Buck is a coin and banknote identifier. You take or import a photo, Buck tells you what the item is, shows an estimated market value or value range, and lets you keep a personal collection. We built Buck to do this with as little personal data as possible. Buck has no user accounts, runs no advertising or analytics SDKs, and does not sell your data or track you across other apps or websites.
This policy is written to be accurate to how Buck works today, including the optional auto-renewing subscription offered through Apple In-App Purchase. It also remains accurate for one feature that is planned but not yet shipped: an optional anonymous device identity. Where a section describes the anonymous device identity as something that "may" apply or that applies "if and when" it ships, that feature is not active in the current version of the App. We will update the effective date above when a planned feature goes live.
1. Who we are and who controls your data
The data controller responsible for your personal data under the EU and UK General Data Protection Regulation (GDPR) is:
Emanuele Pio Totaro
Italy
Contact for privacy matters: privacy@getbuckapp.com
If you are in the European Economic Area, the United Kingdom, or another region with data protection authorities, you also have the right to contact your local supervisory authority (see Section 11, "Your rights").
2. A quick summary
- No account. You do not sign up, log in, or create a profile to use Buck.
- What leaves your device. The photo or photos you choose to scan are sent to our recognition backend so the item can be identified. Our backend passes the image to Google Gemini, an artificial intelligence (AI) service we use as a sub-processor, which returns the identity of the item only.
- Images are not kept in the recognition pipeline. Our recognition backend processes your image to return a result and does not keep a database of users or build a profile of you. A copy of scanned images may appear in our private operational quality logs, which only the developer can access and which you can ask us to delete (see Sections 3.4, 5, and 8).
- Local storage only. Your collection and app data are stored on your device using Apple's standard on-device storage (UserDefaults). They are not uploaded to us.
- No selling, no tracking. We do not sell your personal data. We do not use it for cross-app or cross-site advertising. Buck does not show the App Tracking Transparency prompt because Buck does not track you.
- Apple handles payments. If you purchase a subscription, Apple processes the payment. We never see your full card number or billing details.
The rest of this policy gives the detail that Apple, the GDPR, and the California Consumer Privacy Act (CCPA/CPRA) expect.
3. What data we collect, and why
3.1 Camera images you capture
When you use the in-app scanner, the App accesses your device camera so you can photograph a coin or banknote. Buck requests camera permission through the standard iOS prompt before any camera access. The captured image is used to identify the item and to display an estimated value. See Section 5 for exactly how the image is processed and Section 6 for the third parties involved.
- Purpose: to identify the coin or banknote in the photo and show an estimated value or value range.
- Legal basis (GDPR): performance of a contract (Article 6(1)(b)). Scanning is the core function you ask Buck to perform.
3.2 Photos you submit from your photo library
Instead of using the camera, you can choose an existing photo using the iOS photo picker. The system photo picker hands Buck only the specific image you select. Buck does not get access to your wider photo library, and iOS does not require a photo library permission prompt for this. The selected image is then processed the same way as a camera capture (Section 5).
- Purpose: the same as camera images: identification and value estimation.
- Legal basis (GDPR): performance of a contract (Article 6(1)(b)).
A note about what can be in a photo: an image you submit may contain more than the coin or banknote (for example, a hand, a surface, or background objects). Please photograph only the item you want identified, and avoid including faces, documents, or other sensitive material in the frame.
3.3 Your collection and app preferences (stored on your device)
Buck saves your activity locally on your device using Apple's standard on-device storage. This currently includes a snapshot of the in-app finds feed and similar app state. This information stays on your device. It is not an account, it is not uploaded to our servers, and we cannot read it remotely. Deleting the App removes this local data (see Section 8).
- Purpose: to remember your collection and app state between sessions and let the App work offline.
- Legal basis (GDPR): performance of a contract (Article 6(1)(b)). This data is processed on your device, not by us.
