Privacy Policy for Where Are My Things

Last updated: 2026-07-05

This Privacy Policy explains how Where Are My Things ("the App", "we", "us", or "our") collects, uses, stores, discloses, and protects personal data when you use the Where Are My Things mobile applications for iOS and Android, related APIs, websites, account tools, support channels, and server services.

Where Are My Things is a personal inventory management service. It helps users record belongings, locations, photos, attachments, proof-of-ownership information, shared spaces, AI-assisted item recognition, inventory insights, insurance-readiness information, exports, reports, notifications, and paid subscription features.

1. Controller and contact

The developer and operator of Where Are My Things is the controller of personal data processed by the App. The service is operated by an Individual Entrepreneur registered in Ukraine.

Controller: Danyliuk Vasyl, Individual Entrepreneur registered in Ukraine
Business location: Netishyn, Ukraine 30100
Privacy, legal, and deletion requests: [email protected]
VAT number: not applicable unless stated otherwise in billing materials.
EU/UK representative: not appointed.

2. Data we collect

Depending on how you use the App, we may process the following categories of data.

Account, profile, and sign-in data

  • Email address, user ID, name, first name, last name, locale, timezone, and account timestamps.
  • Email verification code metadata. Verification codes are stored in hashed form and expire quickly.
  • Access tokens, refresh tokens, token family identifiers, expiry timestamps, and logout records used to keep sessions secure.
  • Google Sign-In or Sign in with Apple data, such as provider ID, provider email, display name, avatar URL, provider verification data, and token data needed to sign you in or revoke access where supported.
  • Reviewer or support entitlement records where needed for app review, troubleshooting, or support.

Inventory and organization data

  • Item names, item type, tags, descriptions, estimated prices, expiry dates, possession status, lending recipient/details, possible locations, current location, and timestamps.
  • Location names, labels, type, parent location, descriptions, tree structure, space assignment, and timestamps.
  • Search, filter, list, and view data needed to display, sort, sync, and organize inventory records.
  • Inventory health, insurance-readiness counters, documented value summaries, missing-proof lists, and related score inputs generated from your inventory records.
  • Inventory exports generated at your request in CSV or PDF format.

Photos, attachments, files, and media reports

  • Photos uploaded for items or locations, including images taken with the camera or selected from the photo library.
  • Attachments uploaded for items or locations, such as PDF, DOC, DOCX, and supported image files.
  • File metadata, including original file name, MIME type, file size, checksum, storage path, temporary upload path, variants, thumbnails, processing status, and timestamps.
  • Direct-upload metadata for private object storage, including upload IDs, short-lived upload URLs, required headers, expiry time, and one-time consumption status.
  • Media reports submitted by users, including reporter ID, owner ID, reason, optional note, media metadata snapshot, moderation status, resolver ID, resolution note, and timestamps.

Shared spaces, invitations, and collaboration data

  • Space names, descriptions, owner IDs, member IDs, member names, member emails, roles, and timestamps.
  • Invitation email addresses, invitation tokens, invited role, status, expiry dates, inviter data, and acceptance records.
  • Public invitation preview data. Anyone with a valid invitation token link may view the invited space name, inviter name, inviter email address, invited role, invitation status, and expiry date before signing in or accepting the invitation. Invitation links work as bearer links, so users should send them only to the intended recipient and treat them as confidential.
  • Notifications related to spaces, invitations, membership changes, and inventory actions.

AI scan and inventory insight data

  • If you use AI item scanning, the selected photo is sent to our server and then to the configured AI model provider to identify visible physical items. Do not use AI scanning for photos that contain sensitive information or third-party personal data unless you have the right to process that content.
  • AI scan output may include suggested item names, descriptions, item type, estimated price, tags, and bounding box coordinates.
  • Scan preview data may include the original scan image, editable draft items, selected draft IDs, crop status, generated media records, progress counters, and job status.
  • If you use Inventory Insights, compact inventory fields may be sent to the configured AI model provider, including item IDs, item names, descriptions, item types, tags, current location IDs, possible location IDs, location IDs, location names, parent-location relationships, locale, prompt version, model, and fingerprint metadata. This means user-entered location names may be sent to the configured AI model provider if you have included real-world place names in your inventory.
  • Inventory Insight output may include optimization score, suggestions, severity, confidence, evidence item/location IDs, action labels, action payloads, dismissal status, applied status, and related timestamps.
  • The server records AI usage counts and entitlement data to enforce subscription limits.
  • AI features are optional, user-initiated, and not used to make legal, financial, insurance, health, employment, housing, credit, or similarly significant decisions about you.

