KiBinder

Privacy Policy

Last updated: October 3, 2026

This policy explains what KiBinder collects about you, why, who else sees it, how long it is kept, and what you can do about it. It is written to be read — where a claim is technical, it says the technical thing plainly rather than reserving the right to do something vaguer.

1. Who we are and what this covers

KiBinder is a trading card game collection tracker. This policy covers both of our sites — kibinder.com (our marketing site) and app.kibinder.com (the app itself) — which we refer to together as KiBinder. We are the controller of the personal information described here. You can reach us at any time at support@kibinder.com.

It does not cover other companies' websites. When you follow a link out of KiBinder — to TCGplayer, to eBay, or anywhere else — that site's own privacy policy applies from the moment you arrive.

This policy describes our website and web app. We do not currently publish a mobile app; if that changes, this policy will be updated before it ships.

2. Information we collect

Information you give us:

  • Your email address. You sign in either with a one-time link sent to your email, or with your Google or Discord account. If you use Google or Discord, we receive basic profile information from that provider, including your email address. KiBinder has no passwords — we never ask you to create one, and we do not store one.
  • Your collection. The cards you own and their quantities, the binders and decks you build, the sets you track, your price alerts, and your display preferences. Some of this is free text you type — binder and deck names in particular — so it contains whatever you choose to put there.
  • Anything you send us. If you email support, we have your message and your address.

Information collected automatically:

  • How you use KiBinder. Pages visited, features used, clicks, session duration, and session recordings of your browsing. Section 5 describes exactly what those recordings contain and what is masked out of them.
  • Server logs and telemetry. Technical records of the requests your browser makes. Section 7 sets out precisely what they hold and what has been deliberately kept out of them.

Payment information is collected by Stripe on Stripe's own pages, not by us. Your card number never passes through, and is never stored on, a KiBinder server.

Two things we deliberately do not hold, because it is easier to keep a promise about data that was never collected: our application's own records hold no email addresses and no IP addresses — your email lives only in the sign-in system, and the app reads it from your signed-in session — and our web server's access log is configured to record no client IP address at all.

3. How we use your information

We use what we collect to:

  • Sign you in and keep you signed in
  • Store your collection, show completion progress, and estimate collection values
  • Send the price alerts you set up, and let you manage or stop them
  • Take subscription payments, manage billing, and confirm what you signed up for
  • Send you service messages when we need to — a security or privacy notice, planned downtime, or a change to these terms. These are not marketing, and you cannot unsubscribe from them while you have an account
  • Answer your questions when you contact us
  • Keep the service secure, diagnose faults, and understand which features are worth building on
  • Comply with our legal obligations

If you are in the EEA or the UK, our legal bases are: performance of a contract for everything needed to run your account and your subscription; legitimate interests for keeping the service secure and working, and for answering your messages; consent for analytics and session recording, which do not run until you agree (section 5); and legal obligation where a law requires us to keep records, such as tax records of payments.

We do not sell your personal information, we do not use it for advertising, and there is no advertising or ad-targeting tag on either of our sites.

4. Who else sees your information

We share information with third-party service providers, only as far as each needs it to do its job for us. Each is bound by its own agreement with us and by its own privacy policy. The table below describes them by the role they play rather than by name.

WhoWhat it does for KiBinderWhat it receives about you
Account and collection storageRuns our sign-in and stores your account and everything you save in KiBinderYour email address, your sign-in activity, and all of your collection data
Sign-in providers you choose (Google, Discord)Let you sign in with an account you already have, instead of a KiBinder-specific oneOnly what you approve when you authorise the sign-in. We receive basic profile information back, including your email address
Anti-bot checkConfirms a person, not a script, is requesting a sign-in linkYour IP address and browser signals, at the moment you request a sign-in link
Email delivery and forwardingSends our sign-in links, price alerts and subscription confirmations, and forwards mail you send usYour email address, the contents of the messages we send you, and anything you write to us
Payments (Stripe)Takes subscription payments and runs the billing portal, on its own pagesYour email address, and the payment details you enter on Stripe's own pages. Card numbers never reach our servers
Product analytics and session recordingMeasures how KiBinder is used so we can improve it — see the analytics section belowYour KiBinder user id and your email address as account identifiers, the pages you visit, the actions you take, session recordings of those pages (with form fields, your name and email addresses masked), and your IP address — from which an approximate location (country, region, city) is derived and stored with your activity
Affiliate networkRuns the redirect that every “buy on TCGplayer” link passes through, so purchases can be attributed to usYour IP address, browser user-agent and the fact that you clicked, recorded at the redirect before you reach TCGplayer
Monitoring and error loggingStores our server logs, traces and metrics for 14 days — see the telemetry section belowYour KiBinder user id on some server log lines, and the web addresses your browser requested, including any text you typed into search. No IP address and no user-agent
Hosting and content deliveryServes our two sites, our API, and the card images and set logos you seeStandard web-request information, including your IP address

