Privacy Policy
Last updated: August 3, 2026
1. Introduction
Lustre ("we," "us," or "our") builds the Lustre mobile application ("App"), an AI jewelry identifier and value-estimation tool for iPhone. This Privacy Policy explains what information the App handles, why, who else touches it, and what control you have over it.
We designed Lustre to need as little about you as possible. There are no accounts, no sign-up form, and no profile. You open the App and start identifying pieces. Nothing in the App asks for your name, your email address, your phone number, or your location.
By downloading, installing, or using the App, you agree to the practices described in this policy. If you do not agree, please uninstall the App and stop using it.
2. Information We Collect
2.1 Information We Do NOT Collect
To be explicit about the categories people worry about most, the App does not collect any of the following:
- Your name, username, or any other personal identifier you would recognise as yours.
- Your email address, phone number, or postal address.
- Your precise or approximate device location. Lustre never requests location permission, and the pieces you identify are not geotagged by us.
- Your contacts, calendar, health data, messages, call history, or browsing history.
- Advertising identifiers (IDFA), cross-app tracking identifiers, or any data used to track you across apps and websites owned by other companies. The App contains no advertising SDKs.
- Payment card numbers, bank details, or any other financial credentials.
- Any inventory, schedule, or valuation of what you own beyond what stays on your own device.
We do not sell personal data, and we do not share it for cross-context behavioural advertising. We never have, and the App is not built in a way that would let us.
2.2 Photos, Camera and Photo Library Data
Identifying a piece of jewelry requires a photo, so a photo is the one substantial thing the App sends off your device.
You can supply that photo in two ways. You can capture it with the camera inside the App, or you can select an existing image from your photo library using the iOS photo picker. Both routes lead to the same place: the App uploads the image over an encrypted HTTPS connection to our backend, which runs as a Supabase Edge Function. That function forwards the image to Google Gemini (operated by Google LLC) for AI analysis. Gemini returns a structured appraisal, our backend passes it back to your device, and the App renders the result.
Your photo is processed transiently for the sole purpose of producing that appraisal. We do not retain your photos after the analysis completes, we do not build a photo library on our servers, and we do not use your photos to train models of our own.
Separately, and entirely on your device, the App saves a copy of the photo alongside a piece you choose to keep, so your Vault has something to show. That copy never leaves your iPhone unless you deliberately share it yourself, and it is deleted when you delete the App.
Camera access and photo library access are both permissions you grant through iOS, and you can withdraw either one at any time in the iOS Settings app. Withdrawing camera access stops the App from capturing new photos; withdrawing photo library access stops you from importing existing ones. Neither affects what is already saved locally, and neither grants us any access to the rest of your photo library: the iOS picker hands the App the single image you choose and nothing else.
2.3 Anonymous Identity
Our backend needs some way to tell one installation from another so it can apply rate limits fairly and keep the service available. To do that without knowing who you are, the App creates an anonymous session with Supabase (operated by Supabase Inc.) the first time it needs one.
That session consists of a per-install anonymous identifier and a session token. Both are stored in the iOS Keychain on your device and refreshed automatically as they expire. The identifier is generated randomly. It is not derived from your Apple ID, your device serial number, your phone number, or any other real-world identity, and it is not linked to you as a person.
If you delete and reinstall the App, a new anonymous identity is created and the previous one becomes an orphan record with nothing attached to it.
2.4 Usage Analytics
We use Mixpanel, Inc. to understand how the App is actually used, so we can fix what is broken and improve what is not working. Mixpanel receives anonymous usage events. Typical events include which screens you open, which features you use, when an appraisal succeeds or fails, and when a paywall is shown. Alongside those events we send basic technical context: device model, iOS version, App version, and an anonymous device identifier generated by the analytics library.