Insurance reports and exports

  • Insurance report requests, selected format, requested filters, queued/running/generated status, generated file path, report summary, error messages, and timestamps.
  • Generated PDF or CSV report files that may contain item names, photos or thumbnails, locations, estimated values, proof-of-ownership information, and other inventory records you selected.
  • Temporary export/share files stored on your device when you choose to export or share data.

Billing and subscription data

  • Subscription plan, status, billing period, start date, expiry date, cancellation date, provider, provider subscription identifier, entitlement data, and plan limits.
  • Google Play purchase verification data, including product ID, base plan ID, offer ID, purchase token, order ID, purchase status, expiry date, auto-renewing status, and raw verification data returned by Google Play.
  • Google Play Real-time Developer Notification data, including event ID, purchase token, event type, event time, Pub/Sub message data, and payload.
  • Apple billing verification routes exist in the API but are not enabled in the current server implementation unless separately configured and released.
  • We do not collect or store payment card numbers. App-store payments are processed by Google Play or Apple App Store.

Device, app, notification, and diagnostic data

  • Firebase Cloud Messaging device token, token hash, platform, optional app version, last-seen time, and unregister/logout metadata.
  • Firebase App Check or platform integrity data used to reduce abuse and protect API endpoints.
  • Crash and diagnostic data collected through Firebase Crashlytics in production, such as stack traces, error reports, app version, operating system version, device model, installation IDs, and related technical diagnostics.
  • Firebase Remote Config data needed to fetch app configuration, including app version, platform, Firebase installation identifiers, update flags, maintenance mode, and feature flags.
  • Server logs and request metadata, such as IP address, request path, response status, timestamps, error details, rate-limit events, authentication events, and security events.
  • Language preferences sent through the Accept-Language header or stored in your user profile.

Local and offline data on your device

  • Securely stored auth tokens and session markers.
  • SQLite/offline cache containing inventory items, locations, pending sync operations, dirty records, locally created temporary IDs, sync failures, and cached user/session data.
  • Pending photo and attachment files waiting for upload, temporary compressed images, thumbnails, export/share files, and cached network images.
  • Local preferences such as theme mode, item view mode, app locale, search history, and other interface settings.

Web cookies and browser storage

  • The website and web dashboard may use Laravel session cookies, CSRF/XSRF cookies, and similar security cookies to keep web forms, authenticated sessions, and requests secure.
  • The web authentication and dashboard pages may store access tokens, refresh tokens, token expiry timestamps, pending invitation tokens, and interface preferences such as collapsed location state in browser local storage.
  • Browser storage may remain on your device until you log out, delete your account, clear browser data, or the App clears it as part of the relevant web flow.
  • The current codebase does not use advertising cookies, analytics cookies, pixel tags, or similar tracking technologies for behavioral advertising.

3. Data we do not intentionally collect

  • The current codebase does not include advertising SDKs or behavioral advertising integrations.
  • The current mobile manifests do not request precise device location, contacts, microphone, Bluetooth, calendar, SMS, or advertising tracking permission.
  • We do not sell personal data and do not share personal data for cross-context behavioral advertising.
  • We do not intentionally collect government ID numbers, payment card numbers, biometric identifiers, precise geolocation, health records, or children's data. However, you may choose to upload photos, documents, names, descriptions, or location labels that contain sensitive information.

4. Device permissions and platform access

  • Internet: used to communicate with our API, storage provider, Firebase, Google services, sign-in providers, and app-store services.
  • Camera: used only when you choose to take item/location photos or scan items with AI.
  • Photo library / gallery: used only when you choose images to attach or scan.
  • Notifications: used to send push notifications if you allow them.
  • Billing: used on Android for Google Play subscriptions and in-app purchase verification.
  • File sharing/opening: used as an app feature when you export/share CSV or PDF files or open attachments. This is not a request to read all files on your device.

