Privacy Policy
CoinClue · Last updated 21 August 2026
CoinClue (“we”, “us”) helps you identify coins, estimate their value, organize a collection, and optionally publish classified coin listings. This policy explains what we collect, why we collect it, and the choices available to you.
Information we collect
Coin photos. When you scan a coin, its photos are uploaded to our secure backend and processed by an image-analysis service. Scan and collection photos remain private unless you explicitly choose photos for a classified listing. Published listing photos are visible to other CoinClue users.
Account data. If you create an email account, we collect your email address and our authentication provider securely handles the password. If you use Sign in with Apple, Apple may provide your name on the first authorization and either your email address or an Apple private-relay address, depending on your choice. We store the resulting Apple revocation credential encrypted on our server solely so we can revoke CoinClue’s Apple authorization when you delete your account. On Android, if you choose Sign in with Google, Google provides an account identifier, email address, and the profile name you approved; CoinClue exchanges Google’s short-lived identity token directly with our authentication provider and does not store that Google token on the device. You may also use the app with an anonymous account.
Scan and collection data. We store identification results for your scan history and the coins, estimated grades and values, and albums you choose to save.
Marketplace content. If you use the classified marketplace, we store the listing details and photos you publish, your chosen display name, approximate city or region, listing status, reports, blocks, conversation records, and messages. Listings are public inside CoinClue. Messages are visible to their participants and may be reviewed when reported or when needed to protect users and enforce our rules.
Notification data. Our notification provider may process an app subscription identifier and notification interactions. If you enable notifications, it also receives the Apple Push Notification service token on iOS or the Firebase Cloud Messaging token on Android needed to deliver them.
Product usage analytics. We record a limited allowlist of actions such as app opens, screen names, scan outcomes, saved coins, marketplace actions, sign-in, and purchase-flow steps. Those records include platform, app version, time, a random session identifier, and your account identifier. They help us understand aggregate usage, reliability, abuse, and feature performance. We do not use screen recording or session replay, and analytics never contains screen contents, coin photos, passwords, contact values, messages, listing descriptions, precise location, or keystrokes.
Optional advertising attribution. If this feature is enabled and you authorize Apple’s tracking prompt, our server may send Meta an allowlisted conversion event and a one-way hash of your random account identifier to measure whether an advertisement led to a useful action. Coin photos, scan results, messages, listing text, email addresses, contact details, and precise location are never included. Denying tracking permission stops these Meta events.
Advertising data. When advertising is enabled, free-plan users may see a banner supplied through Google Mobile Ads (AdMob) or may choose to watch a rewarded ad. The Google Mobile Ads SDK may automatically process an IP address (which can indicate general location), app and device information, device identifiers, crash and performance data, ads viewed, and interactions such as app launches, taps, ad impressions, clicks, and video views. Google uses this information for ad delivery, measurement, analytics, security, and fraud prevention. On iOS, the Apple advertising identifier (IDFA) is available to the SDK only when Apple’s App Tracking Transparency permission allows it. On Android, Google’s SDK may process the Android advertising identifier where the device, consent choice, account settings, and applicable law permit it. Ads that do not rely on those identifiers may still be shown where permitted.
Advertising consent. CoinClue uses Google’s User Messaging Platform to request the current consent status and present a consent message when required before requesting ads. Depending on your location, your choices, and applicable law, Google may serve personalized, non-personalized, limited, or technical ads. CoinClue asks the Google SDK whether ads may be requested and does not make an ad request when the SDK reports that consent or another legal basis is not available.
Rewarded-ad verification. Watching a rewarded ad is optional. Before a rewarded ad starts, our server creates a short-lived, opaque reward-session token tied to the signed-in CoinClue account. Google returns a signed server-to-server verification callback containing that token and limited ad-transaction details. Our backend verifies Google’s signature, rejects expired or duplicate transactions, applies the configured daily limit, and only then adds one extra scan. The opaque token is not your email address and does not reveal your coin photos, collection, or marketplace content to Google.
