FAQ & troubleshooting

Scanner can’t read my card

Use stronger lighting, keep the full grid inside frame guides, and avoid glare. You can always switch to manual edits.

Camera permission was denied

Open device settings and re-enable camera permission for BingoFlow.

Does my card image leave my device?

Every Scan starts locally. With separate Cloud permission and server-verified funding, Cloud assistance checks all 24 numbers before you review the card, including confident local predictions. The prompt offers “No thanks” and “Allow Cloud Help”; Settings lets you change your choice. BingoFlow strips image metadata and sends a bounded, metadata-stripped crop of the frozen scan frame through BingoFlow/Cloudflare to OpenAI. It includes the card’s five number rows and printed BINGO header, and may include background visible inside the scan frame. Keep only one card in the frame and avoid personal information. Cloud reads the captured card independently of local perspective rectification. The original full-scene camera image outside the scan frame is not sent. BingoFlow does not persist Cloud-assistance images or result card values. At most one server-authorized orientation retry is allowed. OpenAI API data is not used to train models by default. Default abuse-monitoring logs may retain content for up to 30 days, or longer when required by law or needed to prevent harm; flagged images may be kept for manual child-safety review even under stricter retention controls.

Funding uses a protected anonymous installation credential, a server-assigned RevenueCat customer binding, app-integrity proof, and bounded funding/security records without card values. An opaque, single-scan nonce connects a rewarded ad to signed server verification. These credentials and funding records are not sent to OpenAI or included in model contributions. Scan-operation records are scheduled for deletion 30 days after grant expiry. Verified reward credits and replay records last 365 days from verification; unused credit can fund a later scan. The anonymous billing identity is removed after 365 days without funding activity once no grants or credits remain. See the privacy policy for data handling.

What if I do not want Cloud assistance?

Choose “No thanks” or turn Cloud Help off later in Settings. Free users can choose a rewarded ad for each check; server-verified Pro bypasses the ad. A client ad callback or cached Pro flag alone cannot authorize Cloud. Declining, being offline, an unavailable ad, pending proof, or a service failure keeps the local result with uncertain or incomplete cells marked for review. Separately consented model improvement can still use reviewed local-only outcomes. Existing purchasers may need Restore Purchases to verify ownership for Cloud checks.

When does BingoFlow ask me to help improve scanning?

Reviewed-scan sharing is off by default. When it is fully available, BingoFlow shows the one-time “Help improve scanning?” disclosure after camera access succeeds and before the scanner opens. “Share reviewed scans” requires an affirmative tap; the equal “No thanks” option leaves scanning, local review, Cloud assistance, and manual entry unchanged and prevents another prompt for the current disclosure. You can later opt in or withdraw in Settings. Cloud permission alone never enables contribution or training. If the program is not completely configured, no contribution prompt appears and nothing is collected or shared.

What can Help improve scanning share?

Availability is fail-closed: without complete signed configuration for your platform with capture enabled, consent and protected local capture remain disabled and no model-contribution sample is collected or shared. A complete cleanup-only configuration also keeps consent and new capture disabled while preserving status/deletion cleanup for existing work. A matching private service and retention policy are operator prerequisites, not an online consent gate. If the service is unavailable, upload acceptance fails closed while queued samples remain protected locally within the retention limits. Android sharing additionally requires a hardware-backed key and successful Google Play app, device, and licensing checks; unavailable checks cannot authorize an upload.

The opt-in path is limited to exactly 24 metadata-free 112x112 grayscale number-cell PNG crops plus bounded recognition, quality, version, reviewed-label, correction, integrity, and retry metadata. It excludes the original camera scene, EXIF/location data, device private keys and raw installation key IDs in training data, and account/advertising identifiers. During upload, the private service receives the Cloudflare-provided IP address, keyed-hashes it for abuse prevention, security, deletion, status, and audit, and does not retain the raw IP address.

A separately consented, reviewed and saved Cloud-assisted outcome may enter private quarantine, but OpenAI fallback predictions are stripped first. Only available local predictions and reviewed final labels remain. Such a sample cannot be admitted deterministically or by one reviewer: two independent adjudications must agree or it stays quarantined.

Automated OpenAI review has two independently gated lanes. Ordinary disagreement or verification may send 1–24 selected 112x112 grayscale cell crops; each crop's row and column and local and corrected candidate values; the review kind and prompt version; and an opaque review ID. The separate verified-unreadable lane sends each reviewer exactly one candidate-free crop, the prompt version, and an opaque review ID. It sends no coordinates or number candidates and asks only whether that crop is visually readable. Neither lane sends the full card, unselected crops, raw identifiers, or pseudonymous hashes. OpenAI API data is not used to train models by default. Default abuse-monitoring retention is up to 30 days, or longer when required by law or needed to prevent harm.

Can I decline or delete a contribution?

Yes. Choosing “No thanks” does not affect scanning or manual entry, and BingoFlow does not ask again for the current disclosure. Settings lets you opt in later or withdraw; withdrawal immediately stops new contribution capture, purges known-unsent samples, and requests lifecycle deletion. The app includes protected iOS and Android status/deletion and automatic retry controls; availability requires complete signed app configuration plus a provisioned private service whose retention policy matches the disclosure. Google Play security checks do not receive the contribution crops. Known-unsent local samples and POST replay expire after 7 days; an uncertain exact request expires from protected local storage no later than day 38, even without cleanup networking. Accepted contribution crop/label data is retained for no more than 30 days and online deletion/status access for up to 365 additional days. Disclosed pseudonymous security, provenance, audit, replay, quota, abuse-control, and withdrawal-fence hashes and records remain indefinitely; they contain no crops, labels, card values, or raw identifiers and are not training data. The iOS App Attest public verification record is bounded to 1,095 days after inactivity. Android public verification keys and limited app, counter, and security records support ownership, replay prevention, and audit; records linked to retained evidence may remain indefinitely. Deletion cannot retroactively remove a sample's influence from a model already trained and released.

How do I report a bug?

Use in-app Support (or this web form) and include steps, expected result, and actual result. Attachments are optional and user-controlled.

Are support attachments public?

No. Private support issues store only R2 object keys, not public URLs.