Privacy — PokéItem Chrome extension

Last updated: 20 August 2026

The extension has no server of its own.

  • →The title and the price read from the page are sent to app.pokeitem.fr to identify the card and fetch its price.
  • →The listing photo is sent too, in one specific case, and without you clicking anything — when the text is not enough to identify the card. The "The listing photo" table further down says exactly when, and how to turn that off.
  • →If you are already signed in to PokéItem in Chrome, your NextAuth cookies are used to read your binder and your wishlist. Nothing is stored with a third party.
  • →The history of the last 15 cards stays in chrome.storage, on your own Chrome profile.
  • →Watched listings ("Watch this listing") also stay in chrome.storage.local, on your own Chrome profile — 50 at most, never sent anywhere. Their price only updates when you reopen the listing: the extension never checks a page in the background.
  • →No data is ever sold. eBay links use the affiliate programme already in place in the PokéItem app.

Listings reported to improve prices

Changed on 19/08/2026 — until now this was an optional setting, off by default. That setting no longer exists: it was removed from the code, it has no replacement, and the extension offers no way to refuse this reporting. It now also covers listed items — the price badges on results pages — not only the ones whose panel you open: on a results page, every listing the extension prices along the way is sent, without any click from you. The scope of what is sent, field by field, had not changed that day.

Changed on 20/08/2026 — one field joins the "What is sent" table: the listing's declared condition (Near Mint, excellent, good, played, poor), when the seller stated it or the title says so. It is a property of the public listing, not of the seller nor of you, and it is used to refine per-condition prices. Nothing else changed.

Leboncoin and Vinted have no public API: the only French listings anyone can observe are the ones somebody is looking at. The listings the extension prices are therefore shared to refine everyone's prices.

When — every time the extension prices a listing and the card has been identified unambiguously, whether you opened the listing page or the extension simply placed a price badge on a results page. On a list page this happens without any click from you, for every listing priced.

If the extension hesitates between several cards, it offers you a list and reports nothing: a guessed card pollutes a price instead of improving it. Nothing is ever sent either for a bundle, a sealed product, a site other than Vinted / Leboncoin / eBay / Cardmarket, a page the extension could not read, or a page it could not prove was really about the listing on screen. The same listing at the same price is sent only once per session; sends are batched in twenties.

What is sent — the listing, nothing else:

FieldExample
Site + listing identifierleboncoin · 3201211495
URL with no parameters (query string and anchor stripped)https://www.leboncoin.fr/ad/collection/3201211495
Listing titleKangourex 5/64 1ère édition CCC 8
Price + currency279 · EUR
Pricing language, grading, editionFR · CCC 8 · 1st edition
Declared condition (the tier alone, when known — otherwise nothing)excellent
Matched card + observation datecard_xxx · 2026-08-18T12:00:00Z

What is NEVER sent in this report:

  • →no seller data whatsoever — not their name, not their profile, not their rating, not their review count (the extension reads them to warn you on screen; they stay local);
  • →no identity of yours — your account is used to authenticate the send to app.pokeitem.fr and to rate-limit it; your account identifier is not passed any further (but read "What the server adds" below: the relay attaches a pseudonym derived from that account);
  • →no browsing history: not the pages without a listing, not your searches, not any site outside Vinted / Leboncoin / eBay / Cardmarket;
  • →neither the description, nor the listing photos, nor the messages. ⚠️ This line only holds for this report. The photo does leave, by another route — the scanner's — and the "The listing photo" table further down says which.

Where it goes — the extension only ever talks to app.pokeitem.fr. It is the PokéItem server that relays the listing to its pricing service (api.tcgapi.io) using its own key: the extension holds none. Contributed listings are used solely to compute prices; they are not sold, and they do not carry your identity — they do carry a stable pseudonym, described right below.

What the server adds

The final recipient therefore receives a field the extension does not send, and that has to be said. The extension emits nothing beyond the tables above, but since August 2026 the PokéItem server attaches to every relayed listing a non-reversible pseudonym derived from your account: HMAC-SHA256(server secret, account identifier), truncated to 16 hexadecimal characters. It is computed on the server; the extension never sees it and cannot forge it — the relay overwrites any value that reaches it.

It lets the pricing service establish that two different people saw the same listing: that is the only way to tell a corroborated observation from an isolated one, since the entire extension fleet goes through a single technical key. It is stable (the same account always yields the same pseudonym) but the recipient cannot trace it back to your account: the secret that computes it never leaves the PokéItem server, and it can be rotated. Your account identifier itself is still never transmitted.

What you can refuse

Of this reporting, nothing, within the extension. There is no setting, no checkbox, no "turn off contribution". The only ways to report nothing are to uninstall the extension, disable it in chrome://extensions, or not use it on a listing page. This is stated plainly because it is the truth of the binary. (Sending the photo, on the other hand, can be switched off — see the next section.)

The listing photo

The PokéItem scanner reads a listing's photo to recognise the card when the text is not enough. It also fires on its own, and that has to be said plainly: it is not only "on request".

When the photo is sentYour actionSetting that stops it
Automatic fallback: the listing is open, the panel shows up on its own (autoOpen, on by default), and neither the title nor the description names a cardnone — you clicked nothing"Identify the photo when text isn't enough" (autoIdentify), on by default
"Identify the photo" buttonyou click—
"Upload an image"you pick the file—
Right-click on an image → "Identify this card"you click—

What is sent: the image alone, resized, to https://app.pokeitem.fr/api/scanner/identify — together with your pricing language, and nothing else from the page: not the description, not the seller, not the title. A scan uses 1 credit from your account.

Three limits hold the automatic fallback, and they are written into the code: one attempt per listing only, never while the panel is closed, never on Cardmarket (the product page there names the card, a scan would learn nothing). Untick "Identify the photo when text isn't enough" (panel → Settings, or the options page) and no photo leaves again without you asking for it: it is the only switch in this extension that genuinely stops a send.

The extension is one module of PokéItem: the processing of your PokéItem account data is described in the service's privacy policy. Questions or reports: contact@pokeitem.fr.