← Back to Sabrina

Privacy Policy

Last updated: July 29, 2026

1. Information We Collect

When you create an account, we collect your email address and display name. When you use Sabrina, we store data you provide including card inventory, purchase records, sales records, grading submissions, and expense entries. We also collect basic usage analytics to improve the app.

2. How We Use Your Information

We use your information to:

  • Provide and maintain the Sabrina service
  • Calculate portfolio values, cost basis, and tax summaries
  • Display market prices from third-party pricing sources
  • Send essential account notifications
  • Improve our product and fix bugs

3. Data Storage and Security

Your records - inventory, purchases, sales, grading submissions, expenses - are stored in a Supabase Postgres database protected by row-level security, so a query can only return rows that belong to your account. All traffic between you and Sabrina is encrypted over HTTPS.

Images you upload - photos of your own cards and your profile picture - work differently, and it's worth being precise: they are stored as files, and row-level security covers database rows, not files. A photo's address is not checked against your login, so anyone who has that exact link can open the image without signing in. Treat a photo link like a photo you've handed someone. New uploads are saved at a long random address that contains nothing about you beyond an internal account id. Images uploaded before July 2026 sit at a more predictable address; if that matters to you, remove the photo and upload it again and it will move to a random one.

Deleting removes the file, not just the record: that holds whether you remove a photo from a card, delete the card itself, reset your portfolio, or delete your account.

We do not sell, rent, or share your personal data with third parties for marketing purposes.

4. Third-Party Services

Sabrina relies on the following third-party services. The first group receives data from your account; the second group we only read reference data from, and gets nothing about you.

Services that receive your data

  • Supabase - authentication, database, and file storage for everything in your account
  • Anthropic - the AI model behind Sabrina chat. When you send a message we pass the conversation, whatever portfolio context the question needs (holdings, cost basis, sales, recent activity), and any file or photo you attach - a spreadsheet you're importing, a photo of a card - to Anthropic's API to generate the reply. Card recognition uses the same API: when you scan cards with your camera, the photo is sent to Anthropic to identify what's in the frame.
  • Stripe - subscription payments on the web (we never see or store your card details)
  • Apple - subscription purchases made inside the iOS app. Apple processes the payment and sends us a signed receipt we verify; we never see your payment details.
  • Vercel - web application hosting, plus cookieless page-view and performance metrics

Reference sources we read from

  • PriceCharting - market and graded card prices. We send a card identifier and our own API key, never anything about you or what you own.
  • TCGplayer - the card and sealed product catalog and its prices, read through the public tcgcsv.com mirror, plus card images served from TCGplayer's image CDN
  • Pokemon TCG API - card reference data and images
  • Scrydex - card art for sets the other image sources haven't published yet. It is an image source only - no account, portfolio, or usage data is sent to them.
  • PSA - when you enter or scan a PSA certification number, we send that number to PSA's public certificate API to read back the grade, card details, and population figures, and we cache the result for 30 days. We send only the certification number, which is printed on the slab itself - never your name, account, or anything else you own.

5. Where Your Data Lives, and How Long

Your account and records are stored in the United States (Supabase, US East). Card photos are stored in the same account's file storage. If you use Sabrina from outside the US, your data is transferred to and processed in the US.

We keep your records for as long as your account exists, because the whole point of the product is a running history - cost basis, grading round-trips, and year-end tax summaries all depend on records that may be years old. We do not auto-delete old entries.

When you delete something, it goes. Resetting your portfolio removes every asset, transaction, grading submission, and photo. Deleting your account does that and also cancels any subscription and removes your login. Neither is recoverable, and neither leaves a copy behind for us.

6. Your Rights

Most of these you can exercise yourself, immediately, without asking us:

  • Export your data - the Portfolio page exports your holdings as a CSV. That button is part of Pro, so if you are on the free plan and want a copy of your data, ask us and we will send it to you at no charge. Getting your own data back is a right, not a paid feature.
  • Correct anything inaccurate - every record in Sabrina stays editable for as long as you own it
  • Reset your portfolio - Settings, “Reset portfolio”. Removes every asset, transaction, grading submission, and photo, and keeps your login
  • Delete your account entirely - Settings. Cancels any subscription, removes all of the above, then removes the login itself
  • Opt out of non-essential communications

If you would rather we did any of it for you, or you cannot reach your account, contact us using the details below.

7. Cookies and Local Storage

We use browser local storage to save your theme preference and session tokens. We do not use third-party tracking cookies.

8. Children's Privacy

Sabrina is not intended for children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal data, please contact us so we can delete it.

9. Changes to This Policy

We may update this privacy policy from time to time. Every change is published on this page with a new “last updated” date, and we notify you in the app when a change is significant. If we ever start using your data for something materially different from what is described here, we will ask you first rather than announce it.

10. Contact

If you have questions about this privacy policy or your data, contact us at support@getsabrina.com.