Privacy Policy

    Last updated: July 8, 2026

    1. Introduction

    This Privacy Policy explains how Castellum - Forge s.r.o. ("we", "us", "our") collects, uses, shares, and protects your personal data when you use the Citadel TCG platform, including our website at app.castellum-forge.net, our mobile applications for iOS and Android, and our marketplace services (collectively, the "Service").

    We are the data controller for the personal data processed through the Service. We are committed to protecting your privacy in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the UK General Data Protection Regulation, and all other applicable data protection laws.

    2. Data Controller

    CompanyCastellum - Forge s.r.o.
    AddressPri kaštieli 4855/12, 949 01 Nitra, Slovak Republic
    IČO57340315
    Emailinfo@castellum-forge.net
    Phone+421 904 197 476

    3. Data Protection Officer

    We have appointed a Data Protection Officer (DPO) whom you can contact for any data protection inquiries:

    Juraj Urban
    Email: info@castellum-forge.net
    Castellum - Forge s.r.o., Pri kaštieli 4855/12, 949 01 Nitra, Slovak Republic

    4. What Personal Data We Collect

    4.1 Account Data

    When you register and maintain an account, we collect:

    • Email address, username, display name
    • Password (stored as a one-way cryptographic hash — we never store your actual password)
    • Date of birth (for age verification and compliance with child protection laws)
    • Avatar image (if uploaded)
    • Profile information you choose to provide: bio, location, website, social media links

    4.2 Authentication Data

    If you sign in using a third-party provider:

    • Google Sign-In: Google account ID, email, name, profile picture
    • Apple Sign-In: Apple user ID, email (may be a private relay address), name

    4.3 Collection & Inventory Data

    • Your card collection data: game, set, card number, condition, foil status, quantity, grading information
    • Wishlist entries
    • Sealed product inventory
    • Scan history: images captured through the AI card scanner, identification results, timestamps

    4.4 Social & Communication Data

    • Feed posts, comments, likes, shares
    • Chat messages between users
    • Follow relationships
    • Pages you create or manage, and associated content
    • Content reports you submit

    4.5 Marketplace Data

    • Shop profile: shop name, slug, bio, location, logo, banner, currency
    • Listings: item details, pricing, images, condition
    • Orders: items purchased, order totals, shipping addresses, order status
    • Billing information: name, address, VAT identification number, company name (if applicable)
    • Reviews and ratings submitted
    • Dispute information

    4.6 Financial Data

    • Stripe customer ID and subscription information
    • Advertising wallet balance and transaction history
    • Partner/referral commission data
    • Invoice records

    Note: We do not store your credit card numbers, bank account details, or other payment credentials. All payment processing is handled by Stripe, Inc. and RevenueCat, Inc. (for mobile subscriptions via Apple App Store and Google Play Store).

    4.7 Technical Data

    • IP address (collected in server logs)
    • Browser type and version, operating system
    • Device information (for mobile app)
    • Push notification tokens (if you enable notifications)
    • Timestamps of your activity (login times, last active)

    4.8 Advertising Data

    • Ad campaigns you create: targeting settings, budget, creative content
    • Ad impressions and click data (aggregated for campaign reporting)

    4.9 Camera, Photo Library, and Image Data (Mobile App)

    The mobile app requests access to the following device permissions strictly for the listed purposes. You may grant or deny each permission at the time it is requested, and revoke it later in your device settings. Denying a permission disables the related feature but does not affect the rest of the app.

    • Camera access — used by the AI card scanner to capture images of trading cards for identification, and by the avatar editor to take a profile photo. The live camera feed is processed on-device and on our servers for the duration of a scan session only; we do not record video, audio, or background images. Camera frames are deleted immediately after identification completes (typically within 5 seconds), unless you confirm and save a card to your collection.
    • Photo library access — used when you upload an image from your gallery to: (i) the card scanner (to identify a card from an existing photo), (ii) a marketplace listing (to show the condition of an item you're selling), (iii) a social post or chat message, or (iv) your avatar or profile banner. We process only the specific image(s) you select; we never read, scan, or upload other photos in your library.
    • Image metadata — when you upload an image, we may process EXIF metadata (camera model, capture timestamp) for technical diagnostics. We strip GPS location data from all uploaded images before storage to protect your privacy.
    • Storage location — confirmed card scans and uploaded images are stored on our European-based S3-compatible object storage (Hetzner) and served via CDN. Unconfirmed scan frames are processed in memory only and never persisted.

