Rock Identifier - Privacy

Privacy Policy for Rock Identifier

Effective date: August 10, 2026

This Privacy Policy explains how Rock Identifier ("the app"), developed and published by Furkan Kaya, an independent developer ("we", "us", "the Developer"), handles information when you use the app.

Rock Identifier does not require an account. You never create a username, and we never ask for your name, e-mail address, phone number or date of birth. Almost everything the app knows about you stays on your iPhone. The one thing that leaves your device is the photo you deliberately choose to have identified, and that photo is analysed and discarded — it is never stored by us, never sold, and never used for advertising.

If you do not agree with this Policy, please do not use the app.

1. Information stored only on your device

The following is created by you inside the app and stored in a local database and key–value store on your iPhone. It is not transmitted to us and we cannot read it:

  • Your collection and wishlist entries, including the stone identified, your own photo of it, the place you noted, the date, purchase price and your personal notes.
  • Your scan history.
  • Your preferences: interface language, daily reminder setting, and the interest and experience answers you gave during onboarding.
  • Counters used to apply the daily scanning limit.

This information is removed when you delete the app from your device.

2. Photos you submit for identification

Identification is the only feature that sends information off your device, and it only happens when you actively choose to identify a stone.

What is sent. When you take a photo or pick one from your photo library for identification, the app first resizes and re-encodes the image on your device (maximum 1024 pixels wide, JPEG). Re-encoding removes the embedded photo metadata, so the GPS coordinates, capture time and camera information that iPhone photos normally carry are not transmitted. Only the resulting image, the language code you use the app in, and any optional hint you type yourself are sent.

Where it goes. The image travels over an encrypted (HTTPS) connection to a server operated by the Developer at kayaapps.com.tr. That server forwards it to the Google Gemini API, which analyses the image and returns a text description of the likely stone. The result is then shown to you.

What happens afterwards. The image is held only in memory for the duration of the request. It is not written to disk on our server, not added to any database, not reviewed by a human, and not used to train any model by us. Google processes the image as a data processor on our behalf under the Google APIs Terms of Service and the Gemini API terms applicable to paid API usage, and does not use it to improve its models. Google's handling of the data is described in the Google Privacy Policy.

Please note: the app cannot control what you point the camera at. Do not submit photographs of people, documents, or anything else you do not want processed by an external service.

3. Technical information our server receives

To keep the identification service working and to stop abuse, our server records the following for each request. None of it identifies you personally:

  • An anonymous installation identifier. The first time the app runs, it generates a random identifier and stores it in the iOS Keychain. It is sent with each request so that daily limits and subscription status can be applied to your installation. It is not derived from your device's hardware, contains no personal information, and is regenerated if you delete and reinstall the app.
  • App attestation data. The app uses Apple's App Attest service to prove to our server that the request comes from a genuine, unmodified copy of Rock Identifier. This produces a cryptographic key identifier and signature. It does not identify you or your device to us.
  • A subscription profile identifier supplied by our subscription provider, used to verify that an active subscription exists.
  • Request metadata: timestamp, the feature used, the AI model used, request and response size, processing time, result status, error codes and the interface language.

For a short period after a request, the text result of an identification may be kept in encrypted form so that a retried request does not have to be charged and processed twice. It is automatically erased after that window. The submitted photograph is never part of this.

4. Purchases and subscriptions

Subscriptions are sold by Apple through the App Store. We never see and never receive your payment details. Apple provides us only with the fact that a valid purchase exists.

Subscription state is managed with Adapty, a subscription infrastructure provider. Adapty processes purchase and transaction information and technical device information in order to tell the app whether your subscription is active. Adapty acts as a data processor for us.

5. Notifications

If you enable the daily reminder, the notification is created and scheduled entirely on your device by iOS. No push server is involved and no notification data reaches us. You can turn reminders off inside the app or in iOS Settings at any time.

6. What we do not do

  • We do not show advertising and we do not work with advertising networks.
  • We do not track you across other apps or websites, and the app does not request App Tracking Transparency permission because it has nothing to track.
  • We do not sell, rent or share your information with data brokers.
  • We do not use third-party analytics or crash-reporting SDKs.
  • We do not collect your precise or approximate location.
  • We do not access your photo library beyond the single image you pick, and we do not scan or index your library.

7. Legal bases for processing (EEA/UK users)

Where the EU or UK General Data Protection Regulation applies, we process the limited data described above on the following bases: performance of a contract (delivering the identification you requested and verifying your subscription) and legitimate interests (preventing abuse of the service, keeping it secure and available). Where we ask for your explicit consent — for camera access, photo library access, notifications, and before your photo is shared with our AI provider — the basis is consent, and you can withdraw it at any time in iOS Settings or by not using the identification feature.

8. Retention

  • Photographs: not retained; held in memory only for the duration of the request.
  • Text results cached for retries: automatically deleted after a short window.
  • Request metadata: retained for up to 24 months for abuse prevention, cost accounting and troubleshooting.
  • Everything in your collection: kept on your device until you delete it or delete the app.

9. International transfers

The Developer is based in the Republic of Türkiye. Our server is located in Germany, and Google may process identification requests in the United States or other countries where it operates. Where required, transfers rely on the European Commission's Standard Contractual Clauses or an equivalent safeguard offered by the relevant provider.

10. Your rights

Depending on where you live, you may have the right to access, correct, delete, restrict or object to the processing of your personal information, to data portability, and to lodge a complaint with your supervisory authority. Residents of California may additionally request disclosure of the categories of personal information collected and may opt out of "sale" or "sharing" — we do neither.

Because Rock Identifier has no accounts, most of your data is only on your device and is deleted with the app. For the limited server-side records described in section 3, write to us at the address below. So that we can locate those records, please contact us from inside the app via Profile → Help & Support: the e-mail it prepares already contains your installation identifier, which is the only way we can find the entries that belong to you. We respond within 30 days.

11. Children

Rock Identifier is a general-audience geology tool. It is not directed at children under 13 (or the equivalent minimum age in your country) and we do not knowingly collect personal information from them. If you believe a child has provided us with personal information, contact us and we will delete it.

12. Security

All communication between the app and our server uses TLS encryption. Requests are authenticated with Apple's App Attest so that only genuine copies of the app can use the service. Secrets on the server are stored encrypted, and access to the server is restricted to the Developer. No system can be guaranteed to be completely secure, but we work to protect the very small amount of data we hold.

13. Changes to this Policy

If we change how the app handles information we will update this page and revise the effective date above. Material changes will also be described in the App Store release notes for the version that introduces them.

14. Contact

Furkan Kaya — independent developer
E-mail: support@furkankaya.com.tr

Yorumlar

Bu blogdaki popüler yayınlar

Migraine Tracker - Privacy

Terms of Use for Migraine Tracker

Peptide Tracker - Privacy Policy