5. How we use data

  • Create accounts, sign users in, issue and refresh tokens, and protect sessions.
  • Store, sync, search, display, edit, export, delete, and back up inventory records.
  • Upload, optimize, store, thumbnail, display, download, report, and delete media and attachments.
  • Provide offline-first behavior and synchronize pending changes when connectivity returns.
  • Provide shared spaces, invitations, member roles, access projections, and collaboration features.
  • Provide optional AI scanning and inventory insights when you request them.
  • Generate inventory exports and insurance reports at your request.
  • Calculate inventory health and insurance-readiness summaries.
  • Send service notifications, invitation notifications, and push notifications when enabled.
  • Verify subscriptions, enforce entitlements, apply plan limits, and process app-store events.
  • Fetch Remote Config values, enforce minimum app versions, show maintenance mode, and control feature flags.
  • Respond to user requests, deletion requests, privacy requests, support requests, media reports, and legal requests.
  • Maintain security, prevent abuse, enforce rate limits, diagnose crashes, debug errors, monitor reliability, and operate the service.
  • Comply with legal, tax, accounting, app-store, consumer-protection, security, and dispute-handling obligations.

6. GDPR legal bases

The table below identifies the primary legal basis for each processing purpose. Where more than one basis is listed, each basis applies to the specific purpose described in the same row; for example, contract is used to provide a requested feature, legitimate interests are used for security and abuse prevention, and legal obligation is used only where records must be kept or disclosed by law.

Data category Purpose Legal basis
Account, profile, sign-in, social login, and tokens Account creation, authentication, session security, user preferences, and abuse prevention. Contract; legitimate interests for security and abuse prevention.
Inventory, locations, tags, media, attachments, exports, and local/offline sync data Provide the personal inventory service, sync data, and let you manage records. Contract.
Shared spaces, invitations, access projections, and notifications Provide collaboration, access control, invitations, member roles, and related notifications. Contract; legitimate interests for secure collaboration and abuse prevention.
AI scan images, AI scan output, inventory insight input/output, and AI usage counts Provide optional AI features and enforce plan limits. Contract when you actively request the AI feature; consent where a separate consent control is required by law or app-store rules; legitimate interests for abuse prevention and quota enforcement.
Insurance reports, inventory health, and insurance-readiness data Generate requested reports and provide organizational summaries. Contract.
Billing, subscriptions, purchase verification, and app-store events Verify purchases, provide paid features, prevent fraud, handle disputes, and maintain records. Contract; legal obligation for tax/accounting; legitimate interests for fraud prevention.
Push tokens and notification delivery data Send and manage notifications. Contract for service notifications; consent where required for optional push notifications.
Crash logs, diagnostics, App Check, Remote Config, server logs, and security events Operate, secure, debug, and maintain the App and API. Legitimate interests; legal obligation where records must be kept.
Media reports, support requests, and legal requests Investigate abuse, copyright, privacy, support, and legal issues. Legitimate interests; legal obligation where applicable.

7. Third-party services and recipients

We use third-party providers only where needed to operate, secure, distribute, or improve the App:

  • Apple App Store: app distribution, Sign in with Apple, iOS platform services, and Apple subscription services if enabled.
  • Google Play: app distribution, Android billing, purchase verification, and subscription status notifications.
  • Google Sign-In / Google OAuth: social login and token verification.
  • Firebase Cloud Messaging: push token generation and push delivery.
  • Firebase Crashlytics: production crash reporting and diagnostics.
  • Firebase Remote Config: app configuration, version controls, maintenance mode, and feature flags.
  • Firebase App Check: app integrity and abuse prevention.
  • AI model provider: optional AI scan and inventory insight processing when you request those features.
  • Cloudflare R2 or another configured private object-storage provider: storage of uploaded photos, attachments, temporary uploads, variants, and generated reports.
  • Email delivery provider: login codes, invitations, service emails, and support communications depending on configuration.
  • Hosting, database, Redis/queue, backup, logging, and infrastructure providers: running the API, jobs, database, object storage, logs, backups, and website.
  • Professional advisers, authorities, or legal recipients: where required for legal, security, tax, accounting, dispute, or rights-enforcement purposes.

These providers may process data according to their own terms and privacy policies. We do not authorize providers to use your personal data for our third-party advertising or to sell your personal data.

8. International transfers

Providers such as Apple, Google, Firebase, Cloudflare, hosting providers, support providers, and email providers may process data outside your country, including outside Ukraine, the United Kingdom, and the European Economic Area.

Where GDPR or similar transfer rules apply, the transfer mechanism is the provider's applicable data-processing agreement, Standard Contractual Clauses, UK International Data Transfer Addendum, adequacy decision, or another lawful transfer safeguard offered by the provider for the relevant service. You may request information about the transfer mechanism that applies to your data, or a copy of the relevant safeguard where we can lawfully provide it, by contacting [email protected]. Commercial terms, security-sensitive details, and third-party confidential information may be redacted.

