the small print

Privacy policy

Effective October 4, 2026

Summary

  • We collect what's needed to run your account and your collection.
  • No ads, no tracking cookies, no selling or sharing your data for advertising.
  • Only anonymous, aggregated sale prices are ever shown to anyone else, and you can opt out.
  • Payments go through Stripe; we never see your card. Affiliate links are labelled.
  • Delete your account yourself, any time, from Account settings. It removes everything.

1. Who is responsible

Tung Nguyen runs Pullfolio and is responsible for the personal information described here. Contact: hello@pullfolio.app. This policy is part of our terms of service.

2. What we collect

  • Account: your name, email address, a salted hash of your password if you set one (never the password itself), whether your email is verified, the invite code you signed up with, and short-lived one-time tokens for setting or resetting a password.
  • How you found us: if the link you first arrived by carried a campaign tag (such as ?src=reddit), that tag; otherwise, if another website linked you to us, that website's name only (such as reddit.com), never the page or anything else from its address. We save it on your account when you sign up.
  • Sign-in and security: for each session, its token and the IP address and browser user agent it was created from. We also count recent requests to our sign-in and account endpoints per IP address to block password guessing and abuse.
  • Sign-in with Google, Apple or Discord: if you sign up with or connect one of these, it sends us your name, your email address and whether it has verified that address, the web address of your profile picture (Google and Discord; Apple doesn't share one) and the ID of your account there. Apple shares your name only the first time you sign in. We also keep the tokens it gives us, encrypted, only so we can revoke our access when you disconnect it or delete your account. We ask only for your basic profile and email address: we never post anything on your behalf or read anything else from that account, such as contacts, friends or servers. If you use Apple's Hide My Email, we receive a private relay address ending in @privaterelay.appleid.com instead of your real one; it becomes its own Pullfolio account, separate from any account under your real address, and the emails we send it pass through Apple's relay to you.
  • Your collection and sales: the cards you add, quantities, what you paid, acquisition dates and notes; the sales you record or import, with their price, fees, shipping, sales tax, platform and date; daily snapshots of your portfolio's value; and the matching rules and column mappings you save. Imports can include item titles, SKUs and order or line IDs from the marketplace file; we keep the fields the import maps, plus the file name.
  • Binders, goals and displays: your binders, their covers and pocket order, how you protect each card (sleeve, toploader, slab with the grader, grade and the cert number you type), your goals with their target prices, your display-case plans, and your settings (theme, page sounds, the first-run tips you've seen, how many plan images you've exported). A slab's label photo never leaves your device: it's kept in your browser's storage and isn't uploaded.
  • Alerts: the price watches behind your goals and any sell alerts you set, and a log of the alert emails we send you.
  • Pullfolio+: if you subscribe, Stripe collects your payment details and billing address. We keep only your Stripe customer ID and, for each purchase, its plan, status, renewal date, whether it's set to cancel, and the Stripe IDs needed to match refunds and disputes. We never receive or store card numbers.
  • Feedback: the message, the page you sent it from (including its full address), your email address and your account ID. It is stored and also emailed to us.
  • Usage counts: when you open a public page (home, games, sets, cards, search), your browser tells us its path and we add one to that path's count for the day. The count stores no user, IP address, cookie or query string, and bots are excluded.
  • Server logs: our host keeps the server's logs: each request's method, address (including its query string, such as a search term or an invite code), status and timing, plus details of any errors, which can include data that was being processed at the time.
  • Error reports: when the server or the page in your browser hits an error, a technical report (error message, stack trace, page address without its query string, and details about our server or your browser). It is configured to leave out your name, email, cookies, request headers and form contents, though an error message can occasionally contain a fragment of the data being processed. Reports from your browser go straight to Sentry, which sees your IP address like any website you visit; we don't store it with the report.
  • Email delivery: our email provider records whether each email was delivered and, through a tracking pixel and link redirects it adds, whether it was opened or a link in it clicked. We only use this to diagnose delivery problems.

We never collect card or bank details ourselves (Stripe does, at checkout), and we don't buy data about you from anyone.

3. How we use it

  • To create and secure your account, let you sign in (including with Google, Apple or Discord), verify your email and reset your password.
  • To show you your collection, its value, profit and loss, and history, and to send the price alert emails you asked for.
  • To answer feedback and support requests and to fix bugs.
  • To see which pages are used, from the anonymous counts above.
  • To see which links and websites bring new sign-ups, as counts per day that don't name anyone.
  • To enforce our terms and comply with the law.

We use your email only for account and service messages (verification, password reset, security notices, alerts, and important changes to the Service or these policies). No marketing email without your separate consent.

