Skip to content
Find The Hits Find The Hits
  • Features
  • Community
  • Our Story
  • Get the App

Privacy Policy

Last updated: March 2, 2026

Overview

For The Hobby ("the App") is a sports card collection management app for iOS, developed by Bishop Technology Solutions, LLC ("we", "us", "our"). Your privacy is important to us. This policy explains what data the App collects, how it is stored, what third-party services the App communicates with, and your rights.

Data Collection

For The Hobby does not collect or store your personal data on our own servers. The App does not use advertising frameworks, does not collect or use Apple's Identifier for Advertisers (IDFA), and does not participate in ad tracking.

  • One privacy-focused analytics integration (TelemetryDeck) that collects anonymous usage signals only — no personal data, no device IDs, no IP addresses
  • Zero advertising frameworks
  • Zero server-side user accounts managed by us
  • No IDFA collection or ad tracking

The App uses a privacy-first analytics service (TelemetryDeck) and communicates with third-party services for specific features. These are described in detail below.

Data Storage

All collection data you enter (card details, photos, financial information) is stored locally on your device using Core Data. If you have iCloud enabled, your data syncs to your personal iCloud account via Apple's CloudKit framework. This sync is between your devices only and is governed by Apple's Privacy Policy. We do not have access to your iCloud data.

Camera, Photos, and On-Device Processing

The App requests camera access for the following features:

  • Magic Scan (OCR): Captures photos of trading cards and extracts card information using Apple's Vision framework entirely on your device.
  • Barcode Scanning: Detects barcodes on professionally graded card slabs (e.g., PSA slabs) using Apple's Vision framework to extract certification numbers for lookup. Barcode detection runs on captured photos, not a live camera feed.
  • Card Photos: Photos you take or import are stored locally and in your iCloud account if iCloud sync is enabled. Images are never uploaded to external servers.

On-Device AI and Machine Learning:

All AI and machine learning processing in the App runs entirely on your device:

  • Apple Vision Framework: Text recognition (OCR) and barcode detection for card scanning.
  • Apple Intelligence (iOS 18+): When available on supported devices, on-device language models enhance OCR accuracy. This processing uses Apple's Foundation Models framework and never sends data to any cloud service.

No images, scanned text, or AI processing results are transmitted off your device.

Authentication

For The Hobby uses Sign In with Apple for account authentication. When you sign in, Apple provides the App with a unique anonymous identifier and, if you choose to share it, your name and email address. We do not store your Apple ID credentials. Sign In with Apple is governed by Apple's Privacy Policy.

Face ID and Touch ID

The App offers optional biometric locking using Face ID or Touch ID. Biometric data is handled entirely by Apple's Local Authentication framework and never accessed or stored by the App.

Analytics

The App uses TelemetryDeck (telemetrydeck.com), a privacy-first analytics service based in Germany, to understand aggregate feature usage. TelemetryDeck helps us improve the App by showing which features are used most and where users encounter problems.

What TelemetryDeck Collects:

  • Aggregate usage signals: Feature usage events such as "card scanned," "collection created," or "price lookup performed." These signals contain no personal information.
  • Double-hashed user identifiers: TelemetryDeck generates a user identifier that is cryptographically hashed twice on your device before transmission. Neither we nor TelemetryDeck can reverse this hash to identify you personally.

What TelemetryDeck Does Not Collect:

  • No Apple Identifier for Advertisers (IDFA)
  • No Identifier for Vendors (IDFV)
  • No names, email addresses, or contact information
  • No card data, collection contents, or photos
  • No precise or approximate location
  • No device fingerprinting
  • No cross-app or cross-site tracking

Analytics data is not linked to your identity. TelemetryDeck is GDPR compliant and does not require a consent banner under EU law.

Market Price Lookups

The App includes an optional Market Price feature that checks recent sale prices for cards in your collection. When you initiate a price lookup, the App sends a search query containing only card details (player name, year, brand, set name, and card number) to the SportsCardsPro API (sportscardspro.com).

  • No personal information (name, email, device ID, or location) is included in price lookup requests.
  • Price lookup data is cached locally on your device for up to 7 days to reduce unnecessary network requests.
  • Your SportsCardsPro API key, if configured, is stored securely in your device's Keychain and is never shared with us.
  • This feature is entirely optional. If you do not use price lookups, no data is sent to SportsCardsPro.

SportsCardsPro's use of query data is governed by their own privacy policy, available on their website.

Compare Prices (Browser Links):

The App provides "Compare Prices" links that open external websites in Safari:

  • 130Point.com — Opens the 130Point sold prices search page.
  • eBay Sold Listings — Opens an eBay search pre-filtered to sold/completed listings.

These links open in your device's browser. The App does not send data to these services directly.

Graded Card Certification Lookup

The App can look up certification data for professionally graded cards using cert numbers detected via barcode scanning or entered manually.

  • What is sent: Only the certification number is transmitted. No personal information, device identifiers, or location data is included.
  • How it works: Cert lookup requests are sent to a Supabase Edge Function that proxies the request to PSA's public API (api.psacard.com). The proxy does not log or store your requests.
  • What is returned: Card metadata including player name, year, brand, card number, grade, and population data.
  • Caching: Cert lookup results are cached in memory on your device for 5 minutes.
  • Rate limits: Lookups are limited to 100 per day, tracked locally on your device.

Currently only PSA certifications are supported. BGS, CGC, and SGC lookups are not available as those companies do not offer public APIs.

Card Shows and Discover Features

The App's Discover tab provides information about upcoming card shows and hobby news. This data is served from a Supabase-hosted database.

