PRIVACY NOTICE
COINSIDER · DETAILED INFORMATION ABOUT PROCESSING
Previous version 5.1 · 2026-08-29
Show the version in forceService provider and data controller
Tomasz Żądkowski (Coinsider), jednoosobowa działalność gospodarcza (JDG) Address: ul. Spadek 41, 22-400 Zamość, Polska NIP: 9222733587 REGON: 060204701 Legal and privacy contact: biuro@strefaczysta.pl
1. Data we process
We process account and authentication identifiers; a name or profile name when supplied by a sign-in provider; email and language; coin photographs and information supplied by the user; scan, identification and report metadata; purchase, entitlement and transaction identifiers; support messages and attachments; public-catalog content chosen by the user; and limited security, diagnostic and operational logs. We do not use advertising SDKs and do not sell personal data.
2. Detailed processing table
| Operation and data | Purpose and legal basis | Recipients | Retention |
|---|---|---|---|
| Account and sign-in: email, user ID, optional name/profile, language and sign-in evidence. | Create and protect the account; contract and legitimate security interests. | Base44; selected Google or Apple sign-in provider. | Until account deletion; recovery cycle up to 30 days; security logs up to 12 months. |
| Coin photos and details: photos, crop, liveview full frame, weight, diameter, description and scan metadata. | QC, AI identification, reports and fraud prevention; contract and legitimate security interests. | Base44; Google Cloud/Gemini. | Account content until user deletion; recovery copies up to 30 days; limited Google logs for 30 or 400 days by log class. |
| Results and reports: AI/QC outputs, alerts, reports, serials and operation history. | Deliver and re-download results, troubleshoot errors; contract. | Base44; Google to generate results; authorised support. | Until coin/account deletion; dispute evidence up to 6 years. |
| Publication: sanitised photo copy, description, report, serial, QR and moderation status. | Optional Encyclopedia publication; publication consent and user licence. | Public visitors, search engines and Base44; no private original or owner identifier. | Until unpublishing/deletion; moderation 12 months, appeal 6 months; independent caches may expire later. |
| Purchases: product, transaction, storefront, entitlement, refund/revocation and balance. | Plans and units, double-spend prevention, tax and claims; contract, legal obligation and legitimate interests. | Apple and Base44. | Pseudonymised transaction evidence through 31 December of the sixth year after the transaction year. |
| Support: messages, attachments, contact details and resolution history. | Support, complaints, AI errors and rights requests; contract, legal obligation or legitimate interests. | Base44 and authorised support staff. | Ordinary support 24 months; complaints, disputes and claims up to 6 years. |
| Security: time, action, result, limited session, diagnostic, performance and fraud data. | Service protection, abuse detection and stability; legitimate interests and legal obligations. | Base44, Google Cloud and authorised administrators as necessary. | Generally up to 12 months; required Google Cloud logs up to 400 days. |
| Legal evidence: version, language, text hash, control state, time, product and transaction correlation. | Prove the contract, permission or acknowledgement and defend claims; legal obligation and legitimate interests. | Base44; authorised administrators, authorities or advisers where necessary. | 6 years unless a documented legal hold requires a specific record for longer. |
3. Purposes and legal bases
We process data to create and secure the account, provide scans and AI identification, maintain subscriptions and virtual balances, generate reports, provide support, prevent abuse, meet legal obligations and defend claims. Depending on the activity, the basis is performance of a contract, legal obligation or legitimate interests. Consent is requested only for a specific optional action, such as publishing a report; it is not bundled with access to the service and can be withdrawn prospectively.
4. Data sources and required information
We receive data from the user, the device when a requested feature is used, a selected sign-in provider and Apple in connection with a transaction. Email and account identifiers are required for an account; coin photos and details are required only for the selected analysis; publication is optional. Missing information required for a feature prevents that feature from working but does not authorize another use.
5. Disclosure to Google Gemini
When the user expressly requests QC, identification, a PRO report or image search, selected coin photos, user-supplied details, request context and necessary technical identifiers are transmitted through Coinsider infrastructure to Google Cloud/Gemini. The purpose is limited to the requested feature, security and diagnostics. Under the applicable paid API terms, prompts and responses are not used to improve Google products; Coinsider does not train its own models on them without a separate opt-in.
