Piotr Boroń, sole proprietor operating under Article 5 of the Act of 6 March 2018 — Entrepreneurs’ Law, with a registered address at al. Solidarności 68/121, 00-240 Warsaw, Poland (“we”, “us”, or “our”), operates the Foilio mobile application for iPhone (the “App”).
This policy describes what the App does with information on your device, what leaves the device and what does not, and who else is involved. It is written to be read rather than skimmed.
1. Summary
- There are no accounts. You never create one, and we hold no profile, no email address and no identifier for you.
- We operate no server. There is no Foilio backend, no database on our side, and no cloud sync.
- Your photos, the cards made from them, and all of your progress are stored only in the App’s own storage on your device.
- The App contains no advertising, no attribution service and no cross-app tracking. It never asks for App Tracking Transparency permission and never reads your advertising identifier.
- Purchases are processed by Apple. We never see your payment details.
- The App collects no face data. It performs no face detection or recognition and creates no faceprint or other biometric identifier. See section 5.
- One thing does leave the device: a record of a purchase you made. When you buy something, one third-party service — RevenueCat — receives that a purchase happened, together with an anonymous identifier for that installation. Nothing else is sent, ever. Section 7 sets out exactly what it does and does not receive.
2. Device Permissions
The App asks for the permissions below, each at the moment you first use the feature that needs it, and each optional. Declining any of them leaves the rest of the App working.
| Permission | Why it is asked for | Does the data leave your device? |
|---|---|---|
| Camera | To take a photo inside the App and turn it into a card. | No |
| Photo Library | To read photos you pick, and to draw photos at random from your library when you open a pack. | No |
| Location (While Using the App) | To read your position at the moment you press the shutter, so the card records where it was made and can be placed on the Atlas. | No |
| Notifications | Optional local reminders about your own streak, quests and daily film. No push server and no push token. | No |
The App does not request contacts, microphone, calendar, health data, Bluetooth, background location, or tracking permission.
About the photo library permission
iOS grants photo access at a read/write level, and that is the level the App requests, because drawing random photos for a pack requires it. The App never writes to your library: it does not create, edit, move, delete or reorganise anything in Photos. Saving a card image back to Photos happens through the standard iOS share sheet, which is you doing it, not the App.
If you grant limited access, packs draw only from the photos you selected.
About the location permission
Location is While Using the Apponly, and is read only while the App’s own viewfinder is open. There is no background location, no significant-change monitoring, no geofencing and no location history. Declining it produces cards marked as “off the grid”, which is a normal state the App handles everywhere.
3. What the App Stores on Your Device
Copies of the photos you use
A photo enters the App in one of three ways, all of which you start: you take it with the camera inside the App, you pick it through the system photo picker, or you open a pack and the App draws photos at random from the library you gave it access to.
When a photo becomes a card, the App writes the following into its own private container:
- a centre-square-cropped JPEG copy of the photo, downsized so its longest side is at most 1600 pixels;
- a 400-pixel thumbnail of the same image, for the album grid;
- where iOS finds a clear foreground subject, a PNG cut-out of that subject, at most 900 pixels on its longest side.
Your original photo in the Photos app is never modified, moved or deleted. The App only ever works on its own copy.
What is derived from the photo
At the moment a card is made, the photo is analysed once, on the device, using Apple’s Vision framework. The card then holds: up to ten classification labels that scored at least 20% confidence (words like “bird” or “pelican”), one top category, an overall image aesthetics score, and an accent colour sampled from the photo’s own pixels.
Where a card was made
If a location is available — from the shutter when you use the App’s camera, or from the photo’s own metadata when a pack draws it — the card records four things: the coordinate itself, a six-character geohash covering roughly 1.2 × 0.6 km, the numeric identifier of the nearest city in the bundled dataset, and a two-letter country code.
The coordinate is used only to draw a pin on the map inside the App. The Atlas — the collection of places you have visited — reads only the three coarse values, which is why it can tell two neighbourhoods apart but not two houses.
