1. Scope and data controller
This Policy applies to the PicPrice iOS app, PicPrice API, account and history synchronization, and this public Policy page. It does not control independent websites shown in public market-search results or services you choose through Apple's share sheet.
The data controller is PicPrice, operated by the developer identified by the public GitHub account thepiguy1234.
For private account export and deletion requests, use Settings > Account & Data in PicPrice. For other privacy questions, use the contact information in Section 17. Do not send passwords, verification codes, API keys, financial details, or unnecessary personal photographs in a privacy request.
2. Information PicPrice processes
| Category | Examples | Main purposes |
|---|---|---|
| Account and authentication | Email address; internal account ID; Sign in with Apple identifier and encrypted refresh token; hashed sessions; sign-in times | Create and secure accounts, sign users in, synchronize data, and support deletion or revocation |
| Email verification | Email address, one-time code email, hashed code, expiry, and failed-attempt count | Confirm email ownership and protect accounts |
| Item photographs | One to six selected or camera photographs; one compressed reference image used during visual market research | Identify the item, assess visible condition, reject visibly different matches, and improve pricing relevance |
| Item and user content | Name, category, brand, model, condition, release year, accessories, notes, listing title, and description | Provide identification, pricing, listing assistance, and saved history |
| Pricing and sale details | Currency, estimate, source links, launch MSRP, optional amount paid or asking price, sold status, and actual sale price | Provide buy/sell guidance, possible-profit calculations, and history. PicPrice does not process payment for an item sale |
| Subscriptions and usage | Plan, Apple product and transaction identifiers, status, expiry, and monthly successful-scan count | Verify entitlements, apply allowances, restore purchases, and prevent abuse |
| Guest trial | Random device identifier; one-way SHA-256 hash, trial status, and short-lived scan-pass hash | Offer and enforce guest access without an account or cloud history |
| Device-local information | Original saved photos, local history, cached profile, preferences, and iOS Keychain credentials | Operate the app, display saved results, and keep users signed in |
| Technical and security | Request ID, transient IP address for rate limits, timing, status, AI token counts, and limited diagnostics | Deliver, diagnose, secure, rate-limit, and manage the service |
| Public market information | Public listing title, price, currency, condition, marketplace, URL, and launch-price source | Calculate and explain market estimates |
PicPrice does not ask for contacts, precise location, health information, government identifiers, or advertising identifiers. Avoid including people, addresses, documents, screens, labels, or background details containing personal or confidential information unless needed to identify the item.
3. How PicPrice uses photographs and AI
When you request an appraisal:
- The iPhone prepares the selected photographs and uploads them over an encrypted connection to PicPrice's backend.
- PicPrice validates the files and sends them to OpenAI's API for item identification and visible-condition assessment.
- For market research, PicPrice sends reviewed item details and one reduced-size reference photograph to OpenAI. OpenAI may use web text and image search to compare public listings and find the original launch price.
- PicPrice returns structured item and pricing results. AI-generated information can be inaccurate, so review the identity, condition, sources, and estimate before relying on it.
PicPrice sets store: false on OpenAI API requests. OpenAI states that API
data is not used to train its models unless the API customer opts in. Under OpenAI's
default controls, inputs and outputs may still be retained for up to 30 days in
abuse-monitoring logs unless different controls apply or longer retention is legally
required. Images may also be scanned for child-safety enforcement. See
OpenAI's API data controls
and OpenAI's Privacy Policy.
PicPrice does not intentionally include account email, account ID, optional amount paid, or seller asking price in market-search prompts. Free-form notes and visible photograph contents are sent, so do not include unrelated personal information.
AI results are not used for legal, employment, credit, housing, insurance, educational, or similarly significant decisions. Prices are informational estimates, not guarantees, professional appraisals, or offers to buy or sell.
4. How information is used
PicPrice uses information to:
- provide identification, condition observations, market research, estimates, and listing assistance;
- create and authenticate accounts and synchronize text-based saved history;
- provide guest access and enforce account, trial, rate, and subscription limits;
- verify Apple subscriptions and restore entitlements;
- respond to export, deletion, support, privacy, and security requests;
- maintain, troubleshoot, secure, and improve service reliability;
- detect fraud, misuse, unauthorized access, and violations of law or service rules; and
- comply with legal obligations and protect users, PicPrice, and others.
PicPrice does not use item photographs or account data for third-party advertising, cross-app tracking, data-broker products, or biometric identification.
