Privacy Policy
Policy Version: 2026-08-31-provider-disclosure
Effective Date: 2026-10-02T00:00:00Z
Mineral Wild LLC ("Mineral Wild," "we," "us," or "our"), a Wyoming limited liability company, operates the Mineral Wild mobile application (the "App") and related websites and services. This Privacy Policy explains how we collect, use, disclose, retain, and safeguard your information when you use the App.
By using the App, you agree to the collection and use of information in accordance with this policy. Where we rely on consent as the legal basis for processing (for example, public-profile visibility), you may withdraw your consent as described in §11.
If you are using the App from outside the United States, your information will be transferred to and processed in the United States. See §12.
1. Information We Collect
1.1 Information You Provide
- Account information: email address, required public display name, unique username, username-change history, hashed password (we never store your plaintext password), date you accepted the Terms of Service and Privacy Policy, and the timestamp when the client reported that you passed the 18+ account-access gate. The display name is a non-unique name shown to other users; the username is the unique account handle and profile locator and must contain 2–20 ASCII letters, digits, underscores, or hyphens (
[A-Za-z0-9_-]). The account-access timestamp is an eligibility assertion, not a verified date of birth or identity document. - Profile information (optional): bio, avatar photo, cover photo, and your home location string.
- Specimen data: photos, videos, mineral identification, locality (free text and optional structured country / state / address), purchase price and currency, estimated value, acquisition date, notes, GPS coordinates if you choose to pin a location on a map, "available" flag, and other descriptive fields you choose to fill in.
- Wishlist data: minerals you mark as "wanted" and optional wishlist descriptions.
- Custom tags and named collections you create to organize specimens.
- Mineral suggestions: suggestion details and reference photos if you contribute new minerals to the atlas.
- Direct messages and specimen-data transfers: text and media content of messages you send, message metadata (timestamps, conversation participants, read state), and delivery status. When you send a specimen-data transfer, we preserve your display name and username as they appeared at send time so the recipient can identify the transfer's provenance. If you delete your account, both sender-name snapshots are replaced with deletion tombstones. Media attachments (photos and videos, including any audio track contained in a video) are stored on our cloud infrastructure.
- Social interactions: follow relationships, blocked-user lists, saved listings (other users' available specimens you bookmark), and reports you file.
- Standalone voice input: We do not currently offer standalone voice input or audio transcription. Videos you choose to record or upload in direct messages may include an audio track, which we process as part of the video as described in §§4 and 5. A standalone voice-input feature may be offered in a future release; if it is, this policy will be updated and your separate consent obtained before audio is processed for that feature.
- Account security data: failed-login counts, lockout status, email-verification codes (auto-expired and purged), password-change events, OAuth provider linkage data (Apple user identifier or Google account ID), refresh-token records, and username-change history.
- Activity logs: internal records of key account events (account creation, OAuth log-in, specimen additions, collection changes, listing changes) used for generating your collection timeline and for security audit.
- Push-notification lifecycle: push type, transport provider (Firebase Cloud Messaging for Android and iOS), device platform, sent / delivered / opened timestamps, and delivery status. We do not store full push-message body text in the lifecycle table.
- Mineral atlas corrections and support correspondence: if you submit a correction or report through a mineral page, we process the free-text content you provide together with your account and the mineral concerned. If you contact support by email or through our Discord community, we process the message content and account or contact details you choose to provide so that we can respond. The in-App mineral-correction form does not accept screenshots.
- Legal-acceptance records: when you create an account or accept an updated version of the Terms of Service or Privacy Policy, we record a tamper-evident receipt — the document version and content hash you accepted, your account identifier, the time of acceptance, the truncated IP address (a /24 block for IPv4, /48 for IPv6), the user-agent string, and your declared client language and region. This is required by GDPR Article 7 and analogous laws as the auditable evidence that you consented to the version of the Terms in force at that moment. See §13 for the retention and pseudonymization details.
1.2 Information Collected Automatically
The following automatic collection may occur whether or not you create an account. Guest atlas browsing does not require you to provide account information or User Content, but it is pseudonymous rather than a promise of anonymous or zero data processing.
- Device and installation information: platform, app version and build number, operating-system version, device model, locale, timezone, push-permission status, and a random client-installation identifier generated by the App. The identifier is not a hardware fingerprint and may reset when the App is reinstalled; it accompanies guest atlas API requests for security, compatibility, and operational diagnosis.
- Product-interaction analytics: app-open, session-start, mineral-view, profile-view, search, filter, share-card, and add-specimen funnel events used for launch-readiness analytics. These events may be associated with the random client-installation identifier before account creation. Search queries are reported only as a 16-character SHA-256 hash of the normalized query; the raw search text does not leave your device for analytics.
- Session heartbeats: while the App is in the foreground, it may send periodic heartbeat events to maintain session state and retention analytics.
- Crash and diagnostic data: we use a third-party error-tracking service (Sentry) to collect crash reports and diagnostic data. This may include device identifiers, stack traces, and the circumstances of the error. User-generated content is excluded from these reports where technically feasible.
- IP addresses: your IP address is processed for rate limiting, security (login-attempt tracking, abuse detection), short-term server logging, and country-code derivation via a self-hosted MaxMind GeoLite2 database. We do not store full IP addresses in your profile record, and for country-code derivation the raw IP does not leave our backend. Where we do retain an IP address as a security-audit record, we retain it as follows:
- IP in legal-acceptance records (§13): truncated to a /24 block (IPv4) or /48 (IPv6).
- IP in data-export requests: truncated to a /24 block (IPv4) or /48 (IPv6), so that we can investigate abuse of the export function. Cleared when your account is deleted.
- IP in email-change requests: retained in full. We show it to you in the security alert we email to your previous address (as a
Request IP:line) so that you can tell whether the request was yours, and we keep it afterwards so that we can investigate account-takeover attempts. Cleared when your account is deleted. - IP in confirmed email changes: when an email change completes, that same full IP is also copied into the account-activity record for the change, together with the previous and new addresses. It follows the retention of that record (see §8.1) and is removed when your account is deleted.
1.3 Compliance Keyword Scanning of Specimen Notes
We maintain a list of compliance-sensitive keywords (for example: chrysotile, crocidolite, amosite, nephrite, bowenite, uraninite, pitchblende, and terms indicating sanctions evasion or smuggling). We scan the free-text notes field of your specimen records against this list. The scan runs when you create a specimen yourself, when you change its notes, and when you mark a specimen as sold — including when you mark it sold while sending its details to another collector in a message. A specimen you import from another collector's data transfer is scanned the first time you edit its notes or mark it sold, not at the moment of import. It applies to your specimen records whether or not the specimen is marked "available" and whether or not it is publicly visible.
When a keyword matches, we record an audit entry containing the matched keyword, a short excerpt of the surrounding notes text (approximately 20 characters on either side of the match), the identifier of the specimen concerned, and the time of the match, linked to your account. These entries are retained for up to 2 years (see §8.1) for audit and compliance-investigation purposes, as described in Terms of Service §6.4.
