Skip to content
Find The Hits Find The Hits
  • Features
  • Pricing
  • Community
  • Our Story
  • Join the Beta

Privacy Policy

Effective Date: March 3, 2026  |  Last Updated: March 3, 2026

Overview

FTH ("the App") is a sports card collection management app for iOS, developed by Bishop Technology Solutions, LLC ("we", "us", "our"). Your privacy is important to us. This policy explains what data the App collects, how it is stored, what third-party services the App communicates with, and your rights.

We do not sell, rent, or share your personal information with third parties for advertising or marketing purposes. We do not use advertising frameworks or collect Apple's Identifier for Advertisers (IDFA).

Summary of Data Collected

Data Type Collected Linked to Identity Used for Tracking
Name Yes (Sign In with Apple, optional) Yes No
Email Address Yes (Sign In with Apple, optional) Yes No
Photos Yes (card photos taken or selected by user) Yes No
Coarse Location Yes (approximate, for card show finder) No No
User ID Yes (anonymous Sign In with Apple identifier) Yes No
Product Interaction Yes (anonymized feature usage via TelemetryDeck) No No
Device Identifier Yes (double-hashed, via TelemetryDeck) No No

Data Collection

The App stores your card collection data locally on your device. We do not maintain user accounts on our servers and do not store your personal data on company-operated servers beyond what is described in this policy. Specific data flows to third-party services are detailed in the sections below.

  • One privacy-focused analytics integration (TelemetryDeck) that collects anonymized usage signals only
  • Zero advertising frameworks or IDFA collection
  • Zero server-side user accounts managed by us
  • No ad tracking of any kind

Data Storage

All collection data you enter (card details, photos, financial information) is stored locally on your device using Core Data. If you have iCloud enabled, your data syncs to your personal iCloud account via Apple's CloudKit framework. This sync is between your devices only and is governed by Apple's Privacy Policy. We do not have access to your iCloud data.

Camera, Photos, and On-Device Processing

The App requests camera access for the following features:

  • Magic Scan (OCR): Captures photos of trading cards and extracts card information using Apple's Vision framework entirely on your device.
  • Barcode Scanning: Detects barcodes on professionally graded card slabs (e.g., PSA slabs) using Apple's Vision framework to extract certification numbers for lookup.
  • Card Photos: Photos you take or import are stored locally and in your iCloud account if iCloud sync is enabled. Images are never uploaded to external servers.

On-Device AI and Machine Learning:

All AI and machine learning processing in the App runs entirely on your device:

  • Apple Vision Framework: Text recognition (OCR) and barcode detection for card scanning.
  • Apple Intelligence (iOS 18+): When available on supported devices, on-device language models enhance OCR accuracy. This processing uses Apple's Foundation Models framework and never sends data to any cloud service.

No images, scanned text, or AI processing results are transmitted off your device.

Authentication

FTH uses Sign In with Apple for account authentication. When you sign in, Apple provides the App with a unique anonymous user identifier and, if you choose to share it, your name and email address (you may choose "Hide My Email" to receive a private relay address instead). Your anonymous user identifier is stored locally in your device's Keychain for session persistence. We do not store your Apple ID credentials beyond this anonymous identifier. Sign In with Apple is governed by Apple's Privacy Policy.

Face ID and Touch ID

The App offers optional biometric locking using Face ID or Touch ID. Biometric data is handled entirely by Apple's Local Authentication framework and never accessed or stored by the App.

Analytics

The App uses TelemetryDeck, a privacy-first analytics service headquartered in Germany, to understand aggregate feature usage. TelemetryDeck helps us improve the App by showing which features are used most and where users encounter problems. All analytics data is processed within the European Union.

What TelemetryDeck Collects:

  • Anonymized product interaction data: Feature usage events such as "card scanned," "collection created," or "price lookup performed." These signals contain no personal information.
  • Double-hashed device identifier: TelemetryDeck generates a device identifier that is cryptographically hashed twice on your device before transmission. This is not Apple's IDFA or IDFV. Neither we nor TelemetryDeck can reverse this hash to identify you personally.

What TelemetryDeck Does Not Collect:

  • No Apple Identifier for Advertisers (IDFA)
  • No Identifier for Vendors (IDFV)
  • No names, email addresses, or contact information
  • No card data, collection contents, or photos
  • No precise or approximate location
  • No device fingerprinting
  • No cross-app or cross-site tracking

Analytics data is not linked to your identity. For more information, see TelemetryDeck's Privacy Policy.

Market Price Lookups

The App includes an optional Market Price feature that checks recent sale prices for cards in your collection. When you initiate a price lookup, the App sends a search query containing only card details (player name, year, brand, set name, and card number) to the SportsCardsPro API (sportscardspro.com).

  • No personal information (name, email, device ID, or location) is included in price lookup requests.
  • Price lookup data is cached locally on your device for up to 7 days to reduce unnecessary network requests.
  • This feature is entirely optional. If you do not use price lookups, no data is sent to SportsCardsPro.

