Privacy Policy
In effect from 15 September 2026
Your card photos and collection stay on your device. HoloFail currently has no accounts, advertising or product analytics. Cloudflare handles the network requests that deliver the app, and we receive anything you deliberately send us by email. Here is what that means.
1. Who is responsible
HoloFail is an independent project run by a solo developer based in Finland. In this policy, “we” means the individual operating HoloFail, who is responsible for deciding why and how the personal data described here is processed (the data controller). Privacy questions and requests go to hello@holo.fail.
This policy covers the HoloFail web app, including its installed home-screen version, at holo.fail and the current cardglint.prokkis.com address, its assets at assets.cardglint.prokkis.com, and contact messages. The EU General Data Protection Regulation (GDPR) and Finland’s Data Protection Act apply to our processing. External sites have their own policies.
2. Photos, search and collections
Camera scanning and photo recognition run inside your browser. Camera frames, chosen photos, features calculated from them, text read from cards and recognition results are not uploaded to us or an AI provider. Scans are not collected to train an AI model. The app does not save photo pixels, filenames or recordings in browser storage.
Camera permission is requested after you ask to use it. You can refuse it, use a chosen photo instead, or browse without scanning. The camera stops when you leave Scan, open Card Details, hide or close the page, or the browser freezes it. You can revoke permission in your browser or device settings. The app does not request microphone, contact-list or precise-location access.
Search text is matched against a catalogue downloaded to your device. Collection stores the card IDs, quantities and addition dates you add or import. There is no cloud account, collection sync or server backup. Export collection and Import collection are in Settings. Backup files are read or downloaded locally; we receive neither their contents nor your saved collection.
Displaying a card can still request its data or artwork from Cloudflare. That request may reveal which card file was loaded, together with your IP address, even though it does not include the photo, typed search or local collection. A file request does not tell us whether the card was scanned, browsed or opened another way.
The optional maintainer test page keeps diagnostic results locally. A report is not automatically sent. If you choose to email a report, screenshot or backup, it becomes part of your contact message under section 5. Review it first and remove anything private.
3. Browser storage, cookies and deletion
The application writes no cookies and uses no IndexedDB, service worker or application-managed Cache Storage. It uses local storage for the collection, preferences and a small repeat-photo result cache; session storage holds temporary scanner and currency-rate data. These values are not sent to an analytics provider or used for advertising, cross-site tracking or a profile about you.
The repeat-photo cache stores file hashes and successful card matches, not the photo. A hash is a fingerprint of the selected file; here it is used only on your device to avoid recognising the same file again. The table explains each value and its lifetime.
| Stored value | Where | Contents and purpose | Retention |
|---|---|---|---|
holofail:collection:v1 | Local | Card IDs, copy counts and addition dates for cards you add or import; no images, account details or stored prices. Collection backups are read and downloaded on your device, never uploaded. | Until you remove or replace the collection entries or clear site data. Export a backup before clearing browser data or changing devices. |
holofail:photo-results:v1 | Local | Up to 32 successful photo matches: file hashes, public card identity, outline coordinates, cache time and scanner version; no images or prices | Until replaced or site data is cleared; results older than 30 days or from a different scanner release are ignored |
holofail:scan-mode | Local | Your explicit Camera or Photos choice, so Scan opens in the mode you selected | Until you change it or clear site data |
holofail:camera-device | Local | The browser’s origin-specific ID for the camera you explicitly selected; no label, image or recording | Until you change it, the camera becomes unavailable, or you clear site data |
holofail-recognition-runtime-v1 | Session | The WebGPU or WASM recognition runtime selected by an on-device startup speed test or your explicit backend choice | For the browser session |
holofail-recognition-threads-v1 | Session | The WASM thread count selected by the on-device startup speed test, or the compatible single-thread fallback after a runtime failure | For the browser session |
holofail-recognition-probes-v1 | Session | Successful on-device backend initialization and speed samples, tied to the current recognition release, so only usable backend choices are offered | For the browser session |
holofail:eur-rates:v1 | Session | Public ECB reference rates, their date and cache time, used to convert displayed prices | For the browser session, and treated as stale after one hour |
holofail:settings:v1 | Local | Your display currency, sound, vibration, keep-screen-awake and recognition backend choices | Until you change them or clear site data |
holofail-field-validation-v1 | Local | Only on the maintainer test page: the entered device label, test session ID, card IDs and outcomes, timings, lifecycle notes and device/browser capability details; never photos | Until Reset is used on that page or site data is cleared |
Existing installations can read the same values under the previous cardglint prefix. They move to the HoloFail key after a successful save, within the same browser and site. Old keys are included when you clear that site’s data.
