Pre-release policy draft. The support mailbox, final service-provider list, and backend retention period must be confirmed before store submission.

1. Scope and operator

This policy explains how Fireshark HK, the publisher and operator of ScanFolio TCG, handles information in the mobile app and this support website.

2. Card photos and scan processing

You choose whether to use the camera or photo library. A selected card image is sent over HTTPS to the ScanFolio scan service only when you start a scan. The server temporarily writes the upload for processing and attempts to delete the image immediately after the request finishes, whether the scan succeeds or fails.

For matching and card-number recognition, the release service may send image bytes to configured cloud processors such as Amazon Bedrock and Google Cloud Vision. The final published version of this policy must name only the processors enabled in production.

3. Operational scan records

The server does not retain the card photo itself after processing. It records a scan ID, random server filename, file type and size, a SHA-256 content hash, provider/model details, success or failure status, bounded OCR diagnostics, and returned card candidates. Full OCR text, card-photo bytes, account identifiers, and provider credentials are deliberately excluded.

Launch blocker: an automated retention period for these operational records is not yet defined in the repository. A period and deletion process must be approved and implemented before this draft becomes the production policy.

4. Information stored on your device

Your confirmed scan history, collection, language, theme, and display-currency settings are stored locally by the app and are not synced to ScanFolio servers. The MVP has no ScanFolio account or cloud collection sync. Your operating system may include app data in a device backup or transfer according to platform settings. You can delete individual items or clear the collection/history in the app; removing the app removes its active local data, subject to any separate OS-managed backup.

5. Crash diagnostics

Release builds use Firebase Crashlytics for stability diagnostics. Reports can include stack traces, app state, app version, operating system/device details, crash time, a Crashlytics installation UUID, and a Firebase installation ID. Scan photos, OCR text, search queries, collection contents, scan history, email addresses, advertising IDs, and custom user IDs are not attached by our reporting boundary. Google states that Crashlytics keeps crash traces and associated identifiers for 90 days before removal begins.

6. Website and support messages

Firebase Hosting may process IP addresses and standard request data to deliver and protect this website. If you email support, we receive the address and content you choose to send and use them only to answer, troubleshoot, prevent abuse, and meet legal obligations. Do not send card photos, passwords, API keys, or payment information in a support message.

7. Sharing, subscriptions, advertising, and tracking

Cloud hosting, scan-processing, crash-reporting, RevenueCat, and the applicable app store act as service providers for the purposes described above. ScanFolio has no login. Each installation receives up to five free scans per day and may optionally buy an auto-renewing unlimited-scan subscription. RevenueCat and the store process the anonymous installation identifier and purchase-entitlement information needed to verify access; ScanFolio does not receive your store payment details. We do not sell personal data, display advertising, build advertising profiles, use an advertising ID, or include cross-app tracking.

8. Retention, deletion, and choices

  • Temporary uploaded photos: deleted on a best-effort basis immediately after scan processing.
  • Local collection/history: retained until you delete it or remove the app; an OS-managed backup may retain a separate copy under platform settings.
  • Crashlytics records: retained under Firebase's published Crashlytics schedule.
  • Support messages and operational scan records: final production periods must be approved before launch.

You can deny camera/photo access and use other app features. For a privacy or deletion request, use the support page and include only the minimum information needed to locate the record, such as a scan ID.

9. Contact and changes

Contact the publisher through the support page. We will update the effective date and re-review store disclosures when data practices change.

1. 適用範囲と運営者

本方針は、ScanFolio TCG の提供者・運営者である Fireshark HK がモバイルアプリおよび本サポートサイトで情報をどのように扱うかを説明します。

2. カード画像とスキャン処理

カメラまたは写真ライブラリの利用はユーザーが選択します。カード画像は、ユーザーがスキャンを開始したときだけ HTTPS で ScanFolio のスキャンサービスへ送信されます。サーバーは処理のため一時保存し、成功・失敗にかかわらずリクエスト終了後すぐに削除を試みます。

画像照合とカード番号の認識では、本番環境で有効な Amazon Bedrock や Google Cloud Vision などのクラウド処理サービスへ画像が送られる場合があります。公開版では実際に有効なサービスだけを記載します。

3. 運用上のスキャン記録

処理後のカード画像自体は保持しません。サーバーには、スキャン ID、ランダムなファイル名、種類・容量、SHA-256 ハッシュ、プロバイダー/モデル、成否、限定された OCR 診断、候補カードが記録されます。OCR 全文、画像データ、アカウント ID、認証情報は保存対象外です。

公開前の未完了事項:これらの運用記録の自動保持期間がまだ確定していません。公開前に期間と削除手順を承認・実装します。

4. 端末内に保存する情報

確認済みスキャン履歴、コレクション、言語、テーマ、表示通貨はアプリが端末内に保存し、ScanFolio のサーバーへ同期しません。MVP にはアカウントもクラウド同期もありません。OS の設定により、アプリデータが端末バックアップや移行に含まれる場合があります。アプリ内で項目を削除または履歴・コレクションを消去でき、アプリ削除時は別途 OS が管理するバックアップを除き、使用中のローカルデータが削除されます。

5. クラッシュ診断

リリース版は Firebase Crashlytics を安定性診断に使用します。スタックトレース、アプリ状態、バージョン、OS/端末情報、発生時刻、Crashlytics Installation UUID、Firebase installation ID が含まれる場合があります。当方の送信境界は、カード画像、OCR 文字列、検索、コレクション、スキャン履歴、メール、広告 ID、独自ユーザー ID を添付しません。Google は、Crashlytics のクラッシュ記録と関連 ID を90日保持した後に削除を開始すると説明しています。