Install and session identifiers. The App also generates two of its own identifiers and attaches them to these analytics events. The first is a random install identifier, created the first time the App runs and stored persistently in the App's own storage on your device, so that events from the same installation can be grouped together over time. The second is a random session identifier, created fresh each time you launch the App and discarded when the App is closed, so that events from a single sitting can be grouped together. Both are random values. Neither is derived from your Apple ID, your device hardware, or any other real-world identity, neither is shared with other apps, and both disappear permanently when you delete the App: a reinstall generates a new install identifier with no link to the old one.
These events are not tied to a name, an email address, or any account, because the App has none of those things.
Session Replay. Mixpanel Session Replay is enabled for a small sample of sessions, approximately 10% in the released App, to help us find usability problems we cannot reproduce from event data alone. A replay records the sequence of screens and interactions in that session. Images, text fields, web views, and maps are automatically masked in these replays, so photographs you take and text you type are obscured rather than recorded. We use replays only for diagnosing usability and stability issues.
Appraisal telemetry. Our own backend records a minimal record for each analysis request: which app made it (Lustre's app identifier), whether the photo came from the camera or the photo library, and a timestamp. This is what tells us the service is healthy and how much capacity it needs. It contains no photo, no result content, no value figure, and nothing that identifies you.
We do not collect precise location, contacts, or browsing history for analytics or for any other purpose.
2.5 Purchase Information
Lustre offers optional purchases. All payments are handled entirely by Apple through the App Store. We never see, receive, or store your payment card details, your billing address, or your Apple ID credentials.
To know whether to unlock premium features, the App uses RevenueCat, Inc., which validates App Store receipts and reports back an entitlement status. RevenueCat identifies your purchases under an anonymous identifier, not under your name or email address. What comes back to the App is essentially the answer to one question: is this installation currently entitled to premium access?
2.6 Local Device Data
Most of what Lustre knows about you never leaves your iPhone. The following are stored locally only:
- Your Vault: every piece you have saved, with your photo of it, its name and type, its estimated value, its confidence figure, whether you marked it a favourite, and when you added it.
- The full appraisal report behind each saved piece, including its stones, attributes, value figures, and comparables.
- Preferences and small pieces of app state, such as whether you have completed onboarding and how you like the Vault displayed.
We have no server-side copy of any of this. It lives in your App's private storage, it is included in your device backups if you back up your iPhone, and it is permanently deleted when you delete the App.
3. How We Use Information
We use the limited information described above for these purposes and no others:
- To provide appraisals. Your photo is analysed so the App can return an identification, the piece's stones, metal, setting and era, a confidence figure, and estimated values.
- To keep the service running and fair. The anonymous session and appraisal telemetry let us apply rate limits, detect abuse, and size our capacity.
- To improve the App. Anonymous analytics and sampled session replays show us where people get stuck, which features matter, and which flows are failing.
- To deliver what you paid for. Entitlement status tells the App whether to unlock premium features.
- To respond to you. If you email us for support, we use your message and your email address to answer you.
- To meet legal obligations. Where the law requires us to retain or disclose information, we comply, and we limit disclosure to what is actually required.
We do not use your information to build advertising profiles, to score or rank you, or to make automated decisions with legal or similarly significant effects.
4. Camera & Photo Data Processing
Because photos are the most sensitive thing the App handles, here is the full path a single appraisal takes:
- You capture an image with the camera, or select one from your photo library.
- The App compresses the image on-device and opens an encrypted HTTPS connection to our Supabase Edge Function, carrying your anonymous session token.
- The Edge Function forwards the image to Google Gemini for analysis.
- Gemini returns a structured result. The Edge Function records the minimal appraisal telemetry described in section 2.4 and returns the result to your device.
- The App normalises the result, displays it, and, if you save the piece, stores it locally with your copy of the photo.
- The transmitted image is not retained by us after the request completes.
Google's handling of the image while it is being processed is governed by Google's own terms and privacy documentation for the Gemini API. We do not authorise Google to use your images for anything beyond returning the appraisal we requested.
Please avoid photographing people, identity documents, or anything else you would not want processed by a third-party AI service. Lustre is for jewelry, and framing anything else neither helps the result nor serves any purpose we support.
