Privacy Policy
Effective Date: August 13, 2026 · Last Updated: September 1, 2026
This Privacy Policy explains how the PackBuddy mobile application and packbuddy.io website (together, the “Service”) process personal information. The Service is provided by PackBuddy, operated by Florix Labs LLC (“PackBuddy,” “we,” “us,” or “our”). Florix Labs LLC, doing business as PackBuddy, is the controller of the personal information described in this Policy unless a different role is stated below.
1. Information We Process
- Account and authentication information: email address, internal account identifier, sign-in provider, and account or security events needed to authenticate and protect your account.
- Collection and app content: card identifiers, sets, variants, grades, quantities, notes, wishlist entries, price and portfolio history, scans, pull sessions, correction reports, tutorial progress, and related timestamps.
- Support information: structured card-correction reports submitted in the app and the message, sender address, and attachments you choose to send when you contact support.
- Studio content: videos, audio, selected images, editing instructions, project and job metadata, storage usage, and export activity that you choose to create or upload.
- Subscription information: product, plan, entitlement, App Store product identifier, RevenueCat offering identifier, transaction status, and renewal, cancellation, or refund events. Apple processes payment credentials; PackBuddy does not receive your full payment card information.
- Essential technical and security information: IP address, request time and status, app, browser, device and operating-system version, update-request information, authentication and session events, and rate-limit, fraud-prevention, abuse, and server-error signals needed to deliver and protect the Service.
- Service and security records: account, authentication, security, purchase, transaction, update-request, rate-limit, fraud-prevention, service-operation, and server-error logs needed to provide and protect the Service.
- Website information: when you visit packbuddy.io, Cloudflare processes ordinary network and request information to deliver and secure the site. PackBuddy does not load a website analytics beacon.
PackBuddy currently does not collect account-linked scan-performance analytics, paywall-interaction analytics, or mobile crash diagnostics.
Ordinary card-scan frames and recognized card text are processed on your device and are not uploaded unless you deliberately include content in a Studio project or submit it for support or correction. PackBuddy does not request precise-location permission or intentionally collect GPS coordinates.
2. How We Use Information
We process information as reasonably necessary to:
- provide, personalize, maintain, and support the Service;
- authenticate accounts, synchronize collections, process Studio projects, and apply subscription entitlements;
- secure the Service, prevent abuse, investigate errors, and enforce our Terms of Service;
- comply with law and protect users, PackBuddy, and others.
Where applicable, our legal bases are performance of our agreement with you for account, collection, subscription, and Studio functions; compliance with legal obligations; our legitimate interests in operating, supporting, and securing the Service where those interests are not overridden by your rights; and your consent for device permissions. Withdrawing consent does not affect processing that occurred lawfully before withdrawal.
3. When We Disclose Information
We disclose only the information reasonably necessary to the following providers for the stated functions:
- Supabase: authentication, account email, database, session, and account-linked Service records;
- Render: API hosting, operational logs, and Studio ingest and rendering jobs;
- Cloudflare: website hosting and security, Studio object storage, and content delivery through R2;
- Apple: Sign in with Apple, App Store distribution, in-app purchases, subscription administration, and related account or transaction notifications;
- RevenueCat: purchase validation, subscription status, and entitlement delivery;
- Sentry: scrubbed backend reliability and error reporting needed to operate and protect the Service. Mobile app diagnostics are disabled;
- Resend: delivery of account verification, password recovery, and security emails;
- Expo / EAS Update: delivery of application updates using the operating system, PackBuddy project identifier, and a randomized installation token; and
- hCaptcha (Intuition Machines, Inc.): bot, fraud, and abuse prevention for account flows.
These companies may act as PackBuddy service providers or, for some services such as Apple transactions, as independent controllers under their own terms. PackBuddy does not authorize a provider to use Service data for PackBuddy advertising or cross-app tracking.
PackBuddy uses the hCaptcha security service provided by Intuition Machines, Inc. to protect sign-in, registration, password-recovery, and verification actions from bots, fraud, and abuse. When you enter an app flow protected by hCaptcha, hCaptcha may automatically process your IP address, device and browser information, time spent in that flow, and interaction signals such as touch, mouse, scroll, or keypress activity. In invisible mode this analysis can occur without showing a visual challenge. Intuition Machines provides this processing for account functionality and security, not for PackBuddy advertising or cross-app tracking. hCaptcha's Privacy Policy and Terms of Service provide additional information about its practices.
