CoinProof Privacy Policy

Effective date: on first publication. Last updated: 2026-09-06.

Not reviewed by counsel. It was written from what the app and its backend actually do.

This is the policy published at the Privacy Policy URL that App Store Connect requires and that App Store Review Guideline 5.1.1 requires the app to link to as well. CoinProof is offered in the United States only.

Who we are

CoinProof is published by WorldFlux Inc, the company App Store Connect names as the seller of the app, so the name on the store listing and the name in this policy are one name. "We" and "us" on this page mean WorldFlux Inc. Write to yoshi@worldflux.ai with any question about this policy, to ask what we hold about you, or to ask us to correct or delete it.

What we collect, and why

Photographs of your coins. You take them in the app or pick them from your photo library. They are used to identify the coin and, if you save it, to illustrate your collection. Location and camera metadata are stripped on your device before a photo is uploaded, and photos are stored in private storage that has no public address. We do not use your photographs to train models.

Your collection entries. The name, year and mint mark you confirm or correct, and the acquisition date, price, notes and tags you enter. They exist so that your collection is yours.

A device-only account. An account exists from your first launch, without any sign-in. It is an internal identifier plus a per-installation identifier sent with each request, used to keep your data yours and to stop abuse and rate-limit the service.

An optional account link. If you use Sign in with Apple, we store only a hash of the Apple subject identifier, so we can recognise the same Apple account again. We do not store your Apple email address or your name — there is no column for either.

Purchase records. Subscription and scan-credit state, mirrored from Apple through our purchase platform, so we know what your account is entitled to. No card number, bank detail or billing address ever reaches us; Apple handles payment.

Usage analytics, which you can switch off. Pseudonymous product-analytics events, used to understand how the app is used. They never carry your account identifier, a photo, a URL or free text — the identifier is an opaque salted value and the rest is refused by the event validator. Turn it off under Settings → Data & privacy → Diagnostics sharing; analytics is on by default and crash diagnostics is off until you turn it on.

Crash diagnostics, only if you opt in. A crash kind, a digest of our own stack frames, a release and an OS string. Nothing is collected until you switch it on.

A push token, only if you allow notifications. Stored encrypted, and used to tell you a scan finished, a deletion completed or a billing problem needs attention.

What we do not collect: no location, no advertising identifier, no tracking across apps or sites, no contacts, health data, browsing or search history, and no payment details. There is no advertising SDK in the app.

Who else sees it

We do not sell your personal information and we do not share it for advertising. Four kinds of recipient handle data on our behalf or for their own services:

We may also disclose data where the law requires it, and we will tell you unless we are prohibited from doing so.

How long we keep it, and how to delete it

Your photographs, collection and scan history are kept until you delete them or delete your account. Some things are cleared on a fixed clock: an upload never attached to a scan is purged after 24 hours, an item or scan you delete is held for 30 days and then removed for good, request telemetry is kept 30 days, a generated export's download link lasts 15 minutes, and sessions expire in minutes rather than days.

You can delete your account inside the app, signed in or not, under Settings → Data & privacy → Delete account. It closes the account immediately and then removes your photographs, exports, collection, scan history, consent records, sessions, device records and push tokens, the analytics mapping and the subscriber alias at our purchase platform. The app shows the progress. Two things survive by design and you should know it: the billing and credit record, because it is the financial record, and an empty account row holding an identifier, a state, a locale and timestamps and no personal data. Before deleting, you can take a copy: Settings → Data & privacy → Export my data.

Children

CoinProof is not directed to children under 13 and we do not knowingly collect personal information from a child under 13. If we learn that we have, we delete the account and its contents. If you believe a child under 13 has given us personal information, write to yoshi@worldflux.ai and we will remove it.

Changes

We will post any change on this page and update the date above. A material change is signalled in the app before it takes effect.

Contact

yoshi@worldflux.ai