Privacy Policy
Effective Date: 2026-07-21
Last Updated: 2026-07-21
This Privacy Policy explains how Egghead Labs ("Egghead Labs," "we," "us," or "our") collects, uses, discloses, and retains personal information when you use Blind Box Tracker (the "Application"), visit our related website, or contact us. Egghead Labs is responsible for the personal information described in this policy.
This policy does not apply to third-party applications, app stores, retailers, or websites that we do not control. Their own privacy policies apply when you use their services.
Privacy at a Glance
- We use account and collection information to provide collection tracking, alerts, subscriptions, exports, and support.
- Apple and Google provide sign-in services. Apple processes App Store purchases. Google Firebase provides authentication, database, analytics, diagnostics, cloud functions, and messaging services.
- We do not sell or rent personal information, use it for third-party advertising, or permit cross-app or cross-site tracking for advertising.
- Search text and text placed on an exported image are not sent to Firebase Analytics. Exported images are created on your device.
- You can disable notifications, unsubscribe from marketing emails, correct your profile, and delete your account in the Application.
- Blind Box Tracker is a general-audience service and is not directed to children under 13.
This summary highlights important points. The complete policy below controls if the summary and the detailed terms differ.
1. Information We Collect
Account and profile information
When you sign in with Apple or Google, we receive an account identifier, authentication provider, and, depending on your provider settings, your name and email address. If you change your collector display name in the Application, we store the updated display name with your authentication profile.
Collection and preference information
We store the collectible and collection identifiers you choose to track, quantities marked as owned, wishlisted, or available for trade, collection progress, series and store watches, alert preferences, notification settings, and Application preferences.
Subscription and transaction information
We may receive and store product identifiers, transaction identifiers, App Store account tokens, subscription status, trial or introductory-offer status, purchase and entitlement history, expiration and renewal information, and verification results. We do not receive or store your full payment-card number or complete billing credentials.
Notification and alert information
If you choose to enable alerts, we process your device push token, device platform, watched series or stores, alert preferences, delivery status, and records used to deliver notifications, maintain an alert inbox, and prevent duplicate notifications.
Usage and analytics information
We use Firebase Analytics to process Application instance or device identifiers, your internal user identifier after sign-in, authentication method, membership state, country or approximate region inferred by the provider, screen views, feature interactions, collection and collectible identifiers or names, collection counts and progress, tracking milestones, alert actions, paywall source, selected subscription plan, trial status, purchase results, and general engagement measurements.
For in-app searches, Analytics receives the query length, collection identifier, result count, and whether results were found. We do not send the search text itself as an Analytics event parameter. We do not send your name, email address, series-suggestion text, support-message text, or export-message text as Firebase Analytics event parameters.
Diagnostics and technical information
Firebase Crashlytics and our infrastructure providers may process crash reports, diagnostic logs, timestamps, App version, device model, operating-system version, Application instance or installation identifiers, IP address, network information, and technical state at the time of a crash, error, or request. We use this information for security, reliability, troubleshooting, and service operation.
Suggestions, support, and other communications
If you submit a series suggestion, we store the suggestion text, submission and update timestamps, and review status. You must be signed in to submit a suggestion so the request can be authenticated, but the stored suggestion record does not include your user identifier, name, email address, or display name. Because the stored record is not linked to your account, it is not automatically removed when you delete your account.
If you contact us, we process the information contained in your message, your contact details, and related correspondence to respond, investigate issues, and keep appropriate support records. Please do not send sensitive personal information that is unnecessary for us to assist you.
Information processed on your device
Text you add to an exported collection image is processed on your device and is not uploaded to us solely because you create the export. If you grant photo-library permission, the Application uses that permission to save an export you request; it does not use that permission to upload your existing photo library to us.
Website and external-link information
Our website host may process standard request information such as IP address, browser or device information, requested URL, and timestamps to deliver and secure the website. Our services also check official and selected retailer product pages to provide availability information. If you choose to open an external source or store link, the operator of that website receives information normally transmitted by your browser or device and applies its own privacy policy.
2. Sources of Information
We obtain information:
- directly from you when you use the Application, manage your collection, enable alerts, submit a suggestion, or contact us;
- automatically from the Application, your device, and our website when you interact with the service;
- from Apple or Google when you authenticate;
- from Apple in connection with App Store subscriptions and purchase verification; and
- from service providers such as Firebase when they provide analytics, diagnostics, messaging, hosting, security, or other operational services.
