PackRip: TCG Card Packs

Privacy policy

PackRip: TCG Card Packs has no account system, asks for no e-mail address and knows no name. This page describes exactly what it does collect, why, where it goes, and how to have it removed.

Last updated: 20 August 2026.

Who this covers#

This policy covers the iPhone app PackRip: TCG Card Packs, published by Arinc Elhan. The browser product at packrip.co is a separate product with its own policy; the two keep separate data and separate saves.

There is no account#

On first launch the app generates a random identifier and stores it in the iOS Keychain. That identifier is not your Apple ID, not your iCloud account and not an advertising identifier — it is a random string with no link to who you are. It is what the server uses to recognise your save. You can read and copy it any time from Settings, then About, then Device ID.

There is no signup, no login, no password, no e-mail collection and no social sign-in. The app never asks for your name, phone number, contacts, photos, location, microphone or camera.

What is collected#

These are the same five categories the app declares to Apple in its privacy manifest, and none of them is used to track you across other apps or websites.

  • Device identifier. The random Keychain identifier above. Used to attach your save and your purchases. Stored on your device and in the backend database.
  • Purchase history. Which coin packs and subscription periods were bought, so coins can be granted and PackRip Plus can be recognised. Handled by Apple and RevenueCat, and recorded in the backend database.
  • Product interaction. Anonymous aggregate counts of things happening in the app, for example that a pack failed to open. Used to find and fix problems and to understand which features are used.
  • Crash data. Crash reports, only if you left Apple’s crash sharing enabled during iOS setup. You can change that in iOS Settings, then Privacy and Security, then Analytics and Improvements.
  • Performance data. Timing and failure counts for the same diagnostic purpose.

Cloud save#

Your collection, coins, experience, quests, achievements, Seals, preferences and pity counters live on your device, and the app uploads a versioned snapshot to the backend when it goes into the background so you can recover it later. If the server already holds a newer snapshot than the one being uploaded, the server copy is returned so the two can be reconciled rather than one silently overwriting the other.

The backend is a Cloudflare Worker with a Cloudflare D1 database and Cloudflare KV, at packrip-api.elhanarinc.workers.dev. It stores your device identifier, a token issued for that identifier, your latest snapshot, and one row per purchase. Cloudflare processes standard request logs, including IP address and timestamps, for abuse mitigation under Cloudflare’s privacy policy.

Nothing expires on its own. A snapshot and its purchase records stay until you ask for them to be deleted, which is what the section below explains how to do.

Purchases#

Purchases are processed by Apple. Payment details never reach this app or its backend. RevenueCat validates the receipt and tells the backend so coins can be granted server-side and PackRip Plus can be recognised. RevenueCat receives the anonymous device identifier and Apple’s transaction metadata; it does not receive your Apple ID or contact details. See RevenueCat’s privacy policy.

Diagnostics and product metrics#

The app no longer bundles or contacts a third-party analytics service. The “Share Anonymous Analytics” setting was removed because there was nothing left for it to control.

What remains is first-party and deliberately thin: the app reports anonymous aggregate counts to its own backend — for example that a pack failed to open — with no user identifier attached, no card data and no free text. Those counts exist so failures get found and fixed.

Sponsored and affiliate content#

Some screens can show a sponsored placement supplied by BuySellAds, rendered inside a web view that loads from cdn4.buysellads.net. Placements are labelled Sponsor. The web view uses a non-persistent data store, so cookies and storage it creates are discarded when it closes. The app does not embed a native advertising framework, does not request Apple’s advertising identifier, and therefore never shows the App Tracking Transparency prompt. Sponsored placements are not shown to PackRip Plus subscribers.

Card screens can also show links to buy the real card at TCGplayer or eBay. Those links are labelled Affiliate link and PackRip earns a small commission on a qualifying purchase. Following one takes you to that company’s own site, under its own terms and privacy policy, and it never changes the price you pay.

Card and set content#

Sets, cards and game configuration are delivered from the backend so new content can arrive without an app update. Requests for that content are ordinary content requests and are not used to build a profile of what you look at.

Notifications#

Daily reminders are local notifications scheduled on your own device. No push token leaves the device, and the reminder skips days you already opened the app. Turn them off in iOS Settings, then PackRip, then Notifications.

App Tracking Transparency#

The app declares to Apple that it does not track you, and declares no tracking domains. It does not request the advertising identifier and does not present the App Tracking Transparency prompt.

Children#

Pack opening uses randomised odds, disclosed in the app before any purchase. The app is not directed at children under 13. Parents can restrict purchases with Apple’s Screen Time and Family Sharing controls.

The App Store lists the app at 4+.

Your choices#

  • Have your data deleted. E-mail elhanarinc@gmail.com with your Device ID from Settings, then About, and the cloud-save row and purchase records for that identifier are deleted.
  • Restore purchases. Settings, then Restore Purchases, re-attaches your subscription state.
  • Turn off reminders. iOS Settings, then PackRip, then Notifications.
  • Remove sponsored placements. A PackRip Plus subscription hides them.

Apple privacy manifest#

The app ships a PrivacyInfo.xcprivacy manifest declaring five collected data types — device identifier, purchase history, product interaction, crash data and performance data — none of them linked to an identity and none of them used for tracking. It also declares its required-reason API use for UserDefaults and file timestamps.

Changes#

Material changes appear here with a new date at the top and are announced in the app’s What’s New panel.

Contact#

Questions, deletion requests, anything else: elhanarinc@gmail.com.