Legal
Privacy Policy
Last updated 1 October 2026. This policy explains what GrailFox collects, why, and who else touches it.
1. Who we are
GrailFox is made and run by Maksim Larkin, a sole trader in Berlin, Germany, who is the controller for the personal data described here. The full postal address is on the Impressum. For anything in this policy, write to support@grailfox.net.
2. What we collect
GrailFox has no sign-up, so we hold no name, email address or password unless you write to us. In normal use the app processes four kinds of data: the photograph you take of a card, the records behind your account — your collection, your scan history and your remaining scan allowance — the purchase and subscription state of that account, and product analytics describing how the app is used.
The analytics are a fixed list of events about what happens in the app — it opened, a scan started, succeeded or failed, the paywall was shown, a purchase completed. Each carries the same anonymous account identifier, the app and build version, which build it is, and your device model, manufacturer and operating system version. Our analytics provider also derives an approximate location — country, region and city — from the network address the request arrives on, although the app never asks for your location and cannot read it. No event carries a photograph, a card, a name or an email address, and none uses your device's advertising identifier.
If the app hits an error it did not expect, it also sends a diagnostic report: what went wrong and where in our code it happened. Before it leaves your phone we strip the file paths, shorten the message, and remove the contents of any variable involved, so what we receive tells us which line failed and nothing about you or your cards.
Your account is tied to an anonymous identifier created on first launch, and to nothing else about you. That identifier is kept on your device and is the only way back into the account, so a phone that is lost or reset loses access to the collection.
Your scan history is one of those account records, and it is worth spelling out: we keep a record of every scan attempt — what the app answered, whether it charged an allowance, whether you corrected the answer, and how long it took — including attempts that failed. A failed scan is recorded but never charged; the record of a failure is what tells us recognition is going wrong before the reviews do. The record never contains the photograph or your name, because we hold neither.
Like any server, ours also sees the technical connection data every request carries — your IP address, the time, the request line, the page you came from and your browser's user-agent string — which lands in the web server's log and nowhere else; we use that log to keep the site running and to count the visits each page and campaign brings. The link grailfox.net/get reads the last two, and the operating-system name Chrome and other Chromium browsers send with each request, to send your phone to its own app store and to tell that store which page or campaign sent you; the tag it adds names the source, never you.
3. Card photographs
We never keep a copy of your photographs. Each photograph reaches our server and is passed on, without your identifier, to OpenAI, our recognition provider, which reads the card's name, number and printing clues off it and returns the identification; we put it in no database and write it to no log, and nothing of it is left once the request has finished. Handling an upload of that size means the web server and the framework spool it to a temporary file for the seconds the request lasts — that is how any upload of a few megabytes is received — and the system removes that file when the request ends. When you add a card to your collection, the app keeps that photograph on your device so your collection shows the card you actually own; the app deletes it when you remove the card, deleting GrailFox takes the copies on your phone with it, and it is included in your device backup if you use one — a backup you have already made keeps whatever it captured. While you scan a series, the app also keeps the photos you take on your device, to send them and to show them in the series, and deletes them when the series ends: at once when you discard it or when an add leaves nothing in it, and, if it expires after seven days without use, the next time the app opens and finds it gone. An add that leaves anything in the series keeps all its photos, those of the cards just added included, until the series ends. While they are kept, they are included in your device backup in the same way.
Under our current settings OpenAI may also use photographs to develop and improve its services, including training its models. We have no special deletion arrangement with OpenAI, so how long it keeps a photograph is governed by OpenAI's own policies. Keep the frame on the card: whatever is in the photograph makes that journey with it.
4. Third parties
Seven companies help deliver the service. Each is listed with what it receives; none receives more.
OpenAI (United States) identifies the card from the photograph, as §3 describes. OpenAI is certified under the EU-US Data Privacy Framework, which the European Commission recognises as adequate protection for transfers to certified US companies.
JustTCG supplies the card catalog and the price estimates. Our server asks it about the card, never about you — no personal data is sent to it.
Apple handles payment, subscriptions and app distribution on iPhone. Your purchase there is a purchase from Apple, made under Apple's own terms and privacy policy; we never see your payment details.
Google handles payment, subscriptions and app distribution on Android, through Google Play. Purchases there are processed by Google under Google Play's own terms and privacy policy; we never see your payment details.
RevenueCat (United States) manages purchase and subscription state for us. It receives the anonymous identifier, purchase history and device identifiers, and processes them on our behalf; transfers rest on the EU Standard Contractual Clauses incorporated in its data-processing terms.
PostHog receives the product analytics described in §2, on its European service with the data held in Frankfurt. It receives the anonymous account identifier, the app version and device details, the approximate location it derives from the network address, and the error diagnostics described in §2 — never a photograph, a card or a name.
Because both are keyed to the same anonymous identifier, RevenueCat also sends our purchase events directly to PostHog — the product bought, the amount, the currency and the store — without them passing through the app.
Hetzner hosts our server, in Germany.
This website loads no third-party scripts, fonts, images or analytics, and sets no cookies.
5. Legal bases
Where the GDPR applies: we process the photograph, your collection and your purchase state to provide the service you asked for (Art. 6(1)(b)). Four things rest on our legitimate interests (Art. 6(1)(f)): the server's connection logs, in keeping the service running and secure and in counting the visits each page and campaign brings; the store link's reading of your browser's user-agent, its operating-system hint and the page you came from, in sending you to the right app store and telling it where you came from; the scan records described in §2, in knowing whether the identifications we give are right — the rate at which users correct us is the only honest measure of that; and the product analytics, in understanding which parts of the app people reach and where it fails them. You can object to any processing that rests on a legitimate interest (Art. 21) by writing to us. Purchase records are kept because tax and accounting law requires it (Art. 6(1)(c)). GrailFox makes no automated decisions about you with legal or similarly significant effect within the meaning of Art. 22 — identifying a card is not a decision about you.
6. Retention
We keep no photographs at all — the copies described in §3 are on your device, not ours; the app deletes one when you remove its card, deletes a series' photos when the series ends, as §3 describes, and deleting GrailFox takes the ones on your phone with it — a backup you have already made keeps whatever it captured, as §3 says. What OpenAI keeps is governed by its own policies, as §3 says. Your collection and scan history are kept for as long as your account exists — we cannot tell an inactive account from a patient one, so that means until you ask us to delete it. The web server's access logs are deleted after 14 days. Analytics events are kept for as long as they are useful for the purpose in §5 and are deleted when they are not; we will state a fixed period here once we have one rather than name a number we do not yet keep to. Purchase records are kept for as long as tax and accounting law requires.
7. Your rights
You may ask for access to, correction of, or deletion of personal data we hold, ask for a copy in a portable form, and object to or ask us to restrict processing (Art. 15–21 GDPR). One honest caveat: your account carries no name or email, so we cannot find it from your message alone (Art. 11 GDPR). Write to support@grailfox.net and we will work out with you whether your account can be identified; removing individual cards is something you can do directly in the app. You can also complain to a data protection supervisory authority — ours is the Berliner Beauftragte für Datenschutz und Informationsfreiheit in Berlin.
8. Children
GrailFox is not directed at children under 13, and we do not knowingly collect their personal data.
9. Changes and contact
If this policy changes materially — a new processor, a new purpose — we will update the date at the top and note the change in the app's release notes before the change takes effect. Questions go to support@grailfox.net, or to the postal address on the Impressum.