FoilFile Privacy Policy — Private Beta
Version: 0.9-beta.1
Effective date: July 27, 2026
Operator: Christian Graham (individual operator; entity formation planned)
Status: DRAFT — owner and legal review required before external distribution
> This document is an implementation draft, not legal advice. Replace every bracketed placeholder, reconcile it with the final app and third-party configurations, and obtain qualified legal review before a public commercial launch.
1. Overview
This Privacy Policy explains how Christian Graham (“FoilFile,” “we,” “us,” or “our”) collects, uses, shares, retains, and protects information when you use the FoilFile mobile app, websites, private share pages, and related services (collectively, the “Service”).
FoilFile is initially an invite-only United States beta for users age 18 or older. It helps collectors photograph, identify, organize, value, analyze, export, and selectively share information about individual baseball cards.
This Policy should be read with the FoilFile Terms of Use.
2. Key points
- We collect account information, card images, collection records, and technical information needed to provide the Service.
- Card images and related information may be sent to CardSight or another disclosed provider for identification, catalog, and pricing functions.
- We use uploaded card images, corrections, and confirmed labels to test, improve, and develop FoilFile’s identification and matching systems, including machine-learning models.
- CardSight may also use submissions under its then-current terms and privacy policy, including to operate, train, or improve its systems.
- Collections and card images are private by default.
- You may deliberately create a native share image or an unlisted, revocable snapshot link.
- We do not sell personal information, use it for targeted advertising, or permit cross-app tracking in the private beta.
- You may export your collection and initiate account deletion inside the app.
3. Scope
This Policy applies to information processed by FoilFile through:
- the iPhone application;
- the owner/admin application;
- FoilFile websites and legal pages;
- unlisted public share pages and images;
- authentication, database, storage, and server functions;
- product analytics and diagnostics configured for the Service; and
- support and beta operations.
It does not govern an unaffiliated website, marketplace, social network, email provider, or other service you choose to use after leaving FoilFile or after sending a generated share image.
4. Information we collect
4.1 Account and access information
We may collect:
- email address, including an Apple private-relay address;
- optional name or display name;
- an internal user/account identifier;
- Apple Sign in subject identifier and authentication metadata;
- invitation code, intended invitation email, invitation status, and inviter;
- confirmation that you are at least 18;
- accepted Terms and Privacy Policy versions and timestamps;
- account state, plan/entitlements, and usage-limit counters; and
- support and security communications.
We do not receive your Apple ID password or email password.
4.2 Card photographs and scan information
When you scan or upload a card, we may collect:
- front and back images;
- normalized/resized versions of those images;
- image dimensions, file type, checksum, and quality metadata;
- scan progress, capture source, and upload status;
- provider identification requests and responses;
- proposed candidates, confidence level, model/provider version, and processing time;
- corrections and final confirmed identity; and
- review or unresolved-card status.
The app is designed to remove image metadata such as EXIF and GPS from normalized server copies. Your original device photo may retain metadata outside FoilFile.
4.3 Collection and holding information
We may collect information you provide or confirm about:
- player, team shown on card, year, manufacturer, product, set, subset, and card number;
- parallel, variation, print run, autograph, relic, rookie, insert, and other traits;
- grouped quantity and individual physical copies;
- exact serial number;
- raw or graded status, grading company, grade, and certification number;
- optional copy-specific images;
- purchase price, date, source, shipping, tax, and notes;
- sale, trade, gift, loss, archive, or other disposition information;
- acquisition events, such as packs, boxes, and opening sessions;
- cost-allocation choices;
- current and historical values, freshness, and confidence;
- calculated portfolio and acquisition-event analytics;
- favorite or saved filters; and
- optional seller-proceeds assumptions.
This information can reveal the estimated value and contents of a physical collection. We treat it as private account data.
4.4 Pricing, catalog, and market information
We may collect or receive:
- provider card identifiers and catalog relationships;
- provider market estimates by condition or grade;
- historical price points;
- completed-sale details such as marketplace, date, price, shipping, grade, and listing type;
- confidence, sample size, and freshness;
- provider quota and request metadata; and
- FoilFile-generated daily portfolio snapshots and derived analytics.
We may temporarily retain raw provider responses for troubleshooting and contract validation, subject to provider terms and the retention schedule below.
4.5 Sharing and export information
If you use sharing or export features, we may collect:
- selected share template;
- whether values and display name are shown;
- sanitized snapshot content;
- a random public-link token stored in hashed form;
- share creation, expiration, revocation, and access metadata;
- generated image/object path and readiness state;
- CSV export request, status, row count, and expiration; and
- limited abuse/security data related to public-link access.
Public snapshots are static and unlisted, but anyone with the link may view and forward them while active.