We may also disclose information when you direct us to do so; to comply with law, legal process, or a valid government request; to investigate fraud, security issues, or rights violations; or in connection with a merger, financing, acquisition, reorganization, bankruptcy, or transfer of all or part of the Service, subject to appropriate safeguards.
PackBuddy does not sell personal information, share it for cross-context behavioral advertising, use it for targeted advertising, or track you across other companies’ apps or websites.
4. Permissions and Your Choices
PackBuddy requests camera access to scan cards and record sessions, microphone access when you choose to record audio, and photo-library access when you choose to select or save media. You can change these permissions in iOS Settings. Some features will not work without the related permission.
Optional analytics and mobile crash diagnostics are disabled for every account. The app does not present an analytics opt-in prompt or a related Settings control. PackBuddy continues to process the account, authentication, security, purchase, transaction, update-request, fraud-prevention, service-operation, support, and server-error records needed to provide and protect the Service.
5. Retention and Deletion
Retention depends on the record and why it exists:
- Account, collection, subscription mirror, and active Studio library: while your account is active, until you delete the item where item deletion is available, or until account deletion. Studio storage limits apply, but active library items do not currently have a scheduled time-based expiration.
- Retired optional analytics: legacy on-device queues and active-system scan-performance and paywall-interaction analytics are purged under PackBuddy's analytics shutdown. New optional analytics records are not accepted.
- Temporary Studio uploads: abandoned staging objects are scheduled for deletion after they are at least 24 hours old. The cleanup job runs daily, so the target is approximately 24–48 hours while that job is operating normally; an outage or failed sweep can extend the period until cleanup resumes. A one-way media-deletion fence may remain for up to 24 hours to prevent in-flight work from recreating deleted media.
- Apple server-notification security records: unmatched subject mappings expire after 24 hours; interrupted or failed mapped processing expires within seven days; completed replay receipts expire after eight days. A one-way security watermark that contains neither the raw Apple subject nor PackBuddy account ID may be kept as long as needed to prevent stale identity proofs from reopening a deleted or revoked account.
- Provider logs, transaction records, backend service-reliability records, and backups: for the period required to provide the relevant function, rotate backups, secure the Service, resolve disputes, or meet legal and accounting obligations. Apple and other independent controllers may retain records under their own policies. PackBuddy's provider-specific settings and deletion procedures are reviewed before release and when a provider changes.
You may delete your PackBuddy account from Settings → Account → Delete Account. Deletion removes associated information from active PackBuddy systems. Limited backup copies, one-way anti-replay or fraud records, legally preserved records, and provider-controlled records may remain for the periods or criteria described above. Deleting a PackBuddy account does not cancel an Apple subscription; manage or cancel it separately through your Apple Account.
6. Your Privacy Rights
Depending on where you live, you may have rights to know or access personal information, correct it, delete it, obtain a portable copy, restrict or object to processing, withdraw consent, appeal a decision, and complain to a privacy regulator. You may also have rights to opt out of sale, sharing, targeted advertising, or qualifying profiling. PackBuddy does not engage in those activities. We will not discriminate against you for exercising a privacy right.
Submit a request, including an authorized-agent request where applicable, to support@packbuddy.io. We may verify your identity and authority before acting and may deny or limit a request where permitted by law. If California law applies, the categories collected and disclosed during the preceding 12 months are described in Sections 1 and 3; we have not sold or shared those categories for cross-context behavioral advertising.
7. Age and Younger Users
PackBuddy is a general-audience Service intended only for people aged 13 or older. It is not designed or directed to people under 13. PackBuddy helps people create and privately export content; it does not provide an in-app social feed, chat, or social-media account, and any destination social platform is a separate service. We do not knowingly collect personal information from people under 13. If we learn that an under-13 user provided personal information, we will disable the account and take steps to delete the information. Contact support@packbuddy.io if you believe this has occurred. Users who are 13 or older but below the age of majority where they live must have authorization from a parent or legal guardian.
8. Security
We use reasonable administrative, technical, and organizational safeguards designed to protect personal information, including access controls and encryption where appropriate. No system or transmission method is completely secure, and we cannot guarantee absolute security.
9. International Processing
PackBuddy is operated in the United States. The providers listed above may process information in the United States and other countries whose laws may differ from those where you live. Where applicable law requires a transfer mechanism or additional safeguard, PackBuddy will use the applicable contractual or other legally recognized mechanism.
10. Changes to this Policy
We may update this Policy as the Service or law changes. We will post the revised Policy here, update the date above, and provide additional notice of material changes when required.
11. Contact
Privacy questions and requests may be sent to support@packbuddy.io. This is also the contact for the PackBuddy data controller.