Privacy Policy
Last updated September 29, 2026
Version 2 · Effective October 8, 2026
This policy covers the Grail iOS app and this website. It describes what we collect, why, who handles it, and what happens when you ask to delete it. Grail is operated by Grail Collectibles Inc. Grail is for people 18 or older in the United States. If anything here is unclear, email team@playgrail.io and ask.
What we collect
If you join the list on this site
Your email address and the date you submitted it. We use it to tell you when Grail opens. Submitting the form sends your email to Supabase. Technical request data is described below.
If you create a Grail account
- Your email address, used to sign you in with a 6-digit code. Grail has no passwords.
- An internal account identifier.
- The date you confirmed you're 18 or older. We don't ask for your birth date or government ID.
- A referral code assigned to your account, and who referred you if you enter their code.
What your account records as you use the app
- Your wallet balance and every credit and debit against it.
- Your points balance and every earn and spend.
- The packs you buy, each reveal, and the random seed that produced it, so we can check any reveal against the published hit rates if you ask.
- The cards you hold and your daily check-ins.
- Payment references, amounts, status, refunds and disputes.
- Shipping quotes, the cards and values recorded for a shipment, your confirmation, tracking, delivery status and related support records.
Payment details
Stripe handles payments for wallet credit and any part of a shipping charge not covered by your wallet. You can pay by card, or Apple Pay where available. Payment details go directly to Stripe; Grail's servers do not store your full card number or security code. We keep payment references and transaction records so we can confirm payments and handle refunds or disputes.
If you choose Scan Card when adding a payment card, the app asks for camera access to read the card details into the payment form. You can type the details instead.
Stripe's payment software also collects information about interactions with its payment interface for analytics and app functionality. Stripe states it does not use this data to track you across other companies' apps or websites.
If you request shipping
We collect the recipient's name and US postal address, including any apartment or unit you provide. We keep the entered address and its validated version. Our shipping form does not ask for a phone number. Shippo and the delivery carrier handle the name and address to validate the destination and deliver the package. We ship only within the United States.
When you use shipping, we keep short-lived request counters tied to your account ID and a hashed IP address to prevent abuse, and remove them periodically.
Your device and sign-in requests
The app stores a sign-in token on your device so you stay signed in. Our hosting and service providers process ordinary technical request data, such as IP addresses and timestamps, to operate and secure the service.
While App Review sign-in support is switched on, an invalid or expired code, with the email entered, is checked by our server hosted by Vercel. We keep security records of these attempts that use hashed email and IP information, with times and outcomes, and clear them on a rolling schedule.
What we don't do
- We don't sell your personal information or share it for advertising.
- We don't track you across other companies' apps or websites for advertising, use advertising identifiers, or request App Tracking Transparency permission.
- This website sets no cookies and runs no analytics. Its fonts and images are served from this site; its waitlist form sends information to Supabase.
Who else handles it
- Supabase — hosts our database, runs account sign-in and backend services, and receives waitlist submissions. Your account and transaction records live there.
- Resend — delivers your sign-in code email.
- Stripe — processes payments and payment-interface interaction data. We send payment amounts, your account identifier for wallet funding, and transaction references needed to connect payments to wallet or shipping activity.
- Shippo and USPS — validate shipping addresses and arrange and carry out delivery. Recipient and shipment details needed for those services go to Shippo and USPS and, when a shipment is insured, the insurer Shippo uses.
- Vercel — hosts this website and our administrative system, including server-side shipping operations and the App Review sign-in fallback. Those services process shipping and sign-in data as described above.
- Apple — distributes the app and participates in Apple Pay when you use it. If you've chosen to share analytics with developers in your iOS settings, Apple may give us grouped crash and usage reports.
- PSA and its image host — provide card grading information and images. Our server-side grading lookups do not send your account details. When the app loads a card image directly from PSA's external image host, that host receives your connection's IP address and the requested image path.
Why we collect it
To run your account and keep your balances right; process payments and deliver cards; support you and resolve disputes; audit purchases, payments and shipments; secure sign-in; send service messages; and keep records needed for tax, accounting and legal obligations.
How long we keep it
Account records stay while your account is open. Payment, shipping, custody and audit records can remain after account deletion for reconciliation, support, disputes, accounting and legal obligations. Removing an account link does not erase those records or necessarily make them anonymous. Waitlist emails stay until you ask us to remove them.
We keep shipping addresses for as long as needed to complete and support the shipment, handle returns and disputes, and meet legal, tax and accounting obligations. Deleting an address from Grail's records does not remove copies kept by Shippo and the carrier, including the shipping label.
Scheduled cleanup of App Review sign-in records targets audit entries older than 30 days and rate-limit records untouched for two days. Cleanup runs in batches, so these are cleanup thresholds, not guaranteed deletion deadlines. These records are separate from your account and are not erased by deleting it.
Deleting your data
In the app, open Profile → Delete account. This removes your sign-in account, profile, wallet and points balances, associated ledger entries and reveal history from our active systems. Copies may remain for a limited time in backups and logs, and service providers such as Stripe and Shippo keep their own records under their own policies. It does not erase all records: payment and shipping history, shipping addresses, support and audit evidence, and physical card inventory records can remain as described above. Grail removes your account as the owner of retained payment and shipping records, but they can still contain identifiers that connect them to you, such as your former account ID in Stripe's payment records or a cancellation you requested.
To leave the email list, request a copy or correction of your information, or ask about retained records, email team@playgrail.io. These requests are handled manually through support. Account deletion does not automatically remove an email from the waitlist.
Do Not Track
We don't use cross-app or cross-site advertising tracking. We don't change how the service operates in response to a browser's Do Not Track signal.
Children
Grail is for people 18 or older in the United States. We don't direct Grail or our marketing at children. If you believe someone under 18 has given us information, email team@playgrail.io so support can review it and address account closure and deletion. The retained records and limits described above also apply; closing an account does not erase every record.
Changes
If we change this policy, we'll update the version and date at the top of this page.
Contact
Email team@playgrail.io.