Skip to content
RAREBLINK
Home Terms Privacy
Get the App
DRAFT — requires review by a licensed attorney before publication.

This document was AI-drafted from product specifications and is not legal advice. Do not publish, submit for App Store review, or rely on this document until it has been reviewed and approved by a licensed attorney in North Carolina.

Legal

Privacy Policy

Effective Date: [EFFECTIVE DATE] · Last Updated: [EFFECTIVE DATE]

This Privacy Policy explains how Nickolas Parker, doing business as RAREBLINK (“RareBlink,” “we,” “us,” or “our”) collects, uses, discloses, and protects information in connection with the RareBlink iOS app and website (rareblink.app / rareblink.com) (together, the “Service”). This Policy should be read together with our Terms of Service.

Contents

  1. 1. Overview: Anonymous by Default
  2. 2. Information We Collect
  3. 3. How We Use Information
  4. 4. Third-Party Service Providers (Processors)
  5. 5. No Sale of Personal Data
  6. 6. Data Retention
  7. 7. Your Privacy Rights
  8. 8. Children’s Privacy
  9. 9. Push Notifications
  10. 10. Data Security
  11. 11. Changes to This Policy
  12. 12. Contact Us

1. Overview: Anonymous by Default

RareBlink is built so that you do not need to create an account to use the free tier of the app. Browsing Blinks, setting a limited number of Watches, and running a limited number of Scans all work on an anonymous, device-scoped basis — we assign your device a random identifier rather than asking for a name, email, or phone number. We only ask for account information (via Sign in with Apple or Google) when you choose to sync across devices or subscribe to a paid tier. This section is a summary; the sections below describe our data practices in full.

2. Information We Collect

2.1 Anonymous device identifier

When you use the free tier without creating an account, we generate and store a random device-scoped identifier on our servers. This identifier is used to associate your Watches, Scan history, and notification preferences with your device, without collecting your name, email, or other directly identifying information.

2.2 Push notification tokens

If you enable Blink Alerts, we collect and store a device push token (issued by Apple Push Notification service, via our push provider) so we can deliver alerts to your device. The token is linked to your device identifier (or account, if you have one) and your notification preferences (e.g., alert sensitivity level).

2.3 Watch criteria

Information you configure for Watches — such as player/subject, set, card, minimum RareBlink Value, minimum discount, or minimum Blink Score — is stored so the Service can match new Blinks against your preferences and alert you.

2.4 Scan photos

When you use the RareBlink Scan feature, we collect the photograph(s) you take or upload for card identification. Scan photos are sent to and processed by third-party AI/vision and card-database services (currently including OpenAI’s vision models and CardSight’s card catalog/database) solely to identify the card, its set/parallel/variation, and to estimate its value via comparable sales. Scan photos are not used for advertising or ad targeting, by us or, to our knowledge, by these processors under our current agreements with them. See Section 4 for more on these processors.

2.5 Account information (optional)

If you choose to create an account via Sign in with Apple or Google (through our authentication provider, Supabase), we receive and store the name and email address made available to us by the sign-in provider (Apple allows you to keep your email private via Apple’s private relay; Google does not offer an equivalent built-in relay). We do not collect a password directly — authentication is handled by Apple/Google/Supabase.

2.6 Subscription status

If you subscribe to a paid tier, Apple handles all billing and payment information directly — we never receive or store your payment card details. We receive from Apple a subscription status/entitlement signal (e.g., active, tier, expiration) sufficient to unlock paid features in the Service.

2.7 Usage and diagnostic data (minimal analytics)

We collect a limited set of operational and diagnostic data, such as app crash logs, basic feature-usage events (e.g., which screens are used), and API error rates, to keep the Service running and to improve it. We aim to keep this to the minimum needed for operations and do not currently use third-party advertising analytics/SDKs.

2.8 Information we do not collect

We do not collect precise (GPS) location, contacts, photos other than those you explicitly submit for Scan, or biometric data. We do not knowingly collect payment card numbers (Apple handles all billing).

3. How We Use Information

We use the information described above to:

  • operate core features: matching listings against your Watches, generating and delivering Blink Alerts, and processing Scans;
  • compute and display RareBlink Value, Blink Score, Value Confidence, and Identification Confidence;
  • maintain, secure, debug, and improve the Service;
  • manage your account and Subscription (if applicable);
  • communicate with you about the Service (e.g., service notices, security alerts); and
  • comply with legal obligations and enforce our Terms of Service.

