RAW ENGINE · RawGraded Data-flow overview · Dashboard

Legal

Privacy Policy

How RAW ENGINE products handle your data — RawGraded (web and Studio), Raw Investor (TCG desktop), and RawMarkets (markets terminal).

Effective date: June 8, 2026 · Publisher: RawGraded

1. Overview

RawGraded (operating as RAW ENGINE) publishes several related Windows and web products for collectors and investors. This policy describes what personal and usage data each product collects, where it is stored, and which third parties may receive it.

Products covered:

Raw Investor (TCG portfolio tool) and RawMarkets (finance markets terminal) are separate Windows applications under the RAW ENGINE umbrella. Each section below applies only when you use that product.

No third-party analytics or advertising telemetry (such as Google Analytics, Mixpanel, or Sentry) is embedded in any RAW ENGINE build described here. The marketing landing page may show a newsletter form; that form does not currently send email to our servers — it displays a thank-you message only.

2. RawGraded (Web and Studio)

2.1 RawGraded Web (cloud service)

When you use the web dashboard at rawgraded.com, account and grading data are processed on our servers (PHP/MySQL API). This section applies to browser access and any feature that uploads certificates to your online collection.

Account data Username, email address, and password (stored hashed on the server). Optional Google Sign-In provides a Google user ID (sub), email, display name, and profile picture. Optional X (Twitter) username. Invite codes at signup. Membership application answers if you apply before creating an account.
Authentication & security PHP session cookies to keep you logged in. Two-factor authentication (TOTP) with optional “remember this device” cookies (rg_totp, rg_totp_rm). Browser localStorage may cache your profile and 2FA tokens for convenience.
Grading & certificate data Card images (front, back, thumbnails), grades, defect analysis, metadata (name, set, year, edition, artist, rarity, etc.), user notes, estimated value, and optional acquisition details (price, tax, shipping, date, source, location, tracking number, order ID) uploaded to our database when you save a certificate.
AI processing Card images and prompts may be sent to Google Gemini for grading and analysis via our server queue. You may alternatively supply your own Gemini API key (bring-your-own-key); in that case requests go directly from your client to Google under your key.
Payments Subscriptions and credit purchases are processed by Stripe. We store Stripe customer and subscription identifiers — not full payment card numbers. Card data is handled by Stripe under Stripe’s privacy policy.
Public display Population statistics and public archive features may show certificate data you choose to make visible. Per-certificate hide controls and a global public/private mode are available in your vault settings.
Client cache IndexedDB (RawGradedVault) may cache certificate images locally in your browser for faster loading.
Third-party services Google OAuth and Gemini; Stripe; TCGDex and Pokémon TCG API for card identity; api.qrserver.com for QR code generation on certificates and 2FA setup. Google Sign-In is subject to Google’s Privacy Policy.
Technical data IP address, browser type, and request metadata in standard server logs for security and operation of the service.

2.2 RawGraded Studio (Windows desktop)

RawGraded Studio is a local-first Windows desktop app. Core grading and portfolio features do not require a RAW ENGINE cloud account.

If you also use RawGraded Web and sign in, the web service section above applies to data you upload to the cloud — not to local Studio-only workflows.

3. Raw Investor (TCG desktop)

Raw Investor (RawInvestor.exe) is a desktop-first TCG portfolio and market-analytics application published by RawGraded. By default, portfolio and capture data stay on the local machine.

Local storage SQLite portfolio database, scraped card images, extension capture records, and runtime data under the app’s Windows application data folder (%AppData% or portable pcgr-runtime-data beside the executable). Browser localStorage mirrors portfolio preferences, PSA token, collections, filters, and related UI state.
No vendor account Raw Investor does not require a RawGraded or Raw Investor login for core features. Local API tokens (PCGR_APP_TOKEN, extension tokens, etc.) secure loopback access only.
No cloud sync Your local portfolio database is not intentionally synced to a RawGraded cloud service by default.
Browser & marketplace sessions If you log into third-party sites (eBay, TCGplayer, PriceCharting) inside the embedded browser, that session belongs to you and is stored in the app profile. Optional cookie import from Edge/Chrome copies HTTP cookies for those domains only — browser password databases are not copied.
Browser extension An optional MV3 extension you load yourself posts tab captures to the local API at http://127.0.0.1:3001 — not to RawGraded servers.
Your API keys PSA public API token, eBay OAuth client credentials, and optional programmable web search keys (if configured) are stored in local portfolio metadata and/or localStorage.
Third-party requests When you trigger lookups, the app may contact PriceCharting, TCGplayer, eBay, PSA, GemRate, and other market data sources via automated page retrieval on your PC. Requests originate from your machine.
Updates If RAWENGINE_UPDATE_URL is configured, the app may contact that update host to check for or download releases.
Diagnostics Local capture and boot logs (e.g. rawengine-capture.log) under your app data folder for troubleshooting.

Your responsibility: secure the device where the app runs, control filesystem access to local app data, and comply with third-party marketplace terms when viewing or capturing data.

4. RawMarkets (markets terminal)

RawMarkets (RawMarkets.exe, branded in-app as Raw Investor — Markets Terminal) is a separate Windows desktop application for metals, equities, portfolio research, and news signals. It is local-first with no user accounts.

Local storage SQLite database (rawmarkets.db) including portfolio holdings and transactions, investor journal entries, news article cache, dashboard layout, engine settings, and cached API responses. Packaged builds store data under your Windows application data folder.
No accounts No login or user registration. Admin API routes require localhost access or an optional ADMIN_TOKEN header — not end-user identity.
Browser storage localStorage for pinned market symbols only. The app does not set analytics or session cookies.
Your API keys When you configure them, optional cloud AI, SerpApi, Alpha Vantage, and MetalPriceAPI keys are stored in the local SQLite api_keys table.
Third-party requests Background market readers may fetch Kitco, Yahoo Finance, Google Finance, and Coinbase for quotes. News and RSS feeds (SEC EDGAR, Reuters, Yahoo RSS, Stocktwits, Reddit, and others) are fetched when you use those features. SerpApi is used when enabled. Optional cloud AI analysis sends market context you select when you provide an API key. Local Copilot sends prompts to local AI on your machine when enabled.
Imports Statement CSV and Cash App CSV files you import are parsed and stored locally in portfolio tables.
Rate limiting Local AI chat may track your client IP in server memory briefly to throttle requests — not persisted to disk.
Payments RawMarkets has no Stripe, subscription, or in-app payment integration.

5. How we use data, retention, and your rights

Web service (RawGraded Web)

We use account and grading data to provide the service, process payments, secure accounts, and comply with law. We retain data while your account is active and as required by applicable law.

Under applicable data-protection laws you may have rights to access, correct, erase, restrict, or port your personal data, and to object to certain processing. Contact us using the details below to exercise these rights.

Desktop apps (Studio, Raw Investor, RawMarkets)

Data in desktop apps is primarily under your control on your device. Uninstalling or deleting app data folders removes local storage. Export features in Raw Investor let you copy portfolio data at your discretion.

Security

We use technical and organizational measures appropriate to each product. For the web service, access to personal data is limited to what is needed to operate the platform. For desktop apps, you are responsible for securing your PC and backups.

Policy updates

We may update this policy. Material changes will be reflected in the effective date above. Continued use after an update constitutes acceptance of the revised policy where permitted by law.

Governing law

This policy is governed by the laws of the State of Delaware, United States, without regard to conflict-of-law provisions, consistent with our Terms of Service.

6. Contact

Questions about this privacy policy or requests regarding your personal data:

For product-specific data-flow diagrams (not legal terms), see the landing page privacy overview.