Privacy Policy

Last updated: April 19, 2026

This is the privacy policy for trace (the "app"). The app is made by Alex Brown, a solo developer. If you have questions about anything below, email me at abrown252@gmail.com and I'll get back to you.

I've tried to write this in plain language instead of lawyer-speak. The short version: I collect the minimum amount of data needed to run the app, I don't sell it, and you can delete it whenever you want.

What data the app collects

Account information. When you create an account, I store your email address and a hashed password. If you sign in with Apple, I store the identifier Apple gives me and (if you allow it) your email.

Your collection data. The app lets you catalog your trading card collection — card names, quantities, conditions, purchase info, and any notes you add. That data is stored on my servers so it can sync across your devices. I treat it as yours: I don't read it, train on it, or share it.

Usage and diagnostics. The app uses [analytics/crash tool — e.g., Firebase Analytics + Crashlytics, Sentry, PostHog] to collect anonymized information about how the app is used and to report crashes. This includes things like which screens you visit, how long sessions last, device type, OS version, and crash stack traces. It does not include your collection data.

Things I do NOT collect:

How I use the data

That's the full list. I don't use your data to train AI models, build a profile on you, or target ads.

Who I share data with

I share the minimum necessary with a few service providers who help me run the app:

I don't sell your data. I don't share it with advertisers or data brokers. If I'm ever legally required to hand something over (court order, etc.), I'll push back where I can and notify you where legally allowed.

How long I keep data

Your account and collection stick around as long as your account is active. If you delete your account, I delete your data from live systems within 30 days. Backup copies roll off within 90 days after that. Anonymized analytics may be retained longer in aggregated form.

Your choices

If you're in the EU/UK, you have GDPR rights (access, correction, deletion, portability, objection). If you're in California, you have CCPA rights (roughly the same, plus the right to know what's collected). Email me and I'll handle your request — no special form required.

Children

The app isn't directed at children under 13, and I don't knowingly collect data from them. If you think a child has signed up, email me and I'll delete the account.

Security

Data is encrypted in transit (HTTPS/TLS) and at rest. Passwords are hashed with bcrypt. Access to production systems is limited to me. No system is 100% secure, but I take this seriously and will notify you promptly if a breach affects your data.

Changes to this policy

If I change this policy in a meaningful way, I'll update the "Last updated" date at the top and — for material changes — notify you in the app or by email before the change takes effect.

Contact

Questions, requests, or complaints:
Alex Brown
Email: abrown252@gmail.com