Commercial API

Your card images and API data

A practical guide for developers and businesses integrating CardGrader.AI. Updated October 1, 2026.

This page supplements our Privacy Policy and API Terms. Image handling depends on the endpoint you use.

Grading-only requests

POST /v1/grades processes the front and back of a card and returns numeric condition grades. This endpoint does not add photos to a collection or upload them to our card-image storage.

Images pass through our hosting and grading infrastructure. The grader uses temporary files and schedules their removal after processing. This is not a guarantee of immediate deletion from every system: interrupted requests, diagnostics and infrastructure retention can have different lifecycles.

We retain the API account, request timestamps, usage and billing records, image hashes and numeric grading receipts. These records support result retrieval, duplicate-request protection, billing and security. Images and hashes should not be treated as anonymous merely because a card is the subject.

Prepaid scans have a different storage path

POST /v1/scans supports identification and other prepaid analysis. It stores submitted card images for processing and saved scan results. Choosing a commercial grading subscription does not change retention for prepaid scans on the same account.

If your integration needs grading without stored card photos, use the grading-only endpoint. Do not send requests to the prepaid scan endpoint expecting the same image handling.

Accounts, payments and service providers

We keep your application name, contact email, hashed API credentials, usage and subscription records. Stripe handles payment details and recurring billing; our application retains customer, subscription and invoice identifiers, not complete card numbers.

Our service uses Microsoft Azure for web hosting and data storage, plus grading infrastructure reached through ngrok. These providers and the infrastructure used for a request are part of its processing path. We do not currently offer a self-service EU-only processing location.

The API signup page does not load our Google Tag Manager or Ahrefs analytics scripts. Other parts of our website can use analytics and attribution technologies, as explained in the Privacy Policy.

Service improvement and data requirements

Our API Terms permit processing images and results to provide, operate, secure and improve the service. The grading-only endpoint does not itself create a training-image archive. This does not establish a contractual no-training commitment across every workflow.

If you need a no-training agreement, a fixed deletion deadline, a data processing agreement or a particular hosting region, contact us before sending production data. These are not self-service options or included guarantees in the standard subscription. We will confirm in writing what can be supported.

Access and deletion requests

Email support@cardgrader.ai from your API account contact address to request access, correction or deletion. Include your application name and the relevant grading or scan IDs. Never send API keys or payment-card details.

We verify the requester and review the records and processing paths involved. Account deletion may require retaining records for billing, fraud prevention, disputes or legal obligations. We do not currently provide an API operation that immediately erases every copy, log and backup.

Build with privacy in mind

  • Explain to your users that card photos are sent to CardGrader.AI for analysis, and obtain the permissions your product requires.
  • Photograph the card alone. Avoid faces, addresses, documents and other personal information in the frame or file metadata.
  • Keep API keys on your server. Use HTTPS and do not place keys in image URLs, browser code or support messages.
  • Send sharp, well-lit front and back originals, without sleeves, slabs, glare or edited defects. An AI grade is an estimate, not certification.

For EU/EEA or UK deployments, confirm your controller/processor responsibilities, required agreements and international-transfer arrangements before launch. A subscription purchase alone does not establish that your integration meets every data-protection requirement.

Plans and trial signup · Agent and REST quickstart · API Terms