FoilFile

FoilFile Privacy Policy — Private Beta

Version: 0.9-beta.1

Effective date: July 27, 2026

Operator: Christian Graham (individual operator; entity formation planned)

Status: DRAFT — owner and legal review required before external distribution

> This document is an implementation draft, not legal advice. Replace every bracketed placeholder, reconcile it with the final app and third-party configurations, and obtain qualified legal review before a public commercial launch.


1. Overview

This Privacy Policy explains how Christian Graham (“FoilFile,” “we,” “us,” or “our”) collects, uses, shares, retains, and protects information when you use the FoilFile mobile app, websites, private share pages, and related services (collectively, the “Service”).

FoilFile is initially an invite-only United States beta for users age 18 or older. It helps collectors photograph, identify, organize, value, analyze, export, and selectively share information about individual baseball cards.

This Policy should be read with the FoilFile Terms of Use.


2. Key points


3. Scope

This Policy applies to information processed by FoilFile through:

It does not govern an unaffiliated website, marketplace, social network, email provider, or other service you choose to use after leaving FoilFile or after sending a generated share image.


4. Information we collect

4.1 Account and access information

We may collect:

We do not receive your Apple ID password or email password.

4.2 Card photographs and scan information

When you scan or upload a card, we may collect:

The app is designed to remove image metadata such as EXIF and GPS from normalized server copies. Your original device photo may retain metadata outside FoilFile.

4.3 Collection and holding information

We may collect information you provide or confirm about:

This information can reveal the estimated value and contents of a physical collection. We treat it as private account data.

4.4 Pricing, catalog, and market information

We may collect or receive:

We may temporarily retain raw provider responses for troubleshooting and contract validation, subject to provider terms and the retention schedule below.

4.5 Sharing and export information

If you use sharing or export features, we may collect:

Public snapshots are static and unlisted, but anyone with the link may view and forward them while active.

4.6 Device, usage, and diagnostic information

Depending on the final privacy-safe configuration, we may collect:

We configure analytics and diagnostics not to collect card images, collection values, purchase costs, serial numbers, certificate numbers, private notes, signed URLs, access tokens, or email addresses as event properties.

We do not use Apple’s advertising identifier, request App Tracking Transparency permission, or run advertising/session-replay SDKs in the private beta.

4.7 Support and feedback

If you contact us, we may collect:

Do not send passwords, API keys, payment-card information, or unrelated sensitive information.


5. How we collect information

We collect information:


6. How we use information

We use information to:

6.1 Provide app functionality

6.2 Personalize your collection experience

6.3 Secure and operate the Service

6.4 Analyze and improve the product

6.5 Improve identification and matching systems

Important: We use uploaded card images, proposed identifications, your corrections, and your confirmed labels to test, evaluate, improve, and develop FoilFile’s identification, matching, ranking, quality-control, pricing, and related systems, including machine-learning models.

This may include:

Before long-term model use, FoilFile’s design calls for removing account identifiers, storage paths, image metadata, private notes, purchase data, and unnecessary copy-specific serial/certification information.

6.6 Comply with law and protect rights

We may use information to comply with legal obligations, respond to lawful requests, enforce our Terms, establish or defend legal claims, and protect users, providers, FoilFile, or the public.


7. How we disclose information

We may disclose information in the following circumstances.

7.1 Service providers and subprocessors

We use service providers to operate the Service. The final private-beta stack is expected to include:

Provider/categoryPurposeInformation involved
SupabaseAuthentication, Postgres database, storage, server functions, scheduling, secretsAccount, collection, images, operational data
CardSightCard identification, catalog, pricing, completed-sale dataCard images and card/query metadata; provider results
AppleSign in with Apple, iOS distribution, TestFlight, system sharingAuthentication and app/distribution data governed by Apple
Transactional email providerMagic links, invitations, service noticesEmail address and email-delivery metadata
Sentry, if enabledCrash and error diagnosticsSanitized technical diagnostics and opaque user ID
PostHog, if enabledAllowlisted product analyticsSanitized usage events and opaque user ID
Expo/EASApp build, signing, submission, and update infrastructureBuild/project metadata and owner-managed credentials; not ordinary collection content
Hosting/CDN provider, if separateLegal pages and public share deliveryPublic snapshot content and request/security metadata

We require providers to process information for the contracted purpose, subject to their agreements and applicable law.