3.4 Device, diagnostic, and usage information
Buck does not embed any third-party analytics, advertising, attribution, or crash-reporting software development kits (SDKs). We do run our own lightweight, first-party usage logging so we can see that the App works and improve it. This logging records app events (for example that the App was opened, that a scan was completed, or that the paywall was shown) together with basic technical context: your device model, iOS version, App version, device language, an approximate city-level location derived from the IP address of the request, and a random installation identifier that the App generates on first launch. This identifier is not your name, email, phone number, Apple ID, or advertising identifier, and it cannot be used to identify you across other companies' apps or websites. Scan images may be included in these operational logs so we can monitor and improve recognition quality; see Section 5 and Section 8.
These operational logs are delivered through our backend to a private, access-restricted channel and internal analytics store that only the developer can read. They are used solely to operate, debug, and improve the Service. They are never used for advertising, never sold, and never shared with data brokers.
When the App contacts our recognition backend, the connection also necessarily involves basic technical information that is part of any internet request, such as your device's IP address and a standard request timestamp. We use this to operate the Service securely, including rate limiting and abuse prevention, so that the recognition endpoint stays available and is not misused. We do not use it to build an advertising profile.
If you have enabled Apple's optional sharing of app analytics and diagnostics at the iOS level, Apple may provide us with aggregated, non-identifying crash and usage statistics through App Store Connect. This is controlled by you in your device Settings and is governed by Apple's privacy policy.
- Purpose: to keep the Service running, secure, and reliable.
- Legal basis (GDPR): legitimate interests (Article 6(1)(f)) in operating, securing, and protecting the Service against abuse.
3.5 Subscription and purchase status
Buck offers an optional auto-renewing subscription with a free trial. The purchase is made through Apple's In-App Purchase system. Apple processes the transaction and your payment. We do not receive or store your credit card number, your full billing address, or other payment card details.
Through Apple's StoreKit framework, the App can learn whether you currently hold an active subscription or trial, so it can unlock the corresponding features. If we later keep a record of subscription status on our servers to deliver features across your devices, that record will be limited to subscription state and will not include your payment card data.
- Purpose: to unlock and manage subscription features you have paid for.
- Legal basis (GDPR): performance of a contract (Article 6(1)(b)).
3.6 Messages you send us for support
If you email us (for example at support@getbuckapp.com or privacy@getbuckapp.com), we receive your email address and whatever you choose to put in your message, so we can reply and help you. We do not require you to contact us, and you control what you include.
- Purpose: to respond to your questions, support requests, and rights requests.
- Legal basis (GDPR): legitimate interests (Article 6(1)(f)) in providing support, and compliance with a legal obligation (Article 6(1)(c)) when handling a data rights request.
3.7 Anonymous device identity (planned feature)
Buck may in the future introduce an optional anonymous device identity to power community features such as a leaderboard. If and when this ships, it is designed to use Apple's App Attest, which lets us confirm a request comes from a genuine instance of the App without identifying you personally. An anonymous device identifier is not your name, your email, or your Apple ID, and it is not used to track you across other companies' apps or websites. If we introduce this feature, we will update this policy before it goes live and, where required, ask for your consent and provide an in-app way to delete the associated data.
- Purpose: to enable optional community features while keeping you anonymous.
- Legal basis (GDPR): consent (Article 6(1)(a)) where required, otherwise legitimate interests (Article 6(1)(f)) in providing the requested feature.
4. What we do not collect
To be clear, Buck does not:
- require an account, username, password, or social login;
- collect your name, postal address, date of birth, or government ID;
- access your contacts, microphone, calendar, health data, or precise location;
- use GPS or Core Location (any "near you" content in the App that is not yet backed by real location data is illustrative, not based on your location);
- include advertising, analytics, attribution, or third-party tracking SDKs;
- show the App Tracking Transparency prompt, because Buck does not track you;
- sell or rent your personal data to anyone.
5. How your images are processed
This is the most important section, so we describe it step by step.
- You capture a photo with the camera or pick one from your library.
- The App sends the image to our recognition backend over an encrypted (HTTPS) connection. The image is transmitted so it can be identified.