5. Service providers and disclosures
PicPrice discloses limited information only as needed to operate the service.
| Recipient | Information involved | Purpose |
|---|---|---|
| OpenAI | Item photos, reduced reference photo, item details, condition, release information, notes, and generated search queries | AI identification, condition assessment, structured output, and public web text/image research |
| Railway and Railway-hosted PostgreSQL | Account records, text-only history, plan and usage records, guest hash/status, request data, and limited operational logs | API and database hosting, networking, backup, security, and diagnostics |
| Resend | Email address, verification email contents, and delivery metadata | Deliver passwordless sign-in codes |
| Apple | Apple authentication identifiers and App Store product, transaction, subscription, and account-token information | Authenticate users, verify and restore purchases, process billing, and revoke Apple sign-in during deletion |
| Public web sources | Product-focused search queries generated from item details and image analysis | Find comparable listings, public prices, specifications, and launch MSRP |
Providers process information under their own terms and privacy notices. PicPrice may also disclose information when reasonably necessary to comply with law, valid legal process, safety obligations, rights protection, abuse investigations, or a business reorganization. A successor must use the information consistently with this Policy unless users receive notice and another lawful basis applies.
6. What is stored locally and in the cloud
On the iPhone
Original item photographs and the device's copy of saved results are stored locally using Apple app-storage technologies. Credentials and the guest identifier are stored in iOS Keychain. Apple controls iCloud device backups and other device-level backup behavior selected by the user.
When a guest leaves the result flow, PicPrice removes guest result photos from the app's result object and does not add the result to cloud history. Operating-system or device backups may behave according to Apple's settings and policies.
In PicPrice cloud systems
For signed-in users, PicPrice stores account, plan, scan allowance/usage, and text-based saved history. Cloud history does not contain original item-photo bytes. It can contain details derived from photos, public source URLs, notes, listing text, optional cost or asking price, and sale outcome.
Uploaded photos are processed in server memory and are not deliberately written to PicPrice's PostgreSQL database or application logs. A short-lived pricing cache stores an estimate and non-reversible request fingerprint for up to 30 minutes; it does not store the reference photo.
7. Retention
PicPrice keeps information only as reasonably needed for the purposes described here.
| Information | Typical retention |
|---|---|
| Original uploads on PicPrice servers | In memory for the appraisal; not deliberately persisted in cloud history or application logs |
| OpenAI API inputs and outputs | Subject to OpenAI controls; default abuse-monitoring logs may be retained up to 30 days, with limited legal and safety exceptions |
| Locally saved photos and results | Until the result, account, local app data, or app is removed, subject to Apple backup behavior |
| Account and text-based cloud history | While active, until individual records or the account are deleted |
| Email verification code hash | Code is valid for 10 minutes and removed when used, replaced, cleared, cleaned up, or the account is deleted |
| Sessions | Access session about 1 hour; refresh session about 30 days; earlier on sign-out or deletion |
| Identification-to-pricing scan pass | Up to 24 hours, then invalid |
| Guest-trial hash and status | Retained to remember use of the guest trial; not linked to email or cloud history |
| Subscription and usage record | As needed to provide the plan, enforce limits, resolve purchases, meet legal obligations, or until permitted account deletion |
| Deletion tombstones | While the account exists and as needed to prevent deleted records returning from another device |
| Operational logs | Generally for the hosting provider's current log-retention period; longer only for security, abuse prevention, or legal obligations |
| Pending Apple-token revocation | Until Apple revocation succeeds and final account deletion completes |
Deletion from active systems may not immediately remove encrypted backups, provider security logs, or legally required records. Those copies remain protected, are not restored for ordinary use, and expire under applicable retention schedules.
8. Account export, deletion, and choices
Signed-in users can open Settings > Account & Data to:
- export account information and cloud history as machine-readable JSON;
- sign out and invalidate the active PicPrice session; and
- initiate permanent account deletion.
Account deletion removes sessions, saved cloud history, deletion tombstones, scan usage, and subscription records from active PicPrice systems. For Sign in with Apple, PicPrice also asks Apple to revoke authorization. If Apple is unavailable, PicPrice removes active user data, blocks sign-in, and keeps only the encrypted token and state needed to retry revocation before deleting the final record.
Deleting one result removes its cloud record and creates a marker so it does not return from another device. Local photos must also be deleted from devices on which they were saved, although normal history synchronization performs that cleanup where possible.
