Privacy Policy
Last updated: September 1, 2026
Anime Figure Tracker (“AFT,” “we,” “our,” or “the app”) helps users identify anime figures, manage and privately back up a collection, submit community ratings and photos, and optionally publish a public collection gallery. This policy explains what information is processed, how it is used, and the choices available to you.
1. Scope
This Privacy Policy applies to the Anime Figure Tracker iOS app, its catalog and identification services, private iCloud collection backup and synchronization, public collection galleries, community features, optional anonymous collection analytics, support services, and related websites.
In this policy, information is considered collected when it is sent off your device and retained by AFT or one of its service providers. Information that remains only on your device is described separately. Information synchronized through your personal iCloud account is also described separately from information stored on AFT’s backend.
2. On-device collection storage
AFT stores your personal collection on your device. This may include:
- Figure names, characters, series, manufacturers, lines and scales;
- Purchase prices, currencies and other collection-value information;
- Personal notes, condition, ownership status and shelf groups;
- Photos of your figures and figure boxes;
- Featured-figure selections and rankings;
- Hidden-photo preferences;
- Showcase effects and display preferences;
- App theme, layout and filter preferences; and
- Subscription-entitlement status.
Your complete personal collection is not automatically published or transferred to AFT’s Cloudflare backend. Limited information is sent off-device when required for a feature you use, as described below.
3. Private iCloud backup and synchronization
When you are signed in to iCloud and iCloud Drive is available, AFT uses Apple CloudKit to synchronize your collection through a private database associated with your iCloud account. This allows your collection to return after reinstalling AFT and to remain synchronized across supported devices using the same iCloud account.
Private iCloud synchronization may include:
- Figure names and collection metadata;
- Character, series, manufacturer, line and scale information;
- Ownership status, condition and shelf-group assignments;
- Purchase prices and currency information;
- Personal notes;
- Featured rankings, gallery-photo visibility and display effects;
- Community-rating and submission status associated with a figure;
- Compressed private copies of figure photos;
- Compressed private copies of original photos used for editing; and
- Technical identifiers and fingerprints used to verify backup completion.
These records and photos are stored in the private CloudKit database for your iCloud account. Apple states that only the user can access a private CloudKit database by default, that the user owns its contents, and that private database contents are not visible through the developer portal. Private CloudKit data may count toward your available iCloud storage.
AFT does not copy your private iCloud collection or private backup photos into its Cloudflare database, public gallery storage, analytics dashboard or advertising systems unless you separately choose to use a feature that requires a particular item to be submitted or published.
If iCloud is unavailable, you are signed out of iCloud, or iCloud Drive is disabled, AFT may fall back to local on-device storage. In that case, your collection may not be recoverable after deleting the app or losing the device.
30-day deleted-figure recovery
AFT Pro may preserve a deleted figure and its private photo copies in your private iCloud database for up to 30 days. This allows the figure to be restored through the Recently Deleted feature.
Expired recovery records are removed during a subsequent cleanup and synchronization after the retention period ends. Restoring a figure returns it to your collection and removes the corresponding recovery record.
Deleting AFT from a device does not necessarily delete collection data already stored in your private iCloud database. You can manage AFT’s access to iCloud and its stored iCloud data through Apple’s iCloud settings where those controls are available.
4. Figure scanning, search and identification
When you scan a figure box, photograph a figure, scan a barcode, or perform a catalog search, AFT may process:
- A resized and compressed camera image;
- A barcode or JAN code detected in the image;
- Text detected using optical character recognition;
- Character, series, manufacturer and product names;
- Search queries derived from detected or entered information;
- Potential figure matches and your selected match; and
- Basic request information used for security and rate limiting.
This information is used to search the AFT catalog and, when necessary, request results from configured barcode, retailer, web-search or artificial-intelligence providers.
AFT does not intentionally retain ordinary scan images after the identification request is complete. A scan photo remains in your personal collection only when you choose to save it as the figure’s photo.
AFT may retain catalog matches, confirmed barcodes, unresolved barcode counts, learned catalog aliases, and identification success or failure statistics. This helps improve future identification results and allows a barcode identified by one scan to be recognized more quickly later. AFT does not intentionally store raw OCR text from ordinary scans as part of your collection profile.
Third-party providers may temporarily process images, extracted text, barcodes, product details or search queries according to their own terms and privacy policies.
5. Sign in with Apple and gallery accounts
Signing in is optional and is required only for hosted public-gallery features.
AFT uses Sign in with Apple to authenticate gallery accounts. We do not request your Apple name or email address. We receive an Apple-provided user identifier and store it as a one-way hash. This identifier allows AFT to recognize your gallery account during future sign-ins.
AFT also creates and stores:
- An internal gallery-account identifier;
- A secure session token stored in the iOS Keychain;
- A hashed version of the session token on the server; and
- A session expiration date.
