The short version
- Your scans, coin photos and collection are saved on your iPhone.
- Only if you allow AI analysis, the coin photos you choose go through our server to OpenAI to identify the coin. Our server does not keep them.
- No account, no ads, no tracking, and we never sell your data.
Who we are
Mintwise is made by Wavista Apps, operated by William Tsao, an individual based in California, USA. Contact: [email protected].
What stays on your iPhone
Mintwise has no account. It saves these only in the app's storage on your iPhone:
- your scans: the front and back photos, the AI result, the mode and the date;
- your collection: series, year, mint mark, variety, grade range, your notes and dates;
- your roll-hunting sessions: counts, face value and flagged coins;
- your setup answers, your AI choice, your grading fee settings and other settings.
The app also downloads a public coin reference list from our server; it contains no personal data. If you export your collection as a spreadsheet, the file is made on your iPhone and goes only where you send it from the share sheet.
If you back up your iPhone to iCloud or a computer, the backup includes this data, as it does for any app.
What leaves your iPhone, and who receives it
Our server and OpenAI (coin identification)
Photo analysis needs your permission. The app asks on a consent screen first, and nothing is sent if you choose Not now.
When you scan a coin with AI analysis allowed, the app shrinks each photo and removes its metadata, including any location, and sends our server the front photo, the back photo if you took one, and whether you photographed one side or both. No notes or other text are sent.
In roll mode, on an iPhone with Apple Intelligence, the first look at a coin can run on your iPhone. If that answer is clear enough, only the text result is sent to our server, not the photo. Otherwise the photos are sent as described here.
Our server removes any remaining metadata and sends the photos to OpenAI to identify the coin. It keeps photos in memory only while it gets the result. It does not save them or write them to its logs.
OpenAI receives the photos, but not your name or the app's anonymous ID. We send each request with OpenAI's storage option turned off (store=false), so OpenAI does not keep it as a stored conversation. OpenAI does not use API data to train its models. It may keep API data for up to 30 days only to check for misuse, and then deletes it.
The app keeps your coin photos on your iPhone, with your scans and collection, until you delete them or use Delete my data.
Withdraw your permission at any time: Settings, Use AI analysis.
Metal prices and price links
To show melt values, the app asks our server for current silver and copper prices. Our server gets them from gold-api.com and sends gold-api.com no information about you.
The "Check real prices" links open eBay or Numista in Safari or the eBay app, where their own privacy policies apply; the app sends them only the coin's name or catalog number, nothing about you.
What our server keeps
Every request to our server carries the app's anonymous ID (a random ID created by RevenueCat, see below), so the server can check your subscription and daily limit. Our server keeps:
- A record of each identification: the time, the feature, which kind of AI answered, whether it worked, how long it took, its cost, the confidence of the answer and your answer to "Was this right?" if you give one. It is tied to a scrambled form of the anonymous ID (a salted hash), not the ID itself, and never includes the photos. Records are deleted after 90 days.
- Daily usage counts, tied to the scrambled ID, deleted after 90 days.
- Your subscription status: the anonymous ID with the product, the expiry date, whether it is a trial and whether it was a test purchase. RevenueCat sends this to our server when your subscription changes. We keep it until you use Delete my data.
Our server uses your IP address for a moment, in memory, to limit how many requests one connection can make. It does not save it in its database or its logs. Our server runs on Fly.io, and its database is hosted by Supabase, both in the United States. Every hour we save a backup copy of that database in a separate private storage bucket at Cloudflare R2. Each copy is encrypted before it is uploaded, with a key that only we hold, so Cloudflare cannot read it. We use backups only to recover the database if something goes wrong.
RevenueCat (subscriptions)
RevenueCat runs the subscription for us. It receives the app's random anonymous ID, your App Store purchase records (what you bought, when, its price, and trial and renewal status) and technical details such as the iOS and app version. Its software also sends the identifier for vendor, an ID that Apple gives our apps on your iPhone. RevenueCat never gets your name, email or payment card. If you installed the app from an ad on the App Store (Apple Ads), Apple tells RevenueCat which ad campaign, ad group and search keyword led to the install, so we can see whether our ads pay for themselves. This is Apple's own ad attribution: it does not use the advertising identifier and needs no tracking permission. Apple handles payment.
PostHog (usage analytics, which you can turn off)
We use PostHog to see how the app is used, so we can find problems and improve it. Analytics are on when you install the app, and you can turn them off at any time in Settings, Share usage analytics. When they are off, the app sends nothing to PostHog. When they are on, PostHog receives, tied to the anonymous ID:
- your two setup answers, both picked from a list: your goal (for example, checking pocket change or building a collection) and your experience level;
- events such as opening the app, setup steps viewed, permission answers, your AI choice, when the subscription screen was shown, trials, purchases and restores, when an identification started, finished (how long it took, its confidence) or failed (an error code), your thumbs answer, shares and review prompts;
- that you scanned a coin (its series, whether it is a key date, how many possible varieties it has and whether the photo was usable), viewed a variety, used the grading calculator (its verdict), added a coin to your collection (its series) or finished a roll session (coins checked and flagged);
- details the PostHog software adds, such as the app version, iOS version, device model, language, time zone and screen size.
