Legal
Privacy Policy
Effective date: 29 July 2026. This policy explains what personal data Gemino ("we", "us", "our") collects, why, how we use it, who we share it with, and the rights you have. It is written to comply with the EU General Data Protection Regulation (GDPR 2016/679), the UK GDPR & Data Protection Act 2018, the California Consumer Privacy Act as amended by the CPRA, the Brazilian LGPD, Canada's PIPEDA, South Africa's POPIA, Nigeria's NDPA 2023, Japan's APPI, Australia's Privacy Act, Singapore's PDPA, India's DPDPA 2023, and other applicable data-protection laws.
1. Who we are & how to contact us
Gemino is the AI trust layer for physical commerce. For the purposes of the GDPR and UK GDPR, Gemino is the data controller of the personal data processed through geminotrust.com and the Gemino apps.
Privacy contact: privacy@geminotrust.com.
Data Protection Officer (where required): dpo@geminotrust.com.
2. Scope
This policy applies to the Gemino web app, progressive web app, browser extensions, and any authenticity report generated by Gemino. It does not apply to third-party sites we link to, or to platforms (marketplaces, social networks) where a Gemino report is re-shared by a user.
3. Data we collect
3.1 Data you provide
- Product photos you upload for authenticity analysis.
- Optional product context such as brand, category, seller, purchase location, and free-text notes.
- Account data if you create an account: email address and a hashed password.
- Brand / SME registration data: business name, contact person, phone, official website, registration number, and documents you upload to prove ownership.
- Ownership claim data: name, email, role, and the evidence you submit.
- Donation data: name (optional), email (for receipts), amount, and message. Card details are handled directly by Paystack and never touch Gemino servers.
- Support communications you send us.
3.2 Data we collect automatically
- Approximate country derived from your IP address at the moment of a scan, used to render the global scan map at country-centroid precision with random jitter. We do not store your IP address alongside the report.
- Device identity: a locally generated device ID and a browser fingerprint hash used to enforce free-tier limits and detect abuse (see §6).
- Truncated / hashed IP stored for anti-abuse (rate limiting, fraud scoring) with a short retention window.
- Basic technical logs: user-agent, request path, HTTP status, timestamps.
- Language preference saved locally so the app renders in your language.
3.3 Data we do not collect
- Precise GPS location.
- Phone number, unless you voluntarily provide one on a brand/claim form.
- Contacts, calendar, camera roll, or files beyond the images you explicitly upload.
- Government IDs, biometrics, or health data (please do not upload these).
4. How we use your data (purposes & legal bases)
| Purpose | Data used | GDPR legal basis |
|---|---|---|
| Run AI authenticity analysis | Photos, product context | Contract (Art. 6(1)(b)) |
| Generate a public, shareable report | Photos, product info, verdict, country | Contract; Legitimate interest for public reports |
| Enforce free-tier limits & prevent abuse | Device ID, fingerprint, hashed IP, fraud score | Legitimate interest (Art. 6(1)(f)) |
| Provide accounts & subscriptions | Email, password hash, plan status | Contract |
| Process donations & payments | Email, amount, Paystack reference | Contract; Legal obligation (tax records) |
| Review brand registrations & claims | Business documents, contact info | Contract; Legitimate interest |
| Improve AI reasoning | Aggregated/de-identified scan signals | Legitimate interest, with opt-out |
| Security, incident response, legal defence | Logs, IP hash, account data | Legitimate interest; Legal obligation |
| Send transactional emails | Contract |
Where we rely on legitimate interests, we've completed a Legitimate Interests Assessment (LIA) balancing our interests against your rights. You can object at any time — see §11.
5. Cookies & similar technologies
Gemino uses only essential storage (localStorage, an authentication cookie, and a service-worker cache) needed to sign you in, remember your language, enforce scan limits, and let the PWA work offline. We do not use advertising cookies, cross-site trackers, or Google Analytics-style profiling.
6. AI processing & automated decisions
Gemino uses Google Gemini large-vision models via the Lovable AI Gateway to analyse photos and return a verdict plus a confidence score.
