Opalescent
Privacy
Policy

Privacy, plainly.

Effective 2026-10-01 · covers this website, the launch waitlist, and the Opalescent app

Who we are

Opalescent is an independent app for valuing opals, operated by its founder. Contact: support@opalescent.app.

What this site collects

  • Your email address, only if you join the launch waitlist. We use it to tell you when the app launches. Nothing else.
  • This site sets no advertising cookies and runs no third-party trackers or analytics scripts.

What we do with it

  • We do not sell your email address, share it with third parties, or use it for anything beyond the purposes above.
  • Every email we send includes a way to be removed from the list. You can also just reply and ask — a person reads the inbox.

The app: your photos leave your phone

Valuing an opal needs a vision model, and that model does not run on your phone. When you scan a stone, the frames from your capture are sent to our server, which passes them to Anthropic’s Claude API for grading. Our server keeps them afterwards to improve the grading, unless you turn that off — see below. Anthropic deletes what it received within 30 days and does not train its models on it.

We say this plainly because the opposite claim is common and would be false here. Nothing about this app works without uploading your photographs.

What we do with a scan

Your frames are graded into attributes — body tone, brightness, pattern, weight and so on. The grading model never sets a price.

To price the stone we search live marketplace listings and build a range from what comparable stones are being asked for. Those listings come from eBay. We also look for listings on opal dealer sites, with a second search that runs through Anthropic’s web search, and ask Etsy for listings. Both are shown beside the eBay ones as evidence you can open and check, and neither takes part in working out the range. What we send for all three searches is a short phrase describing the stone — its type, origin and colour, in a few words — and never your photographs or the identifier your scans are recorded against. Etsy receives a shortened form of that phrase.

We keep your scans by default, and you can stop us

When you value a stone, we keep the frames and the grading on our server and use them to improve the grading. That is on unless you turn it off. The app tells you before you first use the camera, and tells you on a result instead if you never passed that screen — nothing is kept from you until one of those has happened. The switch that stops it is in Settings → Privacy & data, and on the notice itself.

We would rather tell you plainly than have you find out: this is a default we chose because a grader gets better from real stones and there is no other source of them. It serves you and it serves us, and you should be able to decline it in one tap, which is why the switch is on the result itself and not buried.

What we keep is the frames and the original grading, recorded against a random identifier for your app installation. That identifier names an installation, not you.

We do not call that anonymous, because it would not be true. The identifier is what lets us find your scans again when you ask us to erase them, and anything that can be found again can be linked back. Photographs also carry more than the stone — a hand, a bench, the reading on your scale. So: no name and no account, one purpose only, and a way out. Not anonymous.

We use shared scans for one thing, which is making the grading better. They are never sold, never used to advertise to you, and never shown to other people using the app. Improving the grading can mean re-reading a stored scan with the grading model, so Anthropic’s terms above apply to those readings too. Beyond that, the only person who looks at them is the person who runs Opalescent.

The app has no accounts, so it never asks for an email address, a password, your phone number, your contacts, your location or an advertising identifier. One personal detail is asked for, and it is optional: testers can enter a name alongside their invite code, and it travels with feedback they send us so we can follow up on a surprising call. It is not attached to your scans.

When you correct an attribute we keep your correction alongside the original grading rather than replacing it. Disagreement is the useful part.

We keep shared scans for as long as we are using them to improve the grading. There is no fixed expiry, and you can have them deleted at any time.

You can change your mind, and it takes effect

Settings → Privacy & data has a switch that stops any further storage from that moment.

To delete what has already been stored, open Settings → Privacy & data → Erase my shared scans in the app. It removes them from the server permanently, tells you how many it removed, and — if it cannot reach the server — says plainly that nothing was deleted rather than reporting a success it does not have.

You can also write to support@opalescent.app from any address, quoting the Install ID shown under Settings → Account. It is a random per-installation identifier, so it is the only thing that ties stored scans to a device — and it is how we find yours.

Valuations you have saved stay on your phone. They were never uploaded, and erasing shared scans does not touch them.

So “erase my shared scans” means what it says, and it is worth knowing what it does not sweep up: feedback you have written to us, and the record of anything you have bought. Ask us about either and we will delete what we hold. The store’s own receipt is the store’s, and outside our reach.