PostHog never receives your photos, notes, grading fees, the sold prices you enter or melt values. Session recording, touch tracking and location lookup from your IP address are turned off. PostHog does not store your IP address.
Sentry (crash reports)
If the app crashes or hits an error, it sends a report to Sentry so we can fix it: what went wrong and where in the app, the device model, iOS and app version, a random ID Sentry makes for the install, and a short trail of what the app did just before. For about 1 in 10 sessions it also sends performance timings. Reports do not include the anonymous ID. Before a report is sent, the app cuts a failed database save down to the kind of action and the table name, so a report never includes what you were saving (such as a collection note). It also leaves out request details and console logs. Sentry does not store your IP address.
Apple
Apple handles the App Store, payments, Apple Intelligence (which runs on your iPhone) and iPhone backups under Apple's own privacy policy.
Email to support
If you email us, we receive your email address, your message and the details that Contact support adds (app version, iOS version and the anonymous ID). We use them only to help you. We keep support emails for 2 years after your last message, then delete them. Cloudflare forwards them to our Gmail (Google) inbox.
Permissions
- Camera and photos: only to take or choose a photo of a coin.
Mintwise does not use your location, contacts, microphone or Apple Health.
How long data is kept
- On your iPhone: until you delete it, use Delete my data or delete the app.
- Coin photos on our server: not stored, only held in memory during the request.
- At OpenAI: up to 30 days, only for misuse checks.
- Request records and usage counts on our server: 90 days.
- Encrypted backups of our server's database: hourly copies for 3 days and daily copies for 35 days, then deleted automatically. Anything removed from the database, including by Delete my data, is gone from every backup within 35 days.
- Subscription status on our server: until you use Delete my data.
- RevenueCat: for as long as we offer the app, so your subscription can be restored.
- PostHog: up to 1 year, or until you use Delete my data.
- Sentry: 30 days.
Delete my data
Open Settings and tap Delete my data. The app deletes everything it saved on your iPhone right away (your scans, coin photos, collection, roll sessions, the collection spreadsheets it made, answers and settings), cancels its reminders (a reminder before a free trial ends stays, like the subscription) and starts again from the beginning. Analytics are turned off on that iPhone until you turn them on again in Settings. Copies of a spreadsheet you sent elsewhere are not affected. Then it asks our server to:
- ask PostHog to delete your analytics profile and its events;
- delete your subscription status record;
- remove the scrambled ID from your request records, so they can no longer be tied to you (they are still deleted at 90 days);
- delete your usage counts from earlier days. Today's count stays until it expires, so daily limits still work.
Backups made before the deletion still hold the old records until those copies are deleted, at most 35 days later. Nobody can read a backup without our encryption key, and we use backups only to recover the database after a failure.
If your iPhone is offline or our server cannot be reached, the app tries again by itself. While the deletion is waiting for our server, Settings shows it and offers Email support. If you delete the app before then, it can no longer finish this step, so first email us from Contact support (it adds the anonymous ID we need) and we will delete the server copy.
Delete my data does not cancel your subscription and does not delete RevenueCat's purchase record, so you can still restore your subscription. To ask for your RevenueCat record to be deleted too, email us.
Your requests
You can email [email protected] to ask what we hold about you, or to delete it. Send the email from Contact support in the app so it includes the anonymous ID; we cannot find your data without it, because we do not know your name. We reply within 30 days.
What we do not do
We do not sell your personal information or share it for advertising. The app has no ads and does not track you across other companies' apps or websites.
The app does not track you across other companies' apps or websites, so there is nothing for a Do Not Track signal to turn off, and the app does not respond to one.
Children
Mintwise is not directed to children under 13, and we do not knowingly collect data from them. If you think a child has used the app, email us and we will help delete the data.
Where the law requires it, the app asks Apple for your age range. The answer stays on your iPhone, is used only to apply age protections, and is never sent to us or anyone else. If Apple says you are under 13, or you choose not to share your age range where it is required, the app turns off usage analytics, Apple Ads attribution (see RevenueCat above), the AI features that send photos to our server and OpenAI, and your answers about AI results.
Security and where data is processed
The app talks to our server and service providers over encrypted connections (HTTPS). Our server stores the anonymous ID only in scrambled form, except in the subscription record. Our server, its database and our service providers process data in the United States. Database backups are encrypted before upload and kept in Cloudflare R2's Eastern North America region.
Changes to this policy
If we change this policy, we will post the new version here with a new effective date. If a change affects how we use data you already gave us, we will tell you in the app first.