Legal

Privacy Policy

Effective September 28, 2026 · Version 2026-09-28

This Privacy Policy explains what personal data YGOBox collects, why, who we share it with, how long we keep it and what rights you have. It applies to everything described as "YGOBox" in our Terms of Service: the website, the web app, our API, the YGOBox apps for computers and phones, the YGOBox Scanner apps, our emails and our support.

The short version

  • We collect what we need to run your account and your collection, and very little else.
  • We do not show ads. We do not sell your personal data or share it for advertising. Our emails contain no tracking pixels, and our apps contain no third-party trackers.
  • You can download your data, change your email address or email preferences, or delete your account at any time in Settings > Account.
  • Photos taken by YGOBox Scanner stay on your phone.
  • PSA lookups go straight from your device to PSA with your own token. Nothing PSA-derived is stored on our servers.

1. Who is responsible for your data

Fritts Films LLC, a Texas limited liability company, Dallas, Texas, USA, runs YGOBox and is the controller of the personal data described here. For any privacy question or request, write to [email protected].

This policy does not cover services run by others that you reach through YGOBox, such as PSA, Stripe's checkout and billing pages, or the App Store and Google Play. Their own privacy policies apply.

2. What we collect

Your account

  • Your email address.
  • Your password, stored only as a one-way hash (scrypt). We cannot read it.
  • When your account was created and your email address confirmed.
  • Your public handle, if you choose one.
  • Two-factor authentication settings, if you turn it on: the authenticator secret (encrypted) and your recovery codes (stored as hashes).
  • Whether you want product news, and when and how you last gave or changed that choice.
  • Which version of the Terms of Service you accepted and when, which version of this policy you have seen, and that you confirmed your age when you signed up.
  • A change of email address you started but have not confirmed yet.
  • Your plan (free or Booster), where Booster came from (the web, the App Store, Google Play, or a free grant from us), its status and renewal date, your Stripe customer ID, and the transaction identifiers the App Store or Google Play gives us.

Your collection and other content

Everything you record in YGOBox: cards and their details (printing, quantity, condition, language, edition, notes), storage locations, purchase details you enter (such as price, date and seller), decks, wants lists, lists, custom cards, cards you import from Yugipedia, graded cards (grading company, certificate number, grade) and photos you add of your own slabs, the settings that sync between your devices, and a history of changes that makes sync and undo work. We also work out your collection's value from market prices each day and keep that history for you.

This lives in your account on our server. Each signed-in YGOBox app on a computer or phone also keeps a full copy on that device.

Scans from YGOBox Scanner

  • The scanner uses your phone's camera to read the name and set code printed on your cards (and the labels of graded slabs). Recognition runs on the phone. Photos and cut-outs of your cards stay on the phone and are never uploaded to us.
  • When you are signed in and send a batch, the scanner sends us the list of cards it identified (card, printing, quantity, condition and similar details, and the name of the storage location), so the batch can be added to your collection.
  • The scanner apps download the card database and card pictures directly from YGOProDeck and may look cards up on Yugipedia. Those services see your phone's IP address, as with any request on the internet, but they receive no account information from us.
  • On Android, text recognition uses Google's ML Kit, which runs on the phone. Google's documentation says ML Kit may contact Google to receive updates and may send Google information about the feature's performance and use; it does not send your camera images.

Devices, sign-ins and security

  • Signed-in devices. For each device where you are signed in: the device name the app sends, the platform (web, desktop, iPhone or Android), and when the session started and was last used. Sign-in tokens are stored only as hashes.
  • Security events. A record of important account events, such as sign-ins, password, email address and two-factor changes, acceptance of the Terms, email preference changes and deletion requests, with the time, the IP address the request came from, and a rough description of the device (browser family, operating system family and platform, for example "Chrome on macOS"; never the exact browser version). The IP address and browser details are kept for 90 days.
  • Failed sign-in attempts, with the IP address, to stop password guessing. They are deleted after one day.
  • "Remember this device" for two-factor authentication stores a hashed token for 30 days.
  • To limit abuse, our server briefly keeps IP addresses in memory to count requests. The "new sign-in" email names only the browser and operating system, never an IP address or a location.

Server logs

Our server writes one line per request: the kind of request, which part of the API it was for, the result, and how long it took. These lines do not contain your IP address, your email address or what you searched for; some contain your account's internal ID. Logs are kept in a fixed amount of space and overwritten as new lines come in, typically within days to a few weeks. They are not sent anywhere else.

Cloudflare, which carries all traffic to our websites and API, processes IP addresses and request details to deliver YGOBox and protect it from attacks.

Payments

We never receive or store your card number or bank details.