9. Retention

We use the retention periods below unless a shorter period is technically available or a longer period is required or permitted for security, fraud prevention, dispute handling, tax, accounting, app-store compliance, legal claims, or legal obligations.

  • Account and profile data: kept while your account exists, unless deletion or a legal exception applies. Verified account deletion requests are normally processed within 30 days, unless the request is complex or a legal exception applies.
  • Inventory, locations, tags, spaces, and uploaded media: kept while the related account, item, location, media record, or shared space exists, unless deleted earlier.
  • Local/offline data: kept on your device until synced, cleaned up by the App, logout, account deletion, app-data clearing, or uninstall.
  • Access tokens: short-lived according to server configuration; the current default is 15 minutes.
  • Refresh tokens: configured to expire after 30 days unless rotated, revoked, or deleted earlier.
  • Login codes: expire after 10 minutes and are stored in hashed form until used, replaced, expired, or cleared after repeated failed attempts.
  • Pending direct uploads: upload URLs are short-lived; unconsumed temporary uploads are designed to be cleaned after approximately 24 hours.
  • Scan previews: abandoned scan preview images are designed to be cleaned after approximately 48 hours.
  • Insurance reports: kept until you delete the report, delete your account, or a retention/legal exception applies.
  • Media reports: kept as long as needed to investigate, resolve, document, and defend moderation, privacy, copyright, safety, or abuse decisions. Media reports may be deleted when related accounts, media, or database records are deleted, and may be retained longer where needed for security, dispute handling, legal claims, or legal obligations.
  • Push tokens: kept until logout, unregistering, account deletion, invalidation, or cleanup.
  • Crash and diagnostic data: kept according to Firebase retention settings and policies.
  • Server logs: daily application logs are configured for 14 days unless production settings or legal/security needs require a different period.
  • Billing records: kept as long as needed for subscription management, app-store compliance, refunds, disputes, fraud prevention, tax, accounting, and legal obligations. Where no longer period is legally required, core billing records are kept for up to 7 years after the relevant transaction or subscription period.
  • Backups: deleted data may remain in encrypted or access-controlled backups until backups rotate or are overwritten. The current production PostgreSQL backup materials use a 3-day retention default. Offsite or provider backups, if enabled, should not retain deleted personal data for more than 90 days unless longer retention is required for legal, security, or compliance reasons.
  • Laravel Telescope diagnostics: disabled in production. If enabled in non-production, it may store diagnostic entries until pruned or cleared. Real production data should not be used in Telescope-enabled non-production environments unless appropriate safeguards apply.

10. Account deletion and data deletion

You can request deletion in the App by going to Settings and choosing Delete Account. The server also supports authenticated account deletion through DELETE /api/user. If you cannot access the App, you may request deletion at [email protected] or through the Account Deletion Request page.

After a verified deletion request, the App deletes the account and associated active-service data listed below from production systems, except where a retention exception applies.

  • Your user account and profile data.
  • Your items, locations, tags, inventory records, and related access projections.
  • Your uploaded media records, generated media variants, and stored media files.
  • Your access tokens, refresh tokens, device push tokens, and social login records.
  • Spaces you own, memberships, invitations, notifications, reports, subscriptions, and related data where database deletion rules and legal exceptions allow deletion.

If your account used Google Sign-In and a revocable Google access token is stored, the server attempts to revoke that token during account deletion. Some billing records, provider records, media report records, security logs, dispute records, legal records, and backups may remain for limited periods where required or permitted by law, app-store rules, accounting obligations, security, fraud prevention, or dispute handling. Deleting your account does not automatically cancel an active app-store subscription; you may also need to cancel it in Google Play or Apple App Store.

11. Your privacy rights

Depending on your location, including the European Union, European Economic Area, United Kingdom, California, and other regions with similar laws, you may have rights to:

  • Access personal data we process about you.
  • Correct inaccurate or incomplete personal data.
  • Delete personal data, subject to legal exceptions.
  • Restrict or object to certain processing.
  • Receive a portable copy of certain data.
  • Withdraw consent where processing is based on consent.
  • Opt out of sale or sharing where applicable. We do not currently sell personal data or share it for cross-context behavioral advertising.
  • Complain to a data-protection authority or other competent regulator.

To exercise rights, contact [email protected]. We may verify your request by asking you to authenticate in the App, confirm control of the account email, or provide information matching account records. We aim to respond within the period required by applicable law.