If you want to know exactly who they are, ask us. We describe these providers by role rather than by company name, which is what data-protection law asks for. It is not a way of avoiding the question: if you would like the specific list, email support@kibinder.com and we will send it to you.

Where our card data comes from. Card names, images, printings and market prices are fetched from tcgcsv and the TCG Tracking API. These are sources we read from, not recipients: nothing about you is sent to either.

Links out to shops. KiBinder links to TCGplayer and eBay so you can buy cards you are missing. Both kinds of link carry an affiliate identifier so that a qualifying purchase can be attributed to us; it costs you nothing extra. Our TCGplayer links pass through a redirect run by TCGplayer's affiliate network, which records the click — you reach that redirect before you reach TCGplayer. Our eBay links carry an affiliate identifier in the eBay address itself: there is no redirect, and eBay records the click when you arrive.

We never send TCGplayer or eBay your email address or your account identity. We send TCGplayer nothing about your collection either, with one exception you choose: the cart export. When you use it, your browser submits a shopping list to TCGplayer's bulk-entry form so your cart arrives filled in — the missing cards from a binder, or the contents of a deck. That list contains, for each card, the quantity, the card name, its card number and its set code, along with which game it belongs to and the affiliate identifier described above. It contains nothing about you: not your email address, not your account, and not the rest of your collection. Our Terms of Service describe the affiliate relationship in full.

We may also share information when the law requires it, to enforce our terms, or to protect the rights and safety of our users or ourselves. If KiBinder is ever sold or merged, account information would transfer with it, and we would notify you.

5. Analytics, session recording, and your choices

We use a third-party product analytics and session-recording provider. It records which pages you visit and what you interact with, and it captures session recordings — replayable reconstructions of your browsing. We use them to find where the app is confusing or broken. We are happy to tell you which provider it is; email support@kibinder.com and ask.

This is not anonymous. When you are signed in we identify you to that provider by your KiBinder user id and your email address, so your activity is attached to your account rather than to an unnamed visitor. It also receives your IP address with each event and derives an approximate location from it. Our two sites share one analytics profile, which means a visit to kibinder.com before you signed up and your later activity in the app can be joined together.

What the recordings show, and what they mask. A recording shows the pages as you saw them — the cards, sets and prices you looked at, your collection and its value, and the names and descriptions you have given your binders and decks — along with your clicks, scrolling and navigation. Masked before it leaves your browser: everything you type into a form field, your name and email address wherever they appear on the page, and any other text that looks like an email address. Masked text is replaced with placeholder characters of the same length, so its length and shape remain visible even though the words do not. Two honest limits: masking applies to visible text, not to HTML attributes, so text placed in an attribute by the page — an image description, for instance — is not masked by this mechanism; and while we remove the sign-in credentials that can appear in a web address, we do not strip the rest of the address, so anything you type into a search box is part of the page address we record.

This changed on October 3, 2026. Before then, recordings masked all on-screen text, which also hid the thing we watch them for: whether a page displayed correctly. They now show the page, with the personal details above still masked.

If you are in the EEA or the UK, we ask first. Analytics and session recording do not start until you agree; declining, or simply not answering, means nothing is collected. We work out whether to ask from your browser's time-zone setting rather than by looking up your location — it costs nothing and sends nothing to anyone, but it is an estimate, so if you are travelling or using a VPN you may be asked when you would not normally be, or the reverse. We remember your answer in a kb_analytics_consent cookie for one year so we do not have to keep asking. Elsewhere, analytics start by default under local rules — and wherever you are, you can turn them off, or back on, whenever you like using the Your privacy choices panel at the end of this page. Declining there applies to both of our sites. You can also block or clear cookies in your browser.

