sparkl

Privacy Policy

Last updated: 14 July 2026

This Privacy Policy explains how Sparkl ("Sparkl", "we", "us", or "our") collects, uses, shares, and protects information when you use the Sparkl mobile application and the website at sparkl.gg (together, the "Service"). We built Sparkl to treat your collection — and your data — with care.

Contents

  1. Who we are
  2. Information we collect
  3. Public profiles
  4. How we use information
  5. Google user data & Limited Use
  6. How we share information
  7. Legal bases (EEA/UK)
  8. Data retention
  9. Security
  10. Your rights & choices
  11. International transfers
  12. Children's privacy
  13. Changes
  14. Contact

1. Who we are

Sparkl is a premium iPhone application for trading-card-game collectors. It lets you scan and identify cards, organize your collection, track its estimated market value, build decks and binders, and set price alerts. The Service is operated by Sparkl. If you have any questions about this policy or your data, contact us at contact@sparkl.gg.

2. Information we collect

2.1 Account information

You can create an account using Sign in with Apple or Continue with Google. When you do, we receive a limited set of details from that provider — your name (if shared), your email address (or a provider-relayed/private email), and a stable account identifier — which we use to create and secure your account and to sync your collection across your devices. We never receive your Apple or Google password.

2.2 Collection & usage content you create

To provide the Service, we store the data you add to your collection — for example the cards you scan or add, finishes and conditions, quantities, binders, decks, wishlist and price-alert targets, and notes. We also store app preferences such as language and display settings.

2.3 Card scanning (camera)

When you scan a card, the app uses your device camera to capture an image solely to recognize the card. Scan images are used only for card identification, are not used to identify you, and are not retained longer than necessary to process the recognition. We do not access your camera for any other purpose, and we do not access your photo library unless you explicitly choose to import an image.

2.4 Purchases

Card scanning is free and unlimited. Sparkl also offers an optional paid "Pro" subscription. Purchases are processed by the Apple App Store; we receive your subscription/entitlement status from Apple but never your full payment-card details.

2.5 Device & diagnostic data

Like most apps and websites, we automatically receive limited technical data such as device type and operating-system version, app version, language, approximate region, and basic interaction or crash/diagnostic events. This helps us keep the Service reliable and improve it.

The sparkl.gg website uses Cloudflare Web Analytics, a privacy-first, cookieless measurement tool that reports aggregate metrics (such as page views and referring sources) without tracking you across other sites and without using advertising cookies.

We also use Google Analytics (GA4) to understand how visitors use the site (for example, pages viewed, approximate location, device and browser type, and referring source). Google Analytics sets cookies and processes a pseudonymous identifier for this purpose. We use Basic Consent Mode: our pages do not request or configure the Google tag, and send no Google Analytics measurement, until you accept the analytics-cookie banner. Accepting grants only analytics storage; advertising storage, advertising user-data, and advertising-personalization signals remain denied. Our legal basis is your consent. To honor your choice on later page loads, Sparkl stores only granted or denied in first-party browser local storage under sparkl_consent_v1 until you change the choice or clear site data. You can withdraw as easily as you opt in by using the control below. Withdrawal immediately records a denied choice, tells Google Analytics that analytics storage is denied, removes our existing Google Analytics cookies, and keeps the Google tag blocked on later page loads unless you opt in again. You may separately clear or block analytics cookies in your browser settings. Information collected via Google Analytics is subject to Google's Privacy Policy; you can also install Google's opt-out browser add-on. We do not use Google Analytics data for advertising or sell it.

2.7 Optional public profiles

Publishing a Sparkl profile is optional and requires an express opt-in. If you publish, Sparkl creates a public page at a stable URL such as sparkl.gg/u/yourhandle (and its French-language equivalent). The page contains only an allowlisted public snapshot, such as the handle, display name, avatar, bio, selected highlights, and coarse collection summaries you chose to make public. It does not expose your email, subscription status, private notes or tags, acquisition prices, targets, certificate numbers, wishlist, scan times, exact private collection records, or exact private collection counts.

If you allow search indexing, search engines and social platforms may index the page or cache a link preview. You can hide the page from search results or unpublish it, but search snippets, social previews, browser caches, screenshots, and copies made by others may remain until those third parties refresh or remove them. We can request or encourage removal but cannot control their timing.

To prevent a stale public URL from later identifying or impersonating a different person, a normalized handle that has ever been public is not reassigned. After a rename or account deletion, we retain that plaintext handle indefinitely as an ownerless reservation. The reservation has no owner identifier. Any secret-keyed former-owner reference created for the finite dispute or appeal window is later removed, but the handle text itself remains and may itself be personal data. Other narrowly limited deletion records are described in the retention section below.

