Resale Records — Privacy Policy
Last updated: 2026-06-30 Effective date: 2026-06-30
Resale Records ("we," "our," or "the app") is a mobile application for individual resellers, pickers, and estate-sale flippers. This Privacy Policy explains what data Resale Records collects, how we use it, who we share it with, and what choices you have.
What Resale Records Is
Resale Records is a financial record-keeping app for resale businesses. It tracks:
- Mileage driven to sourcing trips (estate sales, yard sales, auctions)
- Photos and costs of items purchased at those sources
- Sale records (price, marketplace, fees, shipping)
- Charitable donations of unsold inventory, including paper receipts
Resale Records does not sell items on your behalf, process payments, or file tax returns. It produces a Schedule C-shaped CSV export that you give to your CPA.
What Data We Collect
Data you provide directly
| Category | Examples | When collected |
|---|---|---|
| Account | Email address, password (hashed) | Sign up |
| Pickups | Photo, location name, GPS lat/lng, cost, source type, intended channel, intended price, notes | When you record a pickup |
| Trips | Start time, end time, distance, classification (sourcing/personal) | When you start a trip |
| Sales | Sold date, sold price, marketplace, marketplace fees, shipping cost, listing URL | When you record a sale |
| Donations | Date, organization, fair-market value, receipt photo | When you record a donation |
Data we generate from your inputs
- OCR-extracted donation receipt fields (date, organization, item count, declared value, signature present). Generated when you opt in to "Snap a receipt" donation capture.
- Realized profit per sale (computed locally; not stored as a separate field).
- Aggregated tax export (Schedule C-shaped CSV) generated on demand.
Data we do NOT collect
- We do not collect bank account, payment card, or payment processor credentials.
- We do not track you across other apps or websites.
- We do not serve advertising, and we do not collect advertising identifiers.
How We Use Your Data
- To provide Resale Records's core functionality (mileage capture, pickup records, sales records, donations, tax export).
- To compute derived values (realized profit, Form 8283 auto-flag, mileage deduction).
- To enforce free-tier usage limits (e.g., 25 pickups/month, 50 trips/month, 5 donation-receipt OCRs/month for Free users).
- To authenticate your account and protect against unauthorized access.
We do not sell your data. We do not use your data for advertising. We do not train AI models on your data.
Third-Party AI Disclosure — Donation-Receipt OCR
Resale Records uses an OpenRouter free-tier vision-language model (default nvidia/nemotron-nano-12b-v2-vl:free, configurable via the OCR_MODEL env var on our Cloudflare Worker) to extract structured data (date, organization, item count, declared value, signature present) from paper donation receipts you photograph.
- What is sent: Your donation-receipt photo (the image file) and a small structured prompt asking for the fields above.
- What is NOT sent: Your pickup records, sales records, mileage, or other personal data. The OCR endpoint receives only the receipt image and prompt.
- Consent: Apple App Review Guideline 5.1.2(i) requires explicit consent before sending your data to a third-party AI. Resale Records presents a consent modal the first time you tap "Snap a receipt" on a donation. You can decline and enter donation data manually.
- Data retention by the model provider: OpenRouter is a multi-model gateway; the receipt image is forwarded to whichever underlying provider the model resolves to. OpenRouter's published privacy policy applies to the request in transit, plus the underlying provider's policy (currently NVIDIA for the default
:freemodel). Both providers do not train on our traffic; refer to OpenRouter's terms at https://openrouter.ai/privacy and NVIDIA's Nemotron model terms for the per-request retention window. - Disable: You can disable OCR and use manual entry only. The toggle lives in Settings → Donations → OCR Provider → Manual entry.
Third-Party AI Disclosure — eBay Message-Draft
Resale Records uses an OpenRouter free-tier text model (default openai/gpt-oss-20b:free, configurable via DRAFT_MODEL) to draft a seller reply when you tap "Draft reply" on a buyer message in the eBay Inbox.
- What is sent: The buyer-seller message thread (after a PII strip in the Cloudflare Worker that drops buyer names, emails, and any other non-allow-listed fields), item title, order status, optional tone/instructions.