  • On the web, Stripe, as the merchant of record, collects your payment details, billing address, email address and tax information on its own checkout pages. Stripe tells us your customer ID, which plan you chose, whether the subscription is active, when it renews or ends, and payment events (paid, failed, refunded).
  • In the apps, Apple or Google take the payment. They tell us a transaction identifier, the product, its status and when it expires.

Emails

  • Account and security emails (sign-in codes, password reset links, security notices, deletion confirmations) are part of the Service and are sent whatever your product-news choice is.
  • Product news is sent only if you opt in, at most twice a month. We record which of these emails were sent to your account, so nobody gets the same one twice.
  • Our emails have no tracking pixels and no click tracking. We do not know whether you open an email or click a link in it.
  • Our email provider keeps its own delivery logs (recipient address, time and delivery status).

Support

If you write to us, we receive your email address, your message and anything you attach, such as a diagnostic report you copied from the app. The apps never send diagnostics on their own.

Sharing and public pages

Everything in YGOBox is private unless you change it. If you set an item to "Anyone with the link" or "Public", what you chose to show (cards, and optionally prices, storage locations, quantities or notes) can be seen by anyone with the link, or by anyone at all. Public pages at your handle's address may appear in search engines; link-only pages ask search engines not to list them. Your email address is never shown. For share links we count views, without recording anything about the viewer.

Website and web app analytics

The website and the web app use Cloudflare Web Analytics, which counts page views and measures loading times in aggregate (for example, by country, browser and referring site). According to Cloudflare, it does not use cookies or local storage and does not fingerprint or track visitors across sites. We use no other analytics, and there is no event tracking inside our apps.

Our websites load their fonts from our own servers, not from Google Fonts or another third party.

During the private beta

While the web app is in a private beta, it sits behind Cloudflare Access: if you were invited, your email address is on our access list and Cloudflare emails you a one-time code to get in.

3. What we do not do

  • We do not show ads, and we do not sell your personal data.
  • We do not share your personal data for cross-context behavioral advertising or targeted advertising, and we do not allow advertising or analytics companies to collect it through our apps.
  • We do not buy data about you from data brokers or other sources.
  • We do not collect your precise location or your contacts.
  • We do not make decisions about you based solely on automated processing that have legal or similarly significant effects.

If you are in the EEA, the UK or Switzerland, the law requires us to tell you the legal basis for each use.

WhyWhat dataLegal basis
Create and run your account; store, sync and back up your collection; add scanner batches; show what you share; let you export your dataAccount, collection, scans, devicesPerforming our contract with you
Send account and security emailsEmail addressPerforming our contract with you; our legitimate interest in keeping your account secure
Keep YGOBox and your account secure; prevent fraud, abuse and password guessing; warn you about new sign-ins; investigate problemsIP addresses, device descriptions, security events, logsOur legitimate interest in keeping YGOBox and its users safe
Provide Booster and keep billing recordsPlan, billing and store purchase dataPerforming our contract with you; legal obligations (tax and accounting)
Send product newsEmail address, consent recordYour consent, which you can withdraw at any time
Keep records of consents, unsubscribes and account deletionsThe records listed in section 8Legal obligations; our legitimate interest in showing that we honored your choices and in defending legal claims
Keep an encrypted archive of a deleted account for 30 days, and keep system backupsAll account and collection dataOur legitimate interest (and yours) in recovering from mistakes and disasters
Answer support requestsYour messages and account detailsPerforming our contract with you; our legitimate interest in helping you
Understand how the websites are used and how fast they loadAggregate statisticsOur legitimate interest in improving YGOBox
Comply with the law, enforce our Terms, and establish or defend legal claimsWhatever is needed for that purposeLegal obligations; our legitimate interests

Where we rely on legitimate interests, we have weighed them against your rights, and you can object (section 9).

5. Storage on your device and cookies

YGOBox does not set cookies. The website sets none at all.

The web app keeps a few things in your browser's storage (local storage and session storage), all needed for features you use:

  • your sign-in token and, if you ticked it, the "remember this device" token;
  • an ID for this browser that sync uses;
  • if you use PSA lookups, your PSA token and the details PSA returned (these never go to our servers);
  • the addresses of share links you created on this browser;
  • display preferences, such as the theme and layout; and
  • short-lived notices, for example a message carried across a page reload.

The YGOBox apps for computers and phones keep your collection database, settings and sign-in tokens on the device. YGOBox Scanner keeps its settings, your signed-in email address and your scan history on the phone. Signing out removes the sign-in tokens; if your account is deleted, each device removes what it kept for that account the next time it connects.

