← RockVaultAR
Privacy Policy
Effective date: 11 May 2026 · Last updated: 11 May 2026
This Privacy Policy describes how RockVaultAR ("we," "our," or "the app") collects, uses, and protects your information when you use the RockVaultAR mobile application.
1. Information we collect
- Account information. When you sign in, we collect your email address and a Supabase-issued user ID. Sign in with Apple may provide a relayed email.
- Rock photos and identifications. Photos you scan are sent to our identification service to identify the specimen. The photo is forwarded to Google's Gemini API for classification (see Section 3) and is not retained on our servers after the identification response is returned. Identified specimens (image, name, notes, tags, AR overlay configuration, optional location) are stored in your private vault and synced to your account.
- Optional location. If you grant location permission, the latitude/longitude where a specimen was found is stored alongside that specimen. You can disable this in iOS Settings at any time.
- Subscription status. Apple sends us your subscription tier (free, monthly, annual, lifetime) so we can unlock premium features. We never see your credit card or Apple ID password.
- Diagnostic logs. We log non-personal events on-device (using Apple's OSLog) to diagnose crashes and bugs. These logs stay on your device unless you choose to share them.
2. How we use information
- To provide and improve rock identification and AR overlay features.
- To sync your vault across your devices.
- To grant access to premium features based on your subscription.
- To respond to support requests.
3. Third parties we use
The following third-party service providers receive data from RockVaultAR for the purposes described:
- Supabase (Supabase Inc., processed in Canada) — database, authentication, file storage, and the server-side identification function. Receives your email address, user ID, vault data, and (transiently) the photo bytes you scan. Privacy policy.
- Google LLC — Gemini API (processed in the United States) — performs the rock/mineral classification on each scanned photo. Our identification Edge Function forwards the photo (downscaled to a maximum of 1568 pixels on the longest edge) and a fixed identification prompt to Google's Generative Language API ("Gemini 2.5 Flash"); Google returns a structured JSON classification. We do not send your account identifier, email, or location to Google. Per Google's API terms, photos sent to the paid Gemini API are not used to train Google's models. Google Privacy Policy · Gemini API Additional Terms.
- Apple (Apple Inc.) — Sign in with Apple, App Store payments, push notifications, and platform-level services. Apple's handling of these interactions is covered by Apple's own privacy policy.
We do not sell, rent, or share your personal information with advertisers or data brokers. RockVaultAR does not bundle any third-party advertising or analytics SDK.
4. Data retention
Your account and vault data are retained until you delete your account. When you delete your account from Settings → Delete Account, your authentication record is removed and associated data is removed via cascading database deletion. Server backups containing prior snapshots are rotated within 30 days.
5. Your rights
- Access — view all your data inside the app's Vault and Profile screens.
- Deletion — delete your account in-app via Settings → Delete Account, or email us at the address below.
- Correction — edit specimen data directly in the app.
- Withdraw consent — sign out, revoke camera/location permissions in iOS Settings, or delete the app.
6. Children's privacy
RockVaultAR is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, contact us at the email below and we will delete it.
7. Security
Data in transit is encrypted using HTTPS/TLS. Authentication tokens are stored in the iOS Keychain. Server-side data is stored on Supabase infrastructure with row-level security.
8. International transfers
Our backend is hosted in Canada (Central). Photo classifications are processed by Google's Gemini API in the United States. If you access RockVaultAR from another country, your data will be transferred to and processed in these locations.
9. Changes
We may update this policy from time to time. Material changes will be highlighted in-app on next launch.
10. Contact
Questions or requests: rodel.repulle@gmail.com