Privacy Policy
Last updated: April 28, 2026
1. Introduction
This Privacy Policy explains how Guredo AI s.r.o., VAT ID: CZ29532990, registered at Purkyňova 649/127, Medlánky, 612 00 Brno, Czech Republic ("Guredo.AI", "we", "us") collects, uses, stores, and protects your personal data when you use: (a) the Guredo.AI mobile application (the "App"); and (b) the Guredo.AI marketing website at guredo.ai (the "Website"). Together, the App and the Website are referred to as the "Service". Guredo.AI acts as the data controller for your personal data under Regulation (EU) 2016/679 (the General Data Protection Regulation, "GDPR"). The App and the Website are governed by different data-processing practices. The App does not use cookies, analytics, or advertising tracking. The Website does use cookies for analytics and advertising, but only after you give consent through the cookie banner. See Section 7 for full details.
2. Data We Collect
In the App, we collect the following categories of personal data: Account Data: When you create an account, we collect your email address, username, password (stored in hashed form), and language preference. Profile Data: Information you voluntarily add to your profile, such as your profile picture, eBay username, public/private profile setting, and global content preference. Submission Data: Card images you submit for grading, authentication, or identification, along with associated metadata (submission type, timestamps, AI-generated results). Community Data: Content you create in the community feed, including posts, comments, poll votes, poll responses, likes, saved posts, and marketplace listings (external links and prices). Messaging Data: Messages you send and receive through the in-app messaging feature. Device Data: Basic device information necessary for app functionality, including device type, operating system version, and app version. On supported devices, we may collect attestation data (Apple App Attest key identifiers or Google Play Integrity tokens) for security verification purposes. Security Data: HMAC request signatures, attestation headers, and SSL pinning data used to verify the integrity of communications between the app and our servers. In the App we do NOT collect: • Location data or GPS coordinates. • Contact lists or address books. • Browsing history or activity outside the app. • Advertising identifiers (IDFA, GAID). • Cookies — the App is a mobile application and does not use cookies. On the Website (guredo.ai), we may additionally collect, only with your consent given via the cookie banner: standard web analytics data (pages visited, approximate location at country level, browser and device type, traffic source) and, if you accept advertising cookies, advertising-measurement data linked to Google Ads. Full details, including the cookies set and the legal basis, are in Section 7. Waitlist Email: If you submit your email address through the waitlist form on the Website, we share that email with our newsletter provider (Loops) so we can notify you about the App launch. The legal basis is your consent (GDPR Article 6(1)(a)). You can unsubscribe at any time using the link in any email we send you.
3. How We Use Your Data
We use your personal data for the following purposes: Service Delivery (GDPR Article 6(1)(b) — Contract Performance): • Creating and managing your account. • Processing your card submissions and delivering AI-generated grading, authentication, and identification results. • Providing community features (feed, posts, comments, polls, messaging). • Displaying marketplace listings you create. • Sending you notifications about your submissions, posts, and messages. • Providing customer support. AI Model Training (GDPR Article 6(1)(f) — Legitimate Interest): • Card images and associated metadata may be used to train and improve our AI grading, authentication, and identification models. Our legitimate interest is improving the accuracy and quality of our AI services for all users. You have the right to object to this processing (see Section 8). • Any images you upload to the Service may also be used to extend our reference database of genuine, fake, and graded card images. This database underpins and continually improves the accuracy of our grading, authentication, and identification AI, and helps the community of users analyse their own products. Content Moderation (GDPR Article 6(1)(c) — Legal Obligation and Article 6(1)(f) — Legitimate Interest): • Automated scanning of user-submitted images to detect prohibited content, in compliance with the Digital Services Act (Regulation (EU) 2022/2065). • Human review of flagged or reported content. Security (GDPR Article 6(1)(f) — Legitimate Interest): • Verifying device integrity through attestation. • Protecting the Service against unauthorized access, fraud, and abuse. • HMAC signature verification and SSL pinning. Legal Compliance (GDPR Article 6(1)(c) — Legal Obligation): • Responding to lawful requests from authorities. • Reporting suspected criminal offenses as required by law.
