Privacy Policy

Policy Version: 2026-08-31-provider-disclosure
Effective Date: 2026-10-02T00:00:00Z

Mineral Wild LLC ("Mineral Wild," "we," "us," or "our"), a Wyoming limited liability company, operates the Mineral Wild mobile application (the "App") and related websites and services. This Privacy Policy explains how we collect, use, disclose, retain, and safeguard your information when you use the App.

By using the App, you agree to the collection and use of information in accordance with this policy. Where we rely on consent as the legal basis for processing (for example, public-profile visibility), you may withdraw your consent as described in §11.

If you are using the App from outside the United States, your information will be transferred to and processed in the United States. See §12.


1. Information We Collect

1.1 Information You Provide

1.2 Information Collected Automatically

The following automatic collection may occur whether or not you create an account. Guest atlas browsing does not require you to provide account information or User Content, but it is pseudonymous rather than a promise of anonymous or zero data processing.

1.3 Compliance Keyword Scanning of Specimen Notes

We maintain a list of compliance-sensitive keywords (for example: chrysotile, crocidolite, amosite, nephrite, bowenite, uraninite, pitchblende, and terms indicating sanctions evasion or smuggling). We scan the free-text notes field of your specimen records against this list. The scan runs when you create a specimen yourself, when you change its notes, and when you mark a specimen as sold — including when you mark it sold while sending its details to another collector in a message. A specimen you import from another collector's data transfer is scanned the first time you edit its notes or mark it sold, not at the moment of import. It applies to your specimen records whether or not the specimen is marked "available" and whether or not it is publicly visible.

When a keyword matches, we record an audit entry containing the matched keyword, a short excerpt of the surrounding notes text (approximately 20 characters on either side of the match), the identifier of the specimen concerned, and the time of the match, linked to your account. These entries are retained for up to 2 years (see §8.1) for audit and compliance-investigation purposes, as described in Terms of Service §6.4.

This scan covers specimen notes only. It is distinct from the automated filtering applied to direct messages (see §5.1), which uses a separate filter and does not create these compliance keyword entries. A keyword match alone does not restrict a specimen; listing restrictions are applied separately by the server-side compliance rule table described in Terms of Service §6.4.

1.4 Information We Do NOT Collect


2. How We Use Your Information

We use the information we collect to:

We do not use your information for:


3. How We Share Your Information

3.1 Public Features

If you enable public-profile visibility, the following information may be visible to other App users (signed-in or, where permitted, anonymous viewers):

You control the visibility of these features through the App's privacy settings, including two independent toggles:

When show_available is disabled, specimens you have marked available appear only as regular public collection (subject to show_collection), without available-specific signals such as price, contact CTA, save-listing, matching, or fanout. The privacy combination matrix:

show_collection show_available public collection available-specific signals
true true visible visible
true false visible (downgraded — no price / no contact CTA) hidden
false true hidden available-only surfaces visible
false false hidden hidden

Direct contact features (the in-app private message inbox at Messages and reply-from-public-profile contact buttons) are not gated by these visibility toggles; they are governed by your account's overall messaging preferences and the platform-wide IM availability flag.

You control these toggles through the App's privacy settings.

Separately, if a photo of yours has been accepted into the public atlas, the App provides an atlas visibility control. The atlas uses an independent snapshot, so deleting only the original source photo from your specimen does not withdraw the accepted snapshot from public display. Switching the specimen from “Public · Atlas” to “Public Profile,” deleting the whole specimen, or permanently deleting your account withdraws the community atlas listing from new public atlas listings, API results, and reference-image results. An account-deletion request does not withdraw it during the 30-day grace period; withdrawal occurs at permanent deletion if you do not cancel. See §4.2, §8, and §9.

What "taking something down" does and does not do. The visibility toggles above and atlas withdrawal remove content from the App's public surfaces and new public atlas/API/reference-image results. They do not guarantee erasure of every copy: technical atlas copies may remain in storage, a direct media link issued while content was public may keep resolving, device or CDN caches may retain a copy, and copies other people downloaded, saved, or shared are beyond the reach of an in-App control. Deleting only a specimen's original source photo removes that source photo but does not withdraw an already accepted independent atlas snapshot. Deleting the whole specimen or permanently deleting the account both withdraw the public atlas listing, while the residual-copy limits in this paragraph still apply.

