FoilFox

Privacy Policy

Effective August 27, 2026 · Last updated October 8, 2026

FoilFox is a TCG card scanner and collection-management service owned and operated by Old Blue Chair LLC. This policy explains what information FoilFox handles, why it is needed, and the choices available to you.

Who operates FoilFox. Old Blue Chair LLC owns and operates FoilFox. In this policy, “FoilFox,” “we,” “us,” and “our” mean Old Blue Chair LLC. Where applicable, Old Blue Chair LLC is the controller of the personal information described in this policy.

Information we collect

Google account information

When you choose Sign in with Google, Google provides FoilFox with a stable account identifier and the basic profile information you approve: your name, email address, and profile image. FoilFox does not receive your Google password. We do not request access to Gmail, Google Drive, contacts, calendars, or other sensitive Google services.

Email and Apple sign-in

The collection app also supports email and password. FoilFox stores your email address and a salted password hash, verifies email ownership before password sign-in, and uses temporary tokens for verification and password recovery. We send these account emails through Cloudflare Email Service. Password resets end existing FoilFox sessions. Account emails are separate from optional marketing emails.

When you choose Sign in with Apple, Apple provides an account identifier and the name and email information it makes available, which may include a private relay email address. Connected sign-in methods use the same FoilFox account; adding a password through verified email recovery preserves that account's records.

Collection and scanner information

Signed-in collection records are stored in your FoilFox account. Devices may keep a local cache to display your collection. Collection operations, confirmed card identities, scanner results, corrections, and related timestamps can be associated with your account.

Scanning without an account

You can scan cards in the mobile app without signing in. Your photos stay on your device. Each guest scan sends FoilFox the same scan result a signed-in scan does: the catalog cards the scanner offered, the card you chose or the fact that you rejected or left the result, and the app, platform and scanner versions. A guest scan result carries a random code that the app creates each time it starts, so one session's scans can be read together. The code is not tied to your device, your name or an account. FoilFox uses your IP address only to limit repeated requests and does not store it with these results.

If you create a FoilFox account after scanning as a guest, the scans from that session move into your new account and are treated like its other scan records. Guest scan results that never join an account are deleted after 90 days.

Updated mobile builds identify cards on your device and do not send scan photos to a cloud language model or silently fall back to one. Cloud scanning was retired on September 6, 2026 for all builds. An older app may still attempt to send a photo, but the retired endpoint rejects the request without reading, storing or forwarding the photo or calling a model provider. Update the app to use on-device recognition, or use manual catalog search.

Before retirement, server recognition could send prepared card-focused images to Google’s Gemini API or OpenAI to propose catalog candidates. Those historical requests contained the prepared image and recognition instructions, without your account email or collection database. Recognition results and limited diagnostic metadata may remain under the retention and deletion practices below. Retiring cloud scanning does not imply that previously contributed research data has been deleted.

Service and security information

In app versions with reporting and blocking controls, a report records your account identifier, the reported shared Chase List, its public title, the selected reason, and receipt and review timestamps. Reports are private and are used to review content concerns. A block records the collector or shop you chose to hide and when you blocked them. Blocking applies to signed-in views in the collection app; it does not remove public content for everyone. You can remove blocks in Account. These records remain until account deletion or support removal; deleting your account also removes reports and blocks associated with you. Reports do not contribute to scanner training.

FoilFox and its infrastructure providers may process IP address, device and browser information, request timestamps, session records, error details, and security events. We use this information to deliver the service, protect accounts, diagnose failures, prevent abuse, and enforce service limits.

foilfoxtcg.com and foilfox.app use Cloudflare Web Analytics, a cookie-free measurement of page views and performance. The browser loads a small script from Cloudflare and reports the page address, approximate location derived from IP, browser and device class, and timing. It is not used for advertising. Display-case pages and the signed-in collection app at app.foilfox.app are not included. We can turn this off by removing the site tokens and deploying.

On public pages, FoilFox also counts clicks to its Apple App Store and Google Play listings. These records contain the public page path, the chosen store, and a broad referrer category, such as Google or an unknown source. They contain no account or device identifier, cookie, search query, or full referrer address. Cloudflare hosts these service logs for up to seven days; we may keep aggregate counts to compare articles. A click does not tell us whether someone installed the app.

You can turn website measurement off in this browser or turn it back on. We save only this preference in browser storage, without a visitor identifier. Website measurement also stays off when your browser sends Do Not Track or Global Privacy Control. The preference applies to this website; set it separately on foilfox.app. Private seller and card-search pages are excluded. Public pages without query parameters keep referrers within the same website, so navigating between pages does not look like a new arrival; referrers are withheld from other websites.

How we use scan data to improve FoilFox

Scan results and optional contributions help us investigate recognition errors and test improvements.

