Privacy Policy
1. Data protection at a glance
General information
The following information provides an overview of what happens to your personal data when you use NumisCAN. Personal data is any data by which you can be personally identified.
Summary: the data we store
- Account data: email address, name, password (stored as a secure hash) or, if you sign in with Google, Apple or Facebook, the respective account ID
- Collection data: coin images, descriptions, notes, optionally uploaded documents (e.g. certificates, receipts)
- Billing data: for purchases, name/address, country, VAT ID where applicable, as well as purchase and invoice history (statutory retention)
- Usage data: server logs (IP address, timestamp)
What we do NOT store
- Credit card or bank details (these are processed exclusively by our payment service provider Mollie)
- Precise location data
- No tracking or advertising cookies without your express consent (Meta Pixel – see section 7)
- No Google Analytics or comparable analytics services
2. Controller
The controller responsible for data processing on this website is:
Neumarktstraße 9
06108 Halle (Saale)
Germany
Represented by: Christian Gothe (Managing Director)
Contact:
Email: numiscan-support@gothe.info
No telephone support.
The controller is the natural or legal person who, alone or jointly with others, determines the purposes and means of the processing of personal data.
3. What data do we collect?
3.1 Account data (on registration)
Depending on the sign-in method you choose, we store:
For email registration:
| Data item | Purpose | Legal basis |
|---|---|---|
| Email address | Identification, contact, verification | Art. 6(1)(b) GDPR |
| Name | Personalisation | Art. 6(1)(b) GDPR |
| Password (stored as a secure hash) | Authentication | Art. 6(1)(b) GDPR |
Note: Passwords are stored as bcrypt hashes and cannot be read out in plain text.
For sign-in with Google, Apple or Facebook:
| Data item | Purpose | Legal basis |
|---|---|---|
| Email address | Identification, contact | Art. 6(1)(b) GDPR |
| Name | Personalisation | Art. 6(1)(b) GDPR |
| Google, Apple or Facebook ID | Unique assignment | Art. 6(1)(b) GDPR |
3.2 Collection data
When you record coins, we store:
- Images: photos of the coins (obverse and reverse)
- Metadata: name, country, year, grade, notes
- Storage locations: where you keep your coins (optional)
- Purchase information: price, date, dealer (optional)
- Documents: files (PDF or images) you optionally upload for a coin or a specimen – e.g. certificates of authenticity/grading certificates, purchase receipts/invoices, photos of holders (each with document type and optional title)
Note: Free-text fields such as "Notes" may contain personal data you enter. Please do not enter sensitive data of third parties there.
Note on uploaded documents
Documents you upload (e.g. certificates or invoices) may contain personal data – including that of third parties (such as your name and address on a purchase receipt, or an expert's details on a certificate). We do not evaluate these documents with AI and do not pass them on; they are stored exclusively on our servers in Germany and linked to the associated coin or specimen. Please only upload documents that you are entitled to store. If you mark a document as "Visible in share", it becomes part of a share link you create (see section 5).
3.3 Usage and security data
To provide and secure the service, we collect:
- API usage: number and type of AI analyses, token consumption, costs
- Login history: time, IP address, browser/device for security checks
- Audit logs: logging of security-relevant actions (login, password change, account deletion)
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in the security and integrity of the service and in preventing misuse).
3.4 Server logs
Each time our servers are accessed, the following is recorded automatically:
- IP address
- Date and time of access
- Browser type and version
- Operating system
- Page accessed
This data is required for the security and stability of the service and is automatically deleted after 30 days. It is not merged with other data sources.
4. External services and data transfers
4.1 Sign-in and registration
Email registration
When you register with an email address, we send you a verification email. Emails are sent via our SMTP server in Germany.
Emails we send:
- Account & security: verification on registration, welcome email, password reset, confirmation of changes to your email address or account, deletion confirmation
- Billing: purchase/payment confirmation (receipt) after successful payment, payment reminder if a subscription payment fails, notice of a reversal (chargeback)
- Credits: notice of a low balance and a warning when credits are about to expire (due to the purchase date or prolonged inactivity)
- Community (if you use these features): updates on your bug reports and feature suggestions, invitations that you send yourself
- Newsletter (optional): occasional information on new features and votes – with an unsubscribe link in every message
Invitations: If you invite another person via the app, we send a one-time invitation email to the address you provide. We use this address exclusively for sending the invitation and not for our own advertising. Please only invite people who agree to being contacted.
