Skip to content
← Back to ZeroPop

Privacy Policy

Last updated: July 26, 2026

Overview

Hanlon Digital LLC ("we", "us", "our") operates ZeroPop, a trading card grading and collection management applications for iOS and Android and our website. This Privacy Policy explains what data we collect, how we use it, and your rights regarding that data.

By using ZeroPop, you agree to the collection and use of information as described in this policy.

Notice at Collection

This is the short version, given at or before the point we collect anything. The rest of this policy is the detail.

  • What we collect. Identifiers (an account ID, and an email address if you sign in with one), the photos of cards you scan, the card metadata and collection data you build, purchase and subscription records, anything you choose to publish on a public collector profile, limited device and connection information including your IP address, and product usage events.
  • Why. To run the app: sign you in, sync your collection, produce grade estimates, price cards, operate the optional social features, take payment, prevent fraud and abuse, and understand which parts of the product get used.
  • How long. For as long as your account exists, then erased when you delete it. Exceptions are listed under Data Retention below, and we list them rather than hiding behind "as long as necessary".
  • Do we sell or share it? We do not sell personal information for money. We do not run advertising and we do not disclose your data to anyone for cross context behavioral advertising. See Do Not Sell or Share for the control and for how we honor Global Privacy Control.
  • Sensitive personal information. We do not ask for it and we do not use or disclose any for purposes that require an opt-out right.

Data We Collect

  • Email address - provided optionally through Sign In with Apple. You may choose to hide your email.
  • User ID - a unique identifier created via Firebase Authentication to associate your account with your data.
  • Card images - photos you capture are uploaded to Amazon S3 (AWS, US East region) for cloud sync across your devices. To produce grade estimates, your card images are processed on our AWS infrastructure and sent to our third-party AI grading provider (Anthropic). Older app versions (before 1.5.2) still talk to our previous Google Firebase backend, so images from those versions are uploaded to Firebase Storage instead; that path is shrinking as people update, but it is still live and we would rather say so than pretend otherwise. For identification-only scans in the free Identify mode, your card images are uploaded and stored for your collection but are not sent to the AI grading provider; identification is performed from on-device text recognition matched against our card catalog providers. Card images are never used to serve ads and are never sold.
  • Card identity & scan text - the card name, set, number, year, and OCR text derived from your scans may be sent to pricing, catalog, and AI providers (Google Gemini, CardSight, JustTCG, Brave Search, and eBay) to identify the card, retrieve estimated market values, and power the Scout AI assistant. Your card images are not sent to these pricing/catalog providers.
  • Collection data - card metadata, grades, binder organization, and related information, stored in our Amazon RDS (PostgreSQL) database in the AWS US East region. App versions before 1.5.2 still write this to Google Cloud Firestore on our legacy backend.
  • Profile information - if you choose to create a public collector profile, the username (handle), display name, optional profile photo (avatar), and the cards, statistics, badges, and collection value you elect to showcase. You provide this information voluntarily and control what is published. See "Public Profiles & Social Features" below.
  • Social graph & activity - the accounts you follow and that follow you, accounts you block, reports you submit about other users or content, and the in-app notifications generated by these actions (for example, a notification that another collector followed you). This data is stored in our Amazon RDS database, and in Firestore for app versions still on the legacy backend.
  • Purchase history - subscription status, free trial eligibility, one-time Scan Pack purchases, and transaction records managed through RevenueCat.
  • Device attestation - Firebase App Check verifies that requests to our services originate from a genuine instance of ZeroPop, helping prevent fraud and abuse.
  • Referral & rewards data - if you use the Earn Free Scans program: your invite code, which invite code you redeemed, referral counts, streak check-ins, quest completions, and reward grants. To prevent abuse (such as one device redeeming multiple invites), redemptions and daily check-ins include a one-way hashed device identifier derived from Apple's identifier-for-vendor (or the Android app set ID). The hash cannot be reversed into your device identity and is used only for fraud prevention, never for advertising.
  • Product usage events - which screens and features you use inside ZeroPop, tied to a per-install identifier and, once you sign in, to your account ID. Examples: a scan started, a card graded, a paywall shown, a subscription purchased. These go to Amplitude. On the web this is switched off until you allow it if you are in the EU, EEA or UK, and it can be turned off anywhere from Settings. See Cookies & Browser Storage.
  • Device & connection information - the app or browser version, device or browser type, operating system, language, and the IP address your request arrives from. IP is used to route and secure the request, to block abuse, and by our analytics provider to derive an approximate location (roughly country level). We do not use it to build an advertising profile and we do not resolve it to a street address.
  • Web page views - on zeropop.app we record which of our own pages were viewed, using Vercel Web Analytics. It is aggregate, cookieless, and served from our own domain.