4. Data Storage & Sub-Processors
Your personal data is stored and processed using the following infrastructure: Image Storage: Card images and user-uploaded images are stored on Amazon S3 (Amazon Web Services) and delivered through Cloudflare CDN (Content Delivery Network). Both services process data on our behalf as sub-processors. Application Data: Account data, submission metadata, community data, and messaging data are stored in our application database hosted within the European Economic Area (EEA). Sub-Processors: • Amazon Web Services (AWS) — Image storage (Amazon S3). AWS processes data in accordance with the AWS GDPR Data Processing Addendum. • Cloudflare, Inc. — Content delivery network (CDN) for serving images. Cloudflare processes data in accordance with the Cloudflare Data Processing Addendum. Both sub-processors are bound by data processing agreements that require them to process personal data only on our instructions and to implement appropriate technical and organizational security measures. Data is primarily processed within the European Economic Area (EEA). Where sub-processors process data outside the EEA (e.g., Cloudflare edge servers), appropriate safeguards are in place in accordance with GDPR Chapter V, including Standard Contractual Clauses and, where applicable, adequacy decisions by the European Commission.
5. Data Retention
We retain your personal data as follows: Active Accounts: Your personal data is retained for as long as your account is active. Account Deletion: When you delete your account, your personal data is removed from active systems within 30 days. This includes your account data, profile data, messages, and community posts. Submission Images: Card images associated with your submissions are deleted from storage within 30 days of account deletion. Anonymized Data: Data that has been anonymized or aggregated in a form that no longer identifies you (including data incorporated into AI training datasets) is not considered personal data and may be retained indefinitely. Legal Retention: We may retain certain data beyond the standard retention period where required by law, to resolve disputes, or to enforce our Terms & Conditions. Draft Posts: Draft posts that are not published are automatically cleaned up after 1 hour.
6. Data Security
We implement appropriate technical and organizational measures to protect your personal data, including: • Passwords are stored using secure one-way hashing algorithms. • All communications between the app and our servers are encrypted using TLS (Transport Layer Security). • SSL certificate pinning is used to prevent man-in-the-middle attacks. • API requests are authenticated using HMAC-SHA256 signatures to verify request integrity. • Device attestation (Apple App Attest / Google Play Integrity) is used to verify that requests originate from legitimate app installations. • Access to personal data is restricted to authorized personnel on a need-to-know basis. • JWT (JSON Web Tokens) are used for session management, with short-lived access tokens (7 minutes) and refresh tokens (7 days) stored securely on your device.
7. Cookies, Analytics, and Advertising
In the App: Guredo.AI does not use any cookies, third-party analytics, or advertising tracking. Specifically, in the App we do not collect advertising identifiers (IDFA, GAID), use third-party analytics SDKs (such as Google Analytics, Firebase Analytics, or Mixpanel), share your data with advertisers or ad networks, track your activity across other apps or websites, build behavioral profiles for advertising, or sell, rent, or trade your personal data to any third party. The only data the App processes is the data described in Section 2, used solely for the purposes described in Section 3. On the Website (guredo.ai): We use Google Analytics 4 and Google Ads to measure how visitors find and use the Website, and to measure the performance of any online advertising we run. These services are operated by Google Ireland Limited (and, where applicable, Google LLC) and act as our processors. Specifically: • Google Analytics 4 (measurement ID G-R7HQSQEBK3) — measures pageviews, sessions, traffic sources, approximate location (country level), and aggregate user behavior. No personally identifying information is collected by us through Analytics. • Google Ads — measures which ads led visitors to the Website and supports remarketing. • Google Consent Mode v2 — controls how the above tags behave based on your cookie choices. Legal basis: We set advertising and analytics cookies only with your consent (GDPR Article 6(1)(a) and the ePrivacy Directive as transposed into national law). Strictly necessary cookies (such as the cookie that remembers your consent choice) are