Legal bases: Account, security and billing emails are necessary for the performance of the contract or due to a legal obligation (Art. 6(1)(b) and (c) GDPR). Credit and community notices as well as invitations are based on our legitimate interest in a usable service (Art. 6(1)(f) GDPR). You receive the newsletter only on the basis of your consent or § 7(3) UWG (German Act against Unfair Competition); you can object to it at any time via the unsubscribe link (Art. 6(1)(a) GDPR, Art. 21 GDPR).
Google OAuth (alternative sign-in)
Alternatively, you can sign in with your Google account. You are redirected to Google's servers, where you authenticate. Google then transmits your email address, your name and a unique ID to us.
Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland
Privacy policy:
https://policies.google.com/privacy
"Sign in with Apple" (alternative sign-in)
Alternatively, you can sign in with your Apple ID. You are redirected to Apple's servers and authenticate there. Apple then transmits a unique identifier and – if you allow it – your name and email address to us. Apple offers the "Hide My Email" feature; in this case we only receive an anonymous relay address (@privaterelay.appleid.com). No Apple script is loaded in the background – the redirect only takes place when you actively click.
Provider: Apple Inc., One Apple Park Way, Cupertino, CA 95014, USA
Privacy policy:
https://www.apple.com/legal/privacy/
Facebook Login (Meta, alternative sign-in)
Alternatively, you can sign in with your Facebook account. You are redirected to Facebook's servers and authenticate there. Meta then transmits a unique identifier, your name and – if you allow it – your email address to us. No Facebook/Meta script is loaded in the background – the redirect only takes place when you actively click.
Provider: Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland
Privacy policy:
https://www.facebook.com/privacy/policy
4.2 AI processing by Anthropic Claude (AI analysis)
For automatic coin identification, the coin photos you upload are transmitted to Anthropic's Claude API. The AI analyses the images and extracts information such as country, year and denomination.
Purpose of AI processing
Your coin photos and the associated collection details are processed for AI-assisted identification (country, year, denomination, type), for assessment (grade and non-binding market value estimate) and – at your active request – for numismatic research.
Important information on AI analysis:
- Images are used only for the analysis
- NumisCAN does not use your images and inputs to train AI models
- Anthropic also does not use your images to train AI models
- Transmission is encrypted (HTTPS)
Transfer to the USA (third country) & processing on our behalf
Anthropic is based in the USA. Transmitting your coin photos and coin data therefore constitutes a transfer to a third country (Art. 44 et seq. GDPR). Anthropic processes this data as a processor on our instructions (Art. 28 GDPR). The transfer mechanisms are the EU-US Data Privacy Framework and, additionally, the Standard Contractual Clauses (SCCs) of the European Commission (Art. 46(2)(c) GDPR). Further details on third-country transfers can be found in section 4.9.
Optional research feature (web search): If you start in-depth market/background research on a coin, the details required for this (e.g. country, year, denomination, name) are transmitted as text to the Claude API; the AI carries out web searches on the internet for this purpose and may pass these search terms on to search engines. Coin and collection data is processed in this context (no images required). The feature is optional and is only carried out at your active request.
Provider: Anthropic PBC, San Francisco, USA
Privacy policy:
https://www.anthropic.com/privacy
Legal basis: Art. 6(1)(b) GDPR (performance of a contract – the AI analysis is a core function of the service); insofar as the AI analysis is designed as a separately activatable additional feature, it may additionally or alternatively be based on your consent (Art. 6(1)(a) GDPR), which you give by triggering the analysis and which you can withdraw at any time with effect for the future. The AI analysis is optional; coin data can also be entered manually without AI.
4.3 Push notifications
NumisCAN offers optional push notifications to inform you about important events (e.g. admin messages).
Data stored on activation:
- Endpoint URL: technical address for delivery
- Encryption keys: for secure transmission
- Browser/device: for assigning the notification
Push notifications are delivered using the Web Push standard. Delivery takes place via your browser's push servers (e.g. Google for Chrome, Mozilla for Firefox). You can deactivate push notifications at any time in the app settings or in your browser settings.
Legal basis: Art. 6(1)(a) GDPR (consent through active activation).