Gallery sessions normally expire after 90 days and may be replaced when you sign in again.
Your gallery-account identifier is linked to gallery information and optional gallery photos you publish. It is not provided to advertising partners and is not used to track you across other companies’ apps or websites.
Your Sign in with Apple gallery account is separate from the private iCloud database used for collection backup and synchronization.
6. Public collection galleries
Publishing a gallery is optional. You choose whether to publish a gallery and whether to include collection value or figure photos.
When you publish a gallery, AFT may store:
- Your selected gallery title and theme;
- The number of figures included in the gallery;
- Figure names, characters, series, manufacturers, lines, scales, ownership statuses and featured rankings;
- Your total collection value, only when you enable “Show total collection value”; and
- Resized and compressed gallery copies of figure photos, only when you enable “Include figure photos” and have not hidden that figure’s photo.
Gallery publishing does not include individual purchase prices, personal notes, barcodes, local photo filenames or private shelf-group names. Original full-resolution photos are not uploaded as gallery copies.
Figures with hidden or excluded photos may still be included in the gallery’s figure count and optional total collection value.
A published gallery receives a public link. Anyone who receives that link may view or reshare its public content. AFT instructs search engines not to index gallery pages, but we cannot guarantee that another person will not copy, save or redistribute publicly shared content.
Updating or unpublishing a gallery
You can update a published gallery to change its title, theme, figures, value setting or included photos.
Selecting “Unpublish” makes the public gallery unavailable. Gallery metadata may remain stored so you can republish using the same account and link.
Turning off “Include figure photos” and updating the gallery removes hosted gallery-photo copies. Deleting your gallery account deletes the account, active sessions, gallery metadata and associated hosted gallery photos.
7. Optional anonymous collection analytics
AFT includes an optional “Anonymous Collection Analytics” feature. Collection analytics is off by default. AFT asks whether you want to participate before sending a collection snapshot.
Declining collection analytics does not restrict app functionality. You can change your choice at any time under Settings → Privacy.
When enabled, AFT sends a privacy-minimized snapshot containing:
- A random identifier created for this app installation;
- A random identifier for each figure copy;
- A catalog identifier, when the figure has one;
- Character;
- Series;
- Manufacturer;
- Figure line;
- Ownership status, such as Owned, Preordered or Wishlist; and
- The date the figure was added, when available.
The AFT server applies one-way hashing to the installation identifier and each figure-copy identifier before storing the analytics snapshot. The random installation identifier is not Apple’s advertising identifier and is not connected to your Sign in with Apple gallery account or private iCloud database.
Collection analytics does not send or store:
- Figure or box photos;
- Personal notes;
- Shelf names or shelf-group assignments;
- Prices paid or total collection value;
- Barcodes or JAN codes;
- Your Apple name, email address or Apple account information;
- Your gallery title or public-gallery link; or
- Apple’s advertising identifier.
AFT uses this information to calculate aggregate statistics such as:
- Total registered figure copies;
- Approximate numbers of participating app installations;
- Most collected figures;
- Most collected characters and series;
- Most collected manufacturers and product lines;
- Owned, preordered and wishlist distributions; and
- Collection and catalog trends over time.
These results are displayed through an access-controlled internal analytics dashboard. The dashboard presents aggregate statistics and does not display installation hashes or figure-copy hashes.
When you turn Anonymous Collection Analytics off, AFT sends an empty snapshot during the next successful synchronization. This deletes the stored collection-registration rows associated with that installation. If the device is offline, removal occurs the next time the app can successfully contact the service.
8. Community ratings
If you submit a Community Aura rating, AFT processes:
- The catalog figure being rated;
- Your rating from 1 through 5; and
- A one-way hash derived from a random per-install identifier, used to prevent duplicate ratings.
Community ratings are displayed publicly as an aggregate average and review count. Your gallery account, Apple identity and personal collection are not publicly displayed with the rating.
Submitting another rating for the same catalog figure from the same app installation replaces the previous rating from that installation.
9. Community photo submissions
Community photo submission is optional and requires a separate, explicit confirmation. If you submit a photo for community use, AFT may store:
- The submitted figure photo;
- Associated figure and catalog information;
- A pseudonymous per-install identifier;
- The date and text of your consent;
- The submission’s review status; and
- Internal moderation or reviewer notes.
Community photos are reviewed before approval. An approved photo may be shown to other users as a community catalog image. A rejected photo will not be published.
You may revoke a community photo submission through the available in-app control. Revocation removes the submitted community copy but does not delete the separate photo stored in your personal collection or private iCloud backup.
Only submit photos you took yourself or otherwise have the right to share. Do not submit photos containing faces, addresses, receipts, contact information, account information or other sensitive content.
10. Purchases and subscriptions
AFT Pro subscriptions are processed by Apple through the App Store and StoreKit. AFT does not receive or store your payment-card or bank-account information.