4.6 Device, usage, and diagnostic information
Depending on the final privacy-safe configuration, we may collect:
- app version, build number, environment, and operating-system version;
- device model class and language;
- installation or analytics identifier that is not an advertising identifier;
- app launches, screen views, taps, feature usage, workflow completion, and error state;
- coarse timestamps and performance timing;
- crash logs, stack traces, and technical diagnostics;
- server request IDs, response status, rate-limit state, and sanitized error categories;
- IP address used transiently for security/rate limiting, and a salted/peppered hash where retained; and
- authentication and security events.
We configure analytics and diagnostics not to collect card images, collection values, purchase costs, serial numbers, certificate numbers, private notes, signed URLs, access tokens, or email addresses as event properties.
We do not use Apple’s advertising identifier, request App Tracking Transparency permission, or run advertising/session-replay SDKs in the private beta.
4.7 Support and feedback
If you contact us, we may collect:
- contact details;
- the content of your message;
- attachments you deliberately provide;
- relevant account, device, app-version, and request identifiers; and
- support outcome and correspondence.
Do not send passwords, API keys, payment-card information, or unrelated sensitive information.
5. How we collect information
We collect information:
- **directly from you**, when you create an account, scan cards, confirm data, enter costs, create shares, export, or contact support;
- **from authentication providers**, such as Apple and Supabase Auth;
- **from card-data providers**, such as CardSight;
- **from the app and servers automatically**, through security, usage, and diagnostic events; and
- **from other users**, only in limited cases such as an invitation sent to your email address.
6. How we use information
We use information to:
6.1 Provide app functionality
- authenticate accounts and enforce invitation access;
- capture, upload, and process card images;
- identify cards and retrieve catalog/pricing data;
- organize grouped holdings and physical copies;
- calculate portfolio values, movements, and acquisition-event returns;
- generate charts, exports, share images, and snapshot links;
- sync data across sessions;
- support account deletion; and
- provide customer support.
6.2 Personalize your collection experience
- apply your saved views and display preferences;
- show relevant players, teams, sets, traits, and parallel families;
- display condition-appropriate values; and
- remember seller-proceeds assumptions and other account settings.
6.3 Secure and operate the Service
- prevent abuse, unauthorized access, scraping, and quota evasion;
- enforce row-level and storage access controls;
- detect compromised accounts and suspicious activity;
- monitor provider, queue, pricing, and deletion jobs;
- debug crashes and performance problems;
- audit privileged admin actions; and
- maintain backups, continuity, and incident response.
6.4 Analyze and improve the product
- measure activation, scan completion, retention, and feature usefulness;
- evaluate identification and pricing coverage;
- understand failures and edge cases;
- improve interface and operational reliability; and
- plan future features.
6.5 Improve identification and matching systems
Important: We use uploaded card images, proposed identifications, your corrections, and your confirmed labels to test, evaluate, improve, and develop FoilFile’s identification, matching, ranking, quality-control, pricing, and related systems, including machine-learning models.
This may include:
- building training and evaluation datasets;
- generating image embeddings and derived features;
- comparing a new scan with confirmed scans;
- training, fine-tuning, and evaluating models;
- measuring confidence and error patterns; and
- retaining de-identified examples, aggregate statistics, embeddings not reasonably linkable to you, and model weights.
Before long-term model use, FoilFile’s design calls for removing account identifiers, storage paths, image metadata, private notes, purchase data, and unnecessary copy-specific serial/certification information.
6.6 Comply with law and protect rights
We may use information to comply with legal obligations, respond to lawful requests, enforce our Terms, establish or defend legal claims, and protect users, providers, FoilFile, or the public.
7. How we disclose information
We may disclose information in the following circumstances.
7.1 Service providers and subprocessors
We use service providers to operate the Service. The final private-beta stack is expected to include:
| Provider/category | Purpose | Information involved |
| Supabase | Authentication, Postgres database, storage, server functions, scheduling, secrets | Account, collection, images, operational data |
| CardSight | Card identification, catalog, pricing, completed-sale data | Card images and card/query metadata; provider results |
| Apple | Sign in with Apple, iOS distribution, TestFlight, system sharing | Authentication and app/distribution data governed by Apple |
| Transactional email provider | Magic links, invitations, service notices | Email address and email-delivery metadata |
| Sentry, if enabled | Crash and error diagnostics | Sanitized technical diagnostics and opaque user ID |
| PostHog, if enabled | Allowlisted product analytics | Sanitized usage events and opaque user ID |
| Expo/EAS | App build, signing, submission, and update infrastructure | Build/project metadata and owner-managed credentials; not ordinary collection content |
| Hosting/CDN provider, if separate | Legal pages and public share delivery | Public snapshot content and request/security metadata |
We require providers to process information for the contracted purpose, subject to their agreements and applicable law.