12. California privacy notice

This section applies to California residents if the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA"), applies to us. It describes our personal information practices during the 12 months before the "Last updated" date above.

CCPA category Examples Sources Purposes Recipients
Identifiers Email, name, user ID, social provider ID, device token, token IDs, purchase token, order ID, invitation email, IP address, Firebase installation IDs. You, your device, Google, Apple, Firebase, app stores, invited users, server logs. Account management, sign-in, invitations, notifications, billing, security, support. Hosting, database, email, Firebase, Google, Apple, app stores, infrastructure providers.
California Civil Code 1798.80(e) personal information Name, email, account records, subscription records, billing provider identifiers. You, Google, Apple, app stores. Account and subscription management, compliance, support, disputes. App stores, hosting, infrastructure, legal/compliance providers where required.
Commercial information Subscription plan, purchase product, purchase token, renewal status, entitlement status, AI scan usage. You, Google Play, Apple App Store if enabled, server entitlement checks. Paid features, purchase verification, fraud prevention, accounting, app-store compliance. Google Play, Apple App Store, hosting, database, infrastructure, compliance providers.
Internet or electronic network activity API requests, request paths, response status, IP address, app version, diagnostics, Crashlytics data, Remote Config metadata, App Check metadata. Your device, server logs, Firebase. Service operation, security, rate limits, debugging, crash diagnosis, app configuration. Firebase, hosting, database, Redis/queue, infrastructure, support providers.
Geolocation data The App does not request precise device geolocation. User-entered inventory location names or descriptions may identify real-world places. You. Inventory organization, search, sharing, export, reports. Hosting, database, storage providers, shared-space members you choose to share with.
Audio, electronic, visual, or similar information Uploaded photos, scan images, thumbnails, attachments, documents, file names, MIME types, file sizes, report files. You, your device camera, photo library, selected files. Inventory media, AI scans, reports, exports, moderation, sharing in spaces. Storage providers, hosting, configured AI model provider when requested, shared-space members where shared.
Inferences AI scan suggestions, inventory insight suggestions, confidence/severity, readiness and health scores. Your inventory data, uploaded scan image, AI model output, server calculations. Optional AI assistance, organization recommendations, readiness summaries. Configured AI model provider for optional AI features, hosting/infrastructure providers.
Sensitive personal information Authentication tokens. User-provided photos, documents, descriptions, values, or location labels may contain sensitive information if you choose to include it. You, your device, sign-in providers, Firebase/platform services. Account security, requested uploads/scans, inventory features, abuse prevention, compliance. Hosting, database, storage, Google, Apple, Firebase, configured AI model provider only as needed for requested features.

We do not sell personal information. We do not share personal information for cross-context behavioral advertising. We do not use or disclose sensitive personal information for purposes that require a "Limit the Use of My Sensitive Personal Information" choice under the CCPA.

California residents may request to know/access, delete, correct, opt out of sale or sharing, limit sensitive personal information where applicable, and avoid discriminatory treatment for exercising privacy rights. You may use an authorized agent where permitted by law. We may require proof of authorization and reasonable identity verification.

13. App-store privacy disclosures

Google Play and Apple App Store require developers to keep store privacy disclosures accurate. Based on the current App, relevant disclosure categories may include account identifiers, contact info, user content, photos, files and documents, purchase history, app activity, in-app search history, crash logs, diagnostics, and device or other IDs. Store disclosures must be updated whenever the App's data practices, SDKs, features, or permissions change.

If the Google Play Data Safety form or Apple App Privacy labels describe fewer data categories than this Policy or omit AI, Firebase, billing, diagnostics, user content, photos, files, or device identifiers, the store disclosures should be treated as out of date and corrected before release.

14. Security

We use technical and organizational measures designed to protect your data, including authenticated API access, short-lived access tokens, refresh-token rotation, hashed login codes, server-side validation, App Check, rate limits, private storage where configured, short-lived upload/download URLs, local secure storage for auth tokens, and access controls. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.

15. Children

The App is intended for personal inventory management and is not directed to children. We do not knowingly collect personal data from children below the age required by applicable law. If you believe a child has provided personal data, contact us so we can take appropriate action.

16. Changes to this Privacy Policy

We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date above. If changes are material, we may provide additional notice in the App, on our website, by email, or by another appropriate method.

17. Contact

For privacy questions, data deletion requests, GDPR requests, California privacy requests, or other privacy rights requests, contact [email protected].