The app receives subscription and entitlement information needed to determine whether Pro features are active. Apple handles billing, renewal, cancellation, refunds and payment processing according to Apple’s privacy policy and terms.
11. Advertising
The free version of AFT may display advertising supplied by Google AdMob. Google and its advertising partners may process information such as:
- Device and advertising identifiers;
- Approximate or coarse location derived from device or network information;
- Advertising interactions and product interactions;
- Advertising data;
- IP address and device information;
- Crash, performance and diagnostic data; and
- Consent and privacy-choice information.
The exact information processed depends on your country, device settings, Apple permissions and choices made through any advertising consent form. Google may use this information for ad delivery, frequency control, fraud prevention, measurement, analytics and, where permitted, personalized advertising.
AFT does not provide your Sign in with Apple identifier, private iCloud collection, gallery photos, gallery metadata or optional collection analytics snapshot to Google for advertising.
Pro subscribers do not receive AFT’s regular in-app advertisements while their Pro entitlement is active.
12. Technical, diagnostic and provider-usage information
AFT and its service providers may process limited technical information required to operate and protect network features, including:
- Request timestamps and response status;
- IP address and general network information;
- App and operating-system version;
- Crash and performance information;
- Rate-limit and abuse-prevention information;
- Errors generated while using network features; and
- Service-provider request totals, success rates and response times.
For services such as Anthropic and Brave Search, AFT maintains aggregate operational counters such as request attempts, successful and failed requests, response time and, where supplied by the provider, AI token usage. These counters are used to monitor reliability, capacity, quotas and operating cost. They are not used to build user advertising profiles.
Cloudflare may process IP addresses and request information while delivering and protecting AFT’s backend services. AFT uses this information for security, delivery and rate limiting and does not intentionally attach an IP address to your public gallery profile.
13. How information is used
Information may be processed to:
- Store and synchronize your private collection through iCloud;
- Restore collection records and private photos after reinstalling;
- Provide 30-day deleted-figure recovery to eligible Pro users;
- Verify private iCloud backup completion;
- Identify figures and return catalog results;
- Provide barcode, text and catalog searches;
- Retrieve and improve figure information;
- Maintain and improve the figure catalog;
- Authenticate gallery accounts;
- Publish, update and unpublish public collection galleries;
- Store optional gallery photos;
- Provide community ratings and reviewed community images;
- Calculate aggregate collection statistics when users opt in;
- Verify subscription entitlements;
- Display and measure advertising;
- Monitor service capacity, reliability and provider usage;
- Prevent duplicate submissions, fraud, abuse and excessive usage;
- Diagnose errors and improve performance; and
- Respond to support, privacy and deletion requests.
14. Service providers
AFT relies on service providers that process information as needed to provide their respective services. These may include:
| Provider | Purpose |
|---|---|
| Apple | Private CloudKit collection storage and synchronization, Sign in with Apple, StoreKit subscriptions, App Store distribution, device backups and operating-system services. |
| Cloudflare | Backend hosting, catalog and analytics database storage, public gallery storage, gallery-photo storage, request delivery, administrative tools, security and rate limiting. |
| Anthropic | Image and text analysis used to help identify figures and complete figure information when catalog-only identification is insufficient. |
| Brave Search and configured catalog providers | Product, barcode and figure-information searches when the AFT catalog does not contain a sufficient result. |
| Google AdMob | Advertising, consent management, measurement, fraud prevention and related diagnostics. |
| GitHub | Hosting this privacy-policy website and the public support-issues page. |
Provider privacy information is available at:
- Apple Privacy Policy
- Cloudflare Privacy Policy
- Anthropic Privacy Policy
- Brave Privacy Information
- Google Privacy Policy
- GitHub Privacy Statement
15. Sale, sharing and tracking
AFT does not sell your gallery account, personal collection information or gallery photos for money.
AFT does not use its random collection-analytics identifier to track you across other companies’ apps or websites. It is not connected to your Apple advertising identifier, private iCloud database or Sign in with Apple gallery account.
Information may be disclosed:
- At your direction, such as when you publish or share a gallery;
- When you voluntarily submit a community photo or rating;
- To the service providers described in this policy;
- To comply with law, legal process or enforceable government requests;
- To investigate fraud, abuse or security incidents; or
- To protect the rights, safety and integrity of AFT and its users.
Advertising providers may process or share advertising information according to their own policies, your consent choices and your Apple device settings.
16. Data retention
Retention depends on the feature:
- On-device collection: retained until you edit or delete it, delete the app, erase the associated device data, or synchronize a deletion through iCloud.
- Private iCloud collection backup: retained in your private CloudKit database according to your collection changes and iCloud settings. Deleting the app from one device does not necessarily delete the private iCloud copy.
