Effective 2026-08-29 · Version 1.0
Who we are. TCG Portfolio ("the App") is operated by Oisin McNally, a sole trader established in Ireland ("we", "us", "our"). We are the data controller for the personal data described in this policy.
Contact / postal address: Oisin McNally, Earlspark, Loughrea, H62 WK79, Co. Galway, Ireland. Email: tcgportfoliodev@gmail.com
Scope. This policy explains what personal data we process when you use the App on iOS or Android, why, on what legal basis, how long we keep it, who we share it with, and your rights. The App is available worldwide; most of our users are in the US, UK, Canada and the EU/EEA.
A quick, honest summary. You need an account to track your portfolio, so we process your email address and login data. The App is free and supported by advertising, so advertising partners may process device and usage data to show you ads. We do not sell your personal data for money. However, showing personalised ads can count as a "sale", "sharing" of personal information, or "targeted advertising" under some US state privacy laws — you can opt out (see section 7). We do not run any social, sharing, messaging or user-content features.
| Data category | Purpose | GDPR legal basis (Art. 6) | Retention | Main recipients |
|---|---|---|---|---|
| Account data (username, email, hashed password, email-verification status) | Create and secure your account; sign-in; sending email-verification and password-reset emails | Art. 6(1)(b) performance of contract | Until you delete your account; deleted data is purged from backups within 30 days | AWS (hosting, including Amazon SES for transactional email), Neon (database) |
| Portfolio data (cards you add, quantities, purchase prices/notes you enter) | Provide the core portfolio-tracking service | Art. 6(1)(b) contract | Until you delete the item or your account (30-day backup purge as above) | AWS, Neon |
| Server logs (IP address, request metadata, timestamps, device/OS identifiers in requests) | Operate, secure and debug our servers; prevent abuse and fraud | Art. 6(1)(f) legitimate interest in service security and integrity | Up to 12 months | AWS |
| Card price lookups | Show current estimated values from third-party price sources | Art. 6(1)(b) contract; Art. 6(1)(f) legitimate interest in accurate estimates | Transient; cached only within each source's permitted limits | eBay, TCGplayer (and other price APIs) |
| Device & usage analytics (device model/type, OS and version, app version and build, screen dimensions, timezone, screens/actions in the App, your email address and account identifier where you are signed in, and approximate city-level location — GeoIP coordinates estimated from your IP address) | Understand and improve the App | Art. 6(1)(f) legitimate interest in understanding and improving the App. Analytics is enabled by default; you can opt out at any time in the App's settings | Event-level data up to 12 months, then deleted or aggregated | PostHog (hosted in the United States) |
| Session recordings (replays of your interactions with the App's screens, which can include the contents of your portfolio, card lists and estimated values as they appear on screen) | Understand how the App is used; find usability problems and bugs | Art. 6(1)(f) legitimate interest in improving the App. Recording is enabled by default; opting out of analytics in the App's settings also stops session recording | Up to 12 months | PostHog (hosted in the United States) |
| Crash & error diagnostics (crash logs, stack traces, device state) | Detect and fix crashes and bugs | Art. 6(1)(f) legitimate interest in a working, secure App | Up to 12 months | Sentry |
| Push notification token | Deliver push notifications you enable | Art. 6(1)(a) consent (device permission) | Until you disable notifications or delete your account | Expo, Apple (APNs), Google (FCM) |
| Advertising data (advertising identifier where permitted, device/ad-interaction data) | Show ads that fund the free App; personalised ads only with consent | Art. 6(1)(a) consent (personalised ads / device storage); Art. 6(1)(f) for non-personalised ads | Controlled by the ad networks per their policies | Google AdMob, AppLovin, Google Play services |
We do not use AI/LLM features, card image scanning, OCR, or photo uploads, and we do not knowingly process special-category data.
The App is free and funded by ads served by Google AdMob and AppLovin (MAX). For ad personalisation, these companies generally act as independent controllers of the data they collect through their SDKs, not merely as our processors.