Data We Do NOT Collect

ZeroPop does not collect any of the following:

  • Precise location. We never request device location permission. Our analytics provider infers an approximate region from your IP address, which is not the same thing and is described above.
  • Contacts
  • Your browsing history on other sites. We do record which pages of our own site and app you use, which is the "Web page views" and "Product usage events" entries above, and nothing beyond our own properties.
  • Advertising identifiers, ad-click IDs, and cross-site tracking data. Our analytics SDK is capable of capturing marketing attribution parameters such as gclid and fbclid from the URL you land on; that capture is explicitly disabled in our configuration, and we removed the cookie it used to write.
  • Health data
  • Biometric data. We do not run face or person recognition on anything you upload.

How We Use Your Data

We use your data for app functionality and to improve ZeroPop:

  • Authentication - to sign you in and secure your account.
  • Cloud sync - to keep your collection and card images available across your devices.
  • Grading analysis - to process your card images through machine-learning and third-party AI models (currently Anthropic's Claude) and return grade estimates.
  • Pricing & identification - to identify your cards and retrieve estimated market values via third-party pricing and catalog providers.
  • Scout AI assistant - to answer your questions about your collection, grades, and prices using a third-party large language model (Pro and Ultra tiers).
  • Subscriptions & purchases - to manage your plan, scan-pack credits, and scan limits, and to process payments.
  • Social features - to operate optional public collector profiles, the follow/follower system, personalized following feeds, user search and discovery, follow and activity notifications, and the blocking and reporting tools used to keep the community safe.
  • Fraud prevention - to verify legitimate app usage via device attestation.
  • Product improvement - to improve the accuracy and quality of ZeroPop's grading algorithms, machine learning models, and features (see below).
  • Analytics - to count how the product is used so we can tell which features are worth building on and where people get stuck. This is the one use you can switch off without losing any functionality, and in the EEA and UK it does not start until you allow it.

We do not sell your data. We do not serve ads. We do not track you across apps or websites.

Use of Data for AI and Machine Learning

By using ZeroPop, you grant Hanlon Digital LLC a non-exclusive, worldwide, royalty-free, perpetual, irrevocable license to use, reproduce, modify, and create derivative works from the card images, card metadata, grading data, and associated content you submit through ZeroPop for the purpose of:

  • Training, developing, and improving machine learning models and artificial intelligence systems used in ZeroPop.
  • Improving grading accuracy, defect detection, centering analysis, card identification, and other automated features.
  • Expanding and improving ZeroPop's first-party card catalog and community features using aggregated, de-identified information derived from scans - for example, identifying that a scanned card belongs to a set, card, or variant not yet in our catalog.
  • Developing new product features and capabilities.
  • Conducting internal research and analysis to improve the service.

This license survives account deletion. Data used for AI/ML training may be retained in anonymized or aggregated form indefinitely, even after your account is deleted. Individual card images used in training datasets are not linked to your personal identity.

We will never sell your images or data to third parties for their own AI training purposes. This license is strictly for improving ZeroPop and its products.

Public Profiles & Social Features

ZeroPop includes optional social features that let collectors create public profiles, follow one another, and view a feed of cards graded by collectors they follow. These features are opt-in: you can use ZeroPop's scanning, grading, and collection tools without ever creating a public profile or following anyone. You only appear in the social experience after you choose a username and publish a profile.

What becomes visible to others

When you create a public profile, the following information is made publicly visible to other ZeroPop users (and, where surfaced on our website, to the public) and is discoverable through in-app user search:

  • Your username (handle) and display name
  • Your profile photo (avatar), if you upload one
  • Your subscription tier badge and any earned achievement badges
  • Aggregate collection statistics, such as your number of graded cards, your average grade, and the year you started collecting
  • Your follower and following counts
  • A "top card" and up to five showcase cards you select, including their images, names, and grades
  • Cards you grade may appear in the following feeds of collectors who follow you, and on the public Explore feed, as described in our Terms of Service

Collection value is private by default

Your estimated collection value (in USD) and per-card values are hidden from other users unless you turn on the "show value" setting. When that setting is off, value figures are not written to the public profile record. You can change this setting at any time.

