BinderBuzz Privacy Policy
Effective Date: October 8, 2026
BinderBuzz respects your privacy. This Privacy Policy explains what information BinderBuzz collects, how it is used, and the choices you have when using the service.
BinderBuzz is an early-access service for adults 18 and older.
Feed and community posts, comments and replies can contain up to four photos. Social photos are visible to signed-in members who can access the associated post; community discussions require membership. They do not change collection-folder privacy. Photos are resized and re-encoded without original metadata. Text and images may be processed by OpenAI for safety screening. Flagged content is held privately, and restricted incidents have limited access. Removing a post or comment prevents further access to its photos; account deletion queues associated photos for deletion, subject to documented safety retention.
Information We Collect
Account Information:
BinderBuzz may collect:
- Username
- Email address supplied and verified by the member
- Securely hashed password information
- Account status
- Login/session information
- Signup and last-login information
Passwords are not stored in plain text.
Card and Collection Information:
BinderBuzz may store:
- Trading-card details
- Collections and folders
- Card photos
- Scan history
- Card condition, language, set, rarity and related information
- Other information users choose to enter
Card Recognition:
When a user uses BinderBuzz card recognition, uploaded card images and related information may be processed through OpenAI's API to attempt to identify the card.
Card images may also be stored by BinderBuzz when necessary to provide collection and scanning features.
Technical and Security Information:
BinderBuzz and its service providers may process:
- IP address
- Browser/device information
- Login attempts
- Session information
- Request and error logs
- Security/access information
BinderBuzz currently uses Cloudflare for secure access, network protection and related infrastructure.
Feedback and Support:
If a user submits feedback, reports a problem or requests support, BinderBuzz may store the information they provide, including screenshots, descriptions and contact information.
Users should not include passwords, API keys, financial information or other sensitive information in feedback reports.
How Information Is Used
BinderBuzz may use information to:
- Create and maintain accounts
- Authenticate users
- Provide card scanning and recognition
- Save collections and card information
- Protect accounts and prevent abuse
- Diagnose errors
- Improve BinderBuzz
- Respond to support requests
- Test beta features
- Maintain backups and reliability
Our permanent privacy commitment
We will never sell, rent, or trade your personal information to advertisers or data brokers. We’re here to connect collectors, not profit from their privacy. This commitment remains in place as BinderBuzz develops.
Read The BinderBuzz Promise — Pinky Promise 🩷 on our About page.
Service Providers
BinderBuzz may use third-party providers necessary to operate the service, including:
Cloudflare — security, access control and network services.
OpenAI — card recognition and, when enabled, text/image safety screening. Resend — account verification, recovery and password-change email. Railway — hosting and persistent storage after migration. No Cloudflare identity is automatically linked to member email.
Necessary processing by service providers supports the service; it is not a sale of member information. Cloudflare handles requests, network metadata and, where enabled, beta access authentication. OpenAI receives submitted card images for recognition and, when enabled, submitted content for safety screening. Resend receives recipient email addresses and account-message content when account email is enabled. Railway will store application records and uploads after migration; the current beta remains on the owner-operated server until then.
Open-Meteo processes city/postal search text to find nearby events. Browser/device push providers receive subscription delivery information and encrypted general alerts only when you enable push notifications. External eBay sales searches send card search terms to eBay when you follow the link; other external links are governed by their destination’s policies.
These providers have their own terms, security and retention practices. BinderBuzz does not introduce advertising trackers or data-selling integrations. Our promise does not mean that information is never processed by providers or that complete security can be guaranteed.
Public And Private Information
Your account email is not included in public profiles or member lists. It is available to you, the authorized owner for account administration, and the services needed to deliver account emails. Avoid posting your email in public text or photographs.
Some BinderBuzz features may intentionally display public information, such as a public profile.
Private collections, account information and private media are not intended to become public merely because a person uses BinderBuzz.
Users are responsible for information they intentionally publish through public features.
Seller Studio waitlist
When enabled, the optional waitlist stores your email, one interest choice, consent version and confirmation times. Joining requires explicit consent and email confirmation through Resend. Only the authorized owner can view entries; joining does not create a public profile, guarantee selection or require a purchase. Emails concern Seller Studio testing and availability only. Withdraw at any time using the private link in your confirmation email or contact support. Pending entries are removed after seven days on the next waitlist request or owner review; confirmed entries remain until withdrawal or the waitlist ends. Withdrawal removes the active entry; protected backup copies expire under the backup retention policy.
Data Retention
BinderBuzz retains information for as long as reasonably necessary to:
- Operate accounts
- Maintain collections
- Provide requested features
- Maintain security and backups
- Resolve problems
- Meet applicable legal obligations
Account deletion is available in Account security. Data exports can be requested from support.
Security
BinderBuzz uses reasonable technical safeguards including authentication controls, password hashing, protected sessions, access controls, upload validation, rate limits and HTTPS.
No online service can guarantee absolute security.