FoilFox uses scan results, the card identities collectors confirm or correct, recognition telemetry such as which candidates were shown and whether one was accepted, rejected, or abandoned, and diagnostic records of captures that failed on the device to measure recognition accuracy, investigate defects, and improve FoilFox, including training and evaluating FoilFox's own card-recognition models. These records describe catalog cards and app behavior; by default they do not include your card image.

Optional image contribution (off by default)

In builds that offer image contribution, Contribute scans asks for a separate, versioned permission, which is off by default, before sending eligible guided-camera card crops to FoilFox. Previously enabling diagnostics does not enable image contribution; you must accept the new image-contribution permission for the signed-in account. Ordinary card identification continues on your device.

With this permission, FoilFox receives the prepared card-only image, with camera metadata removed, together with capture time, app and platform version, catalog and model identifiers, the candidates and finish suggestion shown, and the card or finish you accept or correct. The contribution is a crop of the card, never the full camera scene. This version skips photo-library images and captures whose card crop cannot be established. We use these account-linked contributions to develop, train and test FoilFox's own card-recognition models. A collector's choice is recorded separately from the model's suggestion and is not an independently verified label.

Contributions go to FoilFox's private storage hosted by Cloudflare. We do not send them to cloud language-model providers or publish them in the catalog or anywhere public. The app keeps a small pending queue in memory while it is running; it does not keep a permanent offline upload queue. Closing the app can discard pending contributions. Uploads and retries are limited, and saving a card does not wait for an upload.

After you correct a scan, the app may offer Send this scan. Tapping it sends that one card crop and your correction under a separate, one-time permission. It does not turn on scan sharing.

You can turn image contribution off at any time. Turning it off, signing out, or changing accounts drops pending image contributions and stops new ones. An upload already accepted by the server may remain. Turning the setting off does not delete earlier contributions; use account deletion or contact support to request their removal.

The separate diagnostics setting records a session diagnostics journal: capture guidance, the recognition path and results shown, your actions, and errors. It also controls the optional performance reports below. Earlier server-recognition builds could contribute images under their older setting. The retired scanning endpoint no longer accepts those contributions.

Optional mobile performance reports

The diagnostics setting associated with Contribute scans also enables Expo Observe performance reports. Image-contribution permission is separate. It remains off by default. Reports include scan-stage and save timings, success/failure categories, app startup metrics, device and app version, and installation/session identifiers. They exclude photos, recognized text, card identities, prices, account IDs, binder details, private notes, and raw error messages. These reports help us find slow or failing app operations. Turning the switch off stops new app reports and disables dispatch; uploads already in progress may finish.

Android text recognition diagnostics

Android scanning uses Google ML Kit to read text on the device. The SDK sends Google installation identifiers, device and app information, performance measurements, feature events and error codes, and image configuration and input/output sizes for diagnostics and usage analytics. These SDK reports are separate from FoilFox’s optional contributions and Expo Observe reports. The Contribute scans switch does not control ML Kit diagnostics. See Google’s ML Kit data disclosure.

How Google user data is used

Google account information is used only to create and authenticate your FoilFox account, display your account identity, associate your private FoilFox records with you, provide support, and protect the service. FoilFox strips Google access tokens, refresh tokens, and ID tokens before account records are persisted.

FoilFox does not sell Google user data, use it for targeted advertising, or allow humans to read it except when needed for security, support, legal compliance, or service operation with appropriate access controls. FoilFox's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements where applicable.

How information is shared

Your personal collection stays private. A shop's stock is visible only to that shop's authorized members, except in a case the shop owner turns on with a display-case card. The card's link shows the shop's name and, for each card available in that case, its name, printing, condition and the shop's price if it set one. It never shows quantities. Anyone with the link or its QR code can open the page, including away from the store, and search engines are asked not to index it. Visitors don't sign in or give any information, and FoilFox uses a visitor's IP address only to limit repeated requests. Turning the card off stops the link from working; turning it back on restores the same link. Issuing a new link retires the old one, including printed QR codes. Nothing else you save becomes public unless you choose to share a chase list, as described below.

Onsite foilfoxtcg.com access uses a separate, secure, host-only session linked to the same FoilFox identity. FoilFox does not ask for a birth date or age range during routine sign-in. Signing out of foilfoxtcg.com does not sign you out of the collection app. Signing in never publishes a collection or moves inventory.

The inventory workspace displays account-owned cards and, for authorized shop members, that shop's stock, storage locations, quantities and recorded costs. These details are private. Shop staff can hold a copy at the counter, which lowers its available count until the hold ends and staff confirm the card is back in its place; holds and those confirmations are linked to the acting account for inventory history. Trade-in tickets hold a ticket number, a short customer label that staff enter, such as a first name, and each card's condition, offer and decision, linked to the acting account. Don't enter a customer's contact details, identity documents or payment information. FoilFox does not collect payment for cards. Do not send identity documents, tax IDs, or banking information by email.