Cloudflare, which delivers our websites, may set cookies that are strictly necessary for security, for example to tell people from bots, and, during the private beta, a cookie that remembers that you passed the access check.

Because none of this storage is used for tracking or advertising, and it is either strictly necessary for a service you asked for or remembers a preference you set, we do not ask for cookie consent.

6. Who we share your data with

We share personal data only in these cases.

Service providers who help us run YGOBox and may only use the data to provide their service to us:

ProviderWhat they do for usData involvedWhere
OVHcloud (OVH US)Hosts our server and its databasesAll account and collection dataUnited States (Hillsboro, Oregon)
CloudflareDelivers and protects our websites and API (network, DNS, encryption, attack protection), hosts the website and web app, stores working files, forwards email sent to [email protected], provides web analytics and the beta access checkIP addresses and request details; support emails in transit; beta testers' email addressesGlobal network; United States company
Oracle Cloud Infrastructure (Email Delivery)Sends our emailsYour email address and the content of emails to youUnited States (Ashburn, Virginia)
Backblaze (B2)Stores our encrypted backups, the encrypted archives of deleted accounts and our records of deletions and unsubscribesBackups (encrypted); the records in section 8United States
Our email host for the support mailboxStores the support emails that Cloudflare forwards to usYour emails to supportUnited States

Payment providers and app stores, which act on their own account under their own privacy policies when you buy Booster: Stripe (including Link) on the web, and Apple or Google in the apps.

Services you choose to use. If you add a PSA token, your device sends PSA your token and certificate numbers directly. PSA's privacy policy applies.

People you share with. Whatever you make public or share by link is visible to the people who open it.

Card data sources. Our server fetches card data from YGOProDeck and Yugipedia without sending any information about you. The scanner apps contact them directly (see section 2).

Legal reasons and business changes. We may disclose data if the law requires it, in response to a valid legal request, or to protect the rights, property or safety of our users, the public or us. If YGOBox is sold or transferred to another company, your data would go with it, and we would tell you beforehand.

7. International transfers

We are based in the United States, and our servers and providers are in the United States. If you use YGOBox from another country, including the EEA, the UK or Switzerland, your data is transferred to and processed in the United States, where data protection law may differ from yours. We transfer it so we can provide the Service you asked for. Where our providers process personal data from the EEA, the UK or Switzerland, we rely on the safeguards they offer, such as the European Commission's Standard Contractual Clauses (and the UK and Swiss equivalents) in their data processing terms and, where a provider is certified, the EU-US Data Privacy Framework and its UK and Swiss extensions. You can ask us for more information about these safeguards.

8. How long we keep your data

DataHow long
Your account and collectionUntil you delete them or your account. Deleting your account removes them from our live systems at once, or at the end of your paid Booster time if you choose to keep using it until then.
Encrypted archive of a deleted account30 days, then deleted. It is encrypted with a key we keep offline and is used only to restore the account if you ask us to because the deletion was a mistake.
System backupsEncrypted backups roll over automatically. A deleted account disappears from them within about six months.
Record of deleted accounts: email address, account ID, handle, when the account was created and deleted, and who asked30 days after the deletion, then removed together with the encrypted archive.
Record of unsubscribes from product news: email address, account ID, when and howWhile your account exists, so we can show that we honored it. After you delete your account, 30 days, then removed with the rest of its records.
IP address and browser details in security events90 days. The record of the event itself (what happened, when, and the browser and operating system family) is kept until you delete your account.
Failed sign-in attempts1 day.
Signed-in devices (sessions)While you stay signed in (a session ends after 90 days without use), then 30 days.
"Remember this device" tokens30 days.
Emailed codes (sign-up, sign-in, email change) and password reset linksThey expire after 10 minutes and 1 hour, then are deleted.
Scanner batchesUntil you apply or discard them; applied batches are deleted 90 days later.
Hashes of a deleted account's sign-in tokens (no email address)2 years, so a device that reconnects later is told to remove its copy.
Server logs (no IP addresses)Overwritten as new lines come in, typically within days to a few weeks.
Billing recordsOur copy is kept while your account exists. Stripe, Apple and Google keep their own records under their policies and legal obligations.
Email delivery logsKept by our email provider under its own retention period.
Support emailsAs long as needed to handle your request and keep a record of it. Ask us if you want a conversation deleted.
Browser and device storageUntil you sign out, clear it, or your account is deleted.