- Recently Deleted recovery records: retained for up to 30 days and removed during a subsequent app cleanup and synchronization after expiration.
- Identification requests: ordinary scan images are not intentionally retained by AFT after processing. Catalog matches, confirmed barcodes and unresolved barcode statistics may be retained to improve identification.
- Gallery account: retained until you delete the hosted account.
- Gallery sessions: normally expire after 90 days and may be replaced when you sign in again.
- Published gallery: retained until updated or deleted. Unpublishing disables public access but may retain gallery information for later republication.
- Gallery photos: retained while included in the gallery or until removed through a gallery update or account deletion.
- Collection analytics: retained only after you opt in. Turning it off removes that installation’s current collection snapshot during the next successful synchronization.
- Community ratings: may be retained to preserve the accuracy of aggregate ratings and prevent duplicate ratings.
- Community photos: may be retained for review, catalog use, moderation and abuse prevention until revoked or otherwise deleted.
- Operational and diagnostic information: retained only as reasonably needed for security, troubleshooting, service monitoring and legal obligations.
Service providers may maintain backups, security logs or transaction records for limited periods under their own retention requirements.
17. Your choices and controls
You can:
- Decline camera or photo-library access;
- Change camera and photo permissions in iOS Settings;
- Use the app without creating a gallery account;
- Keep collection value and gallery photos private;
- Hide individual figure photos from a public gallery;
- Update or unpublish your public gallery;
- Sign out of your gallery account;
- Delete your hosted gallery account using “Delete Account”;
- Delete locally stored figures and photos within the app;
- Restore eligible Pro figures through Recently Deleted;
- Review private iCloud backup status in AFT Settings;
- Manage AFT’s iCloud access and data through Apple’s iCloud settings;
- Revoke a community photo submission using the available app control;
- Decline or turn off Anonymous Collection Analytics under Settings → Privacy;
- Manage or cancel AFT Pro through Apple’s subscription settings;
- Change advertising consent choices where the consent form is available;
- Limit advertising tracking through Apple’s privacy settings; and
- Contact us with a privacy, access or deletion request.
Signing out removes the local gallery session but does not delete the hosted gallery account. Use “Delete Account” when you want the hosted gallery account and associated gallery data deleted.
Gallery-account deletion, private iCloud collection storage and optional anonymous collection analytics are separate systems. Deleting a hosted gallery account does not automatically delete private iCloud collection data or an opted-in analytics snapshot.
To remove all applicable information, delete the hosted gallery account, turn off Anonymous Collection Analytics, delete collection entries you no longer want, and manage AFT’s stored iCloud data through Apple’s iCloud settings where necessary.
18. Device permissions
AFT may request camera access to scan boxes, figures and barcodes. It may request photo-library access when you choose an existing photo or save an image.
AFT does not require access to your contacts, health information or precise location for its core collection features.
You can review and change app permissions at any time through the iOS Settings app.
19. Security
AFT uses reasonable technical measures intended to protect information, including:
- HTTPS encryption in transit;
- Private CloudKit storage protected through the user’s iCloud account;
- One-way hashing of gallery-account and analytics identifiers;
- Hashed server-side gallery session tokens;
- iOS Keychain storage for gallery sessions;
- Access controls for administrative tools;
- Resizing and compression of uploaded gallery and community photos;
- Upload and request-size limits;
- Rate limiting and abuse prevention; and
- Non-indexed public-gallery links.
No storage or transmission system can be guaranteed to be completely secure. Public gallery information should be treated as public after you share its link.
20. International processing
AFT and its service providers may process information in countries other than the country where you live. Those countries may have different privacy laws. AFT uses established service providers with safeguards intended to protect information during international processing.
21. Children’s privacy
AFT is not directed to children under 13, or the equivalent minimum age required by local law. We do not knowingly collect personal information from children below that age.
If you believe a child has submitted personal information through AFT, contact us so the matter can be reviewed and appropriate action can be taken.
22. Your privacy rights
Depending on where you live, you may have rights to request access, correction, deletion, restriction or portability of personal information, or to object to certain processing.
Many privacy actions can be completed directly in the app or through Apple’s iCloud settings. You may also contact us using the information below. We may need to verify that a request relates to your account or app installation before completing it.
AFT cannot directly provide a copy of records that are accessible only through your private CloudKit database. Access to those records is controlled through your iCloud account and the app.
Do not include passwords, payment information, private collection notes or other sensitive information in a public GitHub support issue.
23. Changes to this policy
This policy may be updated when AFT adds features, changes service providers or addresses legal or operational requirements. The “Last updated” date will be changed when the policy is revised.
Material changes may also be communicated through the app, the App Store listing or another appropriate notice.
24. Contact
For privacy questions, account-deletion assistance or other support, contact Anime Figure Tracker at:
You may also use: Anime Figure Tracker Support