This scan covers specimen notes only. It is distinct from the automated filtering applied to direct messages (see §5.1), which uses a separate filter and does not create these compliance keyword entries. A keyword match alone does not restrict a specimen; listing restrictions are applied separately by the server-side compliance rule table described in Terms of Service §6.4.
1.4 Information We Do NOT Collect
- Payment or financial-transaction data. Purchase prices and estimated values you enter for specimens are collection metadata you provide voluntarily, not payment-processing data.
- Biometric data.
- Your exact date of birth, government identification, or selfie- or biometric-based age-verification data.
- Raw age bounds, age declaration, parental-control status, or regulatory-feature results returned by Apple's Declared Age Range APIs. When those APIs are available, the App classifies the result in memory solely to decide whether account access may proceed; it does not persist, upload, or log the raw Apple result.
- Health data.
- Real-time GPS tracking or continuous location monitoring. Specimen coordinates, when present, are values you have manually picked or typed, not values passively collected from your device.
- Advertising identifiers, ad-tracking data, or cross-context behavioral profiling data.
- Contacts or calendar data. We access the microphone when you choose to record a video — either for a specimen or for a direct message — on a supported device; the recorded video may include sound. We access the photo library only when you choose a file for an App feature, such as uploading media or scanning a QR code on your device. Images selected for QR scanning are processed on-device and are not uploaded.
2. How We Use Your Information
We use the information we collect to:
- Provide, operate, secure, and maintain the App;
- Create and manage your account and let you sign in via email/password, Apple Sign-In, or Google Sign-In;
- Display your mineral collection, atlas progress, and statistics;
- Enable social features (public profiles, follow system, wishlist–available matching, direct messaging, sharing cards);
- Deliver direct messages and send push notifications for new messages or relevant social events;
- Apply automated content moderation to user-uploaded media across the App — direct-message media, specimen photos and videos, avatars, profile and collection covers, and mineral-atlas suggestion photos — and automated keyword screening to public free-text fields (specimen names, custom mineral names, collection names, profile location, and bio), and operate a report-and-review process across user content (see §5), so that abusive or unlawful content is blocked or removed;
- Apply server-side compliance rules to "available" listings of minerals subject to trade restrictions (see Terms of Service §6.4);
- Scan the notes field of your specimen records against a compliance-sensitive keyword list and retain an audit excerpt of any match, for compliance investigation and audit (see §1.3);
- Generate sharing cards and short-link landing pages when you choose to share a specimen externally;
- Measure cohort retention, feature activation, search-to-detail conversion, share-card attribution, push-notification performance, and other aggregate launch-readiness metrics;
- Diagnose bugs and compatibility issues by app version, platform, locale, and device characteristics;
- Prevent abuse and protect analytics integrity on anonymous landing pages using Cloudflare Turnstile invisible challenges;
- Attribute first-party referral flows from share cards without using third-party attribution SDKs or cross-app tracking identifiers;
- Process account-deletion requests, data-export requests, and other data-subject requests;
- Send important service notifications (Terms or Privacy updates, security alerts, account events you've requested);
- Diagnose technical issues, improve the App, prevent abuse, and ensure platform safety;
- Maintain GDPR Article 7 evidence of your acceptance of these policies (see §13).
We do not use your information for:
- Targeted advertising, retargeting, or audience-based marketing;
- Selling, renting, or trading your personal data to third parties;
- Cross-context behavioral advertising (CCPA / CPRA "share" definition);
- Training, fine-tuning, or developing AI / machine-learning / large-language models on your photos, videos, direct messages, or other content, without your explicit opt-in consent;
- Automated decision-making producing legal or similarly significant effects on you. We do operate standard automated security and compliance measures (rate limiting, content filtering, the compliance rule table for
is_availablelistings); these do not produce legal effects in the GDPR Article 22 sense, and you may contact us if you believe one was applied to you in error (Terms of Service Annex III appeal flow).
3. How We Share Your Information
3.1 Public Features
If you enable public-profile visibility, the following information may be visible to other App users (signed-in or, where permitted, anonymous viewers):
- Required display name, unique username, avatar, cover photo, and bio. The username remains the profile locator even when two accounts use the same display name;
- Collection statistics (number of specimens, number of distinct mineral species in your collection, basic aggregate metrics);
- Specimens you have made
is_publicand that are available; - Specimens you have marked
is_available(along with the optional structured locality, photos, notes, andselling_priceyou chose to expose); - Your wishlist, if you've enabled wishlist visibility in privacy settings;
- Public mineral suggestions you have contributed and accepted into the atlas;
- Photos of your specimens that you have submitted, and that have been accepted through review, into the public mineral atlas ("community atlas images"), shown with your contributor attribution (your display name and
@username; the profile link is resolved by username).
You control the visibility of these features through the App's privacy settings, including two independent toggles:
show_collection: controls whether your public profile, specimen list, public galleries, gallery counts, and auto-cover thumbnails surface your regular public collection to visitors.show_available: controls whether the available-specific surfaces — available-specimen list, plaza available feed, available preview, wishlist matching, save-listing creation, contact CTA, and the visible price/currency on saved-listing rows — surface youris_availablespecimens to visitors and trigger fanout notifications to wishlist or saved-listing audiences.
When show_available is disabled, specimens you have marked available appear only as regular public collection (subject to show_collection), without available-specific signals such as price, contact CTA, save-listing, matching, or fanout. The privacy combination matrix:
show_collection |
show_available |
public collection | available-specific signals |
|---|---|---|---|
| true | true | visible | visible |
| true | false | visible (downgraded — no price / no contact CTA) | hidden |
| false | true | hidden | available-only surfaces visible |
| false | false | hidden | hidden |
Direct contact features (the in-app private message inbox at Messages and reply-from-public-profile contact buttons) are not gated by these visibility toggles; they are governed by your account's overall messaging preferences and the platform-wide IM availability flag.
You control these toggles through the App's privacy settings.
Separately, if a photo of yours has been accepted into the public atlas, the App provides an atlas visibility control. The atlas uses an independent snapshot, so deleting only the original source photo from your specimen does not withdraw the accepted snapshot from public display. Switching the specimen from “Public · Atlas” to “Public Profile,” deleting the whole specimen, or permanently deleting your account withdraws the community atlas listing from new public atlas listings, API results, and reference-image results. An account-deletion request does not withdraw it during the 30-day grace period; withdrawal occurs at permanent deletion if you do not cancel. See §4.2, §8, and §9.
What "taking something down" does and does not do. The visibility toggles above and atlas withdrawal remove content from the App's public surfaces and new public atlas/API/reference-image results. They do not guarantee erasure of every copy: technical atlas copies may remain in storage, a direct media link issued while content was public may keep resolving, device or CDN caches may retain a copy, and copies other people downloaded, saved, or shared are beyond the reach of an in-App control. Deleting only a specimen's original source photo removes that source photo but does not withdraw an already accepted independent atlas snapshot. Deleting the whole specimen or permanently deleting the account both withdraw the public atlas listing, while the residual-copy limits in this paragraph still apply.
