1. Scope and controller
This policy applies to the GrandFolio mobile application for iOS and Android and to grandfolio.app. GrandFolio is developed and operated by AristiDevs (Aris Guimera), who acts as the data controller for the personal data described here.
GrandFolio is an independent companion for collectors and is not affiliated with Bandai, Shueisha, Toei Animation, or the One Piece Card Game.
2. Information we process
The information involved depends on the features you choose to use. Guest mode does not require you to provide identity information.
- Local app data: collection entries, quantities, card condition and language, wishlists, decks, price alerts, trade history, settings, and app preferences.
- Optional account data: email address, internal user identifier, authentication tokens, and the login provider you choose (email, Google, or Apple). GrandFolio does not receive your Google or Apple password.
- Optional synchronized content: collection and wishlist data, deck names and cards, alert thresholds, and shared trade information such as participant identifiers or names, cards, currency, status, and timestamps.
- Notifications: a device push token, platform, and alert or trade identifier when you enable notifications.
- Subscriptions: an anonymous or account-linked purchase identifier, product, entitlement, renewal status, and transaction status. Apple, Google, and RevenueCat process the purchase; GrandFolio does not receive your full payment-card details.
- Technical and usage data: app version, device and operating-system information, IP address, app interactions, performance information, and crash diagnostics that may be processed by our infrastructure and the iOS Firebase SDKs.
- Support data: your email address and any information you include when you contact us.
3. Camera and local-first storage
Camera access is optional and is used only when you open the scanner. Card codes and visual features are recognized on your device. Camera frames are not uploaded to GrandFolio or stored on our servers for card recognition.
In guest mode, your collection and related app content remain in local storage under the control of your device. They may be included in operating-system backups depending on your device settings. Deleting the app or clearing its storage may permanently remove local data unless you previously enabled synchronization or made a separate backup.
4. Why we process data and our legal bases
We process data to provide authentication, optional backup and cross-device synchronization, card and price features, shared trades, notifications, subscriptions, customer support, security, fraud prevention, and service reliability.
Where the GDPR or similar law applies, we rely on performance of our agreement with you for requested app features; your consent for optional permissions and choices where consent is required; our legitimate interests in securing, maintaining, and improving GrandFolio; and legal obligations for records or valid requests. You can withdraw a permission or consent through your device or app settings without affecting earlier lawful processing.
5. Service providers and sharing
We do not sell personal data. We disclose only the information needed for the services you use to providers acting on our behalf or as independent controllers.
- Supabase provides account authentication, database hosting, synchronization, and server functions.
- Google and Apple provide optional sign-in and app-store services. Google Firebase provides push notifications and, on iOS, analytics and crash diagnostics.
- RevenueCat manages subscription offerings, entitlements, purchase status, and restoration together with Apple App Store and Google Play.
- Vercel hosts grandfolio.app and may process request metadata needed to deliver and secure the site.
- Cardmarket and TCGPlayer provide market context. If you follow a link to a third-party service, that service handles the visit under its own privacy terms.
- Authorities or professional advisers may receive data when required by law or reasonably necessary to protect rights, users, and service security.
6. International transfers
Some providers may process information outside your country or the European Economic Area. When required, we rely on adequacy decisions, contractual safeguards such as the European Commission's Standard Contractual Clauses, or another lawful transfer mechanism. You may contact us for more information about safeguards relevant to your data.
7. Retention
Local data remains on your device until you delete it, clear app storage, or uninstall the app, subject to device backups. Cloud account and synchronized content are kept while your account is active or as needed to provide the feature.
After a valid deletion request, we aim to delete or de-identify account-linked data within 30 days. Limited information may remain temporarily in protected backups or be retained when required for security, fraud prevention, disputes, or law. Shared trade records may also need to preserve the other participant's data; your identifying data will be removed or de-identified where applicable. Support correspondence is retained only as long as reasonably needed to resolve the request and keep necessary records.
8. Security
We use safeguards appropriate to the data and service, including encrypted network connections, authentication, access controls, and database rules that separate user records. No method of storage or transmission is completely secure, so we cannot promise absolute security. Keep your device and account credentials protected.
9. Delete your account and data
You may request permanent deletion at any time by emailing aris.guimera@gmail.com from the address associated with your account and using the subject “GrandFolio account deletion”. Include only the information needed to identify the account. We may ask you to verify ownership before acting.
Deletion covers the account and associated cloud data, subject to the limited retention described above. It does not automatically cancel an Apple App Store or Google Play subscription; cancel the subscription in your store account to prevent future billing. Data stored only on your device can be removed from the app or by deleting the app and its backups.
Request account deletion10. Your privacy rights
Depending on where you live, you may have rights to access, correct, delete, restrict, object to processing, or receive a portable copy of personal data, and to withdraw consent. You may also complain to your local data-protection authority; in Spain, this is the Agencia Española de Protección de Datos (AEPD).
Email us to exercise a right. We will respond within the time required by applicable law and may request reasonable verification. Some rights are subject to legal exceptions.
11. Children
GrandFolio is not directed to children under 13, or a higher minimum age where local law requires it, and we do not knowingly collect their personal data without the authorization required by law. If you believe a child provided personal data improperly, contact us so we can investigate and delete it.
12. Changes and contact
We may update this policy when GrandFolio, its providers, or legal requirements change. The current version and its update date will remain available at this URL; material changes will be highlighted in the app or on the site when appropriate.
For privacy questions, requests, or complaints, contact AristiDevs (Aris Guimera) at aris.guimera@gmail.com.