7.2 CardSight processing and improvement

FoilFile may send card images and related query information to CardSight to identify and price cards. CardSight operates under its own Terms and Privacy Policy. Its then-current terms may permit it to use submitted data to operate, secure, train, or improve its technology.

CardSight may therefore receive and process card-facing image content even though your FoilFile collection is private. We do not send CardSight your purchase price, private notes, storage location, email address, or seller-proceeds settings unless unexpectedly required and separately disclosed.

Provider terms can change. We will review material changes before continuing live transmission and update this Policy if our practices change.

7.3 User-directed sharing

We disclose the content you select when you:

A public-link recipient may copy, screenshot, or forward the content. Revocation stops future access through FoilFile but cannot retrieve copies already made.

7.4 Legal, safety, and rights

We may disclose information if we reasonably believe disclosure is necessary to:

7.5 Business transfers

If FoilFile is involved in a merger, financing, acquisition, reorganization, bankruptcy, or sale of assets, information may be transferred as part of that transaction, subject to applicable law and appropriate confidentiality protections.

7.6 De-identified and aggregate information

We may use and disclose information that has been aggregated or de-identified so that it cannot reasonably be linked to you, including product statistics, benchmark results, model-evaluation results, and model artifacts.

We do not disclose attributable private collections as a commercial data product.


8. No sale, advertising, or tracking

FoilFile does not, in the private beta:

If this changes, we will update the Service, disclosures, consent flows, and App Store privacy responses before enabling the new practice.


9. Public snapshots and privacy

Collections are private by default. When you create an unlisted snapshot:

“Unlisted” does not mean encrypted for a specific recipient. Anyone with the active link can view it. Do not share it with people you do not trust.

Public share pages do not run product analytics or advertising pixels in the private beta.


10. Data retention

We retain information only as long as reasonably necessary for the purposes described, subject to provider contracts, legal requirements, security incidents, and dispute holds.

The intended beta schedule is:

InformationIntended retention
Account and active collection recordsWhile the account is active
Card and copy imagesWhile needed for the account/holding, unless deleted sooner
Abandoned server scan drafts without a holdingApproximately 30 days
Local interrupted-scan recoveryApproximately 7 days
Raw CardSight response payloadUp to 24 hours by default
Safe provider request metadataUp to 12 months
Normalized catalog/price informationWhile permitted and needed to operate the Service
App-recorded price/portfolio snapshotsWhile the account/card data remains active
Native share export objectUp to 24 hours
Active public share previewUntil revoked or expired
Revoked-share tombstoneApproximately 30 days, without public content
CSV export objectUp to 24 hours
Idempotency recordsApproximately 30 days
Completed operation summariesApproximately 90 days
Failed operation recordsUp to 180 days or resolution plus 30 days
Product analyticsUp to 12 months
Crash/diagnostic eventsUp to 30 days
Admin audit logsUp to 24 months
Invitation recordsUp to 12 months after expiration/revocation, with email minimized sooner where practical
Apple refresh tokenUntil revocation/account deletion, encrypted at rest
Directly attributable training examplesUntil account deletion or earlier exclusion
Genuinely de-identified model artifactsAs needed for the approved improvement purpose
Completed deletion proofApproximately 30 days, then direct linkage removed

Actual provider retention may be governed by the provider’s terms. We will update this table when a materially different practice is adopted.


