Skip to content

Privacy Policy

Last updated: [date]

This policy explains what CardVault Identify ("we", "us", operating at aicardvault.io) collects when you use our website, dashboard, and API, and how we use it.

1. What we collect

We collect the minimum needed to run the service:

  • Account data — your email address, name (if provided via OAuth), and hashed authentication credentials.
  • Uploaded card images — front and back photos you submit to /api/v1/identify, plus any corrections you submit via /api/v1/feedback.
  • Usage and API logs — request timestamps, endpoint, response status, latency, and API key used, for billing, rate limiting, and abuse prevention.
  • Billing data — handled by Stripe; we store your plan, subscription status, and Stripe customer ID, not raw card numbers.

2. How we use images

Images you submit are used to fulfill your identify request — cropping, fingerprinting, and matching against our visual index. Confident matches and corrections you send back also feed a nightly re-indexing flywheel that improves accuracy and coverage over time. We do not sell your images, and we do not share them with third parties beyond the infrastructure needed to process your request.

3. Third parties we use

  • Stripe — payment processing and subscription billing.
  • Resend — transactional email (sign-in links, receipts, notices).
  • GitHub OAuth — if you choose to sign in with GitHub, we receive your public profile email and name.

Each of these providers processes data under their own privacy policy and only receives what's necessary to perform their function for us.

4. Data retention

Account data is retained for as long as your account is active. Uploaded images and request logs are retained for as long as needed to operate and improve the service, and may be kept in aggregated or anonymized form for the accuracy flywheel even after an individual account is deleted. You can request deletion of your account and associated data at any time — see Section 6.

5. Security

API keys are stored hashed, never in plaintext. All traffic to the API and dashboard is encrypted in transit (TLS). Access to production data is limited to the team members who need it to operate the service.

6. Your rights

You can access, correct, export, or delete your account data at any time. Log in to the dashboard to manage your account, or email us and we'll handle the request directly. Depending on where you live, you may have additional rights under laws like the GDPR or CCPA — reach out and we'll do our best to accommodate them regardless of jurisdiction.

7. Changes to this policy

We'll update the "Last updated" date above when this policy changes materially, and for significant changes we'll notify account holders by email.

8. Contact

Questions about this policy or your data? Email support@aicardvault.io.