This Privacy Policy describes how Thrifteye ("Thrifteye," "we," "us," or "our") collects, uses, and shares information when you use our mobile application (the "App"). By using the App, you agree to the practices described here.
If you have questions, contact us at support@thrifteye.app.
1. What we collect
We have intentionally designed Thrifteye to collect as little personal information as practical. Specifically:
Email address. Used only for sign-in via one-time passcode (OTP). We do not store passwords because we do not use passwords.
Device identifier. When you first open the App, it generates a random identifier (a UUID) that stays on your device. We use this to enforce per-device usage quotas. It is not tied to your hardware advertising ID, IMEI, or any persistent device fingerprint we control. If you reinstall the App, a new identifier is generated.
Usage counters. We store integer counts of how many analyses you have performed in the current month, keyed on your device identifier. This is used to enforce free-tier limits and short-window rate limits.
Photos you submit for analysis. When you tap Analyze, the photos in your tray are transmitted to our backend for processing. We do not retain these photos on our servers. They are forwarded to our AI provider (Anthropic) and discarded as soon as the analysis response is returned to your device. See section 4.
Connection metadata. Like any web service, our backend logs connection metadata (such as IP address, timestamp, and request size) for short retention periods, typically a few days, for security and debugging.
We do not collect: your name, address, phone number, payment information (until paid tiers ship — at which point this Policy will be updated), contacts, location, or any data from sensors other than the camera (when you use it).
2. Information that stays on your device
The App keeps a local history of your past analyses in a database stored on your device. This history is never transmitted to our servers. If you uninstall the App or use the in-app "Clear all history" option, that data is deleted from your device and cannot be recovered.
3. How we share information (data processors)
We rely on a small number of third-party services to operate Thrifteye. These are "data processors" — they handle data on our behalf under their own privacy commitments.
Anthropic, PBC — operates the Claude AI model that analyzes your photos and generates the identification and price estimate. Your photos and a system prompt are sent to Anthropic's API. When the AI uses its web-search capability, search queries derived from your photos may be transmitted to Anthropic's search provider. Anthropic's privacy practices: https://www.anthropic.com/legal/privacy
Supabase, Inc. — provides our backend database, authentication, and Edge Functions. Stores your email (associated with your account), tier (free/paid), and the device-keyed usage counters described in section 1. Privacy: https://supabase.com/privacy
We do not sell or rent your information to anyone. We do not share it for advertising. There are no advertising SDKs in the App.
4. Photos: detail
Because the App's core function is sending images to an AI for analysis, we want to be specific about what happens to them.
Photos are captured on your device using the camera permission you grant.
When you tap Analyze, photos are resized to a maximum 1024-pixel long edge (for cost and latency control) and uploaded to our backend over HTTPS.
Our backend forwards them to Anthropic's API along with a system prompt and any required tool configuration. We do not write them to a database or persistent storage on our backend.
Anthropic processes the photos to generate the response. Per Anthropic's API terms, API inputs are not used to train their models by default.
Once the streaming response is complete, the photos in transit are released. The only place they persist is in your device's local history (section 2), unless you delete them there.
If you do not want to send a particular photo to a third-party AI service, do not tap Analyze on that photo.
5. How long we keep things
Account record (email, tier): until you delete your account.
Device usage counters: retained even if you delete your account. These are not personal data — they are integer counts keyed on a randomly generated identifier — and clearing them on deletion would let abusers reset their quota by deleting and recreating accounts.
Photos on our backend: not retained (forwarded and dropped).
Server logs: typically a few days.
6. Your rights
You can:
Access the personal data we hold about you (just your email and tier — nothing else is associated with your account on our side). Email us at support@thrifteye.app.
Delete your account. The App has a built-in "Delete account" option in the Account menu. This permanently removes your authentication record and profile (tier), and clears your local history. As noted in section 5, the device-keyed usage counters remain.
Export your data. Email us at support@thrifteye.app and we will send you the data on file (which is small).
Opt out of future updates by uninstalling the App.
If you are in the European Economic Area, the United Kingdom, or another jurisdiction with applicable data-protection laws (such as GDPR), you have additional rights including correction, restriction of processing, and the right to lodge a complaint with your local supervisory authority.
If you are a California resident, you have rights under the CCPA/CPRA including the right to know, the right to delete, and the right to opt out of sale (we do not sell). To exercise any of these rights, email support@thrifteye.app.
7. Children
Thrifteye is not directed to children under 13 and we do not knowingly collect personal information from anyone under 13. If you believe a child has provided us with personal information, contact support@thrifteye.app and we will delete it promptly.
8. Security
We use standard practices: HTTPS for all transit, OTP rather than passwords for authentication, and a minimal data-collection footprint. No system is perfectly secure. If we discover a security incident affecting your account, we will notify you at the email address on file as required by applicable law.
9. International users
Thrifteye is operated from the United States. If you use the App from outside the US, your information will be transferred to and processed in the US and in the regions used by our processors (which may include the EU and other regions). By using the App you consent to this transfer.
10. Changes
We may update this Privacy Policy. The "Effective date" at the top will reflect the latest version. Material changes will be communicated through the App. Continued use after changes take effect constitutes acceptance.