The short version
- Your scans, photos and collection are saved on your iPhone. If you pin where you found something, that location stays on your iPhone and is never sent.
- Only if you allow AI analysis, the photos you choose, with the kind of place you found it and any area or note you type, go through our server to OpenAI to identify it. Our server does not keep them.
- No account, no ads, no tracking, and we never sell your data.
Who we are
Rocklore is made by Wavista Apps, operated by William Tsao, an individual based in California, USA. Contact: [email protected].
What stays on your iPhone
Rocklore has no account. It saves these only in the app's storage on your iPhone:
- your scans: the photos, the AI result, the details you gave (place type, area and note), shark tooth measurements and your answers to the field tests;
- your collection: each find's name, category, your note, the date, and the place where you found it if you chose to pin it;
- files you export, such as a collection list or a certificate, until you share them;
- your setup answers, your AI choice and your settings.
If you back up your iPhone to iCloud or a computer, the backup includes this data, as it does for any app.
Your location
Rocklore asks for your location only while you use the app, and reads it only when you save a find with Pin where I am now turned on. The pin is saved on your iPhone to place the find on your collection map. It is never sent to our server, to OpenAI or to analytics; analytics learn only whether a find has a pin, yes or no. A scan never reads your location, so your iPhone's location is never sent with your photos.
The collection map is drawn by Apple Maps, which loads map pictures for the area you view, under Apple's privacy policy.
Separately, when you identify a find, you can pick the kind of place it came from and type a state or area yourself. Those go with your photos, as described below.
What leaves your iPhone, and who receives it
Our server and OpenAI (identification)
Photo analysis needs your permission. The app asks on a consent screen first, and nothing is sent if you choose Not now.
When you identify a find with AI analysis allowed, the app shrinks each photo and removes its metadata, including any location, and sends to our server:
- Identification: 1 to 3 photos; the kind of place you pick (beach, river or creek, desert, mountains, backyard, bought it, or somewhere else); the state or area if you typed one (up to 80 characters); your note if you added one (up to 300 characters); and whether you are in shark tooth mode.
- Shark tooth size: in shark tooth mode, 1 photo of the tooth next to a US quarter.
On an iPhone with Apple Intelligence, a one-photo scan first gets a quick look on your iPhone, and only its text answer is sent to our server. If that answer says the photo is not usable, you are asked to retake it and no photo is sent. Otherwise the photos are sent as described here.
Our server removes any remaining metadata and sends the photos and details to OpenAI to get the result. It keeps them in memory only while it gets the result. It does not save them or write them to its logs.
OpenAI receives the photos and details, but not your name, your pinned location or the app's anonymous ID. We send each request with OpenAI's storage option turned off (store=false), so OpenAI does not keep it as a stored conversation. OpenAI does not use API data to train its models. It may keep API data for up to 30 days only to check for misuse, and then deletes it.
The app keeps your scan photos on your iPhone until you delete the scan or use Delete my data.
Withdraw your permission at any time: Settings, Use AI analysis.
What our server keeps
Every request to our server carries the app's anonymous ID (a random ID created by RevenueCat, see below), so the server can check your subscription and daily limit. Our server keeps:
- A record of each identification: the time, the feature, which kind of AI answered, whether it worked, how long it took, its cost, the confidence of the answer and your answer to "Was this right?" if you give one. It is tied to a scrambled form of the anonymous ID (a salted hash), not the ID itself, and never includes photos, notes or places. Records are deleted after 90 days.
- Daily usage counts, tied to the scrambled ID, deleted after 90 days.
- Your subscription status: the anonymous ID with the product, the expiry date, whether it is a trial and whether it was a test purchase. RevenueCat sends this to our server when your subscription changes. We keep it until you use Delete my data.
Our server uses your IP address for a moment, in memory, to limit how many requests one connection can make. It does not save it in its database or its logs. Our server runs on Fly.io, and its database is hosted by Supabase, both in the United States. Every hour we save a backup copy of that database in a separate private storage bucket at Cloudflare R2. Each copy is encrypted before it is uploaded, with a key that only we hold, so Cloudflare cannot read it. We use backups only to recover the database if something goes wrong.
RevenueCat (subscriptions)
RevenueCat runs the subscription for us. It receives the app's random anonymous ID, your App Store purchase records (what you bought, when, its price, and trial and renewal status) and technical details such as the iOS and app version. Its software also sends the identifier for vendor, an ID that Apple gives our apps on your iPhone. RevenueCat never gets your name, email or payment card. If you installed the app from an ad on the App Store (Apple Ads), Apple tells RevenueCat which ad campaign, ad group and search keyword led to the install, so we can see whether our ads pay for themselves. This is Apple's own ad attribution: it does not use the advertising identifier and needs no tracking permission. Apple handles payment.
