Privacy & data
Privacy policy
This policy explains what Mint TCG ("Mint", "we", "us") collects when you use the Mint mobile app or website, why we use it, who processes it, and the choices available to you.
Effective and last updated: August 3, 2026
- Card scans and motion-sensor readings are processed on your device, not uploaded.
- Cloud accounts sync the collection and wishlist information you choose to save.
- Mint does not sell personal information or use it for advertising.
- You can use core features as a guest and can delete a cloud account at any time.
1. Scope and contact
This policy covers the Mint mobile app, mint-tcg.com, and the services they connect to. Mint TCG is responsible for the information described here. For privacy questions or requests, email hello@mint-tcg.com.
2. Information we collect
Account and profile information
If you create an account, we receive an account identifier, email address, display name, and any profile photo supplied by your sign-in provider. You may optionally add a first name, last name, and date of birth. Authentication is provided by Firebase Authentication and, when you choose them, Google Sign-In or Sign in with Apple. Mint does not receive or store your Google or Apple password.
Collections and wishlist
For signed-in users who use cloud sync, we process collection names and display settings, card identifiers, quantities, card conditions, prices recorded when cards are added, collection value history, and wishlist entries such as target price, priority, and notes. Some additional card notes and scan state remain only in local app storage.
Usage analytics
We record first-party usage events to understand and improve Mint. These can include search queries, selected search results, cards and sets viewed, filters used, scan counts and results, collection and wishlist actions, and sign-in or sign-out method. Events include timestamps and relevant card or collection identifiers. Events from signed-in sessions may include your Mint user identifier; guest events do not.
Feedback and optional photos
When you send feedback, we collect the category and message, app version, platform, originating screen, and an optional screenshot or photo you select. Signed-in feedback may also include your user identifier and email address. An attached image can contain information visible in the image or embedded by your device, so review it before submitting.
Push notifications and technical information
If you allow push notifications, Firebase Cloud Messaging or Apple Push Notification service provides a device registration token. We associate that token and its platform with your account to deliver notifications. Our app, hosting, and service providers also receive standard technical information such as IP address, request path and time, app version, operating system, device or installation identifiers, language, time zone, and basic request or error details.
Crash and diagnostic reports
Mint uses Firebase Crashlytics to record crashes and unhandled errors so we can fix them. A report contains diagnostic data such as the exception type and stack trace, the app version and build, your device model and operating system version, and a Crashlytics installation identifier. When you are signed in, the report is associated with your user identifier so we can correlate a crash with a support request. Crash reports do not include your card images, and we do not use them for advertising.
Marketplace browsing and website use
If you choose to open Cardmarket inside Mint, the card or product you selected is included in the page URL. Cardmarket and its infrastructure providers can receive your IP address, browser information, requested pages, cookies, and other browsing data under their own privacy terms. The embedded browser can retain cookies and local website storage. The Mint website loads fonts from Google; Google and the website host receive ordinary web-request information when the page loads.
Information that stays on your device
Images used for normal card scanning and gallery identification are processed on your device and are not uploaded to Mint. Camera audio is disabled. Motion-sensor readings used for visual effects also remain on your device. A scan image leaves your device only if you separately choose to attach it to feedback. Local databases and preferences retain collection, scan, cache, and settings data until the app clears them, you remove the app, or your device or backup service removes them.
3. How we use information
We use the information above to:
- authenticate users and maintain profiles;
- sync collections and wishlists across devices;
- identify cards, provide pricing, and calculate collection values;
- deliver requested notifications and service messages;
- respond to feedback and support requests;
- measure feature use, troubleshoot, secure, and improve Mint;
- prevent abuse and comply with legal obligations.
Depending on where you live, we process information to provide the service you request, based on your consent, for our legitimate interests in operating and improving Mint, and to meet legal obligations. You may withdraw consent where processing relies on consent, without affecting earlier lawful processing.
5. Advertising and tracking
Mint does not show third-party advertising, sell personal information, or use personal information for cross-app advertising. Mint's own analytics are used to operate and improve the service, not to build an advertising profile. Third-party pages you intentionally open, including Cardmarket, may use cookies or similar technology under their own terms; review the choices presented on those pages.
6. Retention
- Account, collection, and wishlist data: retained while your account is active and deleted from active systems when account deletion completes.
- Analytics: retained as individual events for as long as reasonably needed to analyze and improve Mint. Account deletion permanently removes the user identifier from those events; event details that no longer identify your account may remain.
- Feedback: retained while needed to investigate, improve the service, maintain support records, and meet legal obligations. Uploaded feedback images in our storage are configured to expire after 180 days; copies delivered to our private Discord workspace may follow a different deletion schedule. You may ask us to remove identifiable feedback sooner.
- Push tokens: retained until deregistration, account deletion, or removal after the token becomes invalid.
- Logs and backups: retained for limited periods based on security, operational, legal, and service-provider backup schedules, then deleted or overwritten.
- On-device data: retained until cleared by the app or operating system, the app is removed, or a device backup expires.
We may retain information longer when required by law, needed to resolve a dispute, or necessary to protect the service. We may retain information that has been de-identified so it can no longer reasonably identify you.
7. Your choices and rights
- Use guest mode: core features can be used without creating a cloud account.
- Profile: signed-in users can edit or remove optional profile fields in the app.
- Notifications: control permission in device settings and sign out to deregister the current push token.
- Feedback: submitting a message or image is optional.
- Marketplace: opening Cardmarket is optional; you can manage its cookies through the choices shown on its pages.
- Account deletion: delete your account from the Profile screen or follow the instructions at mint-tcg.com/delete-account/.
Depending on your location, you may have rights to access, correct, delete, restrict, or receive a copy of personal information, or to object to certain processing. Email hello@mint-tcg.com from your account address. We may need to verify your identity before completing a request. You may also complain to your local data protection authority.
8. Security and international transfers
We use HTTPS in production, authenticated access controls, and service providers designed to protect information. No system is completely secure, and local app databases are protected by your device rather than separate app-level encryption. Service providers may process information in countries other than your own. Where required, we rely on recognized transfer mechanisms and provider safeguards.
9. Children
Mint is a general-audience collection utility and is not directed to children under 13. Children under 13 should not create an account or send personal information. If you believe a child has provided personal information without appropriate permission, contact us so we can review and delete it.
10. Changes to this policy
We may update this policy as Mint or legal requirements change. We will post the revised policy here, update the date above, and provide additional notice in the app when a change is material and notice is required.
Questions or privacy requests: hello@mint-tcg.com