DRAFT — for review. Not yet in force. Effective date: [DATE — SET AT LAUNCH] KDC Solutions — [email protected]
This is the single, canonical privacy policy for Vaultix. The in-app policy link and the Play Store listing both point here. [DECIDE — hosted URL for this document.]
Card recognition runs entirely on your phone. When you scan a card, the photo is processed on-device: no image, no card name, and nothing about your collection is sent anywhere. Your collection and binders are stored only on your device. The App has no accounts, no ads, no analytics SDKs, and no telemetry.
A small number of things *do* leave your device, each for a specific reason, and this policy lists every one of them. If it isn't listed below, it doesn't leave your phone.
1. Misread flags — only if you choose to send one. If a card is recognized wrong, you can flag it. Flagging is opt-in for each individual flag; nothing is ever submitted automatically. Before anything is sent, the App shows you the exact image that will be submitted. That image is cropped to the card area only — never your table, hands, or room — and is re-encoded with all EXIF and location metadata removed. We use flagged images solely to improve card recognition. Your per-flag consent is recorded with the submission. We never use flagged images for advertising, never sell them, and never share them with third parties.
2. Recognition-accuracy counters attached to those flags. When you send a flag, the App attaches anonymous on-device accuracy counters: numbers and card identifiers only (for example, how many scans locked on the first try). These counters never include images (beyond the flagged image you approved), and never include the names or contents of your collection.
3. Feature-request form text — only if you choose to submit it. The optional feature-request form sends the text you type plus a device identifier used for rate limiting. It is anonymous by design: there are no name or email fields. Please do not put personal information in the free-text box — because submissions are anonymous, we cannot find "your" submission later to retrieve or delete it.
4. Subscription and quota state. Purchases are processed by Google Play Billing; we never see your payment details. To grant your tier and enforce scan quotas, the App periodically checks in with our server, exchanging your purchase state, entitlement tier, scan balances, and a device identifier. This is subscription bookkeeping — numbers and tokens, never images or collection contents. If a referral program is active and you redeem a code, the code redemption is recorded the same way to credit both sides and prevent abuse.
5. Pack downloads and price refreshes. Downloading a game's recognition pack or refreshing prices is an ordinary HTTPS download of public data — the same as any app fetching a file. The request does not include your collection, scans, or identity. Like every internet request from any device, it necessarily exposes your IP address to the server that fulfills it; we do not use IP addresses to identify or profile you.
Vaultix is a general-audience app. It is not directed to children, and by design it collects no personal details — no names, emails, or locations — from any user of any age. The data flows above are the complete list, and the only image flow (misread flags) is opt-in per submission with the exact image shown first. If you believe a child has submitted something they should not have, email [email protected] and we will delete it.
All transmissions use HTTPS/TLS. Flagged images are stored only for processing and deleted per the retention schedule above. No system is perfectly secure, but our best protection is structural: the data we never receive is data that cannot be breached.
We do not sell, rent, or share your data with third parties for their own purposes. The services involved in operating Vaultix are: Google Play (app distribution and billing — governed by Google's own privacy policy) and our infrastructure providers that host our server endpoints and public data files (acting only as processors on our behalf). Public card data and market prices come from public sources; nothing about you is sent to them beyond the ordinary mechanics of an HTTPS download.
If we change what data leaves the device, we will update this policy, change the effective date, and give in-app notice before the new flows take effect. We will never retroactively expand what happens to data you already submitted.
KDC Solutions Email: [email protected]
*Draft for internal review. A licensed attorney must review this policy and the Terms of Service before commercial launch.*
<!-- ======================================================================== INTERNAL — Google Play Data Safety form alignment notes (do not publish as user-facing text; this comment exists so the form submission is a transcription job and stays in lockstep with the policy above).
Overview answers:
Declared data types (see docs/legal/DATA_SAFETY_FORM.md for the full per-question matrix):
======================================================================== -->
This is the same document that ships inside the app — one source of truth, no drift. © 2026 KDC Solutions™