Feedback you send us

While the app is in testing, every screen has a feedback button. If you use it, we receive what you wrote, a screenshot of the screen you were on, the grading that was displayed, your device and build details, and your invite code with the name you entered if you gave one.

Feedback is stored apart from shared scans, so that words written to us in confidence are never swept into the data used to improve the grading. For the same reason it is not covered by a scan deletion — ask us and we will delete it. Our server logs record that feedback arrived; they never contain what you wrote or the image.

Counting your free scans

Free scans are counted per app installation, using the same random identifier, so that the allowance means something. That count lives on our server, as a single number recorded against that identifier.

Paying for a plan

When you buy a subscription, the store takes the payment — the App Store or Google Play, depending on your phone. Opalescent never sees or holds your card. There is no card on file in the app, no invoice list, and nothing for us to charge you with.

RevenueCat handles subscriptions on our behalf. It receives a random billing identifier for your installation — deliberately a different identifier from the one your shared scans are recorded against, so that a purchase and a photograph cannot be joined up — together with what the store tells it about the purchase: which plan you bought, its price and currency, the store and the platform, and the record of renewals, cancellations and refunds. Like any service the app connects to, it also sees the IP address the request came from. It never receives your photographs, your name, or your card details.

We keep that purchase record while your subscription is running, and afterwards for as long as it may be needed to answer a billing question or handle a refund. Ask us and we will delete what we hold. The store keeps its own record of what you bought, and that one is theirs — we cannot delete it, and neither can we see the card behind it.

The app has no accounts, so a subscription is tied to your store purchase rather than to a sign-in. It is the store’s record of what you bought — not a password — that identifies your subscription, and there is nothing to log in to.

What our logs contain

Each valuation writes one line recording how the scan performed: whether a calibration card was seen, how many comparable listings were found, which model ran, and similar. Those lines never contain your photographs and never contain anything you have written to us.

Separately, our server counts how many requests each IP address makes in an hour, so that no single address can run up our costs. Each count is kept with the address for up to about a day, and is used for nothing else.

Who else is involved

  • Anthropic processes your frames to produce the grading, and runs the web search for comparable listings. Under its commercial terms, inputs and outputs are not used to train its models and are deleted from its systems within 30 days.
  • Cloudflare hosts our server, our storage and this site.
  • eBay provides the marketplace listings the range is built from. We do not send them your photographs, and we hold no eBay user data.
  • Etsy provides further listings, shown as evidence and never used to work out the range. It receives a few search words describing the stone, never your photographs, and we hold no Etsy user data. The term ‘Etsy’ is a trademark of Etsy, Inc. This application uses the Etsy API but is not endorsed or certified by Etsy, Inc.
  • RevenueCat handles subscriptions, and the App Store or Google Play takes the payment. What each of them receives is set out under “Paying for a plan” above.

We do not sell your data and we do not use it for advertising. There is no advertising identifier in the app, and no analytics or advertising software in it.

Children

Opalescent is a tool for opal collectors, dealers and sellers. It is not directed at children, and we do not knowingly collect anything from a child under 13.

Asking us anything

Write to support@opalescent.app and we will answer, including about anything held against your installation — what it is, and to have it deleted.

What this is not

A valuation from Opalescent is an estimated range built from asking prices on active listings. It is not a professional appraisal, not a certificate, and not an insurance valuation. The full terms are in the app, under Settings → Terms of use.

What changed on 1 October 2026

This update corrects two things. It now says that our server counts how many requests each IP address makes in an hour, to keep costs bounded, and keeps each count for up to about a day. That was already happening, and the policy should have said so. And it no longer says we hold no personal details: if you gave a name with your invite code, it travels with any feedback you send, and we keep it with that feedback.

What changed on 25 August 2026

Until today, nothing was kept unless you opted in. Now scans are kept by default and you can opt out — with a switch in Settings → Privacy & data, a notice carrying the same switch if you have not been told yet, and a button that erases what has already been kept. We are stating the change rather than letting you notice it.

If you had already declined, that stands. Turning the default on does not overturn an answer you have given.

Changes

If this policy changes, the effective date above changes with it, and material changes will be noted here in plain language.