We share information only as needed to operate FoilFox:

Your binders, scanner images, sign-in profile, and seller storage locations are private. A display-case card shows the shop's name, never the name of the case or any other storage location. FoilFox does not currently offer freeform comments, direct messages, or a social graph. It does offer an explicit chase-list sharing feature: private is the default; an unlisted list can be opened by anyone who possesses its bearer link; and a public list can appear in public discovery. A shared chase list shows its list name, game, card identity and variant details, desired quantity and condition, owned quantity, and remaining quantity. It does not publish your binders, email, storage locations, acquisition details, account profile, or scanner images.

Changing a chase list back to private removes its active share token. Making it shared again creates a new token, so the old link no longer resolves. Removing a target or deleting the list removes it from the shared projection. Treat an unlisted link as shareable access, not as authentication, and change the list to private if the link reaches the wrong person.

Additional sharing or community features will require a separate product decision and an updated notice before they launch.

Saved deck plans, requirements, notes, and their recent versions are private account data used to provide your deck workspace. You can export the plans from My decks. The workspace retains its last 20 saves; deleting your account deletes the deck workspace and its saved versions.

Storage, retention, and deletion

Account and session records are retained while needed to provide and secure your account. Collection and scan records are retained while the related feature is active or until deletion is requested, subject to backup, fraud-prevention, security, and legal requirements. Infrastructure providers may retain limited operational or abuse-monitoring data under their own service terms.

Ordinary identification processes scan photos on the device. Eligible card crops are uploaded only with the image-contribution permission described above. The retired recognition endpoint does not store submitted photos. Images and session journals previously contributed under the optional setting, and separately authorized research contributions, are kept in FoilFox cloud storage for model training and evaluation until they are deleted. There is currently no automatic time-based expiry for these hosted contributions. Historical model providers may retain previously submitted data under their applicable API data policies; provider retention is not controlled by the FoilFox app.

Deleting your FoilFox account permanently deletes your profile, collection records, scan attempts, scan outcomes, and capture diagnostics. Contributed images and session journals are stored under your account identifier and are permanently deleted automatically when you delete your FoilFox account. You can also ask us to remove them at any time at the address below.

Expo performance reports use installation/session identifiers rather than your FoilFox account ID. They follow Expo's retention policy and are separate from account-linked contributions; deleting your FoilFox account does not automatically delete reports already received by Expo.

During account deletion, new account activity is blocked while existing operations finish and data is erased. An interrupted deletion may require a retry or help from support. We retain a keyed, pseudonymous security record of the deleted account to prevent delayed requests from recreating its data; that record contains no card images, collection contents, email address, or sign-in credentials. Optional contributions have account and service-wide upload limits that do not require a paid image-processing service.

To request access, correction, export, or deletion of your account data, email support@foilfoxtcg.com from the address associated with your account. We may need to verify the request before acting on it.

Security

FoilFox uses encrypted transport, server-side secret storage, scoped sessions, validation at service boundaries, and access controls intended to protect your information. No online service can promise absolute security.

Children

FoilFox is a general-audience collection-management service and is not directed to children under 13. We do not routinely ask for a birth date or age range to browse or sign in. FoilFox does not offer accounts to children under 13. Other people who cannot legally accept the Terms where they live may use FoilFox only through an account owned and managed by a parent or guardian.

FoilFox does not knowingly collect personal information from a child under 13 without legally sufficient parental consent, and FoilFox does not currently offer a parental-consent enrollment flow. If we learn that an account is held by a child under 13, we will restrict the account while we review it and delete the child's personal information unless retaining limited information is required for security, legal compliance, or completing the deletion. Contact support@foilfoxtcg.com to report a concern.

Shop inventory tools and seller operations require an adult account holder or authorized business representative with legal capacity. FoilFox does not treat possession of a payment method as universal proof of age.

Your choices

You can use public catalog browsing without signing in. The collection app offers email and password, Google sign-in and, on supported Apple devices, Sign in with Apple for private account-backed features. foilfoxtcg.com currently uses Google sign-in. You may stop using those features, sign out, or request deletion at any time. The image-contribution setting described above is off by default and can be turned off at any time. You can review provider permissions from your Google or Apple account.

Changes to this policy

We may update this policy as FoilFox changes. The effective date above will change when the update is published. Material changes will be communicated through the service or another appropriate channel.

Contact

Questions or privacy requests: support@foilfoxtcg.com.

Your FoilFox account

Sign in

Sign in to open shop inventory or your collection. Guides stay open without an account.