PRIVACY NOTICE
COINSIDER · DETAILED INFORMATION ABOUT PROCESSING
Effective and last updated: 2026-10-03 · v6.0
Previous version 5.1Service provider and data controller
Tomasz Żądkowski (Coinsider), Sole proprietorship (JDG) Address: ul. Spadek 41, 22-400 Zamość, Polska Tax identification number: NIP 9222733587 Registry number: REGON 060204701 Legal and personal data contact: biuro@strefaczysta.pl
1. Data we process
We process account and authentication identifiers; a name or profile name when supplied by a sign-in provider; email and language; coin photographs and information supplied by the user; scan, identification and report metadata; purchase, entitlement and transaction identifiers; support messages and attachments; public-catalog content chosen by the user; and limited security, diagnostic and operational logs. We do not use advertising SDKs and do not sell personal data.
2. Detailed processing table
| Operation and data | Purpose and legal basis | Recipients | Retention |
|---|---|---|---|
| Account and sign-in: email, user ID, optional name/profile, language and sign-in evidence. | Create and protect the account; contract and legitimate security interests. | Base44; selected Google or Apple sign-in provider. | Until account deletion; recovery cycle up to 30 days; security logs up to 12 months. |
| Coin photos and details (Coinsider Vision only): photos, crop, liveview full frame, weight, diameter, description and scan metadata. | QC, AI identification, reports and fraud prevention; contract and legitimate security interests. | Base44; Google Cloud/Gemini. | Account content until the user deletes it. A deleted coin waits in the Trash for 30 days in the Free plan and 90 days in a paid plan, then we delete it for good; recovery copies up to 30 days; limited Google logs for 30 or 400 days by log class. |
| Results and reports: AI/QC outputs, alerts, reports, serials and operation history. | Deliver and re-download results, troubleshoot errors; contract. | Base44; Google to generate results; authorised support. | Until coin/account deletion; dispute evidence up to 6 years. |
| Publication (Coinsider Vision certified scans only): sanitised photo copy, description, report, serial number, QR and moderation status. | Optional Encyclopedia publication; publication consent and user licence. | Public visitors, search engines and Base44; no private original or owner identifier. | Until unpublishing/deletion; moderation 12 months, appeal 6 months; independent caches may expire later. |
| Purchases: product, transaction, storefront, entitlement, refund/revocation and balance. | Plans and units, double-spend prevention, tax and claims; contract, legal obligation and legitimate interests. | Apple and Base44. | Pseudonymised transaction evidence through 31 December of the sixth year after the transaction year. |
| Support: messages, attachments, contact details and resolution history. | Support, complaints, AI errors and rights requests; contract, legal obligation or legitimate interests. | Base44 and authorised support staff. | Ordinary support 24 months; complaints, disputes and claims up to 6 years. |
| Security: time, action, result, limited session, diagnostic, performance and fraud data. | Service protection, abuse detection and stability; legitimate interests and legal obligations. | Base44, Google Cloud and authorised administrators as necessary. | Generally up to 12 months; required Google Cloud logs up to 400 days. |
| Legal evidence: version, language, text hash, control state, time, product and transaction correlation. | Prove the contract, permission or acknowledgement and defend claims; legal obligation and legitimate interests. | Base44; authorised administrators, authorities or advisers where necessary. | 6 years unless a documented legal hold requires a specific record for longer. |
| Coinsider Snap: descriptive data entered by the user, photo hashes and parameters. | Keeping the collection catalogue, synchronisation, restoring from a backup; Article 6(1)(b) GDPR. | Base44. | Until the coin is deleted for good or the account is deleted. A deleted coin waits in the Trash for 30 days in the Free plan and 90 days in a paid plan; recovery copies up to 30 days. |
| Plan and access: the plan of the account, the state and dates of the subscription, the previous plan, the limits and their use. | Granting access and limits according to the plan; Article 6(1)(b) GDPR. | Base44; Apple (purchases). | For as long as the account exists. |
| Account deletion signal: a random secret of the account, stored on the account and on the devices where the account was used, and its SHA-256 hash in the account deletion receipt. | Removal of Coinsider Snap photos and of copies of account data from its devices after the account is deleted; Article 6(1)(c) GDPR in conjunction with Article 17 GDPR. Keeping the hash in the receipt: demonstrating that the erasure request was carried out; Article 6(1)(f) GDPR. | Base44. | Secret: until the account is deleted. Hash: 6 years, like the account deletion receipt. |