- Verdicts are advisory only. They are not certifications and do not create legal rights against a seller.
- We produce a numeric fraud score to protect free-tier abuse. It is not a solely-automated decision with legal effect under Art. 22 GDPR; a human can review and reverse it on request.
- Photos submitted for authenticity analysis are sent to the AI provider under a data-processing agreement. Providers are contractually forbidden from using your images to train foundation models.
7. Sharing & sub-processors
We share personal data only with the sub-processors we need to run Gemino:
- Supabase (database, storage, auth) — EU/US regions.
- Cloudflare (hosting, CDN, DDoS protection).
- Lovable AI Gateway → Google Gemini (model inference).
- Paystack (payments and subscriptions).
- Resend / transactional email provider (receipts, sign-in emails).
We do not sell personal data and we do not share it for cross-context behavioural advertising.
8. International data transfers
Where personal data leaves the EEA, UK, Switzerland, Nigeria, or another country whose laws require a transfer mechanism, we rely on the European Commission's Standard Contractual Clauses (SCCs), the UK IDTA / UK Addendum, or an adequacy decision. Copies of the SCCs are available on request from privacy@geminotrust.com.
9. Data retention
- Authenticity reports & photos: stored until you request deletion, since the report is intended to be a public record you can link to.
- Account data: for the life of the account plus 90 days after closure.
- Payment records: up to 7 years to satisfy tax and accounting obligations.
- Anti-abuse logs (hashed IP, device signals): up to 180 days.
- Support emails: up to 24 months.
10. Security
We use TLS 1.2+ in transit, encryption at rest, Row-Level Security on every user-facing database table, hashed passwords (bcrypt/argon-family via Supabase Auth), signed short-lived URLs for private storage, principle-of-least-privilege service roles, and continuous automated security scanning. No system is perfectly secure; if you believe you've found a vulnerability, please contact security@geminotrust.com.
11. Your rights
Depending on where you live, you may have the right to:
- Access the personal data we hold about you.
- Correct inaccurate personal data.
- Erase personal data ("right to be forgotten").
- Restrict or object to certain processing, including profiling.
- Receive a copy of your data in a portable, machine-readable format.
- Withdraw consent at any time where processing is based on consent.
- Lodge a complaint with your supervisory authority (see §16).
To exercise any right, email privacy@geminotrust.com. We respond within 30 days (or the shorter period required in your jurisdiction). We may ask for information to verify your identity.
12. Children
Gemino is not directed to children under 16 (or the applicable local minimum, e.g. 13 in the US under COPPA, 18 in Nigeria under NDPA). We do not knowingly collect data from children. If you believe a child has provided personal data, contact us and we will delete it.
13. US state privacy rights (CCPA/CPRA & others)
California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana and other US-state residents have the right to know, delete, correct, and opt out of the "sale" or "sharing" of personal information, and to limit the use of sensitive personal information.
We do not sell or share personal information as those terms are defined by the CCPA/CPRA. To exercise your rights, email privacy@geminotrust.com with the subject line "US State Privacy Request". We will not discriminate against you for exercising a right.
14. Regional annexes
EEA / UK
Our lead supervisory authority for EU matters is the data protection authority in your Member State of residence. UK residents may complain to the ICO (ico.org.uk).
Nigeria (NDPA 2023)
You may lodge complaints with the Nigeria Data Protection Commission (NDPC) at ndpc.gov.ng.
Brazil (LGPD)
Your rights (Art. 18 LGPD) may be exercised by contacting our privacy team. The competent authority is the ANPD.
Canada (PIPEDA / Law 25)
You may complain to the Office of the Privacy Commissioner of Canada or, in Quebec, the CAI.
South Africa (POPIA)
The Information Regulator is the competent authority.
Australia
Complaints may be made to the OAIC.
15. Changes to this policy
We'll post material changes here and update the effective date at the top. If changes affect how we use data you've already provided, we'll notify affected users by email or in-app banner.
16. Complaints
We hope to resolve any concern directly. Please contact us first at privacy@geminotrust.com. You may also lodge a complaint with the data-protection authority in your country of residence, work, or where you believe an issue occurred.