- What is NOT sent: Your Supabase JWT is verified by the Worker but never forwarded to OpenRouter; your identity (the JWT
sub), the rest of your Resale Records account data (purchases, donations, mileage, photos). - Consent: First-time only, an inline pre-action disclosure on the Draft-reply button explains the model + provider and lets you decline (you can type the reply yourself).
- Data retention: Same OpenRouter + underlying-provider treatment as OCR. Refer to OpenRouter's privacy policy and
openai/gpt-oss-20b's model card for the retention window. - Disable: Settings → Inbox → AI drafts → Off.
Storage and Security
- Photos, OCR-extracted data, and trip records are stored in Supabase Storage and Postgres with row-level security (RLS) scoped per user.
- All data is encrypted in transit (TLS 1.2+) and at rest (AES-256 at the storage layer).
- Authentication uses Supabase Auth with email+password or magic-link. Passwords are hashed with bcrypt.
- We do not log receipt images, OCR results, or financial data to third-party analytics services.
Data Sharing
We share data only with the following categories of recipients, and only the data they need to perform the service:
| Recipient | What they receive | Why |
|---|---|---|
| Supabase | All your data | Database and storage hosting |
| OpenRouter (multi-model gateway) | Donation-receipt photos (when you tap "Snap a receipt"); stripped eBay message thread + reply metadata (when you tap "Draft reply") | Both AI integrations; the OpenRouter API key never enters the app, and the Worker's allow-list strips PII |
| Apple | Aggregated, anonymized App Store usage signals | App distribution and crash diagnostics |
| eBay, Inc. (optional) | OAuth grant for sell.account, sell.inventory, sell.fulfillment | Read-only sale sync (see "Connected Marketplaces" below) |
Connected Marketplaces (eBay)
Scope. Connecting your eBay seller account enables a read-only integration. Resale Records pulls your active listings and sold orders via eBay's API and creates matching sales records locally. We never create, edit, or delete anything on your eBay account.
What we store. An OAuth refresh token, encrypted at rest with AES-256-GCM using a project key. We also store your eBay user ID, username, granted scopes, and token expiry. Your eBay password is never seen by Resale Records — authentication happens entirely against eBay's servers via standard OAuth 2.0 + PKCE.
How often we sync. When you open the app (foreground), when you tap "Sync now" in Settings, and once per day (3am UTC) via a scheduled background job.
Opt-out. Disconnect at any time from Settings → Marketplaces → Disconnect. This deletes the stored token immediately and stops future syncs; locally-synced sales records are retained unless you delete them.
Third party. All eBay data flows through eBay, Inc. Resale Records does not warrant the accuracy, completeness, or timeliness of eBay-sourced data.
We do not sell, rent, or trade your data to advertisers, brokers, or data aggregators. We do not share your data with other Resale Records users.
Your Rights and Choices
- Access: All your data is accessible inside the app. You can export it as CSV from the Tax Export screen.
- Delete: You can delete individual records from each list screen. To delete your account, sign out and email [email protected] with "Delete account" in the subject line. We will delete your account and all associated data within 30 days.
- Correct: Edit any record by tapping it.
- Disable AI OCR: Settings → Donations → OCR Provider → Manual entry.
- Export: Tax Export screen produces a Schedule C-shaped CSV of all your data.
Children
Resale Records is intended for adult users (18+) running resale businesses. We do not knowingly collect data from anyone under 13. If you believe a child under 13 has created an account, email [email protected].
Tax and Legal Disclosure
Resale Records is a record-keeping tool. It is not a tax preparation service, and we are not a CPA, EA, or licensed tax preparer. The Schedule C-shaped CSV export is for you to give to your CPA or tax preparer.
Resale Records does not give tax advice. Always confirm the application of any deduction with a licensed tax professional in your state.
International Users
Resale Records is operated from the United States. If you use Resale Records from outside the United States, you understand that your data will be transferred to and processed in the United States. The protections of your local jurisdiction may differ from those in the US.
Changes to This Policy
We may update this Privacy Policy. The "Last updated" date at the top will reflect the change. Material changes will be announced in-app and via email if you have an account.
Contact
Acceptance
By using Resale Records, you agree to this Privacy Policy.