Privacy policy
Last updated: 2026-10-05
1. The short version
A coin photo is sent to our identification service, which passes it to an AI model (Anthropic's Claude) so that the coin can be read. We do not keep the image after the answer. Our server keeps scan metadata only.
A copy of each scanned coin also stays in the app's storage on your phone, so your collection and history work.
We do not sell personal data, and we do not use advertising or third-party analytics SDKs. [проверить: crash reporting in the release build]
2. What we process
Coin photos. The obverse photo and, if you add it, the reverse photo. Each photo is resized on your phone to at most 1024 pixels on the longest side and compressed as JPEG before it is sent.
Scan data. The identification result (country, denomination, year if it can be read, mint mark if visible, coin type, metal, and how sure the reading is), and any estimate shown with it. The result is shown to you; the server does not keep these fields.
Identifiers without an account. A random device key stored in the app, and a RevenueCat app user ID that identifies your install for subscriptions. You do not create an account. We use these identifiers to count monthly scans and to limit how often the service can be used.
IP address. Used for hourly rate limiting. [проверить: whether the hosting platform keeps request logs with IP addresses]
Purchase status. Subscriptions are handled by Apple App Store or Google Play. RevenueCat receives your purchase status. We never receive your card details.
Notifications. Reminders are off by default and are created on your phone. You turn them on yourself in the app.
3. How a coin photo is processed
Step 1. Your phone resizes the photo and sends it over an encrypted connection to our identification service. [проверить: the release build uses an https endpoint only]
Step 2. The service checks your scan allowance and the rate limit. It then sends the image to Anthropic's Claude model with instructions to identify the coin and return fields as structured data.
Step 3. The answer returns to your phone and is shown as your result. If the scan fails, no scan is counted.
The server code does not write the image to storage or to its logs. Log entries record events such as token counts and error types. [проверить: deployed logging configuration]
4. What our server keeps, and for how long
The table below describes the server code as written. [проверить: all rows against the deployed server, including its storage settings]
- Scan reference (app user ID, time, whether a reverse was included): about 1 hour, so that a reverse side added within 30 minutes of the first scan is free.
- Monthly scan count per app user: about 45 days.
- Hourly rate-limit counters per device key and per IP address: about 2 hours. The IP address appears in the storage key for that window.
- Coin images: not stored.
5. Anthropic, our AI provider
Anthropic processes the photo to produce the identification result. [проверить: Anthropic API data retention period for inputs, and that API inputs are not used for training under the commercial terms in force]
Photos are sent for identification only. We do not use them to build a training set. [проверить: this is a commitment we must be able to keep]
6. What stays on your phone
Your coin records, the saved copies of your scanned coins, and your settings are stored in the app on your phone. Uninstalling the app removes them from the phone.
The backup export is a JSON file of coin records. It does not include photos.
[проверить: whether deleting a coin record also deletes its saved photo copies (the current code does not appear to do this); whether iOS device backups include the app's stored photos; whether there is a one-tap photo delete]
7. Service providers
We rely on these providers to run Mintglass: Anthropic (AI identification), RevenueCat (subscription status), Apple App Store and Google Play (purchases and billing), and our hosting and key-value storage provider. [проверить: name, region and contract for the hosting and key-value provider]
Providers process data under their own privacy policies.
8. Sharing and sale
We do not sell personal data. We share data only with the providers above, to run the service, or when the law requires it.
9. Retention
Data on your phone stays until you delete it or uninstall the app. Server retention is as described in section 4. [проверить: retention periods, and whether deleting a coin record removes its photo copy]
10. Your choices
You can delete coin records in the app, turn off notifications, and cancel your subscription in your App Store or Google Play account settings.
To ask what scan records we hold about you, or to ask us to delete them, email us. [проверить: the request process and response time]
11. Children
Mintglass is not directed to children under 13 (or the minimum age in your country). We do not knowingly collect personal data from children. If you think a child has sent us data, email us and we will delete it.
12. Where data is processed
Our server and the AI provider may process data outside your country. [проверить: server region and provider region]
13. Changes
We may update this policy. The date at the top shows the latest version. Material changes will be shown in the app or on this page.
14. Contact
Questions about privacy? Email support@trypocketleaf.com.