Separately, after account deletion, Sparkl keeps five narrowly scoped classes of permanent denial mechanisms so delayed or offline work cannot recreate deleted account data. The primary-database fence and the relevant sync-shard fence each retain only the historic internal account identifier. If the account had claimed legacy trainer records, one ID-only fence remains for each historic internal trainer identifier; it contains no account link, token, timestamp, or other field. A UserStore partition and a profile-authorization partition selected from the historic account identifier each retain only a constant erased-state marker; their stored payloads contain no account identifier or deletion token. An exact opaque token is used only while cleanup and its completion-confirmation and bounded-pruning period remain active, then removed from the shard fence, replaced by the UserStore constant marker, and discarded with the transient retry record. There is no permanently shared deletion token. The permanent records do not contain the former email, handle, collection, profile content, network address, or deletion timestamp, but the raw identifiers and identifier-derived partitions can still be related to a known former account or trainer by an authorized system. We therefore treat all five classes as potentially linkable pseudonymous operational data rather than claiming they are anonymous. They are retained only to deny resurrection, are not used for advertising or personalization, and require a documented necessity, proportionality, storage-limitation, security, rights, and objection assessment. They are distinct from the plaintext handle reservation described above.

Cloudflare processes public-profile requests at its network edge to route and protect the Service. This can include the requested URL (and therefore the public handle in a profile path), network address, and request headers before our application code runs. We configure the public-profile gateway not to retain automatic invocation logs or traces, and the gateway removes ambient Cookie and Authorization headers before application routing or downstream calls. These controls do not mean Cloudflare never processes the original edge request. The separate API Worker keeps native platform logs for reliability, with platform retention capped at no more than seven days. Any separately disclosed and approved Logpush, Tail, OpenTelemetry, security-log, or similar destination must have its own reviewed access and retention limit.

Public-profile requests may also generate limited operational and view telemetry in Cloudflare Analytics Engine. We use a secret-keyed pseudonymous profile key rather than a raw handle or account identifier, and record only bounded fields such as route type, locale, result, and a validated referral category. This dataset does not contain exact collection fields and is retained for up to three months. Because these events are pseudonymous and used in aggregate, we may not be able to locate and erase an individual event; it expires under the retention period.

You may report a public profile or appeal a moderation decision as described in our Public Profile & Content Policy. We may review reported content, restrict indexing, unpublish content, or suspend an account where needed to enforce that policy, protect people, or comply with law.

If you use the public-profile report form, we receive the reported profile handle, a report category, your chosen language, any optional detail you submit, and operational timestamps. The web gateway derives a fixed-length deterministic secret-keyed pseudonymous rate token from the network address used for abuse prevention before relaying the report. The API receives the report at a constant internal route and applies report-specific redaction so its application logs and report store do not retain the raw network address or country metadata; the Cloudflare edge processing described above still applies. The derived report/deduplication link is removed after its short operational window, and caller-free daily abuse totals are retained for up to 35 days.

Optional report detail, the report row's copy of the resolution reason, and free-form reasons in report-linked decision or hold events are normally removed within 90 days after a decision. Detail on an undecided report is escalated for review after 30 days and removed after at most 180 days. The ordinary report record and its report-specific events and administrative links are scheduled for removal within 365 days after intake or, if a decision is made later, within 365 days after that decision. A still-active or replayable moderation job may temporarily delay that final deletion so the system does not sever a live workflow; the overdue linkage is counted and alerted, and terminal job links are removed before the report is deleted. An authorized administrator may place a reasoned legal hold. Every hold receives a review deadline no more than 90 days later; a documented review may renew it for another period of no more than 90 days or release it. An overdue deadline alerts the responsible team but does not silently delete preserved evidence. Releasing a hold starts fresh 90-day detail-and-reason and 365-day ordinary-record clocks.

3. How we use information

We do not sell your personal information, and we do not use it for third-party advertising.

4. Google user data & Limited Use

If you choose to sign in with Google, Sparkl requests only your basic Google profile and email address, and only for authentication and account management. Sparkl's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, we use Google user data only to provide and improve the sign-in and account features you request; we do not transfer it to others except as necessary to provide the Service, comply with applicable law, or as part of a merger or acquisition; we do not use it for advertising; and we do not allow humans to read it unless we have your consent, it is necessary for security or to comply with law, or the data has been aggregated and anonymized. You can disconnect Google access at any time from your Google Account's connected-apps settings.

5. How we share information

We share information only as described here:

We never sell your personal information.

If you are in the European Economic Area or the United Kingdom, we process your personal data on the following bases: performance of a contract (to provide the Service you request), legitimate interests (to secure, maintain, and improve the Service), consent (where required, e.g. optional features — which you may withdraw), and legal obligation.