3.2 Third-Party Services

Before enabling a third-party service that receives user data, we review the applicable contractual commitments and the service's published privacy terms to confirm that the service provides the same or equal protection of user data as stated in this Privacy Policy and required by the Apple App Review Guidelines.

As of this policy's Effective Date, the external providers that may receive personal data, their roles, and their processing locations are summarized below:

Our Nginx edge and Centrifugo real-time service are self-hosted on Mineral Wild AWS hosts in the United States, and the MaxMind GeoLite2 database is used offline on those hosts. These processing contexts do not add separate third-party recipients.

This summary is a legal and recipient snapshot as of this policy's Effective Date, not an always-current operational inventory. Our Provider Disclosure is the current source for external provider identities, services, data categories, purposes, regions, and applicable conditions. It also lists self-hosted processing contexts and offline suppliers separately.

Apple Maps Platform Service (Not a Mineral Wild Subprocessor)

The App uses Apple MapKit for interactive maps and static map previews. When you view a specimen location on a map or request a preview, the specimen coordinate you selected determines the visible map area requested from Apple's Maps service. Apple states that Maps requests may send the time of the request, device model and software version, input language, the boundaries of the visible map area, interactions with Maps and places viewed, and application, device, network-configuration, and performance data. The App does not enable current-device location access in these map views, and a specimen pin shown over a static preview is composed on your device after the map snapshot is returned.

Apple handles Maps request data under Apple Maps & Privacy to provide and improve Maps and other location-based products and services, rather than as a service provider processing personal data on Mineral Wild's instructions.

When you open Mineral Wild through another user's sharing card and later create an account, we may store the first-party share_token that attributed the referral to that user. This inviter relationship is used only for product attribution and social graph integrity inside Mineral Wild; it is not shared with third-party attribution SDKs and is handled in data export and deletion workflows together with your account data.

3.3 AI Providers (Standalone Voice Input)

Standalone voice input is not active at launch. If introduced, the current provider identities and service conditions will be listed on the Provider Disclosure page; this section will describe the audio processing, and your separate consent will be obtained before that processing begins. Audio tracks contained in direct-message videos are not processed through a voice-input or transcription provider.

We may disclose information:

3.5 No Sale or "Share" of Personal Data

We do not sell, rent, trade, or "share" (as defined by the CCPA/CPRA for cross-context behavioral advertising) your personal information.


4. Photo and Video Storage and Processing

4.1 Your Photos and Videos

Photos and videos you upload (specimen photos, specimen videos, avatar, cover image, mineral-suggestion reference photos, and chat media attachments) are stored in private cloud storage and delivered through a content-delivery network (CDN) using signed URLs for sensitive paths (e.g., chat media). A chat video may contain an audio track; we process and store that track as part of the video. We generate thumbnails and reduced-resolution copies for faster loading and, for videos, extract a cover frame. During processing, we apply server-side metadata filtering to uploaded media. For specimen photos, we remove standard GPS/location fields, camera-owner information, serial numbers, maker notes, and other non-allowlisted EXIF fields. Specimen photos may retain camera make and model, orientation, and date/time metadata, including image-change and original-capture timestamps. Other processed images are re-encoded without EXIF, XMP, IPTC, or comment metadata. Color-profile data may be retained in processed images. Videos are processed to remove standard container metadata before delivery.

4.2 Photo and Video Retention

Except for chat video attachments, which become inaccessible within 90 days of upload and whose underlying versioned storage copies are automatically purged shortly thereafter as described in §5.4, your photos and videos (including audio tracks contained in videos) are retained while your account is active. When you delete a whole specimen, its user-collection photos and videos are removed from our database and origin storage, and any community atlas listing contributed by that specimen is withdrawn from new public atlas listings, API results, and reference-image results. Deleting only an original source photo does not withdraw an already accepted independent atlas snapshot. Technical atlas copies and existing direct-link, cached, offline, or third-party copies may remain after withdrawal. When you permanently delete your account at the end of the 30-day grace period, your specimen, profile, and mineral-suggestion media are deleted from origin storage and corresponding disaster-recovery replicas are cleared within approximately 90 days, subject to the limited retention items in §8. Community atlas listings are withdrawn at that permanent-deletion step; they remain displayed during the grace period unless you separately withdraw the specimen first.

