, whether by email link, password, Google or Apple, via Supabase. We use it to sign you in and for account email you can control from your notification settings. If you sign in with Apple or Google, we also keep the name they share with us.
- Ownership rows (any signed-in account, because cloud sync is included on every plan): variant IDs, owned flag, acquired-at timestamp, optional notes you type. Stored under your user ID with RLS so only you can read your own data.
- Subscription state (Pro only): subscription status and period end, plus the Stripe customer ID if you subscribed on the website, or the RevenueCat record of your App Store or Google Play purchase if you subscribed in the app. Used to grant Pro features.
- Error reports: when something crashes on the website, we send the error stack + minimal context to Sentry, with PII fields (email, notes) stripped before sending. When the mobile app crashes, it sends the error details to us directly, to the same inbox as your support messages.
- Binder photos (only if you use photo identification): uploaded to a private bucket only you can access, and sent once to identify the cards in frame, to our AI provider (Anthropic) and, as cropped images of each pocket, to Scrydex's card-image matching service. Auto-deleted within 7 days. Photos are never used to train models and never made public.
- Product usage events: first-party analytics (PostHog) covering which features get used (e.g. sign-up, checkout, sync), page performance, and anonymized usage patterns. Used only to improve the product: never sold, never shared with advertisers.
- Email we send you: account emails (a welcome message, occasional tips and milestone notes, new-set announcements, and a notice when someone sends you a binder) are sent via Resend to the address you signed up with. Every one of them has an unsubscribe path. Sign-in links are sent by Supabase.
- Published binders: if you explicitly publish a binder, its contents (and your chosen username) become publicly viewable at your share link until you unpublish. Imagined cards are hidden or badged per your per-binder setting.
What we don't collect
- No advertising trackers or data brokers, ever. Our analytics are first-party product metrics, not ad tech.
- No payment card details. Stripe handles website payments end-to-end, and Apple or Google handle purchases made in the app. We see only the subscription status, not card numbers.
- No location data, contacts or browsing history. The only device identifier is in the mobile app: a random ID created on install, which the app sends to Expo, our app-update service, when it checks for updates. It is not linked to your account.
Where data lives
- Your device:
localStorage(collection, binders, wishlist, theme preference, dismissed hints) + IndexedDB (cached card catalog) on the website; in the mobile app, databases and cached images kept in the app's own storage on your phone. - Supabase (every signed-in account, on any plan): US-East region. Postgres with row-level security; only your user ID can read your rows.
- Stripe (only if you buy Pro): subscription state + payment processing. Stripe's privacy policy applies for payment data.
- RevenueCat, Apple and Google (only if you buy Pro in the app): Apple or Google process the payment; RevenueCat keeps the purchase record under your user ID so Pro works on every device.
- Expo (mobile app): delivers app updates, and push notifications for accounts that turn them on.
- Google Firebase Cloud Messaging (Android app): Android's push-notification service. It may register an app-installation ID on the device.
- Sentry: error reports only. We can disable Sentry entirely by clearing the DSN env var.
- PostHog: product usage events (first-party analytics).
- Resend: outbound email delivery (account messages).
- Anthropic (our AI provider, for photo identification and AI suggestions only): transient processing of the photo or card metadata you submit; nothing is retained for model training.
- Scrydex (our card-data provider): serves the card catalog, and, only when you use photo identification, matches cropped images of each pocket against it.
Your rights
- Export: at /app/data you can download two files at any time: your ownership list as a CSV, and a full backup of your collection (a JSON file with your binders, owned cards, wishlist, activity and achievements). These cover your collection. They do not include your account details, subscription and billing records, or messages you have sent us.
- Delete: delete your entire account yourself from /app/data (Danger zone → Delete account). It removes every cloud-synced row, binder, published page, and uploaded photo, and cancels any active subscription immediately. You can also clear local data only, without deleting your account, from the same page.
- Access / correction: to get a copy of anything the exports above do not cover, or to correct something we hold about you, email
admin@deadcenterstudios.comand we'll respond within 14 days.
Children's privacy
Binder Boss is intended for people aged 13 and over (16 where required, such as parts of the EEA), as set out in the Terms. We do not knowingly collect personal information from children under 13. If we learn that we have, we delete the account and its data promptly. If you believe a child has given us personal information, contact admin@deadcenterstudios.com and we will remove it.
Cookies & analytics
- Essential only, by default: the cookies required to keep you signed in (Supabase session) and to remember an explicit demo-mode choice. These cannot be turned off without breaking sign-in.
- Product analytics: we use PostHog to understand which features get used. It records usage events against a pseudonymous device identifier, not your name or collection contents.
- No advertising cookies. We do not run ads, and we do not sell or share personal information for cross-context behavioural advertising.
Every cookie and storage key we set is itemised in the Cookie Policy.
How long we keep things
- Account & collection data: for as long as your account exists. Deleting your account removes it.
- Binder photos: deleted automatically after 7 days by a scheduled cleanup, and immediately on account deletion.
- Billing records: Stripe retains transaction records for the period its own obligations require, independently of your Binder Boss account.
- Local device data: stays on your device until you clear it from /app/data or clear your browser storage.
Why we're allowed to process it
Where the GDPR applies, we rely on: contract, to provide the account and subscription you asked for; consent, for the optional AI features and for lifecycle email, each of which you can withdraw at any time; and legitimate interests, to keep the service secure, prevent abuse, and fix errors.
Who else touches your data
We use a small number of third-party services to run Binder Boss: hosting, database, payments, email, error monitoring, analytics, and card identification. Each one, what it receives, and where it is located is listed on the subprocessors page.
Card data attribution
Pokémon card metadata (names, set lists, images, rarities) comes from the Scrydex API and the public pokemontcg.io API. Pokémon, the Pokémon TCG, and all related trademarks are property of The Pokémon Company International, Nintendo, Game Freak, and Creatures Inc. Binder Boss is a fan-made independent tool with no affiliation.
Who controls your data
Binder Boss is operated by Dead Center Studios LLC, a limited liability company formed in the State of New York, United States. Dead Center Studios LLC is the data controller for personal information handled by Binder Boss, and is registered with the New York Department of State (DOS ID 7894666).
Contact
Privacy questions: admin@deadcenterstudios.com. Security disclosures: admin@deadcenterstudios.com (see /.well-known/security.txt).
This policy reflects how the app handles data today. Questions: admin@deadcenterstudios.com.