Privacy Policy
Effective: August 11, 2026
This Privacy Policy applies to the Rock Identifier mobile applications and website (together, the “Service”) provided by Glipo (“we,” “us,” or the “Service Provider”). It explains the information processed when you identify a rock, mineral, crystal, or possible fossil, use the web companion, create an account, manage Premium access, or contact us.
Information We Process
Depending on the feature you use, we may process:
- Specimen photos that you intentionally capture or select for a requested visual analysis.
- Analysis and usage metadata, such as feature type, locale, model category, confidence, normalized result status, timing, error code, quota funding source, and request identifiers. We do not place uploaded photo bytes in analytics events.
- Web account data, including email address, authentication records, sessions, project membership, and account-security events.
- Subscription and entitlement data, including purchase source, product or plan mapping, status, expiry, renewal state, and provider verification time. Full payment-card details remain with the payment provider.
- Pseudonymous identifiers. A web visitor receives an HTTP-only random browser identifier used for guest quota and abuse prevention. It is hashed before it reaches the shared usage database. We also derive a separate keyed hash from a coarse network prefix and broad client family to limit rotated guest identifiers; this control does not send the raw IP address or full user agent to the shared usage database. Infrastructure may still process network data in security logs. Mobile providers may use a random, non-personal customer identifier for mobile access.
- Product analytics and diagnostics, such as page or feature navigation, coarse interaction labels, app/browser version, device category, failures, and performance. Private form values, email, billing identifiers, tokens, and photo contents are excluded from the web analytics collector.
- Contact information and messages that you choose to send to support.
The Service does not request precise device location for identification.
Photo and AI Processing
When you request an identification, the selected image is sent over an encrypted connection to the Rock Identifier backend, then through the shared Glipo Platform and a protected AI Gateway to the configured model provider. The prompt and model choice are controlled by the server. The web browser never receives provider credentials, Platform service keys, or Gateway tokens.
Web photos are processed for the requested result and are not stored in the Rock Identifier landing-site database. Glipo may retain content-free usage, security, billing, and diagnostic records. Infrastructure and model providers may process transient copies and technical logs under their applicable security, abuse-prevention, and retention terms. We do not intentionally use submitted photos to train Glipo-owned AI models, and we do not operate routine human review of web specimen photos. A photo may be reviewed only if you separately submit it for support or if limited review is reasonably required to investigate abuse, security, or a legal obligation.
AI results are probabilistic visual assessments. They may be incomplete or wrong and are not laboratory confirmation, professional geological advice, safety certification, environmental guidance, provenance, age determination, or monetary appraisal.
In the mobile app, like/dislike feedback sends text and limited result metadata; it does not attach or upload the specimen photo.
Authentication, Billing, and Service Providers
We use service providers only for the functions needed to operate the Service:
- the self-hosted Glipo Platform and PostgreSQL infrastructure for account, quota, entitlement, usage, and deletion lifecycle;
- Google or Apple authentication when those providers are enabled;
- Google AI/Gemini through the protected Glipo AI Gateway for configured production analysis;
- Adapty for eligible mobile-app subscription entitlement; Rock web Premium is currently verified directly through Paddle and is not linked to mobile access;
- Apple StoreKit and Google Play Billing for purchases made in their stores;
- Paddle as merchant of record for web checkout, taxes, invoices, and billing;
- Arislytic for privacy-limited product analytics, diagnostics, contact, and published blog delivery;
- Google Analytics for aggregate website measurement when it is configured;
- Apple App Attest and Firebase App Check/Play Integrity for mobile request protection.
Relevant provider policies include Apple Privacy, Google Privacy, Adapty Privacy, and Paddle Privacy.
We do not sell personal data. We may disclose information when required by law, to protect users and the Service, investigate fraud or abuse, or to processors acting under appropriate contractual and security obligations.
Local Storage and Retention
Mobile identification history, saved collection entries, and preferences are primarily stored on your device. You can remove saved entries in the app or remove local data by deleting the app.
Server-side account, entitlement, transaction-linkage, usage, security, and diagnostic records are kept only as long as reasonably needed to provide the Service, maintain quota and billing integrity, prevent abuse, meet accounting or legal duties, resolve disputes, and enforce agreements. Records that must be retained may be anonymized or detached from your account where appropriate.
Account Deletion
Signed-in web users can request permanent deletion from the account center. We send a short-lived email confirmation and re-check subscription state before deleting. If a Paddle subscription is still renewing, the server attempts to schedule cancellation at the end of the current billing period and continues only after Paddle confirms it. A renewing App Store or Google Play subscription must be canceled in that store first. Unknown or unverifiable provider state blocks deletion so a renewing subscription is not orphaned.
Confirmed deletion removes or anonymizes the shared Glipo web account, sessions, project memberships across connected companion products, billing mappings, linked product data, and eligible AI records under the applicable retention rules. Deleting a web account does not itself erase records that Apple, Google, Paddle, or Adapty must retain under their own legal obligations.
Your Choices and Rights
You choose which photos to submit, whether to create an account, and whether to send feedback. You can sign out, revoke other sessions, manage a subscription through its purchase source, or stop mobile collection by uninstalling the app.
Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or port applicable personal data. We may request limited information to verify a rights request.
Children, Security, and Changes
The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13. Contact us if you believe a child has provided personal information.
We use reasonable technical and organizational safeguards, including encrypted transport, server-side secrets, first-party secure sessions, scoped service authorization, and content-free analytics boundaries. No system can be guaranteed completely secure.
We may update this Policy as the Service, providers, or legal requirements change. The effective date above identifies the current version.
Contact
For privacy questions or rights requests, email support@glipo.com.tr.