6. Providers and recipients
The principal AI provider is Google Gemini within Google Cloud; Google Cloud Vision and infrastructure may support image analysis. Base44 provides the application platform and hosting. Apple provides StoreKit, App Store billing and applicable authentication services. No push provider is active in release V1. A future push feature requires a separate product, privacy and vendor review before activation. Providers act under applicable contracts. Transfers outside the EEA or UK must rely on adequacy decisions or appropriate safeguards such as standard contractual clauses, the UK Addendum or IDTA, plus any required transfer assessment—not on “consent by use.”
| Provider | Scope and role | Location / transfer | Key terms |
|---|---|---|---|
| Base44 / Wix group | Platform, hosting, authentication, database, functions and storage; processor. | Production: United States; DPA, DPF/adequacy and SCCs. | TLS, encryption at rest, access controls; deleted records recoverable for up to 30 days. |
| Google Cloud / Gemini API | QC, identification, PRO reports, image search and infrastructure; processor/AI service provider. | Core infrastructure europe-west1; other locations under Cloud DPA/SCCs. | Paid API no use of prompts/responses to improve products; no File API or durable Gemini profile. |
| Apple | App Store, StoreKit, refunds, storefront and optional Sign in with Apple; activity-specific role. | Under Apple terms. | Coinsider receives minimal transaction/entitlement identifiers, including a pseudonymous appAccountToken that binds the subscription to one account; account deletion does not cancel a subscription. |
| OneSignal — historical erasure only | No V1 SDK or new notifications; only deletion of a historical identifier. | No new operational transfers. | After erasure it is not a provider of the active release. |
7. International transfers
Base44 hosts production application data in the United States. The Base44 DPA provides applicable adequacy and Data Privacy Framework mechanisms and Standard Contractual Clauses. Configured Google infrastructure operates in europe-west1; other support and subprocessing locations are governed by the Google Cloud DPA and SCCs. Information about safeguards may be requested at biuro@strefaczysta.pl.
8. Retention and account deletion
Active account and coin content is kept until deletion. Immediate deletion starts after verified reauthentication; scheduled deletion provides a 30-day restoration window, while public records are withdrawn immediately. Base44 may retain deleted records in its recovery cycle for up to 30 days. Ordinary support is kept for 24 months after closure; consumer/account/AI disputes and legal claims, legal-text acceptance and deletion evidence for 6 years; moderation evidence for 12 months with a 6-month in-app appeal; security and fraud logs for 12 months. Apple/tax/ledger evidence is de-identified at account deletion and kept through 31 December of the sixth calendar year after the transaction year. A documented court, regulator, tax, claim, security or fraud hold pauses deletion only for the affected class and is reviewed at least every 90 days. Deletion does not cancel an Apple subscription.
9. Rights, complaints and contact
Subject to applicable law, users may request access, correction, deletion, restriction, portability and objection, and may withdraw a specific consent. EEA users may complain to their local supervisory authority or Poland’s UODO; UK users may complain to the ICO. California residents may exercise applicable rights to know, delete, correct and non-discrimination; Coinsider does not sell or share data for cross-context behavioural advertising. Requests: biuro@strefaczysta.pl. Support: coinssupportpl@wp.pl.
10. AI and automated decision-making
Identification and valuation results are probabilistic and informational. Coinsider does not use them to make solely automated decisions producing legal or similarly significant effects on the user. A paid user can report an AI error for human review.
11. Local data, security and minors
The web and app store necessary session state, language, settings and acknowledgement versions locally. We use no advertising SDK, ATT or behavioural-advertising cookies. Measures include transport encryption, access control, minimisation, operation logging and incident procedures. No system can guarantee absolute security. The service is only for persons aged 18 or over.
12. Changes and contact
Material changes are published with a new date and version. If a new purpose requires consent, we ask before processing starts. Data requests: biuro@strefaczysta.pl. Complaints may be made to the competent authority, including Poland’s UODO or the UK ICO.
Account deletion