- Our recognition backend forwards the image to Google Gemini, an AI service we use as a sub-processor, using a server-side key. Your device never holds or sends that key, and the App does not talk to Google directly.
- Google Gemini returns identification details about the item, such as country, denomination, year, mint mark, variety, name, and a confidence indicator. Buck uses only the identity. Any value or grade produced by the AI model is discarded; Buck does not rely on the AI for value.
- The App displays the result to you.
Retention of images on our side. Our recognition backend is a stateless proxy for the identification step: it does not keep a database of users and does not retain the image in the recognition pipeline after the request has been served. Separately, a copy of the scanned image may be recorded in our private operational logs (Section 3.4) so we can monitor and improve recognition quality. These logs are access-restricted to the developer, are never used for advertising, and you can ask us to delete them at any time by writing to privacy@getbuckapp.com.
Estimated value. Buck's value figures are estimates intended to help hobbyists, not a professional appraisal, an authentication, a grading, or financial or investment advice. Actual value depends on condition, grade, authenticity, demand, and the specific buyer. The value pipeline that draws on real market sales data is being rolled out; until it is fully live for a given item, the App will tell you honestly that a value is being checked or is not yet available rather than present a made-up figure.
6. Third parties and sub-processors
Buck shares data with a small, fixed set of service providers who act on our instructions. We do not sell your data to any of them or to anyone else.
| Provider | Role | What it receives | Why |
|---|---|---|---|
| Google (Google Gemini AI) | AI sub-processor for recognition | The image you scan, at the moment of a scan | To identify the coin or banknote in the photo |
| Apple | App distribution and subscription payment processing | App Store interactions and, if you subscribe, your purchase transaction (payment handled entirely by Apple) | To deliver the App and process in-app purchases |
| Hetzner Online GmbH | Hosting and infrastructure for our recognition backend (servers located in Germany, EU) | Network traffic needed to route and serve recognition requests (for example IP address and request metadata) | To run, secure, and scale the Service |
| RevenueCat, Inc. | Subscription management | A random app user identifier and your Apple purchase information (product, price, subscription status); never your payment card details | To reliably unlock and manage your subscription and free trial |
| Telegram (message relay) | Delivery channel for our private operational logs | The operational log messages described in Section 3.4 (app events, device context, approximate location, and scan images where noted), posted by our backend to a private channel readable only by the developer | To monitor that the Service works correctly and to improve recognition quality |
About the AI sub-processor. Because your photos are shared with a third-party AI service (Google Gemini) to perform identification, we disclose this to you and, where required, ask for your permission in the App before the first image is sent. Google processes images as our sub-processor to return a result. We do not permit the use of your images to target advertising to you. Google's handling of data provided through its AI services is governed by Google's own terms and privacy documentation.
7. How we share data (and how we do not)
- We do not sell your personal data. We have not sold and do not sell personal data, and we do not "share" it for cross-context behavioral advertising as those terms are defined under California law.
- No advertising or tracking. We do not disclose your data to advertising networks or data brokers.
- Service providers only. We disclose data only to the sub-processors listed in Section 6, only to operate the Service, and only under terms that require them to protect it.
- Legal and safety. We may disclose information if required by law, legal process, or a valid government request, or where necessary to protect the rights, safety, security, or property of Buck, our users, or the public.
- Business transfers. If Buck is involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction, subject to this policy.
8. Data retention
- Images: not retained by our recognition backend after a request is served. See Section 6 regarding the AI sub-processor's own handling. Copies of scanned images kept in our private operational quality logs (Section 3.4) are periodically purged and are deleted on request at any time.
- Operational usage logs: app event logs and the random installation identifier are kept only as long as needed to operate and improve the Service, and are deleted or anonymized on request.
- On-device data (your collection and preferences): kept on your device until you delete it within the App or delete the App. We do not hold a copy.
- Technical and security logs: any request metadata used for security and rate limiting is kept only for as long as needed for those purposes and then deleted or aggregated.
- Support messages: kept for as long as needed to handle your request and to keep a reasonable record of support history, then deleted.