The App does not scan your library for locations. Only a photo you actually turned into a card ever gets a place recorded.
Your game state
A local database inside the App’s container holds your collection and progress: each card’s title, date, rarity, card number, rolled attributes, variant seed, labels and slab status; and one player record holding experience, credits, film, foil shards, keys, the daily streak, quest counters, the pity counter, purchased film, and permanent ledgers of which photos have been used and which discoveries, sets and places have already paid a bounty.
Preferences
The App’s local settings store holds whether sound and notifications are on, the last day you opened the App, the last purchase tier the App Store confirmed for your account, and a few counters that decide whether the App Store review prompt has been earned. These are numbers on your device. They are not sent anywhere and are not attached to any identity, because there is no identity.
4. Where It Is Stored
Everything in section 3 lives inside the App’s own container — the private storage iOS gives each app. It is not shared with other apps and is not sent to us.
None of it reaches us. Not your photos, not your cards, not your locations, not your progress — not in identifiable form, not de-identified, not in aggregate. There is no database on our side because there is no server on our side. Nothing in section 3 is transmitted anywhere by the App, to us or to anyone else.
The one exception in the whole App is a purchase, and it is the subject of sections 6 and 7. Buying something causes a record of that purchase to be sent to RevenueCat, our purchase-analytics processor, along with an anonymous installation identifier — and, as with any request made over the internet, the IP address the request came from. None of the material in section 3 travels with it, and there is no path in the App by which it could.
If the App’s container is included in your iCloud or local device backup, that backup is between you and Apple, under Apple’s terms. We have no access to it.
5. Processing That Happens On the Device
The subject cut-out, the image labels that fill the Foilodex, and the aesthetics score behind the grade on a card are produced by Apple’s Vision framework, running locally. No image, crop, thumbnail or cut-out is uploaded for analysis — not to us, not to Apple, not to anyone.
Face data
The App does not collect, generate, store, share or use face data of any kind. It performs no face detection, no face recognition, no face tracking, no facial landmark or expression analysis, and no creation of a faceprint, face template, face mesh, face geometry or any other biometric identifier. It does not use the TrueDepth camera, ARKit face tracking, or any face-related Vision request.
The only Vision requests the App makes are: a foreground-subject mask (which separates a subject from its background as a picture, and produces no identity information), a general image classifier that returns everyday nouns such as “dog” or “beach”, and an image aesthetics score. None of these detect, measure, identify or describe a person’s face.
If a photograph you turn into a card happens to contain a person, the App treats it exactly as it treats any other photograph: it stores its own copy on your device, as described in section 3, and derives nothing from the face in it. No face data is created, so none is retained, none is shared with any third party, and none is transmitted off your device. Deleting a card deletes the App’s copies of that photograph, and deleting the App removes everything it stored, as described in section 12.
Turning a coordinate into a city and a country is also done on the device, against a small dataset compiled into the App. The App does not use a geocoding service, so no coordinate is ever sent to one. The Atlas works with the device in airplane mode.
The holographic foil is rendered on the device’s GPU, and card images for sharing are rendered on the device.
6. Purchases
The App sells an optional subscription (Foilio Pro, weekly or yearly), a one-time lifetime unlock, and consumable packs of in-game credits, film and shards. Everything is sold through Apple’s In-App Purchase system.
Apple is the merchant of record. Apple takes the payment, holds the payment method, and holds your Apple Account details. We never receive, process or store your card number, billing address, Apple Account email or any other payment data. What we receive from Apple is the aggregate sales and payout reporting every developer gets in App Store Connect, which tells us how many units sold in which country — not who bought them.
To decide what you are entitled to, the App asks StoreKit — the operating system’s own purchase framework — what your Apple Account currently owns. That request is made by iOS to Apple, and is covered by Apple’s Privacy Policy. The App stores the answer — a single word naming your tier — in its own preferences so that a subscriber is still a subscriber when the device is offline.