3.2 Third-Party Services
Before enabling a third-party service that receives user data, we review the applicable contractual commitments and the service's published privacy terms to confirm that the service provides the same or equal protection of user data as stated in this Privacy Policy and required by the Apple App Review Guidelines.
As of this policy's Effective Date, the external providers that may receive personal data, their roles, and their processing locations are summarized below:
- Amazon Web Services (AWS): application hosting and managed data services, storage and backups, content delivery, transactional email, and media-safety screening in the United States (
us-east-1, with disaster-recovery copies inus-west-2) and through the CloudFront global edge network. - Apple: Sign in with Apple, Apple Push Notification service (APNs), Apple Maps and MapKit, and Declared Age Range through Apple's global service infrastructure.
- Google: Google Sign-In, Firebase Cloud Messaging, the Gmail support mailbox, and optional Google Search through Google's global service infrastructure.
- Cloudflare: authoritative DNS, Web Analytics, Turnstile abuse protection, and Email Routing through Cloudflare's global network.
- Sentry: error and performance monitoring in Sentry's United States region.
- LocationIQ: geocoding and reverse geocoding through its United States API endpoint; LocationIQ does not publish an exclusive processing location.
- Discord: optional community and support services in the United States and other Discord service locations.
Our Nginx edge and Centrifugo real-time service are self-hosted on Mineral Wild AWS hosts in the United States, and the MaxMind GeoLite2 database is used offline on those hosts. These processing contexts do not add separate third-party recipients.
This summary is a legal and recipient snapshot as of this policy's Effective Date, not an always-current operational inventory. Our Provider Disclosure is the current source for external provider identities, services, data categories, purposes, regions, and applicable conditions. It also lists self-hosted processing contexts and offline suppliers separately.
Apple Maps Platform Service (Not a Mineral Wild Subprocessor)
The App uses Apple MapKit for interactive maps and static map previews. When you view a specimen location on a map or request a preview, the specimen coordinate you selected determines the visible map area requested from Apple's Maps service. Apple states that Maps requests may send the time of the request, device model and software version, input language, the boundaries of the visible map area, interactions with Maps and places viewed, and application, device, network-configuration, and performance data. The App does not enable current-device location access in these map views, and a specimen pin shown over a static preview is composed on your device after the map snapshot is returned.
Apple handles Maps request data under Apple Maps & Privacy to provide and improve Maps and other location-based products and services, rather than as a service provider processing personal data on Mineral Wild's instructions.
When you open Mineral Wild through another user's sharing card and later create an account, we may store the first-party share_token that attributed the referral to that user. This inviter relationship is used only for product attribution and social graph integrity inside Mineral Wild; it is not shared with third-party attribution SDKs and is handled in data export and deletion workflows together with your account data.
3.3 AI Providers (Standalone Voice Input)
Standalone voice input is not active at launch. If introduced, the current provider identities and service conditions will be listed on the Provider Disclosure page; this section will describe the audio processing, and your separate consent will be obtained before that processing begins. Audio tracks contained in direct-message videos are not processed through a voice-input or transcription provider.
3.4 Legal and Safety Disclosures
We may disclose information:
- In response to valid legal process (court order, subpoena, search warrant, or comparable legal request);
- To investigate or address suspected violations of these Terms, the Privacy Policy, or applicable law;
- To protect the rights, property, or safety of Mineral Wild, our users, or the public — including, where appropriate, proactive reporting to the U.S. Customs and Border Protection (CBP), the U.S. CITES Management Authority, the U.S. Office of Foreign Assets Control (OFAC), the FBI Internet Crime Complaint Center (IC3), the National Center for Missing & Exploited Children (NCMEC), or local law enforcement, as described in Terms of Service §6.4;
- In connection with a corporate transaction (merger, acquisition, financing, or asset sale), in which case we will require any acquirer to honor this Privacy Policy or to notify you of material changes.
3.5 No Sale or "Share" of Personal Data
We do not sell, rent, trade, or "share" (as defined by the CCPA/CPRA for cross-context behavioral advertising) your personal information.
4. Photo and Video Storage and Processing
4.1 Your Photos and Videos
Photos and videos you upload (specimen photos, specimen videos, avatar, cover image, mineral-suggestion reference photos, and chat media attachments) are stored in private cloud storage and delivered through a content-delivery network (CDN) using signed URLs for sensitive paths (e.g., chat media). A chat video may contain an audio track; we process and store that track as part of the video. We generate thumbnails and reduced-resolution copies for faster loading and, for videos, extract a cover frame. During processing, we apply server-side metadata filtering to uploaded media. For specimen photos, we remove standard GPS/location fields, camera-owner information, serial numbers, maker notes, and other non-allowlisted EXIF fields. Specimen photos may retain camera make and model, orientation, and date/time metadata, including image-change and original-capture timestamps. Other processed images are re-encoded without EXIF, XMP, IPTC, or comment metadata. Color-profile data may be retained in processed images. Videos are processed to remove standard container metadata before delivery.
4.2 Photo and Video Retention
Except for chat video attachments, which become inaccessible within 90 days of upload and whose underlying versioned storage copies are automatically purged shortly thereafter as described in §5.4, your photos and videos (including audio tracks contained in videos) are retained while your account is active. When you delete a whole specimen, its user-collection photos and videos are removed from our database and origin storage, and any community atlas listing contributed by that specimen is withdrawn from new public atlas listings, API results, and reference-image results. Deleting only an original source photo does not withdraw an already accepted independent atlas snapshot. Technical atlas copies and existing direct-link, cached, offline, or third-party copies may remain after withdrawal. When you permanently delete your account at the end of the 30-day grace period, your specimen, profile, and mineral-suggestion media are deleted from origin storage and corresponding disaster-recovery replicas are cleared within approximately 90 days, subject to the limited retention items in §8. Community atlas listings are withdrawn at that permanent-deletion step; they remain displayed during the grace period unless you separately withdraw the specimen first.
4.3 Sharing Externally
When you use the App's sharing features (e.g., sharing a specimen card to social media, or generating a public short-link), the shared content leaves our platform. Once shared externally, the content is subject to the third-party platform's terms and is beyond our control.
5. Direct Messaging
5.1 Message Content and Moderation
The App provides a direct-messaging feature for one-on-one communication. Message content (text and media) is transmitted through our real-time messaging infrastructure (Centrifugo) and stored on our servers.