7.2 CardSight processing and improvement
FoilFile may send card images and related query information to CardSight to identify and price cards. CardSight operates under its own Terms and Privacy Policy. Its then-current terms may permit it to use submitted data to operate, secure, train, or improve its technology.
CardSight may therefore receive and process card-facing image content even though your FoilFile collection is private. We do not send CardSight your purchase price, private notes, storage location, email address, or seller-proceeds settings unless unexpectedly required and separately disclosed.
Provider terms can change. We will review material changes before continuing live transmission and update this Policy if our practices change.
7.3 User-directed sharing
We disclose the content you select when you:
- send or save a generated share image;
- create an unlisted snapshot link;
- copy a private link; or
- export a CSV and send it elsewhere.
A public-link recipient may copy, screenshot, or forward the content. Revocation stops future access through FoilFile but cannot retrieve copies already made.
7.4 Legal, safety, and rights
We may disclose information if we reasonably believe disclosure is necessary to:
- comply with law, legal process, or a valid government request;
- protect the rights, safety, or property of FoilFile, users, providers, or others;
- investigate fraud, abuse, or a security incident;
- enforce agreements; or
- establish, exercise, or defend legal claims.
7.5 Business transfers
If FoilFile is involved in a merger, financing, acquisition, reorganization, bankruptcy, or sale of assets, information may be transferred as part of that transaction, subject to applicable law and appropriate confidentiality protections.
7.6 De-identified and aggregate information
We may use and disclose information that has been aggregated or de-identified so that it cannot reasonably be linked to you, including product statistics, benchmark results, model-evaluation results, and model artifacts.
We do not disclose attributable private collections as a commercial data product.
8. No sale, advertising, or tracking
FoilFile does not, in the private beta:
- sell personal information;
- share personal information for cross-context behavioral advertising;
- display third-party advertising;
- use data brokers;
- use the Apple advertising identifier;
- combine app activity with third-party data for targeted advertising; or
- permit Sentry, PostHog, or CardSight to use FoilFile account data for advertising on FoilFile’s behalf.
If this changes, we will update the Service, disclosures, consent flows, and App Store privacy responses before enabling the new practice.
9. Public snapshots and privacy
Collections are private by default. When you create an unlisted snapshot:
- FoilFile creates a frozen copy of selected information;
- the link uses a hard-to-guess token and is not intended for search indexing;
- values and display name are optional;
- purchase prices, cost basis, private notes, exact serial numbers, grading certificate numbers, and storage locations are excluded by design;
- the link can be revoked in Settings; and
- the snapshot does not update automatically when your collection changes.
“Unlisted” does not mean encrypted for a specific recipient. Anyone with the active link can view it. Do not share it with people you do not trust.
Public share pages do not run product analytics or advertising pixels in the private beta.
10. Data retention
We retain information only as long as reasonably necessary for the purposes described, subject to provider contracts, legal requirements, security incidents, and dispute holds.
The intended beta schedule is:
| Information | Intended retention |
| Account and active collection records | While the account is active |
| Card and copy images | While needed for the account/holding, unless deleted sooner |
| Abandoned server scan drafts without a holding | Approximately 30 days |
| Local interrupted-scan recovery | Approximately 7 days |
| Raw CardSight response payload | Up to 24 hours by default |
| Safe provider request metadata | Up to 12 months |
| Normalized catalog/price information | While permitted and needed to operate the Service |
| App-recorded price/portfolio snapshots | While the account/card data remains active |
| Native share export object | Up to 24 hours |
| Active public share preview | Until revoked or expired |
| Revoked-share tombstone | Approximately 30 days, without public content |
| CSV export object | Up to 24 hours |
| Idempotency records | Approximately 30 days |
| Completed operation summaries | Approximately 90 days |
| Failed operation records | Up to 180 days or resolution plus 30 days |
| Product analytics | Up to 12 months |
| Crash/diagnostic events | Up to 30 days |
| Admin audit logs | Up to 24 months |
| Invitation records | Up to 12 months after expiration/revocation, with email minimized sooner where practical |
| Apple refresh token | Until revocation/account deletion, encrypted at rest |
| Directly attributable training examples | Until account deletion or earlier exclusion |
| Genuinely de-identified model artifacts | As needed for the approved improvement purpose |
| Completed deletion proof | Approximately 30 days, then direct linkage removed |
Actual provider retention may be governed by the provider’s terms. We will update this table when a materially different practice is adopted.
