Privacy Policy

Effective Date: June 14, 2026

Last updated: July 7, 2026

1. Information We Collect

We collect information you provide directly and information generated by your use of the Service:

  • Account data: email address, display name, and a bcrypt password hash. We never store plaintext passwords. Authentication uses a custom session cookie (grail_user_id).
  • Collection & watchlist data: card titles, images, acquisition prices, AI scores, and P&L entries you create within the platform.
  • eBay account data: OAuth access token, refresh token (encrypted at rest), and watchlist items synced from eBay when you connect your account.
  • Usage data: scan history, search queries, feature interactions, and session timestamps — used for quota enforcement and service improvement.
  • Payment data: billing plan and subscription status are stored by us. Credit card details are processed exclusively by Stripe and are never stored on AgentGrail servers.
  • Card image data: when you scan a card, the card image (as base64 bytes) may be transmitted to Anthropic's API for AI-powered card identification and grading. See §5 for details.
  • Technical data: IP address, browser type, device identifiers, and server logs — retained for up to 30 days for security and debugging.

2. How We Use Your Information

We use your information to:

  • Provide and improve the AgentGrail Service, including AI card analysis, deal detection, P&L tracking, and personalized recommendations.
  • Enforce scan quotas and plan limits associated with your subscription.
  • Send transactional emails (account verification, billing receipts, price alerts, weekly digests) based on your notification preferences.
  • Detect and prevent fraud, abuse, and security incidents.
  • Improve our AI models using aggregated, anonymized scan data.
  • Comply with legal obligations.

We do not sell your personal data to third parties. We do not use your data for targeted advertising.

3. Data Storage & Security

Your data is stored in a PostgreSQL database hosted on Railway (US region). Card images submitted for AI analysis are stored in Cloudflare R2 (US region) in a permanent, content-addressed cache so repeat scans of the same image return instantly and so the image can back your scan history and collection entries. Scanned images may also be added, with anonymized metadata, to our AI training corpus to improve grading accuracy — you can opt out of training use at any time from Settings > Training, and opting out does not affect your scan results. eBay OAuth tokens are encrypted at rest using AES-256. We use TLS 1.2+ for all data in transit. Despite these safeguards, no system is perfectly secure — we encourage you to use a strong, unique password for your account.

4. Data Retention

We retain your personal data for as long as your account is active. When you delete your account:

  • Soft delete: your account is immediately deactivated and all personal identifiers (name, email, eBay tokens) are removed within 30 days.
  • Anonymized retention: aggregate scan statistics and AI training labels (stripped of personal identifiers) may be retained indefinitely to improve the Service.
  • Legal hold: certain records may be retained longer if required by law or ongoing disputes.

5. Third-Party Services

We integrate with the following third-party sub-processors, each of which has its own privacy policy:

  • eBay — marketplace data and watchlist sync (developer.ebay.com)
  • Stripe — payment processing (stripe.com/privacy)
  • Resend — transactional email delivery (resend.com/privacy)
  • Railway — web hosting and database (railway.app/privacy)
  • Cloudflare — CDN, image delivery (images.agentgrail.ai), and R2 object storage (cloudflare.com/privacypolicy)
  • Anthropic — AI card identification and grading. When you scan a card, the card image (base64 bytes) may be transmitted to Anthropic's API for vision-based analysis. Anthropic does not use API inputs to train models by default. See Anthropic's privacy policy at anthropic.com/legal/privacy.
  • PostHog — product analytics (error tracking, feature usage). PostHog collects anonymized usage events with your consent, governed by our consent banner. See posthog.com/privacy.
  • CardSight — sports card catalog and pricing data (used for market comps).

6. AgentGrail Chrome Extension

The AgentGrail Card Classifier browser extension has a single purpose: AI-grading sports cards you are viewing. This section describes exactly what it collects and when.

  • Collection is scan-initiated only. The extension collects data solely when you explicitly run a scan (right-click “Classify Card”, the popup, or “Scan All”). It does not passively read, collect, or transmit anything from pages you browse, and it does not collect your browsing history.
  • What a scan sends: the card image you selected (its URL, or the image bytes when the source site restricts access) and, on supported marketplaces, listing details visible on the page — title, player, set, year, grade, price, and the marketplace item ID.
  • How scan data is used: to return your grading result, enforce your plan’s scan quota, power the shared scan cache (the result for a public listing — never your identity — is shown to other users who scan the same listing), and improve our AI models (opt out from Settings > Training, see §3).
  • Authentication: the extension authenticates with your AgentGrail account token; scans are recorded to your account exactly like scans made on the website.
  • Limited Use: our use of data collected by the extension complies with the Chrome Web Store User Data Policy, including the Limited Use requirements. Extension data is used only for the single purpose above and is never sold, transferred for advertising, or used for creditworthiness determinations.
  • Changes: if the extension’s data practices ever change, we will disclose the change prominently before it takes effect, in addition to updating this policy.

7. Cookies

We use cookies and similar technologies. Here is what is currently in use:

  • Authentication cookie (essential): our custom session system sets a cookie named grail_user_id required to keep you logged in. This cookie is strictly necessary for the Service to function and cannot be disabled.
  • Analytics (PostHog): we use PostHog for product analytics and error tracking. A consent banner is displayed on first visit; analytics are only activated after you accept. You may withdraw consent at any time from Account > Privacy. PostHog cookies are non-essential and are not set without your consent.

8. Your Rights

Depending on where you are located, you may have the following rights regarding your personal data:

  • Right of access (GDPR Art. 15): request a copy of the personal data we hold about you.
  • Right to rectification (GDPR Art. 16): request correction of inaccurate data from the Account settings page.
  • Right to erasure / Right to be forgotten (GDPR Art. 17): request deletion of your account and all associated personal data. You can initiate this directly from Account > Settings > Delete Account. We will complete the deletion within 30 days and confirm by email.
  • Right to data portability (GDPR Art. 20): export your collection, watchlist, and scan history from Account > Settings > Export Data.
  • Right to object / opt out: you may opt out of non-essential communications (digest emails, price alerts) at any time from Account > Notifications.
  • California residents (CCPA / CPRA): you have the right to know what personal information is collected and to opt out of the sale or sharing of personal information. We do not sell or share your personal information — we have no targeted-advertising program, no data-broker relationships, and no cross-context behavioral advertising. Our PostHog analytics are consent-gated and do not constitute “sharing” under CPRA. If you have questions or wish to exercise California rights, contact [email protected].

To exercise any of these rights, contact us at [email protected]. We will respond within 30 days.

9. Children’s Privacy

AgentGrail is not directed to children under the age of 18. We do not knowingly collect personal information from minors. If you believe a child has provided us with personal information, please contact us and we will delete it promptly.

10. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will revise the “Last updated” date above. For material changes, we will notify you via email at least 7 days before the change takes effect.

11. Contact

For privacy questions, data requests, or concerns, contact us at [email protected].