Privacy Policy
1. Who we are
Sylera (“we”) operates the Sylera mobile application — the house of Collectors — for discovering Pokémon trading cards, managing a Vault, chasing cards, finding other collectors, chatting, and scanning cards.
Contact: support@sylera.co.il. Legal entity details will be published before public launch.
2. Who this policy covers
This policy applies to the Sylera Android app identified as com.sylera.app, and to this website when you use pages such as Privacy, Delete Account, and Support. It does not describe third-party websites or catalog art owned by others.
You must be 16 or older to use Sylera. We do not knowingly offer the service to children under 16.
3. Information we collect
Account and authentication
Phone number is required. Sylera uses Google Firebase Authentication for phone sign-in (SMS / device verification). We store the number in E.164 format on your private account.
Real name (given name and family name) is collected during profile setup and stored privately as a combined real name. It is not shown on your public profile.
Email is optional. If you add one, Sylera only keeps it on your private account after it is verified through Firebase Auth. Email is not shown on your public profile.
We also store terms and privacy acceptance version and timestamp, notification preferences, and an account role flag.
Public profile (visible to signed-in collectors)
Other people signed in to Sylera may see:
- Nickname (public handle)
- City (you type this) and country (ISO two-letter code)
- Bio and collect focus
- Optional profile photo (avatar)
- A “verified phone” badge (not your phone number)
- Server-computed reputation counts: rating average, number of ratings, deals, and card counts
Your phone number, real name, and email are not part of the public profile. Chase cards are stored on your private account and are not copied onto the public profile document.
Country and city — not GPS
Sylera does not collect GPS precise or approximate location. We do not request device location permission for mapping you.
Country is an ISO country code inferred from your phone dialing prefix or device language/region settings, with a fallback if those are missing. City is text you enter. These are personal/profile fields, not device GPS.
Language preference is stored on your device only (not as a cloud profile field).
Vault, Watch, and Chase
Vault entries record cards you own or want (catalog id, status, variant, timestamps). Watch entries record cards you follow. Chase entries record cards you are hunting, including optional variant and country code used for matching.
Discoverable Vault statuses (for example available, trade-only, or wishlist) can be used so signed-in collectors in the same country can find you for that card. That discovery list may include your public nickname, city, photo, ratings, and the card status/variant — not your phone, real name, or email.
Chat, deals, vault shares, and reviews
- Direct messages: text you send, timestamps, and optional card context. Messages are stored so both participants can read the thread. They are not end-to-end encrypted.
- Deal completion records between two participants.
- Vault shares: a snapshot of selected card ids/statuses/variants shared with a chat partner (not your private notes).
- Reviews after a completed deal: star rating and optional text, shown on relevant profiles to signed-in users.
Reports
If you report a message or conversation, Sylera stores reporter and reported user ids, reason, optional details, and — for message reports — a copy of the reported message text as moderation evidence. Clients cannot read the reports collection.
Notifications and device identifiers
To send push notifications (for example Chase matches or chat), Sylera may store:
- An FCM (Firebase Cloud Messaging) device token
- A random installation identifier created on the device
- Platform (Android/iOS) and app version
In-app notification items (titles and routing ids) are stored for your account. Chat push payloads use routing ids; they do not include the full message body.
Subscriptions (Sylera Pro)
If you subscribe through Google Play, Play Billing processes the purchase. Sylera’s servers verify the purchase with Google Play and store subscription status, product id, store, expiry, auto-renew flag, and a hashed purchase identifier — not the raw Play purchase token in that billing link record.
Card scanner and camera
The scanner uses the camera (and on-device recognition). Captured scanner images are processed locally on your device. Sylera does not upload, store, or share those scan photos. A successful scan may increment a monthly usage count on your private account (a number only — not the image). Optional profile avatars, if you choose one from the gallery, are uploaded to store your public photo.