11. Security
FoilFile uses administrative, technical, and organizational safeguards designed for the sensitivity of collection data, including:
- private storage buckets and signed URLs;
- Supabase row-level security and per-user object paths;
- server-side provider calls;
- encryption in transit;
- secure device token storage;
- encrypted server storage for Apple revocation credentials;
- secret separation and rotation;
- restricted admin access and audit logs;
- rate limiting and abuse controls;
- sanitized analytics and diagnostics;
- deletion and retention jobs; and
- testing designed to prove one user cannot access another user’s data.
No system is perfectly secure. You are responsible for protecting your device, email, and Apple account and for promptly reporting suspected unauthorized access.
Do not treat an unlisted snapshot as confidential storage.
12. Your choices and controls
12.1 Review and correct collection information
You may review and edit supported collection details, confirm or correct identifications, manage copies, and remove content through the app.
12.2 Hide optional display information
You can choose whether PSA 10 reference values appear on collection tiles and whether values/display name appear in a generated share.
12.3 Revoke shared links
You can view and revoke active snapshot links in Settings. Revocation does not delete a screenshot or copy already made by a recipient.
12.4 Export
You may request a CSV export of your collection. The export may include sensitive collection details, so store and share it carefully.
12.5 Analytics opt-out
The app will provide an analytics preference where required by the implementation. Essential authentication, security, fraud-prevention, and operational logging cannot be disabled because the Service cannot operate safely without them.
12.6 Authentication choices
You may use available Sign in with Apple or email magic-link options. Apple allows you to use a private-relay email address.
12.7 Delete your account
You may initiate deletion inside the app at:
`text
Settings → About → Delete account…
`
The app will explain the effect, offer an export reminder, and require deliberate confirmation.
13. Account deletion
After a valid deletion request, FoilFile will ordinarily:
1. restrict new account activity;
2. revoke active snapshot links immediately;
3. queue full deletion, normally targeted for completion within 24 hours;
4. delete private card images, copy images, exports, scans, holdings, acquisition events, notes, and other attributable collection data;
5. delete or exclude directly attributable learning examples that have not been genuinely de-identified;
6. delete the FoilFile authentication account;
7. attempt to revoke Sign in with Apple authorization where a valid token is available; and
8. send or display a completion notice when practical.
If FoilFile cannot programmatically revoke Apple authorization, it will still complete deletion and may instruct you how to remove FoilFile manually from Apple ID settings.
We may retain:
- a short-lived sanitized deletion record for retry/audit purposes;
- information required by law, security incident, or dispute hold;
- genuinely de-identified aggregate information;
- embeddings that cannot reasonably be linked back to you; and
- model weights already trained from permitted data.
Deleting your account cannot retrieve native share images, CSV files, or public-snapshot copies already downloaded by someone else.
14. Rights under applicable law
Depending on where you reside and applicable law, you may have rights to:
- know or access personal information;
- correct inaccurate information;
- obtain a portable copy;
- delete information;
- restrict or object to certain processing;
- withdraw consent where processing relies on consent; and
- appeal a denied request.
The private beta is United States-only. You may exercise available rights through in-app controls or by contacting privacy@foilfile.com. We may need to verify your identity and authority before completing a request.
We will not discriminate against you for exercising a legally protected privacy right.
Drafting note: Before public launch, counsel should evaluate state-specific notice and request-process requirements based on actual users, thresholds, entity status, and data practices.
15. Children
The private beta is not directed to children or anyone under 18. We do not knowingly permit users under 18. If you believe a minor has created an account or submitted personal information, contact privacy@foilfile.com.
16. United States processing and international users
FoilFile is initially offered only in the United States. Information may be processed in the United States and in other locations where our service providers operate, subject to their terms and safeguards.
Do not use the private beta from a jurisdiction where the Service or these practices are unlawful. International support, including Canadian-dollar display, may be added later with updated disclosures and controls.
17. Third-party links and destinations
The Service may link to or share through eBay, Messages, X, Discord, Instagram, or other third-party services. Their privacy practices govern information after you choose to send it to them.
FoilFile is not responsible for an unaffiliated service’s privacy, security, content, or transaction practices.
18. Changes to this Policy
We may update this Policy when the Service, providers, laws, or data practices change. We will update the version/effective date and provide notice of material changes. We may require you to accept a new version before continuing to use the Service.
Material changes include new data categories, new providers, broader model-training uses, advertising or tracking, public profiles, marketplace features, monetization, international expansion, minor access, or materially longer retention.
19. Contact
For privacy questions or requests:
`text
Christian Graham
Individual operator (entity formation planned)
Privacy: privacy@foilfile.com
Support: support@foilfile.com
Privacy Policy: https://foilfile.com/legal/privacy
Privacy choices: https://foilfile.com/legal/privacy.html
`