FoilFox legal
Privacy Policy
Effective August 27, 2026 · Last updated September 6, 2026
FoilFox is a TCG card scanner and collection-management service owned and operated by Old Blue Chair LLC. This policy explains what information FoilFox handles, why it is needed, and the choices available to you.
Who operates FoilFox. Old Blue Chair LLC owns and operates FoilFox. In this policy, “FoilFox,” “we,” “us,” and “our” mean Old Blue Chair LLC. Where applicable, Old Blue Chair LLC is the controller of the personal information described in this policy.
Information we collect
Google account information
When you choose Sign in with Google, Google provides FoilFox with a stable account identifier and the basic profile information you approve: your name, email address, and profile image. FoilFox does not receive your Google password. We do not request access to Gmail, Google Drive, contacts, calendars, or other sensitive Google services.
Collection and scanner information
Signed-in collection records are stored in your FoilFox account. Devices may keep a local cache to display your collection. Collection operations, confirmed card identities, scanner results, corrections, and related timestamps can be associated with your account.
Updated mobile builds identify cards on your device and do not send scan photos to a cloud language model or silently fall back to one. Older builds may still use server recognition. For server recognition, the app prepares a card-focused image and sends it to the FoilFox API. FoilFox sends that image to Google’s Gemini API to propose catalog candidates. OpenAI may process recognition requests when an OpenAI model is configured. The request contains the prepared card image and recognition instructions, without your account email or collection database. By default, FoilFox does not retain the original submitted image in its application database; the prepared image is kept only if you have turned on the optional image-contribution setting described below. Recognition results and limited diagnostic metadata may be stored to operate the feature, investigate errors, enforce budgets, and improve measured accuracy.
Service and security information
FoilFox and its infrastructure providers may process IP address, device and browser information, request timestamps, session records, error details, and security events. We use this information to deliver the service, protect accounts, diagnose failures, prevent abuse, and keep model usage within defined limits.
How we use scan data to improve FoilFox
In short: the results of your scans — not your card images, unless you turn on the optional setting below — help us make the scanner more accurate.
FoilFox uses scan results, the card identities collectors confirm or correct, recognition telemetry such as which candidates were shown and whether one was accepted, rejected, or abandoned, and diagnostic records of captures that failed on the device to measure recognition accuracy, investigate defects, and improve FoilFox, including training and evaluating FoilFox's own card-recognition models. These records describe catalog cards and app behavior; by default they do not include your card image.
Optional image contribution (off by default)
FoilFox has an explicit developer and preview setting, which is off by default, for contributing scan diagnostics. In older builds using server recognition, turning it on also uploads the prepared card-focused image — cropped to the card with camera metadata removed, never the full camera scene — together with its scan metadata and confirmed card identity, to FoilFox cloud storage. Updated on-device builds keep ordinary scan photos local even when diagnostics are enabled; Finish Lab image contributions require a separate, explicit research action. We use contributed images and labels to train and validate FoilFox's own recognition models.
The same setting also records a session diagnostics journal: a log of what the app did while you scanned, such as capture guidance states, the recognition path and results shown, the actions you took, and errors. We use these journals for troubleshooting and quality improvement. You can turn the setting off at any time, which stops future contributions.
Optional mobile performance reports
In updated mobile builds, the same Contribute scans switch also enables Expo Observe performance reports. It remains off by default. Reports include scan-stage and save timings, success/failure categories, app startup metrics, device and app version, and installation/session identifiers. They exclude photos, recognized text, card identities, prices, account IDs, binder details, private notes, and raw error messages. These reports help us find slow or failing app operations. Turning the switch off stops new app reports and disables dispatch; uploads already in progress may finish.
How Google user data is used
Google account information is used only to create and authenticate your FoilFox account, display your account identity, associate your private FoilFox records with you, provide support, and protect the service. FoilFox strips Google access tokens, refresh tokens, and ID tokens before account records are persisted.
FoilFox does not sell Google user data, use it for targeted advertising, or allow humans to read it except when needed for security, support, legal compliance, or service operation with appropriate access controls. FoilFox's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements where applicable.
How information is shared
Marketplace browsing is public. When a collector or eligible shop explicitly publishes a listing, the seller display name, card and variant details, seller-stated condition, asking price, and availability become visible without sign-in. Collector sets and bundles show their exact included cards and quantities at one total asking price. Shop listings may also show a completed-reservation rating summary. Paused listings and unpublished stock are not in the public storefront. Private collections, internal stock identifiers, storage locations, member identities, and buyer information are not included. Catalog reference images are not seller photographs.
Onsite marketplace access uses a separate, secure, host-only session linked to the same FoilFox identity. FoilFox does not ask for a birth date or age range during routine sign-in. Signing out of the marketplace does not sign you out of the collection app. Signing in or saving seller setup never publishes a collection or moves inventory.
Optional seller setup stores a proposed display name, individual/business selection, country, draft shipping preferences, and selected card-listing drafts in your account. This information is not anonymous and is private during setup. Internal revision and request records protect against stale edits and duplicate saves. The setup screen offers a versioned JSON export, and account deletion through the collection app removes this setup and its drafts. Existing collection export is separate.