Premium no-ads. When CoinClue recognizes an active Premium entitlement, the app does not request CoinClue banner or rewarded ads. Advertising consent and advertising identifiers are not used by CoinClue to serve ads during that recognized Premium period.
Purchase status. Apple processes iOS purchases and Google Play processes Android purchases. RevenueCat helps us verify subscription and Lifetime Premium entitlement status across supported platforms. CoinClue never receives your full payment-card details.
How we use information
We use information to authenticate users, identify coins, estimate values, save and synchronize collections, publish and moderate classified listings, deliver messages, investigate abuse reports, deliver notifications, provide subscriptions, show and measure ads to eligible free-plan users, verify rewarded scan credits, enforce reward limits, understand aggregate feature usage, maintain security, and improve service reliability.
We do not sell personal information for money. Some privacy laws may define personalized advertising as “sharing” or “targeted advertising”; where applicable, the Google consent choices and Apple tracking permission described below control whether that advertising can occur.
Service providers
Information is processed only as needed by service providers that support CoinClue, including Supabase for authentication, database, storage, and server functions; OpenAI for coin-photo analysis; OneSignal and Firebase Cloud Messaging for notifications; RevenueCat for subscription entitlement management; Apple for account authentication and iOS payment processing; Google for optional Android account authentication and Google Play purchase processing; eBay for current listing context without personal information; Meta for optional advertising conversion measurement only after Apple tracking permission is authorized; and Google Mobile Ads (AdMob) and Google’s User Messaging Platform for ad delivery, consent choices, reporting, security, fraud prevention, and server-side reward verification. Learn more about how Google uses information from apps that use its services and review Google’s Privacy Policy.
CoinClue does not process classified-marketplace payments and does not require payment-card or banking information in marketplace messages.
Your advertising choices
When Google presents an advertising-consent message, you can use the choices shown there. If Apple’s tracking prompt appears, you can allow or deny tracking and later review that choice in iPhone Settings → Privacy & Security → Tracking. On Android, advertising controls may also be available under Settings → Privacy → Ads, with wording that varies by device. Restricting an advertising identifier does not necessarily prevent limited, contextual, or non-personalized ads.
You never have to watch a rewarded ad. If you decline or close it, no rewarded scan is added. An active Premium entitlement removes CoinClue banner and rewarded ads. If you need help with an advertising privacy choice, contact us using the address below.
Security and retention
Information is encrypted in transit. Account, photo, collection, listing, and message information is retained while your account remains active or as needed to provide the service. Reward-session tokens are short-lived; limited verified reward-transaction records may be kept to prevent duplicate credits, enforce daily limits, investigate fraud, and account for issued scans. After deletion, we retain a minimal security tombstone containing the random former account identifier and deletion-workflow timestamps. It contains no email, photos, collection, listing, message, or contact content and exists to prevent an already-issued access token from recreating uploads. Other limited records may be retained when reasonably necessary to investigate a safety report, prevent abuse, resolve a dispute, or comply with law.
Delete your data
You can request deletion of your account and associated saved data, listings, messages, photos, authentication identity, UUID-linked RevenueCat customer record, OneSignal notification identity, and—if used—Sign in with Apple authorization in the app from Profile → Delete account. CoinClue reports success only after its backend verifies the deletion steps; if it reports a failure, retry or contact us. Deleting CoinClue does not cancel an Apple App Store or Google Play subscription or remove transaction records those stores must retain under their own terms. For detailed instructions, visit our account deletion page.
Children
CoinClue is intended for adults and is not directed to children under 13. We do not knowingly collect personal information from children.
Your rights
Depending on where you live, you may have rights to access, correct, or delete your personal information. Use the in-app controls or contact us to exercise those rights.
Contact
Questions about privacy can be sent to tkchbils@gmail.com.