3. How and Why We Use Information
We use information to:
- authenticate users and maintain accounts;
- provide collection tracking, wishlists, trade quantities, progress, exports, watchlists, release information, and store availability;
- deliver alerts you enable and maintain alert preferences and delivery records;
- process, verify, restore, and administer subscriptions, trials, renewals, cancellations, expiration, refunds, revocations, and premium access;
- provide support and evaluate product or series suggestions;
- measure feature use and subscription funnels, improve the Application, and understand reliability;
- detect, investigate, and prevent fraud, abuse, security incidents, unauthorized entitlement claims, and technical failures;
- send required account, legal, security, purchase, support, and service communications;
- send occasional marketing or product emails where permitted by law and subject to your choices; and
- establish, exercise, or defend legal rights and comply with applicable law.
Legal bases for EEA and UK users
Where European Economic Area or United Kingdom data-protection law applies, our legal bases depend on the processing:
- Contract: processing needed to provide your account, collection tracking, alerts you request, subscriptions, exports, and support.
- Consent: processing based on an optional permission or choice, such as push notifications and marketing communications, and other processing where consent is required by law. You may withdraw consent, but withdrawal does not affect earlier lawful processing.
- Legitimate interests: securing, maintaining, troubleshooting, and improving the Application; understanding feature performance; preventing fraud; and protecting users and our business, where those interests are not overridden by your rights.
- Legal obligation: processing necessary to comply with tax, accounting, consumer-protection, law-enforcement, or other legal requirements.
We do not use personal information for solely automated decisions that produce legal or similarly significant effects.
4. When We Disclose Information
We do not sell or rent personal information. We do not use personal information for third-party advertising or permit cross-app or cross-site tracking for advertising. We disclose information only as described below.
Service providers
- Google Firebase: Authentication, Cloud Firestore, Cloud Functions, Analytics, Cloud Messaging, and Crashlytics.
- Apple: Sign in with Apple, App Store purchases and subscriptions, transaction verification, fraud prevention, and Apple Push Notification service delivery.
- Google: Google Sign-In and associated account authentication.
- Operational providers: website hosting, email, and support services used to operate the Application and respond to requests.
These providers process information on our behalf or as independent providers under their own terms and privacy policies. Relevant information is available from Firebase Privacy and Security, Google Analytics for Firebase, Apple, and Google.
Legal, safety, and business purposes
We may disclose information when reasonably necessary to comply with applicable law or a valid legal process; investigate fraud, abuse, or security incidents; protect the rights, safety, and property of users, Egghead Labs, or others; enforce our agreements; or establish, exercise, or defend legal claims.
If Egghead Labs is involved in a merger, financing, acquisition, reorganization, bankruptcy, or transfer of all or part of the Application or business, information may be reviewed or transferred as part of that transaction, subject to appropriate confidentiality and legal safeguards.
User-directed sharing
When you export or share collection information, you decide where and with whom to share the resulting content. Third-party applications or services you choose to use for sharing apply their own privacy practices.
5. Analytics and Diagnostics
Firebase Analytics helps us understand adoption, navigation, collection activity, alerts, and subscription performance. Crashlytics helps us identify crashes and technical failures. These services may associate pseudonymous Application or device identifiers with events and diagnostics and may process information outside your country.
We configure our own Analytics events not to include your search text, name, email address, suggestion text, support-message text, or export-message text. Information may nevertheless be processed by Firebase as described in Google's documentation and privacy terms.
6. Notifications and Store Alerts
We request notification permission only when you choose to enable alerts. You can disable push notifications through the Application or your device settings. Disabling device permission stops push presentation, but saved watch preferences or alert records may remain until you remove them or delete your account.
7. Subscriptions and Purchases
Apple processes App Store payments and billing information. We receive the transaction and entitlement information needed to verify and provide premium access, restore purchases, prevent duplicate or unauthorized claims, resolve support issues, and account for subscription status changes. Apple retains purchase and account records under its own policies.
Deleting the Application or your Blind Box Tracker account does not cancel an active App Store subscription. You must manage or cancel the subscription through your Apple account settings.
8. Retention and Account Deletion
We retain personal information only for as long as reasonably necessary for the purposes described in this policy, including providing the Application, maintaining security, resolving disputes, enforcing agreements, and meeting legal, accounting, and fraud-prevention obligations. Retention depends on the type of record and why it is processed:
- Account and core collection data are generally retained while your account is active.
- Notification tokens and alert preferences are retained while needed to provide alerts or until they are disabled, replaced, or deleted.
- Subscription and transaction-verification records may be retained after account deletion where reasonably necessary for entitlement verification, accounting, fraud prevention, refunds, disputes, or legal compliance.
