Legal

Privacy

FiLot is a non-custodial wealth companion. We collect as little as possible, and what we do hold is kept private to you.

What we store

For the waitlist, we store the email address you submit and a note that it came from the website. Inside the beta product, we store the gold photos you choose to upload in a private, owner-only bucket, and the portfolio snapshots derived from them: cost basis, weights, and the figures you confirm. We do not store payment details or wallet private keys, because FiLot never handles them.

If you use the forwarding address we give you, we also store what we read out of the purchase emails you send there: the vendor, the product, the date, the weight and the amount. We keep a redacted outline of the message body, with every digit replaced, so we can tell why a receipt failed to parse without holding the numbers themselves. You can stop this at any time by not forwarding, and the address can be reset.

On-device EXIF & GPS stripping

Before any photo leaves your device, EXIF metadata including GPS and location coordinates is stripped on-device. We never receive where a photograph was taken, only the image content you intend to record.

Fraud prevention & security

To keep gold records trustworthy and detect fraud, when you log a gold item we record a security signal: the item’s serial number, weight and purity, a one-way hash of the photo (a fingerprint of the image, not the image or its coordinates), and your account identifier, IP address, and approximate location (region or city level) at the time. Because a genuine bar’s serial is unique to that bar, this lets us flag the same bar being claimed by different accounts, a sign of a duplicate or counterfeit. These signals are held internally for security only. They are never sold, shared, or used for advertising, and are protected by the same owner-only isolation described below.

This is separate from the on-device stripping above: we remove any location embedded inside your photo, but your network IP address is naturally visible when your device connects to us, and we may use it, and the approximate location derived from it, to prevent abuse. Because these signals exist to prevent fraud, we may retain them after account deletion, anonymised (de-linked from you) where possible.

We never sell your data

We do not sell or rent your personal data or portfolio information, and we do not share it with advertisers, data brokers, or anyone building a profile of you. Your records exist to serve you, not to be monetised.

Running the product does mean a short list of companies handle your data on our behalf, and they are all named below. The ones that hold your gold records, your photos and your email act on our instructions only and may not use your data for their own purposes.

We do advertise, so we owe you a clearer line than “none of them is an advertiser”. We run Google Analytics and Google Ads to see which pages work and which advert brought someone here. That is measurement about pages, not about your holdings: the analytics tools never receive your portfolio, your gold records or your photos. What they do receive, and what you can refuse, is set out under Cookies, analytics and advertising below.

Who else handles your data

Google reads your photo. When you scan a bar, an invoice, or a receipt, the sanitised image is sent to Google’s Gemini vision model, which returns the text it can see so we can pre-fill the form for you. The image is sent for that one request and we do not keep a copy on the server that makes the call. This is the step that turns a photograph into figures, so it cannot be switched off while still using the scanner. If you would rather no image ever left your device for reading, enter the details by hand instead.

Resend delivers our email and receives anything you forward to your FiLot address. A forwarded receipt sits with them for up to 30 days before it ages out.

Supabase hosts the database and the private photo storage described below.

Hostinger runs the mail server behind our own @filot.meaddresses, so anything you write to us passes through them.

Google Firebase serves this website, and Cloudflare sits in front of it. Both see the ordinary things any web server sees: your IP address, your browser, and which page you asked for. Cloudflare uses that to block attacks and to keep the site fast.

Google Fonts supplies the typefaces on these pages, which means your browser fetches them from Google and Google sees your IP address when it does. This happens on every page, before any consent question, because it is part of how the page renders.

Google Analytics and Google Ads are covered in their own section below, because unlike the others you can turn them off.

Cookies, analytics and advertising

We do not use cookies. Not for analytics, not for advertising, not for anything. If you accept measurement, your choice is remembered in your browser’s own local storage on your device, under the name filot_consent. You can clear it in your browser at any time and you will simply be asked again.

We run two Google tools: Google Analytics 4 (propertyG-2NJ3DTWJJ3) to see which pages people actually read, and Google Ads (account AW-18343728325) to tell whether an advert we paid for brought someone here. Google receives that information and handles it under its own terms as well as ours.

Nothing measuring you loads until you decide. When the page opens, all four Google consent categories, analytics storage, ad storage, ad user data and ad personalisation, are set to denied before the tag is allowed to run. The banner then asks you. Decline and they stay denied.

If you decline, we still count that a visit happened, without identifying you: advertising identifiers are stripped from those pings, and where an advert click needs to be matched to a visit, the reference travels in the web address rather than being stored on your device.

What these tools see is which pages were viewed, roughly which country the visit came from, which device type, and which advert or search led here. They never receive your gold records, your photos, your holdings, your wallet address or the contents of your chats. Those live in the database described under Storage and isolation, and the analytics tools have no access to it.

The beta application at beta.filot.me carries the same two tools, on the same consent rules.

Deletion

You can clear local data on your device at any time. When you request account deletion, we cascade the removal through our cloud storage: your photos, snapshots, forwarded-receipt entries, and waitlist entry are deleted from our systems. The one exception is the fraud signals described above, which we may keep, de-linked from you where possible, because a record that vanishes when the account does would defeat the purpose of keeping it.

Storage & isolation

Data is stored with Supabase, protected by Row Level Security (RLS) so that each account can only ever read and write its own rows and its own files. Owner-only isolation is enforced at the database and storage layer, not just in the app.

Non-custodial by design

FiLot never holds your gold, your private keys, or your funds. Every transaction requires your explicit signature in your own wallet, so there is no custodial data to lose or leak.

Contact

Questions about your privacy or a deletion request? Reach us at [email protected].

Last updated: August 2026.