| Coin state: the identifier and number of a coin in the collection and its state (in the collection, in the Trash, deleted for good or replaced by a Coinsider Vision card). | Consistency of the collection across devices and when restoring from copies: a deleted or replaced coin does not come back from a copy or from pending writes; Article 6(1)(b) GDPR. | Base44. | Until the account is deleted. |
| Coinsider Coins wallet: grant, debit, automatic return and balance operations. | Accounting for AI services, crediting Coinsider Coins back to the balance, accounting for payment refunds and handling complaints; Article 6(1)(b), (c) and (f) GDPR. | Base44; Apple (purchases). | Until 31 December of the sixth year after the year of the operation; after account deletion the data are pseudonymised. |
| Pack purchase confirmation: product, number of units, date, transaction identifier, the statements given and the e-mail address of the account. | Confirmation of the contract on a durable medium; Article 6(1)(c) GDPR in conjunction with Article 21(1) of the Polish Consumer Rights Act. Keeping the record of the sending: demonstrating that the obligation was met; Article 6(1)(f) GDPR. | Base44; e-mail provider of the platform. | We do not keep the text of the message; the record of the sending, with SHA-256 hashes, is kept for 6 years. |
| Iron Vault file: the Coinsider signature of the data and identification results of Coinsider Vision coins, containing the account identifier and an HMAC hash of the original App Store subscription transaction identifier (originalTransactionId); when restoring, the data and photos of these coins from the file. | Data export and restoration of the collection on the account or on a new account with the same Apple ID, without accepting altered results; Article 6(1)(b) and (c) GDPR in conjunction with Article 20 GDPR. | Base44. | We do not store the signature on the server; you keep the file. Restored coins and photos are kept like other account content. When restoring we also record an entry for the photo upload limit; we keep it for 12 months. |
| Account activity: the date of the last sign-in of a Free plan account and the e-mail notice of a planned deletion of the account because of inactivity. | Limiting the storage of data of unused accounts and warning the user before the account is deleted; Article 6(1)(f) GDPR. | Base44; e-mail provider of the platform. | Date of the last sign-in: until the account is deleted. Record of the notice sent: 6 years, like the account deletion receipt. |
3. Purposes and legal bases
We process data to create and secure the account, provide scans and AI identification, maintain subscriptions and virtual balances, generate reports, provide support, prevent abuse, meet legal obligations and defend claims. Depending on the activity, the basis is performance of a contract, legal obligation or legitimate interests. Consent is requested only for a specific optional action, such as publishing a report; it is not bundled with access to the service and can be withdrawn prospectively.
4. Data sources and required information
We receive data from the user, the device when a requested feature is used, a selected sign-in provider and Apple in connection with a transaction. Email and account identifiers are required for an account; coin photos and details are required only for the selected analysis; publication is optional. Missing information required for a feature prevents that feature from working but does not authorize another use.
5. Disclosure to Google Gemini
When the user expressly requests QC, identification, a PRO report or image search, selected coin photos, user-supplied details, request context and necessary technical identifiers are transmitted through Coinsider infrastructure to Google Cloud/Gemini. The purpose is limited to the requested feature, security and diagnostics. Under the applicable paid API terms, prompts and responses are not used to improve Google products; Coinsider does not train its own models on them without a separate opt-in.
Coinsider Snap does not use AI and does not transfer photos or data to Google.
The permission to transfer data to AI is separate and voluntary. Your collection, Coinsider Snap and support provided by people work without it. We ask for it before you first use an AI feature; at sign-up you may give it or skip it.
AI features are: the photo quality check, identification, the PRO analysis, image search, the assistant in support, and the machine translation of your messages to support and of your appeals against moderation. Before each such operation our server checks the permission of the owner of the data, also when a member of Coinsider staff acts. Without the permission neither your photos nor your texts reach the AI provider, and our staff read your messages in the original.
You can withdraw the permission at any time in your account settings, as easily as you give it. After the withdrawal we start no new AI operation on your data; operations already accepted are completed. Results saved in your collection remain, and the withdrawal does not affect the lawfulness of earlier transfers.
