Last updated 18 September 2026
You can sign in with Google or Apple only — there is no email and password sign-in. Passwords are never handled by the app; sign-in is handled by the identity provider and a managed authentication service.
Every coin, profile and archived-run row carries your account ID, and access rules on the database only return rows that belong to the signed-in account. Even a request with your account's public app key cannot read someone else's collection.
Coin photos are kept in a private store, filed under a folder named after your account. Access rules block anyone else from reading, replacing or deleting them, and the app only ever shows them through temporary links that expire.
All traffic between your device and the app is encrypted over HTTPS.
Use a password you don't use elsewhere, and sign out on shared devices. If you think your account has been accessed by someone else, change your password immediately.
If you find a security problem, please report it to the app owner rather than sharing it publicly, and we'll address it as quickly as we can.