Legal
Gold Vantage privacy policy
Effective date: To be confirmed before public launch
Gold Vantage can be used without an account. This policy explains what happens to information in the Gold Vantage mobile apps and their supporting services.
Who we are
Gold Vantage is provided by [Controller legal name — to be confirmed], [Controller postal address — to be confirmed]. For privacy questions, requests or complaints, email privacy@goldvantage.app. For general or account support, email support@goldvantage.app.
Information we use
Information on your device. Saved Vault records, jewellery details, photos, receipts and negotiations are stored in each app’s private device storage. Guest preferences, app-lock choices, analytics consent and other device-specific state also remain local. The local database and files remain the authoritative copy and stay until you delete them, clear the app’s storage or uninstall the app. The optional Cloud Vault and Add with AI exceptions are described next.
Optional Cloud Vault. An eligible signed-in user may explicitly enable structured Cloud Vault sync. Gold Vantage then sends Vault items and collections to Railway for cross-device sync and recovery. The service encrypts that structured data before storing it in Supabase, but the authorised backend can decrypt the minimum records needed to provide the service; this is not end-to-end or zero-knowledge encryption. Android may also sync encrypted photo and receipt objects when its separate attachment capability is enabled. Cloud attachment transfer is unavailable on iOS. Negotiations, guest/device state and unsynchronised local files are not uploaded by Cloud Vault. Disabling or losing the capability pauses transfer without silently deleting the local authoritative copy.
Optional Add with AI. In the current Android app, if a signed-in user explicitly submits jewellery or receipt images to Add with AI, Gold Vantage sends temporary, resized and metadata-stripped copies through Railway to OpenAI to extract candidate item details for review. Add with AI is unavailable on iOS. Saved Vault records are not uploaded by this action. Railway does not retain the image or full receipt text after processing. Sanitized candidate results are retained for no more than 24 hours and a safe request ledger for no more than 30 days; account rate state remains until the account is deleted. OpenAI receives the request with storage disabled and does not use API content to train models by default, although standard abuse-monitoring retention may apply. Our lawful bases are providing the feature requested and preventing misuse. Do not submit evidence you do not have the right to process.
If you enable app lock, Android or iOS asks the operating system to check an enrolled biometric or device credential. Gold Vantage receives only the result of that check; it does not receive or store biometric data.
Optional account. If you create an account, Supabase processes your email address, user ID, password-derived credentials, session tokens and related security information. Plain-text passwords are not retained. Gold Vantage and Railway process your user ID, entitlement state and portable preferences so choices such as purchase jurisdiction, display currency, weight unit, tax overrides, valuation method and appearance can follow you between devices and future sign-ins. If you create a price alert in the current Android flow, they also process its above-or-below direction, target, currency and weight-unit snapshot, one-time or repeating choice, paused/status state and timestamps. The lawful bases are performance of our service agreement and our legitimate interest in preventing misuse.
Optional Android subscription. If you choose to buy, restore or verify Premium on Android, the app supplies your Supabase user ID to RevenueCat as the subscription customer identifier. RevenueCat and Google Play process the selected product, purchase and subscription state, and Railway mirrors only the verified entitlement and its expiry for access control. Gold Vantage does not receive your full card or bank details. iOS billing is not currently available. The lawful basis is performing and managing the subscription you request.
Optional price-alert notifications. Price-alert creation and notifying delivery are currently Android-only and available only to registered users. The iPhone app can consume shared account alert/inbox data but disables creation because APNs/native registration is not implemented. On Android, if you choose to receive an alert on that device, Google Firebase Cloud Messaging processes a Firebase Installation ID, and Gold Vantage and Railway process that identifier with a random account/device binding and app version so the requested notification can be delivered securely. A versioned Android notification includes the alert direction, threshold, current public market price, currency, unit and trigger time. Gold Vantage also keeps account-synchronised creation and trigger history, including whether each event has been read, for 90 days so the notification centre remains consistent across signed-in devices. Repeating alerts can send a new notification after the market returns to the other side of the threshold and crosses it again. It does not include your email address, account ID, Vault or jewellery information, attachments or sign-in credentials. Android asks for notification permission when you first save an alert. You can pause, edit or delete an account alert in the app. You can separately disable permission or the Price alerts channel in Android settings; account alerts and notification-centre history remain saved for their stated retention periods. Signing out attempts immediate server and Firebase unregistration and always clears the local binding so the app rejects later messages for it. If a remote removal fails, the server registration can remain; records older than 270 days are excluded from new deliveries but are not automatically deleted. Deleting the account deletes its alerts, notification history, registrations and delivery records. Our lawful basis is to provide the alert you request.