We employ automated content filtering on direct messages: text is screened by an automated keyword/pattern filter, while image attachments and cover frames extracted from video attachments pass through Amazon Rekognition for automated moderation. Video audio tracks are not sent to Rekognition. Messages or media that match our filters — including text matching listed CSAM, hate-speech, or other prohibited terms — are blocked from delivery and the attempt is logged. This automated screening is keyword- and image-based; it is not exhaustive or semantic detection of every category of prohibited content. Separately, on obtaining actual knowledge of apparent CSAM, we report it to the NCMEC CyberTipline as required by law (see Terms of Service §6.4). We do not use message content for advertising, profiling, or training machine-learning models.
The same automated image moderation applies to all other user-uploaded media in the App: specimen photos and videos, avatars, profile and collection covers, and mineral-atlas suggestion photos (images and cover frames extracted from videos) pass through Amazon Rekognition before they are published, and media that matches our filters is blocked and never made publicly available. Video audio tracks are not sent to Rekognition for these uploads either. Public free-text fields — specimen names, custom mineral names, collection names, profile location, and bio — are screened by the same automated keyword/pattern filter, as are public usernames and display names. Content blocked by these filters can be deleted and replaced by you; we do not operate a human pre-publication review queue.
5.2 Administrative Access
Our administrative team may access message content in the following limited circumstances:
- When reviewing a user report filed through the App's reporting feature;
- When investigating suspected violations of these Terms, the Privacy Policy, or applicable law;
- When required by valid legal process.
Administrative access is restricted to authorized personnel and limited to the circumstances described above. Moderation decisions made through our in-App reporting workflow are recorded. We do not proactively monitor private conversations beyond the automated content filtering described above.
5.3 Push Notifications
The App initializes Firebase Cloud Messaging at startup. After you sign in, if a device registration token is available, the App makes a best-effort attempt to register it with Mineral Wild. Token registration can occur independently of whether you have granted operating-system notification permission, and a registration failure does not block your use of the App.
We use Firebase Cloud Messaging as the app-level push provider for Android and iOS. On iOS, Firebase delivers through Apple Push Notification service (APNs) as the operating-system delivery layer. Actual notification delivery depends on your operating-system permission and account notification preferences. Notification preview content is sanitized server-side: we send the message type and a generic preview string rather than the full message body, so that intercepted push payloads do not reveal sensitive chat content. You may disable push notifications at any time through your device settings or account notification preferences.
5.4 Message Retention and Deletion
Messages are retained as long as the conversation exists and at least one participant has not deleted it. When you delete a conversation, your view of the conversation is removed but the other participant may retain their copy. Media attachments (photos and videos, including audio tracks contained in videos) sent in messages are stored on our cloud infrastructure subject to the same retention rules, except that video attachments — including their audio tracks and generated cover frames — become inaccessible within 90 days of upload regardless of conversation state. Underlying noncurrent storage versions are permanently purged shortly thereafter under automated storage-lifecycle controls.
When you delete your account, your platform-managed sender identity is removed from the message records and their content is retained for up to 2 years to preserve conversation context for the other participant. After 2 years, the original content is permanently erased. A minimal anonymized message tombstone — such as message type, timestamp, and conversation linkage, without your sender identity or original content — may remain while the other participant retains the conversation. Media attachments you sent are deleted within 90 days of account deletion.
5.5 Data Portability
While your account remains accessible, you may request a copy of your data, including your current display name and username, username-change history, messages, media, and specimen-data transfers, through the App (Settings → Account → Download My Data). Sent transfers include your own display-name and username snapshots as recorded at send time. Received transfers include the sender's display-name and username snapshots while that sender account remains linked; if the sender has deleted the account, both fields are anonymized in your export to protect the former sender's rights. We will prepare your data as a machine-readable ZIP archive (JSON + CSV + media files + a legal-receipts.json file documenting your accepted Terms / Privacy versions) and email a download link to your verified address, typically within 30 minutes. The link is valid for 7 days; the archive is auto-deleted from our storage 8 days after generation. This self-service path includes the 30-day account-deletion grace period while the account remains accessible. If your account is no longer accessible, contact mineralwild@gmail.com; we will assess the request under §13 and applicable law.
6. Local Device Storage of Compliance and Safety Acknowledgments
Two related categories of one-time acknowledgments are stored locally on your device, never transmitted to our servers:
(a) Compliance advisories. When you mark a specimen is_available and the request matches an advisory rule (such as radioactivity-level warnings, mercury and arsenic health advisories, or asbestos-classification awareness), we record locally that you have acknowledged that specific rule. The stored value is the short code of the acknowledged rule (for example, OFAC_BURMA_AMBER, ADVISORY_RADIOACTIVITY_HIGH) and a timestamp. No personally identifiable information is included.
(b) Contact-safety acknowledgments. When you initiate a private message from the available-specimen contact action for the first time, we record locally that you have acknowledged the contact-safety notice (an account-scoped pseudonymous local key derived from a one-way hash of your account UUID, plus an ISO timestamp). This lets the App suppress the same notice on subsequent sends from the same account on the same device. The stored value contains no readable account identifier and cannot be used to identify you in isolation.
Both categories are stored using local app storage on your device (device preferences, secure key-value storage, depending on platform). Because this storage is device-local, neither category syncs across your devices, and clearing the App's data on your device will reset the acknowledgments and cause the corresponding advisory or notice to appear again the next time the matching condition is met.
7. Data Security
We implement reasonable technical and organizational measures to protect your personal information, including:
- Password hashing using a modern key-derivation function (passwords never stored in plain text);
- HTTPS / TLS encryption for all data in transit;
- TLS to our database and to managed Redis / cache layers;
- Rate limiting on authentication and upload endpoints, account-lockout on repeated failures;
- Private cloud storage with access controls; signed URLs for sensitive media (chat attachments);
- Server-side media metadata filtering as described in §4.1;
- Refresh-token rotation, revocation on sign-out of all devices, and revocation on password change;
- Automated dependency-security scanning;
- Logging and alerting on anomalous login behavior, backup state, and authorization failures.
No method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security and recommend you use a strong, unique password and enable platform-level account protections (Apple ID 2FA, Google account 2FA) if you sign in via OAuth.
8. Data Retention
We retain each category of personal data only for as long as necessary to operate the App, meet legal obligations, defend legal claims, or enforce our Terms of Service. The Retention Schedule below lists specific retention periods.
