FiLot is a non-custodial wealth companion. We collect as little as possible, and what we do hold is kept private to you.
For the waitlist, we store the email address you submit and a note that it came from the website. Inside the beta product, we store the gold photos you choose to upload in a private, owner-only bucket, and the portfolio snapshots derived from them: cost basis, weights, and the figures you confirm. We do not store payment details or wallet private keys, because FiLot never handles them.
If you use the forwarding address we give you, we also store what we read out of the purchase emails you send there: the vendor, the product, the date, the weight and the amount. We keep a redacted outline of the message body, with every digit replaced, so we can tell why a receipt failed to parse without holding the numbers themselves. You can stop this at any time by not forwarding, and the address can be reset.
If you message us on WhatsApp, we store your phone number, because on that channel it is your account. Messaging us creates one, without a form and without a password, and the number is how we know which gold is yours. We also keep a one-way hash of the number against each message we receive, so we can count how many people wrote to us and spot one number flooding the service, without keeping a list of phone numbers. We do not store the words you send. Photographs you send there are stored exactly like photographs you upload in the app, in the same private, owner-only bucket. You can unlink the number in Settings, and deleting your account deletes it.
When you upload a photo in the app, EXIF metadata including GPS and location coordinates is stripped on your own device, before the picture leaves it.
A photo sent to us on WhatsApp never passes through the app, so we strip it on our server instead: EXIF, GPS and embedded XMP are removed from the file the moment it arrives, before it is stored and before it is sent to Google to be read. Either way we do not receive where a photograph was taken, only the image content you intend to record.
One exception, stated plainly: if you send a PDF rather than a picture, we do not strip it, because editing a PDF safely needs a full parser and a half-edited document is a damaged one. A PDF you send reaches us as you sent it.
To keep gold records trustworthy and detect fraud, when you log a gold item we record a security signal: the item’s serial number, weight and purity, a one-way hash of the photo (a fingerprint of the image, not the image or its coordinates), and your account identifier, IP address, and approximate location (region or city level) at the time. Because a genuine bar’s serial is unique to that bar, this lets us flag the same bar being claimed by different accounts, a sign of a duplicate or counterfeit. These signals are held internally for security only. They are never sold, shared, or used for advertising, and are protected by the same owner-only isolation described below.
This is separate from the on-device stripping above: we remove any location embedded inside your photo, but your network IP address is naturally visible when your device connects to us, and we may use it, and the approximate location derived from it, to prevent abuse. Because these signals exist to prevent fraud, we may retain them after account deletion, anonymised (de-linked from you) where possible.
We do not sell or rent your personal data or portfolio information, and we do not share it with advertisers, data brokers, or anyone building a profile of you. Your records exist to serve you, not to be monetised.
Running the product does mean a short list of companies handle your data on our behalf, and they are all named below. The ones that hold your gold records, your photos and your email act on our instructions only and may not use your data for their own purposes.
We do advertise, so we owe you a clearer line than “none of them is an advertiser”. We run Google Analytics and Google Ads to see which pages work and which advert brought someone here. That is measurement about pages, not about your holdings: the analytics tools never receive your portfolio, your gold records or your photos. What they do receive, and what you can refuse, is set out under Cookies, analytics and advertising below.
Google reads your photo. When you scan a bar, an invoice, or a receipt, the sanitised image is sent to Google’s Gemini vision model, which returns the text it can see so we can pre-fill the form for you. The image is sent for that one request and we do not keep a copy on the server that makes the call. This is the step that turns a photograph into figures, so it cannot be switched off while still using the scanner. If you would rather no image ever left your device for reading, enter the details by hand instead.
Resend delivers our email and receives anything you forward to your FiLot address. A forwarded receipt sits with them for up to 30 days before it ages out.
Meta carries WhatsApp. If you choose to use that channel, everything you send us there, your messages and your photographs, passes through Meta’s servers and is held by them under their own privacy policy, not ours. Media sits with them for around thirty days. We can only reply inside the twenty-four hours after you message us, which is WhatsApp’s rule and not a setting we control. Nothing obliges you to use WhatsApp: the app does the same things, and involves Meta in none of it.
Supabase hosts the database and the private photo storage described below.
Hostinger runs the mail server behind our own @filot.me addresses, so anything you write to us passes through them.