Following, followers & notifications

When you follow another collector, that account is notified that you followed them, and your username, display name, avatar, and tier are shown in that notification. Following is public: follower and following lists are visible to others. When someone follows you, you receive an in-app notification. We use this information solely to operate the social features and do not use it for advertising.

Blocking & reporting

You can block any user, which hides your profile and cards from them and theirs from you, and automatically removes any follow relationship between you. You can also report a profile or piece of content for reasons such as harassment, impersonation, spam, or inappropriate content. Reports are sent to us for moderation review and include the reporting and reported account identifiers and the reason selected. Reports are confidential and are not shown to the user you report.

Your controls

  • Edit or unpublish - you can change your username, display name, avatar, and showcase, toggle whether your collection value is shown, or remove your public profile from within the app.
  • Stop participating - you can unfollow accounts, remove followers by blocking, and clear your showcase at any time.
  • Delete - deleting your account removes your public profile, username claim, follow relationships, and associated social data, subject to the retention periods below. Content that was already cached or displayed by other users or indexed by search engines may persist outside our control.

Because public profile information is, by design, visible to others, you should not include sensitive personal information in your username, display name, avatar, or showcase. We cannot control how other users view, copy, or redistribute information you choose to make public.

Cookies & Browser Storage

This is the complete list of what ZeroPop puts on your device through a web browser, and why. "Strictly necessary" means the site cannot do what you asked without it. "Optional" means it is analytics or a third-party embed, and it is the category the consent banner and the Settings controls govern.

NameWhat it isCategory
zp_trialAnti-fraud cookie for the free web trial grade, set by our API on api.zeropop.app. HttpOnly, Secure, SameSite=Lax, 400 day lifetime. It is set only when you press the button that submits a trial scan, never on a page view. It holds 128 bits of random data plus a signature and nothing else: no name, no email, no account ID. Its only job is to stop one browser claiming the free grade over and over.Strictly necessary
zp-consentYour accept or reject choice for analytics, 180 days. This is what stops us asking again.Strictly necessary
zp-privacyCountry (from the network edge) and whether your browser sent a Global Privacy Control signal, 1 day. It is how the page knows whether it must ask you before running analytics. It contains no identifier.Strictly necessary
NEXT_LOCALEThe language you picked, 1 year.Strictly necessary
_GRECAPTCHASet by Google reCAPTCHA, which powers Firebase App Check. App Check is what proves a sign-in request came from the real ZeroPop and not a script, and our sign-in is configured to reject requests without it. It loads when you are signing in or already have an account on this browser, not merely because you read a page.Strictly necessary (sign-in)
firebaseLocalStorageDb, firebase-installations-database, firebase-app-check-database, firebase-heartbeat-databaseIndexedDB databases created by the Firebase SDK: your signed-in session, a Firebase Installation ID, the App Check token, and SDK usage heartbeats. The Installation ID is a persistent per-browser identifier created by Firebase. Same trigger as above: signing in, or already having an account on this browser.Strictly necessary (sign-in)
zp-has-account, zp-onboarded, zp-collector-profile, zp-collecting-years, zp-trial, zp_hunt_collected, zp_device_hash, zp-whats-new-seen, zp-growth-card-dismissed, zp-signup-slidein-dismissed-at, zp_android_banner_dismissed, themelocalStorage entries the app uses to remember your state on this browser: that you have an account here, that you finished onboarding, your onboarding answers, an in-progress trial scan, cards you marked as collected, a random per-browser value used to stop one device redeeming many invites, which banners you dismissed, and your light or dark theme. They stay on your device and are not analytics.Strictly necessary
zp-return-to, zp-signup-slidein-shown, zp_grade_reveal_upsellsessionStorage, cleared when you close the tab: where to send you back to after sign-in, and which one-time prompts you have already seen this session.Strictly necessary
AMP_*, zp_evt_*Amplitude analytics identity (a per-browser device ID and session state) and the flags that stop a one-time milestone event firing twice. These are localStorage entries, not cookies. We deliberately configured Amplitude to use localStorage instead of its default cookie, and we delete the analytics cookies its earlier configuration left behind. Nothing here is written unless analytics is allowed.Optional (analytics)
Vercel Web AnalyticsAggregate page-view counting served from our own domain. It sets no cookie and stores nothing on your device, but it is still analytics, so it is gated by the same choice.Optional (analytics)
TikTok embedOur homepage shows TikTok videos. The TikTok player is not loaded at all until you scroll it into view; once loaded, TikTok sets its own cookies and storage under its own policy, which we do not control.Third party
StripeLoaded only on the web checkout, by our payments provider RevenueCat. Stripe sets its own cookies for payment fraud prevention under its own policy.Strictly necessary (payment)

