RRiviz WorksHome

Unbinder · Privacy

Unbinder Privacy Policy

How the Unbinder mobile app collects, uses, and protects your information. For the Riviz Works company website, see the company privacy policy.

Last updated: May 13, 2026

About this policy

This policy describes how Riviz Works ("we", "us") collects, uses, and shares personal data when you use the Unbinder mobile app and related services. Unbinder is a Pokémon trading card collection tracker.

For privacy questions about the Riviz Works company website, see the company privacy policy at /privacy. For Unbinder-specific questions, contact hello@rivizworks.com.

Who is the data controller

Riviz Works, established in the Netherlands.

Contact for privacy inquiries: hello@rivizworks.com.

Information we collect

Account data. Your email address (required for sign-up), an encrypted password if you use email-and-password sign-in, or an Apple ID identifier if you use Sign in with Apple. Optionally a display name if you set one. Account creation date.

Collection data. The cards, sealed products, binders, slots, prices, conditions, grading data, tags, and notes you add to your collection. Price history you track inside the app.

Card photos. Photos you take or upload to identify cards. These photos are sent to our AI image-embedding service in real time, processed into a numeric card fingerprint, and then discarded. We do not store the raw photos.

Usage analytics. Anonymous in-app events such as which screens you visit, which features you use, and errors you encounter, collected via PostHog (EU region). Analytics events do not contain the contents of your card collection.

Device and technical data. Device model, operating system, app version, language, time zone, and basic crash reports.

Affiliate link clicks. When you tap an affiliate link inside Unbinder (for example to eBay or Amazon), the destination platform may set cookies or tracking parameters to attribute the click for commission purposes. We receive aggregated commission reports only and no personal data from these clicks.

What we do not collect

We do not collect your real name, address, phone number, payment information, or government identification.

We do not access your camera, microphone, contacts, or location outside of what you explicitly allow for card photo capture.

We do not sell your personal data.

Sign-in methods

Unbinder supports email sign-in (one-time code or password) and Sign in with Apple on iOS. We do not currently use Google sign-in or other third-party sign-in providers.

How we use information

To operate the core app: store and sync your collection across your devices, identify cards you scan, show prices, and send transactional emails such as password resets.

To improve the product: anonymous analytics and crash reports help us understand which features are used and where the app is failing.

To prevent abuse: server logs and basic security telemetry help us detect and respond to misuse.

Legal basis (GDPR)

Contract. Processing necessary to provide your account and core app features.

Legitimate interest. Analytics, crash reports, security and abuse prevention, balanced against your privacy.

Consent. Optional features such as marketing emails are processed only if you opt in.

Third parties (subprocessors)

Unbinder relies on the following processors to operate. They process limited personal data on our behalf under standard data processing agreements.

Supabase — database, authentication, file storage. Region: Ireland (EU).

Fly.io — backend API hosting and the AI image-embedding service. Region: Amsterdam (EU).

PostHog — product analytics. Region: EU.

Resend — transactional email such as password reset. Region: Ireland (EU).

Apple — Sign in with Apple, if you choose to use it.

eBay Partner Network and Amazon Associates — affiliate-commission tracking when you tap affiliate links.

Cloudflare — DDoS and abuse protection on certain web endpoints.

Public Pokémon card data and price data are fetched from public sources (such as PokeTrace, tcgcsv, and Cardmarket) on our servers. These services do not receive any information about you.

Data sharing

We do not sell, rent, or trade your personal data.

We share data only with the processors listed above and only to the extent needed to provide the app.

We may disclose data if required by law, such as a valid court order or regulatory request.

International transfers

Most data stays within the European Union. Some processors (Apple, Cloudflare, eBay, Amazon) operate globally. Where personal data is transferred outside the EU, we rely on Standard Contractual Clauses approved by the European Commission.

Data retention

Active accounts. Data is retained while your account exists.

Deleted accounts. Account data is deleted within 30 days of your deletion request.

Analytics. PostHog events are retained for up to 12 months, then deleted.

Backups. Encrypted backups may persist up to 35 days after deletion.

Server logs. Retained for up to 30 days for security and abuse prevention.

Your rights

Under the GDPR and similar laws, you have the right to access the data we hold about you, correct inaccurate data, delete your account and personal data, export your data (data portability), object to certain processing, and lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).

To exercise any right, email hello@rivizworks.com. We respond within 30 days.

Account deletion

You can delete your account directly inside the app via Settings → Profile → Delete Account & All Data. Deletion removes your account and personal data within 30 days, except where retention is legally required.

If you cannot use the in-app option for any reason, email hello@rivizworks.com from the address tied to your account and we will process the deletion on your behalf.

Children

Unbinder is not directed to children under 13 and we do not knowingly collect personal data from children under 13. If you believe a child has provided us data, contact us and we will delete it.

Security

All network connections use HTTPS with TLS 1.2 or higher.

Passwords are hashed by Supabase Authentication. We never see plaintext passwords.

Database access is restricted via Supabase Row-Level Security so users only see their own data.

Backups are encrypted at rest.

We follow standard industry practices, though no system is fully immune to compromise.

Changes to this policy

We may update this policy as the app evolves. Material changes will be announced in the app or by email. The date below reflects the current version.

Contact

For privacy questions about Unbinder, email hello@rivizworks.com.

Please include enough detail for us to understand and respond to your request.