PostHog (usage analytics, which you can turn off)
We use PostHog to see how the app is used, so we can find problems and improve it. Analytics are on when you install the app, and you can turn them off at any time in Settings, Share usage analytics. When they are off, the app sends nothing to PostHog. When they are on, PostHog receives, tied to the anonymous ID:
- your two setup answers, both picked from a list: what you find most, and the kind of place you hunt (a category such as beaches or rivers, not a location);
- events such as opening the app, setup steps viewed, permission answers, your AI choice, when the subscription screen was shown, trials, purchases and restores, when an identification started, finished (how long it took, its confidence) or failed (an error code), your thumbs answer and review prompts;
- that you scanned a find (its category and the top confidence), completed field tests (how many, and whether the top answer changed), measured a shark tooth (whether it worked), added a find to your collection (whether it has a pin, yes or no) or exported (the format);
- details the PostHog software adds, such as the app version, iOS version, device model, language, time zone and screen size.
PostHog never receives your photos, notes, the area you typed, names, pinned locations or specimen names. Session recording, touch tracking and location lookup from your IP address are turned off. PostHog does not store your IP address.
Sentry (crash reports)
If the app crashes or hits an error, it sends a report to Sentry so we can fix it: what went wrong and where in the app, the device model, iOS and app version, a random ID Sentry makes for the install, and a short trail of what the app did just before. For about 1 in 10 sessions it also sends performance timings. Reports do not include the anonymous ID. Before a report is sent, the app cuts a failed database save down to the kind of action and the table name, so a report never includes what you were saving (such as a find's name, note or pin). It also leaves out request details and console logs. Sentry does not store your IP address.
Apple
Apple handles the App Store, payments, Apple Maps, Apple Intelligence (which runs on your iPhone) and iPhone backups under Apple's own privacy policy.
Email to support
If you email us, we receive your email address, your message and the details that Contact support adds (app version, iOS version and the anonymous ID). We use them only to help you. We keep support emails for 2 years after your last message, then delete them. Cloudflare forwards them to our Gmail (Google) inbox.
Permissions
- Camera and photos: only to take or choose a photo of a find.
- Location, while using the app: only to pin a find on your collection map, as above.
Rocklore does not use your contacts, microphone or Apple Health.
How long data is kept
- On your iPhone: until you delete it, use Delete my data or delete the app.
- Photos and details on our server: not stored, only held in memory during the request.
- At OpenAI: up to 30 days, only for misuse checks.
- Request records and usage counts on our server: 90 days.
- Encrypted backups of our server's database: hourly copies for 3 days and daily copies for 35 days, then deleted automatically. Anything removed from the database, including by Delete my data, is gone from every backup within 35 days.
- Subscription status on our server: until you use Delete my data.
- RevenueCat: for as long as we offer the app, so your subscription can be restored.
- PostHog: up to 1 year, or until you use Delete my data.
- Sentry: 30 days.
Delete my data
Open Settings and tap Delete my data. The app deletes everything it saved on your iPhone right away (your scans, photos, collection, pins, exports, answers and settings) and starts again from the beginning. Analytics are turned off on that iPhone until you turn them on again in Settings. Files you already shared elsewhere are not affected. Then it asks our server to:
- ask PostHog to delete your analytics profile and its events;
- delete your subscription status record;
- remove the scrambled ID from your request records, so they can no longer be tied to you (they are still deleted at 90 days);
- delete your usage counts from earlier days. Today's count stays until it expires, so daily limits still work.
Backups made before the deletion still hold the old records until those copies are deleted, at most 35 days later. Nobody can read a backup without our encryption key, and we use backups only to recover the database after a failure.
If your iPhone is offline or our server cannot be reached, the app tries again by itself. While the deletion is waiting for our server, Settings shows it and offers Email support. If you delete the app before then, it can no longer finish this step, so first email us from Contact support (it adds the anonymous ID we need) and we will delete the server copy.
Delete my data does not cancel your subscription and does not delete RevenueCat's purchase record, so you can still restore your subscription. To ask for your RevenueCat record to be deleted too, email us.
Your requests
You can email [email protected] to ask what we hold about you, or to delete it. Send the email from Contact support in the app so it includes the anonymous ID; we cannot find your data without it, because we do not know your name. We reply within 30 days.
What we do not do
We do not sell your personal information or share it for advertising. The app has no ads and does not track you across other companies' apps or websites.
The app does not track you across other companies' apps or websites, so there is nothing for a Do Not Track signal to turn off, and the app does not respond to one.
Children
Rocklore is not directed to children under 13, and we do not knowingly collect data from them. If children use Rocklore, a parent should set it up and choose whether AI analysis and location pins are allowed. If you think a child has used the app on their own, email us and we will help delete the data.
Where the law requires it, the app asks Apple for your age range. The answer stays on your iPhone, is used only to apply age protections, and is never sent to us or anyone else. If Apple says you are under 13, or you choose not to share your age range where it is required, the app turns off usage analytics, Apple Ads attribution (see RevenueCat above), identifying finds (every scan goes through our server, even after a quick look on your iPhone), and your answers about AI results. Your collection and location pins keep working on your iPhone.
Security and where data is processed
The app talks to our server and service providers over encrypted connections (HTTPS). Our server stores the anonymous ID only in scrambled form, except in the subscription record. Our server, its database and our service providers process data in the United States. Database backups are encrypted before upload and kept in Cloudflare R2's Eastern North America region.
Changes to this policy
If we change this policy, we will post the new version here with a new effective date. If a change affects how we use data you already gave us, we will tell you in the app first.