AgentMClose
VintSnaptitraCitedSitePriceSiblinyLanyardTariffShieldPopSnap

Privacy policy

Last updated 31 August 2026. This policy applies to the VintSnap app for Android and iOS.

Legal · VintSnap

01 Overview

This policy explains what VintSnap collects, why, and the choices you have over your information. We keep it short and in plain English.

VintSnap is made by Agent M. It is an independent app: it is not affiliated with Vinted, we never ask for your Vinted login, and we never connect to or post from your Vinted account. You copy your finished listing across and post it yourself.

02 What we collect

We collect only what the app needs to work:

  • Account basics. Your email address and an account ID when you create an account. On Android you can sign in with Google; on iOS with Apple. If you use Sign in with Apple and choose to hide your email, we only ever see Apple's private relay address.
  • Your photos and listings. The photos you take or import, and the title, description, hashtags and price the app writes for them. These live on your device — see section 03 for what happens during an analysis.
  • Credits and purchases. Your credit balance, how many rewarded ads you have watched today, your referral code, and a record of credit packs you have bought.
  • Diagnostics. Crash reports and basic performance data, so we can fix what breaks.
  • Product analytics. Which screens and features you use, and whether an analysis succeeded. This is tied to a one-way hashed version of your account ID, not to your email address.
  • Advertising data. If you see ads, standard ad-request information (device and app details, an advertising identifier where you have consented, and an approximate location derived from your IP address).
  • Support messages. Whatever you write in the in-app feedback form or email to us.

We do not ask for your date of birth, your address, or your payment card details. Card details are handled entirely by Google Play or the App Store — we never see them.

03 Your photos and how the AI analysis works

This is the part people ask about most, so here it is in full.

  • Where your photos go. When you analyse an item, the app resizes your photos and sends them to Google's Gemini models, which generate the listing. Depending on the platform and the release, that request goes either straight from the app or through our own Cloud Functions hosted in Europe.
  • The fallback. If Gemini is unavailable or fails, the same photos and prompt may be sent instead to OpenAI (GPT-4o-mini) so your analysis still completes. This only happens on that fallback path.
  • We do not keep your photos. Photos are passed through for the analysis and are not written to our database or to any file storage. Your photos and your listing history stay on your device unless you choose to share or email them.
  • Google and OpenAI process them as our providers, under their own terms, for the purpose of returning the analysis.
  • Emailing a listing to yourself. If you use "email me my listing", or attach photos to a support message, those photos are sent through our email provider to your own verified account email or to our support inbox.
  • The photo-trust badge. Photos taken inside the VintSnap camera get a small badge burned in with a short code such as VS-8F3K2. When that happens we register the code with the capture date, how many photos were in the batch, and the platform. We do not register the photo itself, and the public check at vintsnap.app/verify never returns your account or your identity. Photos imported from your gallery are never badged.

04 How we use your information

  • To provide and improve the core features of VintSnap — writing listings, suggesting prices, and keeping your history and credits in sync.
  • To take payment for credit packs and to grant the credits you have earned or bought.
  • To keep the service secure and prevent abuse — for example, checking that a rewarded ad was really watched.
  • To show ads to users on the free tier, and to measure whether our own marketing works.
  • To respond when you contact support.

Free users see ads. Buying any credit pack — including the cheapest one — removes all ads permanently.

  • Google AdMob serves the ads (rewarded video, banners and native placements).
  • Liftoff Monetize (Vungle Exchange) is our only other advertising partner. It bids on ad requests through AdMob and receives the bid-request data described in section 02. It is registered as vendor 667 in the IAB Transparency & Consent Framework.
  • Meta Audience Network is no longer in the app. The adapter was removed in August 2026, and the Unity adapter earlier the same year. No Meta or Facebook advertising SDK ships in VintSnap.

Consent in the UK and EEA

Before any ads or analytics run, we show Google's consent form (the User Messaging Platform). If you decline, or if the form cannot be shown for any reason, we fail closed: nothing personalised runs.

You can change your mind at any time. Open Settings in the app and use the privacy and ads consent row to reopen that form. On Android the same option also appears on the Credits screen. The row is shown where Google's consent framework tells us your region requires it.

If you decline consent, we opt you out of product analytics, run our attribution provider in anonymised mode with no device identifiers, and do not request personalised ads.

App Tracking Transparency (iPhone)

On iPhone, we also show Apple's standard "Allow app to track" prompt. If you choose "Ask App Not to Track", we don't receive your device's advertising identifier: ads still show but are not personalised, and attribution runs in anonymised mode. You can change this at any time in iOS Settings → Privacy & Security → Tracking.

