Privacy Policy
Last updated 2026-10-02 · v2026-10-02
Who we are
Sereal is a personal collectibles tracker for cards and comics, operated by Brian Lehnen. This policy explains what we collect, why, and the choices you have. Questions or requests: privacy@serealbox.com.
What we collect
Account data: your email address and a securely hashed password (we never store your password in plain text).
Collection data you enter: cards, comics, costs, spend and sale records, wishlist, grading and sale plans, and any photos you upload.
Operational data: error diagnostics and server logs needed to keep the service reliable.
Abuse-prevention data: to protect sign-up and other sensitive actions from automated abuse, we retain a keyed, pseudonymous identifier derived from your IP address (for sign-up attempts) — not the raw IP address itself — to recognize repeated sign-up attempts, or your account for other sensitive actions, along with the time and allow/block outcome of the attempt. This is kept for 30 days and then automatically deleted, and is collected even for sign-up attempts that do not result in an account.
Documentation feedback: when you submit feedback on a documentation page, we store the page path (without any query string), the category you selected, and the text you wrote. We do not store identifiers or IP addresses for this feature. The text you write is also copied into a private issue tracker hosted by GitHub so we can act on it, so please do not include anything you would not want recorded there. Submissions are protected from automated abuse by Cloudflare Turnstile, which is operated by Cloudflare and processes request data under its own terms.
External lookups
To power comp, deal, and certification-lookup features, card and comic details you enter may be sent as search or lookup queries to third-party services: eBay, SoldComps, PSA, CGC, and CardSight (card release and parallel data). We send only what those lookups require.
Connecting your eBay account (optional)
If you choose to connect your eBay account for purchase importing, we store an encrypted (sealed) eBay OAuth refresh token plus sync metadata; the token is encrypted at rest and is never exposed to your browser.
We import your eBay purchase and order data — item titles, seller usernames, prices, shipping, totals, timestamps, listing URLs, and the raw order record — so you can review and add purchases to your collection.
You can disconnect at any time. If eBay notifies us that you deleted your eBay account, we purge the eBay connection data we hold for you.
Service providers (subprocessors)
Supabase — database, authentication, and photo storage.
Google Cloud Run — application hosting and server logs.
Amazon SES — sending the deal-digest emails you opt into.
Sentry — error monitoring, configured not to capture IP addresses or personal data by default.
Plausible Analytics — privacy-friendly, cookie-free, aggregate visitor analytics on our public marketing pages only (no cross-site tracking, no personal profiles). It is not used inside your authenticated account.
GitHub — hosts the private issue tracker that documentation feedback you submit is copied into (see "What we collect" above).
Cloudflare — operates Turnstile, the anti-abuse check protecting our public forms (documentation feedback and the waitlist), and processes request data under its own terms.
Cookies
Inside your account we use only essential cookies required for sign-in and session security. We do not use advertising or cross-site tracking cookies. Plausible on our public pages is cookie-free.
Security & retention
Passwords are hashed, eBay tokens are sealed, and access is controlled and scoped to your account. We retain your data while your account is active and remove it when your account is deleted.
Exception: abuse-prevention data (see "What we collect") is retained for a fixed 30 days regardless of account status, since it must outlive sign-up attempts that never become an account.
Your rights
You can request access to, an export of, or deletion of your data by contacting privacy@serealbox.com. During beta these requests are handled manually. You can also delete most records directly within the app.
Optional improvement metadata
Any future use of anonymized metadata to improve the product, support AI features, or power shared/community features is separate from the operation of your account, is off by default, and will only happen if you explicitly opt in. It will be described and consented to separately before any such collection begins.