Lithico Privacy Policy
Last updated: 6 August 2026
This page and docs/privacy-policy.md in the Lithico repository are edited together — if you spot a difference between them, tell us and we'll fix it.
Lithico is a rock, crystal and mineral identification app. This policy explains what we collect, why, and what control you have over it.
Who we are
Lithico is operated by an individual developer in Australia. Contact: pfolvig@gmail.com. This policy is governed by the laws of Australia.
Anonymous by default
You don't need to sign up to scan a rock. On first launch, Lithico creates an anonymous account for you (via Supabase Auth) so your scans and collection can sync to your device without asking for an email address or a password. If you later choose to link an email, Apple, or Google sign-in from Settings, your existing anonymous history carries over to that identity. Nothing about using Lithico requires you to give us your name, email, or any other identifying detail unless you choose to link an account.
What a scan collects
When you identify a rock, Lithico uploads:
- The photo you take or choose. It's sent to our identification service to generate a result and is stored so you can revisit the scan and add it to your collection.
- Location, only if you turn it on. The location toggle on the scan screen is off by default. If you switch it on, we capture your device's GPS coordinates at the time of the scan and store them with that scan. You can leave it off and identification works exactly the same.
We do not collect contacts, microphone audio, or any other device data, and we do not read data from other apps. Location is collected only for the scans where you have switched the location toggle on — see “Location” below — and never otherwise.
How photos are used
Your photos are used to identify your rock and to display it back to you in your collection. We do not sell your photos, and we do not use them to train identification models unless you explicitly opt in (see below).
Contribution opt-in. After a confirmed identification, you may be asked whether to add that specimen to the Lithico reference library. This is off by default and only ever offered for confirmed results. If you say yes — either in that prompt or by turning on the "Contribute to the reference library" toggle in Settings — the photo and test results for the specimens you choose are credited to your account and may be used to improve identification, including as reference material for future identification requests from other users. You can turn this off at any time in Settings; turning it off stops future contributions but does not retroactively withdraw material already contributed.
Storage and retention
Photos and scan data are stored in our database and file storage (provided by Supabase) for as long as your account exists, or until you delete them. There is no automatic deletion timer — we keep what you keep.
Your rights: export and deletion
From Settings, you can at any time:
- Export your data. Download your collection, scan history, and test results in a plain file you can keep or move elsewhere.
- Delete a photo or a scan. Removing an item from your collection deletes its stored photo along with the database record — not just the reference to it.
- Delete your account. This permanently removes your profile, scans, collection, test answers, and stored photos. It cannot be undone.
Step-by-step instructions, and how to ask by email if you no longer have the app: Delete your account.
Subscriptions
Lithico's paid tier is billed and managed through RevenueCat, which relays purchase and subscription status from the Apple App Store or Google Play. RevenueCat receives a device identifier and your purchase/subscription events; it does not receive your rock photos or collection data. We never see your payment details — Apple and Google handle billing directly.
No ads, no tracking, no data sale
Lithico has no advertising, no third-party analytics SDKs, and no tracking pixels. We do not sell your data to anyone, for any purpose. The only outside services involved in running the app are:
- Supabase — hosts the database, file storage, and authentication.
- OpenAI — processes scan photos server-side to generate an identification result. Photos are sent for this purpose only.
- RevenueCat — manages subscription status, as described above.
Changes to this policy
If this policy changes, we'll update the date at the top and the in-app version linked from Settings. Material changes will be called out in the app.
Contact
Questions, requests, or concerns about your data: pfolvig@gmail.com.