4.3 Sharing Externally

When you use the App's sharing features (e.g., sharing a specimen card to social media, or generating a public short-link), the shared content leaves our platform. Once shared externally, the content is subject to the third-party platform's terms and is beyond our control.


5. Direct Messaging

5.1 Message Content and Moderation

The App provides a direct-messaging feature for one-on-one communication. Message content (text and media) is transmitted through our real-time messaging infrastructure (Centrifugo) and stored on our servers.

We employ automated content filtering on direct messages: text is screened by an automated keyword/pattern filter, while image attachments and cover frames extracted from video attachments pass through Amazon Rekognition for automated moderation. Video audio tracks are not sent to Rekognition. Messages or media that match our filters — including text matching listed CSAM, hate-speech, or other prohibited terms — are blocked from delivery and the attempt is logged. This automated screening is keyword- and image-based; it is not exhaustive or semantic detection of every category of prohibited content. Separately, on obtaining actual knowledge of apparent CSAM, we report it to the NCMEC CyberTipline as required by law (see Terms of Service §6.4). We do not use message content for advertising, profiling, or training machine-learning models.

The same automated image moderation applies to all other user-uploaded media in the App: specimen photos and videos, avatars, profile and collection covers, and mineral-atlas suggestion photos (images and cover frames extracted from videos) pass through Amazon Rekognition before they are published, and media that matches our filters is blocked and never made publicly available. Video audio tracks are not sent to Rekognition for these uploads either. Public free-text fields — specimen names, custom mineral names, collection names, profile location, and bio — are screened by the same automated keyword/pattern filter, as are public usernames and display names. Content blocked by these filters can be deleted and replaced by you; we do not operate a human pre-publication review queue.

5.2 Administrative Access

Our administrative team may access message content in the following limited circumstances:

Administrative access is restricted to authorized personnel and limited to the circumstances described above. Moderation decisions made through our in-App reporting workflow are recorded. We do not proactively monitor private conversations beyond the automated content filtering described above.

5.3 Push Notifications

The App initializes Firebase Cloud Messaging at startup. After you sign in, if a device registration token is available, the App makes a best-effort attempt to register it with Mineral Wild. Token registration can occur independently of whether you have granted operating-system notification permission, and a registration failure does not block your use of the App.

We use Firebase Cloud Messaging as the app-level push provider for Android and iOS. On iOS, Firebase delivers through Apple Push Notification service (APNs) as the operating-system delivery layer. Actual notification delivery depends on your operating-system permission and account notification preferences. Notification preview content is sanitized server-side: we send the message type and a generic preview string rather than the full message body, so that intercepted push payloads do not reveal sensitive chat content. You may disable push notifications at any time through your device settings or account notification preferences.

5.4 Message Retention and Deletion

Messages are retained as long as the conversation exists and at least one participant has not deleted it. When you delete a conversation, your view of the conversation is removed but the other participant may retain their copy. Media attachments (photos and videos, including audio tracks contained in videos) sent in messages are stored on our cloud infrastructure subject to the same retention rules, except that video attachments — including their audio tracks and generated cover frames — become inaccessible within 90 days of upload regardless of conversation state. Underlying noncurrent storage versions are permanently purged shortly thereafter under automated storage-lifecycle controls.

When you delete your account, your platform-managed sender identity is removed from the message records and their content is retained for up to 2 years to preserve conversation context for the other participant. After 2 years, the original content is permanently erased. A minimal anonymized message tombstone — such as message type, timestamp, and conversation linkage, without your sender identity or original content — may remain while the other participant retains the conversation. Media attachments you sent are deleted within 90 days of account deletion.

5.5 Data Portability

While your account remains accessible, you may request a copy of your data, including your current display name and username, username-change history, messages, media, and specimen-data transfers, through the App (Settings → Account → Download My Data). Sent transfers include your own display-name and username snapshots as recorded at send time. Received transfers include the sender's display-name and username snapshots while that sender account remains linked; if the sender has deleted the account, both fields are anonymized in your export to protect the former sender's rights. We will prepare your data as a machine-readable ZIP archive (JSON + CSV + media files + a legal-receipts.json file documenting your accepted Terms / Privacy versions) and email a download link to your verified address, typically within 30 minutes. The link is valid for 7 days; the archive is auto-deleted from our storage 8 days after generation. This self-service path includes the 30-day account-deletion grace period while the account remains accessible. If your account is no longer accessible, contact mineralwild@gmail.com; we will assess the request under §13 and applicable law.


