Numikeep
How it worksLegacy planPrivacyFAQLog inGet early access

Privacy

Privacy policy

In effect 26 September 2026. Numikeep is operated by Snowpack Numismatics, Colorado, USA.

The short version. Your collection — every coin, what you paid, where it is kept, and your notes about it — is stored on our servers, encrypted at rest and in transit, behind your account. A small number of people here can reach it, and only to keep the service running or to help you; that is covered in §2, which is the section worth reading. We do not sell anything to anyone, we run no advertising and no trackers inside the app, and we never share your data except with the infrastructure providers listed below. This marketing website measures its own traffic with Google Analytics; the app where your collection lives does not.

1. How your account works

Numikeep works like an ordinary online account. Your collection lives on our servers, behind your sign-in, so it is the same on your phone, your computer and the web, and so that losing a password or a phone never means losing the record you have built — for you, or for the family the legacy plan is there to help.

It also means your collection is not hidden from us the way the contents of a safe deposit box are. We can help you back in, and we can see what went wrong when something breaks. What we owe you in return is precision about who can look and when, which is the rest of this page. If that is not the arrangement you want, §9 explains how to export everything and close your account, and we will not make it difficult.

2. Who can reach your collection

Your collection is stored in a database that our servers can read. It is encrypted in transit and encrypted at rest on disk by our hosting provider — which protects it from a stolen hard drive, and does not protect it from us. We would rather say that than let “encrypted” do work it has not earned.

Within Snowpack, access falls into three cases:

  • Support access, logged. The application has exactly one sanctioned way for a person here to open somebody else's collection. It cannot run without first writing a record of who looked, when, and the reason given. That record is kept and cannot be edited afterwards.
  • Engineers with database credentials. A small number of people can reach the database directly, because somebody has to be able to restore a backup or fix a broken migration. Direct database access is not captured by the log above, and we are telling you that rather than letting the previous bullet imply a completeness it does not have. This is true of essentially every hosted service you use; it is rarely written down.
  • Nobody else, for any reason. Not to browse, not out of curiosity, not to decide what to offer you, and not to build a list of who owns what. See §8 on our conflict of interest, which is the version of this that would actually be tempting.

We deliberately do not store a running total of what your collection is worth on your account record, and we do not compute one for our own use. On a product like this that single number is a targeting signal all by itself, and we would rather not be holding it.

3. What we hold

All of it:

  • Your collection — each coin, its grade and certification, what you paid and when, which location it is kept in, your dealers, your photographs, and the instructions you wrote for your heir.
  • Your email address, and a hash of your password. A hash is a one-way fingerprint: it lets us check a password you type without our ever holding the password itself.
  • Your backup phrase, hashed the same way. We cannot read it and cannot tell you what it is — if you lose it, you set a new one from inside your account.
  • Your passkeys, if you use your fingerprint or face. What we store is a public key, which can verify you but cannot impersonate you. Your fingerprint itself never leaves your device and we never receive it.
  • Session and sign-in records — hashed session tokens, single-use email sign-in links, and a push notification token if you turned notifications on.
  • Your access cards: the name you gave each card and a one-way fingerprint of its words — never the words themselves, so we cannot print or read a card for anyone.
  • Your mobile number, if you add one for text alerts — proved with a texted code, and used only for access-card countdown alerts.
  • If someone uses one of your cards: the name and email address they type in, when they started the countdown, when it opens, whether you stopped it, and a log of every email we sent about it — to you and to them — and whether it went, including texts. You can see all of this in Settings. See §6.
  • Any API key you add for a service like PCGS. This one is encrypted with a key we hold separately, because a credential to somebody else's account is a different kind of liability from a coin list.
  • Support correspondence, if you write to us. See §5.
  • Ordinary server logs — request times, error traces, and the health of scheduled jobs.
  • Connected apps, if you connect one. For each app you connect — by pasting a key or with “Connect with Numikeep” — we hold its name, the permissions you gave it, when it was connected and last used, and one-way fingerprints of its keys and tokens (never the keys themselves). We also record which coins, locations and photos each app added, so it can change only its own. What a connected app may do is in §8.