The iOS and Android apps do not use cookies. They store the equivalent state on the device and hold your session in the system keychain or its Android equivalent.

Third-Party Services

ZeroPop uses the following third-party services to operate. The second column says what each one actually receives.

ServicePurposePrivacy Policy
Firebase AuthenticationUser sign-in and identity. Receives your email address or Apple/Google identity token, your account ID, and sign-in metadata such as IP and timestamp.firebase.google.com
Firebase Firestore (legacy)Collection data and card metadata for app versions before 1.5.2, which still run on our previous backend. Current versions use Amazon RDS instead.firebase.google.com
Firebase Storage (legacy)Card images uploaded by app versions before 1.5.2. Current versions upload to Amazon S3 instead.firebase.google.com
Google Cloud (legacy)Hosts the legacy backend that still serves app versions before 1.5.2, including their grading requests. Receives card images and card metadata from those versions.cloud.google.com
RevenueCatSubscription and purchase management. Receives your account ID, the store receipt or transaction, your plan and its status, and (for web purchases) hands the payment itself to Stripe.revenuecat.com
Firebase App CheckDevice attestation & fraud preventionfirebase.google.com
eBay Browse APIMarketplace data, active listings, sold-comparable aggregates & historical pricingebay.com
Anthropic (Claude)AI grade analysis & Scout AI assistantanthropic.com
Google Gemini APICard identification & pricing query constructionpolicies.google.com
CardSightSports-card identification & market pricingcardsight.ai
JustTCGTrading-card game market pricingjusttcg.com
Brave SearchMarket-price lookups (fallback)brave.com
Amazon Web ServicesOur current backend. S3 stores your card images, RDS (PostgreSQL) stores your account, collection, grades, quota and social data, and our API and grading worker run on AWS compute in the US East region. AWS receives whatever you store with us plus the network metadata of your requests, including your IP address.aws.amazon.com
AmplitudeProduct analytics. Receives usage events (screens opened, scans started, cards graded, paywalls shown, purchases), a per-install device identifier, your account ID once you sign in, your subscription tier, app version and platform, and your IP address, which it uses to derive an approximate location. It does not receive your card images. Marketing attribution capture is disabled in our configuration.amplitude.com
VercelHosts zeropop.app and web.zeropop.app, and provides the aggregate Web Analytics page counts. As the host it processes every request to the site, including IP address and user agent.vercel.com
StripePayment processing for web purchases, loaded by our RevenueCat integration. Receives your payment details directly (we never see or store a card number), the amount, and fraud-prevention signals from the checkout page.stripe.com

Card Catalog & Pricing Data

ZeroPop maintains its own first-party card catalog - card names, set names, numbers, and rarities - compiled from publicly available sources, including manufacturer-published checklists (for example, checklists that trading card publishers post on their own websites) and other public reference sources. This catalog is built independently of any individual user's scans, images, or account information and contains no personal data.

Much of ZeroPop's card catalog is refreshed automatically on a recurring basis (typically daily) to add newly released sets and cards. Some catalog sources are added or updated manually and less frequently rather than on an automated schedule.

Market pricing shown in ZeroPop comes from the third-party pricing and catalog providers listed above (CardSight, JustTCG, and eBay, with Google Gemini and Brave Search used for card identification and pricing queries). Pricing data retrieved from these providers is cached on our servers for a period of time to reduce repeated lookups and improve app performance; cached pricing may not reflect the most current market conditions.