6. Cookies and local storage

Not everything below is a cookie. Two of them are ordinary browser storage, which behaves like a cookie from your point of view — it persists until you clear it — but is never sent to a server.

  • Sign-in (browser storage, not a cookie). Holds your session so you stay signed in. Without it you would have to sign in on every page.
  • Preferences (browser storage, not a cookie). Remembers choices such as light or dark mode.
  • kb_analytics_consent (cookie). Records your answer to the analytics question for one year, on kibinder.com and app.kibinder.com alike.
  • Analytics (cookie, set by our analytics provider). Identifies your analytics session across our two sites. Created only while analytics are running, and removed when you turn analytics off.

7. Server logs and telemetry

Our API sends operational telemetry — request traces, application logs and performance metrics — to a third-party monitoring provider, where it is kept for 14 days and then deleted. It exists so we can see that a page is slow or an endpoint is failing.

It is deliberately filtered. Traces carry the request method, the URL path, the response status and how long it took; the caller's IP address, the browser user-agent and the query string are removed before anything is sent. Logs carry the request method, the URL, and — where it makes a line meaningful — your KiBinder user id; request headers, cookies, IP addresses and email addresses are stripped out. A user id identifies you to us only by looking it up against your account.

One thing logs deliberately keep: the full web address, including its query string. That is what makes a log line useful when a page misbehaves, and almost everything in a KiBinder address is an identifier or a number. The exception is the card search box: if you type something there, the text you typed is part of the address and is kept in our logs for those 14 days. Please do not type anything into search that you would not want recorded. Separately, the web server that serves the app records no client IP address in its access log.

8. Public binders and decks

You can make a binder or a deck public. Please treat that as publishing: anyone with the link can view it without signing in, and anyone signed in can import a public binder or deck as their own private copy.

A copy someone else has made belongs to them. Making the original private again, or deleting your account entirely, does not reach into other people's accounts and remove their copies. Public pages do not display your email address. If you would rather something were not public, change it back in the app before sharing the link further.

9. How long we keep information

  • Your account and collection: for as long as your account exists. Deleting your account removes them immediately (section 10).
  • Database backups: our database provider keeps daily backups for 7 days, so deleted data can persist in a backup for up to a week before ageing out.
  • Server logs and telemetry: 14 days, then permanently deleted.
  • Analytics and session recordings: recordings are kept for up to 30 days on our analytics plan; analytics events are kept for longer, under that provider's retention schedule. Both are deleted when you delete your account.
  • Payment records: Stripe keeps records of payments it has processed for as long as tax, accounting and anti-fraud law requires, even after we delete your customer record.
  • Email: messages we have already sent stay in your mailbox, and our sending provider keeps a record that they were sent. Support conversations stay in our inbox until we clear them.
  • Your analytics choice: the kb_analytics_consent cookie lasts one year, or until you clear it.

10. Deleting your account

You can delete your account yourself, at any time, from Settings > Security > Delete Account. It is immediate and irreversible — there is no recovery window and no way for us to restore it afterwards. If you cannot sign in, email support@kibinder.com from the address on the account and we will handle it for you.

Deleting your account does three things, in this order:

  1. Any active subscription is cancelled and your customer record at Stripe is deleted. If this step fails, the deletion stops rather than leaving you paying for an account that no longer exists.
  2. Your sign-in identity is deleted, and with it every row tied to it — your collection, binders, decks, tracked sets, price alerts, preferences, and your subscription record.
  3. Your analytics profile is deleted, along with its events and its session recordings.

Honestly, some traces outlive the deletion:

  • Database backups, for up to 7 days.
  • Server log lines carrying your user id, for up to 14 days.
  • Stripe's own record of payments you made, which it must keep by law.
  • Emails already delivered to you, and our provider's record of sending them.
  • Copies other people made of anything you published publicly, which belong to them (section 8).
  • If the analytics deletion in step 3 fails, your analytics profile remains until we remove it by hand. We log that failure against your user id specifically so it can be found and cleared.

