Privacy policy
Your radar should not become someone else’s data source.
Magpye uses a private account to synchronize the settings needed for your buying radar. It does not serve advertisements, sell personal data, or use cross-app tracking.
Effective
Account and cloud information
Sign in with Apple and Supabase process your account identifier, your name if Apple provides it, and your email or Apple private-relay address. Magpye stores your display name, onboarding status, marketplace selections, Watch definitions, notification preferences, and synchronization version so those settings can be restored across authenticated sessions.
Supabase also stores source scan and run diagnostics and marketplace matches associated with your account. A match may include a public listing identifier and listing content, Magpye's derived valuation, whether you saved or dismissed it in your Inbox, and freshness and lifecycle timestamps.
Terms acceptance records
When you affirmatively accept the Terms of Use, Magpye stores your account ID, the Terms version, the document SHA-256 identifier, the server acceptance time, and that explicit clickwrap was used. The receipt does not record which paragraphs you viewed or how long you spent reading them. Material changes require a new acceptance receipt.
Watch interactions and optional purchase feedback
When you tap a current Watch result, Magpye records that a listing review started. If you confirm the verification warning, Magpye separately records the authorized marketplace handoff. These account-linked events contain only canonical account, match, Watch, source, event, idempotency, and server-time values; the interaction ledger does not copy the listing title, URL, seller, price, or provider payload.
You may optionally self-report whether you purchased, did not purchase, or are still considering a match and, for a purchase, which statement best describes Magpye's involvement. This does not prove Magpye caused a transaction. Feedback can be updated or removed on a privacy-safe historical card after provider content expires. Removing the match from the Inbox removes its purchase feedback in the same database transaction.
Information on your device
Magpye maintains a local working copy of your profile and Watches. Listing analyses may include titles, source URLs you choose to save, seller-provided metal and weight details, acquisition costs, calculated valuations, and safety-gate results. This information is used to provide the app’s features.
Private-beta Discovery review feedback
The account owner may use a separately protected Team console to label whether one of their own Discoveries was useful, a false positive, or needs investigation. Optional structured reasons and a written note can identify relevance, metal, purity, weight, valuation, cost, duplication, evidence, or listing-freshness issues. This feedback is stored separately and does not change the original provider evidence, Watch definition, decision trace, or valuation.
A Copy for Codex control creates a reviewer-directed diagnostic packet. It excludes Magpye account identifiers and email, seller identity, listing and image URLs, marketplace credentials, raw provider payloads, internal secrets, and exact global quota state. The reviewer should not enter passwords, API keys, or other secrets in the optional note.
Marketplace and market-reference data
Approved marketplace APIs may provide public listing information to Magpye. The app also requests a shared cached snapshot of gold, silver, platinum, and palladium reference rates. Metals.Dev receives scheduled requests from the Magpye backend rather than a separate request for every user or Watch.
A direct eBay Watch check first reuses a fresh shared result set when an equivalent provider request was recently completed. If no reusable result set is available and Magpye's bounded request capacity permits it, the backend sends the relevant search criteria to eBay's official API. An Etsy Watch check sends relevant search criteria to Etsy's official API only after an explicit user refresh. Magpye does not send your Magpye user identifier or marketplace password with provider search requests, and it does not collect marketplace passwords. If you open a listing, the destination marketplace handles that visit under its own privacy policy and terms.
eBay and Bonanza public listing evidence is retained for a 24-hour discovery-review window after Magpye observes it. Etsy listing evidence is hidden before it becomes six hours old. The observation time remains visible because neither window proves that a listing is still available. At expiration, provider payload and valuation fields are redacted and any private shared-catalog row is deleted. If a listing had entered your Inbox, Magpye may retain a minimal account-owned tombstone plus save, dismiss, freshness, and lifecycle timestamps so your workflow remains coherent without retaining the expired provider payload.
Notifications
Notification permission is optional and can be changed in iOS Settings. If you opt in, Magpye stores an installation identifier, Expo push token, device platform, and time zone in Supabase. Generic Watch-hit notices travel through the Expo Push Service and Apple Push Notification service. They do not include listing, price, Watch, or marketplace-account details. Disabling notifications unregisters the installation, and invalid tokens are disabled automatically.
Service providers and network information
Apple provides authentication, Supabase provides account storage and backend infrastructure, Expo provides push delivery when enabled, Cloudflare provides the public website and related security services, Metals.Dev supplies shared metal-rate references, and approved marketplace APIs may provide public listing data. These providers may process standard network information for delivery, security, logging, and abuse prevention under their own policies.
No sale, advertising, or cross-app tracking
The private beta does not include advertising SDKs, data-broker sharing, or cross-app tracking. Magpye does not sell personal data.
Retention and deletion
Signing out removes that account's Magpye working cache from the device. Uninstalling the app also removes local app data. Cloud account information, Watch definitions, revoked installation records, and account-owned workflow records remain until you delete the account; shared provider payload follows the shorter retention period described above. Terms acceptance receipts also remain until account deletion. You can delete your account in the app or follow the instructions on the account-deletion page.
Children
Magpye is not directed to children under 13, and we do not knowingly collect personal information from children under 13.
Changes and contact
This policy will change when Magpye adds new connectors, analytics, or other data processing. Material changes will be reflected here and in the App Store privacy disclosures.
Questions or privacy requests can be sent to [email protected].