Data Retention

We would rather describe what the software actually does than quote a schedule that sounds reassuring. So:

  • Your data is retained for as long as your account exists.
  • Deleting your account happens immediately, not on a timer. When you delete from Settings, the request runs straight away: your card images are removed from our storage, your rows are deleted from our database, and your sign-in credential is deleted. Your public profile, username claim, showcase, follows and followers go with it. If any one of those steps fails, the deletion request is recorded on our side so it can be completed rather than silently dropped, and you can email us if anything looks like it survived.
  • Deleted data can still exist for a while in routine encrypted infrastructure backups, until those backups age out on their normal rotation. We do not mine backups, and restoring one is a disaster-recovery action, not a routine one.
  • Some records deliberately outlive the account, because deleting them would break abuse prevention or accounting: the strike record attached to a banned device (with the account ID removed from it), reports submitted about other users, records that a free trial was already claimed from a given browser, and purchase transaction records. These are kept for safety, moderation, fraud prevention and legal or tax compliance.
  • A banned account is not deleted automatically.We keep the ban so the ban means something. If your account is banned and you want it erased, ask us and we will erase it, keeping only the anonymized abuse record described above.
  • Our AI grading provider (Anthropic) and Google may retain card images and request data submitted for grading or AI-assistant features for a limited period in accordance with their data processing policies. Card identity sent to pricing and catalog providers (CardSight, JustTCG, Brave, eBay) is retained per those providers' policies. We do not control, and are not responsible for, third-party providers' retention or use of data under their own terms.

International Data Transfers

ZeroPop is operated from the United States and your data is processed there. Specifically: our current backend runs on Amazon Web Services in the US East region (S3 for card images, RDS for your account and collection); sign-in runs on Google Firebase; the legacy backend that still serves older app versions runs on Google Cloud in the US; the website is hosted by Vercel; subscriptions run through RevenueCat and, for web purchases, Stripe; grading and the Scout assistant call Anthropic; analytics go to Amplitude. All are US-based or US-processing.

If you are in the EEA, the UK or Switzerland, that means your data is transferred out of your region. We rely on the Standard Contractual Clauses (and the UK Addendum where it applies) offered by these providers in their data processing terms as the transfer mechanism. Some of them are also certified under the EU-US Data Privacy Framework. We are a small company and we do not negotiate bespoke terms with these providers; we rely on the standard ones they publish, and we would rather tell you that plainly.

Your California Privacy Rights (CCPA)

If you are a California resident, you have the following rights under the California Consumer Privacy Act:

  • Right to know - request what personal information we have collected about you.
  • Right to delete - request deletion of your personal information.
  • Right to correct - request correction of inaccurate personal information.
  • Right to non-discrimination - we will not discriminate against you for exercising your rights.
  • Right to opt out of sale or sharing - see the next section.
  • Right to limit use of sensitive personal information - we do not collect sensitive personal information for any purpose that triggers this right, so there is nothing to limit.

We will respond to verified requests within 45 days. To exercise your rights, contact us at support@zeropop.zendesk.com. You may use an authorized agent; we will ask for proof that you authorized them.

These rights are written into California law, but we apply them to everyone who asks, wherever you live. It is less work than maintaining two standards.

Do Not Sell or Share My Personal Information

Two different words, and we should answer both rather than answering the easy one.

Sale. We do not sell your personal information. No one pays us for it and we do not trade it for anything of value.

Sharing. Under California law "sharing" has a specific meaning: disclosing personal information for cross context behavioral advertising, which is advertising to you on somebody else's site based on what you did on ours. We do not do that. We run no advertising, we have no ad-network pixels or tags on this site or in the apps, and we do not build audiences for advertisers. Our analytics SDK is capable of capturing ad-click identifiers from your landing URL; we have that turned off, and we delete the cookie an earlier configuration of ours used to write.

We are not going to hide behind that answer, though. Analytics is the only thing we run that anyone could reasonably argue about, so we treat opting out of analytics as the opt-out:

  • In the app or on the web - open Settings and turn Product analytics off. It takes effect immediately in that browser and nothing further is collected.
  • Global Privacy Control - if your browser or an extension sends a GPC signal, we treat it as an opt-out automatically, everywhere, not just in California or the EU. You do not have to tell us twice, and we read it both from the request header and from the browser API. If GPC is on, the analytics switch shows as off and stays off.
  • By email - write to support@zeropop.zendesk.com and we will apply it to your account.