5. Third-Party Services
The App relies on a small number of named third parties. Each one receives only what it needs to do its job.
5.1 Google Gemini (Google LLC)
Receives: the image you submit for analysis, plus the instruction our backend sends with it.
Purpose: generating the identification, the stone and metal details, and the value estimates shown in the result.
Gemini does not receive your anonymous identifier, your device information, or your Vault. Google's use of the data it receives is governed by Google's terms and privacy policies for the Gemini API.
5.2 Supabase (Supabase Inc.)
Receives: your anonymous session identifier and token, the image in transit while it is being relayed to Gemini, and the minimal appraisal telemetry described in section 2.4.
Purpose: hosting our backend Edge Function, issuing and refreshing anonymous sessions, and metering usage.
Supabase acts as our infrastructure provider and processes this data on our behalf under its own security and privacy commitments.
5.3 Mixpanel (Mixpanel, Inc.)
Receives: anonymous usage events, the random install and session identifiers described in section 2.4, device model and iOS version, App version, an anonymous device identifier, and, for approximately 10% of sessions, a masked session replay.
Purpose: product analytics and diagnosing usability problems.
Mixpanel does not receive your photos, your appraisal results, your name, or your email address. Images, text fields, web views, and maps are masked in session replays.
5.4 RevenueCat (RevenueCat, Inc.)
Receives: an anonymous purchase identifier and the App Store receipt data needed to validate a purchase or subscription.
Purpose: validating purchases, reporting entitlement status back to the App, and enabling the Restore Purchases function.
RevenueCat does not receive your payment card details, which never leave Apple.
5.5 Apple App Store (Apple Inc.)
Receives: everything associated with distributing the App and processing your purchase, including your Apple ID and payment details.
Purpose: app distribution, payment processing, subscription management, and refunds.
Your relationship with Apple is governed by Apple's own terms and privacy policy. We receive no payment information from Apple, only the entitlement status described above.
We are not responsible for the independent practices of these third parties, and we encourage you to read their privacy policies. We do not add third parties casually; each one above exists because the App cannot function without it.
6. Data Storage & Security
We protect the small amount of data we handle with measures appropriate to its sensitivity:
- Encryption in transit. Every request between the App, our backend, and our processors uses HTTPS with TLS. The App does not transmit analysis data over unencrypted connections.
- Keychain storage. Your anonymous session identifier and token are stored in the iOS Keychain, which is encrypted by the operating system and protected by your device passcode and Secure Enclave.
- On-device isolation. Your Vault, your saved reports, and your saved photos live in the App's sandboxed container, which iOS keeps inaccessible to other apps.
- Minimisation. The most effective security control we have is not holding the data at all. We do not retain your photos, we hold no copy of your Vault, and we never collect the identifying information that would make a breach meaningful.
- Access control. Backend credentials are held in a managed secret store, rotated when needed, and never embedded in the App.
No method of transmission or storage is completely secure. While we work to protect your information, we cannot guarantee absolute security, and you use the App with that understanding.
7. Data Retention
- Photos: not retained by us after an analysis completes. The local copy stays on your device until you delete the piece or delete the App.
- Anonymous session records: retained while the installation remains active, so rate limiting continues to work. They contain no identifying information.
- Appraisal telemetry: retained in aggregate for capacity planning and abuse detection. Individual rows contain only an app identifier, a photo source, and a timestamp.
- Analytics events and session replays: retained by Mixpanel according to our configured retention settings, then deleted. Replays are short-lived and sampled.
- Purchase and entitlement records: retained by Apple and RevenueCat for as long as their own policies and applicable tax and accounting law require.
- Local device data: retained until you delete it in the App or delete the App itself, at which point iOS removes the container permanently.
8. Children's Privacy
The App is intended for users aged 13 and over, or the minimum age required in your jurisdiction if that age is higher. If you are under 18, you may use the App only if your parent or legal guardian has reviewed and agreed to our Terms of Service on your behalf.