4.4 Feature sponsoring
NumisCAN offers the option of financially supporting feature suggestions (sponsoring). When you sponsor a feature, the following data is collected:
Data stored for sponsoring:
- Amount and currency: your pledge of support
- Message: optional comment on the sponsoring
- Anonymity setting: whether your name should be displayed
- Timestamp: date of the pledge
Public display: Unless you choose "anonymous", your name is displayed as a sponsor of the feature. For implemented features, sponsors are named (unless anonymous).
Note: No external payment processing takes place for sponsoring via NumisCAN. Sponsoring is a pledge of support; the actual payment is made directly (e.g. bank transfer). For paid credit purchases, see section 4.8 (Payment processing).
Legal basis: Art. 6(1)(a) GDPR (consent by actively creating the sponsoring).
4.5 External resources
Apart from the Meta Pixel, which is only loaded with your consent (see section 7), NumisCAN does not load any external resources from third-party providers. All stylesheets, scripts and media are served from our own servers in Germany. Your IP address is not transmitted to CDN providers.
4.6 Coin research services (optional)
If you use the optional coin research feature, data is transmitted to the following external services in order to obtain technical and historical information about your coins:
Numista API
For technical coin data such as catalogue numbers, weight and dimensions.
- Data transmitted: coin name, country, year, denomination
- Provider: Numista (numista.com), France
- Privacy policy: https://en.numista.com/privacy.php
Legal basis: Art. 6(1)(a) GDPR (consent through active use of the research feature).
Wikidata (Wikimedia Foundation)
For historical context such as information on rulers and periods.
- Data transmitted: coin and person names (public search queries)
- Provider: Wikimedia Foundation, USA
- Privacy policy: https://foundation.wikimedia.org/wiki/Privacy_policy
Note: No personal data is transmitted to Wikidata, only public search queries about coins and historical persons.
4.7 Community features
Bug reports
When you report a bug, the following data is collected:
- Entered by you: title, description, optional screenshots
- Collected automatically: browser type, operating system, screen size
- Optional: browser console errors (for technical analysis)
This data helps us identify and fix bugs. It is used only internally for software development.
Legal basis: Art. 6(1)(b) GDPR (improvement of the service) and Art. 6(1)(a) GDPR (consent by actively creating the bug report).
Feature suggestions & votes
For feature suggestions and votes, we store:
- Feature suggestions: title, description, your username
- Votes: your vote (upvote/priority), linked to your account
- Comments: text, timestamp, your username
This data enables transparent prioritisation of features based on community feedback. Your name is publicly displayed as the author.
Legal basis: Art. 6(1)(a) GDPR (consent through active participation).
4.8 Payment processing (Mollie)
To process paid purchases (credit packs and credit subscriptions), we use the payment service provider Mollie. In doing so, the data required for payment is processed and/or transmitted to Mollie.
Data processed for purchases:
- Name and email address
- Billing address and country and, where applicable, VAT ID
- Amount, currency and order/transaction identifier
- Payment method data (e.g. card or bank details) is entered by you directly with Mollie; it is not disclosed to us in plain text.
Mollie processes the payment data as an independent controller in accordance with its own privacy policy. We retain invoice and transaction data due to obligations under tax and commercial law.
Provider: Mollie B.V., Keizersgracht 126, 1015 CW Amsterdam, Netherlands
Privacy policy: https://www.mollie.com/privacy
Legal basis: Art. 6(1)(b) GDPR (performance of a contract); for the
retention of invoice data, Art. 6(1)(c) GDPR (legal obligation,
§ 147 AO (German Fiscal Code), § 257 HGB (German Commercial Code)).
Third-country transfer: None – Mollie is based in the Netherlands (EEA).
4.9 Transfers of data to third countries (Art. 44-49 GDPR)
When certain features are used, personal data is transferred to countries outside the European Economic Area (EEA):
Transfers to the USA
| Recipient | Purpose | Safeguards |
|---|---|---|
| Anthropic PBC | AI image analysis & research | EU-US Data Privacy Framework, SCCs |
| Google LLC (with OAuth) | Authentication | EU-US Data Privacy Framework, SCCs |
| Apple Inc. (with "Sign in with Apple") | Authentication | EU-US Data Privacy Framework, SCCs |
| Meta Platforms Inc. (with Facebook Login / Meta Pixel) | Authentication, advertising measurement (only with consent) | EU-US Data Privacy Framework, SCCs |
| Browser push services | Push notifications | Depends on the browser provider |
Legal bases for third-country transfers:
- EU-US Data Privacy Framework: adequacy decision of the European Commission of 10 July 2023 (Art. 45 GDPR) for certified US companies
- Standard Contractual Clauses (SCCs): contractual clauses approved by the European Commission pursuant to Art. 46(2)(c) GDPR
Note: The USA has surveillance laws (e.g. FISA 702) that may, under certain circumstances, allow US authorities to access personal data. By using the AI analysis, you consent to the associated data transfer. The AI analysis is optional; coin data can also be entered manually.