8.1 Retention Schedule
| Data Category | Retention Period | Basis |
|---|---|---|
| Account data (display name, username and username history, profile, specimens, photos, videos, collections, wishlist, custom tags, follows, blocks, saved listings, and mineral atlas corrections) | While your account is active. Permanently deleted within approximately 90 days after the account-deletion grace period ends, subject to the separately listed retained records and residual-copy boundaries. Disaster-recovery replica copies are cleared on the same schedule. | Core service provision |
| Direct messages and specimen-data transfers (text + metadata) | While the conversation exists between participants. When both participants delete the conversation, permanently deleted within 90 days. After account deletion, sender identity is removed immediately; this includes replacing both transfer sender-name snapshots with deletion tombstones. Original message content is retained up to 2 years and then permanently erased. A minimal anonymized tombstone may remain while the other participant retains the conversation. | Service continuity for remaining participant |
| Chat media attachments (photos and videos in messages, including audio tracks contained in videos) | Same as the message itself, except: videos, their audio tracks, and generated cover frames become inaccessible within 90 days of upload regardless of message state; underlying noncurrent storage versions are purged shortly thereafter, and the disaster-recovery replica is cleared within about a further 7 days. | Storage cost + user expectation |
| Account activity timeline (specimen additions, collection and listing changes, and similar account events) | Approximately 12 months. | Security audit + abuse investigation |
| Sign-in events (login and registration, including via Apple or Google) | Approximately 90 days. | Security audit + abuse investigation |
| Registered device records (for push notification delivery) | Retained while the device remains registered. The record is deleted when you sign out on that device, when you sign out of all devices remotely, when you delete your account, or when the push provider reports that the device's notification token is no longer valid (for example after you uninstall the App, move to a new device, or the operating system rotates the token). If a sign-out request does not reach us, the record remains until one of those other events occurs. There is no time-based expiry. | Push-notification delivery |
| Moderation records (reports filed, strikes, suspensions, bans, takedowns) | Up to 2 years from the underlying incident date (DSA Article 24). | Platform safety + repeat-offender detection |
| Compliance keyword hit logs (excerpt of specimen notes surrounding a flagged keyword, with the matched keyword and specimen identifier — see §1.3) | Up to 2 years. | Compliance investigation + audit |
| Data-export audit trail (who requested a DSAR, when, request outcome, and a truncated request IP — see §1.2) | Up to 7 years. The exported data itself is not kept in this record; the requester's IP is cleared when the account is deleted. | GDPR Art 30 (records of processing) + CCPA §1798.185 audit |
| Email-change audit trail (request, outcome, and the full request IP — see §1.2) | While your account exists. The email addresses and the IP are erased when your account is deleted. | Account-security audit + abuse investigation |
| Data-export ZIP files | Download link valid 7 days. ZIP auto-deleted from storage 8 days after generation. | User self-service + storage hygiene |
| Database backups | 90 days rolling. | Disaster recovery |
| Crash reports / error logs | 30–90 days (Sentry default). | Debugging + stability tracking |
view_events (product interaction, search hash, filter, view events) |
30 days. | Cohort analytics + product quality |
landing_events (anonymous share-card landing funnel) |
30 days. | Referral attribution + funnel debugging |
push_events (push lifecycle) |
Approximately 90 days. | Delivery diagnostics + push CTR |
user_sessions |
180 days. | Retention analytics + session integrity |
account_deletion_log |
2 years. | GDPR / CCPA deletion audit |
| Deletion-execution audit records (an internal account identifier, the time of execution, the operation performed, counts of the rows and stored objects removed, and, when a deletion did not complete or its completion could not be verified, the storage key associated with that deletion — no name, email address, or content) | Retained indefinitely, so that we remain able to evidence that a deletion request was actually carried out, and to identify any deletion that did not complete. | GDPR Art 17(3)(e) (establishment, exercise, or defence of legal claims) + Art 30 (records of processing) |
| Transactional-email delivery queue | Successfully delivered rows are normally deleted approximately 7 days after delivery; undeliverable dead-letter rows are normally deleted approximately 30 days after terminal delivery failure. Scheduled cleanup may complete later during a service interruption. The row includes a recipient-email snapshot, which may therefore remain for this short operational period after you change your email or delete/abandon the related account. | Reliable account/security notices + delivery diagnosis |
| CDN cached content (after deletion) | After origin deletion, residual cached copies may persist on our content-delivery network for up to ~30 days for publicly served media (specimen photos and videos, avatars, cover images) and up to ~24 hours for media served through expiring signed links (such as chat attachments). Taking content out of public display without deleting it does not start this window — see §3.1. | Physical edge-cache expiry |
| Legal-acceptance audit trail (your acceptance of these Terms / Privacy versions) | While your account is active plus 5 years after account deletion in HMAC-pseudonymized form (no plaintext user identifier, no plaintext IP/UA) — see §13. | GDPR Art 7 evidence + GDPR Art 17(3)(e) defense-of-legal-claims basis + UK 6-year statute of limitations + Italy 10-year SoL for certain consumer claims |
| Listing-price records | While linked to a user or specimen, retained as linked personal data. After both links are removed, the records are de-identified but may still constitute personal data; a weekly cleanup permanently deletes them once the original listing-status transition is more than three years old. See §14. | Listing-history recordkeeping and data-subject access |
| Atlas-featured images (photos of your specimens accepted into the public atlas) | An independent snapshot is displayed until you withdraw the specimen from “Public · Atlas,” delete the whole specimen, or permanently delete your account. Deleting only the source photo does not withdraw the snapshot. Withdrawal removes the community listing from new public atlas listings, API results, and reference-image results, but technical atlas copies and existing direct-link, cached, offline, or third-party copies may remain. | Community mineral-reference service + technical delivery |
If you need your data deleted before a scheduled retention period ends, you may request erasure by contacting us (see §11). We will honor the request unless an overriding legal obligation requires continued retention, in which case we will tell you why. For an atlas-featured image, use the specimen's atlas visibility control, delete the whole specimen, delete your account, or contact us under §11. Each path withdraws the community listing as described above; it does not guarantee deletion of technical, direct-link, cached, offline, or third-party copies.
9. Account Deletion
An email/password registration is not a full account until its email address is verified. Before verification, you may abandon that incomplete registration through the App by entering its current password. Abandonment is immediate: the unfinished registration and its reserved email address and username are released instead of entering the 30-day account-deletion grace period.
After registration is finalized, you may delete your account at any time through the App (Settings → Delete Account). The App requires a fresh account-control check appropriate to the account: current password, native Sign in with Apple authorization, or a one-time code delivered to the verified provider email address of a linked Google account. A verified account's deletion enters a 30-day grace period. If your account remains eligible to sign in, you may cancel through the App during that period. If you cannot sign in, including because of an age-eligibility checkpoint, suspension, ban, or inactive status, contact mineralwild@gmail.com. For a support-assisted formal account-deletion request or cancellation, we send a confirmation to the exact verified email address stored on the account and must receive an explicit reply from that address in the same email thread. If that account email is unavailable or undeliverable, support cannot make the change through this route; provider screenshots or login-history evidence are not substitutes. Where applicable law requires us to act on a verified request through another route, we will use the verification method that law requires. This deletion-only process does not remove any suspension, ban, inactive status, or other access restriction. Accounts known to be operated by a person under 18 follow the separate minor-account deletion process and do not receive this grace-period cancellation path. After the grace period ends:
Permanently deleted:
- Personal information (display name, username, username-change history, email, avatar, cover photo, bio);
- All specimen records, photos, and videos (removed from the user-content database and origin storage; CDN edge caches may persist), with any community atlas listings contributed by those specimens withdrawn from new public atlas listings, API results, and reference-image results; technical atlas copies and existing direct-link, cached, offline, or third-party copies may remain;
- Wishlist entries and wishlist visibility settings;
- Follow relationships;
- Activity logs;
- Custom tags and tag associations;
- Named collections and collection contents;
- Pending, rejected, or duplicate mineral-suggestion drafts and their attached photos;
- Saved listings, blocks, and other personalized social state;
- OAuth provider linkage records.
