Privacy Policy
This policy explains what the Figfolio public website handles today and what will change before account features become available.
Current scope
Figfolio is in development. The public website currently presents the product and catalog artwork. Public collector profiles are designed to be searchable but are not yet enabled on the live service. Apple sign-in, user uploads, trade chat and in-app account deletion are not available in the current release. We will update this policy before those features begin collecting or publishing user data.
Website data
When you visit the site, your browser sends ordinary connection information, including your IP address and browser details, to the services that deliver pages and images. Cloudflare serves the website. Where catalog images are shown, Supabase Storage may deliver them. These providers may process technical logs for delivery, reliability and security.
On the landing page and public-profile routes, Figfolio uses PostHog for limited, cookieless usage measurement. Events are limited to a page type and selected navigation or profile actions. We do not send full URLs, search parameters, profile handles, referrers, chat text or image contents as analytics event properties. The website does not create a PostHog person profile or set an analytics cookie. Browser Global Privacy Control and Do Not Track signals prevent this optional analytics from starting.
To show a consistent version of the landing page during a design test, Figfolio stores only the choice between the current and motion versions in a first-party, host-only cookie for up to 30 days. This cookie contains no unique visitor ID and uses Secure, HttpOnly and SameSite=Lax protections. The cookie itself is not sent to PostHog; when optional analytics is active, landing events include only the version label. If your browser sends Global Privacy Control or Do Not Track, the site shows the current version without setting this cookie.
Public collections
When collector accounts become available, a collector's chosen handle, display name, optional bio, selected series, owned figures, automatically derived Wanted figures and available duplicates are intended to appear on a public profile. Public profiles may be accessible to visitors without an account and to search engines. Blocking another signed-in collector will not hide a public collection from an anonymous visitor. Do not add private information to your public name or bio.
Personal item photos, avatar and cover uploads are not active today. Before they launch, we will explain their visibility and deletion behavior here and in the app. Official catalog imagery is separate from user uploads.
App features before launch
The planned iPhone app uses Sign in with Apple and is intended for collectors aged 18 or older in the United States. When enabled, account and collection features will use an Apple account identifier and, if Apple provides one, an email address (which may be a relay address). They will also require an age and country declaration, your chosen public profile details, and your collection selections and owned quantities. Match and trade features may also process requests and account relationships. These account features are not currently available to the public, and their exact App Store privacy disclosures will be checked against the released app and its SDKs before launch.
We do not offer in-app payments, escrow, shipping labels or authenticity verification. We do not sell personal information or use website analytics to track people across other companies' apps or websites for advertising.
Why and with whom
We use technical data to serve and secure the site, limited analytics to understand whether the public pages work, and information you send us to answer a request. Our current service providers include Cloudflare (website delivery), Supabase (catalog media and planned app backend), PostHog (limited analytics), and Google (the support email inbox). They process data for these service purposes under their own infrastructure and terms. We may disclose information when legally required or to address abuse and security incidents.
Service infrastructure may process information in different countries. The PostHog project is hosted in the EU and the Supabase project is in Frankfurt; Cloudflare's delivery network is distributed globally. A visitor's network location does not imply that every processing step remains in that country.
Retention and deletion
We keep website analytics for product measurement while needed for that purpose. Because those cookieless events are not linked to a named visitor, we may be unable to identify and remove one person's historical anonymous events. Delivery and security logs are kept by the relevant provider under its operational retention settings. We keep support emails while needed to resolve the request and related follow-up, unless a longer period is legally required.
There is no working in-app account-deletion flow yet. If you have a privacy request about information you have sent to us, contact alisahindev@gmail.com. We will verify the request as needed and explain what can be accessed, corrected or removed. A future account-enabled app must provide deletion from within the app; this website contact route does not replace that requirement. See account deletion status.
Your choices
You can enable Global Privacy Control or Do Not Track in your browser to stop Figfolio's optional website analytics. You can also contact us about access, correction or deletion of information you have directly provided. Public collector content, once launched, may remain visible in search engine caches after it is removed from Figfolio; search engines control their own refresh timing.
Figfolio's planned account service is for adults 18 and over. Please do not send us information about a child. If you believe that has happened, contact us so we can review it.
Changes and contact
We will update this page when account, media, chat, moderation or deletion features go live. The effective date above will change with a material revision. For privacy questions, write to Ali Şahin at alisahindev@gmail.com. For product help, use the Support page.