Privacy Policy
Last updated: 23 September 2026
The short version
SphereDex has no ads and does not track you across apps or websites. Your collection is saved on your device unless you choose cloud sync. The Android scanner uses Google ML Kit: Google says the SDK sends limited device/app details and scanner performance and usage metrics to Google, but not the camera images or recognition results. We explain that below. SphereDex also receives the data needed for price lookups, push notifications, optional sync and messages you choose to send.
What is stored on your device
Your collection lives on your device (in your browser or app storage): the cards you own, wishlist and favourites, graded slabs, notes, decks, sealed products, settings, and the market prices you have looked up. You can export this to a file, or clear it at any time by clearing the app or browser data.
Optional account and cloud sync
If you choose to create an account to sync your collection across devices, we store on our server:
- Your email address and a securely hashed password. Your email is used to sign you in and, if you forget your password, to send you a one time reset code through our email provider (Resend).
- Your collection data (the same information listed above) and a few account settings, such as your market, currency, grading company and text size, so they sync between your devices.
This is entirely optional. If you never sign in, none of this is collected. You can delete your account and its synced data at any time from the Account page in the app using Delete account, or by contacting us using the details below.
Notifications
The iPhone and Android apps can send you push notifications about new sets, news, release dates, stock, card-price alerts, and (if you turn them on) a weekly collection recap, collection milestone, or wishlisted-card availability alert. To make this work, the app registers a push token for your device with our server. The Android app does this when it opens, and the iPhone app does it once you allow notifications. Along with the token we store:
- Your platform (iPhone or Android) and when the app last checked in.
- Your notification choices, including the sealed products you follow for stock alerts.
- Your chosen market, so alerts match your region.
- Only if you enable the weekly recap: one aggregate number of distinct cards added to your active collection in the last seven days. This count is refreshed with your push preferences, used to send the weekly push, and is not accompanied by card names, IDs, notes, deck contents or a collection snapshot.
- Only if you enable collection milestone alerts: the aggregate number of unique cards in your active collection, so the server can detect milestone thresholds. We do not send the card identities, names, notes or collection list for this feature. Turning it off deletes its per-device milestone records.
- Only if you enable wishlisted-card availability: the card IDs on your wishlist and your market, so the server can compare them with current eBay listings. A small per-device/card state records whether a verified listing was present, to detect when one appears. It is not linked to your account. Turning the option off removes this watch state during the next daily check; names and IDs are not included in the push message.
The token is not linked to your account or email address. Optional recap, milestone and availability alerts are off by default. Switching the weekly recap off stops future counts being included in push preferences. A small per-token/week send record prevents duplicate recaps and is deleted after 90 days. Turning milestone alerts off deletes their per-device milestone records; first-time opt-in establishes a baseline without sending past milestones. Turning availability off removes its per-device/card state on the next daily check. Notifications are delivered through Google Firebase Cloud Messaging (Android) and Apple Push Notification service (iPhone). The web app does not register a push token.
Sharing and visibility
Collections, wishlists, decks, notes, and account data are private by default. SphereDex currently has no public profile, public binder, or trade-list sharing feature. We will not expose synced collection data through a public link unless a future feature clearly identifies exactly what will be visible, requires a separate opt-in, supports revoking access, and excludes private notes and account details by default.
Contact form
If you send feedback through the app or the form on our roadmap page, we receive the topic, your message, and your email address if you choose to add one so we can reply. Messages sent from the app also include the app version and platform (web, iPhone or Android) so we can look into problems. It is delivered to us by email through our email provider (Resend) and is used only to respond to you.
Camera
In the iPhone and Android apps, SphereDex can use your camera to recognise a card, or the grading label on a slab. Camera frames are processed on your device and are not uploaded, stored or shared by SphereDex. The iPhone app uses Apple Vision on-device. The Android app uses Google ML Kit on-device; Google says ML Kit may send SDK diagnostics and usage metrics (such as device/app details, API events and performance measurements) to Google. Google says it uses those metrics to measure performance, debug, maintain and improve ML Kit, and detect misuse or abuse. They do not include the camera images or recognition results. See Google's ML Kit data disclosure for the current Android SDK details.
