Legal

Privacy Policy

Last updated: May 16, 2026

1 Who We Are

Pocaly ("we," "our," or "us") is an iOS application that helps K-pop fans track their photocard collections. We are an independent developer. You can reach us at hello@pocaly.app.

2 What This Policy Covers

This Privacy Policy explains what information we collect when you use the Pocaly app, how we use it, who we share it with, and your rights regarding that information.

3 Information We Collect

3.1 Information You Provide Directly
Account information
username, display name, optional bio, optional location, and optional profile photo when you create an account.
Collection data
the photocards, albums, and merchandise you add to your collection, including optional notes, condition ratings, quantity, and purchase price.
Wishlist data
wishlist names, the cards on each list, and the priority levels you assign.
Bias and group preferences
the members and groups you mark as favorites or biases, including ult bias designations.
Collector goals
which members you are actively collecting per release.
Trade contact information
if you choose to enable the trade feature, an optional handle (Instagram, Twitter, Carrd) you provide for other users to contact you off-platform.
Photocard contributions
images you photograph and submit for review, including card front and back images.
Camera and photo library
Pocaly accesses your camera to scan and photograph photocards, and your photo library if you choose to upload images from your device. We store the resulting images in your personal collection only unless you explicitly choose to submit them to the community database.
3.2 Information Collected Automatically
Account identifiers
a user ID assigned by our authentication provider (Supabase) when you sign in with Apple.
Subscription status
your current subscription tier (Free, Bias, or Ult) as reported by the App Store and RevenueCat.
AI scan usage
a monthly count of how many AI card-matching scans you have used, reset on the first of each month.
Contributions activity
counts of how many card submissions you have had approved, pending, or rejected.
3.3 Information We Do Not Collect
We do not collect precise device location. We do not collect contacts. We do not collect browsing history outside the app. We do not run advertising trackers.

4 How We Use Your Information

We use your information only to operate and improve Pocaly. We do not use your data to serve third-party advertising. We do not sell your data.

  • Provide and operate the app — sync your collection, wishlists, and preferences across devices.
  • Authenticate your identity via Apple Sign In.
  • Display your profile and collection to you.
  • Process subscription purchases and enforce feature tier limits.
  • Run AI card-matching (CLIP embeddings via Replicate) when you use the scan feature.
  • Review fan-submitted photocard images in our admin panel before they are published.
  • Improve database accuracy based on community submissions.
  • Respond to support requests sent to hello@pocaly.app.

5 Third Parties We Share Data With

We share data only with the services needed to operate Pocaly. We do not sell your data.

Supabase
Handles our database and file storage. Your collection data, account information, and submitted images are stored on Supabase servers.
supabase.com/privacy →
Apple
Provides Sign In with Apple authentication and processes App Store subscription billing.
apple.com/legal/privacy →
RevenueCat
Handles subscription management and purchase validation. Receives your subscription status and purchase history.
revenuecat.com/privacy →
Replicate
Runs the AI model used for card matching. Your scan image is sent to Replicate for processing and is not retained beyond the duration of the prediction.
replicate.com/privacy →
Vercel
Hosts our internal admin panel, which is not user-facing.
vercel.com/legal/privacy-policy →

6 User-Submitted Photocard Images

When you choose to submit a photocard scan to the community database:

  • Your image is uploaded to private storage and reviewed by a Pocaly administrator before publication.
  • If approved, the image is published to the Pocaly database and visible to all users.
  • If rejected, your submission is deleted.
  • Approved images may be attributed to you by your Pocaly username if you consent to attribution. Attribution is optional.
  • You retain ownership of photographs you took. By submitting, you grant Pocaly a non-exclusive, royalty-free license to display that image within the app.

7 Children's Privacy

Pocaly is not directed at children under 13. We do not knowingly collect personal information from anyone under 13. If you believe we have inadvertently collected such information, contact us at hello@pocaly.app and we will delete it promptly.

8 Data Storage and Security

Your data is stored on Supabase servers. Supabase uses Row Level Security (RLS) to ensure users can only access their own data. Data is encrypted in transit (TLS) and at rest.

We are an independent developer and cannot guarantee absolute security, but we apply industry-standard practices and will notify you promptly in the event of a breach affecting your personal data.

9 Data Retention

We retain your account and collection data for as long as your account is active. If you delete your account, we will delete your personal data within 30 days, except where we are required by law to retain it. Community-contributed photocard images that have been approved and published may remain in the database after account deletion because they are part of the shared community record.

10 Your Rights

Depending on where you live, you may have rights including:

Access
Request a copy of the data we hold about you.
Correction
Ask us to correct inaccurate data.
Deletion
Ask us to delete your account and personal data.
Portability
Request your collection data in a portable format.
Objection
Object to processing based on legitimate interest.

To exercise any of these rights, email hello@pocaly.app. We will respond within 30 days. If you are in the European Economic Area, you also have the right to lodge a complaint with your local data protection authority.

11 California Residents (CCPA)

If you are a California resident, you have the right to know what personal information we collect, the right to delete it, and the right to opt out of its sale. We do not sell personal information. To submit a request, email hello@pocaly.app.

12 Changes to This Policy

We may update this policy as the app evolves. We will post the updated policy at pocaly.app/privacy and update the "Last updated" date. For material changes, we will notify you in-app.

13 Contact

Questions about this policy?
hello@pocaly.app