PicPrice Privacy Policy

Your data, explained clearly

Privacy Policy

This Policy explains how the PicPrice iOS app and PicPrice-operated backend services process information when you identify, research, price, and save resale items.

Effective: August 3, 2026 Last updated: August 3, 2026

1. Scope and data controller

This Policy applies to the PicPrice iOS app, PicPrice API, account and history synchronization, and this public Policy page. It does not control independent websites shown in public market-search results or services you choose through Apple's share sheet.

The data controller is PicPrice, operated by the developer identified by the public GitHub account thepiguy1234.

For private account export and deletion requests, use Settings > Account & Data in PicPrice. For other privacy questions, use the contact information in Section 17. Do not send passwords, verification codes, API keys, financial details, or unnecessary personal photographs in a privacy request.

2. Information PicPrice processes

Category Examples Main purposes
Account and authentication Email address; internal account ID; Sign in with Apple identifier and encrypted refresh token; hashed sessions; sign-in times Create and secure accounts, sign users in, synchronize data, and support deletion or revocation
Email verification Email address, one-time code email, hashed code, expiry, and failed-attempt count Confirm email ownership and protect accounts
Item photographs One to six selected or camera photographs; one compressed reference image used during visual market research Identify the item, assess visible condition, reject visibly different matches, and improve pricing relevance
Item and user content Name, category, brand, model, condition, release year, accessories, notes, listing title, and description Provide identification, pricing, listing assistance, and saved history
Pricing and sale details Currency, estimate, source links, launch MSRP, optional amount paid or asking price, sold status, and actual sale price Provide buy/sell guidance, possible-profit calculations, and history. PicPrice does not process payment for an item sale
Subscriptions and usage Plan, Apple product and transaction identifiers, status, expiry, and monthly successful-scan count Verify entitlements, apply allowances, restore purchases, and prevent abuse
Guest trial Random device identifier; one-way SHA-256 hash, trial status, and short-lived scan-pass hash Offer and enforce guest access without an account or cloud history
Device-local information Original saved photos, local history, cached profile, preferences, and iOS Keychain credentials Operate the app, display saved results, and keep users signed in
Technical and security Request ID, transient IP address for rate limits, timing, status, AI token counts, and limited diagnostics Deliver, diagnose, secure, rate-limit, and manage the service
Public market information Public listing title, price, currency, condition, marketplace, URL, and launch-price source Calculate and explain market estimates

PicPrice does not ask for contacts, precise location, health information, government identifiers, or advertising identifiers. Avoid including people, addresses, documents, screens, labels, or background details containing personal or confidential information unless needed to identify the item.

3. How PicPrice uses photographs and AI

When you request an appraisal:

  1. The iPhone prepares the selected photographs and uploads them over an encrypted connection to PicPrice's backend.
  2. PicPrice validates the files and sends them to OpenAI's API for item identification and visible-condition assessment.
  3. For market research, PicPrice sends reviewed item details and one reduced-size reference photograph to OpenAI. OpenAI may use web text and image search to compare public listings and find the original launch price.
  4. PicPrice returns structured item and pricing results. AI-generated information can be inaccurate, so review the identity, condition, sources, and estimate before relying on it.

PicPrice sets store: false on OpenAI API requests. OpenAI states that API data is not used to train its models unless the API customer opts in. Under OpenAI's default controls, inputs and outputs may still be retained for up to 30 days in abuse-monitoring logs unless different controls apply or longer retention is legally required. Images may also be scanned for child-safety enforcement. See OpenAI's API data controls and OpenAI's Privacy Policy.

PicPrice does not intentionally include account email, account ID, optional amount paid, or seller asking price in market-search prompts. Free-form notes and visible photograph contents are sent, so do not include unrelated personal information.

AI results are not used for legal, employment, credit, housing, insurance, educational, or similarly significant decisions. Prices are informational estimates, not guarantees, professional appraisals, or offers to buy or sell.

