Doubloon Privacy Policy
Effective: 8 October 2026 Contact: support@getdoubloon.app
Who we are
Data Controller
Geometry Lab L.L.C-FZ, Licence No. 2651608.01, Meydan Grandstand, 6th floor, Meydan Road, Nad Al Sheba, Dubai, United Arab Emirates.
EU Representative (Art 27 GDPR)
Prighter EU Rep GmbH, Schellinggasse 3/10, 1010 Vienna, Austria.
UK Representative (Art 27 UK GDPR)
Prighter Ltd, 20 Mortlake High Street, London, SW14 8JN, United Kingdom.
You can exercise privacy rights through the Prighter rights portal, by emailing support@getdoubloon.app, or by contacting privacy@geometryapps.com. The Geometry app directory is at geometryapps.com.
The short version
Doubloon values coins, bullion and gold or silver jewelry. Your vault is stored on your iPhone and works without an account. When you scan an item, the photos are sent to our server and an AI provider to identify it; scan photos are processed in memory and not stored. If you sign in, your vault, its photos and your alert settings are stored in your account so they sync across your devices.
Doubloon does not show advertising, does not use the advertising identifier (IDFA), does not track you across other companies' apps or websites, and does not sell or share personal information for advertising.
Information stored on your iPhone
Doubloon stores these records in the app's private storage on your device:
- vault items: the coin, bullion product or jewelry piece, quantity, condition, optional purchase price, notes, photos you keep with the item, and the values shown when you saved it;
- your alert rules and app settings, including your onboarding answers;
- the most recent metal prices, so values display offline;
- a random installation identifier kept in the iOS Keychain, used to count free scans on this device (it remains after the app is deleted and reinstalled);
- your analytics choice.
Doubloon asks for camera access to take scan photos. It does not request access to your photo library, contacts, location, microphone, health data or advertising identifier.
Scanning and identification
When you scan a coin, a bullion product or a jewelry hallmark, the app resizes each photo on your iPhone and saves it as a new JPEG without the camera's metadata, then sends up to two photos to Doubloon's server at api.getdoubloon.app. The server resizes them again in memory and sends them to an AI model to read the item. The primary model is provided by OpenAI, with OpenAI's response storage turned off; when it is unavailable, a model hosted by Cloudflare Workers AI is used. The provider receives the photos and the type of scan, not your name, email address or account identifier. Doubloon does not store scan photos after the identification response is returned.
Each scan request carries security data that protects the free allowance and the service from abuse: an Apple App Attest assertion, the installation identifier, your account token when you are signed in, and, when you are signed out, the anonymous purchase identifier described under Subscriptions. The server keeps a count of free scans per device and per account.
For jewelry, you may also send the weight you entered so the server can return the metal value.
Collector estimates
When a Doubloon Pro member asks for a collector estimate, the server sends the coin's identity (type, year, mint mark, variety and condition) to an AI research step that searches the public web for recent sales, listings and price guides. No photo, name, email or account identifier is included. Results are cached for 7 days per coin identity and condition and are shared by every member who asks about the same coin. Each estimate lists the web pages it was built from.
The "See sold listings" button opens eBay's website in your browser. eBay's own privacy policy applies to that visit.
Metal prices
Gold, silver, platinum and palladium prices are fetched by our server from a market data provider (gold-api.com or metalpriceapi.com). No information about you is sent to obtain prices.
Optional account and sync
You can use Doubloon without an account. If you sign in with Apple, Google or an email code, we process the provider's account identifier, your Doubloon account identifier, your email address when the provider supplies it, and the security records needed to keep the session safe. Accounts are never merged because two sign-ins share an email address. You can add or remove sign-in methods in Settings, as long as one remains.
When you are signed in, these records are stored in your account on Cloudflare so they appear on your other devices: vault items and the photos you keep with them, alert rules, app settings, and a daily history of your vault's total value. Vault photos have metadata removed and are stored in account-scoped storage. To deliver the daily summary and price alerts, the app registers your device's push token, time zone, locale, app version and notification setting with the server; signing out removes that registration.
Email sign-in codes are delivered by Resend.
Notifications
If you allow notifications, Doubloon Pro can send a daily vault summary and the price alerts you set. These are sent by our server through Apple Push Notification service and contain your vault's total and change or the metal price that crossed your threshold. A trial reminder, when shown, is scheduled on your iPhone.
Subscriptions
Apple processes payment for Doubloon Pro. RevenueCat receives App Store transaction and entitlement information tied to an anonymous RevenueCat identifier so Doubloon can unlock and restore Pro. When you sign in, that identifier is linked to your Doubloon account. Geometry does not receive your payment card number or Apple Account password.
