PRIVACY

Privacy policy

Holofile is built to keep your collection on your phone. This page explains, in plain words, the little that leaves it and why.

Effective October 8, 2026

Who we are

Holofile is an app for tracking Pokémon TCG cards and sealed product. Holofile is operated by Holofile LLC, based in Florida, USA. In this policy, “Holofile”, “we” and “us” mean Holofile LLC, and we’re responsible for the personal data described here. You can reach us any time at hello@holofile.app.

This policy covers the Holofile iPhone app, its online services (accounts, Cloud sync and support) and this website.

Your collection stays on your iPhone

Holofile is local-first. Everything you add, from cards, sealed product and copies with their prices paid, grades, notes and photos to rips, sales, stats and badges, is stored in a database on your iPhone. You can use every free feature without an account, and nothing you enter is sent to us unless you turn on Cloud sync.

The app also keeps a copy of the card catalog and prices on your phone, so search and scanning work offline. To remove everything from your phone, use Settings → Data → Delete all data, or delete the app.

What the app sends to our servers

Holofile’s servers run on Cloudflare (api.holofile.app and cdn.holofile.app). Like any app that goes online, every request carries your IP address. Here’s what the app asks for and sends:

  • Catalog, prices and card images. The app downloads the card catalog, the day’s prices and card images. Detailed price files are downloaded per set, only for sets you own something in, so those requests show which sets they are. None of these requests carry an account or a device ID.
  • Price history. When you open a chart, the app asks for that card’s history. These requests don’t identify you either.
  • A random device ID. The app makes a random ID the first time it runs. It isn’t tied to your hardware, your Apple Account or Apple’s advertising identifier. It goes with spreadsheet matching and sign-in code requests (so we can stop abuse), and with Cloud sync (see below). Deleting the app deletes it.
  • Spreadsheet import. Most rows in an imported CSV are matched on your phone. Rows it can’t match are sent to our server with their card details only: name, set, number, printing, rarity, language and whether it’s a card or sealed, plus which app the file came from. Prices, quantities, conditions, grades, notes and dates never leave your phone. Our server asks an AI model running on Cloudflare (Workers AI) to pick the right card, and doesn’t save the rows. Cloudflare’s AI Gateway, which carries the request to the model, can keep a log of it, which we use only to fix matching problems.

Accounts

An account is optional and only needed for Cloud sync. You sign in with your email address: we email you a 6-digit code (sent through Cloudflare’s email service), and there’s no password.

  • What we store: your email address, when the account was created, and your sign-in sessions. Each session records the IP address and the app’s user agent at sign-in, which helps us spot account misuse. Sign-in codes are stored hashed and expire after 10 minutes.
  • Limits: to stop people flooding an inbox with codes, we count code requests per address. We store that count against a one-way hash of the address, not the address itself, and clear it after about two days.
  • On your phone: the session token is kept in the iOS Keychain.

We only email you sign-in codes. We don’t send newsletters or marketing email.

Cloud sync and photo backup

Cloud sync needs an account and Holo10, and it’s off until you turn it on. While it’s on, we store a copy of your collection so your devices stay in sync: your copies (including prices paid, purchase details, grades, cert numbers, notes and sale details), rips, box breaks, badges and photos. Each change carries your device ID and a timestamp, which is how your devices agree on the latest edit.

  • Your cloud copy is kept in Cloudflare Durable Objects, one private store per account. Photos are kept in private Cloudflare R2 storage and can only be fetched through short-lived signed links.
  • Photos are uploaded as they are. If a photo has details saved in it by your camera, such as where it was taken, those details go with it.
  • If you sign out, sync stops on that phone and everything stays on it. If Holo10 ends, sync pauses and we keep your cloud copy so it’s there if you come back. Delete your account to remove it.

Purchases

Apple handles all payments for Holo10 through the App Store; we never see your payment details. We use RevenueCat to check what you’ve bought:

  • RevenueCat receives your App Store purchase records, a random customer ID, and basic device details its SDK sends with each request: your device model, iOS version, app version, language, App Store country and Apple’s identifier for vendors.
  • If you don’t sign in, RevenueCat knows you only by that random ID. When you sign in, the app gives RevenueCat your Holofile account ID, so Holo10 follows your account to your other devices, and your account’s email address, so we can find your purchases when you ask for help. We use that address only for support and to sort out purchase problems, never for marketing.
  • Our server asks RevenueCat whether an account has Holo10 before it syncs. When you delete your account, we remove your email address from RevenueCat; it keeps the purchase history, which Apple’s billing needs.
  • RevenueCat also gives us totals, such as how many people subscribe or start a trial, which we use to run Holofile. They don’t identify you.

See Apple’s privacy policy and RevenueCat’s privacy policy.

Camera and photos

  • Camera: Holofile reads cards on your phone with Apple’s on-device text recognition and the catalog stored in the app. Frames are processed on your iPhone, written only to temporary files that are deleted as the scanner goes, and never uploaded.
  • Photo library: when you add a photo to a copy or pick a photo to scan, Holofile opens Apple’s photo picker and only gets the photos you choose.
  • Saving to Photos: when you save a share card, Holofile asks to add it to your library. It can’t read your library with that permission.

You can change any of these in the iPhone’s Settings → Holofile.