4. Cookies and browser storage

When you sign in we set one essential cookie that keeps you signed in. If you pick light or dark mode we set a small pf-theme cookie so pages open in that theme. If you arrive by a tagged link or from another website, a small pf-src cookie holds that tag or website's name for up to 30 days so we can save it on your account if you sign up. We only ever read it when an account is created, it's cleared when you open your account, and it's ours alone, never sent to anyone else. That's all: no advertising, analytics or third-party tracking cookies. Your browser's local storage remembers your Goals sort order, its IndexedDB holds any slab label photos you add, and its session storage remembers scroll positions so the back button returns you to the same place; none of that leaves your browser. Because we don't track you across sites, we don't show a cookie banner, and we don't respond differently to “Do Not Track” signals because there is nothing to switch off.

5. Who else processes your data

We don't sell or rent personal information, and we don't share it for cross-context behavioural advertising. These service providers process it on our behalf, only to run the Service:

  • OVHcloud hosts our server in the United States. The website, the database, the server logs described above and our encrypted backups are all on it, so it carries every request, including your IP address.
  • Brevo delivers our emails, so it sees your email address and the email contents, and records the delivery events described above.
  • Sentry receives the error reports described above.
  • Google, Apple and Discord handle the sign-in when you choose to continue with one of them, under their own privacy policies: they learn that you signed in to Pullfolio and send us the details described above. If you use Apple's Hide My Email, Apple's relay forwards our emails to you.
  • Stripe processes Pullfolio+ payments, subscriptions, refunds and the billing portal under its own privacy policy, and tells us when a purchase changes.

Price data comes from TCGplayer (via TCGCSV), JustTCG, Cardmarket, Scryfall, YGOPRODeck, TCGdex, Lorcast and PriceCharting; we send them only card and set identifiers, never anything about you. Card images load directly from their image hosts (TCGdex, Lorcast and OPTCG API), which see your IP address and browser like any website you visit. Shop links go to TCGplayer or eBay; eBay links marked “affiliate link” pass through the eBay Partner Network, which learns that the click came from us, never who you are on Pullfolio. We may also disclose information if the law requires it, to protect people's safety or our rights, or to a successor if the Service is transferred (with this policy still applying).

The website and database are hosted in the United States. Brevo is based in France and processes email in the European Union, and Sentry may store error reports in the United States or the European Union. If you use the Service from elsewhere, your data is transferred to those countries.

6. How long we keep it

  • Account, collection, binders, goals, displays, sales and alerts: until you delete them or your account.
  • Pullfolio+ purchase records: deleted with your account. Stripe keeps its own payment records as the law requires (for example for tax and fraud prevention).
  • Sessions: they expire about 7 days after you last used the site, and signing out deletes them. The record of an expired session (with its IP address and user agent) can stay in the database until your account is deleted.
  • Connected Google, Apple or Discord accounts and their tokens: until you disconnect them or delete your account. Either way we delete the tokens and ask the provider to revoke our access.
  • Rate-limit counters: removed automatically, normally within minutes.
  • Feedback: kept until you delete your account, which deletes it too; the copy emailed to us is deleted from our inbox at the same time on request.
  • Anonymous page counts: kept indefinitely; they contain no personal data.
  • Backups: an encrypted copy of the database is made nightly and each copy is deleted after 14 days, so data you delete can remain in backups for up to 15 days.
  • Server logs: kept on our server and deleted automatically as they rotate out. Email delivery records and error reports: kept by Brevo and Sentry for the limited periods their services allow.

7. Your choices and rights

  • Access and export: view everything in your account and download your holdings and sales as CSV at any time.
  • Correct or delete: edit or delete binders, goals, displays, items, sales and alerts yourself. To delete your account, use Delete my account in Account settings and confirm with your password (or, if your account has no password, by signing in again with Google, Apple or Discord): it first cancels any Pullfolio+ subscription (refunds, where they apply, are handled by email), then deletes your account and everything in it, feedback and connected sign-in accounts included, straight away, and asks Google, Apple or Discord to revoke our access. You can also email hello@pullfolio.app from the address on the account and we'll do it within 30 days.
  • Sign-in methods: connect or disconnect Google, Apple or Discord under Sign-in methods in Account settings. Disconnecting one deletes the tokens we hold for it and revokes our access there. You can't remove your last way to sign in unless your account has a password; we can email you a link to set one.

Depending on where you live (for example California, Virginia or the EU/UK), you may also have rights to know, access, correct, delete or port your data, to object to or restrict processing, and not to be discriminated against for using these rights. Email us to use any of them; we'll verify the request comes from the account holder and respond within the time the law requires. You can appeal a decision by replying to our answer, and you may complain to your data protection authority. Where the GDPR applies, we rely on performing our contract with you (your account and collection), our legitimate interests (security and bug fixing) and legal obligations.

8. Security

Connections to the site and between our servers and the database are encrypted with TLS, passwords are hashed, tokens from Google, Apple and Discord are encrypted, sign-in attempts are rate limited, and backups are encrypted. No system is perfectly secure; if a breach affects your information we'll notify you as the law requires.

9. Children

The Service isn't directed to children under 13 and we don't knowingly collect their information. If you believe a child under 13 has an account, contact us and we'll delete it.

10. Changes

We'll post any update here with a new effective date and email you about material changes at least 14 days before they take effect.