Card Show Data:

  • Card show event data is stored in a Supabase PostgreSQL database with PostGIS for geographic queries.
  • No user accounts exist on Supabase. No personal data about you is stored in this database.
  • When you use "Shows Near Me," your approximate location coordinates are sent to find nearby events. This location data is used only for the query and is not stored or logged on the server.
  • Card show results are cached locally on your device for offline access.

Hobby News:

The Discover tab includes a hobby news feed aggregated from public RSS sources. No personal data is sent or stored in connection with viewing news articles.

Apple MapKit:

Card show locations are displayed using Apple's MapKit framework, governed by Apple's Privacy Policy.

Location Data

The App requests access to your device's approximate location for the Discover tab's card show features.

  • Location access is only requested when you use the Discover tab and can be denied or revoked at any time.
  • Your approximate location is used to sort card shows by distance and to query nearby events from our card show database.
  • Your last known location coordinates are cached locally on your device for faster display when you reopen the App. This cache is stored only on your device.
  • Your location is never shared with third parties or used for advertising.
  • If you deny location access, you can still browse card shows by state or date.

In-App Purchases and Subscriptions

The App offers optional in-app purchases and subscriptions to unlock additional functionality. These transactions are processed entirely by Apple through the App Store. We do not collect or store payment information.

Data Export and Deletion

You can export your entire collection to CSV at any time. You can delete individual cards, collections, or all data from within the App. Uninstalling the App removes all local data. iCloud data can be managed through your device's iCloud settings.

Third-Party Services Summary

Service Purpose Data Sent Linked to Identity
Apple CloudKit (iCloud) Data sync between your devices Your collection data, photos Yes (your Apple ID)
Apple Sign In Authentication Anonymous ID, optional name/email Yes (if you share name/email)
TelemetryDeck Aggregate analytics Double-hashed user ID, feature usage events No
SportsCardsPro Market price lookups Card details (player, year, brand, set, number) No
Supabase Card show data, news, cert proxy Location coordinates, cert numbers No
PSA (via proxy) Graded card certification lookup Certification number only No
Apple MapKit Map display for card shows Map tile requests (handled by Apple) Per Apple's policy

Planned Features

The following features are on our development roadmap and may affect data practices when released. This policy will be updated before each feature launches:

  • Collection Sharing: Share your collection via a link.
  • Hosted Seller Profile: A public-facing profile for selling cards.
  • Grading Submission Tracker: Track cards sent for professional grading.
  • Trade Manager: Manage card trades with other collectors.

These features do not currently exist in the App and no data is collected for them.

Children's Privacy (COPPA)

For The Hobby does not knowingly collect personal information from children under 13. The App uses Sign In with Apple for authentication but does not independently collect names, email addresses, or other personal data from users. Apple manages age restrictions for child accounts through Family Sharing. If you believe a child has provided personal information through the App, please contact us.

The App's analytics service (TelemetryDeck) uses double-hashed identifiers that cannot identify individual users, including children.

European Users (GDPR)

If you are located in the European Economic Area (EEA), the United Kingdom, or Switzerland, the following applies:

  • Data Controller: Bishop Technology Solutions, LLC, contactable at support@fthcards.com.
  • Legal Basis: We process data based on your consent (by using the App) and our legitimate interest in providing the service. Analytics data collected via TelemetryDeck is processed under legitimate interest (Art. 6(1)(f) GDPR). TelemetryDeck is GDPR compliant and based in Germany (EU).
  • Your Rights: You have the right to access, rectify, erase, restrict processing, and port your data. You can exercise these rights by exporting your collection to CSV or deleting data within the App.
  • Data Transfers: If you enable iCloud sync, your data may be stored in Apple data centers outside the EEA. This transfer is governed by Apple's data processing agreements. Analytics data is processed by TelemetryDeck within the EU.
  • Complaints: You have the right to lodge a complaint with your local supervisory authority.

California Users (CCPA/CPRA)

If you are a California resident, the following applies under the California Consumer Privacy Act and California Privacy Rights Act:

  • Categories of Data: The App stores collection data (card details, photos, financial figures) that you enter. Sign In with Apple provides an anonymous identifier and optionally your name and email. Market price lookups send card details (not personal information) to SportsCardsPro. Location data is used for card show proximity sorting and is cached locally on your device. Usage data (anonymous feature usage events) is collected by TelemetryDeck using double-hashed identifiers.
  • Retention Periods: Collection data is retained on your device and in iCloud until you delete it. Market price cache expires after 7 days. Cert lookup cache expires after 5 minutes. Location cache is overwritten on each use. TelemetryDeck retains aggregated analytics data per their retention policy.
  • Sale of Data: We do not sell or share your personal information with third parties.
  • Sensitive Personal Information: We do not collect sensitive personal information as defined by the CPRA.
  • Your Rights: You have the right to know what data is collected, request deletion, and opt out of data sales (not applicable as we do not sell data). We will not discriminate against you for exercising these rights.
  • Contact: To exercise your rights, email support@fthcards.com.

Changes to This Policy

We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated "Last updated" date.

Contact

If you have questions about this Privacy Policy, contact us at support@fthcards.com.

Find The Hits Find The Hits

Find the Hits. Feed the Hobby.

  • Features
  • Community
  • Roadmap
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Bishop Technology Solutions, LLC. All rights reserved.

Apple, the Apple logo, iPhone, iPad, App Store, iCloud, Face ID, and Touch ID are trademarks of Apple Inc., registered in the U.S. and other countries.