Prices and service security. When the app requests metal prices, the price service receives the requested currency, metal or chart range, IP address, request time and ordinary network metadata. We use this to return prices, keep the service reliable and investigate abuse. The lawful bases are performance of our service agreement and our legitimate interest in operating a secure service. Vault information is never included in these requests.
Optional analytics. In the current Android app, if you choose Allow, Firebase Analytics receives limited app-use and lifecycle events, a random app-instance identifier, basic app and device information, and an approximate country or region derived from a masked IP address. iOS analytics is unavailable. Completed negotiations may include rounded maker-fee percentages and percentage differences from the seller’s first price. Gold Vantage does not send account identity, jewellery records, weights, quote or payment amounts, merchant details, photos, receipts, sign-in details, URLs or free text. The lawful basis is your consent. You can withdraw it at any time in Settings. This stops future collection and resets the local analytics identifier, but does not delete events already uploaded.
Messages to us. If you contact support or make a privacy request, we use your contact details and message to respond, resolve the issue and meet legal obligations.
Service providers and international transfers
We use Supabase for accounts and account data; Railway for service hosting and technical logs; RevenueCat and Google Play for Android subscription processing and verification; OpenAI for evidence you explicitly submit to Add with AI; and Google Firebase for Android price-alert delivery you request and analytics you allow. iOS billing, push, analytics and Add with AI are not currently configured. These providers process information for us under contract or under the applicable store terms. We do not sell personal information, use it for advertising or allow these providers to use Gold Vantage data for advertising.
These providers may process information outside the UK. Where required, we rely on UK adequacy regulations or approved contractual safeguards such as the UK International Data Transfer Agreement or UK Addendum. Email privacy@goldvantage.app to request information about the relevant safeguard.
How long we keep information
- Account, entitlement, portable-settings, price-alert and opted-in structured Cloud Vault data: while the account is open or until the applicable record or Cloud Vault is deleted; deleted from live systems when the account is deleted. Encrypted Supabase backups expire within 7 days.
- Android subscription data: the RevenueCat customer-erasure request must succeed before Gold Vantage deletes the account. Deletion does not cancel the Google Play subscription, and Google Play retains store records under its own terms and legal obligations.
- Android Cloud Vault attachment ciphertext: until the attachment, Cloud Vault or account is deleted. It becomes unavailable for download immediately after deletion is requested; encrypted objects remain counted until the storage service confirms deletion, and backup expiry still applies.
- Price-alert installation registration: until successful unregistration, invalidation or account deletion. Sign-out attempts immediate removal and clears the local binding. If remote removal fails, records older than 270 days are excluded from new deliveries but are not automatically deleted.
- Price-alert delivery data: a queued Firebase message expires after no more than 24 hours. Railway retains the versioned delivery row—including the binding, direction, threshold, current public market amount, currency, unit and trigger time—after terminal delivery until account deletion.
- Account notification-centre history and read state: 90 days, or immediately on account deletion.
- Add with AI images: no Gold Vantage image storage after processing. Sanitized candidates: no more than 24 hours. Safe request ledger: no more than 30 days. OpenAI standard abuse-monitoring retention may apply.
- Firebase event-level data: 2 months. Anonymous aggregated reports may remain longer.
- Railway technical logs: no more than 30 days.
- Support and privacy correspondence: only as long as needed to resolve the matter and meet legal obligations.
Your choices and rights
Accounts, Cloud Vault, price-alert notifications and analytics are optional. Signing out attempts to unregister supported account-bound work and clears its local binding, but does not delete the account’s portable preferences, saved alerts or recent notification history. If remote unregistration fails, the server record is retained as described above. You can delete alerts in Settings. Android and signed iPhone Debug builds support in-app account deletion; users on either platform can also request deletion through our account-deletion page. Account deletion removes the account’s synced preferences, Cloud Vault, alerts, notification history, registrations and delivery records. You may separately choose coordinated erasure of app-owned information on that device. iPhone Release authentication remains disabled pending App Store release work.
Subject to legal conditions, you have rights to access, correct, erase, restrict or receive your personal information and to withdraw consent.
Your right to object. You may object to processing based on legitimate interests. Email privacy@goldvantage.app to exercise a right or complain. We will investigate and explain the outcome.
If you remain dissatisfied, you can complain to the Information Commissioner’s Office.
Security and changes
Gold Vantage uses app-private storage and HTTPS for network traffic. Android cloud backup and device-to-device transfer are disabled, and session/PKCE material is protected by Android Keystore-backed encryption. iOS keeps the local database, preferences and attachments in backup-excluded protected Application Support storage; session and PKCE values use separate non-synchronising, device-only Keychain items. No security measure can remove every risk.
We will update this policy and its effective date when our practices change. We will ask again before materially expanding consent-based analytics.