    We do not request or use the following permissions: location (GPS), microphone, contacts, calendar, Bluetooth, or device motion sensors.

    5. How We Use Your Data

    We process your personal data for the following purposes, each with a specific legal basis under GDPR Article 6(1):

    PurposeLegal Basis
    Account creation, authentication, and managementPerformance of contract (Art. 6(1)(b))
    Providing the card collection management servicePerformance of contract (Art. 6(1)(b))
    Processing subscriptions and paymentsPerformance of contract (Art. 6(1)(b))
    Operating the marketplace (listings, orders, shipping)Performance of contract (Art. 6(1)(b))
    AI-powered card scanning and identificationPerformance of contract (Art. 6(1)(b))
    Social features (posts, chat, follows, pages)Performance of contract (Art. 6(1)(b))
    Partner/referral program and commission trackingPerformance of contract (Art. 6(1)(b))
    Advertising system (CPC campaigns)Performance of contract (Art. 6(1)(b))
    Sending transactional emails (verification, order updates, password reset)Performance of contract (Art. 6(1)(b))
    Sending marketing communicationsConsent (Art. 6(1)(a))
    Age verification and child protectionLegal obligation (Art. 6(1)(c))
    VAT calculation and tax complianceLegal obligation (Art. 6(1)(c))
    DAC7 reporting of marketplace seller income to tax authoritiesLegal obligation (Art. 6(1)(c))
    Invoice generation and accounting recordsLegal obligation (Art. 6(1)(c))
    Fraud prevention and platform securityLegitimate interest (Art. 6(1)(f))
    Content moderation and enforcing our TermsLegitimate interest (Art. 6(1)(f))
    Aggregated analytics for service improvementLegitimate interest (Art. 6(1)(f))

    6. Marketplace-Specific Data Processing

    6.1 Seller Data

    If you operate a shop on our marketplace, we collect additional information as required by the Digital Services Act (EU) 2022/2065, Article 30, and Directive (EU) 2021/514 (DAC7):

    • Legal name and address
    • Tax identification number (TIN / IČO / DIČ)
    • VAT identification number (if applicable)
    • Seller type (professional business or private individual)
    • Stripe Connect account details (onboarding, payout, and verification status)

    Under DAC7, we are legally required to report certain seller data (identity, TIN, transaction totals, number of sales) to the Slovak Financial Administration (Finančná správa SR) annually if you exceed the reporting thresholds (more than 30 sales or more than €2,000 in total consideration per year). This information may be shared with tax authorities in other EU member states.

    6.2 Buyer Data Shared with Sellers

    When you purchase items on our marketplace, the seller receives: your display name, shipping address (for physical goods), and order details. This sharing is necessary for order fulfillment.

    6.3 Public Marketplace Visibility

    The marketplace is publicly browsable. If you open a shop, the following information is visible to anyone on the internet without logging in and may be indexed by search engines (such as Google):

    • Shop name, shop URL (slug), bio/description, logo and banner images
    • Shop location (city/country you entered), seller type (professional or private), and average rating
    • Your active listings: card or product, price, condition, language, quantity, and listing images
    • Support e-mail address — professional sellers only; private sellers' support e-mail is never shown publicly

    Your account e-mail address, internal account identifiers, billing address, tax identification numbers, and order history are never part of public pages.

    When you close your shop or delete your account, this information is removed from our platform. Search engines may retain cached copies for a limited time after removal; you can request expedited removal via the search engine's own tools (e.g. Google's "Remove Outdated Content" tool) or contact us at info@castellum-forge.net and we will assist. Sellers acknowledge this public visibility when opening a shop (see the Marketplace Seller Agreement).

