Abditex

Privacy policy

This is the plain-language version. The complete enumeration of every piece of data that ever leaves your device (every endpoint, every header, every retention window) ships inside the app as the Privacy Ledger. The ledger is the canonical source; this page summarizes it.


The short version

  • We don't ask for your name, email, phone number, or any account.
  • Your inventory lives on your device, encrypted at rest. We never see it.
  • If you use shared inventory, the shared data is end-to-end encrypted; we hold ciphertext, not keys.
  • We don't run analytics, advertising SDKs, or third-party trackers. Anywhere. Ever.
  • Subscriptions are handled by Apple's App Store or Google Play. We never see your payment information.

What we don't collect

  • No accounts. The app does not require, support, or accept a login. There is no username, password, email address, or recovery token associated with you.
  • No precise location. Dealer-locator features use ZIP code only, entered by you. We do not request, receive, or store device GPS.
  • No analytics. No Google Analytics, no Firebase Analytics, no Mixpanel, no Amplitude, no Segment, no first-party event tracking. We don't know what screens you visit or what features you use.
  • No advertising identifiers. No IDFA, no AAID, no advertising SDKs of any kind.
  • No crash-reporting SDK. Abditex includes no Crashlytics, Sentry, Bugsnag, or equivalent. The app does not transmit crash data anywhere. If the app crashes, your operating system may retain a local crash log in the standard platform location, retrievable by you through OS tools. That's between you and the platform, not us.

What does cross the network, and why

The app makes a small, enumerated set of network calls. Each is documented in the in-app Privacy Ledger with full detail; here is the summary:

  • Spot-price updates. The app fetches current bullion spot prices from our server. The server sees only that some device asked for prices; no inventory is included in the request.
  • Dealer directory updates. The app downloads the dealer directory file periodically. All searching, filtering, and zip-code matching happen on-device against the cached file, so the server does not see what you're looking for.
  • Subscription validation. The app sends a platform-issued receipt (Apple / Google) to our server to validate your subscription. Validated state is mapped to an opaque license token. We never see your payment method or store account.
  • Attestation. Some endpoints require an App Attest (iOS) or Play Integrity (Android) attestation token, used solely for anti-abuse. The token is not joined with anything that identifies you.
  • Sync relay (Pro, opt-in). If you create or join a shared inventory, encrypted blobs flow through our relay. We hold ciphertext only; we cannot derive plaintext.
  • Push notifications (Pro, opt-in). Empty wake-up notifications via APNs (Apple) or FCM (Google). Notification content is computed on-device after the wake-up; the platform never carries content through our pipes.

The ledger documents, for each call, exactly what data it carries, exactly what the server stores, and exactly how long retention runs.

Subscriptions and payments

Subscriptions are sold and managed entirely by the App Store (iOS) or Google Play (Android). Abditex never sees your name, billing address, payment method, or store account identifier. We see only the platform-issued opaque receipt, which we exchange for an opaque license token. Family Sharing is supported on both platforms.

Children

Abditex is not directed at children under 13 (or the equivalent minimum age in your jurisdiction). Because we collect no personal information from anyone, we do not knowingly collect personal information from children either.

Data we cannot produce

Because we do not have your decryption keys and do not store plaintext inventory, we cannot produce your inventory in response to legal process. We can only produce the ciphertext we hold. This is by architectural design, not policy choice.

Changes to this policy

If we change what data crosses the network, the change appears in the in-app Privacy Ledger first, in the same release that introduces the change. This page is updated to match. The ledger's version history is preserved across releases.

Contact

Privacy questions: email privacy@abditex.com. Security disclosures go to the security page.