Google Firebase serves this website, and Cloudflare sits in front of it. Both see the ordinary things any web server sees: your IP address, your browser, and which page you asked for. Cloudflare uses that to block attacks and to keep the site fast.
Google Fonts supplies the typefaces on these pages, which means your browser fetches them from Google and Google sees your IP address when it does. This happens on every page, before any consent question, because it is part of how the page renders.
Google Analytics and Google Ads are covered in their own section below, because unlike the others you can turn them off.
We set four small cookies of our own. filot_consent remembers your answer to the cookie banner, yes or no, for a year, so you are not asked on every page. It works across filot.me and beta.filot.me, and a copy is kept in your browser’s local storage in case cookies are blocked. filot_internal is only ever set on the FiLot team’s own devices, so that our own visits are left out of the numbers. filot_seen keeps only the day of your first visit, so our own visit count can tell a returning visitor from a new one. It is set only when analytics is allowed, and deleted if you decline. filot_vid is set only if you press Accept: a random code made in your browser, so our own visit count can show one visitor’s visits together, which screens were opened and what kind of question was asked of FiLot’s AI (the topic, never the words). It lasts 90 days at most and is never renewed, it is deleted if you decline, and our own records drop it after 90 days. None of them holds your name, your email or your holdings. Clear them in your browser at any time and you will simply be asked again.
We run two Google tools: Google Analytics 4 (property G-2NJ3DTWJJ3) to see which pages people actually read, and Google Ads (account AW-18343728325) to tell whether an advert we paid for brought someone here. Google receives that information and handles it under its own terms as well as ours. Google sets its advertising cookies only if you accept. Its analytics cookies follow the rule in the next paragraph.
Google’s advertising measurement never starts until you accept. When the page opens, ad storage, ad user data and ad personalisation are set to denied before the tag is allowed to run, for everyone. Analytics storage is set to denied too, except on a device whose time zone or language is Indonesian: there Google Analytics counts the visit from the start (analytics only, never advertising), and the banner lets you turn it off. Decline, and all four are denied, on that page and on every later visit. Google then still counts that a visit happened, without identifying you: advertising identifiers are stripped from those pings.
We also count visits ourselves. Each page view sends our own server the page address, the site that sent you, and any campaign tags or advert click reference in the link. Your IP address and browser type are used once to make a daily code, a one-way fingerprint that changes every day, so one person is counted once a day; the IP address itself is never stored. This count runs whether or not you accept, holds no name, email or holdings, and is never passed to Google or any advertiser. If analytics is allowed, it also says whether you have been here before, as a rough range (first day, next day, within a week, within a month, longer), never the date. If you pressed Accept, each visit also carries the random code filot_vid described above, and so does each question you ask FiLot’s AI (its topic, never your words), so we can see one visitor’s visits together. Without Accept there is no code.
Where your first visit came from. When you first arrive from an advert, a campaign link or another site, your browser keeps a note of it in local storage under filot_first_touch: the campaign tags, the advert click reference, the referring site and the time. If you later create an account, that note is saved with your account, so we can tell which campaign brought you. You can clear it in your browser at any time.
What these tools see is which pages were viewed, roughly which country the visit came from, which device type, and which advert or search led here. They never receive your gold records, your photos, your holdings, your wallet address or the contents of your chats. Those live in the database described under Storage and isolation, and the analytics tools have no access to it.
The beta application at beta.filot.me carries the same two tools, on the same consent rules.
You can clear local data on your device at any time. When you request account deletion, we cascade the removal through our cloud storage: your photos, snapshots, forwarded-receipt entries, and waitlist entry are deleted from our systems. The one exception is the fraud signals described above, which we may keep, de-linked from you where possible, because a record that vanishes when the account does would defeat the purpose of keeping it.
Deleting your account also removes your WhatsApp number from our systems. What we cannot delete is the copy of the conversation held by Meta and the copy on your own phone; those are yours and theirs to clear, in WhatsApp itself.
Data is stored with Supabase, protected by Row Level Security (RLS) so that each account can only ever read and write its own rows and its own files. Owner-only isolation is enforced at the database and storage layer, not just in the app.
FiLot never holds your gold, your private keys, or your funds. Every transaction requires your explicit signature in your own wallet, so there is no custodial data to lose or leak.
Questions about your privacy or a deletion request? Reach us at [email protected].
Last updated: October 2026.