Privacy policy
Last updated:
This policy explains how the CardLens browser extension handles your information. I am Tomasz Jasek, its developer and the person responsible for the data practices described here. For privacy questions or requests, contact [email protected].
Card recognition and search
When you use the recognition shortcut while pointing at an image or video, CardLens takes a temporary screenshot of the visible tab and crops it to the image or video area. The initial screenshot can include other visible page content, including text in forms. The screenshot and crop are processed only in memory on your device; they are never saved to disk or uploaded. Capture and recognition run only when you use the shortcut.
Image recognition, ordinary text lookups, and searches typed in the overlay use software and card data bundled with the extension and work offline. Those search queries and recognized text are not sent to a server. Some supported card references require a separate Scryfall request, as described below. CardLens does not access your browser history or cookies, or extract values from website form fields. It has no accounts or advertising.
Card references and images from Scryfall
Hovering over supported card links or names in double brackets can open a preview automatically, without the shortcut or a screenshot. Ordinary webpage text is looked up locally when you use the shortcut. Unqualified names in double brackets are also matched against the bundled catalog.
To resolve certain supported references or a specific printing, CardLens requests card metadata from api.scryfall.com. Depending on the reference, the request includes a Scryfall card identifier, a Gatherer multiverse identifier, a set code and collector number, or a card name and set code. Scryfall receives that reference and connection information including your IP address. These requests need an internet connection unless the result is already cached in memory; cached metadata expires after five minutes.
When a card is recognized, a reference is resolved, or you select a search result, CardLens automatically loads its image from cards.scryfall.io or images.scryfall.io unless a copy is already stored in your browser. Loading a new image requires an internet connection. Scryfall and its hosting providers receive the image address, which identifies the card, and connection information including your IP address.
Metadata and image requests use HTTPS without credentials or referrer information. They do not include screenshots, the address or full content of the page you are viewing, queries typed in the overlay, or text recognized from an image. The card reference described above is included only when needed to resolve that reference. See Scryfall’s privacy policyfor its data practices.
Usage data, feedback, and error reports
CardLens uses PostHog to help me understand feature use, improve recognition, and diagnose problems. Sharing is enabled by default in releases configured for analytics. Firefox also requires its optional technical and interaction data permission; CardLens respects your choice to refuse or revoke it.
When sharing is enabled, CardLens sends:
- Random identifiers for the installation and individual lookups, event times, extension version and build, browser type and major version, and operating system type.
- Feature activity and performance, such as lookup and search outcomes, response times, media type and approximate size, image-loading results, and changes to settings.
- Problem categories you choose to submit, such as “Wrong card,” “Couldn’t find it,” or “Too slow.” Usage events and error reports are collected automatically; this feedback is submitted only when you select it.
- Error types, predefined categories, and locations in CardLens’s own code. Raw error messages and details from the website’s code are excluded.
The installation identifier links reports from the same installation, so this data is pseudonymous, not fully anonymous. Reports do not include screenshots, image crops, card names or identifiers, recognized text, search queries, page content, website addresses, browsing history, custom shortcuts, or exact pointer positions. CardLens does not record browsing sessions or automatically track website page views and clicks.
Reports are sent over HTTPS to PostHog’s EU service without credentials or referrer information. PostHog receives connection information, including your IP address, when handling an upload. CardLens disables PostHog’s person profiles and IP-based location enrichment. See PostHog’s privacy policyfor more information about its practices.
CardLens’s PostHog project is configured to retain usage data and error reports for one year. This server-side retention period is separate from the seven-day limit for unsent reports stored in your browser.
To opt out, open Settings & privacy in the extension popup and turn off Share usage data and error reports. Recognition and search continue to work. Turning sharing off cancels pending uploads and deletes unsent reports and the installation identifier from your browser. It does not delete reports already received by PostHog. Turning sharing back on creates a new identifier.
Data stored in your browser
- Settings and card images. CardLens stores your shortcut and sharing preferences, the websites on which you have disabled it, a timestamp to prevent captures too close together, and recently displayed card images with their identifiers and last-used times. The image cache holds up to 12 images and approximately 3 MB, removing older entries as needed.
- Local diagnostics. Recognition counts, outcomes, and timings are stored without screenshots, website addresses, or recognized text. These records are separate from the reports sent to PostHog. Chrome, Edge, and Firefox clear them when the browser session ends; Safari keeps them in local extension storage until replaced or that storage is removed.
- Unsent reports. When sharing is enabled, CardLens stores the installation identifier and queues up to 200 events for delivery. Events older than seven days are discarded when the queue is processed and are not sent. Successfully sent events are removed from the queue. This seven-day limit applies to unsent events on your device, not to reports already received by PostHog.
Settings and cached images remain until replaced or the extension’s storage is cleared. Uninstalling CardLens removes its extension storage, including any unsent reports, but does not delete reports already sent to PostHog.
Permissions and controls
CardLens uses website and tab access to locate images, videos and text under your pointer, detect supported links and double-bracket card names for automatic hover previews, respond to the shortcut, and display results. It captures the visible tab only when you request recognition over an image or video. Other browser permissions support local processing, saved settings, and retries for unsent reports. CardLens starts enabled on websites where your browser allows it to run. You can disable it for a website in the popup, restrict website access in your browser’s extension settings, or uninstall it.
I use browser data only to provide, maintain, and improve CardLens’s features. I do not sell it or use it for advertising or unrelated profiling. CardLens’s handling of user data follows the Chrome Web Store User Data Policy, including the Limited Use requirements.
Contact and privacy requests
If you email me, I receive your email address and the information you choose to share. I use this information to respond and retain the correspondence only as needed to handle your request or meet legal obligations. To request access, correction, or deletion of your personal data, email [email protected].
Changes to this policy
Updates will be published on this page with a revised “Last updated” date.