To remove local data, use your browser’s site-data controls for the address you used. Export your collection from Settings first if you want to keep it. Removing a home-screen icon alone may not clear browser data. Session data normally disappears when the session ends, but a browser can restore sessions. Changing browsers, devices or domains does not transfer a collection; use your exported backup. Downloads and device backups remain under your control and are not deleted by clearing HoloFail’s site data.
Your browser and Cloudflare also cache public app files, models and card artwork to deliver them efficiently. These delivery caches contain no user photos. HoloFail does not guarantee offline operation. Cloudflare may set a security cookie when a protection feature is triggered, as explained next. No optional analytics cookies are used today; future optional analytics will have a separate choice under section 8.
4. Cloudflare and network requests
Cloudflare hosts and delivers the app, card data, models and artwork and protects the service against abuse. A request exposes network information such as your IP address, request time, URL and method, browser headers, response status and Cloudflare request identifiers. Cloudflare can also derive a rough location from the IP address. An app URL can include a selected view or card ID. This is request data, not a camera recording or a copy of your collection, and it should not be described as anonymous.
We enable sampled Worker logs for 10% of app requests and diagnostic traces for 1% to investigate errors, security problems and reliability. These sampled records remain in Cloudflare for no more than seven days, subject to its plan limits. The sampling does not mean that Cloudflare sees only those requests: it handles the network connection for every request. Its separate network/security records and aggregate service metrics have their own purposes and retention under the Cloudflare Privacy Policy.
Cloudflare may set site-specific security cookies if a challenge or bot-protection feature is active. For example, cf_clearance remembers a passed challenge and __cf_bm supports bot protection. They are not advertising cookies. Their duration depends on the feature and settings; Cloudflare documents a default 30-minute challenge clearance and a 30-minute inactivity expiry for __cf_bm. See its cookie documentation.
Currency conversion contacts /fx/eur on the app domain. Our server fetches the European Central Bank’s public reference rates without forwarding your browser details, scans or card choices. Catalogue and price sources are contacted by our private data-building process, not by your browser during recognition.
5. Messages you send us
If you contact hello@holo.fail, we receive your email address, any name you provide, message, attachments and normal email routing information. Email delivery involves the providers used to send and receive the message. Contact is optional and is not required to scan cards or use your collection. Please send only what is needed to explain the issue; avoid identity documents, payment details, children’s personal details and unrelated photos.
We use messages to respond to support, privacy, security and rights-holder enquiries. We do not add correspondents to a marketing list. Resolved correspondence is deleted within 12 months after the last action. If a specific legal obligation or dispute requires longer retention, we keep only the relevant material for that purpose and delete it when the obligation or need to establish, exercise or defend the claim ends.
6. Why processing is permitted
- Delivering and protecting HoloFail: our legitimate interests in providing a working service, preventing abuse and diagnosing faults (GDPR Article 6(1)(f)). We limit the data and retention and consider users’ rights, especially children’s.
- Answering enquiries: our legitimate interests in responding to the message you chose to send and resolving the issue (Article 6(1)(f)).
- Legal duties: compliance with a specific applicable legal obligation, such as responding to a valid data-rights request or binding legal order (Article 6(1)(c)).
- Future optional analytics: a separate, informed choice before activation, on the basis of consent (Article 6(1)(a)), if the feature is introduced as described below.
We do not need your name or email to provide the app, but network request data is necessary to deliver it. Local storage supports the functions described in section 3; blocking it can prevent saving a collection or preferences. Browser camera permission is permission to use your device, not blanket consent to collect data. Reading this policy or accepting the Terms of Service is not consent to optional analytics.
7. Providers and international transfers
Cloudflare and its authorised subprocessors handle hosting and delivery data. Email hosting and delivery providers handle messages you send. We may disclose the limited information necessary to professional advisers or public authorities to deal with a legal claim, binding request or security incident. We do not sell personal data or share it for cross-context behavioural advertising.