Platform-managed account identifiers removed or public listings withdrawn; some records or residual copies may remain:
- Approved mineral suggestions whose content has been incorporated into the public atlas (your user identifier is removed; the mineral entry remains);
- Photos of your specimens that were accepted into the public atlas (the community listing is withdrawn from new public atlas listings, API results, and reference-image results; technical atlas copies and existing direct-link, cached, offline, or third-party copies may remain);
- Reports you filed (your identity is removed; the report content is retained for platform safety and audit per the moderation-records retention period);
- Direct-message records (your sender identity is removed; original message content is retained up to 2 years and then permanently erased; a minimal anonymized tombstone may remain while the other participant retains the conversation; media attachments you sent are deleted within 90 days);
- Specimen-data transfer records retained for the recipient (both sender display-name and username snapshots are replaced with deletion tombstones; system-generated transfer source text does not copy your account name, while any later recipient-authored source text remains the recipient's own free-text content);
De-identified after both links are removed (may still be personal data):
- Listing-price records retain the mineral identifier, listing amount, currency, status transition, and timestamp. Account deletion removes both the user and specimen links. The remaining record follows the three-year weekly-cleanup lifecycle in §14 and is not treated as anonymous.
Pseudonymized and retained (still personal data):
- Legal-acceptance audit-trail records (your user identifier is replaced with a one-way HMAC pseudonym; IP and user-agent are NULLed; document version, content hash, language, jurisdiction, and acceptance time are retained for 5 years; see §13).
Retained briefly by third parties:
- Database backups are automatically purged on a 90-day rotation cycle.
- Photo and video copies held in our encrypted disaster-recovery replica storage are automatically purged within approximately 90 days of origin deletion (chat media attachments: approximately 7 days). They are not readable by the App or by any of our application services while they await purge.
- Diagnostic data in our error-tracking service (Sentry) is automatically purged within its standard retention period (30–90 days).
- Cached copies of photos and videos on our CDN may persist after origin deletion for up to ~30 days where the media was served publicly, and for up to ~24 hours where it was served through expiring signed links (such as chat attachments).
10. Children's Privacy
The public mineral atlas contains general-audience educational information and may be browsed without an account. Account creation, sign-in, and all account-based features are limited to people who are at least 18 years old. We do not offer youth accounts or a parent- or guardian-consent path for account creation.
Guest browsing may still involve the limited automatic device, network, diagnostic, security, and product-interaction data described in §1.2. A person under 18 must not create an account, provide account information, or submit User Content. If we learn that an account is operated by a person under 18, we will restrict or close it and delete associated personal data promptly, subject to the limited retention obligations in §§8–9.
If you are a parent or legal guardian and believe a person under 18 created an account or submitted personal information through account features, contact us at mineralwild@gmail.com.
11. Your Rights
Depending on your location, you may have the following rights regarding your personal data:
- Access: Request a copy of the personal data we hold about you. Most of this is available self-service through Settings → Account → Download My Data, and the README included in that export explains the main categories of information redacted or withheld from it. A small number of internal compliance and security audit records — such as the keyword-match log described in §1.3 — are not included in the export and are not provided on request; if you ask, we will confirm whether such a record concerning you exists and explain the basis for withholding it. Where the specimen record still exists, the notes text such a record was derived from is exported in full with that specimen.
- Correction: Request correction of inaccurate personal data. Most profile fields are user-editable in the App.
- Deletion: Request deletion of your account and personal data (see §9). For deletion of specific items beyond Settings → Delete Account (e.g., partial deletion, deletion beyond the 30-day grace window, deceased-user requests), email us.
- Data portability: Request your data in a structured, machine-readable format. The Settings → Account → Download My Data export is in JSON / CSV / image-file form, suitable for portability.
- Objection: Object to certain processing of your personal data, including processing based on legitimate interest.
- Withdraw consent: Where processing is based on consent, you may withdraw at any time.
To exercise any of these rights, contact us at mineralwild@gmail.com. We respond within the statutory window that applies to the request: EU and UK requests are generally handled within one calendar month, Swiss FADP access requests within 30 days, CCPA / CPRA requests within 45 days, and PIPL requests within 15 business days. Extensions and identity-verification timing follow the applicable law, as described below. For CCPA / CPRA requests we may require identity verification proportionate to the sensitivity of the data.
11.1 California Residents (CCPA / CPRA)
If you are a California resident:
- You have the right to know what personal information we collect, use, disclose, and retain;
- You have the right to request deletion of your personal information;
- You have the right to correct inaccurate personal information;
- You have the right to opt out of the sale or sharing of your personal information — we do not sell or share your personal information for cross-context behavioral advertising, and we do not knowingly sell or share personal information of consumers under 16 years of age;
- You have the right to limit the use of sensitive personal information — we do not use sensitive personal information beyond the purposes disclosed in this policy;
- You have the right to non-discrimination for exercising your rights.
Do Not Track and Global Privacy Control signals. Some browsers can send a "Do Not Track" (DNT) or Global Privacy Control (GPC) signal. We do not change how the App or our websites behave in response to those signals, and we do not treat them as an opt-out request. How we handle the sale and sharing of personal information is described in §3.5.
Third-party collection on our websites. Our public web pages use Cloudflare Web Analytics and, on sharing-card landing pages, Cloudflare Turnstile. These services receive the request and usage data needed for website analytics and abuse mitigation, which may include your IP address, website origin, requested page, and browser or device information, as described in §3.2. Website fonts are served from our own domain; our public pages do not contact Google Fonts. We do not embed advertising SDKs or cross-site tracking pixels on our web pages or in the App.
Categories of personal information we collect (CCPA §1798.140 categories):
| Category | Examples | Source | Business Purpose |
|---|---|---|---|
| Identifiers | Email, display name, username and username-change history, specimen-transfer sender identity snapshots, IP address, OAuth provider identifiers | You / automatic | Account management, public account presentation, transfer provenance, security |
| Internet/network activity | Device info, app version, crash logs, page-view metrics (pseudonymous / installation-associated before account creation) | Automatic | App improvement, bug fixes |
| User content | Photos, videos and their audio tracks, specimen data, direct messages | You | Core App functionality |
| Geolocation | Specimen GPS coordinates (manually provided) | You | Map display feature |
| Inferences | Aggregate collection statistics | Derived from your content | Atlas progress display, social features |
| Sensitive personal information | Specimen GPS coordinates (precise location); legal-acceptance audit records (linked by user FK while the account is active; HMAC-pseudonymized after deletion) | You / automatic | As disclosed in this policy |
To exercise CCPA / CPRA rights, contact us at mineralwild@gmail.com. We will respond within 45 days, with a one-time 45-day extension permitted by §1798.130(a)(2) if reasonably necessary. A retention period of up to 7 years for the audit trail of DSAR requests themselves is maintained per §1798.185.