- Subscription status: if we store subscription state, it is kept only while needed to provide the subscription and to meet legal, tax, and accounting obligations.
9. Security
We protect data with measures appropriate to its sensitivity, including:
- encrypted transport: communication between the App and our backend uses HTTPS;
- a server-side AI key that is never shipped in the App, so it cannot be extracted from your device;
- a stateless recognition backend that does not build a store of your images;
- rate limiting and abuse prevention to protect the Service.
No method of transmission or storage is completely secure, so we cannot guarantee absolute security, but we work to protect your information and to limit what we collect in the first place.
10. Children's privacy
Buck is rated for general audiences (Apple age rating 4+) and contains age-appropriate content about coins, banknotes, and collecting. The App is not directed to children, and we do not knowingly collect personal data from children under 13, or under the minimum age of digital consent in your country (which can be up to 16 in parts of the EEA). If you believe a child has provided us personal data, contact us at privacy@getbuckapp.com and we will delete it.
11. Your rights
Depending on where you live, you may have some or all of the following rights:
- Access: ask what personal data we hold about you.
- Correction: ask us to correct inaccurate data.
- Deletion: ask us to delete your personal data ("right to be forgotten").
- Portability: ask for a copy of data you provided in a portable format.
- Restriction and objection: ask us to limit or stop certain processing, including processing based on legitimate interests.
- Withdraw consent: where we rely on consent, withdraw it at any time.
- Non-discrimination (California): you will not be treated differently for exercising your privacy rights, and the value of the Service to you will not change because you exercised them.
Because Buck has no account and does not store your images or build a profile of you, much of your data simply never leaves your device, and there is usually no server-side personal profile for us to retrieve. Most of your information lives in the App on your phone and is under your direct control.
How to exercise your rights and delete your data
- Local data: to delete your collection and app data, delete it within the App where the option is provided, or delete the App from your device. This removes the data stored locally on your phone.
- Server-side and support requests: to make any access, deletion, or other rights request, email privacy@getbuckapp.com. We will respond within the time required by applicable law (for example, generally within one month under the GDPR). We may need to verify your request, for example by asking you to confirm it from the same email address you used to contact us.
- Subscription: if you subscribe, you manage and cancel your subscription through your Apple ID in the iOS Settings or App Store. To request deletion of any subscription record we may hold, contact privacy@getbuckapp.com.
- Anonymous device identity (planned): if and when this feature ships, the App will provide an in-app way to delete the data associated with it, and you can also contact privacy@getbuckapp.com.
If we ever introduce an account, we will also provide an in-app way to delete that account and its associated data directly from within the App, as Apple requires.
12. International data transfers
We are based in, and operate the Service from, Italy, and our sub-processors (including Google and Apple) may process data in the United States and other countries. If you are in the EEA, the UK, or Switzerland, this means your information may be transferred outside your home region to countries that may not provide the same level of data protection.
Where we make such transfers, we rely on appropriate safeguards required by law, such as the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, and, where applicable, providers' approved data transfer frameworks. You can contact us at privacy@getbuckapp.com for more information about these safeguards.
13. Cookies and our website
The Buck App does not use cookies. If our website at getbuckapp.com uses cookies or similar technologies (for example, for basic site functionality or aggregate visit statistics), that use will be described on the website itself. This policy covers the App and the recognition Service.
14. Changes to this policy
We may update this Privacy Policy from time to time, for example when a planned feature such as the anonymous device identity goes live, or when we add a new sub-processor. When we make a material change, we will update the "Effective date" at the top and, where appropriate, notify you within the App. Your continued use of Buck after an update means you accept the revised policy.
15. Contact us
Questions, requests, or concerns about your privacy:
- Privacy: privacy@getbuckapp.com
- General support: support@getbuckapp.com
- Data controller: Emanuele Pio Totaro, Italy
We will do our best to resolve any concern you raise. If you are in the EEA or the UK and are not satisfied with our response, you may lodge a complaint with your local data protection supervisory authority.