4. Coin values

Numikeep does not answer per-coin price queries, and there is no log anywhere of which coins you looked up. Your device downloads the entire public price table — the same file, byte for byte, that every other user downloads — and does the arithmetic locally. That table is public market data with no user information in it whatsoever.

This mattered more when we could not see your collection, and we have kept it anyway: it is simpler, it works offline, and it means the price guide vendor learns nothing about any individual collector.

5. If you write to us for help

Support email is handled by our own system, not a hosted helpdesk, so that correspondence about a private product does not end up living in a third party's database.

People in difficulty send everything they have, and that includes secrets. So before an incoming message is stored, it is automatically scanned for things that look like backup phrases, heir card secrets or passwords, and those are stripped out. The redacted text is what gets written down; the original is never stored. We keep only the fact that a redaction happened, so we can tell you what occurred and advise you to set a new one.

If you send us a password or a backup phrase, treat it as compromised regardless and replace it. It has passed through email, which is not private, and no amount of care on our end changes that.

We will never ask you for your password or your backup phrase. Not by email, not on the phone, not to “verify your identity”. We do not need them to help you, and anybody who asks is not us.

6. The person who uses an access card

Someone who uses one of your access cards gives us their name and email address, so that you know who is asking and so we can tell them when the countdown ends. That is somebody else's personal information, and it deserves saying plainly:

  • We use it for exactly one purpose — that request. We show it to you, the owner, and we email them about the request. Never marketing, never anything else.
  • The name and email are what they typed. We don't verify them, and we say so wherever we show them to you.
  • They can ask us what we hold about them, and the answer is short: a name, an email address and the messages we sent about that request. If they ask us to delete it, we will, and the request is stopped.

7. If you show us a coin

You can choose to show a single coin to Snowpack Numismatics for a purchase or consignment offer. That is a deliberate act, one coin at a time, and it is the one moment a coin is put in front of a buyer.

When you do, that coin's details and the photographs you chose are put in front of a buyer here as a piece that may be for sale. Where it is stored is refused by the system — the storage location is never included in an offer, even if you try to send it. The same holds when the app drafts an email to an auction house or another dealer: the location, what you paid and your own notes are left out, always. You can withdraw the offer, which stops us showing it to our buyers, but we cannot un-see what was already read, and we will not pretend otherwise.

To be exact, since §2 already told you we can see your collection: showing us a coin is not what makes it visible to us — it is what makes it commercially in play. That is a real distinction and it is the one this section is about. Nobody here goes looking through collections for things to make offers on, and §8 is where we explain why you should hold us to that.

8. Who else touches your data

We use infrastructure providers. They store or transmit what we described above, under contract, and none of them are permitted to use it for anything but providing that service to us:

  • Google Cloud (United States) — servers, database, file storage and key management.
  • Cloudflare — this website, the app, DNS, and the anti-spam check on our forms (see below).
  • Apple and Google — push notifications, if you turn them on. A notification tells you to open the app; it never contains collection data.
  • Twilio — only if you add a mobile number: it delivers our text alerts, so it receives your number and the text of each alert. Never anything about your coins. We never sell, rent or share your mobile number or your consent to receive texts with anyone for marketing. See text alerts.
  • Our email provider — for the messages we send you and for support mail you send us.
  • Greysheet / Collectors Universe — we fetch the public price table from them. They receive nothing about you, because we ask on behalf of everybody at once rather than on behalf of any user.

Apps you connect yourself

You can connect another app to your collection — CoinVault, for example, or a tool that adds coins for you. Nothing is shared with an app until you connect it, and you choose what it may do:

  • Add coins (every connected app): it can add coins, storage locations and photos to your collection, and change or remove only what it added. It cannot change or delete anything you entered.
  • See which coins you have (only if you allow it): what each coin is — date, series, grade, grading service, certification, CAC sticker, quantity, copper colour, and when it was added or changed.
  • Never, whatever you allow: where your coins are kept, what you paid, your notes, your photos, your heir plan, or anything about your account. A connected app cannot sign in as you.