Guest access avoids cloud history but still requires temporary photo/AI processing and stores the guest-trial hash. Camera and photo access can be changed in iOS Settings. Without a submitted photo, AI identification and live visual pricing do not work.
9. Legal bases for EEA and UK users
Where EEA or UK data-protection law applies, PicPrice relies on:
- Performance of a contract: account creation, authentication, subscriptions, requested scans, pricing, synchronization, export, and deletion.
- Consent: selected photo access and user-initiated photo and item-content disclosure to third-party AI processing where consent is required. Consent can be withdrawn for future processing by not submitting photos and changing iOS permissions.
- Legitimate interests: service security, fraud and abuse prevention, rate limiting, reliability, cost control, and limited diagnostics, balanced against user rights.
- Legal obligation: records or disclosures required by applicable tax, accounting, consumer, privacy, law-enforcement, or other law.
Information is generally required to provide the requested feature. Without required account or photo information, PicPrice may be unable to create an account, verify a plan, identify an item, or provide a live appraisal.
10. Privacy rights
Depending on location and applicable law, users may have rights to:
- know whether and how personal information is processed;
- access, correct, delete, or receive a portable copy of information;
- restrict or object to certain processing;
- withdraw consent for future processing;
- appeal or complain about a privacy decision; and
- lodge a complaint with a local data-protection authority.
In-app export and deletion are the fastest methods for account access, portability, and deletion. PicPrice may verify a request by asking the requester to sign in or confirm control of the relevant account. PicPrice responds within periods required by law and does not discriminate against users for exercising privacy rights. Legal exceptions may apply, including fraud prevention, another person's rights, legal claims, and compliance obligations.
11. California privacy notice
To the extent the California Consumer Privacy Act, as amended by the California Privacy Rights Act, applies, Section 2 describes categories collected in the preceding 12 months, sources, and purposes. They may correspond to identifiers, customer records, commercial information, internet or electronic-network activity, audio/visual information, user content, and item-related inferences.
PicPrice may disclose these categories to providers in Section 5 for business purposes. PicPrice does not sell personal information, share it for cross-context behavioral advertising, or use sensitive personal information for purposes requiring a right to limit. It has no actual knowledge that it sells or shares information of users under 16 and offers no financial incentive in exchange for personal information.
California residents may request access, categories, correction, deletion, and portability and exercise applicable opt-out or limitation rights. Because PicPrice does not sell or share personal information for cross-context behavioral advertising, it does not provide a "Do Not Sell or Share" control. Legally valid browser opt-out signals will be honored if practices later change in a way that requires them.
12. International processing
PicPrice and providers may process information in the United States, Canada, Europe, or other countries where they operate. Those countries may have different privacy laws. Where required, PicPrice takes steps intended to use an applicable transfer mechanism and contractual or organizational safeguards. Users may contact PicPrice for more information about relevant transfer safeguards.
13. Security
PicPrice uses safeguards designed for the information processed, including encrypted HTTPS transport, iOS Keychain storage, hashed session and scan tokens, encrypted Apple refresh tokens, provider access controls, request-size validation, rate limits, short session lifetimes, and separation of app credentials from backend secrets.
No transmission or storage method is completely secure. Users should protect their device, email and Apple accounts, and verification codes and promptly report suspected unauthorized access.
14. Children
PicPrice is a general resale tool and is not directed to children under 13. Children must not create an account or submit personal information without parent or guardian permission where law requires it. PicPrice does not knowingly collect a child's personal information in violation of applicable law. A parent or guardian who believes that happened should contact PicPrice so it can investigate and delete the information.
15. Third-party links and sharing
PicPrice displays links to public marketplaces, retailers, manufacturers, and publications. Those sites independently determine their privacy practices, and PicPrice is not responsible for their content or privacy practices.
When a user selects Share, Apple presents the system share sheet. The user chooses the receiving app or person. That destination's privacy practices govern information shared through it.
16. Changes to this Policy
PicPrice may update this Policy when features, providers, laws, or data practices change. The updated version will show a new "Last updated" date at this same public URL. PicPrice will provide additional in-app notice or request consent before a material change where required by law.
17. Contact
For private, account-specific requests, use Settings > Account & Data in PicPrice to export data or initiate permanent deletion after signing in.
For other privacy questions, contact PicPrice Privacy through the developer's public GitHub profile: github.com/thepiguy1234.
Do not post personal information, verification codes, photographs, or account credentials in a public GitHub issue.