We do not knowingly collect personal information from children under 13, and the App is not directed to children under 13 within the meaning of the Children's Online Privacy Protection Act (COPPA). Because Lustre has no accounts and collects no name, email address, or contact information, we have no practical means of building a profile of any user, child or adult.
If you believe a child under 13 has provided us with personal information, for example by emailing our support address, contact us at adk0110112@gmail.com and we will delete it promptly.
9. Your Rights & Choices
9.1 Permissions
Camera access and photo library access are both granted and revoked in the iOS Settings app under Lustre. Neither is required to install the App, and revoking one only disables the feature that depends on it.
9.2 Local Data
You can remove individual pieces from within the App. Deleting the App removes everything stored on your device, including your Vault, your saved reports, and every saved photo. This action cannot be undone and there is no server-side copy for us to restore.
9.3 Analytics
If you would prefer not to contribute anonymous usage events or session replays, email us at adk0110112@gmail.com and we will explain the current opt-out options. Deleting the App stops all further collection immediately and discards the install and session identifiers described in section 2.4.
9.4 Subscription Management
Purchases and subscriptions are managed entirely through your Apple ID at apps.apple.com/account/subscriptions. We cannot see, modify, or cancel them on your behalf.
9.5 Rights Under Privacy Laws
Depending on where you live, you may have rights under the General Data Protection Regulation (GDPR), the California Consumer Privacy Act as amended (CCPA/CPRA), or similar laws, including the right to access, correct, delete, or port your personal information, the right to object to or restrict processing, the right to withdraw consent, and the right not to be discriminated against for exercising any of these rights.
We honour these rights. Please note an inherent limitation: because Lustre collects no account, no email address, and no identifier that points at you as a person, we usually cannot link any data we hold to you. If you send us a request, we will do our best to help, but we may be unable to locate records associated with you, and we will not ask you to provide additional identifying information solely so that we can perform the search. In most cases the fastest and most complete way to exercise a deletion right is to delete the App, which removes everything that is actually about you.
To make a request or ask a question about your rights, email adk0110112@gmail.com. We will respond within the timeframes required by applicable law.
Where GDPR applies, our legal bases for processing are: performance of a contract with you (delivering appraisals and purchased features), our legitimate interests (keeping the service secure, available, and improving), and your consent (device permissions you grant).
10. Subscriptions & Payments
Lustre may offer auto-renewable subscriptions and one-time purchases. Current plans and prices are always displayed in the App before you buy. All billing is handled by Apple and charged to your Apple ID.
We receive no payment information. What we receive, through RevenueCat, is an anonymous entitlement status. Refunds are handled by Apple, as described in our Terms of Service.
11. International Data Transfers
We operate from, and our processors are principally located in, the United States. If you use the App from outside the United States, the limited information described in this policy will be transferred to and processed in the United States and other countries where our processors operate, which may have data protection laws different from those in your country.
Where required, these transfers rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses or equivalent mechanisms adopted by our processors. By using the App you acknowledge this transfer.
12. Do Not Track Signals
The App does not track you across other companies' apps or websites, so there is nothing for a Do Not Track or Global Privacy Control signal to switch off. The App contains no advertising SDKs and requests no advertising identifier. iOS App Tracking Transparency is not triggered because Lustre does not perform tracking as Apple defines it.
13. Changes to This Privacy Policy
We may update this Privacy Policy to reflect changes in the App, our processors, or the law. When we do, we will revise the "Last updated" date at the top of this page and post the new version here. Material changes will additionally be signalled in the App.
Your continued use of the App after an update takes effect constitutes acceptance of the revised policy. If you do not agree with a change, please stop using the App and delete it.
14. Contact Us
Questions, concerns, or requests about this policy or your privacy are welcome. We read everything sent to the address below.
- Email: adk0110112@gmail.com
- Support Page: Lustre Support
We aim to respond to privacy enquiries within 30 days, and usually much sooner.
Have Questions About Your Privacy?
Ask us directly. No form, no ticket number, just a reply.
adk0110112@gmail.com