Overview
River AI TCG is a Pokémon TCG pricing, collection, and selling-inventory app. This Privacy Policy explains what information we collect when you use the River AI TCG mobile app, how we use it, and the choices you have. By using River AI TCG you agree to this policy.
This policy covers data and privacy. The prices, portfolio values, market-analysis "signals," and AI responses in the app are informational only and are not financial or investment advice — see Section 7 of our Terms of Service for that.
Three things are worth knowing up front, because they shape everything below:
- Card scanning happens entirely on your device. Camera images are never uploaded to us or to anyone else.
- Your collection is stored on our servers. If you subscribe to Pro, the collections, favorites, selling inventory, and portfolio history you build in the app are kept in our database so they survive a lost phone and stay consistent across your devices. An earlier version of this app stored that data only on-device; that is no longer how it works.
- The AI assistant sends your chat content to Google Gemini. River's answers are generated by the Google Gemini API, a service operated by Google. The app asks for your explicit permission before it sends anything to Google Gemini, and you can withdraw that permission at any time in Settings → Privacy. See Chat content below.
Information we collect
Account information
We use a third-party authentication provider for Sign in with Apple and Sign in with Google. When you create an account, that provider shares the following with us:
- Your email address
- Your name as provided by your OAuth provider
- Your avatar URL, if your provider supplies one
- A unique user identifier
We store these fields in our database and use them to identify you across sessions. We never see your password — that's handled by Apple or Google.
We also store your device's time zone, which the app sends when you sign in. We use it for one purpose: deciding when "today" ends for you, so your daily portfolio snapshot is taken at the right local boundary.
Subscription information
If you subscribe to River AI TCG Pro, the transaction is processed by the Apple App Store and managed by a third-party subscription-management service. We don't see or store your payment card. In connection with your subscription we store:
- A customer identifier that links your account to the subscription-management service
- Your Pro entitlement status and its expiry date
- The time we last verified that status
We verify your entitlement against the subscription-management service directly rather than trusting the app, so a claim from a modified client can't unlock paid features.
Your collection, selling inventory, and portfolio
This is the most significant category of personal data we hold, and it is stored on our servers. For Pro subscribers we store:
- Collections — the collections you create and every card or sealed product in them, including the exact variant, condition, grading company and grade, and how many copies you own
- Prices paid — the cost basis you optionally record for each copy
- Favorites — the products on your watchlists, and the lists themselves
- Selling inventory ("Vending") — items you list for sale, their groups, your asking prices, and for completed sales the sold price, the sale date, and the market value at the time of sale
- Portfolio history — a daily snapshot of your collection's total value, taken once per day in your local time zone
- A record of changes — when you add, remove, reconfigure, or reprice an item, we append an immutable entry recording what changed and the market values at that moment. This is what makes it possible to tell apart "your collection is worth more because the market moved" from "your collection is worth more because you bought something," without rewriting past snapshots
- Synchronization bookkeeping — a change log and a record of the operation IDs your device has sent, so an interrupted request is never applied twice
Taken together, this is a detailed financial record of what you own, what you paid, what you sold, and what it has all been worth over time. We treat it accordingly: it is tied to your account, it is never sold, and it is never shared with advertisers or data brokers. It is deleted immediately and permanently when you delete your account.
Your device also keeps a local copy of this data in an on-device database so the app can render instantly. That local copy is a cache; our servers are authoritative. The app requires an internet connection to work.
Card scanning
When you scan a card with the camera — a single card or a whole binder page — the recognition runs entirely on your device using a machine-learning model bundled inside the app. Camera frames, the photos taken during a scan, and any text read off a card by on-device OCR are processed locally and are never transmitted to our servers or to any third party. We do not receive, store, or see them. What leaves your device is at most the identifier of the card you chose to add to a collection.