set on the basis of our legitimate interest in operating the Website (GDPR Article 6(1)(f)). Default state: When you first visit the Website, all advertising and analytics cookies are denied by default. The Google tags load in a "cookieless ping" mode that sends only aggregate, anonymized signals — no identifiers, no cookies — until you accept. This is implemented via Google Consent Mode v2. Cookies we may set after you give consent: • _ga, _ga_R7HQSQEBK3 — Google Analytics, used to distinguish users (analytics category). • _gcl_au, _gcl_aw, _gcl_dc — Google Ads conversion linker (advertising category). • cc_cookie — our own cookie that records your consent choices (strictly necessary). International transfers: Google may process some data in the United States. Such transfers rely on the EU–US Data Privacy Framework and Standard Contractual Clauses, in accordance with GDPR Chapter V. Managing your choices: You can change your cookie preferences at any time using the "Cookie settings" link in the Website footer. When you withdraw consent for a category, the corresponding cookies are cleared from your device on your next page load.
8. Your Rights Under GDPR
Under the General Data Protection Regulation (GDPR), you have the following rights regarding your personal data: Right of Access (Article 15): You have the right to request a copy of the personal data we hold about you. Right to Rectification (Article 16): You have the right to request correction of inaccurate or incomplete personal data. You can update most of your profile data directly in the app settings. Right to Erasure (Article 17): You have the right to request deletion of your personal data ("right to be forgotten"). You can delete your account through the app. Data that has been anonymized or incorporated into AI training datasets in a form that no longer identifies you is not subject to erasure. Right to Restriction (Article 18): You have the right to request restriction of processing in certain circumstances (e.g., while we verify the accuracy of your data). Right to Data Portability (Article 20): You have the right to receive your personal data in a structured, commonly used, and machine-readable format. Right to Object (Article 21): You have the right to object to processing based on legitimate interest, including the use of your data for AI model training. Upon receiving your objection, we will cease processing your data for that purpose unless we can demonstrate compelling legitimate grounds. Right Regarding Automated Decision-Making (Article 22): You have the right not to be subject to decisions based solely on automated processing that produce legal effects or similarly significantly affect you. You may request human review of any AI-generated grading, authentication, or identification result by contacting [email protected]. Right to Lodge a Complaint: You have the right to lodge a complaint with your national data protection authority. For users in the Czech Republic, this is the Office for Personal Data Protection (Úřad pro ochranu osobních údajů, www.uoou.cz). To exercise any of these rights, please contact us at [email protected]. We will respond to your request within 30 days.
9. Children's Privacy
The Service is intended for users who are at least 16 years old (or the minimum age required in your country to consent to the use of digital services). We do not knowingly collect personal data from children below this age. If you are between 16 and 18 years old, you confirm that you have obtained consent from your parent or legal guardian to use the Service. If we become aware that we have collected personal data from a child below the applicable minimum age without proper consent, we will take steps to delete that data as soon as possible. If you believe we may have collected data from a child, please contact us at [email protected].
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or in-app notification at least 30 days before the changes take effect. Your continued use of the Service after changes take effect constitutes acceptance of the updated Privacy Policy. If you do not agree to the updated Privacy Policy, you must stop using the Service and may delete your account. The "Last updated" date at the top of this policy indicates when it was most recently revised.
11. Contact Information
For any questions about this Privacy Policy, to exercise your GDPR rights, or to raise any data protection concerns, please contact us at: Data Controller: Guredo AI s.r.o. (VAT ID: CZ29532990) Address: Purkyňova 649/127, Medlánky, 612 00 Brno, Czech Republic Email (general): [email protected] Email (data protection): [email protected] We communicate in English and Czech.
Questions? Contact us at [email protected]