Privacy Policy
Effective date: 14 June 2026 · Last updated: 15 June 2026
Explain the Card (“the App”) is provided by Danny Hollek (“we”, “us”, “our”). This Privacy Policy explains what data the App processes, why, who it is shared with, and the choices you have. It applies to the Explain the Card iOS app and its supporting backend.
If you have any questions, contact us at support@rosalabs.app.
Summary
- No account, no sign-in, no personal profile. The App never asks for your name, email, phone number, contacts, or location.
- No cross-app tracking and no advertising. We use Google Firebase Analytics to understand how the App is used in aggregate (e.g. how many people open it and which screens are popular). This is first-party measurement — it uses no advertising identifier (IDFA), is not used to track you across other apps or websites, and we run no ad networks.
- Scanning and card data are fully private. Card recognition happens on your device; card images and text are never used to identify you.
- AI explanations are opt-in. Nothing is sent to the AI provider until you explicitly agree via an in-app consent screen. Only the text you type and public card data are sent — never personal data.
- Your history stays on your device. Scans and questions are stored locally and are not uploaded to us.
Who we are (data controller)
Danny Hollek is the controller responsible for the data described here.
Contact: support@rosalabs.app
What we process, and why
The App is designed to minimise data. Most of what you do — scanning cards, reading oracle text, rulings, legalities, and combos, and browsing your history — happens on your device and shares nothing with us.
1. Anonymous identifier
On first launch the App creates an anonymous install identifier. This is a random identifier; it is not linked to your name, email, Apple ID, or any contact detail. We use it for one purpose only: to meter AI usage and credit purchases to the correct install (see below).
- Purpose: app functionality (AI metering, purchase entitlement).
- Legal basis (GDPR): performance of our agreement with you (the Terms of Use) and our legitimate interest in preventing abuse of paid features.
2. AI explanations (data sent to a third-party AI)
The App's AI features — single-card explanations, two-card interaction analysis, and free-form rules Q&A — are generated by Google's Agent Platform (Gemini), a third-party AI service, reached through our backend.
This only happens after you explicitly opt in. Before the first AI generation, the App shows an in-app disclosure that names the processor (Google Agent Platform) and states exactly what is sent. You can decline, and you can revoke consent at any time in Settings → “AI & Data Sharing”. Until you consent, the free, non-AI features remain fully usable.
When you do use an AI feature, the following is sent off-device:
| Sent to Google Agent Platform | Not sent |
|---|---|
| The text you type (your questions and follow-ups) | Your name, email, or any account |
| The cards being asked about — public oracle text, rulings, and relevant rules excerpts | Contacts, location, photos |
| The anonymous identifier described above | Any advertising or cross-app tracking identifier |
Because the question field is free text, please do not type personal or sensitive information into it. Only enter rules questions.
- Purpose: generating the explanation you requested.
- Legal basis (GDPR): your consent (which you may withdraw at any time).
- Retention / training: Google's paid Agent Platform Gemini API does not use your prompts to train its models, and we do not store your prompts on our servers. Google may retain request data transiently for abuse monitoring under its enterprise data-governance terms. We re-verify Google's then-current terms before each release.
3. Purchases and usage records
If you buy the credit pack or a Premium subscription, the purchase is processed by Apple. We never see your payment card or Apple ID. Against your anonymous install identifier, our backend records only what is needed to honour your entitlement and process renewals and refunds: your remaining AI-call balance, reset timestamps, and purchase records.
- Purpose: delivering and protecting paid features.
- Legal basis (GDPR): performance of the agreement; legal obligation (tax/accounting handled by Apple); legitimate interest in preventing fraud.
4. Camera
If you grant camera permission, the camera feed is used solely to recognise the card in front of you using on-device text recognition. No image or video is stored, and none is ever uploaded to us or any third party.
- Purpose: card scanning.
- Legal basis (GDPR): your consent (the iOS camera permission), withdrawable in iOS Settings.
5. Device integrity (anti-abuse)
To stop unauthorised clients from abusing our service, backend requests carry a device-integrity check that confirms the request comes from a genuine, untampered copy of the App. It does not identify you.
- Purpose: security / abuse prevention.
- Legal basis (GDPR): legitimate interest in protecting the service.