Children
BinderBuzz is for adults aged 18 and older during the initial launch.
Users must confirm they are at least 18 years old. No full date of birth is collected.
Self-attestation is not conclusive age verification. Report suspected underage accounts privately for review and possible suspension.
User Choices
Users may use BinderBuzz Feedback & Support to request help with:
- Account information
- Privacy questions
- Account access
- Account deletion requests
- Questions about stored information
Changes
BinderBuzz may update this policy as the service develops.
The current effective date should remain visible at the top.
Contact
For privacy or account questions, use BinderBuzz Feedback & Support.
Current beta feature privacy details
What people can see
- Your username, display name, profile photo, bio, status, Bench, Buy links and public collections are visible to anyone who can reach the app.
- Private collections and their card photos are restricted to your account. Site-admin privileges do not bypass these collection rules.
- Posts appear to signed-in people who follow you. Anyone with an account can follow a public profile; posts are not confidential messages.
- Live chat is shared with signed-in members. Event venues and descriptions are also visible to signed-in members.
- Community pages and membership lists are public. The My communities section on your profile shows only memberships you explicitly select in Edit profile; hiding a community there does not hide its public member list.
What is stored and sent
- The app stores account details, password hashes, photos, collections, memberships, follows, posts, chat and events on the server. It does not ask for a real name, phone number, payment information or home address to register.
- Card photos are sent to OpenAI when you choose to scan. Keep faces, mail, addresses and other personal details out of the picture. Photo metadata is stripped, but visible content remains in the image.
- City search sends the city or postal text you enter to Open-Meteo. It does not send your account details or request your device’s GPS location.
- Server access logs may include IP addresses, page paths and times. Login protection retains hashed attempt identifiers for up to 24 hours before cleanup on a subsequent attempt. Local backups contain private app data.
- Removed posts, chat messages and events are hidden from the app but retained in the database and possibly backups. Account deletion removes your personal content and photos from active storage. Shared communities remain without your creator media and description. Contact support for data export. Restricted safety incidents may require protected retention.
Community posts and notifications
Community posts are visible to joined members; anyone with an account can join a public community. Posts are not confidential messages. Notifications are off by default and can be turned on separately for each joined community. Leaving removes that preference. Blocking hides each other's community posts and alerts. Removed posts remain in the database/backups but are no longer shown or notified.
Phone and desktop alerts require HTTPS hosting, a separate device opt-in and browser permission. Push subscriptions and delivery queues are stored on the server and associated with your current login session. Signing out or session expiry stops future delivery; enable the device again after signing in. Browser push providers deliver an encrypted general alert without post text or names. Alerts already delivered can remain on a device. Turn device alerts off in Notifications, or turn individual communities off in their Feed. In-app notifications still work without device permission.
Bench photos
Choose one to five visible Bench spots. Each spot can show a linked profile, an uploaded photo, or both, with an optional caption. Photos are private while being uploaded and become public when you save them in a visible Bench spot. Reducing your Bench size keeps extra spots saved for you but hides their entries and uploaded photos from visitors. Increasing the size makes those saved spots public again. Removing a photo from the Bench stops public access, but a copy may remain in storage or backups. Up to ten unassigned uploads are retained per account; those older than 24 hours are cleaned up on a later upload. Photo metadata is removed. Captions are personal labels, not verified seller ratings or marketplace listings.
Protect your account
Use a unique password. Sign out on shared devices. Edit profile includes “Sign out all devices” if a device is lost or a session is no longer trusted. Signing out invalidates that session on the server.
Blocking
Use Block account on a profile and manage your blocks in Edit profile. Blocking hides each other’s feed posts, shared chat messages and events while signed in. It prevents follows and Bench connections in both directions and removes existing connections. Unblocking does not restore those connections. Your block list is visible only to you, though someone may infer a block when following becomes unavailable. Public profiles, public collections and community membership remain public, including to signed-out visitors. Blocking is not an account ban or a substitute for moderation.
Current connection limits
The home-network preview at an http:// address is not encrypted in transit. Keep this beta on a trusted private network. A verified HTTPS host, encrypted storage/backups, operational monitoring, account recovery and further security review are needed before a public launch. Database files are not encrypted by the app, and an authorized server operator can access them.
Accounts and safety
Account security provides verified email enrollment, password recovery, password changes and permanent account deletion. Password and email changes invalidate active sessions. Recovery links expire after 30 minutes and work once. The designated owner must arrange an ownership transition before deleting the owner account.
Public content may be screened or held privately before publication. Reports and moderation decisions are restricted to the owner. Suspected child exploitation incidents are handled outside ordinary image review. Read the Community guidelines or report a concern.
The proposed launch backup retention is 30 days. Backups are protected and access restricted; deleted information can remain in backups until expiry. Documented legal/safety preservation may require longer retention. This retention schedule must be configured before public registration.
Support and privacy contact: bones@buildsnbones-tcg.biz.