5. Sharing feature (share links)
NumisCAN allows you to share coins, specimens or your entire collection with other people via share links.
Important: public visibility
When you create a share link, the shared content can be viewed by anyone who knows the link – even without signing in to NumisCAN.
What is shared?
- Coin data: name, country, year, material, grade, notes
- Images: obverse and reverse of the coins
- Specimen details: purchase price, purchase date, dealer, storage location (if recorded)
- Documents: only those you have expressly marked as "Visible in share" (e.g. a certificate); other documents remain private
- Your name: displayed as "Shared by [name]"
Your control
- Password protection: you can protect links with a password
- Expiry date: links can be time-limited (1h, 24h, 7 days, 30 days)
- Revoke: you can deactivate links at any time
- Delete: deleted links become invalid immediately
Legal basis: Art. 6(1)(a) GDPR (consent by actively creating the link).
6. Storage and security
6.1 Storage location
All your data is stored on servers in Germany. No data is stored in third countries (with the exception of temporary processing by Anthropic, see above).
6.2 Storage period
| Type of data | Storage period |
|---|---|
| Account data | Until the account is deleted |
| Collection data & images | Until deleted by the user |
| Uploaded documents | Until deleted by the user (automatically together with the coin/specimen or account) |
| Share links | Until the expiry date or deletion by the user |
| Server logs (access) | 30 days |
| Invoice & payment data | 10 years (§ 147 AO, § 257 HGB) – even after account deletion |
| Activity logs (audit logs) | Until account deletion (for compliance and security) |
| API usage statistics | Until the account is deleted |
| Push subscriptions | Until deactivation or account deletion |
| Bug reports & feature suggestions | Permanently (public community content) |
| Feature sponsorings | Until account deletion (for anonymous sponsorings: permanently anonymised) |
6.3 Security measures
- Encrypted transmission (HTTPS/TLS)
- Password-protected database
- Regular security updates
- Access restricted to authorised administrators
6.4 Notification of personal data breaches (Art. 33/34 GDPR)
In the event of a personal data breach, we notify the competent supervisory authority without undue delay (within 72 hours), provided that the breach is likely to result in a risk to the rights and freedoms of natural persons. Data subjects are notified if there is a high risk to their rights and freedoms.
7. Cookies & local storage
Sparing use of cookies – only with consent
We do not set any tracking cookies for operating the service itself. Only if you expressly consent via our consent banner do we load the Meta Pixel for measuring the reach and conversions of our advertising (see below). Without your consent, no advertising tracking takes place; you can change your choice at any time via "Cookie settings".
What we do NOT use without consent
- No Google Analytics or comparable analytics services
- No advertising cookies without your consent
- The Meta Pixel is loaded only after active consent
Meta Pixel & Conversions API (only with consent)
With your consent, we use the Meta Pixel and the server-side Conversions API of the provider Meta Platforms Ireland Ltd. (4 Grand Canal Square, Dublin, Ireland). This allows us to measure the success of our ads (e.g. registration, purchase) and optimise their delivery. In the process, a pseudonymous browser identifier (cookies _fbp/_fbc) and – with the Conversions API – hashed (made unrecognisable) details such as your email address are transmitted to Meta. A transfer to the USA is possible; this is based on the EU Standard Contractual Clauses and/or the EU-US Data Privacy Framework.
Legal basis: Art. 6(1)(a) GDPR (consent), § 25(1) TDDDG (German Telecommunications Digital Services Data Protection Act). Consent is voluntary and can be withdrawn at any time with effect for the future (via "Cookie settings").
| Cookie | Purpose | Storage period |
|---|---|---|
| cc_cookie | Stores your cookie choice (consent banner) | 12 months (strictly necessary) |
| _fbp | Meta Pixel – pseudonymous browser ID (only with consent) | up to 90 days |
| _fbc | Meta Pixel – click ID from ads (only with consent) | up to 90 days |
Campaign/source data (acquisition attribution)
If you visit our website via an ad or a partner link, we record information on the source of your visit in order to measure the success of our advertising and to settle accounts correctly with our advertising partners. We record exclusively campaign parameters from the link address (so-called UTM parameters, e.g. utm_source, utm_campaign), the landing page variant displayed, the referring page (referrer) and the time of the visit – no Meta identifiers (e.g. no click IDs) and no information about your device.
