FoilFox ← Back to FoilFox

FoilFox legal

Privacy Policy

Effective August 27, 2026

FoilFox is a TCG card scanner and collection-management service. This policy explains what information the FoilFox preview handles, why it is needed, and the choices available to you.

Information we collect

Google account information

When you choose Sign in with Google, Google provides FoilFox with a stable account identifier and the basic profile information you approve: your name, email address, and profile image. FoilFox does not receive your Google password. We do not request access to Gmail, Google Drive, contacts, calendars, or other sensitive Google services.

Collection and scanner information

Collection records may remain on your device in the current preview. Account-backed features can associate collection operations, confirmed card identities, scanner results, corrections, and related timestamps with your FoilFox account.

When you submit a card image for recognition, the app prepares a card-focused image and sends it to the FoilFox API. FoilFox sends that image to OpenAI to propose catalog candidates. FoilFox does not retain the original submitted image in its application database. Recognition results and limited diagnostic metadata may be stored to operate the feature, investigate errors, enforce budgets, and improve measured accuracy.

Service and security information

FoilFox and its infrastructure providers may process IP address, device and browser information, request timestamps, session records, error details, and security events. We use this information to deliver the service, protect accounts, diagnose failures, prevent abuse, and keep model usage within defined limits.

How Google user data is used

Google account information is used only to create and authenticate your FoilFox account, display your account identity, associate your private FoilFox records with you, provide support, and protect the service. FoilFox strips Google access tokens, refresh tokens, and ID tokens before account records are persisted.

FoilFox does not sell Google user data, use it for targeted advertising, or allow humans to read it except when needed for security, support, legal compliance, or service operation with appropriate access controls. FoilFox's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements where applicable.

How information is shared

We share information only as needed to operate FoilFox:

  • Google provides account authentication.
  • Cloudflare hosts FoilFox's web application, APIs, databases, networking, and security controls.
  • OpenAI processes card images submitted to the scanner to generate recognition candidates.
  • Legal and safety recipients may receive information when reasonably necessary to comply with law, protect users, or defend the service.

The MVP does not publish profiles, collection records, scanner images, comments, messages, or a social graph. Future sharing or community features will require a separate product decision and an updated notice before they launch.

Storage, retention, and deletion

Account and session records are retained while needed to provide and secure your account. Collection and scan records are retained while the related feature is active or until deletion is requested, subject to backup, fraud-prevention, security, and legal requirements. Infrastructure providers may retain limited operational or abuse-monitoring data under their own service terms.

FoilFox does not store the original card image submitted to the recognition endpoint. A model provider may temporarily retain submitted data for abuse monitoring under its applicable API data policy; provider retention is not controlled by the FoilFox app.

To request access, correction, export, or deletion of your account data, email steve@oldbluechair.com from the address associated with your account. We may need to verify the request before acting on it.

Security

FoilFox uses encrypted transport, server-side secret storage, scoped sessions, validation at service boundaries, and access controls intended to protect your information. No online service can promise absolute security.

Children

FoilFox is designed as a collection-management tool and is not directed to children under 13. If you believe a child has provided personal information through FoilFox, contact us so we can review and delete it as appropriate.

Your choices

You can use public catalog browsing without signing in. Google sign-in is required for private, account-backed features. You may stop using those features, sign out, or request deletion at any time. You can also review Google's account permissions from your Google Account.

Changes to this policy

We may update this policy as FoilFox changes. The effective date above will change when the update is published. Material changes will be communicated through the service or another appropriate channel.

Contact

Questions or privacy requests: steve@oldbluechair.com.