Product analytics and diagnostics
The app contains no analytics or advertising SDK such as PostHog, Firebase, Amplitude, Mixpanel, Segment or an attribution SDK. It sends fixed, content-free events with iOS URLSession to our own relay at e.getdoubloon.app, which forwards them to PostHog Cloud EU. Events describe screens viewed and actions taken, with fixed values only. They never contain photos, vault items, values, notes, email addresses or account identifiers.
The app decides on the device before any product event leaves:
- In Germany and Austria, and on devices whose region is unavailable, no product analytics are sent unless you choose Allow.
- In other regions, product analytics start on and can be turned off in Settings > Privacy & Data. Turning analytics off stops product events and removes the stored analytics identifier.
The relay then applies one of two branches:
- For the EEA, the United Kingdom, Switzerland and unknown regions, each event gets a new random identifier, no IP address or country is forwarded, and no person profile is created, so events cannot be linked to each other.
- For other countries, the app creates a random app-scoped identifier after the relay confirms this branch. It is not your name, email, account identifier or IDFA.
Crash and performance reports from Apple MetricKit (crash, hang and resource-exception counts with app and iOS versions) are always sent and carry no analytics identifier. When an action fails, the app can send a fixed failure record (screen, action, error code, app and iOS version, whether you were signed in) with no free text or identifiers.
Why we process information
- To provide the service you ask for: scanning, valuation, accounts, sync, notifications, subscriptions, support, export and deletion.
- With your consent, for product analytics where the app asks first.
- For our legitimate interests in security, abuse prevention, free-allowance enforcement, service stability and content-free analytics and diagnostics, balanced against your rights.
- To meet legal obligations.
Service providers and international transfers
Doubloon uses Cloudflare (servers, database, photo storage, backups, analytics relay, website, email routing and fallback AI identification), OpenAI (primary identification and estimate research), PostHog Cloud EU (product analytics and diagnostics), Apple (App Store purchases, Sign in with Apple, App Attest, push notifications and MetricKit), Google (optional sign-in), RevenueCat (subscriptions), Resend (sign-in codes), gold-api.com or metalpriceapi.com (metal prices, no personal data) and Slack (internal support and operational notifications).
Processing may take place in the European Union, the United Kingdom, Switzerland, the United Arab Emirates, the United States and the other locations listed in each provider's subprocessor notice. Where European or UK transfer rules apply, transfers rely on the providers' Standard Contractual Clauses or UK transfer terms, together with data minimization, encryption in transit and access controls.
Retention
- Vault records on your iPhone remain until you delete them or remove the app.
- Scan photos are not stored after identification.
- Synced records and photos remain while your account exists.
- Collector estimates are cached for 7 days and contain no personal data.
- Email sign-in codes expire after 10 minutes.
- Daily operational backups of the account database are kept for about 35 days.
- Pseudonymous analytics follow the PostHog project's retention settings; aggregate events cannot be linked to you.
- Store and RevenueCat purchase records follow Apple's and RevenueCat's retention obligations.
Deleting your data
- On your iPhone: delete a vault item, use Settings > Privacy & Data > Delete All Data on This iPhone, or remove the app.
- Your account: Settings > Account > Delete Account permanently deletes your account, synced vault items, photos, alert rules, device registrations, value history and the account's free-scan count, and revokes Sign in with Apple access when it was used. The free-scan count kept for each device is not linked to your account and remains, so reinstalling does not reset the free allowance. Backups containing the account expire within about 35 days.
- Without the app: email support@getdoubloon.app from your account email with the subject "Delete my Doubloon account". We verify ownership before deleting. Instructions are also at getdoubloon.app/support.
Deleting your account does not cancel Doubloon Pro. Cancel the subscription in your Apple Account settings.
Your choices and rights
Settings provides CSV export of your vault, account export, analytics opt-out, sign-in method management, sign-out and account deletion. Depending on where you live, you may have the right to access, correct, delete, restrict or port your data, to object to processing, to withdraw consent and to complain to a data-protection authority. Use the Prighter rights portal or email support@getdoubloon.app. We verify requests before disclosing or deleting account data.
Doubloon does not sell personal information or share it for cross-context behavioral advertising.
Children
Doubloon is intended for adults and is not offered to anyone under 18.
Security
Doubloon uses TLS for every connection, account-scoped authorization, Apple App Attest for scan and account requests, request and spending limits, metadata removal from photos, and encrypted or hashed credentials. No security measure removes all risk.
Changes to this policy
We update this policy when our processing, providers or the law changes. The effective date above identifies the current version.
Contact
- Support and privacy: support@getdoubloon.app
- Data-protection enquiries: privacy@geometryapps.com
- Rights portal: app.prighter.com/portal/geometry