Storage: This information is initially stored only temporarily in your browser's session storage (sessionStorage) and automatically deleted when the browser tab is closed. Only if you register is it transmitted to us once and stored with your user account. It is removed when the account is deleted; only an anonymised registration count entry without any personal reference remains for internal statistics.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in correct settlement with our advertising partners and in preventing billing fraud).
Recipients: Our advertising partners receive only aggregated totals without any personal reference (e.g. the number of registrations obtained through a campaign and the resulting revenue totals) – no individual data and no information that allows conclusions to be drawn about you.
Storage period: The source data is stored for the lifetime of your user account and removed when the account is deleted. We retain aggregated billing data in accordance with the statutory retention periods (§ 147 AO).
localStorage (local browser storage)
For authentication, we use exclusively localStorage – storage directly in your browser. This data is not sent to servers and remains on your device.
| Key | Purpose | Type |
|---|---|---|
| numiscan_access_token | Authentication (JWT) | Strictly necessary |
| numiscan_refresh_token | Automatic session renewal | Strictly necessary |
| numiscan_user | Cached user data | Strictly necessary |
| numiscan-show-back | UI preference (coin view) | Strictly necessary |
Note: You can delete this data at any time in your browser settings (Developer tools → Application → Local Storage). When you sign out, the authentication data is deleted automatically.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in providing a working sign-in). As localStorage is technically necessary and has no tracking functions, no consent is required.
8. Your rights
You have the following rights regarding your personal data at any time:
Access (Art. 15 GDPR)
You can request information about the data stored about you.
Rectification (Art. 16 GDPR)
You can request the rectification of inaccurate data.
Erasure (Art. 17 GDPR)
You can request the erasure of your data ("right to be forgotten").
Restriction of processing (Art. 18 GDPR)
You can request the restriction of processing, e.g. if you contest the accuracy of the data. By email to: numiscan-kontakt@gothe.info
Data portability (Art. 20 GDPR)
You can receive your data in a commonly used format.
Objection (Art. 21 GDPR)
You can object to processing insofar as it is based on legitimate interest.
Withdrawal of consent (Art. 7(3) GDPR)
Insofar as processing is based on your consent (e.g. push notifications, newsletter, marketing), you can withdraw it at any time with effect for the future. The lawfulness of processing carried out before the withdrawal remains unaffected.
Complaint (Art. 77 GDPR)
You can lodge a complaint with a supervisory authority.
Deleting your account and data yourself
You can delete your entire collection and your user account in the app at any time. The following will be irrevocably deleted:
- Your user account and all account data
- All coin entries and specimens
- All uploaded images
- All uploaded documents (certificates, receipts, etc.)
- All share links created
9. Automated decision-making and profiling (Art. 22 GDPR)
NumisCAN uses artificial intelligence (AI) for the automatic analysis of coin images. This processing falls under the term automated decision-making.
Type of automated processing:
- Image analysis: AI-assisted recognition of coin features
- Classification: automatic assignment to country, year, denomination
- Grade: automatic assessment of the condition
- Market value estimate: automatic price estimate based on AI analysis
The AI analysis has no legal effects on you and does not similarly significantly affect you within the meaning of Art. 22(1) GDPR, because:
- the results constitute exclusively non-binding information,
- all results can be edited and overwritten by the user,
- no automatic contractual or payment decisions are made,
- manual data entry without AI analysis is possible at any time.
⚠️ Disclaimer:
The automatically generated results may be incorrect. They have no legally binding effect and do not replace a professional numismatic appraisal. We accept no liability for decisions based on AI results. See also: Terms and Conditions, § 3 and § 12.
10. Minors
NumisCAN is not aimed at persons under the age of 16. We do not knowingly collect personal data from children. If you are a parent or legal guardian and believe that your child has provided us with personal data, please contact us.
11. Changes to this privacy policy
We reserve the right to amend this privacy policy in order to adapt it to changes in the legal situation or in the event of changes to the service. You can always find the current version on this page.
Last updated: 7 October 2026
Version: 2.0