An app that can see your coins holds what it has seen under its own privacy policy, not ours — only connect apps you trust. You can disconnect any app in Settings → Connected apps, and it stops working immediately. Resetting your password or signing in with your backup phrase disconnects every app, in case either was done because someone else got in. We may disable an app that breaks these rules.

We do not use advertising networks, session recorders or data brokers, and we never sell or share your information for advertising.

Analytics, and where they are not

This marketing website — numikeep.com, the pages you are reading now — uses Google Analytics to count visits and see which pages people find useful. It sets cookies and Google receives your IP address and general location, as it does on most of the web.

The app does not. There is no analytics, no tag manager and no third-party script of any kind on app.numikeep.com. That is deliberate and it is the line we care about: nothing about which coins you own, what they are worth or where they are kept is ever sent to Google, to an advertiser, or to any third party by us. Your collection goes to our servers and stops there — the only exception is an app you connect yourself and allow to see your coins, described above, and even then never where they are kept or what you paid.

If you would rather not be counted even on the marketing pages, any browser tracker-blocker stops it, and nothing on this site behaves differently when it is blocked.

Cloudflare Turnstile, on our forms

Our forms are protected by Cloudflare Turnstile, which checks that a submission comes from a person rather than a script. We use it because the alternative — publishing an email address on the open web — is how a small company's inbox becomes unusable, and how the people who genuinely need help end up waiting behind a thousand pieces of spam.

When a form loads, Turnstile collects the following from your browser and sends it to Cloudflare for that check:

  • your IP address;
  • your TLS fingerprint;
  • your browser's user-agent string;
  • the site key and the page the form is on.

Cloudflare states that it cannot identify individuals from these signals, and uses them to detect bots and to improve that detection. It is not used to profile you, to advertise to you, or to follow you between websites, and we receive none of it — only a pass or fail. Turnstile does not display ads and, unlike some alternatives, does not ask you to label photographs.

Your use of Turnstile is subject to the Cloudflare Turnstile Privacy Addendum and the Cloudflare Privacy Policy.

None of this touches your collection. Turnstile runs on public forms — writing to us, and asking for access — and there is no Turnstile check anywhere near your collection, because it never passes through a form in the first place.

We have never sold personal information and we will not. There is no version of this business where that makes sense: we are a coin dealer, we make our money on coins, and one collector who trusts us is worth far more over a lifetime than any list would fetch once.

9. Keeping it, and deleting it

You can export your entire collection at any time, in a readable format, from your own device. You do not need us to do it and you do not need our permission.

You can delete your account from the app. When you do, we delete your collection, your photographs, your sign-in credentials and passkeys, your mobile number, your access cards, and every request made with them — including the name and email of anyone who used one. Deletion of the live data is immediate; it ages out of encrypted backups within 35 days.

One thing survives, and you should know it: support tickets are kept for two years. They do not contain your collection.

10. Your rights

Depending on where you live you may have formal rights to access, correct, export or delete your personal information, and to appeal if we refuse. We extend all of them to everyone, regardless of jurisdiction, because drawing those lines by geography would be more work than simply honouring the requests.

Write to contact form and a person will answer within 30 days. We do not require you to create anything or pay anything to exercise a right, and we will not treat you differently for having exercised one.

11. Children

Numikeep is not for anyone under 18 and we do not knowingly collect information from children. If you believe a child has created an account, write to us and we will remove it.

12. Changes

If we change this policy in a way that affects what we collect or who we share it with, we will email you before it takes effect — not merely update the date at the top and hope you re-read it. The date at the top tells you which version you are looking at.

13. Contact

Use our contact form for anything on this page, or for everything else. A person reads both.

Snowpack Numismatics · Colorado, USA

© 2026 Numikeep, a Snowpack project.
Privacy policyTermsDevelopersContact us

Coin values shown in Numikeep are CPG retail prices sourced from Greysheet / Collectors Universe, used with attribution. They are estimates for guidance only — actual sale prices vary with market, venue and condition.

Coins pictured are from the National Numismatic Collection at the Smithsonian Institution — public domain.