We do not have a "financial incentive" program, so nothing about your plan or price changes if you opt out.

Your European Privacy Rights (GDPR)

If you are located in the European Economic Area (EEA) or the United Kingdom, we process your data under the following legal bases:

  • Performance of a contract - to provide ZeroPop's core services (authentication, cloud sync, grading).
  • Consent - where you have given explicit consent, such as providing your email address.
  • Legitimate interest - fraud prevention and service security, including device attestation, the anti-fraud trial cookie, and abuse and ban enforcement. Our interest is in keeping a free scan from being farmed at our expense; the processing is limited to random identifiers and one-way hashes rather than anything about you.
  • Consent - product analytics. In the EEA and the UK, Amplitude and Vercel Web Analytics do not run at all until you accept, and the analytics identifiers are not written to your browser until then. You can withdraw consent at any time from Settings, and withdrawing is as easy as giving it. We do not claim legitimate interest for analytics.
  • Legal obligation - keeping transaction and tax records.

Your Rights

  • Access - request a copy of your personal data.
  • Rectification - request correction of inaccurate data.
  • Erasure - request deletion of your data.
  • Portability - receive your data in a machine-readable format.
  • Object - object to processing based on legitimate interest.
  • Complaint - lodge a complaint with your local data protection authority.

Automated Decision-Making

ZeroPop uses automated analysis to produce card grade estimates. These grades are advisory in nature and carry no legal effect. They do not constitute professional grading opinions and should not be the sole basis for financial decisions. You are not subject to decisions with legal or similarly significant effects based solely on automated processing.

EU and UK Representative

Hanlon Digital LLC is established in the United States. Where Article 27 of the GDPR (and its UK equivalent) requires a controller outside the region to appoint a local representative, one must be named here.

We have not appointed a representative yet. This is a known gap, not an oversight we are hiding. Until one is named, send anything you would send to a representative directly to support@zeropop.zendesk.com, and we will handle it ourselves on the same timelines. You can also complain to your national data protection authority at any time, whether or not you contact us first.

Children's Privacy

ZeroPop is not intended for use by children under the age of 13. We do not knowingly collect personal information from children under 13. If we learn that we have collected data from a child under 13, we will delete that information promptly. If you believe a child under 13 has provided us with personal data, please contact us at support@zeropop.zendesk.com.

ZeroPop's social features - public profiles, following, feeds, and user search - make certain information publicly visible to other users. If you are between 13 and 18, you should use these features only with the involvement of a parent or guardian, and you should not publish a profile photo or other personal details that could identify you to strangers. We encourage parents and guardians to review the social features and the available privacy controls (including the option not to create a public profile and to keep collection value hidden) with younger collectors. If we learn that a user is ineligible to use these features, we may remove the relevant profile or content.

Your Rights & Choices

  • Use without an account - you may use ZeroPop's on-device scanning features without creating an account.
  • Use without a public profile - the social features are optional. You can manage, hide, or remove your public profile and control what it displays from the app's profile settings at any time.
  • Delete your account - you can delete your account at any time from the app's settings, and the deletion runs immediately. See Data Retention above for exactly what goes and what stays. Deleting your ZeroPop account does not cancel a subscription you bought through Apple, Google or the web: only the store can do that, so cancel there first or you will keep being billed for an account that no longer exists.
  • Export your collection - export your collection as a CSV file at any time from within the app.
  • Request a data copy - email us and we will send you a copy of the personal data we hold about you. We do this by hand today, so allow us the 30 days the law gives us rather than expecting an instant download.
  • Turn analytics off - Settings has a Product analytics switch, and we honor Global Privacy Control automatically. See Do Not Sell or Share.

Changes to This Policy

We may update this Privacy Policy from time to time. When we make changes, we will update the "Last updated" date at the top of this page and notify you through the app or by email if the changes are significant. Your continued use of ZeroPop after changes are posted constitutes acceptance of the updated policy.

Contact Us

If you have questions about this Privacy Policy or your data, contact us at:

support@zeropop.zendesk.com
Hanlon Digital LLC
United States