Foilscope
Privacy
The short version: we ask for a username and nothing else. There is no email box you have to fill in, no password for anyone to steal, and the card scanner never sends a photo anywhere.
Your account is a name and a passkey
When you sign up, you choose a username. That is the only thing we ask for. Your passkey — your face, your fingerprint, or your device's PIN — stays on your device; what reaches us is the public half of a key pair and an opaque identifier for it.
This is not a detail. A password database is a thing that can be stolen and cracked at leisure. A list of public keys is a thing you could publish on a billboard. We hold the second kind.
You may add a recovery email. It is optional, it is marked optional, and it is used for exactly one thing: helping you back in if you lose every passkey. It is not a mailing list, we send no marketing, and you can delete it from your account page whenever you like.
The scanner never uploads a photo
Point the scanner at a card and the camera frame is read on your device. What crosses the network is a card number — text like "FB05-041" — and nothing else. No image is uploaded, none is stored, and there is no bucket of photographs of your kitchen table anywhere in this system.
What we do store
- Your username and display name. Plus a recovery email if you chose to add one.
- Your portfolio. The cards you record, what you paid, the shelf you filed them on, and any notes you write. This is the product; it is what you came here for. It is never published, never shown to another user, and never an input to a public price.
- Your watchlist and alert rules, and the alerts they fired.
- Your sessions. A hash of the sign-in cookie, when it was made, and the browser string it came from — so you can see your signed-in devices and end the ones you do not recognise.
- Feedback you send, if you press the feedback button: your message, the page you were on, and your screen size. No screenshot is taken.
What reaches the server anyway
Being honest about the unglamorous parts: your IP address reaches our server, because that is how the internet works. We use it to rate-limit sign-ups and sign-ins, and we do not keep it — the abuse log stores a one-way fingerprint made with a salt that changes daily, which can tell us "the same host tried forty times today" and can tell nobody anything at all tomorrow.
Web server logs are kept short and are not joined to your account. There is no analytics script on this site, no advertising pixel, and no third-party tracker. Nothing you do here is sold, shared or syndicated, because there is nobody to sell it to and it is not that kind of product.
If you connect your own alert bot
Alerts go to your Telegram bot or your Discord webhook, not to a shared Foilscope one. The token or URL you paste is encrypted before it is written down, and disconnecting deletes it. We never operate a bot that can see everyone's alerts at once.
Where the prices come from
Prices are market data. Foilscope reads publicly listed and completed sales from marketplaces, plus grading populations from PSA and Beckett, and computes a range from them. That is a statement about the market, not about you, and your holdings are never part of the calculation — not yours, not anybody's.
Deleting things
You can remove holdings, watch targets, alert rules and your recovery email from inside the app at any time. To delete the whole account, use the feedback button and say so; it is done by hand today because the product is small enough that a human reading the request is faster and safer than a button nobody has tested.
Changes, and how you will know
If what we store ever changes, this page changes with it and the change is noted in the app. It is a short page on purpose: everything on it is something we could be held to.