Collectors can use My listings to save drafts, publish, edit, pause, remove, and export listings from owned copies. Publication requires an adult account holder or authorized adult representative. Active listings allocate the selected copies; pausing releases that allocation. Listings and retry records are stored in your account and deleted with it. Collector checkout and reservations, payment verification, connected payouts, public profile pages, seller-photo uploads, and review text are not enabled by this setup. Do not send identity documents, tax IDs, or banking information by email. Existing approved-inventory publishing remains separately permissioned; its listing updates are linked to the acting account for inventory history and retry protection.
We share information only as needed to operate FoilFox:
- Google provides account authentication and processes prepared scanner images through its Gemini API. Its use and retention of recognition inputs and responses are governed by the Gemini API terms; paid and unpaid services have different data-use terms.
- Cloudflare hosts FoilFox's web application, APIs, databases, networking, and security controls.
- Expo receives optional mobile performance reports through EAS Observe when diagnostics are enabled in a supported build. See Expo's privacy policy.
- OpenAI may process prepared scanner images to generate recognition candidates when an OpenAI model is configured.
- Legal and safety recipients may receive information when reasonably necessary to comply with law, protect users, or defend the service.
Your binders, scanner images, sign-in profile, and seller storage locations are private. A seller display name is public on a deliberately published listing. FoilFox does not currently offer freeform comments, direct messages, or a social graph. It does offer an explicit chase-list sharing feature: private is the default; an unlisted list can be opened by anyone who possesses its bearer link; and a public list can appear in public discovery. A shared chase list shows its list name, game, card identity and variant details, desired quantity and condition, owned quantity, and remaining quantity. It does not publish your binders, email, storage locations, acquisition details, account profile, or scanner images.
Changing a chase list back to private removes its active share token. Making it shared again creates a new token, so the old link no longer resolves. Removing a target or deleting the list removes it from the shared projection. Treat an unlisted link as shareable access, not as authentication, and change the list to private if the link reaches the wrong person.
Additional sharing or community features will require a separate product decision and an updated notice before they launch.
Saved deck plans, requirements, notes, and their recent versions are private account data used to provide your deck workspace. You can export the plans from My decks. The workspace retains its last 20 saves; deleting your account deletes the deck workspace and its saved versions.
Storage, retention, and deletion
Account and session records are retained while needed to provide and secure your account. Collection and scan records are retained while the related feature is active or until deletion is requested, subject to backup, fraud-prevention, security, and legal requirements. Infrastructure providers may retain limited operational or abuse-monitoring data under their own service terms.
Unless the optional image-contribution setting is turned on, FoilFox does not store the card image submitted to the recognition endpoint. Images and session journals contributed under that setting are kept in FoilFox cloud storage for model training and validation until they are deleted. A model provider may temporarily retain submitted data for abuse monitoring under its applicable API data policy; provider retention is not controlled by the FoilFox app.
Deleting your FoilFox account permanently deletes your profile, collection records, scan attempts, scan outcomes, and capture diagnostics. Contributed images and session journals are stored under your account identifier and are permanently deleted automatically when you delete your FoilFox account. You can also ask us to remove them at any time at the address below.
Expo performance reports use installation/session identifiers rather than your FoilFox account ID. They follow Expo's retention policy and are separate from account-linked contributions; deleting your FoilFox account does not automatically delete reports already received by Expo.
During account deletion, new account activity is blocked while existing operations finish and data is erased. An interrupted deletion may require a retry or help from support. We retain a keyed, pseudonymous security record of the deleted account to prevent delayed requests from recreating its data; that record contains no card images, collection contents, email address, or sign-in credentials. Optional contributions have account and service-wide upload limits that do not require a paid image-processing service.
To request access, correction, export, or deletion of your account data, email support@foilfox.cards from the address associated with your account. We may need to verify the request before acting on it.
Security
FoilFox uses encrypted transport, server-side secret storage, scoped sessions, validation at service boundaries, and access controls intended to protect your information. No online service can promise absolute security.
Children
FoilFox is a general-audience collection-management service and is not directed to children under 13. We do not routinely ask for a birth date or age range to browse or sign in. FoilFox does not offer accounts to children under 13. Other people who cannot legally accept the Terms where they live may use FoilFox only through an account owned and managed by a parent or guardian.
FoilFox does not knowingly collect personal information from a child under 13 without legally sufficient parental consent, and FoilFox does not currently offer a parental-consent enrollment flow. If we learn that an account is held by a child under 13, we will restrict the account while we review it and delete the child's personal information unless retaining limited information is required for security, legal compliance, or completing the deletion. Contact support@foilfox.cards to report a concern.
Marketplace purchases, sales, payment setup, payouts, and seller operations require an adult account holder or authorized business representative with legal capacity. Payment providers may perform identity, tax, banking, and risk checks for transactions; FoilFox does not treat possession of a payment method as universal proof of age.
Your choices
You can use public catalog browsing without signing in. The collection app offers Google sign-in and, on supported Apple devices, Sign in with Apple for private account-backed features. The marketplace website currently uses Google sign-in. You may stop using those features, sign out, or request deletion at any time. The image-contribution setting described above is off by default and can be turned off at any time. You can review provider permissions from your Google or Apple account.
Changes to this policy
We may update this policy as FoilFox changes. The effective date above will change when the update is published. Material changes will be communicated through the service or another appropriate channel.
Contact
Questions or privacy requests: support@foilfox.cards.