Skip to main content

Legal

Privacy Policy

Effective Date: 9 August 2026

MetalScan AI respects your privacy.

Information We Collect

Account and profile data:

  • Name, email address, phone number where provided, and password credentials held in hashed form
  • Company or trading name, account type (buyer, seller or business) and role
  • Two-factor authentication settings and approved devices

Product data:

  • Uploaded scan images, AI results, confidence scores and scan history
  • Inventory records, valuations, quotes, invoices and customer (CRM) records you enter
  • Marketplace listings, listing media, supporting documents (such as assay or XRF reports), offers, counter-offers, comments and public reviews
  • Orders, shipping and delivery addresses, courier names, tracking numbers and delivery-stage events
  • Payment metadata from our payment provider — amount, currency, status, last four digits and card brand. We never receive or store full card numbers
  • Business verification material — company details, registration or licence numbers and documents you upload for review
  • Support enquiries, abuse and fraud reports, moderation records and appeals

Technical data:

  • Device and browser information, app version and language
  • IP address and approximate country, used for security and regional compliance
  • Optional usage analytics, collected only where you have accepted analytics

How We Use Your Information

We use your information to:

  • Provide AI metal identification, indicative valuations and reporting
  • Operate the marketplace, including listings, negotiation, orders, shipping and delivery tracking
  • Process payments, platform fees, refunds and invoices through our payment provider
  • Verify business identity and display verification badges
  • Send transactional notifications about offers, messages, orders and delivery stages
  • Investigate reports of fraud, abuse, prohibited or stolen material, and enforce our Terms
  • Meet legal, tax and record-keeping obligations
  • Improve platform performance and reliability

We do not sell your personal information, and we do not use it for advertising or cross-site tracking.

Image Storage

Uploaded images may be securely stored to provide scan history and improve future AI performance.

Images are never sold to third parties.

Cookies

We use strictly necessary cookies and local storage to:

  • Keep users logged in and protect sessions
  • Remember interface preferences and approved devices
  • Process payments securely at checkout

Optional analytics cookies are loaded only after you accept analytics in the cookie banner. We do not use marketing or advertising cookies.

AI Data Processing

MetalScan AI uses the AI provider OpenAI, accessed through the Lovable AI Gateway, to analyse images and information you submit for metal identification.

  • AI provider: OpenAI, accessed through the Lovable AI Gateway
  • Data sent to OpenAI: the images you upload or capture and the information you provide for analysis (such as scan details, valuation inputs like metal type, weight, purity, grade and price, and any notes you enter). No account credentials, payment details or customer records are sent
  • Why it is sent: solely to generate your metal identification and analysis results
  • Legal basis: your explicit consent, captured before any data is transmitted
  • No data is sent to OpenAI until you select “Agree & Continue” on the AI Data Processing Consent screen. If you decline, the refusal is stored and no data is transmitted; the consent is re-checked on every AI request, including photos queued while offline
  • OpenAI does not use your submissions to train its models, and no data is sold or used for advertising

You can review or withdraw this consent at any time under Settings → Privacy controls. Withdrawing consent stops all future AI analysis until you agree again.

Third Parties and Overseas Processing

We rely on trusted providers to deliver the service:

  • Cloud hosting, database, storage and authentication providers
  • Stripe for payments, subscriptions and identity verification
  • Email and push notification delivery providers
  • AI model providers used to analyse the images you submit for scanning
  • Communication infrastructure providers used for calling and messaging delivery

These providers act on our instructions and may process or store data outside your country, including in the United States and the European Union. Where personal information is transferred overseas, we rely on the provider's contractual data-protection commitments and take reasonable steps to ensure it is handled consistently with this policy and applicable law.

Data Retention

We keep personal information only as long as needed for the purpose it was collected, and then for as long as required by law:

  • Account, profile and verification records — for the life of the account and up to 7 years afterwards where tax, financial or dispute-resolution law requires it
  • Scans, inventory and reports — until you delete them, or until the account is deleted
  • Marketplace listings, orders, invoices and payment metadata — at least 7 years, as financial records
  • Messages — retained on our servers in encrypted form until deleted by participants; moderation copies retained only for the life of the case
  • Moderation cases, access logs and audit logs — retained for at least 2 years for accountability
  • Support correspondence — up to 2 years after the enquiry closes

Complaints

If you believe we have mishandled your personal information, contact us first and we will acknowledge your complaint within 5 business days and aim to resolve it within 30 days. If you are not satisfied with the outcome, you may escalate to your local privacy or data protection regulator — for example the Office of the Australian Information Commissioner in Australia, your supervisory authority in the EEA or UK, or your state authority in the United States.

Private Messages and Moderation Access

Private message bodies and shared files are encrypted in your browser or app before they are sent, and all traffic is encrypted in transit (TLS). This client-side encryption has not yet been independently audited, so we do not describe it as verified end-to-end encryption. MetalScan AI staff cannot browse private conversations.

Access is only ever granted on a case-by-case basis. An administrator must open a documented moderation case naming the specific conversation, the authorised staff member and one of the following grounds:

  • A conversation or message that has been reported to us
  • A safety investigation into fraud, abuse or threats to people or property
  • A legal obligation, such as a lawful request from a regulator or law enforcement

Every case, and every time an authorised staff member opens the conversation, is recorded permanently with the staff member's identity, the written reason, the lawful ground and the date and time. Access automatically expires (maximum 30 days) and can be revoked at any time. General administrators without an open case cannot view private conversations.

If you report a message, please be aware that the reported conversation may be reviewed by authorised moderation staff for that investigation. Content that remains encrypted on participants' devices stays sealed to those devices.

Data Security

We use industry-standard encryption and secure cloud infrastructure to protect user information.

User Rights

Users may request to:

  • Access their data
  • Correct information
  • Delete their account
  • Export their information

Contact

Questions regarding privacy may be directed to:

contact.metalscan.ai@gmail.com