On-device preferences
The app may keep local preferences such as language, selected Vault list, terms-acceptance version, and the installation identifier. Those live on the device and are not fully cleared by server-side account deletion.
4. How we use information
- Create and secure your account (phone verification, trust)
- Show public profiles and card discovery to other signed-in collectors
- Operate Vault, Chase, Watch, chat, deals, reviews, and notifications
- Enforce usage limits (for example scanner and Chase quotas)
- Verify Play subscriptions
- Moderate abuse reports and protect the service
- Honor legal and accounting obligations for purchases
Marketing push is off by default in notification preferences. We do not run advertising or analytics SDKs in the current app package (no Firebase Analytics or Crashlytics dependency in the current product).
5. Who we share with
Other collectors (inside Sylera)
Public profile fields listed above; discovery results for a card; chat and vault-share content with conversation participants; reviews with signed-in users viewing a profile.
Service providers
- Google Firebase (Authentication, Cloud Firestore, Cloud Functions, Cloud Storage, Firebase Cloud Messaging) to run the app backend. Functions used by these features run in Google Cloud region europe-west1 as configured in the current project.
- Google Play Billing and the Google Play Developer API to purchase and verify Sylera Pro.
- TCGdex (api.tcgdex.net) for Pokémon catalog data and related card information. The app sends catalog queries (for example card or set identifiers, search names) — not your phone number, real name, or email — in those catalog requests.
- On-device Google ML Kit text recognition and ONNX Runtime for scanning; these run locally in the current implementation.
Google and other providers process data under their own terms. SMS for phone sign-in is delivered through Firebase / Google.
This website does not use analytics, advertising, cookies, or marketing scripts.
6. Security
Traffic to Firebase and this site is designed to use HTTPS. Access to private account documents is restricted to the signed-in owner by server rules. Chat is not end-to-end encrypted. No method of transmission or storage is perfectly secure.
7. Account deletion and retention
You can delete your account in the app: Settings → Account → Delete Account. You can also request deletion by emailing support@sylera.co.il (see Delete Account). We may need to verify that you control the account.
Deletion does not erase every record. In the current implementation:
Deleted
- Private account document (including phone, real name, email, prefs)
- Firebase Authentication user
- Profile avatars in storage
- Vault collections and list items, Watch entries, Chase cards
- Device tokens / installation records for push, scanner usage counts
- Your in-app notification inbox and hidden-chat markers
- Nickname reservation
- Reverse discovery indexes (who owns / who is chasing a card) for your account
- Short-lived chat send-rate counters
Anonymized
- Public profile: nickname replaced with “Deleted collector”; bio, city, photo, and similar public fields cleared; profile hidden from discovery
- Conversation nickname and photo labels for your user id, so the other collector still has the thread without your public identity
May be retained (limited, for a legitimate reason)
- Billing / accounting: purchase-link records and a subscription row marked as account-deleted (hashed Play identifiers, plan/status — not your public profile)
- Fraud, security, and moderation: chat reports, including reported message text held as evidence
- The other participant’s history: message text, deals, reviews, and vault-share snapshots they already received. Those records keep user ids and the content of the exchange; they do not keep your public nickname, photo, city, or country on the profile tombstone
Historical notification titles on someone else’s device may still show an old nickname. Message bodies are not rewritten. Local data on your phone is not wiped by the server.
8. Card catalog and trademarks
Card names, set information, and art come from catalog sources (including TCGdex). Trademarks belong to their owners (for example The Pokémon Company). Sylera does not provide licensed market prices as a guaranteed product feature.
9. International processing
Account and app data are processed using Google Firebase / Google Cloud. Current callable functions are configured in europe-west1. Your information may be processed in other countries where Google operates, according to their terms.
10. Changes
If this policy changes in a way that requires a new in-app acceptance, the app terms version will be updated. The effective date at the top of this page will change when the public policy is updated.
11. Contact
Questions about privacy or deletion: support@sylera.co.il.