4. How information is used

PicPrice uses information to:

  • provide identification, condition observations, market research, estimates, and listing assistance;
  • create and authenticate accounts and synchronize text-based saved history;
  • provide guest access and enforce account, trial, rate, and subscription limits;
  • verify Apple subscriptions and restore entitlements;
  • respond to export, deletion, support, privacy, and security requests;
  • maintain, troubleshoot, secure, and improve service reliability;
  • detect fraud, misuse, unauthorized access, and violations of law or service rules; and
  • comply with legal obligations and protect users, PicPrice, and others.

PicPrice does not use item photographs or account data for third-party advertising, cross-app tracking, data-broker products, or biometric identification.

5. Service providers and disclosures

PicPrice discloses limited information only as needed to operate the service.

Recipient Information involved Purpose
OpenAI Item photos, reduced reference photo, item details, condition, release information, notes, and generated search queries AI identification, condition assessment, structured output, and public web text/image research
Railway and Railway-hosted PostgreSQL Account records, text-only history, plan and usage records, guest hash/status, request data, and limited operational logs API and database hosting, networking, backup, security, and diagnostics
Resend Email address, verification email contents, and delivery metadata Deliver passwordless sign-in codes
Apple Apple authentication identifiers and App Store product, transaction, subscription, and account-token information Authenticate users, verify and restore purchases, process billing, and revoke Apple sign-in during deletion
Public web sources Product-focused search queries generated from item details and image analysis Find comparable listings, public prices, specifications, and launch MSRP

Providers process information under their own terms and privacy notices. PicPrice may also disclose information when reasonably necessary to comply with law, valid legal process, safety obligations, rights protection, abuse investigations, or a business reorganization. A successor must use the information consistently with this Policy unless users receive notice and another lawful basis applies.

6. What is stored locally and in the cloud

On the iPhone

Original item photographs and the device's copy of saved results are stored locally using Apple app-storage technologies. Credentials and the guest identifier are stored in iOS Keychain. Apple controls iCloud device backups and other device-level backup behavior selected by the user.

When a guest leaves the result flow, PicPrice removes guest result photos from the app's result object and does not add the result to cloud history. Operating-system or device backups may behave according to Apple's settings and policies.

In PicPrice cloud systems

For signed-in users, PicPrice stores account, plan, scan allowance/usage, and text-based saved history. Cloud history does not contain original item-photo bytes. It can contain details derived from photos, public source URLs, notes, listing text, optional cost or asking price, and sale outcome.

Uploaded photos are processed in server memory and are not deliberately written to PicPrice's PostgreSQL database or application logs. A short-lived pricing cache stores an estimate and non-reversible request fingerprint for up to 30 minutes; it does not store the reference photo.

7. Retention

PicPrice keeps information only as reasonably needed for the purposes described here.

Information Typical retention
Original uploads on PicPrice serversIn memory for the appraisal; not deliberately persisted in cloud history or application logs
OpenAI API inputs and outputsSubject to OpenAI controls; default abuse-monitoring logs may be retained up to 30 days, with limited legal and safety exceptions
Locally saved photos and resultsUntil the result, account, local app data, or app is removed, subject to Apple backup behavior
Account and text-based cloud historyWhile active, until individual records or the account are deleted
Email verification code hashCode is valid for 10 minutes and removed when used, replaced, cleared, cleaned up, or the account is deleted
SessionsAccess session about 1 hour; refresh session about 30 days; earlier on sign-out or deletion
Identification-to-pricing scan passUp to 24 hours, then invalid
Guest-trial hash and statusRetained to remember use of the guest trial; not linked to email or cloud history
Subscription and usage recordAs needed to provide the plan, enforce limits, resolve purchases, meet legal obligations, or until permitted account deletion
Deletion tombstonesWhile the account exists and as needed to prevent deleted records returning from another device
Operational logsGenerally for the hosting provider's current log-retention period; longer only for security, abuse prevention, or legal obligations
Pending Apple-token revocationUntil Apple revocation succeeds and final account deletion completes

Deletion from active systems may not immediately remove encrypted backups, provider security logs, or legally required records. Those copies remain protected, are not restored for ordinary use, and expire under applicable retention schedules.

8. Account export, deletion, and choices

Signed-in users can open Settings > Account & Data to:

  • export account information and cloud history as machine-readable JSON;
  • sign out and invalidate the active PicPrice session; and
  • initiate permanent account deletion.