    7. Who We Share Your Data With

    We share personal data only with the following categories of recipients, and only to the extent necessary:

    RecipientPurposeLocation
    Stripe, Inc.Payment processing, subscriptions, marketplace payouts, fraud preventionUSA (EU-US Data Privacy Framework)
    Google LLCGoogle Sign-In authentication, email delivery (Gmail SMTP)USA (EU-US Data Privacy Framework)
    Apple Inc.Apple Sign-In authenticationUSA (EU-US Data Privacy Framework)
    RevenueCat, Inc.Mobile subscription management via App Store / Play StoreUSA (EU-US Data Privacy Framework)
    Hetzner Online GmbHServer hosting (web app, API, database)Germany (EU)
    Amazon Web ServicesMedia file storage (S3 — avatars, images, videos)EU region
    Marketplace sellersOrder fulfillment (shipping address, display name)Varies by seller

    We do not sell your personal data. We do not share your data with advertising networks, data brokers, or any other third parties for their own marketing purposes.

    8. International Data Transfers

    Some of our service providers are located in the United States. Where personal data is transferred outside the European Economic Area (EEA), we rely on the following safeguards:

    • EU-US Data Privacy Framework: Stripe, Google, Apple, and RevenueCat are certified under the EU-US Data Privacy Framework, which has been recognized as providing adequate protection by the European Commission (Adequacy Decision of July 10, 2023).
    • Standard Contractual Clauses (SCCs): Where the Data Privacy Framework does not apply, we use EU-approved Standard Contractual Clauses as a transfer mechanism.
    • EU-based processing: Our primary hosting (Hetzner) and media storage (AWS EU region) are located within the EU. The AI card recognition processing is performed on a GPU server located in Germany (Hetzner).

    9. Data Retention

    We retain your personal data for the following periods:

    Data CategoryRetention PeriodReason
    Account dataDuration of account + 30 days after deletion requestService provision + recovery window
    Chat messagesIndefinite (while account is active)Ongoing communication history
    Feed posts and comments10 years from creationCommunity content preservation
    Orders and invoices10 years from transaction dateLegal obligation (tax and accounting law)
    Ad campaign data and clicks10 years from campaign endLegal obligation (tax records) and dispute resolution
    Content reports20 years from report dateLegal compliance and platform safety
    Moderation flags (Tier 1 / Tier 2)6 months from creationPattern detection, filter improvement, abuse repeat-offender tracking
    Rate-limit countersAuto-purged at the end of each window (per-minute / per-day)Spam prevention only
    Admin chat-access audit log2 years from accessAccountability for staff access to private content
    Scan history (unconfirmed)Deleted when scan session ends without confirmationTemporary processing only
    Scan history (confirmed cards)Duration of accountPart of collection data
    Server logs (IP addresses)90 daysSecurity and debugging
    Stripe payment dataPer Stripe's retention policyLegal obligation (payment regulations)
    DAC7 seller dataDuration of relationship + 10 yearsLegal obligation (tax reporting)

    When you delete your account, we initiate a 30-day recovery window during which you can restore your account by logging in. After 30 days, your personal data is permanently deleted or anonymized, except for data we are legally required to retain (e.g., invoices and transaction records).

    10. Your Rights

    Under the GDPR and applicable data protection laws, you have the following rights:

    • Right of access (Art. 15): Request a copy of the personal data we hold about you.
    • Right to rectification (Art. 16): Request correction of inaccurate personal data.
    • Right to erasure (Art. 17): Request deletion of your personal data ("right to be forgotten"), subject to legal retention obligations.
    • Right to restriction (Art. 18): Request that we limit the processing of your data in certain circumstances.
    • Right to data portability (Art. 20): Receive your data in a structured, machine-readable format (JSON). Use the data export feature in your account settings.
    • Right to object (Art. 21): Object to processing based on legitimate interest, including for direct marketing.
    • Right to withdraw consent (Art. 7(3)): Where processing is based on consent, withdraw it at any time without affecting prior processing.
    • Right not to be subject to automated decision-making (Art. 22): See Section 12 below regarding our AI features.