06 Analytics, crash reporting and attribution

  • PostHog gives us product analytics — which features get used, and where people get stuck. It runs on PostHog's EU infrastructure, and identifies you by a one-way hash of your account ID rather than your email. Session recording is switched off.
  • Sentry collects crash reports, hosted in Germany. We strip your email address, username and IP address from every crash report before it is sent.
  • AppsFlyer tells us which marketing brought someone to the app. Without your consent it runs in anonymised mode, with no device identifiers attached.
  • Google Analytics for Firebase is bundled as part of the Firebase toolkit we use for crash reporting. We do not send it any custom events of our own.

07 Who we share data with

We never sell your personal data. We share it only with the providers we need to run the service, under contract, and only for the purposes below.

ProviderWhat they do for usWhat they receive
Google (Firebase)Sign-in, your account record, app configuration, push notifications, crash reporting, anti-abuse checks and our own server functionsYour email address, account ID, credit balance and app diagnostics
Google (Gemini)Writes your listing from your photosYour item photos and the analysis prompt
OpenAIFallback listing generation when Gemini is unavailableYour item photos and the analysis prompt, on that fallback only
Google AdMob and the User Messaging PlatformServes ads and collects your consent choiceAd-request data and your consent status
Liftoff Monetize (Vungle Exchange)Bids on ad requests through AdMobAd bid-request data
Google Play BillingTakes payment on AndroidYour purchase; Google handles the payment details
Apple and RevenueCatTake payment and validate purchases on iOSPurchase receipts and an anonymous app user ID
eBay (Browse API)Supplies comparable market pricesSearch terms describing the item, such as brand and category — no personal data
PostHogProduct analytics (EU hosting)Feature usage against a hashed account ID
SentryCrash reporting (German hosting)Crash and error details, with personal fields stripped
AppsFlyerMarketing attributionInstall and campaign data, anonymised without consent
ResendSends the "email me my listing" email and delivers your support messagesYour email address, the listing text and any attached photos

We may also share information where the law requires it, or to investigate fraud or abuse of the credit system.

08 Where your data is held

Our server functions run in Google's europe-west1 region. PostHog is on its EU infrastructure and Sentry on its German infrastructure.

Some of the providers listed above are based outside the UK and the EEA, or operate global infrastructure, so your information may be processed outside your country. Where that happens it is covered by the safeguards those providers offer, such as standard contractual clauses.

09 Storage and security

Data is encrypted in transit, and encrypted at rest by the cloud providers that hold it. Access to production systems is limited to the people who need it.

Listings are prepared for you to post yourself; we never see, connect to, or store your Vinted account credentials.

The photo-trust registry is server-only — no app, and no other user, can write to it. That is deliberate: a registry anyone could write to would let someone forge a "captured live" record for photos they did not take.

10 How long we keep things

  • Your account record is kept until you delete your account.
  • Your photos are not retained by us at all — see section 03.
  • Your listings and photo history live on your device, so they go when you delete them or remove the app.
  • Analytics and crash data are held by PostHog and Sentry under their own retention settings.
  • Photo-trust records are kept so that a badge code stays checkable by a buyer. They contain no photo and no account identifier.
  • Anonymous sale data. When you mark an item as sold, the app can add the brand, category, condition, sold price, region and how long it took to sell to a shared pool that improves price suggestions for everyone. These records carry no account identifier and cannot be traced back to you, so they stay in the pool after you delete your account.

11 Your choices and controls

  • Consent. Reopen the ads and privacy consent form from Settings at any time, as described in section 05.
  • Turn ads off entirely. Buy any credit pack and ads stop for good.
  • Delete your account. Settings → Delete account removes your account record and your sign-in. You can also start the process at agentm.co.uk/products/vintsnap/delete/.
  • Notifications. Turn them off in your phone's settings, or in the app.
  • A copy of your data. There is no export button in the app yet, so email us and we will send you what we hold.

12 Your rights

Where UK or EU data protection law applies, you have the right to ask us for a copy of your data, to correct it, to delete it, to restrict or object to how we use it, and to have it sent to another provider. You can also withdraw consent at any time, which will not affect anything we did before you withdrew it.

Email us and we will handle your request. If you are not happy with how we have handled it, you can complain to the UK Information Commissioner's Office, or to your local data protection authority.

13 Children

VintSnap is not intended for children. You should only use it if you are old enough to hold a resale marketplace account in your country.

14 Changes and contact

We will post material changes on this page and update the date at the top. Questions about your privacy? Email hello@agentm.co.uk.

Kept with the app’s source code and published here unchanged.

How AgentM handles data across all its products