Account deletion removes sessions, saved cloud history, deletion tombstones, scan usage, and subscription records from active PicPrice systems. For Sign in with Apple, PicPrice also asks Apple to revoke authorization. If Apple is unavailable, PicPrice removes active user data, blocks sign-in, and keeps only the encrypted token and state needed to retry revocation before deleting the final record.

Deleting one result removes its cloud record and creates a marker so it does not return from another device. Local photos must also be deleted from devices on which they were saved, although normal history synchronization performs that cleanup where possible.

Guest access avoids cloud history but still requires temporary photo/AI processing and stores the guest-trial hash. Camera and photo access can be changed in iOS Settings. Without a submitted photo, AI identification and live visual pricing do not work.

10. Privacy rights

Depending on location and applicable law, users may have rights to:

  • know whether and how personal information is processed;
  • access, correct, delete, or receive a portable copy of information;
  • restrict or object to certain processing;
  • withdraw consent for future processing;
  • appeal or complain about a privacy decision; and
  • lodge a complaint with a local data-protection authority.

In-app export and deletion are the fastest methods for account access, portability, and deletion. PicPrice may verify a request by asking the requester to sign in or confirm control of the relevant account. PicPrice responds within periods required by law and does not discriminate against users for exercising privacy rights. Legal exceptions may apply, including fraud prevention, another person's rights, legal claims, and compliance obligations.

11. California privacy notice

To the extent the California Consumer Privacy Act, as amended by the California Privacy Rights Act, applies, Section 2 describes categories collected in the preceding 12 months, sources, and purposes. They may correspond to identifiers, customer records, commercial information, internet or electronic-network activity, audio/visual information, user content, and item-related inferences.

PicPrice may disclose these categories to providers in Section 5 for business purposes. PicPrice does not sell personal information, share it for cross-context behavioral advertising, or use sensitive personal information for purposes requiring a right to limit. It has no actual knowledge that it sells or shares information of users under 16 and offers no financial incentive in exchange for personal information.

California residents may request access, categories, correction, deletion, and portability and exercise applicable opt-out or limitation rights. Because PicPrice does not sell or share personal information for cross-context behavioral advertising, it does not provide a "Do Not Sell or Share" control. Legally valid browser opt-out signals will be honored if practices later change in a way that requires them.

12. International processing

PicPrice and providers may process information in the United States, Canada, Europe, or other countries where they operate. Those countries may have different privacy laws. Where required, PicPrice takes steps intended to use an applicable transfer mechanism and contractual or organizational safeguards. Users may contact PicPrice for more information about relevant transfer safeguards.

13. Security

PicPrice uses safeguards designed for the information processed, including encrypted HTTPS transport, iOS Keychain storage, hashed session and scan tokens, encrypted Apple refresh tokens, provider access controls, request-size validation, rate limits, short session lifetimes, and separation of app credentials from backend secrets.

No transmission or storage method is completely secure. Users should protect their device, email and Apple accounts, and verification codes and promptly report suspected unauthorized access.

14. Children

PicPrice is a general resale tool and is not directed to children under 13. Children must not create an account or submit personal information without parent or guardian permission where law requires it. PicPrice does not knowingly collect a child's personal information in violation of applicable law. A parent or guardian who believes that happened should contact PicPrice so it can investigate and delete the information.

15. Third-party links and sharing

PicPrice displays links to public marketplaces, retailers, manufacturers, and publications. Those sites independently determine their privacy practices, and PicPrice is not responsible for their content or privacy practices.

When a user selects Share, Apple presents the system share sheet. The user chooses the receiving app or person. That destination's privacy practices govern information shared through it.

16. Changes to this Policy

PicPrice may update this Policy when features, providers, laws, or data practices change. The updated version will show a new "Last updated" date at this same public URL. PicPrice will provide additional in-app notice or request consent before a material change where required by law.

17. Contact

For private, account-specific requests, use Settings > Account & Data in PicPrice to export data or initiate permanent deletion after signing in.

For other privacy questions, contact PicPrice Privacy through the developer's public GitHub profile: github.com/thepiguy1234.

Do not post personal information, verification codes, photographs, or account credentials in a public GitHub issue.