    To exercise any of these rights, contact us at info@castellum-forge.net. We will respond within one month, which may be extended by two further months for complex requests. We will verify your identity before processing any request.

    11. Children's Privacy

    Citadel TCG takes the protection of children's privacy seriously.

    • Under 13: Registration is not available to children under the age of 13. We do not knowingly collect personal data from children under 13. If we discover that a child under 13 has registered, we will promptly delete their account and associated data.
    • Ages 13–15: Users between 13 and 15 years of age may register only with verifiable parental or guardian consent. During registration, the child must provide their parent's or guardian's email address. We will send a verification request to the parent, who must confirm consent and provide the required information before the account is activated.
    • Age 16 and older: Users aged 16 and older may register and consent to data processing independently, in accordance with the Slovak Republic's implementation of GDPR Article 8.
    • NSFW content: Content flagged as not safe for work (NSFW) is only accessible to users who have verified they are 18 years of age or older.

    If you are a parent or guardian and believe your child has provided personal data without your consent, please contact us at info@castellum-forge.net and we will take steps to delete the data.

    12. Automated Content Moderation, AI, and Admin Oversight

    12.1 Card scanning and identification

    When you use the card scanner, your card image is first processed by AI models on our own EU-hosted GPU server (Hetzner, Germany) — computer vision (DINOv2) and a small visual language model (Qwen 2B) — to identify the trading card. This processing is automated but does not produce legal effects or similarly significant effects on you. It is a tool to assist card identification — you can always manually select or correct the identification result.

    Third-party AI fallback: when our local scanner cannot identify a card with sufficient confidence (low recognition score, no candidate matched, or unreadable card name), the image is automatically sent to Anthropic's Claude Haiku 4.5 vision APIfor an additional identification attempt. Anthropic processes the image on US-located servers under their Data Processing Addendum (GDPR-compliant Standard Contractual Clauses). The image is sent only as part of a single API call, is not used by Anthropic to train their models, and is not retained by Anthropic beyond the response. The image, the identification result (card name, set, language), and basic metadata (your user ID, timestamp, the local recognition score) are stored in our scan-job database for up to 24 hours, then automatically deleted.

    Voluntary contribution to scanner training: if a third-party AI fallback successfully identifies your card AND you save the result to your inventory, we retain that same image (already taken, no additional capture) on our EU servers for the purpose of retraining and improving our local scanner. Each retained image is labeled with the confirmed card identifier (printing ID) and is used only to fine-tune our own DINOv2 visual model. These images are never published, shared with third parties, or used for marketing. The legal basis is our legitimate interest (Art. 6(1)(f) GDPR) in improving the accuracy of the service. You can request deletion of your contributed images at any time via privacy@castellum-forge.net (we keep a printing-ID index that lets us locate and delete your specific contributions).

    12.2 Tier 1 — Automated keyword filter

    Posts, comments, and chat messages are screened by an automated word/phrase filter before publication. Blocked content is not stored as a public post — only a moderation flag record is created (containing your user ID, the matched words, the content type, a short preview of the attempted content, severity, and timestamp) so that we can review patterns of abuse and improve the filter. Chat messages tolerate higher severity than posts because chats are private; only severe violations (e.g. threats, slurs, self-harm prompts) are blocked in chat.

    12.3 Tier 2 — AI content classification

    Some content that passes Tier 1 is additionally reviewed by an AI classification model running on our own EU-hosted GPU server (Hetzner, Germany). The model returns scores for toxicity, hate, political extremism, threats, and sexual content. Content with a high score is logged for human review but is not retroactively removed without human action. Your posts, comments, chat messages, and other text content are never sent to third-party AI providers (e.g. OpenAI, Anthropic, Google) for moderation purposes. (Card scanner images are a separate, narrowly scoped exception — see §12.1.)

    12.4 Anti-spam rate limits

    We apply per-plan rate limits to posting, commenting, liking, and messaging to prevent spam and abuse. Counters (per user, per action, per time window) are stored in our database and reset automatically. Exceeding a limit returns a temporary error; no permanent record is kept after the window resets.