Learn more / manage choices: AdMob & Google (https://policies.google.com/privacy and https://policies.google.com/technologies/ads); AppLovin (https://www.applovin.com/privacy/).
The following organisations process data for or with us. Better Auth is not a third party — it is open-source authentication software we self-host on our own AWS infrastructure, with records stored in our Neon database.
Business transfers. If the App or our business is transferred to a company we form or control (for example, a limited company incorporated to run TCG Portfolio), or to a successor in a merger, acquisition or sale of assets, your personal data may be transferred to that entity. It will remain subject to this policy (or a successor policy offering at least equivalent protection), and we will notify you of any such transfer.
We may also disclose data where required by law (for example, a court order), or where necessary to protect our rights, your safety or the safety of others, or to investigate fraud.
Some providers are established in the United States and may process data outside the EEA/UK. In particular, our analytics provider (PostHog) is hosted in the United States, so analytics data — including your email address and account identifier where you are signed in — is processed there. Where data is transferred to the US we rely on the EU-US Data Privacy Framework (and the UK Extension / Swiss-US framework for UK and Swiss users) where the provider is certified, and on the European Commission's Standard Contractual Clauses as a safeguard where it is not. You can ask us for current details of the safeguards used for any provider.
We keep account and portfolio data for as long as your account exists. When you delete your account (from within the App, via our account deletion page, or by emailing us at tcgportfoliodev@gmail.com) we delete your account and portfolio data from our live systems without undue delay and purge them from backups within 30 days, except where we must keep limited records to comply with law or to resolve disputes or security incidents, which we delete once no longer needed.
Residual data collected before deletion — server logs, crash diagnostics, session recordings and event-level analytics — is not individually erased when your account is deleted; it expires automatically under its retention period, which in each case is up to 12 months. This means some of this data may persist for up to 12 months after account deletion. If you would like it deleted sooner, email tcgportfoliodev@gmail.com and we will action your request, subject to any legal obligation to retain it.
You have the right to access, rectify, erase, restrict, and port your data, to object to processing based on legitimate interests (for analytics, the quickest way is the opt-out toggle in the App's settings), and to withdraw consent at any time (without affecting prior processing). To exercise these rights, email tcgportfoliodev@gmail.com. You also have the right to lodge a complaint with the Irish Data Protection Commission — 21 Fitzwilliam Square South, Dublin 2, D02 RD28, Ireland; info@dataprotection.ie; +353 1 765 0100; www.dataprotection.ie — or with your local supervisory authority. UK users may complain to the UK ICO (ico.org.uk).
Depending on your state (e.g., California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Indiana, Kentucky, Rhode Island), you may have the right to access, delete, correct and port your data, and to opt out of the "sale" or "sharing" of personal information and of targeted advertising. Serving personalised ads may be considered a "sale"/"share" under some of these laws. To opt out, use the in-app "Do Not Sell or Share My Personal Information / Opt out of targeted advertising" control, decline ad-personalisation consent, or email tcgportfoliodev@gmail.com. We honour the Global Privacy Control (GPC) signal where required. We do not discriminate against you for exercising these rights.
The App is intended for users aged 13 and over (and 16 and over in the EEA, where consent for ad-related processing requires that age). We do not knowingly collect personal data from children below these ages. If you believe a child has provided us data, contact us and we will delete it. The App is not directed to children and is not part of any "designed for families" programme.
We use reasonable technical and organisational measures, including encrypted transport (HTTPS/TLS), hashed passwords, access controls, and reputable infrastructure providers. No system is perfectly secure, and we cannot guarantee absolute security.
If a personal-data breach is likely to result in a risk to your rights, we will notify the Irish DPC within 72 hours where required, and affected users where the risk is high.
We may update this policy. We will change the effective date and version above and, for material changes, provide notice in the App. Continued use after changes take effect means you accept the updated policy.
← Back to TCG Portfolio