Crystal KeeperStone Journal
The journalPrivacySupport

Privacy Policy

Crystal Keeper is local-first and aims to collect as little personal information as possible. This policy explains the limited exceptions required for AI identification and service protection.

Last updated
10 July 2026← Back to home

1. Who We Are

Crystal Keeper is operated by Sean, an independent developer. For privacy questions or requests, contact seanliu353@gmail.com.

2. A Note on Local-First Design

Your crystal collection and the information you record are stored on your device, not on our servers. We do not currently operate user accounts or a central collection database.

The principal exception is AI identification: when you actively request it, a compressed copy of the selected photo is sent through our server to a third-party AI service. Our server also processes a random device identifier, your IP address, and limited service data for usage limits, security, and reliability.

3. Information We Collect

  • Submitted photos: uploaded only when you request AI identification; collection-only photos remain on your device.
  • Crystal information: names, notes, and other details remain locally stored.
  • Camera and photo access: used with your permission to capture and select images.
  • Anonymous device identifier: a random Keychain identifier helps enforce per-device limits and prevent abuse; counters use a one-way keyed hash.
  • IP and limited service data: used for short-term rate limiting, security, performance, and troubleshooting.
  • Apple diagnostics: aggregated crash and usage statistics may be provided by Apple if you enable sharing.

We do not collect your name, email, contacts, precise location, or payment details through the App itself.

4. AI Image Identification

A compressed image is transmitted through our production proxy at api.crystal-keeper.com and processed by Alibaba Cloud Model Studio / Bailian, currently using Tongyi Qianwen models. The server holds the request body in memory while servicing the request and does not intentionally write submitted images to permanent storage.

Production proxy and model API endpoints are currently in the United States. Use outside the United States involves international transfer. Do not submit people, faces, documents, location-revealing details, or sensitive information.

5. How We Use Information

  • Provide core features, including AI identification.
  • Apply usage limits, prevent abuse, secure the service, and troubleshoot.
  • Comply with legal obligations.

6. Legal Bases for EEA/UK Users

Depending on context, processing relies on performance of a contract, consent or your affirmative choice, and legitimate interests in securing and operating the service.

7. Sharing

Limited information is shared only with AI providers, hosting and infrastructure providers, Apple where needed for distribution or support, and authorities where legally required.

We do not sell personal information, use your photos for advertising, or share data for third-party direct marketing.

8. Data Retention

  • Your local collection remains until you delete entries, clear data, or delete the App.
  • Our application server does not intentionally retain submitted image files after servicing a request.
  • Weekly successful-identification counts are stored under a one-way keyed hash and reset each Monday at 00:00 UTC.
  • Short-term security counters clear on restart or at the daily UTC window reset.
  • Limited operational logs are retained only as reasonably necessary for security and troubleshooting.
  • The random Keychain identifier may remain after app deletion so reinstalling does not reset service limits.

9. Your Privacy Rights

Depending on where you live, you may have rights to access, correct, delete, export, object to, or restrict processing. Most collection data is already under your direct control on your device. Contact us to exercise applicable rights; we may need to verify your identity. EEA/UK users may complain to their local authority. We do not sell or share personal information as defined by California law.

10. Security

We use HTTPS, limited server-side handling, request-size limits, and abuse controls. No transmission or storage method is completely secure, and you remain responsible for securing your device.

11. Children’s Privacy

The App is not directed to children under 16, and we do not knowingly collect their personal information. Contact us if you believe a child has submitted information.

12. Changes

We may update this policy and will change the “Last updated” date, make the revised policy available in the App, and provide any notice or obtain any consent required by law.

13. Contact Us

Sean — Crystal Keeper
Email: seanliu353@gmail.com

Crystal KeeperStone Journal
TermsPrivacySupport

Made by Sean.