We do not use Scan photos, Watch criteria, or account information to serve you third-party advertising, and we do not build advertising profiles about you.

4. Third-Party Service Providers (Processors)

We rely on the following third-party service providers (“processors”) to operate the Service. Each processes data on our behalf and under its own terms/privacy policy, linked where available. This list reflects our current architecture and may change; material changes will be reflected in an updated version of this Policy.

ProviderRoleData it may processNotes
Supabase Backend database (Postgres) and authentication Device identifiers, Watch criteria, account name/email (if signed in), push tokens, subscription status Primary data store; US-hosted
Vercel Web hosting / API infrastructure Request logs, operational data in transit Hosts our website and backend API endpoints
Apple App distribution, Sign in with Apple, In-App Purchase billing Sign-in identity token, subscription/billing status, push notification delivery (APNs) Apple’s own privacy policy governs how Apple itself uses your Apple ID/payment data — we never see your payment details
OpenAI AI vision processing for Scan card identification Scan photographs, associated identification metadata Used to identify cards from photos; per our agreement, not used to train OpenAI’s general models or for advertising
CardSight Card catalog/identity database and sales-comp pricing data Scan photographs / parsed listing text (for identification), card identity queries, pricing/comp lookups Third-party sales-comp data underlies RareBlink Value estimates
eBay / eBay Partner Network (EPN) Source marketplace for Blinks; affiliate tracking on link-out Listing data we retrieve from eBay; when you tap “View on eBay,” eBay and/or EPN may set cookies or use tracking parameters embedded in the link to attribute the referral and any resulting purchase to RareBlink This occurs on eBay’s own site/app after you leave RareBlink, governed by eBay’s own privacy policy and cookie practices, not this Policy

We require our processors to protect data consistent with this Policy and to use it only to provide services to us, except as required by law.

5. No Sale of Personal Data

We do not sell your personal information, and we do not share it with third parties for their own independent advertising purposes. Our disclosures to the processors in Section 4 are made solely to operate, provide, and improve the Service (or, in eBay’s case, to enable the marketplace link-out and affiliate attribution you initiate by tapping “View on eBay”), and do not constitute a “sale” or “share” as those terms are defined under the CCPA/CPRA (see Section 7.1).

6. Data Retention

We retain information for as long as reasonably necessary for the purposes described in this Policy:

  • Device identifiers, Watch criteria, and push tokens are retained for as long as your device/account remains active, and are deleted or anonymized after a period of prolonged inactivity or upon deletion request.
  • Scan photographs are retained only as long as needed to complete identification/valuation and to support your Scan history within the app; you may delete individual Scan results, which removes the associated photo from our active systems.
  • Account information (name, email) is retained until you delete your account, per Section 7.3.
  • Subscription/billing status is retained as needed to administer your Subscription and for reasonable recordkeeping/legal purposes after cancellation.
  • Backups and logs may persist for a limited additional period after deletion for security and disaster-recovery purposes, after which they are purged on a rolling basis.
Attorney note

Confirm and specify concrete retention periods (e.g., “device identifiers inactive for 24 months are purged”) once actual database TTL/cleanup jobs are implemented — the above is a policy commitment that engineering should be able to satisfy.

7. Your Privacy Rights

7.1 California residents (CCPA/CPRA)

If you are a California resident, you have the right to:

  • Know/access the categories and specific pieces of personal information we have collected about you, and the categories of sources, purposes, and third parties involved;
  • Delete personal information we have collected from you, subject to certain exceptions;
  • Correct inaccurate personal information;
  • Opt out of “sale” or “sharing” of personal information — as noted in Section 5, we do not sell or share personal information as defined by the CCPA/CPRA, so there is currently no sale/sharing to opt out of;
  • Limit use of sensitive personal information — we do not believe we collect “sensitive personal information” as defined by the CCPA/CPRA in the ordinary operation of the Service; and
  • Non-discrimination — we will not discriminate against you for exercising any of these rights.

To exercise these rights, contact us at [CONTACT EMAIL]. We may need to verify your identity before completing certain requests.