SportsCardsPro's use of query data is governed by their own privacy policy, available on their website.

Compare Prices (Browser Links):

The App provides "Compare Prices" links that open external websites in Safari:

  • 130Point.com: Opens the 130Point sold prices search page.
  • eBay Sold Listings: Opens an eBay search pre-filtered to sold/completed listings.

These links open in your device's browser. The App does not send data to these services directly.

Graded Card Certification Lookup

The App can look up certification data for professionally graded cards using cert numbers detected via barcode scanning or entered manually.

  • What is sent: Only the certification number is transmitted. No personal information, device identifiers, or location data is included.
  • How it works: Cert lookup requests are sent to a Supabase Edge Function that proxies the request to PSA's public API (api.psacard.com). The proxy does not log or store your requests.
  • What is returned: Card metadata including player name, year, brand, card number, grade, and population data.
  • Caching: Cert lookup results are cached in memory on your device for 5 minutes.
  • Rate limits: Lookups are limited to 100 per day, tracked locally on your device.

Card Shows and Location Data

The App's Discover tab helps you find upcoming card shows and hobby news. Card show event data is hosted on our Supabase server infrastructure.

Location Usage:

  • When you use "Shows Near Me," your approximate location coordinates are sent to our Supabase server to calculate proximity to card shows. Location data is used only for this proximity calculation and is not stored on our servers beyond the duration of the request.
  • Location access is only requested when you use the Discover tab and can be denied or revoked at any time in your device's Settings.
  • If you deny location access, you can still browse card shows by state or date.
  • Your last known location is cached locally on your device for faster display when you reopen the App.
  • Your location is never used for advertising or shared with third parties for marketing purposes.

Hobby News:

The Discover tab includes a hobby news feed aggregated from public RSS sources. No personal data is sent or stored in connection with viewing news articles.

Apple MapKit:

Card show locations are displayed using Apple's MapKit framework, governed by Apple's Privacy Policy.

In-App Purchases and Subscriptions

The App offers optional subscriptions ($3.99/month, $29.99/year, or $79.99 lifetime) to unlock additional features. These transactions are processed entirely by Apple through the App Store. We do not collect or have access to your payment information.

Both free and paid subscription tiers collect the same categories of personal information. The paid tier provides additional features but does not require additional personal data. Subscription pricing is not based on the value of your personal information.

Data Export and Deletion

You can export your entire collection to CSV at any time. You can delete individual cards, collections, or all data from within the App. Uninstalling the App removes all local data. iCloud data can be managed through your device's iCloud settings (Settings > Apple ID > iCloud > Manage Storage).

Data Retention

Data Category Retention Period
Card collection data Stored locally until you delete it or uninstall the App
iCloud synced data Retained in your personal iCloud account until you delete it via the App or iCloud settings
Sign In with Apple identifier Retained locally until you sign out or delete the App
TelemetryDeck analytics Retained by TelemetryDeck per their data retention policy (anonymized, non-identifiable)
Price lookup cache 7 days, then automatically purged
Certification lookup cache 5 minutes, then automatically purged
Location data Used ephemerally for proximity calculation; cached locally for the current session only
App preferences Retained in UserDefaults until you delete the App

Third-Party Services

Service Data Sent Purpose Linked to Identity
Apple CloudKit (iCloud) Your collection data, photos Data sync between your devices Yes (your Apple ID)
Apple Sign In None (Apple sends to App) Authentication Yes (anonymous ID)
TelemetryDeck Double-hashed device ID, anonymized usage events Aggregate analytics No
SportsCardsPro Card details (player, year, brand, set, number) Market price lookups No
Supabase Approximate location (Shows Near Me), certification numbers Card show proximity, PSA cert lookup proxy No
PSA (via proxy) Certification number only Graded card certification lookup No
Apple MapKit Map tile requests (handled by Apple) Map display for card shows Per Apple's policy

We maintain data processing agreements with our third-party service providers as required by applicable law, ensuring they process your data only for the purposes described in this policy.

How We Obtain Consent

For device permissions (camera, photos, location), we request your consent through iOS system permission dialogs at the point of first use. You can modify or revoke these permissions at any time in your device's Settings app.

Analytics collection via TelemetryDeck uses anonymized, non-personal data processed under legitimate interest (GDPR) and does not require individual opt-in consent.

Children's Privacy (COPPA)

The App is not directed at children under 13. We do not knowingly collect personal information from children under 13 as defined by the Children's Online Privacy Protection Act (COPPA). If we become aware that we have inadvertently collected personal information from a child under 13, we will promptly delete that information within 30 days.

Parents or guardians who believe their child has provided personal information may contact us at support@fthcards.com and we will delete such information promptly. Age restrictions are additionally enforced through Apple's Family Sharing controls and App Store age rating.

The App's analytics service (TelemetryDeck) uses double-hashed identifiers that cannot identify individual users, including children.

