Privacy Policy
This policy explains what data ScanMyRock ("we", "us") collects when you use the ScanMyRock app and the scanmyrock.com website, why we collect it, and the choices you have. The short version: we collect what the app needs to work, we do not sell your data, and you can delete your account and everything in it at any time.
1. What we collect
Photos you scan
When you scan a stone, the photograph you take or choose is uploaded to our servers to run the identification, and the photo, the date, and the resulting candidates are stored in your scan history so you can return to them. If you save a find to your collection, your photo is stored with it.
A photograph you submit may also be selected to illustrate the matching stone's detail page in the reference catalogue, including in edited form, for example with the background removed. This use is anonymous: nothing that identifies you is shown with the photo. You can opt any photo out by emailing us. The Terms of Service describe this licence in full.
Account data
The first time you open the app we create an anonymous identity for you, a random identifier with no name or email on it, so your scan history and collection work without signing up. If you create an account we additionally store your email address and authentication credentials, attached to that same identity. Accounts are managed by our infrastructure provider Supabase. Browsing the catalogue requires no identity at all.
Collection data
What you choose to record about your finds: the identification, your notes, a nickname for the specimen, its size, and optionally where and when you found it. Location details are stored only if you enter them; the app does not record your position in the background.
Onboarding answers
When you first open the app we ask a few optional questions (your goal, what you plan to scan, your preferred units, and how you heard about us) so the app can lead with the part you came for and so we know where to spend our time. Answers are linked to your usage profile.
Usage analytics
We use Mixpanel to understand how the app is used in aggregate: which screens are opened, how scans progress, and where people get stuck. This helps us decide what to fix and build next.
Crash and error reports
We use Sentry to collect crash reports and technical error data (device model, operating system version, app version, and the state of the app at the time of the error) so we can find and fix faults.
2. What we do not collect
- We do not sell or rent your personal data to anyone.
- We do not track your location in the background. Find locations exist only if you type them in or attach them yourself.
- We do not access your photo library beyond the photos you explicitly choose.
- We do not show third-party advertising and we do not share your data with advertisers.
3. Why we process your data
- To provide the Service (contract): running identifications, keeping your scan history and collection, signing you in.
- To improve the Service (legitimate interest): aggregate analytics, crash reporting, improving identification reliability, and illustrating catalogue entries with selected submitted photos as described above.
- To communicate with you (legitimate interest or consent): service messages about your account, and replies when you contact us.
4. Where your data lives
Your data is stored with our hosting and infrastructure providers, principally Supabase (database, authentication and file storage). Analytics data is processed by Mixpanel and error data by Sentry. These providers process data on our behalf under their own data processing agreements. Data may be processed outside your country; where it is, we rely on appropriate safeguards such as the EU standard contractual clauses.
5. How long we keep it
- Scan history and collection data: for as long as your account exists.
- Account data: for as long as your account exists, then deleted.
- Analytics and crash data: retained according to the provider's retention settings, and not linked back to your account once the account is deleted.
6. Your rights
Depending on where you live, you have rights to access, correct, export, restrict and delete your personal data, and to object to certain processing. You can exercise the important ones directly:
- Delete your account and data by emailing us from the address on the account, or from the app's profile screen where available. Deletion removes your account, scan history and collection.
- Ask for a copy of your data by emailing us.
- Opt a photo out of catalogue use by emailing us with the photo in question.
If you believe we have mishandled your data, you can complain to your local data protection authority. In the Netherlands this is the Autoriteit Persoonsgegevens.
7. Children
The Service is not directed at children under 13, and we do not knowingly collect personal data from them. If you believe a child has created an account, contact us and we will delete it.
8. Security
Data in transit is encrypted, access to production systems is restricted, and accounts are protected by industry-standard authentication. No system is perfectly secure; if a breach affecting your personal data occurs, we will notify you and the relevant authority as the law requires.
9. Changes to this policy
We may update this policy as the Service evolves. If a change is material, we will give notice in the app or by email before it takes effect. The effective date at the top always tells you when it last changed.
10. Contact
Privacy questions and requests: [email protected].