Support and this website

  • Support messages: when you write to us through the support form, we store your email address, topic, message, the app version and device you entered (if any), and the country Cloudflare estimates from your connection. We don’t store your IP address. The message is emailed to our support inbox so we can answer you, and we use your email address only to reply. We also count messages per address, as a one-way hash, to stop abuse.
  • Bot check: the support form uses Cloudflare Turnstile to tell people from bots. Turnstile looks at signals from your browser, such as your IP address and browser details, only to detect bots. See Cloudflare’s Turnstile privacy addendum.
  • This website has no analytics, no ads and no tracking cookies, and its fonts are served from our own domain. Turnstile loads only on the support page.

Server logs and metrics

Our servers keep short-lived logs to find and fix problems. A log entry describes a request (such as its address, which can include an account or card ID, and whether it worked) and can include your IP address. Cloudflare keeps these logs for 7 days.

We also record simple metrics for each request: which feature it used, whether it worked, how long it took and the Cloudflare location and country it came through. Metrics don’t include IP addresses, device IDs, account IDs or email addresses, and are kept for three months.

To limit abuse, we briefly count requests per IP address, device ID or account. These counters last minutes.

What we don’t do

  • No ads, and no advertising or tracking SDKs in the app.
  • No third-party analytics. The app contains no Google, Meta, Firebase or similar analytics.
  • We don’t sell your personal data, and we don’t share it for cross-context behavioral advertising. We don’t track you across other companies’ apps or websites, which is why Holofile never asks for tracking permission.
  • We don’t use your data to train AI models.

Who helps us run Holofile

These companies process data for us, only to provide their service and under their own privacy and security commitments:

  • Cloudflare: hosting, storage, Cloud sync, email delivery, AI matching for imports, and the Turnstile bot check.
  • Apple: the App Store, payments and the iOS features the app uses.
  • RevenueCat: checking and restoring purchases, and finding them when you ask for help.
  • Our email provider: receives support messages and the replies we send.

We may also share information if the law requires it, to protect people’s safety or our rights, or as part of a business transfer such as a merger, in which case this policy keeps applying to your data.

How long we keep things

  • Your collection on your phone: until you delete it or the app.
  • Your account: until you delete it.
  • Sessions: expire 90 days after you last use the app signed in; signing out or deleting your account ends them.
  • Sign-in codes: work for 10 minutes and are deleted within a day. Code counters: up to two days.
  • Cloud copy and photos: until you delete your account. Items you delete are removed from the cloud copy after 90 days, and deleted photos after 31 days, so your other devices can catch up first.
  • Support messages: two years, then our servers delete them automatically. Ask us and we’ll delete them sooner, along with the emails about them. Message counters last a day.
  • Server logs: 7 days. Metrics: three months.
  • Purchase records at Apple and RevenueCat are kept under their policies. The email address RevenueCat holds for a signed-in account is removed when you delete the account. Tell us if you’d like us to ask RevenueCat to delete your purchase history too.

Deleting and exporting your data

  • Delete your account in the app: Settings → Account → Delete account. This deletes your account and sessions, your Cloud sync copy and your backed-up photos from our servers right away, and removes your email address from RevenueCat; server logs that mention the account age out within 7 days. Your collection stays on your iPhone. It doesn’t cancel a Holo10 subscription, which you manage in your Apple Account.
  • Delete everything on your phone: Settings → Data → Delete all data, or delete the app.
  • Export: with Holo10, Settings → Data → Export CSV saves your whole collection as a spreadsheet. Anyone can ask us for a copy of what our servers hold about them.

Your rights

Wherever you live, you can ask us to tell you what personal data we have about you, give you a copy, correct it or delete it. Email hello@holofile.app from the address you use with Holofile, or tell us which account it’s about, and we’ll answer within 30 days. We won’t treat you differently for asking.

If you’re in the EU, the EEA or the UK

You also have the right to object to or restrict how we use your data and to move it elsewhere. We rely on these legal bases: providing the app and the services you ask for (accounts, sync, purchases and support); our legitimate interests in keeping Holofile secure, preventing abuse and fixing problems (logs, metrics, limits and the bot check); and your consent for camera and photo access, which you can withdraw in iOS Settings. You can complain to your local data protection authority.

If you’re in California or another US state with a privacy law

In the past 12 months we’ve collected identifiers (email address, account ID, device ID, IP address), purchase status, the content you choose to sync or send us (collection data, photos and support messages), server logs and approximate location (country). We use them only for the purposes in this policy. We don’t sell or share personal information for cross-context behavioral advertising, and we don’t use sensitive personal information to infer things about you. You can use an authorized agent to make a request.

Children

Anyone can use Holofile on their phone without giving us personal data: no account is needed, and the collection stays on the device. Accounts, purchases and support are for people 13 and older, and we don’t knowingly collect personal data from children under 13. If you think a child under 13 has given us personal data, for example by creating an account, email us and we’ll delete it.

Where your data is processed

Cloudflare runs our servers on its global network, so your data may be processed in the United States and other countries where Cloudflare operates, which may have different data protection laws from yours. Where the law requires it, these transfers are covered by safeguards such as the European Commission’s standard contractual clauses in our providers’ terms.

Security

Everything travels over encrypted connections. Sign-in codes and per-address counters are stored hashed, your session token sits in the iOS Keychain, and backed-up photos are private. No system is perfectly secure, so if something goes wrong we’ll tell you as the law requires.

Changes to this policy

If we change how Holofile handles your data, we’ll update this page and its effective date. If a change is significant, we’ll also tell you in the app before it takes effect.

Contact us

Questions, requests or worries: hello@holofile.app, or the form on the support page. Holofile is operated by Holofile LLC, Florida, USA.