11. Your rights, and how to use them

  • Delete everything. Settings > Security > Delete Account — no request needed, see section 10.
  • Get a copy of your data. There is no self-service export today. Email support@kibinder.com from your account address and we will send you what we hold.
  • Correct something. Most of what we hold is yours to edit directly in the app. For anything else — including your email address — email support@kibinder.com.
  • Withdraw or grant analytics consent. The Your privacy choices panel at the end of this page, at any time.
  • Cancel your subscription. Settings > Subscription, through the billing portal.
  • Object, restrict, or ask for portability where the law where you live gives you those rights (section 12 and section 13).

We will acknowledge a request promptly and answer it within 30 days. We may need to confirm you control the account's email address before acting. Exercising any of these rights costs nothing and we will not treat you differently for it.

12. If you are in the EEA or the UK

KiBinder is the controller of your personal information; you can reach us at support@kibinder.com. Our legal bases are set out in section 3, the retention periods in section 9, and the recipients in section 4.

In addition to the rights in section 11, you may object to processing we carry out on the basis of legitimate interests, ask us to restrict processing while a dispute is resolved, and ask for the information you gave us in a portable form. Where we rely on your consent — analytics and session recording — you can withdraw it at any time, and doing so does not make the processing before that point unlawful.

We operate from the United States and our service providers store information there, so using KiBinder involves transferring your information out of the EEA and the UK. Where a provider offers data-processing terms, we rely on the transfer safeguards in them, such as the European Commission's standard contractual clauses. One exception we would rather state than gloss: mail you send to our published addresses is forwarded and read through ordinary commercial email services, on their standard consumer terms rather than under a data-processing agreement negotiated by us.

If you think we have got this wrong, please tell us first — but you also have the right to complain to your national data protection authority.

13. If you are in California

In the past twelve months we have collected these categories of personal information: identifiers (your email address and your KiBinder user id), commercial information (your subscription status and payment history), internet or other electronic network activity (how you use KiBinder, including session recordings), and approximate geolocation (a country-level and city-level estimate our analytics provider derives from your IP address). The sources, purposes, recipients and retention periods are in section 2, section 3, section 4 and section 9. We do not collect sensitive personal information in order to infer anything about you.

We do not sell your personal information, and we do not share it for cross-context behavioural advertising as California law defines those terms. There is no advertising or ad-targeting tag on either of our sites today, so there is nothing to opt out of. To be exact about the twelve-month window this section covers: until August 2026 kibinder.com carried a Google Ads conversion tag, which we removed outright rather than put behind a consent prompt. Since that removal we have neither sold nor shared personal information, and we have no advertising tags left through which to share it.

Our sites do not currently respond to browser Do Not Track or Global Privacy Control signals. The consent controls described in section 5 are the mechanism we honour, and the Your privacy choices panel at the end of this page turns analytics off wherever you are.

You have the right to know what we collect, to get a copy of it, to correct it, to delete it, and not to be discriminated against for asking. Section 11 explains how to do each. You may use an authorised agent; we will ask for proof of their authority.

14. Children

KiBinder is not directed to young children, and you must be at least 13 to use it — or 16 in those EEA countries whose law sets that age for consenting to online services. (The United Kingdom sets it at 13, so 13 is the minimum there too.) We do not knowingly collect personal information from anyone below the age that applies to them. If you believe a child has given us information, email support@kibinder.com and we will delete the account and its data.

15. How we protect your information

Connections are encrypted in transit, sign-in uses short-lived tokens rather than passwords we could lose, and access to production data is restricted. Card numbers never touch our servers, our own database holds no email or IP addresses, and our logs and session recordings are filtered before they leave, as section 5 and section 7 describe. None of that makes any online service perfectly secure, and we cannot guarantee absolute security.

16. Changes to this policy

We may update this policy. When we do, we post the new version here and change the "Last updated" date at the top. If a change materially affects what we collect or who we share it with, we will make that clear rather than relying on the date alone.

17. Contact us

Questions, requests, or anything in this policy that does not match what you see in the app: email support@kibinder.com and a person will read it.

Your privacy choices