Account policies

Privacy Policy

Effective September 26, 2026 · Version 2026-09-26

This policy describes the information WhatLedger processes to operate your account and the features you choose. It also explains account deletion and optional connections.

Information we collect

How we use information

We use information to authenticate accounts, provide the features you select, calculate reports, synchronize connected services, process billing, enforce scan allowances, prevent abuse, troubleshoot problems and respond to support requests. Authorized administrators can view account identity, subscription and scan information and perform account-management actions. Administrative changes are recorded.

Optional AI card scanning

When you choose AI scanning, your selected card photo and game are sent to OpenAI to suggest a card identity. WhatLedger does not save the submitted photo. It retains request fingerprints, identification results and usage counts to prevent repeat billing and enforce limits. This feature does not send Gmail messages, receipts, account credentials or existing inventory records to OpenAI. OpenAI handles API data under its applicable policies. Review AI results before relying on them.

Optional Gmail connection

Connecting Gmail is optional. Google requests read-only access to email messages and settings. That permission is broader than TCGplayer receipts; WhatLedger uses it to search for and read TCGplayer purchase receipts and identify the connected mailbox. This permission does not allow the app to send, modify or delete mail.

WhatLedger processes matching email text and HTML to identify cards, sellers, order numbers, dates, quantities and acquisition costs. It stores parsed purchase information, source message IDs, import status, corrections and audit history. Full email bodies and attachments are not retained. Unclear matches or totals require your review. Encrypted OAuth access and refresh tokens allow syncing while you are away.

Gmail data is not sold, used for advertising or used to train general-purpose AI models. WhatLedger’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Human access to Google user data is limited to circumstances permitted by that policy, including your affirmative permission for support, security needs or legal requirements.

Service providers, links and sharing

Render hosts the app and its data. Google provides optional Gmail access and account email delivery. Stripe handles payments and subscriptions. OpenAI provides optional AI identification. Marketplace integrations communicate with the marketplace you connect or use. Product images can load from the store or image host associated with a saved Buy again link. Those services receive ordinary connection information, such as an IP address, when contacted.

The app uses Impact affiliate scripts on some pages to track impressions and attribute qualifying marketplace links. These scripts may process browser/device information, link activity and identifiers according to Impact’s privacy policy. Gmail contents, credentials and imported purchase records are not supplied to the affiliate script. Session cookies are used to keep you signed in and protect account requests. Your browser settings control cookies and other site storage, but blocking essential storage can prevent sign-in.

Group participation and sharing are optional. If you enable sharing, selected profit metrics and card performance may include values derived from imported purchases. Gmail credentials and full email bodies are not shared with group members. Downloads and exports can contain business details and message references; you control subsequent sharing. Other users may retain copies of information you previously shared.

Security

Hosted account documents, including connected-service credentials and business records, are encrypted at rest. Passwords are stored as salted hashes. Hosted connections use HTTPS and access controls restrict account data. No service can promise perfect security. Keep your password private and contact support if you suspect unauthorized access.

Disconnecting and deleting

Use Gmail imports → Disconnect Gmail to stop syncing and remove active Gmail credentials. The app also requests revocation with Google. You can revoke access in your Google Account’s third-party connections settings. Disconnecting Gmail alone preserves imported inventory and cost records.

To delete your WhatLedger account, open Settings → Your profile → Delete account. After a warning, type DELETE MY ACCOUNT to confirm permanent deletion. This removes the account and its records from the active app database, including stored documents, Gmail-derived records, connection credentials, scan balances and memberships. Groups you own are deleted. Linked Stripe subscriptions are stopped as part of deletion; completed marketplace purchases are not reversed. The app may ask you to wait for active scans or syncs to finish. If a step fails, it will tell you rather than claim deletion is complete.

Active account records are generally kept while your account remains open, unless removed through available controls. Deleted information may remain temporarily in hosting backups or technical caches until their retention cycles expire. Payment providers may retain transaction records for their own legal, accounting or fraud-prevention obligations. We cannot erase exports you downloaded or copies held by people or services outside our control. No fixed backup-deletion deadline is promised here; contact us for details about a specific request.

You can also contact us from your account email address to request access, correction, deletion of retained Gmail-derived information, or help exercising rights available under applicable privacy law. We may verify identity before acting on a request.

Age and updates

Account registration is intended for adults age 18 or older. If you believe a child has provided information, contact us. Updated policies will show a new effective date. We will communicate material changes and obtain additional consent where required, including before new uses of Google user data.

Contact

Questions, privacy requests or account support: nickgcodes@gmail.com.