6. Local Device Storage of Compliance and Safety Acknowledgments

Two related categories of one-time acknowledgments are stored locally on your device, never transmitted to our servers:

(a) Compliance advisories. When you mark a specimen is_available and the request matches an advisory rule (such as radioactivity-level warnings, mercury and arsenic health advisories, or asbestos-classification awareness), we record locally that you have acknowledged that specific rule. The stored value is the short code of the acknowledged rule (for example, OFAC_BURMA_AMBER, ADVISORY_RADIOACTIVITY_HIGH) and a timestamp. No personally identifiable information is included.

(b) Contact-safety acknowledgments. When you initiate a private message from the available-specimen contact action for the first time, we record locally that you have acknowledged the contact-safety notice (an account-scoped pseudonymous local key derived from a one-way hash of your account UUID, plus an ISO timestamp). This lets the App suppress the same notice on subsequent sends from the same account on the same device. The stored value contains no readable account identifier and cannot be used to identify you in isolation.

Both categories are stored using local app storage on your device (device preferences, secure key-value storage, depending on platform). Because this storage is device-local, neither category syncs across your devices, and clearing the App's data on your device will reset the acknowledgments and cause the corresponding advisory or notice to appear again the next time the matching condition is met.


7. Data Security

We implement reasonable technical and organizational measures to protect your personal information, including:

No method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security and recommend you use a strong, unique password and enable platform-level account protections (Apple ID 2FA, Google account 2FA) if you sign in via OAuth.


8. Data Retention

We retain each category of personal data only for as long as necessary to operate the App, meet legal obligations, defend legal claims, or enforce our Terms of Service. The Retention Schedule below lists specific retention periods.

