Valore Privacy Policy

Last updated: 10 October 2026

This policy explains what data the Valore app (iOS) processes, why, who it is shared with, and what rights you have, under Regulation (EU) 2016/679 (“GDPR”) and Italian Legislative Decree 196/2003.

1. Data controller

TooT S.r.l.
Viale della Resistenza 198, 87036 Rende (CS), Italy
VAT no. 03518790781 · REA CS-240879
PEC: toot@kelipec.it · Email: info@toot.srl

2. In short

  • No sign-up needed: the app creates an anonymous account, with no email or password.
  • The photos you take are used only to recognise the item and estimate its value; they stay private.
  • No ads, no tracking, no selling of data.
  • The server is located in the European Union (Frankfurt).
  • You can delete your account and all your data from the app at any time.

3. What data we process

Data Examples Where it comes from
Account identifier anonymous code generated by the app created automatically on first launch
Profile name and city (optional), market (Italy, France, Spain), platforms you sell on entered by you
Item photos up to 4 photos per item, and an optional note written by you (e.g. “model A2093”) taken or chosen by you
Valued items brand, model, condition, estimated prices, price history, alerts, status (to sell, listed, sold) and sale price if you provide it generated by the app from the photos and public listings
Generated listings title and description for Vinted, Subito, eBay and other platforms generated by the app, editable by you
Service usage number of scans this month, credits used, listings generated, date and time recorded by the server to apply limits and credits
Purchases Pro subscription status and credit balance Apple and RevenueCat (we never see payment details)

We do not collect: email, phone number, GPS location, contacts, advertising identifier (IDFA), payment details.

On your phone, the app also uses the camera to suggest how to photograph the item (for example “Is it a phone?”): this recognition happens entirely on the device and sends nothing. Notifications (scan completed, price alerts) and the Live Activity are generated on your phone.

Purpose Legal basis (GDPR)
Recognising the item, estimating its value, generating listings, saving your items and tracking their price performance of a contract, i.e. the Terms of Use (art. 6.1.b)
Managing the subscription, free trial and credits performance of a contract (art. 6.1.b)
Applying usage limits, preventing abuse, ensuring security and controlling service costs legitimate interest (art. 6.1.f)
Replying to your support requests performance of a contract and legitimate interest (art. 6.1.b and f)
Notifications on your phone your consent, given and revocable in iOS Settings

We do not use your data for advertising profiling or for automated decisions with legal effects. The price estimate is an automatic calculation based on public listings: it is an indication, not a professional appraisal.

5. Who we share data with

We process data through providers acting as data processors (art. 28 GDPR), only for the purposes stated:

Provider What it receives Where
Supabase (database, photo storage, server functions) all account data European Union (Frankfurt)
Anthropic (Claude artificial intelligence model) the item photos and optional note, to recognise it; the text, to write the listing United States
RevenueCat (in-app purchase management) anonymous account identifier, subscription status and credits United States
Apple (App Store, payments, notifications) the data needed for the purchase, which Apple processes as an independent controller under its own privacy policy —

To estimate prices, the app queries the public listings of eBay (through the official eBay Browse API), Vinted, Subito, Leboncoin and Wallapop, also through web page reading services. We send these services only the search text (for example “nintendo switch oled”), never personal data or photos.

Anthropic, under its commercial terms, does not use data sent through its API to train its models and keeps it for a limited period for security purposes.

Transfers outside the EU. Transfers to the United States are based on the EU-U.S. Data Privacy Framework, where the provider participates in it, or on the Standard Contractual Clauses approved by the European Commission (art. 46 GDPR).

We do not sell or transfer your data to third parties for commercial purposes.

6. How long we keep data

  • Account, profile, items, photos and listings: until you delete them. When you delete an item, we also delete its photos; when you delete your account, we delete all linked data.
  • Usage log (scans, credits): for the lifetime of the account, because it is needed to calculate monthly limits.
  • Database backups: deleted data may remain there for up to 30 days, after which it is overwritten.
  • Purchase data: Apple and RevenueCat keep it according to their own terms and legal obligations.

The account is anonymous and tied to this device: if you uninstall the app without having linked it to anything else, we will not be able to link you back to your data; it remains on the server until you ask for it to be deleted (see section 7).

7. Your rights

You can exercise at any time the rights provided by arts. 15–22 GDPR: access, rectification, erasure, restriction, portability and objection.

  • Erasure: from the app, in Profile › Delete account (see the Account deletion page).
  • Rectification: name, city and market can be changed directly in Profile.
  • All other rights: write to us at info@toot.srl or by PEC at toot@kelipec.it, stating if possible the account identifier you find in Profile. We reply within 30 days.

You also have the right to lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali) (www.garanteprivacy.it) or with the authority of your country of residence.

8. Children

Valore is not intended for children under 14. If you are a parent and believe your child has given us data, write to us and we will delete it.

9. Security

Data is encrypted in transit (HTTPS). Photos are kept in private storage accessible only to your account; each user can read and edit only their own data. The keys of external services stay on the server and are never present in the app.

10. Changes

If we change this policy, we will update the date at the top and, for significant changes, let you know in the app.