Chat content
When you chat with the in-app AI assistant ("River"), the most recent messages in the conversation are sent to our backend, which forwards them to Google — specifically the Google Gemini API — to generate a response that is streamed back to you. Google is the only AI provider we use. We do not store your chat messages or conversation history on our servers after responding. Your conversation lives in the app on your device and is not backed up to us.
We ask first. Before the app sends anything to Google, it shows you an in-app disclosure naming Google as the recipient and listing exactly what is sent, and you must tap Agree & Continue to proceed. Nothing is transmitted to Google unless and until you do. You can withdraw that consent at any time under Settings → Privacy; withdrawing it stops all chat data leaving your device and disables River chat. The rest of the app — your collection, pricing, portfolio, and on-device card scanning — keeps working.
What Google Gemini receives. The text of your recent chat messages; and, only when your question is about your own inventory, the collection entries needed to answer it (card and set names, quantity, condition, grading company and grade, market value, and any price paid you recorded). Google Gemini does not receive your name, email address, avatar, account identifier, payment information, or any camera image.
The assistant can read your collection. When you ask River about your own inventory — "what are my most valuable cards," "how has my portfolio done this month," "which of my raw cards are worth grading" — it queries your stored collection, favorites, selling inventory, and portfolio history directly on our servers, using your authenticated identity. The relevant results become part of what is sent to Google to answer that question. The app no longer attaches a copy of your collection to every message; data is read only when a question calls for it.
The assistant can propose changes, but never makes them. River can prepare a proposal to add a card to a collection or watchlist, add an item to your selling inventory, set an asking price, or mark an item sold. Proposals are inert: nothing is written to your account until you confirm it yourself in the app.
Card images displayed in the app
The card artwork and product photos you see in the app are loaded directly from third-party image hosts operated by our market-data provider, rather than from our own servers. When your device loads one of these images, the hosting service receives your device's IP address and standard request information, as it would for any image on the internet. We don't control those hosts' logging; their own privacy policies apply.
Shared card links
If you share a card from the app, we generate a link on our domain that carries the card's name, the price and configuration you were viewing, and the card's image URL. That link is served by a third-party edge-network provider so that messaging apps can render a preview. Anyone you send the link to — and the messaging platform that unfurls it — can see those details. We don't attach your identity to a shared link, and we don't log who opened one. Only you decide whether to share.
Server logs and usage counters
Our backend writes operational logs. These may include request timestamps, endpoint paths, request identifiers, user identifiers, AI token-usage counts, the number of items in a request, and error stack traces. In production these logs go to our hosting provider's standard log stream. We do not currently use third-party log-aggregation, analytics, or error-tracking services.
We also keep a short-lived counter of your daily AI token usage to enforce fair-use limits. It expires automatically after 48 hours.
Information we do NOT collect
We've designed River AI TCG to minimize data collection. We do not:
- Run analytics, attribution, or tracking SDKs
- Collect your location, contacts, microphone audio, or photo library
- Upload camera images or anything else the scanner sees
- Track you across other apps or websites
- Use advertising identifiers, fingerprinting, or marketing cookies
- Store your chat messages or conversation history on our servers
- Collect the answers you give during onboarding — those stay in the app's memory and are discarded
Third-party services
River AI TCG relies on the following categories of providers. Each has its own privacy policy, which governs how they handle data we share with them:
- Clerk — authentication, for Sign in with Apple and Sign in with Google (privacy policy)
- Apple — the App Store, as payment processor (privacy policy)
- RevenueCat — subscription management and entitlement verification (privacy policy)
- Google — the Gemini API, which generates River's chat responses (privacy policy, API terms)
- A third-party market-data provider — pricing data aggregated from major TCG marketplaces, and the image hosts that serve card artwork
- A cloud hosting provider, where our servers and database run
- Cloudflare — the edge network that renders previews for shared card links (privacy policy)
- Expo — mobile app build and delivery infrastructure (privacy policy)
Protection by our providers. Each provider above is bound by a contract or by its published terms of service to process the data we send it only to deliver the service to us, to keep it confidential and secure, and not to sell it or repurpose it. We have satisfied ourselves that each provides privacy and security protections at least equivalent to those described in this policy, and we share the minimum data each one needs to do its job.
