Privacy Policy

Last Updated: December 8, 2025

1. Introduction

ComicGrades ("we", "us", or "our") respects your privacy and is committed to protecting your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service.

By using ComicGrades, you agree to the collection and use of information in accordance with this policy.

2. Information We Collect

2.1 Information You Provide

  • Account Information: Email address when you create an account.
  • Payment Information: Payment details are collected and processed by Stripe, our payment processor. We do not store your full credit card information.
  • Comic Images: Photos of comic books you upload for grading.
  • Communication: Information you provide when contacting customer support.

2.2 Automatically Collected Information

  • Usage Data: Information about how you use the Service, including grading history and feature usage.
  • Device Information: IP address, browser type, operating system, and device identifiers.
  • Cookies: We use cookies and similar tracking technologies to maintain your session and improve the Service.
  • Log Data: Server logs including timestamps, page requests, and errors.

2.3 Information from Third Parties

  • Stripe: Payment confirmation and subscription status information.
  • eBay: Market pricing data for comics (no personal information).

3. How We Use Your Information

We use the information we collect to:

  • Provide and maintain the Service, including AI grading analysis.
  • Process and manage your subscription and payments.
  • Store your grading history and uploaded images.
  • Send you service-related communications (e.g., subscription confirmations, billing notices).
  • Respond to your customer service requests and support needs.
  • Monitor and analyze usage patterns to improve the Service.
  • Detect, prevent, and address technical issues and security threats.
  • Comply with legal obligations and enforce our Terms of Service.
  • Send you marketing communications (you may opt out at any time).

4. AI Processing and Image Usage

When you upload comic book images for grading:

  • Images are sent to OpenAI's API for AI analysis to generate grade estimates.
  • OpenAI processes images according to their own data usage policies.
  • Images are stored on our servers to provide your grading history.
  • We do not use your images to train AI models without your explicit consent.
  • We do not share your images with third parties except as necessary to provide the Service (e.g., OpenAI for analysis).
  • You retain all rights to images you upload.

5. How We Share Your Information

We do not sell your personal information. We may share your information with:

5.1 Service Providers

  • Stripe: Payment processing and subscription management.
  • OpenAI: AI image analysis for comic grading.
  • eBay: Retrieving market pricing data.
  • Hosting Provider: Server hosting and data storage.

5.2 Legal Requirements

We may disclose your information if required to do so by law or in response to:

  • Valid legal processes (subpoenas, court orders).
  • Government requests.
  • Protection of our rights, property, or safety.
  • Prevention of fraud or illegal activity.

5.3 Business Transfers

If ComicGrades is involved in a merger, acquisition, or asset sale, your information may be transferred. We will provide notice before your information becomes subject to a different privacy policy.

6. Data Security

We implement appropriate technical and organizational security measures to protect your information, including:

  • Encryption of data in transit using SSL/TLS.
  • Secure storage of images and data.
  • Regular security assessments and updates.
  • Access controls and authentication requirements.
  • Payment processing through PCI-compliant providers (Stripe).

However, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security of your information.

7. Data Retention

We retain your information for as long as:

  • Your account is active.
  • Needed to provide you services.
  • Required to comply with legal obligations.
  • Necessary to resolve disputes and enforce agreements.

When you delete your account, we will delete or anonymize your personal information within 90 days, except where we are required to retain it by law.

8. Your Privacy Rights

Depending on your location, you may have the following rights:

8.1 Access and Portability

  • Request access to your personal information.
  • Receive a copy of your data in a portable format.

8.2 Correction and Deletion

  • Correct inaccurate personal information.
  • Request deletion of your personal information (subject to legal retention requirements).

8.3 Objection and Restriction

  • Object to processing of your personal information.
  • Request restriction of processing in certain circumstances.

8.4 Marketing Communications

  • Opt out of marketing emails at any time using the unsubscribe link.
  • You will still receive service-related communications (billing, security alerts).

To exercise these rights, please contact us through your account settings or at the contact information provided below.

9. California Privacy Rights (CCPA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):

  • Right to know what personal information we collect, use, and disclose.
  • Right to request deletion of your personal information.
  • Right to opt out of the sale of personal information (we do not sell personal information).
  • Right to non-discrimination for exercising your CCPA rights.

10. European Privacy Rights (GDPR)

If you are located in the European Economic Area (EEA), you have rights under the General Data Protection Regulation (GDPR):

  • Right of access to your personal data.
  • Right to rectification of inaccurate data.
  • Right to erasure ("right to be forgotten").
  • Right to restriction of processing.
  • Right to data portability.
  • Right to object to processing.
  • Right to withdraw consent at any time.
  • Right to lodge a complaint with a supervisory authority.

Our legal basis for processing your personal data includes: performance of a contract, legitimate interests, and your consent.

11. Children's Privacy

Our Service is not intended for users under 18 years of age. We do not knowingly collect personal information from children under 18. If you are a parent or guardian and believe your child has provided us with personal information, please contact us, and we will delete such information.

12. Cookies and Tracking Technologies

We use cookies and similar technologies to:

  • Maintain your session and keep you logged in.
  • Remember your preferences.
  • Analyze how you use the Service.
  • Detect and prevent fraud.

You can control cookies through your browser settings. However, disabling cookies may affect the functionality of the Service.

13. International Data Transfers

Your information may be transferred to and processed in countries other than your country of residence. These countries may have different data protection laws. We take appropriate safeguards to ensure your information remains protected in accordance with this Privacy Policy.

14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by:

  • Posting the new Privacy Policy on this page.
  • Updating the "Last Updated" date.
  • Sending you an email notification for significant changes.

Your continued use of the Service after changes become effective constitutes acceptance of the revised Privacy Policy.

15. Third-Party Links and Services

Our Service may contain links to third-party websites. We are not responsible for the privacy practices of these third parties. We encourage you to read their privacy policies.

16. Contact Us

If you have questions or concerns about this Privacy Policy or our privacy practices, please contact us through:

  • Your account settings
  • The contact information provided on our website

We will respond to your request within a reasonable timeframe, typically within 30 days.

17. Data Protection Officer

For GDPR-related inquiries, you may contact our Data Protection Officer through the contact methods provided above.