9. Your rights

Wherever you live, you can:

  • see and download your data: Settings > Account > Your data > "Download my account data" gives you a file (JSON) with what our server keeps about your account: your profile, plan and billing status, your consent and legal-document history, your security settings, signed-in devices and security events, your share links and public handle, which product emails you were sent, and any scheduled deletion. "Download my collection" leads to the full backup and exports in Settings > Maintenance;
  • correct it: edit anything in your collection yourself, and change your email address in Settings > Account > Email address ("Change email");
  • delete it: remove any item yourself, or delete your whole account in Settings > Account > Delete account;
  • stop product news: use the Unsubscribe link in any product email, or Settings > Account > Email preferences;
  • ask us questions about how we use your data.

EEA, UK and Switzerland

Under the GDPR, the UK GDPR and the Swiss Federal Act on Data Protection you also have the right to access your data, to have it corrected or erased, to restrict or object to how we use it (including an absolute right to object to direct marketing), to receive it in a portable format, and to withdraw consent at any time without affecting what we did before. You can complain to the data protection authority where you live or work, or where you think the law was broken, for example the Information Commissioner's Office in the UK or the Federal Data Protection and Information Commissioner in Switzerland. The European Data Protection Board lists the EU authorities at edpb.europa.eu. We would appreciate the chance to help first.

California and other US states

If you live in California, Texas, Virginia, Colorado, Connecticut, Oregon or another US state with a consumer privacy law, you have rights under that law. We give them to everyone:

  • Right to know and access the categories and specific pieces of personal data we hold about you.
  • Right to delete your personal data.
  • Right to correct inaccurate personal data.
  • Right to data portability.
  • Right to opt out of the sale or sharing of personal data and of targeted advertising and profiling. We do none of these, so there is nothing to opt out of. If your browser sends a Global Privacy Control signal, we treat it as an opt-out anyway.
  • Right not to be discriminated against for using these rights.

In the last 12 months we have collected these categories of personal information (as the California law names them), for the purposes in section 4, from you, your devices and our payment providers:

CategoryExamplesDisclosed for a business purpose to
IdentifiersEmail address, account ID, IP address, public handleService providers (section 6)
Customer recordsEmail address and billing statusService providers; payment providers
Commercial informationYour plan and purchase records; purchase prices you enter for your cardsService providers; payment providers
Internet or other network activitySecurity events, device descriptionsService providers
Audio, electronic or visual informationPhotos you add of your own slabsService providers
Sensitive personal informationYour account login (email address and password)Service providers

We do not collect precise geolocation, and we do not draw inferences to build a profile about you. We use sensitive personal information only to sign you in and keep your account secure, not to infer anything about you. We have not sold or shared personal information, including that of anyone under 16, and we do not disclose it to third parties for their own direct marketing.

You may use an authorized agent to make a request; we will ask for proof that you gave them permission and may need to confirm the request with you. If we decline a request, you can appeal by replying to our answer with "Appeal" in the subject. We will answer an appeal within 60 days. If you are not satisfied, you can contact your state's attorney general.

How to use your rights

  • In the app: Settings > Account has Download my account data, Change email, Email preferences and Delete account.
  • By email: write to [email protected] from the email address of your account. To protect your data, we check that a request comes from the account's owner, for example by asking you to confirm from that address or to sign in, and we ask for no more information than we need.
  • We answer within one month (30 days). If a request is complex, the law may let us extend that; we will tell you if we do and why.
  • Using your rights is free, unless a request is clearly unfounded or excessive.

10. Children

You must be at least 13 to use YGOBox, and at least 16 in the EEA, the UK or Switzerland unless a parent or guardian agrees. YGOBox is not directed at children under 13, and we do not knowingly collect personal data from them. If we learn that we have, we delete the account and its data. If you are a parent or guardian and think your child has given us personal data, write to [email protected].

11. How we protect your data

  • All connections to our websites and API are encrypted (HTTPS).
  • Passwords are stored as scrypt hashes; sign-in tokens, reset links and recovery codes are stored as hashes; two-factor secrets are encrypted.
  • You can turn on two-factor authentication, and repeated wrong passwords or codes lock sign-in for a while.
  • Our server accepts no web traffic directly; all of it arrives through Cloudflare. Administrative access uses keys, not passwords.
  • Backups are encrypted before they leave our server. The archive of a deleted account is encrypted with a key that our server does not have.
  • The key our server uses to upload deleted-account archives and our records of deletions and unsubscribes can only add files, not read or delete them.

No system is perfectly secure. If a breach affects your personal data, we will tell you and the authorities as the law requires.

12. Changes to this policy

The version and effective date are shown at the top. When this policy changes, YGOBox shows you a notice that links to the new version; if we make a material change, we will also email you before it takes effect. Smaller changes, such as clearer wording, take effect when we publish them with a new date. You can ask us for an earlier version at any time.

13. Contact

Fritts Films LLC
Dallas, Texas, USA
Email: [email protected]