An authorized agent may submit a California privacy-rights request on your behalf by emailing mineralwild@gmail.com and identifying it as an authorized-agent request. We may require proof of your signed permission and may ask you to verify your identity directly or confirm the authorization; we will not require you to submit the request again in your own name. Those additional consumer steps do not apply where the agent holds a valid power of attorney under California Probate Code §§4121–4130, although we will still verify the agent and the association between the principal and the records requested.
11.2 European Economic Area, United Kingdom, and Switzerland (GDPR / UK GDPR / FADP)
Data Controller: Mineral Wild LLC, a Wyoming limited liability company, USA. Email: mineralwild@gmail.com. We have not yet appointed an EU representative under GDPR Article 27; if monthly EU users grow above the threshold for which an EU representative is required by enforcement practice, we will appoint one and update this policy.
Legal bases for processing (GDPR Article 6):
| Processing | Legal Basis |
|---|---|
| Account creation, authentication, providing the App's core features (collection management, atlas, maps, social features, direct messaging) | Contractual necessity — Art 6(1)(b) |
| Public-profile visibility, display of your collection to other users, public sharing of "available" specimens | Consent — Art 6(1)(a) (toggleable in privacy settings) |
Displaying photos you contributed to the public mineral atlas (shown with your display name and @username; the profile link uses the username) |
Consent — Art 6(1)(a) while the image is displayed. You may withdraw the specimen from “Public · Atlas,” delete the whole specimen, delete your account, or contact us under §11. Deleting only the original source photo does not withdraw the independent atlas snapshot. Withdrawal removes the community listing from new public atlas listings, API results, and reference-image results; technical and already-distributed copies may remain for delivery and operational purposes under legitimate interest — Art 6(1)(f) |
| Automated content moderation, automated compliance rule enforcement, abuse prevention, security logging | Legitimate interest — Art 6(1)(f) (platform safety, user safety, legal-compliance defense) |
| Maintaining legal-acceptance audit trail (§13) | Consent captured at the time you accept this Privacy Policy and the Terms — Art 6(1)(a); post-deletion pseudonymized retention is based on necessary for the establishment, exercise or defense of legal claims — Art 17(3)(e) |
| Crash and diagnostic data | Legitimate interest — Art 6(1)(f) (App stability) |
| Email communications about account events, policy changes, security alerts | Contractual necessity + legitimate interest |
| Cross-border transfer of your data to U.S. processors | Standard Contractual Clauses approved by the European Commission (Art 46(2)(c)), plus Privacy Policy disclosure (Art 13(1)(f)); for a provider not yet covered by such safeguards, the explicit-consent derogation (Art 49(1)(a)) as an exceptional fallback |
Your additional rights under GDPR / UK GDPR / FADP:
- Right to withdraw consent — at any time, by deleting your account, by taking a specific item down where the App provides a control (including withdrawing a specimen from “Public · Atlas”), or by ceasing to use a specific consent-based feature. Withdrawal does not affect the lawfulness of processing before withdrawal. For an accepted atlas image, deleting only the source photo does not withdraw the independent snapshot; withdrawing the specimen, deleting the whole specimen, permanently deleting the account, or an honored request under §11 stops new public atlas listings, API results, and reference-image results. Technical atlas copies and existing direct-link, cached, offline, or third-party copies may remain as described in §3.1 and §8.1.
- Right to restriction — in the circumstances of GDPR Art 18.
- Right to object — to processing based on legitimate interest, including for direct-marketing-like purposes (we do not engage in direct marketing).
- Right to lodge a complaint with your local data-protection supervisory authority. A directory is available at https://edpb.europa.eu/about-edpb/about-edpb/members_en (EU) or https://ico.org.uk/ (UK) or https://www.edoeb.admin.ch/ (Switzerland).
- Right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects on you (GDPR Art 22). We do not engage in such processing in the GDPR Art 22 sense; the automated content-filter and compliance-rule outcomes are not legal-effect decisions and you may appeal them as described in Terms of Service Annex III.
- Right to information about certain personal-data breaches: under GDPR / UK GDPR, we communicate a breach without undue delay when it is likely to result in a high risk to your rights and freedoms, unless an Article 34 exception applies (for example, effective protection such as encryption, later measures that remove the high risk, or disproportionate effort requiring an equally effective public communication). Other laws may impose different or earlier duties.
International data transfers: Your data is transferred to and processed in the United States. Where required by GDPR, transfers to the U.S. are supported by Standard Contractual Clauses (SCCs) included in our agreements with U.S. service providers. SCCs and other Art 46 safeguards are our primary transfer mechanism. If, exceptionally, such safeguards are not yet in place for a specific provider, we rely on the explicit-consent derogation under GDPR Art 49(1)(a), coupled with the disclosures in this policy, as a transitional fallback while safeguards are put in place.
For EU GDPR requests, the response period generally starts when we receive the request and ends one calendar month later. If we have genuine doubts about identity and request necessary additional information without undue delay, timing is handled under the applicable EU rule rather than automatically restarting on a generic verification date. For UK GDPR requests, the period generally starts on receipt, but where reasonably requested identity or authority information is outstanding, the current UK rule starts the period when sufficient information is received. For complex or multiple EU / UK requests, we may extend the period by two further calendar months and will notify you of the extension and reasons within the initial one-month period. Under the Swiss FADP, access requests are generally answered within 30 days; if we cannot do so, we will tell you within that period why and when to expect the response.
We document every personal-data breach. For EU / UK breaches, we notify the competent supervisory authority without undue delay and, where feasible, within 72 hours after becoming aware, unless the breach is unlikely to result in a risk to individuals; a delayed notice includes reasons. For Swiss breaches likely to result in a high risk to personality or fundamental rights, we notify the FDPIC as soon as possible. Swiss data-subject notice is provided where necessary for protection or when the FDPIC requires it. Other applicable jurisdictions are assessed separately.
11.3 Other Jurisdictions
Users in other jurisdictions (Canada, Australia, Brazil LGPD, Japan APPI, Korea PIPA, India DPDPA, etc.) may have additional or different rights under their local law. We will honor verifiable local-law rights to the extent applicable; contact us at mineralwild@gmail.com.
12. International Data Transfers
Our primary servers are located in the United States (AWS us-east-1). If you access the App from outside the United States, your information will be transferred to and processed in the United States.
Where required by GDPR / UK GDPR or other cross-border-transfer laws, we use Standard Contractual Clauses approved by the European Commission and the equivalent UK addendum, included in our agreements with our U.S. and global service providers. These safeguards are our primary transfer mechanism. If, exceptionally, such mechanisms are not yet in place for a specific provider, we rely on the explicit-consent derogation, in conjunction with the disclosures in this policy, as a transitional fallback while transfer safeguards are put in place.