Card scanning is not in this list, because no third party is involved: the model runs on your device.
About AI training. We use Google's paid Gemini API. Under the Gemini API Additional Terms of Service for paid services, the content we send — your chat messages and any collection data read to answer your question — is processed only to generate a response for you and is not used to train or improve Google's models. Google may retain inputs transiently for abuse and safety monitoring as described in those terms. We do not send your identity alongside that content, and we will update this policy if our provider or configuration changes.
How we use your information
- To operate the app — sign you in, store and synchronize your collection, fetch pricing, run AI features
- To calculate your portfolio value and its history
- To decide which market prices to refresh — our background price updates only cover products someone actually holds in a collection or has actively listed for sale
- To process subscriptions and unlock entitlements
- To communicate with you about service issues, security, and material changes
- To prevent fraud, abuse, and Terms violations, and to enforce fair-use limits
Sharing and disclosure
We share information with the third-party services listed above to operate the Service. We may also disclose information when required by law, subpoena, or valid government request; when necessary to enforce our Terms or protect rights and safety; or in connection with a business transfer such as a merger, acquisition, or sale of assets. We do not sell your personal information.
Data retention and deletion
- Profile data — retained until you delete your account
- Collections, favorites, selling inventory, portfolio history, and the change record — retained until you delete your account. We keep them indefinitely, including if your Pro subscription lapses, so that resubscribing restores everything exactly as you left it
- Chat messages — never stored on our servers; discarded once the response is returned
- Camera images — never received by our servers
- Market prices and catalog data — these describe cards, not people. They are not personal data and are retained after account deletion
- Daily AI usage counters — expire after 48 hours
- Server logs — retained for operational purposes and rotated periodically
Deleting your account. Open Settings → Delete Account in the app. This immediately and permanently deletes your profile and every record we hold that belongs to you — collections, collection items, favorites and lists, selling groups and items including sales history, portfolio snapshots, the change record, and your synchronization state — along with your identity at our authentication provider. It cannot be undone, and we cannot recover it afterward. Deleting your account does not cancel your subscription: cancel that separately in your Apple ID subscription settings, or you will continue to be billed.
You can also email [email protected] to request deletion, and we'll process it within 30 days.
Your rights
Depending on where you live, you may have rights under GDPR, CCPA, or other privacy laws, including:
- The right to know what personal data we hold about you
- The right to correct inaccurate data
- The right to deletion ("right to be forgotten")
- The right to data portability
- The right to opt out of any "sale" of personal information (we don't sell)
- The right to withdraw consent where processing is based on consent
You can exercise deletion yourself at any time from Settings → Delete Account. For anything else — access, correction, or a copy of your collection data — email [email protected]. We'll verify your identity and respond within statutory timeframes.
Children's privacy
River AI TCG is not intended for children under 13 (or under 16 in the EU and UK). We do not knowingly collect data from anyone under those ages. If you believe a child has provided us information, contact us and we'll delete it promptly.
International users
River AI TCG is operated from the United States. If you use the Service from outside the US, your information will be transferred to and processed in the US. By using River AI TCG you consent to that transfer.
Security
All traffic between the app and our backend uses HTTPS/TLS. Authentication tokens are stored on-device in the iOS keychain. Our database is not exposed to the public internet. Access to paid features and to your synchronized data is verified server-side on every request, not assumed from the app. We use industry-standard practices, but no system is 100% secure — keep the OAuth account you use to sign in protected with a strong password and two-factor authentication.
Changes to this policy
We may update this policy as the Service evolves. Material changes will be posted in-app and on this page with a new "Last updated" date. Continued use after the change means you accept the updated policy.
Contact us
Questions about privacy? Email [email protected].