Privacy policy
Last updated: 4 October 2026
PokeScan is an IV scanner and battle planner for Pokémon GO. It is built so that your data stays on your device unless you choose otherwise: scanning works entirely in your browser, and only features you actively use — an account, sync, or the AI features in Pro — send data to a server. This page says exactly what leaves your device, where it goes, and why.
Who is responsible
The data controller is Martijn Veenstra, sole trader (eenmanszaak) registered with the Dutch Chamber of Commerce (KvK) under number 42120153, operating PokeScan. Contact: martijn.veenstra84@gmail.com.
What stays on your device
Screenshots and recordings you scan are opened and measured on your device, in your browser; the whole image is never uploaded. To turn the text in them into words, the app sends only small crops (the numbers, the Pokémon's name, a few lines of text) to our own server, which reads them and keeps nothing. Without an account, your scans, roster, teams, battle log and settings live only in this browser's storage and are sent nowhere. The schedule of events and raids is fetched from public sources, which see your IP address like any website you visit does.
What leaves your device, and when
| When you… | What is processed | Where |
|---|---|---|
| Create an account and sign in | Your e-mail address, name if you provide one, and session tokens | Clerk (auth provider), our server |
| Sync your data | Your scans (Pokémon stats, no images), roster, teams, battle log and progress, stored under your account id | Our server (Railway, Postgres database) |
| Subscribe to Pro | Payment details, e-mail and a customer id — handled by Stripe; we never see your card number | Stripe |
| Use the AI coach (credits) | A text summary of your roster, team or battle — no images, no account details | Our server → DeepSeek |
| Import a screenshot or a battle recording | Small crops of the screenshot: numbers, the Pokémon's name, a few lines of text. Not stored | Our server only (no third party) |
| Send feedback | Your message, its kind (idea, bug, other), the app version and phone type, your account id when signed in, and an e-mail if you leave one (only to answer you). Kept until handled | Our server, and GitHub as an issue in our private repository |
| The app hits an error | A trimmed error message and stack trace — no personal data, no images | Our server (logs) |
Our processors
- Clerk (US) — accounts and sign-in. Legal basis: performance of the contract. When we move to a new sign-in service, your new account takes over your old one if both have the same verified e-mail address.
- Stripe (US/EU) — payments and subscription management. Legal basis: performance of the contract and legal obligations (bookkeeping).
- DeepSeek (China) — the AI model that writes team and battle reviews, only when you ask for one. It receives a text summary of your roster, team or battle: no images, no account details. Legal basis: performance of the contract (you ask for the feature).
- Railway (US) — hosting of the server and the Postgres database that holds synced data.
- GitHub (US) — the event schedule is fetched from raw.githubusercontent.com, which sees your IP address (legitimate interest: showing the schedule); feedback you send is filed as an issue in our private repository there, which only we can read (legitimate interest: answering and acting on it).
Some of these providers are outside the EU: in the United States, and DeepSeek in China. Transfers to the United States rely on the EU–US Data Privacy Framework or standard contractual clauses, depending on the provider; a review sent to DeepSeek is a transfer you ask for each time you request it.
How long we keep things
- Synced data: for as long as you keep it in your account. You can delete it at any time (below).
- History snapshots: the server keeps up to 50 recent snapshots per data type to guard against data loss; old ones are pruned automatically. Deleting your synced data deletes these too.
- AI jobs: a review or screenshot read lives in server memory for at most one hour and is never written to disk. The screenshot itself is not stored.
- Credits: your credit balance and a ledger of every change (a trial grant, a monthly reset, a pack you bought, a request and its refund) with a reference to the Stripe payment or the request. Kept for as long as your account has credits, and the ledger for 7 years for bookkeeping. Never the content of a request.
- AI usage records: for every AI request we store your account id, which feature it was, the model that answered, how many tokens it used, what it cost us and whether it worked. Never the text, screenshot or answer itself. We use this to keep the costs fair and to spot abuse, and delete each record after 13 months. Legal basis: legitimate interest (running a paid AI service at a sustainable cost).
- Payment records: Stripe retains what tax law requires; we keep your subscription status and a Stripe reference, not your payment details.
- Server logs: kept briefly for operations and debugging, then rotated away.
Your rights
You can ask for access to, correction of, or deletion of your personal data, ask us to restrict or stop processing, and take your data elsewhere (portability). In the app: account box → Delete my synced data removes everything stored under your account on the server, and the Export button gives you a full copy. Deleting your Clerk account removes your sign-in data. For anything else, e-mail martijn.veenstra84@gmail.com — we answer within 30 days.
If you believe we handle your data unlawfully, you have the right to complain to the Dutch supervisory authority, the Autoriteit Persoonsgegevens.
Changes
When this policy changes in a way that matters, the date above changes and the app points it out. Questions: martijn.veenstra84@gmail.com.
PokeScan is not affiliated with Niantic or The Pokémon Company. See also the terms of service.