PRIVACY POLICY

Date of Last Revision: January 26, 2026

 

1. Introduction & Scope

Legit App Inc. (“LegitApp,” “we,” “us,” or “our”) is committed to protecting your privacy. This policy explains how we collect, use, and share your information when you use our website, mobile application, API, and authentication services (collectively, the “Services”).

By using the Service, you consent to the data practices described in this policy.

 

2. Information We Collect

We collect information to provide accurate authentication and improve our AI models.

2.1 Information You Provide:

  • Account Data: Name, email address, encrypted password, and billing details.
  • Authentication Data (Crucial): Photos of items, receipts, certificates, and descriptions you upload for authentication.
  • Communications: Support tickets, dispute documentation, and feedback.

2.2 Automated Data Collection:

  • Device Data: IP address, device model (e.g., iPhone 15 Pro), operating system, and unique device identifiers (UDID/IDFA). We use this to detect fraud (e.g., multiple accounts from one device).
  • Usage Data: Time spent on app, clickstreams, and error logs.
  • Location Data: General location based on IP address.

2.3 Image & Biometric Disclaimer:

While we do not actively collect biometric data (like face scans), you acknowledge that photos you upload may inadvertently contain images of yourself or others (e.g., a hand holding a bag, a reflection in a watch face). By uploading these images, you consent to our processing of this incidental data.

 

3. How We Use Your Information (The "AI Training" Clause)

This section is critical for protecting your business model.

We use your data to:

  • Provide Services: Process orders, issue certificates, and handle payments.
  • Train Artificial Intelligence (Protective Upgrade): We use the images and item data you upload to train, validate, and improve our machine learning algorithms and computer vision models. This allows our system to become smarter at detecting fakes. You acknowledge that this use is essential to the Service.
  • Fraud Prevention: Detect suspicious activity, such as users attempting to validate known counterfeits to resell them.
  • Marketing: Send you updates, provided you have not opted out.

 

4. Data Ownership & User Content

4.1 Your License to Us:

While you retain ownership of the photos you take, by uploading them to LegitApp, you grant us a perpetual, irrevocable, worldwide, royalty-free, and non-exclusive license to use, reproduce, modify, and display these images for:

  • Issuing the authentication result.
  • Internal research and AI model training.
  • Marketing materials (e.g., "Real vs. Fake" educational blog posts), provided we remove personally identifiable information.

4.2 Anonymization:

We may aggregate and anonymize your data (stripping your name and email) to create industry reports (e.g., "Top Counterfeited Brands of 2025"). We own all right, title, and interest in this aggregated data.

 

5. Sharing Your Information

We do not sell your personal data. We share data only as follows:

  • Service Providers: With payment processors (Stripe/PayPal), cloud hosting (AWS/Google Cloud), and customer support tools.
  • Legal Compliance: If required by subpoena, court order, or to report criminal activity (e.g., trafficking of counterfeit goods) to law enforcement.
  • Business Transfers: If LegitApp is acquired or merged, your data (including authentication history) will be transferred to the new owner.

 

6. Data Retention & Deletion

6.1 Retention: We retain your personal data as long as your account is active.

6.2 Authentication History (Protective): Even if you delete your account, we retain the images and data related to completed authentications indefinitely. This is necessary to:

  • Maintain the integrity of issued Certificates (so a future buyer can verify them).
  • Prevent "Certificate Shopping" (users re-submitting the same fake item until it passes).
  • Continue training our AI models.

We will anonymize this retained data upon your account deletion request.

 

7. International Data Transfers

LegitApp operates in the United States. If you are accessing the Service from the EU, UK, or other regions, you acknowledge that your data will be transferred to and processed in the U.S., where data protection laws may differ. We utilize standard contractual clauses and strict security measures to protect international transfers.

 

8. Your Rights (GDPR / CCPA)

Depending on your location, you may have the right to:

  • Access: Request a copy of the data we hold about you.
  • Correction: Update incorrect information.
  • Deletion: Request deletion of your Personal Data (Name/Email). Note: As stated in Section 6.2, we may retain non-personal authentication images.
  • Opt-Out: Unsubscribe from marketing emails.

To exercise these rights, contact us at privacy@legitapp.com.

 

9. Security

We use industry-standard encryption (SSL/TLS) to protect your data in transit and at rest. However, no transmission over the internet is 100% secure. You are responsible for keeping your account credentials confidential.

 

10. Children's Privacy

Our Service is not for users under 13 (or 16 in the EEA). We do not knowingly collect data from children. If we discover such data, we will delete it immediately.

 

11. Changes to This Policy

We may update this policy to reflect changes in our AI technology or legal requirements. Material changes will be notified via email or an in-app notification.