8.1 Retention Schedule

Data Category Retention Period Basis
Account data (display name, username and username history, profile, specimens, photos, videos, collections, wishlist, custom tags, follows, blocks, saved listings, and mineral atlas corrections) While your account is active. Permanently deleted within approximately 90 days after the account-deletion grace period ends, subject to the separately listed retained records and residual-copy boundaries. Disaster-recovery replica copies are cleared on the same schedule. Core service provision
Direct messages and specimen-data transfers (text + metadata) While the conversation exists between participants. When both participants delete the conversation, permanently deleted within 90 days. After account deletion, sender identity is removed immediately; this includes replacing both transfer sender-name snapshots with deletion tombstones. Original message content is retained up to 2 years and then permanently erased. A minimal anonymized tombstone may remain while the other participant retains the conversation. Service continuity for remaining participant
Chat media attachments (photos and videos in messages, including audio tracks contained in videos) Same as the message itself, except: videos, their audio tracks, and generated cover frames become inaccessible within 90 days of upload regardless of message state; underlying noncurrent storage versions are purged shortly thereafter, and the disaster-recovery replica is cleared within about a further 7 days. Storage cost + user expectation
Account activity timeline (specimen additions, collection and listing changes, and similar account events) Approximately 12 months. Security audit + abuse investigation
Sign-in events (login and registration, including via Apple or Google) Approximately 90 days. Security audit + abuse investigation
Registered device records (for push notification delivery) Retained while the device remains registered. The record is deleted when you sign out on that device, when you sign out of all devices remotely, when you delete your account, or when the push provider reports that the device's notification token is no longer valid (for example after you uninstall the App, move to a new device, or the operating system rotates the token). If a sign-out request does not reach us, the record remains until one of those other events occurs. There is no time-based expiry. Push-notification delivery
Moderation records (reports filed, strikes, suspensions, bans, takedowns) Up to 2 years from the underlying incident date (DSA Article 24). Platform safety + repeat-offender detection
Compliance keyword hit logs (excerpt of specimen notes surrounding a flagged keyword, with the matched keyword and specimen identifier — see §1.3) Up to 2 years. Compliance investigation + audit
Data-export audit trail (who requested a DSAR, when, request outcome, and a truncated request IP — see §1.2) Up to 7 years. The exported data itself is not kept in this record; the requester's IP is cleared when the account is deleted. GDPR Art 30 (records of processing) + CCPA §1798.185 audit
Email-change audit trail (request, outcome, and the full request IP — see §1.2) While your account exists. The email addresses and the IP are erased when your account is deleted. Account-security audit + abuse investigation
Data-export ZIP files Download link valid 7 days. ZIP auto-deleted from storage 8 days after generation. User self-service + storage hygiene
Database backups 90 days rolling. Disaster recovery
Crash reports / error logs 30–90 days (Sentry default). Debugging + stability tracking
view_events (product interaction, search hash, filter, view events) 30 days. Cohort analytics + product quality
landing_events (anonymous share-card landing funnel) 30 days. Referral attribution + funnel debugging
push_events (push lifecycle) Approximately 90 days. Delivery diagnostics + push CTR
user_sessions 180 days. Retention analytics + session integrity
account_deletion_log 2 years. GDPR / CCPA deletion audit
Deletion-execution audit records (an internal account identifier, the time of execution, the operation performed, counts of the rows and stored objects removed, and, when a deletion did not complete or its completion could not be verified, the storage key associated with that deletion — no name, email address, or content) Retained indefinitely, so that we remain able to evidence that a deletion request was actually carried out, and to identify any deletion that did not complete. GDPR Art 17(3)(e) (establishment, exercise, or defence of legal claims) + Art 30 (records of processing)
Transactional-email delivery queue Successfully delivered rows are normally deleted approximately 7 days after delivery; undeliverable dead-letter rows are normally deleted approximately 30 days after terminal delivery failure. Scheduled cleanup may complete later during a service interruption. The row includes a recipient-email snapshot, which may therefore remain for this short operational period after you change your email or delete/abandon the related account. Reliable account/security notices + delivery diagnosis
CDN cached content (after deletion) After origin deletion, residual cached copies may persist on our content-delivery network for up to ~30 days for publicly served media (specimen photos and videos, avatars, cover images) and up to ~24 hours for media served through expiring signed links (such as chat attachments). Taking content out of public display without deleting it does not start this window — see §3.1. Physical edge-cache expiry
Legal-acceptance audit trail (your acceptance of these Terms / Privacy versions) While your account is active plus 5 years after account deletion in HMAC-pseudonymized form (no plaintext user identifier, no plaintext IP/UA) — see §13. GDPR Art 7 evidence + GDPR Art 17(3)(e) defense-of-legal-claims basis + UK 6-year statute of limitations + Italy 10-year SoL for certain consumer claims
Listing-price records While linked to a user or specimen, retained as linked personal data. After both links are removed, the records are de-identified but may still constitute personal data; a weekly cleanup permanently deletes them once the original listing-status transition is more than three years old. See §14. Listing-history recordkeeping and data-subject access
Atlas-featured images (photos of your specimens accepted into the public atlas) An independent snapshot is displayed until you withdraw the specimen from “Public · Atlas,” delete the whole specimen, or permanently delete your account. Deleting only the source photo does not withdraw the snapshot. Withdrawal removes the community listing from new public atlas listings, API results, and reference-image results, but technical atlas copies and existing direct-link, cached, offline, or third-party copies may remain. Community mineral-reference service + technical delivery

If you need your data deleted before a scheduled retention period ends, you may request erasure by contacting us (see §11). We will honor the request unless an overriding legal obligation requires continued retention, in which case we will tell you why. For an atlas-featured image, use the specimen's atlas visibility control, delete the whole specimen, delete your account, or contact us under §11. Each path withdraws the community listing as described above; it does not guarantee deletion of technical, direct-link, cached, offline, or third-party copies.


9. Account Deletion

An email/password registration is not a full account until its email address is verified. Before verification, you may abandon that incomplete registration through the App by entering its current password. Abandonment is immediate: the unfinished registration and its reserved email address and username are released instead of entering the 30-day account-deletion grace period.

After registration is finalized, you may delete your account at any time through the App (Settings → Delete Account). The App requires a fresh account-control check appropriate to the account: current password, native Sign in with Apple authorization, or a one-time code delivered to the verified provider email address of a linked Google account. A verified account's deletion enters a 30-day grace period. If your account remains eligible to sign in, you may cancel through the App during that period. If you cannot sign in, including because of an age-eligibility checkpoint, suspension, ban, or inactive status, contact mineralwild@gmail.com. For a support-assisted formal account-deletion request or cancellation, we send a confirmation to the exact verified email address stored on the account and must receive an explicit reply from that address in the same email thread. If that account email is unavailable or undeliverable, support cannot make the change through this route; provider screenshots or login-history evidence are not substitutes. Where applicable law requires us to act on a verified request through another route, we will use the verification method that law requires. This deletion-only process does not remove any suspension, ban, inactive status, or other access restriction. Accounts known to be operated by a person under 18 follow the separate minor-account deletion process and do not receive this grace-period cancellation path. After the grace period ends:

Permanently deleted:

Platform-managed account identifiers removed or public listings withdrawn; some records or residual copies may remain:

De-identified after both links are removed (may still be personal data):

Pseudonymized and retained (still personal data):

Retained briefly by third parties:


10. Children's Privacy

The public mineral atlas contains general-audience educational information and may be browsed without an account. Account creation, sign-in, and all account-based features are limited to people who are at least 18 years old. We do not offer youth accounts or a parent- or guardian-consent path for account creation.

Guest browsing may still involve the limited automatic device, network, diagnostic, security, and product-interaction data described in §1.2. A person under 18 must not create an account, provide account information, or submit User Content. If we learn that an account is operated by a person under 18, we will restrict or close it and delete associated personal data promptly, subject to the limited retention obligations in §§8–9.

If you are a parent or legal guardian and believe a person under 18 created an account or submitted personal information through account features, contact us at mineralwild@gmail.com.


11. Your Rights

Depending on your location, you may have the following rights regarding your personal data:

To exercise any of these rights, contact us at mineralwild@gmail.com. We respond within the statutory window that applies to the request: EU and UK requests are generally handled within one calendar month, Swiss FADP access requests within 30 days, CCPA / CPRA requests within 45 days, and PIPL requests within 15 business days. Extensions and identity-verification timing follow the applicable law, as described below. For CCPA / CPRA requests we may require identity verification proportionate to the sensitivity of the data.

11.1 California Residents (CCPA / CPRA)

If you are a California resident:

Do Not Track and Global Privacy Control signals. Some browsers can send a "Do Not Track" (DNT) or Global Privacy Control (GPC) signal. We do not change how the App or our websites behave in response to those signals, and we do not treat them as an opt-out request. How we handle the sale and sharing of personal information is described in §3.5.

Third-party collection on our websites. Our public web pages use Cloudflare Web Analytics and, on sharing-card landing pages, Cloudflare Turnstile. These services receive the request and usage data needed for website analytics and abuse mitigation, which may include your IP address, website origin, requested page, and browser or device information, as described in §3.2. Website fonts are served from our own domain; our public pages do not contact Google Fonts. We do not embed advertising SDKs or cross-site tracking pixels on our web pages or in the App.

Categories of personal information we collect (CCPA §1798.140 categories):

Category Examples Source Business Purpose
Identifiers Email, display name, username and username-change history, specimen-transfer sender identity snapshots, IP address, OAuth provider identifiers You / automatic Account management, public account presentation, transfer provenance, security
Internet/network activity Device info, app version, crash logs, page-view metrics (pseudonymous / installation-associated before account creation) Automatic App improvement, bug fixes
User content Photos, videos and their audio tracks, specimen data, direct messages You Core App functionality
Geolocation Specimen GPS coordinates (manually provided) You Map display feature
Inferences Aggregate collection statistics Derived from your content Atlas progress display, social features
Sensitive personal information Specimen GPS coordinates (precise location); legal-acceptance audit records (linked by user FK while the account is active; HMAC-pseudonymized after deletion) You / automatic As disclosed in this policy

To exercise CCPA / CPRA rights, contact us at mineralwild@gmail.com. We will respond within 45 days, with a one-time 45-day extension permitted by §1798.130(a)(2) if reasonably necessary. A retention period of up to 7 years for the audit trail of DSAR requests themselves is maintained per §1798.185.

An authorized agent may submit a California privacy-rights request on your behalf by emailing mineralwild@gmail.com and identifying it as an authorized-agent request. We may require proof of your signed permission and may ask you to verify your identity directly or confirm the authorization; we will not require you to submit the request again in your own name. Those additional consumer steps do not apply where the agent holds a valid power of attorney under California Probate Code §§4121–4130, although we will still verify the agent and the association between the principal and the records requested.