European Users (GDPR)

If you are located in the European Economic Area (EEA), the United Kingdom, or Switzerland, the following applies:

Data Controller:

Bishop Technology Solutions, LLC
21168 East Ocotillo Rd #1154
Queen Creek, AZ 85142
United States
Email: support@fthcards.com

Bishop Technology Solutions, LLC is not required to appoint a Data Protection Officer under GDPR Article 37 due to the nature and scale of our processing activities. For privacy inquiries, contact support@fthcards.com.

Legal Basis for Processing:

Processing Activity Legal Basis
Card collection storage and management Contract performance (Art. 6(1)(b))
iCloud sync Consent (Art. 6(1)(a)): you enable iCloud on your device
Sign In with Apple authentication Contract performance (Art. 6(1)(b))
TelemetryDeck analytics Legitimate interest (Art. 6(1)(f)): improving app quality
Market price lookups Contract performance (Art. 6(1)(b))
Location for card show proximity Consent (Art. 6(1)(a)): you grant location permission
Camera and photo access Consent (Art. 6(1)(a)): you grant device permissions
Biometric app lock Consent (Art. 6(1)(a)): you enable the feature

Your Rights:

Under the GDPR, you have the right to:

  • Access your personal data
  • Rectify inaccurate personal data
  • Erase your personal data ("right to be forgotten")
  • Restrict processing of your personal data
  • Port your data (export via CSV within the App)
  • Object to processing based on legitimate interest
  • Withdraw consent at any time by adjusting device permissions (camera, location, photos) in your device Settings or by contacting us. Withdrawal of consent does not affect the lawfulness of processing conducted prior to withdrawal.

To exercise any of these rights, contact support@fthcards.com with the subject line "Privacy Request." We will respond within 30 days.

You have the right to lodge a complaint with your local data protection supervisory authority. A list of EU/EEA supervisory authorities is available at edpb.europa.eu. For UK residents, contact the Information Commissioner's Office (ICO).

International Data Transfers:

When your data is processed outside the European Economic Area, we rely on the following safeguards:

  • The EU-US Data Privacy Framework for transfers to certified US organizations
  • Standard Contractual Clauses (SCCs) approved by the European Commission where the Data Privacy Framework does not apply
  • Apple's own data processing agreements for iCloud and CloudKit services

TelemetryDeck processes all analytics data within the European Union.

California Users (CCPA/CPRA)

If you are a California resident, the following applies under the California Consumer Privacy Act and California Privacy Rights Act:

Categories of Personal Information Collected (per Cal. Civ. Code §1798.140(v)):

Category Examples Business Purpose
Identifiers Sign In with Apple anonymous ID, optional name and email Account authentication
Internet or electronic network activity Anonymized app usage analytics via TelemetryDeck App improvement and feature usage analysis
Geolocation data Approximate location when using card show features Displaying nearby card shows
Audio, electronic, visual, or similar information Card photos taken or selected within the App Card collection management, OCR scanning
Commercial information Card collection data, purchase prices, estimated values Collection tracking, market value display

Your Rights:

  • Right to Know: You may request the categories and specific pieces of personal information we have collected.
  • Right to Delete: You may request deletion of your personal information. You can also delete data directly within the App.
  • Right to Correct: You may correct inaccurate personal information by editing your data within the App or contacting us.
  • Right to Opt Out of Sale/Sharing: We do not sell your personal information as defined by the CCPA/CPRA. We do not share your personal information for cross-context behavioral advertising purposes.

To exercise any of these rights, email support@fthcards.com with the subject line "Privacy Request." We will respond within 45 days. We will not discriminate against you for exercising these rights.

Sensitive Personal Information: We do not collect sensitive personal information as defined by the CPRA.

Financial Incentives: The App offers free and paid subscription tiers. Both tiers collect the same categories of personal information. The paid tier provides additional features but does not require additional personal information. Subscription pricing is not based on the value of your personal information.

Changes to This Policy

We may update this Privacy Policy from time to time. Updates will be posted at this URL with a new "Last Updated" date. Material changes that affect how we process your personal data will be communicated through the App before they take effect. Continued use of the App after changes are posted constitutes acceptance of the revised policy.

Contact

Bishop Technology Solutions, LLC
21168 East Ocotillo Rd #1154
Queen Creek, AZ 85142
United States

For privacy questions, data requests, or concerns:
Email: support@fthcards.com
Subject line for data requests: "Privacy Request"
Response time: 30 days (GDPR) / 45 days (CCPA/CPRA)

Find The Hits Find The Hits

Find the Hits. Feed the Hobby.

  • Features
  • Pricing
  • Community
  • Our Story
  • Roadmap
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Bishop Technology Solutions, LLC. All rights reserved.

Apple, the Apple logo, iPhone, iPad, App Store, iCloud, Face ID, and Touch ID are trademarks of Apple Inc., registered in the U.S. and other countries.

Get Notified at Launch

FTH is in beta on TestFlight right now. Want us to email you when it's live on the App Store?

Notify Me at Launch
or
Join the Beta Now on TestFlight