Privacy Policy
Last updated: 25 July 2026
No account required
Auloy does not require you to create an account. Your holdings and portfolio are stored on your device (and optionally in your personal iCloud if you enable sync). They are never uploaded to Auloy’s servers. iCloud sync uses your own private iCloud database — Auloy has no access to it and cannot read your holdings. Item photos stay on your device: they are not sent to Auloy and are not copied into iCloud sync (only the filename reference syncs).
What we receive
- IP address — your device’s IP is recorded in our request logs when the app calls our API (including price, history, and config requests), and in our CDN/edge logs. We also use short-lived per-IP rate limits (for free price tiers and optional feedback). We do not keep an application database of IPs and we do not use them to build a profile of you; these logs rotate and expire under our server and CDN log settings.
- Receipt token — if you subscribe to Pro, your device sends an App Store receipt so we can verify your subscription. We check its signature and do not store the receipt itself. Because a receipt identifies a specific App Store purchase, purchase history is labelled as linked to you in the App Store privacy label; on our side we hold no name, email, or account to link it to. To apply per-subscription rate limits, our server keeps a short-lived in-memory entry keyed by a one-way (SHA-256) hash of the receipt; that entry is not written to a database. If you use price alerts, we store one identifier from the receipt — Apple’s subscription identifier for your purchase (
originalTransactionId) — together with your tier and its expiry date, so alerts can use the right price feed and stop when a subscription lapses. We do not create this record for subscribers who have not registered an alerts device, and we delete it when no alerts device references it. That record contains no name, email, or account.
- Price alerts (only if you create one) — alerts are checked on our servers so a notification can reach you when Auloy is closed. Saving your first alert after accepting the alerts disclosure sends: Apple’s push notification token for your device (plus the app version and whether notifications are still enabled), and the alert itself — the metal, whether you want above or below, and your threshold amount. That is all the alert needs. Your holdings, item names, notes, photos, and portfolio totals are never sent — a spot alert is evaluated from the public metal price and your number alone. Deleting your last alert deletes the device token and all server-side rules. If you turn notifications off, the app asks our server to delete the same data the next time you open Auloy, even while the alerts feature is remotely disabled; if that request fails offline, it retries on a later open. Local rules stay on your device so they can be restored if you turn notifications back on. Uninstalling does not itself send us a notice; we delete the token and its rules when Apple reports that the token no longer works or after 90 days without registration or alert-rule activity. We never sell or share this data, and we do not use it for advertising.
- Platform and app version headers — used for routing, debugging, and operational metrics (for example Free vs Pro response paths).
- Optional in-app feedback — only when you choose Settings → Send Feedback. That may include: your message, optional reply-to email, Free/Pro tier, app version and build, iOS version, and device model. The app shows you this list before you send. Holdings, photos, and credentials are never included. The message, your reply-to email if you give one, and that device metadata are emailed to our support inbox, where they are read by a person and kept as a support record until we delete them. Feedback is not used for advertising and is not sold. To have a past message and its reply-to email removed, email us at the address below.
- Optional product metrics — only if you turn on Help improve Auloy in Settings. The app may then send allowlisted feature-usage events (for example import completed, alert created, paywall shown, melt opened). Events never include holdings, weights, values, names, notes, or photos. Events carry no account, device, or advertising identifier, and they deliberately do not carry your receipt — so they cannot be tied back to you or to a purchase. They are written to our server logs, which rotate and expire like our other logs. There is no third-party analytics SDK. Metrics are not used for ads and are not sold. You can turn this off anytime; after off, no further metric events are sent.
What we do NOT collect
We do not require an account or email to use the app. We do not collect your name or location for product use. We do not use third-party analytics SDKs or advertising trackers, and we do not collect an advertising identifier (IDFA). We do not receive your portfolio contents, photos, or exports — for metrics, for feedback, for price alerts, or at all. The only device identifier we hold is Apple’s push notification token, and only if you create a price alert; it exists solely to deliver your notifications and is not used to profile you or track you across apps. Your email address and device model reach us only if you choose to send feedback; product metrics, if you enable them, contain neither.
Third-party services
Spot prices are retrieved by our servers from third-party market data providers. The app never contacts those providers directly, so what they see is our server’s request under their own policies — not your portfolio and not your device’s IP. Your IP is visible to our servers and CDN, as described above. App Store purchases are processed by Apple. Auloy contains no third-party analytics, advertising, or crash-reporting SDKs of any kind.
Data security
Communication between the app and our API uses TLS. On-device portfolio storage uses iOS Data Protection (hardware-backed encryption at rest). Optional Face ID / Touch ID can lock the app. Shared exports and Auloy backup packages leave the device only when you choose to share them — treat shared files as sensitive.
Contact
Questions? Reach us at support@auloy.com.