Privacy Policy
Last updated: September 28, 2026
1. Introduction
This Privacy Policy defines the procedure for processing information by the eyeCARD service (hereinafter referred to as the Service). The Service is designed to conduct neuromarketing audits of product cards and provide analysis results to users.
2. Account and Authentication Data
To access the Service, a user creates an account using a Telegram username as a login and a password set by the user. The following account data is processed:
- Telegram username (login) — used as a unique account identifier. The Service does not collect email addresses or phone numbers.
- Password hash — the password is stored only as a bcrypt hash. The plain-text password is never stored.
- Telegram ID (chatId) — used solely for sending completed reports and system notifications via the Telegram bot.
- JWT token — a session token stored locally in the browser (for the web app) or in
chrome.storage.local(for the extension) to authenticate API requests. - Auth channel — indicates the messenger used for report delivery (Telegram, VK, etc.).
3. Processed Technical Information
To ensure the functionality of the Service and timely delivery of completed reports (Visual Passports), the Service stores the following technical information:
- Account identifiers — Telegram username, Telegram ID, and internal user ID.
- Balance data — the number of eyeCARD Coins associated with the account.
- Analysis metadata — job identifiers, timestamps, and delivery status, used to provide history and send reports.
- Technical data transmitted automatically — IP address, cookies, browser information, time of access, and requested page address. Cookies are not used to establish the user's identity.
4. Analysis of Publicly Available Images
The Service performs visual and semantic audits based on product images that are freely and publicly available on marketplace pages (Wildberries, Ozon, etc.). The Service does not collect, analyze, or transmit confidential graphic materials or closed seller data.
5. Data Security and Protection
We take the security of account data seriously:
- Passwords are stored as bcrypt hashes; plain-text passwords are never retained.
- All API communication is performed over HTTPS.
- JWT tokens are stored in secure browser storage and are not shared with third parties.
- Telegram username, Telegram ID, and account data are stored in Google Firestore with restricted access and are used only by automated Service modules.
6. Data Retention and Deletion
Account data is stored for as long as the account remains active. Users may request deletion of their account and associated data by contacting support@eyecard.ru. Upon request, the Service will remove the Telegram username, Telegram ID, analysis history, and balance information in accordance with applicable law.
7. Children's Privacy
The eyeCARD service is not intended for individuals under the age of 13. We do not knowingly collect personal data from children under 13. If we become aware that we have received such information, we will immediately delete it from our database.
8. Changes to This Policy
The Service reserves the right to make changes to this Privacy Policy at any time. Changes take effect from the moment they are published on this page.
9. Contact Information
If you have any questions or suggestions regarding this Privacy Policy, please contact us by email: support@eyecard.ru.