6. Data that stays only on your device
- History — every scan and question, including AI answers, is saved locally on your device. It is not uploaded to us. Delete an entry in-app, or delete the App, to remove it.
- Quota, credit, and AI-consent state — stored securely on your device only.
- Card images — fetched on demand and held in an on-device cache, cleared by the system or by deleting the App.
- The optional offline card database — if you choose to download it in Settings → Card Database, the file is stored on your device only.
7. Analytics
We use Google Firebase Analytics to understand how the App is used in aggregate, so we can find problems and decide what to improve. When you use the App, Firebase Analytics automatically collects standard measurement data, including:
- app opens, session count and length, and general engagement;
- which screens you view within the App;
- your App and OS version, device model, and coarse, IP-derived region and language;
- a random, app-generated instance identifier Google uses to count distinct installs.
We do not send your name, email, the text of your questions, scanned card images, or precise location to Analytics, and we do not log the specific cards you look up. This analytics data is not used to track you across other apps or websites and uses no advertising identifier (IDFA) — our privacy manifest declares NSPrivacyTracking = false.
- Purpose: analytics — measuring and improving the App.
- Legal basis (GDPR): our legitimate interest in understanding usage and improving the App; the data is pseudonymous and not used to identify you. To object to this processing, email support@rosalabs.app.
- Retention: this analytics data is retained by Google according to our Firebase data-retention setting and Google's own controls.
Third parties and processors
We share data only as needed to run the App's features:
| Provider | Role | What it receives |
|---|---|---|
| Google (cloud backend infrastructure) | Anonymous identity, usage metering, purchase records, device-integrity checks | Anonymous identifier, balance/purchase records, integrity token |
| Google Firebase Analytics | Aggregate usage measurement | App/screen-usage events, app and OS version, device model, coarse region/language, app-instance identifier |
| Google Agent Platform (Gemini) | Generates AI explanations | Your typed questions + public card data (only after consent) |
| Apple | Payment processing, device integrity | Purchase transactions, device-integrity token |
| Third-party card-data & rules providers | Card data, card images, rules and combo lookups | The card name / query you look up, your IP address |
These providers act under their own privacy policies. We do not sell your data, and we share it only for the purposes described above.
International transfers
Our backend runs on Google Cloud and AI requests are processed by Google's Agent Platform, which may process data in the United States or other countries. Apple processes payments globally. Where data leaves your country, it is transferred under the providers' standard contractual safeguards.
Data retention
- On-device data (history, caches, secure on-device state) is retained until you delete it or uninstall the App.
- Your usage record is retained for as long as your anonymous install exists and as long as needed to honour entitlements and meet Apple's renewal/refund obligations.
- AI prompts are not stored by us; Google's transient handling is governed by its enterprise terms (see §2).
- Analytics data collected by Firebase Analytics is retained by Google according to our Firebase data-retention setting and Google's controls (see §7).
To request deletion of the backend usage record associated with your install, contact support@rosalabs.app. Because the identity is anonymous, please contact us from the device so we can identify the correct record; once the App is deleted we may be unable to locate it.
Your rights
Depending on where you live (e.g. under the GDPR or similar laws), you may have the right to access, correct, delete, or restrict processing of your data, to object to processing, and to data portability. Since we hold no information identifying you personally and store no contact details, the data we can act on is the anonymous usage record described above. To exercise any right, email support@rosalabs.app. You also have the right to lodge a complaint with your local data-protection authority.
Children
The App is not directed to children and does not knowingly collect personal data from children. The App's age rating is set in the App Store. If you believe a child has provided personal data through the free-text question field, contact us and we will address it.
Security
Connections use HTTPS/TLS. Backend access is gated by device-integrity checks, anonymous authentication, and server-side access controls so that a client can read only its own records and cannot alter its own balance. Sensitive on-device state is stored securely and excluded from device backups.
Changes to this policy
We may update this policy as the App evolves. Material changes — particularly any change to what AI data is shared or who it is shared with — will be reflected here and will require you to re-confirm the in-app AI consent before AI features continue.
Contact
Danny Hollek
Email: support@rosalabs.app
Card data shown in the App (oracle text, rulings, card images, mana symbols) is the property of Wizards of the Coast and is displayed under the Fan Content Policy. Explain the Card is unofficial Fan Content and is not produced, endorsed, or affiliated with Wizards of the Coast or Hasbro.