Fairspire Privacy Policy

Software described as of 12 September 2026.
Publication effective date: not yet set. This page can be hosted at a stable public URL once the operator publishes it.

This policy describes what the current Fairspire application actually does. Where something has not been decided, this page says so instead of inventing an answer.

Fairspire is a local-first coin and bullion collection app. Your collection lives on your device. Some optional online features send limited data to Fairspire’s servers and, from there, to the service that performs that feature.

What Fairspire is

Fairspire helps you track coins, bullion, purchase and sale history, notes, and photos on the device you use. You can use the collection without signing in.

If you sign in, you can use online features that are currently gated behind an account: AI coin scanning, Numista catalogue search, and PCGS certification lookup.

Local collection data

Unless you use an online feature described below, the following stay on this device and are not sent to Fairspire servers:

Photos are stored in a separate device-local photo database. Collection backups include portfolios, items, sales, and chart snapshots. Photos and your metals.dev API key are not included in the backup file.

Account deletion does not wipe this on-device collection.

Account information

If you request a sign-in link, Fairspire stores your email address (trimmed and lowercased), an internal user id, a plan id used only to decide which features your account may use, hashes of session and login tokens, and expiration timestamps.

There is no in-app purchase or payment collection today.

The raw session token lives only in an HttpOnly cookie in your browser. The raw magic-link token lives only in the email link until you use it. Fairspire does not store those raw values.

AI scanning

If you scan a coin, the front and back photos for that scan are sent to Fairspire’s scan service, then forwarded to the AI vision provider for analysis.

Fairspire does not keep those scan images or the scan result on its servers after the request finishes. The result is returned to your device so you can decide whether to save anything into your local collection.

Fairspire does keep a spend/accounting record of the scan. That record may temporarily include your opaque user id so monthly AI limits can be enforced. After account deletion, that user id is removed; the dollar totals stay for accounting.

A third-party processor may process the images under its own terms. Fairspire does not claim that provider deletes the images immediately.

Numista searches

If you search or open a catalogue detail, Fairspire sends the search text or catalogue id to Numista through Fairspire’s proxy. Fairspire does not keep a catalogue copy. It stores a per-account monthly usage count, not the search text.

If you choose a result, this device may store the Numista number (N#) you picked on that local item.

Optional Google Sheets import

This feature is optional. It is not Google Sign-In for your Fairspire account.

If you paste a Google Sheets link and connect Google, Fairspire requests temporary, read-only access (spreadsheets.readonly) through Google Identity Services in your browser. Google then returns spreadsheet metadata and cell values for the spreadsheet ID in the link you pasted. That data is processed in this browser and is not uploaded to Fairspire servers.

The access token is kept only in memory for the import wizard. It is not stored in Fairspire settings, inventory, localStorage, or backups. You can disconnect Google; that does not delete items you already imported. After you confirm an import, accepted rows become ordinary local Fairspire inventory.

Google’s OAuth grant technically allows reading Sheets that Google account can access. Fairspire’s product only requests the spreadsheet you paste.

Fairspire’s use of data obtained from Google APIs is limited to providing this import feature and is intended to follow the Google API Services User Data Policy, including Limited Use. Public production use remains blocked until Google sensitive-scope verification, branding, and a published privacy-policy URL are completed. Local and Testing-mode OAuth clients are for development.

Live metal prices

If automatic prices are enabled and the operator has configured the shared feed, Fairspire’s servers request latest metal prices from metals.dev (gold, silver, platinum, and palladium, in USD per troy ounce). You do not need a Fairspire account for that request. Your own metals.dev API key is not transmitted to Fairspire. Fairspire does not send your email, user id, inventory, or a user-supplied key with the price request.

If the operator enables Market Details, Fairspire’s servers may also request reference Bid/Ask quotes from the same metals.dev vendor. That data is informational only. It is not used to value your collection.

If an older version saved a metals.dev key on this device, that key stays on the device and is not uploaded. You can still type metal prices by hand when the live feed is off, unavailable, or stale beyond the server’s limit.

Certification lookups

If you look up a certification number, Fairspire sends that number (currently PCGS only) through Fairspire’s proxy. Fairspire may keep a short-lived in-memory cache of the result on the server process. That cache is not a durable database and is not tied to your account. Your device may save the cert number on a local item if you choose to.