11. Security

FoilFile uses administrative, technical, and organizational safeguards designed for the sensitivity of collection data, including:

No system is perfectly secure. You are responsible for protecting your device, email, and Apple account and for promptly reporting suspected unauthorized access.

Do not treat an unlisted snapshot as confidential storage.


12. Your choices and controls

12.1 Review and correct collection information

You may review and edit supported collection details, confirm or correct identifications, manage copies, and remove content through the app.

12.2 Hide optional display information

You can choose whether PSA 10 reference values appear on collection tiles and whether values/display name appear in a generated share.

12.3 Revoke shared links

You can view and revoke active snapshot links in Settings. Revocation does not delete a screenshot or copy already made by a recipient.

12.4 Export

You may request a CSV export of your collection. The export may include sensitive collection details, so store and share it carefully.

12.5 Analytics opt-out

The app will provide an analytics preference where required by the implementation. Essential authentication, security, fraud-prevention, and operational logging cannot be disabled because the Service cannot operate safely without them.

12.6 Authentication choices

You may use available Sign in with Apple or email magic-link options. Apple allows you to use a private-relay email address.

12.7 Delete your account

You may initiate deletion inside the app at:

`text

Settings → About → Delete account…

`

The app will explain the effect, offer an export reminder, and require deliberate confirmation.


13. Account deletion

After a valid deletion request, FoilFile will ordinarily:

1. restrict new account activity;

2. revoke active snapshot links immediately;

3. queue full deletion, normally targeted for completion within 24 hours;

4. delete private card images, copy images, exports, scans, holdings, acquisition events, notes, and other attributable collection data;

5. delete or exclude directly attributable learning examples that have not been genuinely de-identified;

6. delete the FoilFile authentication account;

7. attempt to revoke Sign in with Apple authorization where a valid token is available; and

8. send or display a completion notice when practical.

If FoilFile cannot programmatically revoke Apple authorization, it will still complete deletion and may instruct you how to remove FoilFile manually from Apple ID settings.

We may retain:

Deleting your account cannot retrieve native share images, CSV files, or public-snapshot copies already downloaded by someone else.


14. Rights under applicable law

Depending on where you reside and applicable law, you may have rights to:

The private beta is United States-only. You may exercise available rights through in-app controls or by contacting privacy@foilfile.com. We may need to verify your identity and authority before completing a request.

We will not discriminate against you for exercising a legally protected privacy right.

Drafting note: Before public launch, counsel should evaluate state-specific notice and request-process requirements based on actual users, thresholds, entity status, and data practices.


15. Children

The private beta is not directed to children or anyone under 18. We do not knowingly permit users under 18. If you believe a minor has created an account or submitted personal information, contact privacy@foilfile.com.


16. United States processing and international users

FoilFile is initially offered only in the United States. Information may be processed in the United States and in other locations where our service providers operate, subject to their terms and safeguards.

Do not use the private beta from a jurisdiction where the Service or these practices are unlawful. International support, including Canadian-dollar display, may be added later with updated disclosures and controls.


17. Third-party links and destinations

The Service may link to or share through eBay, Messages, X, Discord, Instagram, or other third-party services. Their privacy practices govern information after you choose to send it to them.

FoilFile is not responsible for an unaffiliated service’s privacy, security, content, or transaction practices.


18. Changes to this Policy

We may update this Policy when the Service, providers, laws, or data practices change. We will update the version/effective date and provide notice of material changes. We may require you to accept a new version before continuing to use the Service.

Material changes include new data categories, new providers, broader model-training uses, advertising or tracking, public profiles, marketplace features, monetization, international expansion, minor access, or materially longer retention.


19. Contact

For privacy questions or requests:

`text

Christian Graham

Individual operator (entity formation planned)

Privacy: privacy@foilfile.com

Support: support@foilfile.com

Privacy Policy: https://foilfile.com/legal/privacy

Privacy choices: https://foilfile.com/legal/privacy.html

`


FoilFile · Home · Terms · Privacy · support@foilfile.com