Privacy policy
Last updated:
This policy covers the CardLens browser extension, developed by Tomasz Jasek. For privacy questions or requests, contact tomasz@tjasek.com.
What happens when you use CardLens
When you press the recognition shortcut over an image or video, CardLens takes a temporary screenshot of the visible tab. This can include other visible page content before it is cropped to the media area. The screenshot and crop are processed in memory on your device; they are never saved to persistent storage, uploaded, or shared with a server. No capture or recognition runs while idle.
Card recognition and name search use software and card data bundled with the extension. Search queries and recognized text are not sent to a server. CardLens has no accounts, advertising, analytics, telemetry, or recognition server. It does not read your browser history, cookies, or form entries.
Card images from Scryfall
When a card is recognized or you select a search result, CardLens automatically requests its image from cards.scryfall.io or images.scryfall.io unless it is already cached. Scryfall and its hosting providers receive the requested image address and ordinary connection information, including your IP address. The image address identifies the card being displayed. Requests use HTTPS and omit credentials and referrers; they do not include screenshots, the page URL, search queries, or recognized text.
These requests are subject to Scryfall’s privacy policy. Recognition and search work offline; uncached card images need a connection.
What stays in your browser
Local extension storage holds your shortcut preference, hostnames where you disabled CardLens, a timestamp used to limit capture frequency, and a cache of recent card images and their identifiers and last-used times. The cache is limited to 12 images and approximately 3 MB, with older entries removed as needed.
Local diagnostics record recognition counts, outcomes, and timings, without screenshots, page URLs, or recognized text. In Chrome these diagnostics use session storage and are cleared when the browser session ends. Preferences and cached images remain until replaced or the extension’s storage is removed. Uninstalling CardLens removes its extension storage.
Permissions and your controls
Website access lets CardLens detect the pointer and shortcut, display results, and capture the visible tab when you request recognition. Active-tab access identifies the current website for the popup; scripting and offscreen processing support the interface and local recognition; storage saves the data described above. CardLens starts enabled on ordinary websites. You can disable it per website in the popup, restrict website access in Chrome’s extension settings, or uninstall it.
CardLens uses browser data only to provide these features. It does not sell user data or use it for advertising, profiling, or unrelated purposes. Its use of information received from Google APIs follows the Chrome Web Store User Data Policy, including the Limited Use requirements.
Contact and updates
If you email me, I receive your email address and the information you choose to share. I use it to respond and keep the correspondence only as needed to handle your request or meet legal obligations. You can request access, correction, or deletion by emailing tomasz@tjasek.com. Changes to this policy will appear here with an updated date.