The current list of providers and their processing locations is on our Subprocessors page.
13. Legal-Acceptance Audit Trail (GDPR Article 7)
When you create an account or accept an updated Terms of Service or Privacy Policy, we record a tamper-evident "receipt" so that, in the event of a dispute or regulatory inquiry, we can prove the exact text in force at the moment you consented. This record is required by GDPR Article 7 ("the controller shall be able to demonstrate that the data subject has consented") and analogous laws.
What is recorded:
- Receipt UUID;
- Document type (Terms of Service or Privacy Policy);
- Document version label (for example,
2026-04-28); - Document content hash (SHA-256 of the body of the document at that version);
- Document full-text URL (so the exact body can be reconstructed);
- Action (
accepted, orreacceptedafter a material policy update); - Acceptance method (
register_checkbox_submit,oauth_implicit_log, etc.); - Source (
registration,oauth_login, etc.); - Time of acceptance (UTC);
- Account identifier (foreign-key reference to your user record while it exists);
- IP address, truncated to a /24 block for IPv4 or /48 for IPv6 (this is the maximum granularity retained, in line with GDPR data-minimization);
- User-agent string (truncated to ≤ 1000 characters);
- Declared client language (from the app's
X-MW-Localeheader, falling back to theAccept-Languageheader for older clients) and optional declared region.
Retention and pseudonymization:
- While your account is active, the record is linked to your user identifier (foreign-key reference).
- When you delete your account, the audit-trail record is pseudonymized in place: the foreign-key reference is set to NULL, the IP address and user-agent are NULLed, and a one-way HMAC-SHA-256 pseudonym (
deleted_user_hash) is stored in their place. This pseudonym uses a server-side secret. If we later replace that secret, the superseded secret is retained under our key-management controls for as long as any pseudonym created with it is still retained, so those records remain verifiable. - The pseudonymized record is then retained for 5 years under GDPR Article 17(3)(e) ("for the establishment, exercise or defence of legal claims"). 5 years is chosen to cover the longest of the typical applicable consumer-claim limitation periods (UK 6 years, Italy 10 years for some consumer matters; we use 5 years as the cross-jurisdiction baseline at launch and may extend in specific jurisdictions if required by local law).
- After 5 years, the pseudonymized record is permanently deleted.
The pseudonymized record contains no direct account identifier. Re-associating it with the original account requires additional information protected by our technical and organizational controls. Under GDPR Recital 26, the record remains personal data even though it is not directly identifying.
While your account remains accessible — including during the 30-day account-deletion grace period — you may obtain a copy of your legal-acceptance receipts through Settings → Account → Download My Data. They are included in the export ZIP as legal-receipts.json.
After hard deletion, Settings and the direct account identifiers used by the standard export are no longer available. You may contact support at mineralwild@gmail.com and we will assess the request under applicable law, but we cannot promise that a specific retained receipt can be re-associated with you. An internal old-account identifier, HMAC pseudonym, or key may help us locate or audit a candidate record; none of those items, by itself, verifies the external requester's identity. We may ask for additional identifying or verification information where permitted by applicable law. If we cannot reliably identify or verify that a specific receipt relates to you, we will not disclose that receipt, and we will explain the reason and the applicable follow-up, complaint, or judicial-remedy routes. This operational limit does not by itself waive or extinguish statutory privacy rights.
- GDPR / UK GDPR: Article 11 applies only where the purposes for which we process the retained record do not or no longer require us to identify you and we can demonstrate that we are not in a position to identify you. In that case, Articles 15–20 do not apply to that processing unless you provide additional information enabling identification. If we do not act on the request, we will provide the Article 12(4) notice, including the reason and the right to lodge a complaint with a supervisory authority and seek a judicial remedy. Hard deletion alone does not automatically trigger Article 11.
- CCPA / CPRA, where applicable: a request for a specific legal-acceptance receipt is treated as a request for specific pieces of personal information and requires verification to a reasonably high degree of certainty. If we cannot meet that standard, we will not disclose the specific receipt; we will also assess the request as a categories request and provide or direct you to our general information practices as required.
- PIPL and other applicable laws: we will use the verification, response, and remedy process required by the applicable law rather than applying the GDPR process automatically.
14. Listing-Price Retention
Listing-price records linked to a user or specimen remain personal data, and the three-year cleanup does not apply while either link remains. These records capture a listing or asking price when a specimen leaves the "available" state; they are not verified sale prices.
After both links are removed, we treat the records as de-identified. They retain the mineral identifier, listing amount, currency, status transition, and timestamp. Because those fields may permit re-identification when combined with other information, the records may still constitute personal data and are not treated as anonymous.
A weekly cleanup permanently deletes de-identified listing-price records once their original listing-status transition is more than three years old. Because the three-year period runs from that original transition, a record already older than three years is eligible for deletion on the next weekly cleanup after both links are removed.
15. Account-Deletion Grace Period
Deletion requests for finalized, verified accounts enter a 30-day grace period. During that period, accounts that remain eligible to sign in may cancel through the App; an account that cannot sign in must use the deletion-only support process described in §9. Support cancellation does not restore account access or remove an existing restriction. An unfinished email/password registration that has not verified its email can instead be abandoned immediately after current-password confirmation and does not enter this grace period. After the grace period for a finalized account expires, personally identifiable data is permanently deleted in accordance with §9 (compliant with the CCPA §1798.105 45-day response window). Pseudonymized legal-acceptance records are retained as described in §13. Listing-price records follow the separate retention described in §14.
16. Territory
The App is not available in every region. Where it can be installed is determined by the Apple App Store and Google Play storefronts in which it is listed.
Where the law of a region in which the App is available requires additional privacy disclosures or a separate cross-border-transfer consent, we will publish those disclosures and obtain any consent that law requires.
17. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. For material changes — including changes to the categories of data we collect, the purposes of processing, the legal bases, third-party recipients, retention periods, or your rights — we will notify you with an in-app notice and/or by email at least 30 days before the changes take effect (where reasonably practicable). Your continued use of the App after the effective date constitutes acceptance of the updated policy. If you do not agree, you may delete your account before the effective date.
Where an immediate update is necessary to comply with law, platform-review requirements, or urgent user-safety obligations, we may make the updated policy effective immediately after notice and require in-app re-acceptance before continued use. All other material changes continue to follow the 30-day notice approach described above, where reasonably practicable.
For non-material changes (typo fixes, contact-information updates, restructuring without substantive change), we may publish the update without prior notice.
18. Contact Us
If you have any questions about this Privacy Policy or wish to exercise a data-subject right:
Email: mineralwild@gmail.com Entity: Mineral Wild LLC (a Wyoming limited liability company)
Features, availability, and this Privacy Policy may change over time. We will notify you of material changes as described in §17.