Prices and card data
To show market values, the app asks our server for prices using card names and numbers (plus the grade, for graded slabs) and the market you chose. When the app opens it may also send the numbers of the cards you own, so their last sold prices can be refreshed. Price lookups are not linked to your account. For market-quality planning, our server records the card number, market, source, price type and confidence, observed market/last/average values and currency, lookup outcome, whether it was a direct or background request, and (when available) the number of valid sales and the price difference from the previous result. These records are used to assess source coverage and lookup quality, not to build a profile; they are automatically deleted after 90 days and are not joined to your account or push token. To stop any one install using up the shared daily price lookups, the app makes a random tag for itself, keeps it on your device, and sends it only with price lookups. The server keeps a one way scrambled form of it for a day, then deletes it. It is tied to nothing else and is never used to identify you. Older versions of the app send no tag, and for those the server uses your IP address the same way. The app also tells the server which version it is running, so we can see how many people are on each build. That is a version number on its own, with nothing attached to it. Our server then asks eBay and our price providers (OpenWeb Ninja and Palworld Prices) for prices, without sending anything that identifies you. Buy links open the retailer's own website, where that retailer's privacy policy applies.
Service providers
We use a small number of companies to run SphereDex. Each one only gets what it needs for its job:
- Cloudflare runs our server and database (accounts, synced collections and notification tokens) and keeps short term request logs.
- GitHub Pages hosts this website and the web app.
- Resend sends password reset codes and delivers contact form messages to us.
- Google Firebase Cloud Messaging and Apple Push Notification service deliver notifications to Android and iPhone.
- eBay, OpenWeb Ninja and Palworld Prices supply price data. They receive card searches from our server, never your personal details.
- Google ML Kit recognises cards on your device in the Android app. Google says the SDK sends device/app details and API performance/utilisation metrics for diagnostics, analytics and abuse prevention. Camera images and recognition results stay on your device.
- The official Palworld card game website supplies the artwork for any card whose image is not yet built into the app, so your device loads that image from their site.
What we do not do
- No advertising and no ad networks.
- No SphereDex advertising analytics, behavioural profiling, or tracking across other apps or websites. The Android ML Kit scanner SDK sends its own limited diagnostics and API utilisation metrics to Google, as described above. The download and install counts we see come from the standard reports Apple and Google give every developer.
- No selling or sharing of your data with third parties for their own use.
Delete your SphereDex account
You can delete your SphereDex account and the data synced to it at any time.
- In the app: open the Account page, tap Delete account, then tap Yes, delete. This happens straight away.
- Without the app: email spheredex@thecraigescape.com from the address on your account and ask us to delete your SphereDex account. We will delete it and reply to confirm.
- What is deleted: your email address, your hashed password, any password reset code, and your synced collections and account settings.
- What is kept: nothing linked to your account. Your notification token is not linked to your account, so mention it in the same email if you also want it removed. Cards saved on your device stay until you clear the app or its data.
Data retention and deletion
Data on your device stays until you remove it (clear the app or browser storage, or export then delete). If you created an account, you can delete it and all of its synced data from our server at any time with Delete account on the Account page, or by contacting us. We keep a notification token until Google or Apple tell us it is no longer valid, which we only learn when we next send that device a notification. A device that is not being sent notifications, for example one with every notification turned off, may stay stored until then. Contact us if you want yours removed.
Children
SphereDex is not directed at children under 13 and does not knowingly collect their personal information.
Changes
If this policy changes, we will update the date at the top of this page.
Contact
Questions, or want your account data deleted? Use the feedback option inside the app, or email us at spheredex@thecraigescape.com.
SphereDex is a free, fan made tracker for the Palworld Trading Card Game. Card data and artwork are © Pocketpair / Bushiroad. SphereDex is not affiliated with or endorsed by Pocketpair or Bushiroad.