We record the giving and the withdrawal of the permission with the date, the version and the language of the text, so that we can demonstrate what you agreed to or withdrew. We keep this record for 6 years.
6. Providers and recipients
The principal AI provider is Google Gemini within Google Cloud; Google Cloud Vision and infrastructure may support image analysis. Base44 provides the application platform and hosting. Apple provides StoreKit, App Store billing and applicable authentication services. No push provider is active in release V1. A future push feature requires a separate product, privacy and vendor review before activation. Providers act under applicable contracts. Transfers outside the EEA or UK must rely on adequacy decisions or appropriate safeguards such as standard contractual clauses, the UK Addendum or IDTA, plus any required transfer assessment—not on “consent by use.”
| Provider | Scope and role | Location / transfer | Key terms |
|---|---|---|---|
| Base44 / Wix group | Platform, hosting, authentication, database, functions and storage; processor. | Production: United States; DPA, DPF/adequacy and SCCs. | TLS, encryption at rest, access controls; deleted records recoverable for up to 30 days. |
| Google Cloud / Gemini API | QC, identification, PRO reports, image search and infrastructure; processor/AI service provider. | Core infrastructure europe-west1; other locations under Cloud DPA/SCCs. | Paid API no use of prompts/responses to improve products; no File API or durable Gemini profile. |
| Apple | App Store, StoreKit, refunds, storefront and optional Sign in with Apple; activity-specific role. | Under Apple terms. | Coinsider receives minimal transaction/entitlement identifiers, including a pseudonymous appAccountToken that binds the subscription to one account; account deletion does not cancel a subscription. |
| OneSignal — historical erasure only | No V1 SDK or new notifications; only deletion of a historical identifier. | No new operational transfers. | After erasure it is not a provider of the active release. |
7. International transfers
Base44 hosts production application data in the United States. The Base44 DPA provides applicable adequacy and Data Privacy Framework mechanisms and Standard Contractual Clauses. Configured Google infrastructure operates in europe-west1; other support and subprocessing locations are governed by the Google Cloud DPA and SCCs. Information about safeguards may be requested at biuro@strefaczysta.pl.
8. Retention and account deletion
Active account and coin content is kept until deletion. Immediate deletion starts after verified reauthentication; scheduled deletion provides a 30-day restoration window, while public records are withdrawn immediately. Base44 may retain deleted records in its recovery cycle for up to 30 days. Ordinary support is kept for 24 months after closure; consumer/account/AI disputes and legal claims, legal-text acceptance and deletion evidence for 6 years; moderation evidence for 12 months with a 6-month in-app appeal; security and fraud logs for 12 months. Apple/tax/ledger evidence is de-identified at account deletion and kept through 31 December of the sixth calendar year after the transaction year. A documented court, regulator, tax, claim, security or fraud hold pauses deletion only for the affected class and is reviewed at least every 90 days. Deletion does not cancel an Apple subscription.
When a subscription ends, the account and its data stay in the Free plan until you delete the account. We may delete a Free plan account that nobody has signed in to for 3 months, after an e-mail notice sent at least 30 days in advance; this does not apply to accounts with unused Coinsider Coins or purchased scans. Details are set out in the Terms, section “End of the subscription and account deletion”.
A coin you delete is kept in the Trash for 30 days in the Free plan and 90 days in a paid plan, and is then deleted for good.
After you ask for your account to be deleted, you can restore it within 30 days, or within 3 months for an account in the PRO plan. We then delete the account and its data, except data we must keep by law and data covered by a documented deletion hold (legal hold). You can also delete the account at once.
9. Rights, complaints and contact
Subject to applicable law, users may request access, correction, deletion, restriction, portability and objection, and may withdraw a specific consent. EEA users may complain to their local supervisory authority or Poland’s UODO; UK users may complain to the ICO. California residents may exercise applicable rights to know, delete, correct and non-discrimination; Coinsider does not sell or share data for cross-context behavioural advertising. Requests: biuro@strefaczysta.pl. Support: coinssupportpl@wp.pl.