For the permanent ownerless reservation of a once-public handle, our intended legitimate interest is preventing stale-link impersonation and protecting the identity and expectations attached to an intentionally public URL. Before public profiles launch, counsel must confirm that indefinite plaintext retention is necessary and proportionate, document the balancing and storage-limitation analysis, and confirm the applicable objection process; otherwise we will change the design or retention period before launch.

For the permanent account-deletion denial records described above, our intended legitimate interest is preventing delayed, retried, or offline writes from recreating account data after a deletion has completed. Before launch, counsel must confirm that each retained account or legacy-trainer identifier and each identifier-derived partition is necessary, that the transient deletion token is removed after the completion-confirmation and bounded-pruning period under a monitored maximum-retention control, that no less-identifying reliable control is reasonably available, and that indefinite retention, access controls, security, storage limitation, data-subject rights, and the objection process are proportionate; otherwise we will change the design or retention before launch.

7. Data retention

We keep your information for as long as your account is active or as needed to provide the Service, and thereafter only as required to comply with legal obligations, resolve disputes, enforce our agreements, or pursue a documented and proportionate legitimate interest described in this policy. When you delete your account, we delete or anonymize your personal data within a reasonable period except for such limited justified retention.

When you unpublish a profile, Sparkl first blocks new authorized access and starts durable cleanup of generated profile and social-preview artifacts. The Sparkl page normally stops resolving within a few minutes. Account deletion starts the same durable cleanup before account removal completes; if cleanup is delayed, we retain only the minimum state needed to finish and verify it. Depending on how you signed in, this can include a minimal account tombstone and provider-revocation state, including Apple revocation state where applicable, until that work completes. An exact opaque deletion token remains only in the active cleanup fences and transient retry record. After cleanup completes, the retry record is held for a 24-hour completion-confirmation window and then becomes eligible for bounded oldest-first deletion; deletion backlog and maximum retention must be monitored and approved before launch. A completed deletion may leave an unlinkable randomized security-erasure receipt that does not contain the raw account identifier. Deterministic former-owner links used for an erasure dispute or appeal are removed after their finite operational window, normally within 90 days after completed erasure. The once-public handle remains as an ownerless plaintext reservation with no owner identifier. The five denial-mechanism classes described in Section 2.7 remain permanently as potentially linkable pseudonymous operational data under the documented assessment described above: the primary and sync-shard fences retain only the historic internal account identifier; any legacy-trainer fences retain only their historic internal trainer identifier, with no account link; and the UserStore and profile-authorization partitions retain only constant erased-state markers. No shared deletion token remains permanently. We do not imply that every provider-side identifier, security record, or token disappears at the same instant. Third-party search, social, browser, or recipient-held copies can persist longer as explained above. Public-profile Analytics Engine events expire within three months.

8. Security

We use technical and organizational measures designed to protect your information, including encryption in transit and access controls. No method of transmission or storage is completely secure, so we cannot guarantee absolute security, but we work to protect your data and to promptly address any issues.

9. Your rights & choices

Depending on where you live, you may have the right to access, correct, delete, export, or restrict the processing of your personal data, to object to certain processing, and to withdraw consent. You can delete your account at any time from within the app, which removes your associated personal data as described above. To exercise any right, email contact@sparkl.gg; we will respond as required by applicable law. If you are in California, we do not sell or "share" your personal information as those terms are defined under the CCPA/CPRA, and you will not be discriminated against for exercising your rights. You may also have the right to lodge a complaint with your local data-protection authority.

You can separately unpublish a public profile or turn off search indexing without deleting your account. Reports and moderation appeals follow the process in our Public Profile & Content Policy.

10. International transfers

We may process and store information in countries other than your own. Where we transfer personal data internationally, we rely on appropriate safeguards (such as Standard Contractual Clauses) where required by law.

11. Children's privacy

Sparkl is not directed to children under 13 (or the minimum age of digital consent in your country, which may be higher — for example 16 in parts of the EEA), and we do not knowingly collect personal data from them. If you believe a child has provided us personal data, contact contact@sparkl.gg and we will take appropriate steps to delete it.

12. Changes to this policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date above and, where appropriate, provide additional notice. Your continued use of the Service after an update means you accept the revised policy.

13. Contact us

Questions, requests, or concerns about this policy or your data? Email contact@sparkl.gg.

Sparkl is an independent collection-management tool. It is not affiliated with, endorsed by, or sponsored by Nintendo, The Pokémon Company, Creatures, GAME FREAK, Riot Games, or any trading-card publisher. Card names and images are the property of their respective rights holders and are used for identification purposes only.