Privacy
We fetch, parse, and forget.
This is a plain-English note, not a legal product. CardScope is a small utility. We try to collect as little as possible.
What happens when you check a URL
A Cloudflare Worker fetches the URL you submitted (and, if present, the preview image) from Cloudflare’s network. It reads Open Graph, Twitter, title, and description tags in memory, then discards the HTML. We do not store page HTML, cookies from the target site, or a screenshot of the live page.
What we do store
- Rate limits. For the free plan we store a hash of your IP address plus a count, keyed by UTC day, in Cloudflare KV. It expires within 48 hours. We do not store the raw IP.
- Pro licenses. If you buy Pro, we store a hash of your license key and the Stripe Checkout session id used to mint it. The key itself lives in an HttpOnly cookie on your browser unless you paste it elsewhere.
- Shared reports (Pro). A report is the parsed tag snapshot you already saw — not the HTML. It expires after 7 days. Anyone with the link can view it.
What we don’t do
- No user accounts, no mailing list, no “growth” pixels on this app.
- No selling of URLs you check.
- No live-page screenshots. Previews are reconstructed from meta tags.
Third parties
The app runs on Cloudflare (Workers, KV, and the request logs that come with that). Stripe processes the $19 one-time Pro payment. We do not invent or embed Stripe keys in this repository.
Your choices
Don’t submit URLs you are not allowed to fetch. If you use Pro, treat the license key like a password. To drop the local license cookie, you can clear site cookies for this origin.