HoloFail uses Cloudflare infrastructure, including processing in the United States and other countries outside the European Economic Area (EEA). Data is not confined to Finland or the EU. Cloudflare processes customer data under its Data Processing Addendum, which provides for the EU–US Data Privacy Framework for eligible transfers and Standard Contractual Clauses with additional safeguards for other restricted transfers. Cloudflare also has responsibilities of its own for some network and security processing, described in its privacy policy.
Transfers we arrange must have an applicable lawful safeguard, such as an adequacy decision or appropriate contractual and supplementary measures. Using the app does not waive your GDPR rights or constitute consent to an otherwise unlawful transfer. You can contact us for information about recipients and a copy or explanation of the applicable safeguards, with confidential information protected where necessary.
Cardmarket and TCGplayer links open only if you choose them, without prefetching or sending a referrer. The site you visit then receives its own request and applies its own privacy policy. We do not send it your scans or collection.
8. Future optional analytics
Product analytics is not enabled in this version. We are considering Mixpanel to help understand which features work well and where the app fails. Mixpanel does not currently receive HoloFail events, and no analytics identifier is currently created by the app.
Before enabling optional analytics, we will explain the selected provider, events, identifiers, storage, retention, processing locations and transfer safeguards, and offer a clear opt-in choice. Declining will leave scanning, browsing and collections available. Withdrawing consent will be as easy as giving it and will stop future optional tracking; it does not change the lawfulness of processing before withdrawal.
We will not treat this policy as advance permission, load optional analytics before a valid choice, or send camera images, chosen photos, search text, collection contents or contact messages as analytics. Any introduction must also satisfy the children’s safeguards below and the provider’s rules. The separate notice will be published before that processing begins.
9. Your rights and complaints
Under the GDPR, you can request access to personal data we hold about you and ask us to correct it. You can request erasure or restriction where the legal conditions apply. You can object, for reasons relating to your situation, to processing based on legitimate interests; we must then stop unless we have overriding grounds or need the data for legal claims. Portability applies where data is processed automatically on the basis of consent or a contract. You can withdraw consent whenever processing relies on it.
Send requests to hello@holo.fail. We respond without undue delay and normally within one month. If a request is complex or there are several requests, the GDPR permits up to two additional months; we will explain the extension within the first month. Requests are normally free. A refusal or permitted fee for a manifestly unfounded or excessive request will be explained, together with your right to complain or seek a judicial remedy.
We may ask only for information reasonably needed to locate the data and verify your entitlement to it. We do not collect additional identifying data just to link future requests. Because logs are sampled and short-lived, a matching record may not exist. We cannot remotely access, export or delete your device-only collection: section 3 explains the controls you can use yourself. We do not make decisions about people based solely on automated processing that have legal or similarly significant effects.
You can complain to Finland’s Office of the Data Protection Ombudsman, or the competent authority where you live, work or believe a violation occurred. We welcome the opportunity to resolve an issue directly; contacting us does not remove your right to complain or go to court.
10. Children and parents
HoloFail is for card collectors, including younger collectors using it with a parent or guardian. We do not ask for a date of birth, create children’s profiles, provide public chat or use behavioural advertising. A child’s visit still produces the hosting requests explained above, so we do not claim that children generate no personal data.
For younger collectors: your card photos stay on your device. Ask a trusted adult before emailing us or following a shop link. Do not send your home address, school, phone number or photos of yourself. A scan is a helpful guess, not proof that a card is real or worth a particular amount.
Parents and guardians can help with camera permissions, backups and privacy requests. Contact us if a child has sent unnecessary personal information so we can investigate and delete it where appropriate. We will not introduce consent-based tracking of children without the safeguards and authorisation required by law. In Finland, the relevant age for a child’s own consent to an online service is 13; other EEA countries may set it as high as 16. This is a data-consent rule, not a claim that every 13-year-old can enter any contract. A provider may impose stricter restrictions.
11. Security
We reduce exposure by processing recognition locally, using HTTPS, restricting app network connections and limiting diagnostic retention. Please protect access to your device and exported backups: another person using the same browser profile may see its collection. No internet service or device is completely secure. If a personal-data breach occurs, we will assess it and notify the supervisory authority and affected people where the GDPR requires us to do so.
12. Changes to this policy
We will update the date above when this policy changes. For a material new use of personal data, we will provide a prominent notice before it begins and request any consent the law requires. A privacy notice explains processing; it does not grant us new rights over your data merely because you continue using the app. You can keep a copy using your browser’s print or save function.