This Privacy Policy describes how moonstone (moonstonehq.com), operated from California, USA, handles information when you use the service.
What we collect
Account information: an email address and a password (stored as a salted hash that we cannot read). If you sign in with Google instead, we receive and store the email address, the name on your Google profile, and the URL of your profile picture. Portfolio data: the cards and products you add, with quantities, printings, and optional purchase prices. Scan images: photos you submit to the scanner on this website are processed to identify cards, and some are kept for a limited period to improve accuracy, described under “Scan data” below. Photos sent to the paid Scan API are processed and not kept. Developer account data: if you use the Scan API, we store a hash of each API key, the name you give it, and per-period call counts, which are usage records tied to your account rather than to any individual call. Technical data: standard server logs (IP address, user agent, timestamps) for security and reliability, a short-lived record of your IP address used to rate-limit sign-up, sign-in and password-reset attempts, and session cookies to keep you signed in.
We do not sell personal information, and we do not use third-party advertising trackers.
Scan data
This section is about the scanner on this website. Card photos are processed to produce an identification. When a scan comes back uncertain, and when you confirm or correct a result, we keep a copy of that photo together with recognition metadata (which card was matched, the confidence, and what you chose) so we can improve the scanner. Some of these are kept automatically, without you tapping anything, because a scan the model got wrong is the one we most need to learn from. These records are stored without your account identifier and are deleted after 180 days.
Photographs sent to the paid Scan API are handled differently and are not kept. They are processed to produce the response and are not written to storage, do not enter the corpus described above, and cannot be retrieved afterwards. What we do record about an API call is the usage count that meters your plan, not the image. While the call is running the image is passed to the same third-party processors listed below, because the API and the website scanner run on one recognition pipeline.
Service providers who process your data
Running moonstone means passing some of your data to companies that perform a specific job for us. Each is bound by its own contractual obligations, none of them is a data broker or an advertiser, and none is permitted to use your data for its own purposes. The current list, which can change as providers do:
Hosting and delivery: Vercel (application hosting) and Turso (database). Payments: Stripe, which receives your email address and handles your card details directly. We never see or store a card number.
Card photographs you upload to the scanner, send to the assistant, or submit to the Scan API are transmitted to Google Cloud Vision for text recognition, to a GPU service we run on Modal for image analysis, and to Anthropic and to models reached through OpenRouter (which routes to whichever model answers first, and can include models hosted by Google, NVIDIA, Meta or MiniMax) for reading and describing the card. Questions you type to the assistant are transmitted to those same model providers together with the market data needed to answer them. Do not upload a photograph, or type anything into the assistant, that you would not want processed by those providers.
Email: the transactional messages we send, such as a password reset, are delivered by an email service provider that receives your address and the content of that message.
We use first-party analytics we run ourselves rather than a third-party service. It records the page visited, the referring site, an approximate country, and a UTM tag when one is present. It does not record your IP address, does not set an advertising cookie and does not follow you across other sites.
How we use information
To provide the service (accounts, portfolios, pricing), to secure it (rate limiting, abuse prevention), to improve it (aggregate usage patterns, scanner accuracy), and to communicate service matters. We do not sell personal information to data brokers or advertisers, and we do not use advertising trackers.
California privacy rights (CCPA/CPRA)
If you are a California resident, you have the right to know what personal information we collect and how it is used (this policy), to request access to or deletion of your personal information, to correct inaccurate information, and to not be discriminated against for exercising these rights. We do not sell or share personal information as those terms are defined by the CCPA/CPRA, and we do not use or disclose sensitive personal information for purposes requiring a right to limit.
To exercise any right, contact us at the email below; we will verify your request via your account email and respond within the statutory window.
Retention and security
Account and portfolio data are retained while your account exists. You can delete the account yourself at any time, which removes your profile, portfolio, watchlist, API keys and usage records; cancel any subscription first, because deleting the account here does not stop a charge that lives at Stripe. We use industry-standard measures (encrypted transport, hashed credentials, scoped access) but no system is perfectly secure; use a unique password.
moonstone is not directed to children under 13, and we do not knowingly collect their personal information.
Contact
Privacy requests and questions: privacy@moonstonehq.com. We may update this policy; material changes will be reflected by the “Last updated” date.