7. RevenueCat
RevenueCat is a purchase-analytics service. Its SDK is a real third-party dependency, compiled into every build of the App and active. It is the only third-party code in the App and the only reason anything at all leaves your device.
It runs in observer mode, which is a specific arrangement worth spelling out. The App’s own StoreKit code makes the purchase, verifies it, delivers the goods and closes the transaction. RevenueCat is told afterwards that this happened. It does not make purchases, does not grant entitlements, and is not on the path between you and Apple — if it were unreachable, buying and restoring would work exactly as they do now.
What it receives, when you complete a purchase:
- the purchase itself — which product, and when;
- an anonymous installation identifier the SDK generates on the device, plus the identifier iOS gives the App for this vendor. Neither is your advertising identifier, neither is stable across a delete-and-reinstall, and neither is tied to a name, an email address or an account, because the App has none of those to give;
- the ordinary technical facts of an HTTPS request — device model, OS version, App version, and the IP address it came from.
What it never receives: your photos, the cards made from them, their labels, their locations, your Atlas, your Foilodex, your currencies or any other part of your progress. There is no code path in the App that passes any of it, which is a stronger guarantee than a promise not to.
RevenueCat is a processor acting on our behalf, subject to its own privacy policy. We use it to see how many subscriptions and unlocks are active and how many lapse — the questions App Store Connect answers slowly and in aggregate.
This is what the App Store privacy label declares, and the two are meant to be read against each other: Purchase History and Device ID, both under Data Not Linked to You, used for App Functionality and Analytics, and not used to track you. If this page and that label ever disagree, one of them is out of date and we want to hear about it at the address in section 15.
The SDK is configured only on a real device in a release build. In the Simulator, in a debug build and during automated screenshot runs it is never configured, so it makes no network request at all.
8. Analytics, Advertising and Tracking
Apart from the purchase analytics described in section 7, the App contains no analytics framework, no crash-reporting SDK, no advertising SDK, no attribution or install-referrer service, and no social-network SDK. Nothing measures what you do inside the App: there is no event, screen, session or funnel telemetry of any kind, and no engagement data is collected. It shows no advertising. It does not fingerprint your device. It never presents the App Tracking Transparency prompt, because it does no tracking to ask about. Its privacy manifest declares no tracking domains.
9. Other Parties, and What They Are Doing
Besides Apple and RevenueCat, there are three moments worth naming, because in each one iOS is acting for you rather than the App reaching out on its own:
- iCloud Photos.If a photo you pick — or one a pack lands on — lives in your iCloud Photo Library and its full-size version is not currently on the device, the App allows iOS to fetch it. That transfer is between your device and your own iCloud account, performed by Apple’s Photos system. The App never sees an account or a credential.
- Sharing a card. When you share, the App renders an image on the device and hands it to the standard iOS share sheet. You choose what happens next. The App does not know, record or report where it went.
- The App Store review prompt.Occasionally, and never more than Apple’s limit of three times a year, the App asks iOS to show Apple’s rating prompt. Apple runs it. The App never learns whether you left a review or what you said, and nothing is withheld from you for not leaving one.
The App’s Settings screen links to the websites of the people whose data, icons and sounds it credits, and to this site. Opening one of those links leaves the App and enters an ordinary web page under someone else’s policy.
10. Notifications
The App’s reminders are local notifications, scheduled by the App on your device. The App is never registered for remote notifications, so there is no push server, no push token and no way for anyone to send you a message through it.
Every message is built from your own game state on your own phone: your streak, your pity counter, an unfinished quest, film that has refilled. At most three are delivered on any day, at least four hours apart, never before 09:00 or from 21:00 onward in your local time, and none at all on a day you have already opened the App. The App sets no badge. You can turn them off inside the App or in the iOS Settings app at any time.
