CarDex

Privacy, in plain language

Privacy Policy

This policy explains how CarDex handles information when you photograph cars, identify them, and build your private collection.

Effective August 23, 2026

1. Information CarDex collects

CarDex uses an anonymous account identifier to keep each player's collection separate. Gameplay does not currently require a name, email address, phone number, password, or social login. If you choose to contact support, the separate support form requires a contact email.

  • An anonymous account identifier used to maintain the game session.
  • Vehicle photos taken with the camera or selected from the photo library.
  • Discovered vehicles, discovery dates, sighting counts, rarity, and XP.
  • Support-form information: contact email, request category, device and OS information (or N/A), anonymous Player ID (or N/A), and a free-text message.
  • Technical request data necessarily processed for hosting, security, and authentication.

CarDex does not currently request precise or approximate location.

2. How information is used

We use this information to provide vehicle identification and collection features, save and restore a collection, associate photos with the correct private collection, award XP, secure anonymous sessions, and diagnose operational failures when necessary. Support-form information is used to respond to requests, troubleshoot issues, verify and complete data requests, keep necessary request records, and prevent abuse.

CarDex does not sell personal information or use it for targeted advertising or cross-app tracking.

3. Vehicle photos and identification

When you submit a vehicle photo, CarDex uploads a normalized JPEG to private Supabase storage associated with your anonymous identifier.

An authenticated server function sends the image transiently through an operator-managed home gateway to Google Cloud Vertex AI for vehicle identification. The gateway processes the request in memory and does not retain a second copy of the photo.

Google processes the image to provide the requested AI result. The original private Supabase photo remains associated with your collection until it is deleted through the process below.

4. Service providers

CarDex uses Supabase for anonymous authentication, database storage, private photo storage, and server-side functions; an operator-managed gateway for transient request routing; and Google Cloud Vertex AI for vehicle identification. CarDex uses Tally to host and store responses to the support and data-request form. These providers process data to provide and protect the applicable service.

5. Retention and deletion

Vehicle photos, anonymous identifiers, and collection history may be retained while needed to provide your persistent CarDex collection or meet legal, security, and dispute-resolution obligations.

Support-form submissions may be retained while reasonably needed to respond, troubleshoot, verify and complete the request, maintain necessary records, prevent abuse, and meet legal obligations. Deleted Tally form data may remain in Tally backups for up to 90 days unless permanently removed sooner.

CarDex does not use traditional email/password accounts. To request deletion, choose Data deletion request in the support form. We may need the anonymous player ID available in the app to locate the correct private records. We will verify the request before deleting data.

6. Camera and photo-library access

CarDex asks for camera access so you can photograph vehicles and may request photo-library access so you can select an existing image. These permissions are used only when you initiate a capture or selection flow.

7. Children's privacy

CarDex is a general-audience car collection game and is not directed specifically to children. If its intended audience or data practices change materially, this policy will be reviewed and updated.

8. Security

CarDex uses authenticated sessions, private storage, access controls, and encrypted network connections to protect game data in transit and restrict access to player-specific records. No security system can guarantee absolute protection.

9. Changes to this policy

We may update this policy when features, providers, or data practices change. We will update the effective date on this page when we do.

10. Contact

CarDex is operated by Sewon Min. Privacy questions and data requests can be sent through the official Tally-hosted support form. Do not include passwords, authentication tokens, payment information, or unrelated sensitive data.

CarDex Support & Data Requests

Technical help, privacy questions, feedback, and deletion requests.

Open support form