RockLens Privacy Policy
Effective July 21, 2026
RockLens identifies rocks, crystals, gems, and gemstone jewelry from photos. We do not sell personal information, use advertising trackers, or build advertising profiles.
Information RockLens processes
- Scan photos and locale: Photos you choose to scan, together with your language/locale, are sent through our Cloudflare Worker to the Google Gemini API to produce an identification.
- Device and quota data: A random Keychain-backed device identifier, quota counters, recent scan identifiers, and up to 20 recent text identification results are stored by the Worker to enforce limits and safely replay a lost network response. Replay identifiers and text results are deleted after 48 hours. The Worker does not persist scan photos.
- Purchases: RevenueCat processes purchase and entitlement information. RockLens uses the random device identifier as its RevenueCat app-user ID and sends it to the Worker to verify premium access without multiplying device quotas.
- Apple Ads attribution: If you install RockLens after tapping an Apple ad, Apple AdServices creates a short-lived attribution token on your device. The RevenueCat SDK sends that token to RevenueCat, which receives the standard attribution record from Apple. That record can identify the attribution source and the campaign, ad group, and keyword that led you to RockLens. RevenueCat links it to the random app-user ID and your purchase history so we can measure campaign and subscription analytics. RockLens does not store or receive the token, does not send it to our Worker or TelemetryDeck, and does not use it for cross-company tracking.
- Product analytics: RockLens may send coarse product-interaction events to TelemetryDeck. Events use stable categories rather than raw SDK error text and are not used for advertising tracking.
- Location: Saved specimen coordinates remain stored on your device and are not uploaded to RockLens, its Worker, or Google Gemini. Displaying or opening a specimen map sends the visible map area and map interactions to Apple Maps under Apple's privacy terms.
- Support: A Support ID is derived from the retained device identifier. It may be included in an email you choose to send and, when correlation is enabled, in selected operational failure logs retained for no more than 30 days. It identifies this app installation, is not authentication, and is not used for advertising or tracking. Delete All preserves the underlying quota identity and Support ID.
- Scan operations: When enabled, Cloudflare stores a Support-ID-linked history for up to 30 days containing scan status, tier, language, up to three candidate names and confidence levels, retry and failure details, timing, token counts, and model version. Photos, prompts, and full responses are not stored. Anonymous daily activity totals are kept for up to 397 days. Named operators may view this history for support and reliability. You may request access or deletion using your exact Support ID; this deletes linked history but does not reset quota identity.
How information is used
We use this information to identify specimens, return and recover results, enforce usage limits, verify subscriptions, diagnose reliability, and improve the app.
Storage and your choices
Your saved collection, notes, photos, and optional locations remain on your device until you delete them. Settings lets you export the collection and delete all on-device RockLens data. Worker replay data expires after 48 hours. Lifetime free-scan and daily quota counters remain associated with the random device identifier so deleting local data cannot reset limits.
Service providers
RockLens uses Cloudflare for the API gateway and quota storage, Google Gemini for image analysis, RevenueCat for subscriptions, TelemetryDeck for privacy-focused product analytics, Apple Maps for saved-location maps, and Apple AdServices (Apple Ads) for install and campaign attribution. Their processing is governed by their applicable terms and privacy commitments.
Google Gemini data handling
RockLens uses an authorized paid Gemini API project for its approved audience and launch regions. For Gemini API Paid Services, Google states that prompts, uploaded files such as scan images, and responses are not used to improve Google products.
Google may retain prompts and responses for a limited period for abuse monitoring and legal or regulatory disclosures. RockLens does not claim zero data retention without project approval and compatible features. The RockLens Worker does not persist scan photos; replay identifiers and text results expire after 48 hours.
Contact
For privacy questions, email rocklens@spacewa.lk.