Eyevo mobile apps and website

Privacy Policy

What Eyevo processes, why it is needed, and which data stays on your device.

Last updated: August 21, 2026

The short version

  • Camera frames are processed on your device and are not uploaded or stored by Eyevo.
  • Your card collection and scan history are stored locally. Eyevo does not require an account.
  • Product analytics are pseudonymous, not fully anonymous. Eyevo does not create PostHog person profiles or send names, email addresses, collection names, search text, or advertising IDs to PostHog. Selected attribution and purchase-funnel events include RevenueCat's pseudonymous app-user ID.
  • Meta and TikTok receive limited app-attribution signals so Eyevo can measure install campaigns. Advertising-ID collection and automatic purchase tracking are disabled.
  • Eyevo does not ask for your age or date of birth and does not show an age gate.

1. Controller

Eyevo is operated by Julian Beck, Theoderichweg 5, 70469 Stuttgart, Germany. Contact: [email protected]. Additional legal information is available in the Impressum.

2. Data that stays on your device

Eyevo uses the camera to recognize trading cards. Camera frames are processed locally and discarded after recognition. They are not uploaded to Eyevo servers. Your collections, scan history, preferences, custom values, and portfolio history are also stored locally in the app database.

You can export collection and scan data from the app. Deleting the app removes its local data, subject to backups controlled by your device and Apple or Google. Files you deliberately export or share are handled by the destination you choose.

3. Pseudonymous product analytics

Eyevo uses PostHog's EU service to understand which features work and where users encounter problems. Events can include a random installation identifier, event type, app version/build, platform, feature choices, and public catalogue identifiers such as a card or set ID. Most non-critical events are collected from a stable 10% sample; essential install, scanner, paywall, and purchase-funnel events may be counted for all installations.

Eyevo disables person profiles, automatic screen capture, element capture, and session replay inside the mobile apps. The analytics filter removes user-authored collection names, search queries, URLs, error text, contact fields, local collection IDs, and unapproved cross-system identifiers. Selected attribution, paywall, and purchase-funnel events include RevenueCat's pseudonymous app-user ID so results can be joined between PostHog and RevenueCat; this ID is not a name, email address, or advertising ID. Events also ask PostHog not to add IP-derived location. As with any internet request, PostHog's receiving server necessarily sees the source IP while handling the connection.

Because events from the same installation can still be grouped using a random installation identifier, this data is accurately described as pseudonymous, not completely anonymous.

4. Purchases and subscriptions

Purchases are processed by Apple App Store or Google Play. RevenueCat receives a pseudonymous app-user identifier and store subscription information such as product, purchase, trial, renewal, cancellation, refund, entitlement status, and transaction timing so Eyevo can unlock Pro and manage subscriptions. Eyevo does not receive your full payment-card details.

5. Install and advertising attribution

Eyevo uses the Meta and TikTok app-events SDKs to measure whether an advertising campaign produced an installation or later app activity. These providers may process app, device, network, and event metadata under their own privacy terms.

  • Meta: Eyevo sends an explicit app activation and a Meta-generated anonymous app-device ID. That ID is passed to RevenueCat so RevenueCat can deliver subscription lifecycle events to Meta. Meta automatic app-event and purchase logging is disabled.
  • TikTok: Eyevo permits automatic install, launch, and two-day-retention signals. Automatic in-app-purchase tracking and enhanced identity postback are disabled.
  • Advertising identifiers: Eyevo does not request Apple's IDFA, does not show an App Tracking Transparency prompt, disables Google Advertising ID collection, and removes the Android AD_ID permission.

6. Diagnostics and notifications

Firebase Crashlytics may process crash reports, diagnostic details, app/device information, and installation identifiers to help fix stability problems. If you enable push notifications, Firebase Cloud Messaging and Apple Push Notification service or Google Play services process a push token and delivery metadata. Eyevo does not use notification permission to access contacts or messages.

7. Website analytics and advertising pixels

The Eyevo website is separate from the mobile apps. It uses self-hosted Plausible analytics, PostHog EU, the Meta Pixel, and the TikTok Pixel. These tools can process page views, clicks, referral and campaign parameters, browser/device data, cookies or local storage identifiers, and network information. Meta and TikTok use their website data for advertising measurement under their own terms.

PostHog website analytics use a persistent 10% sample, while App Store and Play Store click events are counted exactly. For sampled visits that begin on an Eyevo /get campaign page, PostHog session replay may record interactions on the website. Passwords and payment information are not collected through those Eyevo campaign pages.

8. Service providers, purpose, and retention

Eyevo uses Apple, Google/Firebase, RevenueCat, PostHog, Meta, TikTok, and hosting/network providers to provide app functionality, subscriptions, diagnostics, analytics, notifications, security, and campaign measurement. Data may be processed outside your country using the safeguards offered by the relevant provider.

Eyevo keeps provider-side data only as long as reasonably needed for these purposes, legal obligations, fraud prevention, and dispute handling, subject to each provider's retention controls. Local app data remains until you delete it or uninstall the app. Eyevo does not sell camera images or collection contents.

9. Age and children's privacy

Eyevo does not ask for a birth date and does not use an age gate. The iOS age rating describes content suitability; the intended Google Play audience starts at age 13. Eyevo is a general-audience card utility and is not primarily directed to children under 13.

Eyevo does not knowingly request personal information from children under 13. Where local law requires parental permission for a younger user, a parent or guardian must supervise the use. If you believe a child has provided personal information, contact us so it can be investigated and deleted where possible.

10. Your choices and rights

  • You can deny or revoke camera and notification permissions in system settings.
  • You can export supported collection data in the app and delete local data by removing the app.
  • You can use browser privacy controls to restrict cookies, local storage, and advertising pixels on the website.
  • Depending on your location, you may request access, correction, deletion, restriction, objection, or portability for personal data Eyevo can identify.
  • You may complain to a competent data-protection authority.

Requests can be sent to [email protected]. Because Eyevo does not require an account and deliberately avoids direct identity fields in product analytics, it may not be possible to connect an analytics record to you without additional information from your device.

11. Changes

This policy may be updated when Eyevo's products, providers, or legal obligations change. The current version and update date are published on this page.

Eyevo is an independent application and is not affiliated with The Pokémon Company, Nintendo, Game Freak, or Creatures Inc.