11.2 European Economic Area, United Kingdom, and Switzerland (GDPR / UK GDPR / FADP)

Data Controller: Mineral Wild LLC, a Wyoming limited liability company, USA. Email: mineralwild@gmail.com. We have not yet appointed an EU representative under GDPR Article 27; if monthly EU users grow above the threshold for which an EU representative is required by enforcement practice, we will appoint one and update this policy.

Legal bases for processing (GDPR Article 6):

Processing Legal Basis
Account creation, authentication, providing the App's core features (collection management, atlas, maps, social features, direct messaging) Contractual necessity — Art 6(1)(b)
Public-profile visibility, display of your collection to other users, public sharing of "available" specimens Consent — Art 6(1)(a) (toggleable in privacy settings)
Displaying photos you contributed to the public mineral atlas (shown with your display name and @username; the profile link uses the username) Consent — Art 6(1)(a) while the image is displayed. You may withdraw the specimen from “Public · Atlas,” delete the whole specimen, delete your account, or contact us under §11. Deleting only the original source photo does not withdraw the independent atlas snapshot. Withdrawal removes the community listing from new public atlas listings, API results, and reference-image results; technical and already-distributed copies may remain for delivery and operational purposes under legitimate interest — Art 6(1)(f)
Automated content moderation, automated compliance rule enforcement, abuse prevention, security logging Legitimate interest — Art 6(1)(f) (platform safety, user safety, legal-compliance defense)
Maintaining legal-acceptance audit trail (§13) Consent captured at the time you accept this Privacy Policy and the Terms — Art 6(1)(a); post-deletion pseudonymized retention is based on necessary for the establishment, exercise or defense of legal claims — Art 17(3)(e)
Crash and diagnostic data Legitimate interest — Art 6(1)(f) (App stability)
Email communications about account events, policy changes, security alerts Contractual necessity + legitimate interest
Cross-border transfer of your data to U.S. processors Standard Contractual Clauses approved by the European Commission (Art 46(2)(c)), plus Privacy Policy disclosure (Art 13(1)(f)); for a provider not yet covered by such safeguards, the explicit-consent derogation (Art 49(1)(a)) as an exceptional fallback

Your additional rights under GDPR / UK GDPR / FADP:

International data transfers: Your data is transferred to and processed in the United States. Where required by GDPR, transfers to the U.S. are supported by Standard Contractual Clauses (SCCs) included in our agreements with U.S. service providers. SCCs and other Art 46 safeguards are our primary transfer mechanism. If, exceptionally, such safeguards are not yet in place for a specific provider, we rely on the explicit-consent derogation under GDPR Art 49(1)(a), coupled with the disclosures in this policy, as a transitional fallback while safeguards are put in place.

For EU GDPR requests, the response period generally starts when we receive the request and ends one calendar month later. If we have genuine doubts about identity and request necessary additional information without undue delay, timing is handled under the applicable EU rule rather than automatically restarting on a generic verification date. For UK GDPR requests, the period generally starts on receipt, but where reasonably requested identity or authority information is outstanding, the current UK rule starts the period when sufficient information is received. For complex or multiple EU / UK requests, we may extend the period by two further calendar months and will notify you of the extension and reasons within the initial one-month period. Under the Swiss FADP, access requests are generally answered within 30 days; if we cannot do so, we will tell you within that period why and when to expect the response.

We document every personal-data breach. For EU / UK breaches, we notify the competent supervisory authority without undue delay and, where feasible, within 72 hours after becoming aware, unless the breach is unlikely to result in a risk to individuals; a delayed notice includes reasons. For Swiss breaches likely to result in a high risk to personality or fundamental rights, we notify the FDPIC as soon as possible. Swiss data-subject notice is provided where necessary for protection or when the FDPIC requires it. Other applicable jurisdictions are assessed separately.

11.3 Other Jurisdictions

Users in other jurisdictions (Canada, Australia, Brazil LGPD, Japan APPI, Korea PIPA, India DPDPA, etc.) may have additional or different rights under their local law. We will honor verifiable local-law rights to the extent applicable; contact us at mineralwild@gmail.com.


12. International Data Transfers

Our primary servers are located in the United States (AWS us-east-1). If you access the App from outside the United States, your information will be transferred to and processed in the United States.

Where required by GDPR / UK GDPR or other cross-border-transfer laws, we use Standard Contractual Clauses approved by the European Commission and the equivalent UK addendum, included in our agreements with our U.S. and global service providers. These safeguards are our primary transfer mechanism. If, exceptionally, such mechanisms are not yet in place for a specific provider, we rely on the explicit-consent derogation, in conjunction with the disclosures in this policy, as a transitional fallback while transfer safeguards are put in place.