We give effect to the right to data portability by, among other means, the Iron Vault file, which you can save in the application on every plan, also after your subscription ends. The file covers the whole collection: Coinsider Snap and Coinsider Vision coins, including those in the Trash, their data and identification results in JSON and CSV files, and their photos, in ZIP archives. It is a commonly used, machine-readable format. You can encrypt the file with your password; anyone who has a file saved without a password can open it. We receive neither the file nor the password. We will provide data that the file does not cover on a request sent to the address given above.
10. AI and automated decision-making
Identification and valuation results are probabilistic and informational. Coinsider does not use them to make solely automated decisions producing legal or similarly significant effects on the user. Every user can ask for a human review of an AI result, whatever the plan; we reply within 7 days.
11. Data stored on your device
The application saves in the storage of your device the data necessary for the operation of the services you ask for: session state, language and settings, a copy of collection data for offline use and photos of coins added in Coinsider Snap. Coinsider Snap photos do not leave the device unless you export them yourself, for example in an Iron Vault file or in a collector card PDF. A backup of the whole device that you turn on in the system settings (for example iCloud) may include the application data, including these photos. You and the provider of the system manage such a backup. You can exclude the data of this application from such a backup in the backup settings of the system. Before saving, the application re-encodes the photo, reduces its size if necessary and removes its metadata, including location information. Saving these data is necessary to provide the service, so it does not require separate consent (Article 399 of the Polish Electronic Communications Law). You can delete these data in the application settings, by deleting the application or by clearing the site data in the browser.
We do not process Coinsider Snap photos on our servers and we have no access to them. We process only the descriptive data linked to the coin and the cryptographic hash and parameters of the photo (size, dimensions, time added). We do this to recognise the photos when they are restored from an Iron Vault file or a Coinsider Snap backup and to avoid creating duplicates.
After migration from Coinsider Snap to Coinsider Vision is complete, the new card keeps the collection number and date added. We retain the link between records and the consent and completion markers so that old backups and pending writes cannot restore the deleted Snap card. These technical records remain until account deletion, even if you delete the new Vision card earlier. Backup files and PDFs previously saved outside the application remain under your control.
12. Local data, security and minors
The web and app store necessary session state, language, settings and acknowledgement versions locally. We use no advertising SDK, ATT or behavioural-advertising cookies. Measures include transport encryption, access control, minimisation, operation logging and incident procedures. No system can guarantee absolute security. The service is only for persons aged 18 or over.
The application removes EXIF metadata, including GPS data, from Coinsider Snap photos and does not send these photos to servers. Files on the device are kept separate for each account. The application encrypts the Iron Vault file with a password that you choose, using AES-256; a file saved without a password is not encrypted. We receive neither the file nor the password. When Coinsider Vision coins are restored, the application sends us only their data and photos from the file, and we keep those photos like the photos of scans. Coinsider Snap coins return to the account as descriptions, and their photos stay on the device. Details are set out in the section “Data stored on your device”.
13. Changes and contact
Material changes are published with a new date and version. If a new purpose requires consent, we ask before processing starts. Data requests: biuro@strefaczysta.pl. Complaints may be made to the competent authority, including Poland’s UODO or the UK ICO.
Account deletion14. Data in content notices
The Coinsider service provider identified in this Notice controls notice data. We process contact details, supplied name, language, URL/identifier, description, reasons, correspondence and necessary email metadata to review, reply, handle appeals and prevent abuse. The bases are applicable legal obligations and legitimate interests in protecting the service and people’s rights, not marketing consent or AI permission.
Preparing the form does not transmit its fields to Base44 or AI or save them in browser storage. Opening your email app passes the text to that app; subsequent processing and sending follow your email service. WP Poczta (Wirtualna Polska Media S.A.) and authorised Coinsider staff handle mail to coinssupportpl@wp.pl. Where necessary for moderation or appeal, an authorised person may record case evidence in Base44; receiving an email does not automatically create a ticket or run AI.
Moderation evidence follows the retention table: generally up to 12 months, and appeal evidence up to 6 months; specific claims evidence may require up to 6 years, with longer retention where legally required or subject to a documented legal hold. Access is limited to necessary staff and providers. Reporter contact details are not published in the archive. Without contact details, an individual reply is impossible. Data rights and contact biuro@strefaczysta.pl are described in this Notice.
Reporting and notice-and-action