Privacy Policy

Last updated: September 23, 2026

Grail ("we", "us", "Grail") is an iOS app that helps you track a portfolio of trading cards (Pokémon TCG and One Piece Card Game). This page explains what data the app collects, why, and how you can control it.

Data we collect

  • Account data: when you sign up, we collect your email address via Firebase Authentication to create and secure your account.
  • Portfolio data: the wallets, cards, quantities, wishlist, and wantlist entries you create in the app, stored in our database (Firebase Firestore) so they sync across your devices and, for shared wallets, with the collaborators you explicitly invite.
  • Usage events: product analytics (e.g. "a wallet was created", "a search was performed") tied to your account ID and email address, used only internally to understand which features are actually used and to support your account. They are never sold or used for advertising. No card values or portfolio amounts are included in these events.
  • Card scanning: when you use the camera to scan a card, text recognition runs entirely on your device using Apple's built-in Vision framework. Photos are never uploaded to our servers or to any third party.
  • Face ID / Touch ID: used only to lock the app locally on your device via Apple's LocalAuthentication framework. Biometric data never leaves your device and is never seen by us.

Data we do not collect

We do not collect location data or contacts.

How data is used

  • To operate your account and sync your portfolio across devices.
  • To calculate card and portfolio prices, using our own backend which queries public trading card market data.
  • To understand product usage in aggregate and improve the app.
  • To show ads that keep Grail free (see "Advertising" below).

We do not sell your data. Other than the advertising identifiers described below, shared with Google AdMob for ad serving, we do not share your data with data brokers.

Advertising

Grail is free to use and is supported by ads served through Google AdMob. We currently show banner ads only — no interstitial or rewarded ads.

  • Consent (EEA/UK): before showing ads, we ask for your consent through Google's User Messaging Platform (UMP), as required by GDPR/UK data protection law. You can choose to see only non-personalized ads.
  • App Tracking Transparency (iOS): after your first meaningful action in the app — not on first launch — iOS will ask whether Grail can track you across other companies' apps and websites for personalized advertising. If you decline, you will still see ads, just not personalized ones.
  • What AdMob may collect: depending on the choices above, AdMob may collect an advertising identifier (such as Apple's IDFA, only if you grant tracking permission), your IP address, and general device and app-usage signals to select and measure ads. This data is handled by Google under its own Privacy Policy.

If we ever introduce a paid plan, we plan to let subscribers remove ads entirely — this policy will be updated when that happens.

Third-party services

  • Firebase (Google) — authentication and database storage.
  • Cloudflare Workers — our own backend for price history and card data.
  • Axiom — internal product analytics, tied to your account ID and email address.
  • Google AdMob — serves ads to keep Grail free; see "Advertising" above.

Shared wallets

If you join or create a shared wallet, the cards, quantities, and wantlist entries in that wallet are visible to every member of that wallet. Your email address is also visible to the other members in the wallet's member list, so they know who is in it.

Data retention & deletion

You can request deletion of your account and all associated data at any time by contacting us at [email protected]. We will delete your data within 30 days, except where we are required to retain it by law.

Children

Grail is not directed at children under 13, and we do not knowingly collect data from them.

Changes to this policy

We may update this policy as the app evolves. Material changes will be reflected here with an updated "Last updated" date.

Contact

Questions about this policy? Email us at [email protected].

We use a couple of cookies to keep this site working — no analytics or ads run without your OK. Cookie Policy