The current list of providers and their processing locations is on our Subprocessors page.


13. Legal-Acceptance Audit Trail (GDPR Article 7)

When you create an account or accept an updated Terms of Service or Privacy Policy, we record a tamper-evident "receipt" so that, in the event of a dispute or regulatory inquiry, we can prove the exact text in force at the moment you consented. This record is required by GDPR Article 7 ("the controller shall be able to demonstrate that the data subject has consented") and analogous laws.

What is recorded:

Retention and pseudonymization:

The pseudonymized record contains no direct account identifier. Re-associating it with the original account requires additional information protected by our technical and organizational controls. Under GDPR Recital 26, the record remains personal data even though it is not directly identifying.

While your account remains accessible — including during the 30-day account-deletion grace period — you may obtain a copy of your legal-acceptance receipts through Settings → Account → Download My Data. They are included in the export ZIP as legal-receipts.json.

After hard deletion, Settings and the direct account identifiers used by the standard export are no longer available. You may contact support at mineralwild@gmail.com and we will assess the request under applicable law, but we cannot promise that a specific retained receipt can be re-associated with you. An internal old-account identifier, HMAC pseudonym, or key may help us locate or audit a candidate record; none of those items, by itself, verifies the external requester's identity. We may ask for additional identifying or verification information where permitted by applicable law. If we cannot reliably identify or verify that a specific receipt relates to you, we will not disclose that receipt, and we will explain the reason and the applicable follow-up, complaint, or judicial-remedy routes. This operational limit does not by itself waive or extinguish statutory privacy rights.


14. Listing-Price Retention

Listing-price records linked to a user or specimen remain personal data, and the three-year cleanup does not apply while either link remains. These records capture a listing or asking price when a specimen leaves the "available" state; they are not verified sale prices.

After both links are removed, we treat the records as de-identified. They retain the mineral identifier, listing amount, currency, status transition, and timestamp. Because those fields may permit re-identification when combined with other information, the records may still constitute personal data and are not treated as anonymous.

A weekly cleanup permanently deletes de-identified listing-price records once their original listing-status transition is more than three years old. Because the three-year period runs from that original transition, a record already older than three years is eligible for deletion on the next weekly cleanup after both links are removed.


15. Account-Deletion Grace Period

Deletion requests for finalized, verified accounts enter a 30-day grace period. During that period, accounts that remain eligible to sign in may cancel through the App; an account that cannot sign in must use the deletion-only support process described in §9. Support cancellation does not restore account access or remove an existing restriction. An unfinished email/password registration that has not verified its email can instead be abandoned immediately after current-password confirmation and does not enter this grace period. After the grace period for a finalized account expires, personally identifiable data is permanently deleted in accordance with §9 (compliant with the CCPA §1798.105 45-day response window). Pseudonymized legal-acceptance records are retained as described in §13. Listing-price records follow the separate retention described in §14.


16. Territory

The App is not available in every region. Where it can be installed is determined by the Apple App Store and Google Play storefronts in which it is listed.

Where the law of a region in which the App is available requires additional privacy disclosures or a separate cross-border-transfer consent, we will publish those disclosures and obtain any consent that law requires.


17. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. For material changes — including changes to the categories of data we collect, the purposes of processing, the legal bases, third-party recipients, retention periods, or your rights — we will notify you with an in-app notice and/or by email at least 30 days before the changes take effect (where reasonably practicable). Your continued use of the App after the effective date constitutes acceptance of the updated policy. If you do not agree, you may delete your account before the effective date.

Where an immediate update is necessary to comply with law, platform-review requirements, or urgent user-safety obligations, we may make the updated policy effective immediately after notice and require in-app re-acceptance before continued use. All other material changes continue to follow the 30-day notice approach described above, where reasonably practicable.

For non-material changes (typo fixes, contact-information updates, restructuring without substantive change), we may publish the update without prior notice.


18. Contact Us

If you have any questions about this Privacy Policy or wish to exercise a data-subject right:

Email: mineralwild@gmail.com Entity: Mineral Wild LLC (a Wyoming limited liability company)


Features, availability, and this Privacy Policy may change over time. We will notify you of material changes as described in §17.