7.2 EEA/UK residents (GDPR/UK GDPR)

If you are located in the European Economic Area or United Kingdom, we process your personal data on the following legal bases, depending on the data at issue: performance of a contract (operating the Service and any Subscription you purchase), our legitimate interests (securing and improving the Service, preventing abuse), and consent (e.g., where required for push notifications or certain optional features).

You have the right to: access your personal data; rectify inaccurate data; erase your data; restrict or object to certain processing; request data portability; and lodge a complaint with your local data protection supervisory authority.

International transfers. Our infrastructure (Supabase, Vercel, and other processors listed in Section 4) is currently US-hosted. If you access the Service from outside the United States, your information will be transferred to, stored, and processed in the United States, which may not have data protection laws equivalent to those in your jurisdiction.

Attorney note

Confirm whether a GDPR transfer mechanism (e.g., Standard Contractual Clauses with each processor, or reliance on each processor’s own SCC/DPA framework — Supabase, Vercel, OpenAI, and Apple each publish their own) needs to be affirmatively documented here, and whether RareBlink needs an EU/UK representative under Art. 27 GDPR / UK GDPR given actual/expected EU user volume.

7.3 Account and data deletion

You may delete your account, and the personal data associated with it, at any time from within the app (Profile → Account → Delete Account), consistent with Apple App Store Guideline 5.1.1(v), which requires apps that support account creation to also offer in-app account and associated-data deletion. Deleting your account will delete your account information (name/email) and disassociate your device identifier, Watch history, and Scan history from your identity; some information may be retained as described in Section 6 or as required by law.

If you use the free/anonymous tier without an account, you may request deletion of your device-associated data by contacting us at [CONTACT EMAIL] with your device identifier (found in Profile → Settings), or by uninstalling the app, which stops further data collection from that device (though previously collected data tied to the anonymous identifier may persist per Section 6 unless you separately request deletion).

8. Children’s Privacy

The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13 (or any higher applicable minimum age under local law). RareBlink does not impose its own age gate; marketplace purchases are governed by eBay’s own 18+ account requirement and subscriptions by Apple’s age and family-account rules (see Terms of Service Section 2). If we learn that we have collected personal information from a child under the applicable minimum age without appropriate consent, we will delete it promptly. If you believe a child has provided us with personal information, contact us at [CONTACT EMAIL].

9. Push Notifications

Blink Alerts are delivered via push notification only if you enable them. You can:

  • decline or disable push notifications at any time through your device’s Settings (Settings → Notifications → RareBlink), or
  • adjust the alert sensitivity/threshold within the app (e.g., “All Blinks,” “Strong Blinks,” “Exceptional Only”) to control notification frequency.

Disabling push notifications does not affect your ability to browse Blinks within the app.

10. Data Security

We use commercially reasonable technical and organizational measures (including reliance on our processors’ own security practices — e.g., Supabase’s and Vercel’s infrastructure security, row-level access controls on our database) designed to protect information against unauthorized access, loss, misuse, or alteration. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.

11. Changes to This Policy

We may update this Policy from time to time. If we make material changes, we will provide notice (for example, through the app, by updating the “Last Updated” date above, or by email if you have an account). Your continued use of the Service after changes take effect constitutes acceptance of the revised Policy.

12. Contact Us

Questions or requests regarding this Privacy Policy, or to exercise any privacy rights described above, can be sent to:

Nickolas Parker, d/b/a RAREBLINK
[CONTACT EMAIL]


Attorney note

This draft assumes (a) US-only hosting with no EU/UK data-localization commitments, (b) no current use of third-party ad-tech/advertising SDKs, and (c) that CardSight’s and OpenAI’s processing agreements permit the “not used for advertising” representation in Section 2.4 — confirm current CardSight and OpenAI DPAs/terms actually support that language before publishing. Also confirm whether a standalone Cookie Policy/banner is needed for the rareblink.app/.com website (as opposed to the iOS app) if any web analytics or cookies are added there, and whether a formal CCPA “Do Not Sell/Share My Personal Information” link is required given actual data flows once EPN integration is finalized.

RAREBLINK

Marketplace intelligence for collectors. See it before it’s gone.

RareBlink Home Terms Privacy

Affiliate disclosure: RareBlink participates in the eBay Partner Network. When you open a listing through RareBlink and make a purchase, RareBlink may earn a commission — at no additional cost to you.

© 2026 RareBlinkrareblink.app