    12.5 Admin access to user chat for safety investigations

    Citadel administrators may, in cases of reported abuse, harassment, fraud, or other safety investigations, view user-to-user chat content read-only, including media attachments. This access is restricted to staff with the admin role, every read is recorded in our internal admin audit log (admin user ID, timestamp, conversation ID), and is used solely to enforce our Terms and Community Guidelines. Chat content is never used for advertising, marketing, training third-party AI models, or shared with third parties except where required by law (court order, law-enforcement request) or to protect the vital interests of a person.

    12.6 Right to human review

    Automated moderation flags do not by themselves result in account suspension. Material actions (warning, suspension, ban) are taken only after human admin review. You have the right to request human review of any automated decision that affects you, and to contest a moderation outcome. Contact us at info@castellum-forge.net.

    13. Cookies and Tracking Technologies

    For detailed information about the cookies and storage technologies we use, please see our Cookie Policy.

    In summary: we use a minimal set of strictly necessary and functional cookies/storage. We do not use any third-party analytics or advertising trackers.

    14. Data Security

    We implement appropriate technical and organizational measures to protect your personal data, including:

    • Encryption of data in transit (HTTPS/TLS for all connections)
    • Cryptographic hashing of passwords (bcrypt)
    • Access controls and authentication for all systems
    • Regular security updates and monitoring
    • EU-based hosting with ISO 27001-certified providers (Hetzner)
    • No storage of payment card details (handled entirely by Stripe)

    While we take reasonable measures to protect your data, no system is completely secure. In the event of a data breach, we will notify the relevant supervisory authority within 72 hours and affected individuals without undue delay, as required by GDPR Articles 33 and 34.

    15. Jurisdiction-Specific Disclosures

    15.1 United Kingdom

    If you are a UK resident, your data is protected under the UK GDPR. Your rights are substantially the same as described in Section 10 above. The supervisory authority for the UK is the Information Commissioner's Office (ICO), ico.org.uk.

    15.2 California (USA)

    If you are a California resident, the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) may grant you additional rights, including:

    • Right to know what personal information we collect, use, and disclose
    • Right to delete your personal information
    • Right to opt out of the sale or sharing of personal information — we do not sell or share your personal information for cross-context behavioral advertising
    • Right to non-discrimination for exercising your rights

    Categories of personal information collected are described in Section 4. We collect this information for the business purposes described in Section 5. To exercise your rights, contact us at info@castellum-forge.net.

    15.3 United States — COPPA

    We comply with the Children's Online Privacy Protection Act (COPPA). We do not knowingly collect personal information from children under 13 without verifiable parental consent. See Section 11.

    15.4 Brazil (LGPD)

    If you are a Brazilian resident, the Lei Geral de Proteção de Dados (LGPD) grants you rights similar to those described in Section 10, including the right to anonymization, blocking, or deletion of unnecessary or excessive data.

    15.5 Japan (APPI)

    If you are a Japanese resident, we process your data in accordance with the Act on the Protection of Personal Information (APPI). We specify the purposes of data use as described in Section 5 and provide opt-out mechanisms for third-party data provision.

    16. Changes to This Policy

    We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. When we make material changes, we will:

    • Post the updated policy on this page with a new "Last updated" date
    • Notify registered users via email or in-app notification
    • Where required by law, obtain your renewed consent

    17. Contact and Complaints

    For any privacy-related questions, requests, or complaints:

    Castellum - Forge s.r.o.
    Attn: Data Protection Officer — Juraj Urban
    Pri kaštieli 4855/12, 949 01 Nitra, Slovak Republic
    Email: info@castellum-forge.net
    Phone: +421 904 197 476

    If you are not satisfied with our response, you have the right to lodge a complaint with a supervisory authority:

    • Slovakia: Úrad na ochranu osobných údajov SR, Hraničná 12, 820 07 Bratislava, dataprotection.gov.sk
    • United Kingdom: Information Commissioner's Office, ico.org.uk
    • Other EU countries: You may lodge a complaint with the supervisory authority in your country of residence