Privacy Policy
Lupa (“Lupa: Rock & Mineral ID” for iOS) is built and operated by Zakhar Sazanavets, an independent developer. This policy describes what the app processes, where it goes, and what stays on your device. The short version: there are no accounts, your collection lives on your phone, and nothing is sold to anyone.
What stays on your device
Your collection — photos, identifications, field-check results, notes, saved locations — is stored locally on your iPhone. We run no server that stores it. Deleting the app deletes this data. You can export a full archive of it anytime from Profile → Export your data.
What is processed to identify a find
- Your photo. When you request an identification, the photo is sent over an encrypted connection to our relay server (hosted on Cloudflare) and forwarded to OpenRouter, where an AI model by Anthropic analyzes it and returns candidate matches. We use the photo only to produce that answer; our relay does not keep a copy.
- One coordinate. At the moment of identification the app takes a single location fix (no background tracking, ever). It is sent to the Macrostrat geologic API to look up the rock formations at that spot, and included in the identification request as context. It is saved locally with your find. It is never published or shared beyond these lookups.
Purchases
Payments are handled entirely by Apple — we never see your payment details. Subscription status is managed by RevenueCat using an anonymous identifier and the App Store receipt.
Usage analytics and crash reports
We collect anonymous usage events (which screens are used, whether an identification succeeded, paywall views) through PostHog, and crash reports through Sentry, to understand what works and fix what breaks. These are not tied to your name or email — the app never asks for either. No advertising identifiers, no cross-app tracking, no data brokers.
What we never collect
- No accounts, names, or email addresses
- No contacts, no continuous or background location
- No advertising or tracking across other apps
- No selling or renting of any data, to anyone
Service providers
The app relies on these processors, each receiving only what is described above: Cloudflare (relay hosting), OpenRouter and Anthropic (photo identification), Macrostrat (geologic lookup), RevenueCat (subscriptions), PostHog (analytics), Sentry (crash reports), and Apple (payments and app distribution).
Your rights
Because your data lives on your device, access and deletion are in your hands: export from the Profile tab, delete by removing data or the app itself. If you are in the EU/EEA, you have rights under the GDPR (access, rectification, erasure, objection); our legal bases are performance of a contract (producing the identifications you request) and legitimate interest (analytics and crash reporting). For anything this page doesn't answer, write to us.
Children
Lupa is not directed at children under 13, and we do not knowingly collect personal information from them.
Changes
If this policy changes, the new version will be posted here with an updated effective date.