- Alert delivery and notification-deduplication records may be retained as necessary to operate alerts, diagnose delivery, and prevent repeated messages.
- Analytics and diagnostic information is retained under our configured settings and the applicable provider's retention and deletion processes, and may remain in aggregated, de-identified, or pseudonymous form.
- Support correspondence is retained as reasonably necessary to respond, document the issue, prevent abuse, and meet legal obligations.
- Series suggestions are stored without an account identifier and may be retained to evaluate product coverage and avoid duplicate work.
- Backups may retain information for a limited period until they are overwritten or expire under normal backup procedures.
Deleting your account
You can initiate account deletion in the Application's settings. The process requires recent authentication and deletes your Firebase Authentication account and core user collection records, alert watchlists, notification-token records, alert preferences, and Application preferences associated with your account.
Account deletion does not automatically remove the limited records described above when continued retention is reasonably necessary or permitted by law. It also does not remove a stored series suggestion because the stored suggestion is not linked to your account. Account deletion does not cancel an App Store subscription.
9. Your Choices and Privacy Rights
Depending on where you live and subject to applicable exceptions, you may have the right to request access to personal information, obtain a copy, correct inaccurate information, request deletion, restrict or object to processing, withdraw consent, or request portability. You may also have the right to complain to a privacy or data-protection regulator.
You can exercise common choices directly:
- Profile: update your display name in the Application.
- Notifications: change alert choices in the Application or disable notification permission in device settings.
- Marketing email: use the unsubscribe link in a marketing email, visit the Marketing Email Opt-Out page, or contact us.
- Subscriptions: manage or cancel your subscription through your Apple account.
- Account deletion: use the in-app deletion feature or contact the Privacy Officer.
To make another privacy request, email eggheadlabs.dev@gmail.com with the subject "Privacy Request." Describe the request and the account email or sign-in method involved. We may need to verify your identity before responding. We will respond within the period required by applicable law and will explain if an exception prevents us from fulfilling all or part of a request.
Canadian users
You may request access to and correction of personal information under applicable Canadian privacy law and challenge our compliance by contacting the Privacy Officer. If we do not resolve a concern, you may have the right to contact the Office of the Information and Privacy Commissioner for British Columbia or the Office of the Privacy Commissioner of Canada, as applicable.
EEA and UK users
Where applicable, you may have rights of access, correction, erasure, restriction, portability, objection, and withdrawal of consent. You may lodge a complaint with the data-protection authority where you live, work, or believe an infringement occurred.
California and other U.S. state residents
Where applicable law grants these rights, you may request access to categories or specific pieces of personal information, correction, deletion, or information about disclosures. You may also have a right to opt out of sale, sharing, or targeted advertising and to receive equal service when exercising a privacy right. We do not sell personal information, share it for cross-context behavioural advertising, or process it for targeted advertising.
10. International Processing
Egghead Labs and its service providers may process information in Canada, the United States, and other countries where they operate. Those countries may have privacy laws different from the laws where you live, and information may be accessible to courts, law enforcement, or regulators under applicable law. Where required, we use contractual or other recognized safeguards for international transfers.
11. Security
We use reasonable administrative, technical, and organizational safeguards designed to protect personal information, including authenticated access, access controls, and encrypted network transmission provided by the Application and service providers. No method of transmission, storage, or security is completely reliable, and we cannot guarantee absolute security.
You are responsible for maintaining the security of your Apple or Google account and your device. Contact us promptly if you believe your Blind Box Tracker account or information has been compromised.
12. Children's Privacy
Blind Box Tracker is a general-audience service and is not directed to children under 13. Children under 13 must not create an account or submit personal information through the Application. We do not knowingly collect personal information from children under 13. If we learn that we have collected personal information from a child under 13 without legally valid authorization, we will take reasonable steps to delete it. A parent or guardian who believes a child has provided personal information should contact the Privacy Officer.
13. Changes to This Policy
We may update this Privacy Policy to reflect changes to the Application, our practices, service providers, or legal requirements. We will post the updated policy and effective date on this page and may provide additional in-app, email, or other notice when required by law or appropriate for a material change. If consent is required for a new purpose, we will request it before using information for that purpose.
Previous versions are available in the Legal Archive.
14. Contact the Privacy Officer
Questions, complaints, and requests concerning this policy or Egghead Labs' handling of personal information may be directed to:
Privacy Officer
Egghead Labs
Email: eggheadlabs.dev@gmail.com
Please use the subject "Privacy Request" or "Privacy Complaint" so we can route your message appropriately.