Coop Vision

Privacy Policy

Coop Vision measures colour with your camera and matches it against thread and paint catalogues.

Effective 16 August 2026

The short version. Camera frames are analysed on your device and are not uploaded. There is no advertising, no third-party analytics and no tracking of any kind. Your account is anonymous unless you choose to add an email address. You can export everything you have made, and you can delete your account from inside the app.

1. Who we are

Coop Vision (“we”, “the app”) is the data controller for the information described below. You can reach us at support@vision-app.space or through the support form.

2. The camera

The app needs camera access to do the one thing it exists for: read the colour under the on-screen reticle. Video frames are processed entirely on your device and are never streamed, uploaded or stored by us. Nothing leaves your phone while you are measuring.

The one exception is explicit and visible: if you pin colours to a photo and save that palette, the app stores a small still image of that frame so the pins still point at something. If you have cloud sync switched on, that image is uploaded with the palette. Location metadata is stripped from it before it is stored.

Photos you pick from your library are handled the same way — read on device, and only uploaded if they become a saved palette frame.

3. What we store

DataWhy
A random installation identifierCreates your account without asking you to sign up. We store only a one-way hash of it.
Device model, OS version, app version, languageSupport and compatibility — knowing which build a bug came from.
Palettes, measured colours, matched codes, notes, quantitiesThe work you make in the app. Synced so it survives a reinstall or a new phone.
Your own saved swatches (“My Colours”)Your personal catalogue.
App settingsSo a second device behaves like the first.
White-card calibration recordsColour accuracy: a reading taken under a known calibration can be trusted more than one taken without.
Palette frame imagesOnly when a palette has pinned points, as described above.
Email address and passwordOnly if you choose to add one, so you can sign in on another device. Passwords are stored as a bcrypt hash and never in readable form.
Support messagesTo answer you. See section 8.

4. What we do not do

5. Legal bases

Where the UK GDPR or EU GDPR applies, we rely on performance of a contract for the account and sync features you asked for, and on our legitimate interests in keeping the service working and free of abuse for security logging and rate limiting. Where we ask for consent — camera access, notifications — you can withdraw it at any time in iOS Settings.

6. Sharing

We share your data with nobody for their own purposes. Data is stored on our own servers. We disclose information only where we are legally required to, and we will tell you unless we are prohibited from doing so.

If you create a share link for a palette, anyone holding that link can view that one palette until you revoke it. The page shows only the colours, codes, quantities and notes in that palette — never your account, your email or any other palette. You can revoke a link at any time from the app.

7. How long we keep it

8. Support messages

When you write to us we store your name, email address, message, and a coarse, hashed form of your network address. The address is truncated to a network block before hashing, so it is enough to spot a flood of spam and not enough to identify or locate you.

9. Your rights

You can:

Write to support@vision-app.space for anything you cannot do yourself. If you are in the UK or EEA and are unhappy with our response, you may complain to your national data protection authority.

10. Children

Coop Vision is not directed at children under 13, and we do not knowingly collect their personal information. If you believe a child has provided us data, write to us and we will erase it.

11. Security

All traffic between the app and our servers is encrypted with TLS, and the app additionally verifies the server's certificate against a copy built into the app, so a network that intercepts traffic cannot read it. Passwords are stored as bcrypt hashes; installation identifiers and sign-in tokens are stored only as hashes. Sign-in tokens are single-use and rotate on every refresh — if one is ever replayed, every session on the account is signed out automatically.

No system is perfectly secure, and we will not pretend otherwise. If you find a vulnerability, please write to support@vision-app.space and we will work with you.

12. International transfers

Our servers are located in the European Union. If we ever transfer data outside your region, we will do so under an approved safeguard such as the Standard Contractual Clauses.

13. Changes

If we change this policy materially, we will update the effective date above and give notice in the app before the change takes effect.