6. ウェブサイトとサポート連絡

Firebase Hosting は配信と不正利用防止のため IP アドレスと標準的なリクエスト情報を処理する場合があります。サポートへメールすると、送信元アドレスと本文を受領し、回答、問題解決、不正防止、法的義務のためだけに使用します。カード画像、パスワード、API キー、決済情報は送らないでください。

7. 提供、サブスクリプション、広告、トラッキング

クラウドホスティング、スキャン処理、クラッシュ診断、RevenueCat、該当するアプリストアは上記目的のサービス提供者です。ScanFolio にログインはありません。各インストールは1日5回まで無料でスキャンでき、任意で自動更新の無制限スキャン購読を購入できます。RevenueCat とストアはアクセス確認に必要な匿名インストール ID と購入権利情報を処理しますが、ScanFolio がストアの支払情報を受け取ることはありません。個人データの販売、広告、広告プロファイル、広告 ID、アプリ横断トラッキングは行いません。

8. 保持、削除、選択

  • 一時アップロード画像:処理直後にベストエフォートで削除。
  • 端末内コレクション/履歴:ユーザーが削除するかアプリを削除するまで保持。OS 管理のバックアップには別のコピーが残る場合があります。
  • Crashlytics:Firebase の公開保持期間に従う。
  • サポート連絡と運用スキャン記録:公開前に期間を確定。

カメラ/写真アクセスを拒否して他の機能を使えます。プライバシーや削除の依頼は、スキャン ID など記録の特定に必要な最小限の情報だけを添えてサポートページからご連絡ください。

9. 連絡先と変更

サポートページから提供者へご連絡ください。取扱いが変わる場合は発効日とストア申告を見直します。

1. 適用範圍及營運者

本政策說明 ScanFolio TCG 發行及營運者 Fireshark HK 點樣處理流動應用程式同支援網站嘅資料。

2. 卡牌相片及掃描處理

你可以自行選擇使用相機或相片圖庫。只有當你開始掃描時,所選卡牌相片先會經 HTTPS 傳送到 ScanFolio 掃描服務。伺服器會為處理而暫時寫入上載檔案,並會喺請求完成後立即盡力刪除,無論掃描成功與否。

為咗配對圖像同辨認卡號,正式版本可能會將圖像資料交由已啟用嘅雲端處理服務,例如 Amazon Bedrock 或 Google Cloud Vision。正式政策只會列出 production 實際啟用嘅服務。

3. 營運掃描紀錄

處理後唔會保留卡牌相片本身。伺服器會記錄掃描 ID、隨機檔名、檔案類型及大小、SHA-256 雜湊、供應商/模型、成功或失敗狀態、有限度 OCR 診斷同候選卡牌。完整 OCR 文字、相片內容、帳戶識別碼同供應商憑證會刻意排除。

推出阻擋:程式庫目前未定義呢啲營運紀錄嘅自動保留期限。推出前必須批核並實作保留期同刪除流程。

4. 儲存喺裝置嘅資料

App 會將已確認掃描紀錄、收藏、語言、主題同顯示貨幣儲存喺你部裝置,唔會同步到 ScanFolio 伺服器。MVP 冇 ScanFolio 帳戶或雲端收藏同步。作業系統仍可能按平台設定將 app 資料加入裝置備份或轉移。你可以喺 app 刪除個別項目或清除收藏/紀錄;解除安裝會移除使用中嘅本機資料,但 OS 另行管理嘅備份除外。

5. 當機診斷

Release 版本使用 Firebase Crashlytics 改善穩定性。報告可能包括 stack trace、app 狀態、版本、作業系統/裝置資料、發生時間、Crashlytics Installation UUID 同 Firebase installation ID。我哋嘅回報邊界唔會附加卡牌相片、OCR 文字、搜尋、收藏、掃描紀錄、電郵地址、廣告 ID 或自訂用戶 ID。Google 表示 Crashlytics 會保留當機紀錄及相關 ID 90 日,之後開始刪除。

6. 網站及支援訊息

Firebase Hosting 可能會處理 IP 地址及標準請求資料,用作網站傳送及防止濫用。如果你電郵支援,我哋會收到你選擇提供嘅地址及內容,只會用作回覆、排解問題、防止濫用及履行法律責任。請勿喺支援訊息傳送卡牌相片、密碼、API key 或付款資料。

7. 分享、訂閱、廣告及追蹤

雲端託管、掃描處理、當機回報、RevenueCat 同適用嘅 app store 只會按上述用途提供服務。ScanFolio 冇登入。每個安裝每日有最多 5 次免費掃描,亦可選擇自動續期嘅無限掃描訂閱。RevenueCat 同商店會處理驗證存取所需嘅匿名安裝識別碼同購買權益資料;ScanFolio 唔會收到你嘅商店付款資料。我哋唔會出售個人資料、顯示廣告、建立廣告檔案、使用廣告 ID 或跨 app 追蹤。

8. 保留、刪除及選擇

  • 暫時上載相片:掃描處理後立即盡力刪除。
  • 本機收藏/紀錄:直至你刪除資料或移除 app;OS 管理嘅備份可能另行保留副本。
  • Crashlytics:按 Firebase 公開嘅保留時間處理。
  • 支援訊息及營運掃描紀錄:推出前必須批核正式期限。

你可以拒絕相機/相片權限並繼續使用其他功能。如要提出私隱或刪除要求,請經支援頁聯絡,並只提供識別紀錄所需嘅最少資料,例如掃描 ID。

9. 聯絡及政策更新

請經支援頁面聯絡發行者。資料處理方式有變時,我哋會更新生效日期並重新檢視商店申報。