11. Children’s Privacy
The App is not directed at children. In its App Store age-rating declaration we have disclosed that it contains randomized virtual items reachable with in-game currency bought for real money, and infrequent or mild references to weapons in its card artwork. Everything else in that questionnaire — gambling, simulated gambling, contests, violence, sexual content, profanity, horror, drugs, medical content, user-generated content, chat, social media, unrestricted web access and advertising — is declared as none, because none of it is in the App. The resulting age rating is shown on the App Store listing itself, which is authoritative and always current.
We do not knowingly collect personal information from a child under 13, or under 16, or under any other threshold that applies where you live. The App has no accounts, no advertising, no social features, no chat and no user content visible to other people. A child using Foilio makes cards from photos on their own device, and those cards stay on that device. The only thing that leaves it is a purchase record carrying an anonymous installation identifier (section 7), which identifies an installation rather than a person and cannot be used to contact, profile or advertise to anyone.
Purchases are the part parents should know about. They are made through the Apple Account signed in on the device, and are governed by Apple’s own controls: Ask to Buy, Screen Time restrictions and Family Sharing all apply, and the App honours a purchase held for a parent’s approval by granting nothing until it is approved.
12. Retention and Deletion
We retain nothing, because we receive nothing. Everything is on your device and you can remove it yourself, at four levels of severity:
- Delete one card. The card, its stored photo copy, its thumbnail and its subject cut-out are removed from the device immediately.
- Forget every place (Atlas screen). The coordinate, geohash, city and country are cleared from every card in your collection. The cards themselves are kept.
- Erase everything(Settings screen). This deletes every card and every player record from the local database, deletes every stored photo copy, thumbnail and cut-out from disk, removes the App’s entire preferences domain, and cancels every scheduled notification. The next launch is a first launch. Your photos in the Photos app are untouched, and every photo becomes usable again.
- Delete the App. iOS removes the whole container at once and permanently.
There is no account to close and no deletion request to file, and no copy is retained anywhere because no copy was made anywhere. Two consequences follow from that, and both cut against you, so they are worth stating plainly: nothing can be restored, and erasing does not return your in-game credits, film or shards — including any bought with money. Export a card before you delete it if you want to keep it.
Erasing in the App does not reach Apple, and does not reach RevenueCat. Your purchase history stays with Apple, which is what lets a lifetime unlock or an active subscription be restored on a reinstall. The purchase records already sent to RevenueCat also stay there — write to us and we will have them deleted. Because those records carry only an anonymous installation identifier, tell us the approximate date and the product so the right installation can be found.
13. Your Rights
Laws such as the GDPR and the CCPA give you rights over personal data a company holds about you: to know what it holds, to get a copy, to correct it, to have it deleted, to restrict its use, and to know whether it has been sold or shared.
We hold no name, email address, account or profile for you, so for almost every category there is nothing for us to produce, correct or delete: the data is entirely in your hands, on your device, and section 12 is how you remove it.
The one set of records held on our behalf is the purchase history at RevenueCat described in section 7, keyed to an anonymous installation identifier. If you want it produced or deleted, write to us with the approximate date and the product and we will do it. We have never sold or shared personal data, in the specific senses the CCPA gives those words or in any other sense, and we do not do so now. We do not use it for advertising, we do not combine it with anything, and there is nothing else to combine it with.
For the parts we genuinely cannot answer for — your purchase history and your Apple Account — the controller is Apple, and their process for data requests applies.
14. Changes to This Policy
We may update this policy. Any change is reflected by the effective date at the top of the page. If a future version of the App collects or transmits something it does not collect or transmit today, it will be described here before that version ships, and it will be something you are asked about rather than something that starts happening.
15. Contact
Questions about this policy, or about your privacy in relation to the App:
Email: support@n1apps.com
Questions about using the App are answered on the Foilio support page, and the Terms of Service cover purchases and the rules of the game systems.
Piotr Borońal. Solidarności 68/121
00-240 Warsaw, Poland