Feedback

If you submit in-app feedback, Fairspire stores a campaign id, a rating, an optional comment, the time it was submitted, and the app version of the server that received it.

Feedback is not linked to your Fairspire account, email address, user ID, or session. Please avoid including personal information in your feedback comment, because the comment is stored as you submit it. IP addresses are used only to limit abuse in memory and are not stored with the feedback.

Technical and security information

Fairspire’s servers briefly see your IP address for rate limiting, request timing, coarse error codes, and AI spend counters. IP addresses are not written to the account, spend, or feedback databases.

Server logs use fixed categories. They are not supposed to include email addresses, tokens, cookies, image bytes, or feedback comments.

Fairspire does not currently include an analytics, advertising, crash-reporting, or tracking SDK.

How information is used

Fairspire uses this information to keep your local collection on your device, sign you in, run the online feature you asked for, enforce feature limits, keep a global AI spend ceiling, receive optional feedback, and protect the service from abuse.

Fairspire does not use this information for advertising, marketing lists, or profiling people across other companies’ apps or websites.

Third-party service providers

When a feature is enabled and you use it, these processors may receive data. Each has its own terms. Fairspire does not control how long those companies keep data. Interface typefaces are self-hosted with the app and are not loaded from Google Fonts.

ServiceWhenWhat they receive
ResendYou request a sign-in linkYour email address and the one-time sign-in URL
OpenAIYou run an AI scanThe two scan images and Fairspire’s analysis prompts
NumistaYou search or open catalogue detailThe search query or type id
PCGSYou look up a certification numberThe certification number
metals.devFairspire fetches live market prices (no account required). Optional reference Bid/Ask if the operator enables Market DetailsFairspire’s server-side latest-price and, if enabled, Bid/Ask requests. Not your email, inventory, or a user-supplied API key
Google SheetsYou choose optional Google Sheets importYour browser sends an OAuth request and then reads the pasted spreadsheet from Google. Fairspire servers do not receive the sheet

Data retention

On your device, collection data remains until you delete it, restore a backup over it, or clear the app’s storage.

Account data stays until you delete the account, or until a session or login token expires. Expired authentication records are periodically removed by the server. That cleanup is not guaranteed at the exact moment of expiry.

AI spend records are kept for accounting. After account deletion, the user id on those rows is cleared. Dollar totals stay.

Numista and Cert Lookup per-account monthly counts are deleted with the account. Counts only — not search text or certification numbers.

Aggregate UTC-day provider-call counts (no user id, no certificate numbers) stay for operator/provider budget accounting. They are not tied to an account and are not deleted when a user deletes their account.

Feedback is stored until an operator defines a retention policy. There is no automatic deletion today.

Account deletion

If you are signed in, Settings → Account → Danger Zone lets you permanently delete your Fairspire account. You must confirm, then type DELETE ACCOUNT.

Fairspire then removes your user row, all sessions, all login tokens, your Numista monthly usage, and your Cert Lookup monthly usage, and removes your user id from historical AI spend rows. It does not change historical dollar totals.

Deletion does not erase the collection, photos, notes, or sales on this device. It does not find or delete previously submitted feedback. It does not erase aggregate global provider-call counts.

After deletion you are signed out. The same email may register later as a new account with a new user id. Old anonymized spend is not attached to that new account.

If account deletion succeeds but spend cleanup cannot finish, the account is still gone. A leftover opaque user id may remain on old spend rows until cleanup is retried. The app will not claim that privacy cleanup fully finished in that rare case.

Security

Fairspire stores login and session secrets only as hashes, sends the session in an HttpOnly cookie, and requires a CSRF header on cookie-authenticated requests. Provider API keys stay on the server and are not shipped in the app bundle.

Selling, advertising, and tracking

Based on the current application, Fairspire does not sell personal information, does not include third-party advertising, does not include analytics or tracking SDKs, and does not track you across other companies’ apps or websites.

Children

Fairspire is a collection tool for coin and bullion records. A minimum age has not been published. That decision must be made before a public store listing.

Your choices

This draft is not a GDPR, CCPA, or similar compliance claim.

Changes

When this policy is published, updates will be posted at the same public URL with a new date.

Contact

A privacy contact email, support email, mailing address, and legal operator name have not been published. They must be filled in before this policy is used for a public or App Store listing.

Until then, use any support channel the operator of your deployment has given you.