Privacy Policy
Last updated: September 1, 2026
MADI (Meta Analysis Data Interface) is operated by Fernlume Labs LLC. It helps card, comic, and collectible shops scan items, grade and price them, list them to their sales channels, and price customer collections for buy offers. This policy explains what data MADI collects, how it is used, and who it is shared with.
What we collect
- Account & shop details. Your name, email, and the shop you belong to, used to sign you in and keep each shop’s data separate and private to its members.
- Item photos. Photos you capture are sent to our AI provider to identify the item and draft its listing; condition grades are estimated by MADI. A resized copy is stored so it can appear in your inventory and be listed later. See How long we keep it below, which is more specific than “we delete them”.
- Item & inventory data. Titles, categories, grades, prices, buy-offer cost, and the timeline of actions on each item, stored for your shop.
- Connected credentials. If you connect eBay or Shopify, those tokens are stored encrypted at rest and used only to list on your behalf. We never see your passwords for those services. MADI no longer accepts an AI provider key from you; scanning runs on our own.
- Usage. Counts such as scans per period, to operate your plan, plus standard server logs for reliability and abuse prevention.
- Notifications. If you turn on push notifications, your browser gives us a subscription for that device so we can send them. Turning them off removes it.
Who we share it with
We use a small set of service providers to run MADI, and share only what each needs to do its job:
- Google (Gemini) - reads your item photos to identify the item and write the listing text, and fills in item specifics when you publish to eBay.
- PriceCharting and sold-comps.com - provide market prices and recent sold prices for matching. They receive the item details being priced, not your photos.
- Pokémon TCG API - provides card data and official card images when a scan is a trading card.
- eBay and Shopify - receive a listing only when you choose to publish to them.
- Supabase (database, sign-in, photo storage) and Vercel (hosting) - store and serve the app.
- Cloudflare - runs the check that tells a person from a bot on the sign-in and sign-up screens.
- Stripe - processes payments when billing is enabled. Card details go directly to Stripe and are never stored by MADI.
We do not sell your data, and we do not share it for advertising.
How long we keep it
- Photos of items you have listed or sold are deleted about a week after the item was created, because by then they are live on the marketplace or the item is gone.
- Photos of items still in your inventory are kept until you remove the item. They are what lets you list it later, so deleting them on a timer would break the queue they belong to.
- Item and inventory records are kept for as long as your shop exists, so your history and sales figures stay intact.
- Demo sandboxes are deleted automatically about three days after they are created, along with the anonymous account that made them.
The demo
Trying the demo creates an anonymous account with no email and no password, and a sandbox shop stocked with sample items. Scans in the demo return a prepared sample result - your photo is not read by the AI, and no listing is ever published. The sandbox and its anonymous account are deleted automatically after about three days.
Your control
- Disconnect any channel or remove a stored key at any time in Settings.
- Remove any item you have scanned, which removes its stored photos.
- Turn push notifications off at any time to remove that device.
- To export or delete your shop’s data, or close your account, contact us and we will take care of it.
Contact
Questions about this policy or your data can be directed to the shop owner who operates your MADI account, or to Fernlume Labs LLC at support@madi-scan.com.