Privacy policy
Version 3 — 2026-09-29. This version describes exactly what the app does today.
This policy explains what personal data the app collects, why, where it is kept, for how long, and what you can do about it. It is written in plain language on purpose. "Processing" means everything we do with data: storing it, reading it, sending it.
Who is responsible for your data
The controller of your personal data is HomeItemFinder, the name under which this app is operated.
For anything about your data, write to privacy@HomeItemFinder.com. This is the address for exercising your rights under this policy.
What we collect and why
Your account. To create and protect your account we keep your email address and your password. The password is stored only as a hash (a scrambled form that cannot be undone): we never see it. We also keep a display name (it may be empty), your chosen language, and the dates the account was created and changed. You may give a phone number, and it is optional: it is kept for you alone, it is shown to nobody else — not to the people you share projects with, not to whoever runs the app — and you can change it or erase it whenever you want in Settings. If you turn two-step verification on, we keep the secret of your authenticator app and your recovery codes (stored as hashes). We also record the date and version of the terms you accepted. We use this to sign you in, to show your name to the people who share a project with you, and to send you the emails the account needs: confirmation, password recovery, security notices (one of them when a new device signs in), and notices about your projects (someone without access read one of your boxes; an invitation was accepted).
Projects and their content. A project holds what you and the other members write in it: the project's name and description, the origin and destination addresses of a move, boxes and their notes, items (description, category, attributes, notes, estimated value, barcode), locations, the names of the people you associate with items, and stock movements. This is your content. We process it only to provide the app to you and to the members of the project.
Photographs. Photographs of items are compressed on your device before upload (WebP or JPEG, limited size) and any metadata in the file — including the location where the photo was taken — is removed before it leaves your device. They are stored in a private storage bucket that only the members of the project can read. Small thumbnails are kept on your device so the app works offline.
History and scans. The project's history records the following.
- Every relevant action on a box or item (created, moved, checked, scanned, and so on), with the identifier and the display name of the person who did it. Kept for as long as the event exists.
- The display name as it was at that moment: changing your name later does not rewrite the history, and the recorded name stays even if your account is later removed. Kept for as long as the event exists.
- One GPS position with a scan or action, if you allow location access in your browser — never continuous tracking, one position at one moment. Kept for as long as the event exists.
- A reading of a box's QR code or NFC tag by someone who is not an editor of the project, with the position if the browser shared it. Kept in the box's history for as long as the event exists.
Artificial intelligence. The suggestion feature is off by default on each device. When you ask for a suggestion, or when you switch on automatic suggestions, we send the following to Google's Gemini API for processing: a limited number of the item's photographs, the text you already wrote about the item (description, category, notes and attributes — never the estimated value or the purchase date), the language you use, and our own list of categories. We do not send your name, your email, the project's name or any address. The text sent and the suggestion returned are kept for 30 days after the request finishes, then deleted; only counts (tokens, model, outcome) remain. What Google does with data sent to its API is governed by Google's own terms and privacy policy, which you should read.
Invitations. To invite someone to a project, you type that person's email address. We keep that address, the role you chose, who invited them, and the dates the invitation was created, accepted or revoked. The invitation link stops working after seven days. The record of the invitation is kept after it is accepted, revoked or expired; it is not yet deleted automatically, and you can ask us to delete it. The invitation email tells the invited person your display name (or your email address, if you have no name set), the name of the project and the role offered. When the invitation is accepted, you receive a notice with the display name of the person who joined (or the invited email address, if they have no name set). The invited person can ignore the invitation.
Commercial contacts. If you get in touch with us about the app, we may keep a commercial contact record in our administration portal: name, email address, phone number, language, where the contact came from, the legal basis and the date of consent when there is one, the date of the last interaction, notes on our conversations, business opportunities and the organisation you belong to. A contact linked to an account is kept for as long as the account exists. Any other contact is deleted automatically 12 months after the last interaction (or after it was created, if there was none).
Security and technical records. To limit abuse and keep the app running, we keep the following technical records.
- Anti-abuse counters for QR and NFC readings, invitations and two-step verification recovery, per network address and, in recovery, also per account. The address itself is never stored: only a keyed hash of it, combined with the day, which cannot be turned back into the address. The counters expire after 24 hours and are removed on the next request.
- An audit log of administration actions and two-step verification events, with the email address of the person who acted, their network address and their browser identification. After 24 months these three fields are blanked; the action, its target, its technical details and the date remain.
- A technical diagnostic when a photograph fails to process (browser identification, app version, sizes — never the image). Kept for 90 days.
- A queue of emails to be sent, with your address, the type of email, your language and, for links, the single-use token. The token is removed the moment the email is sent; the entry is deleted after 90 days.
- Cloudflare Turnstile protects sign-in, password recovery and creating an account from an invitation; what Turnstile collects is described in Cloudflare's privacy policy.
Administration. The administration portal never shows the content of your projects: it shows only identifiers, counts, sizes and dates, and every access through it is written to the audit log. Direct access to the database and to the backups exists only for maintenance and restore, and is limited to the people who operate the app.
Where your data is kept and who processes it for us
The database and the file storage are hosted in the European Union (Frankfurt, Germany). We use the following providers, who process data on our behalf:
- Supabase — database, authentication, file storage and server functions.
- Vercel — hosting of the app.
- Cloudflare — Turnstile (protection against automated abuse) and R2 (an encrypted second copy of the photographs).
- Resend — sending of the app's emails.
- GitHub — encrypted weekly backups, in the United States.
- Google — the Gemini API, only when you use the AI suggestions.
GitHub, Google's Gemini API, Cloudflare R2 and Resend may process data outside the European Union, under the safeguards each provider publishes.
Backups: once a week we take a copy of the database (including account data such as email addresses and password hashes, but not two-step verification secrets or sessions) and of all photographs. The data travels from the providers to the machine that makes the copy over TLS, and each copy is encrypted there (AES-256) before it is stored. The encrypted copies are stored as private files on GitHub for 35 days; the encrypted copy of the photographs is also stored in Cloudflare R2, where it is kept until we delete it (a 180-day rule is planned).
How long we keep your data
- Your account: for as long as it exists.
- Projects, boxes, items, locations, people and history: for as long as the project exists. When you delete something in the app, it is marked as deleted and hidden from everyone; photograph files are removed from storage. The marked records are not yet removed automatically from the database. You can ask us to erase them permanently.
- Photographs: removed from storage when the item, box or project is deleted, or when a cleanup of orphaned files is run.
- The name of the person who acted, in a project's history: for as long as the event exists, even after the account is gone.
- GPS position in a scan or action: for as long as the event exists.
- AI requests: text sent and suggestion received are deleted 30 days after the request finishes.
- Invitations: the record stays after the invitation is accepted, revoked or expired (the link stops working after seven days); it is not yet deleted automatically.
- Commercial contacts: 12 months after the last interaction; for as long as the account exists, if the contact is linked to one.
- Anti-abuse counters (hashed address; in recovery, also the account): expire after 24 hours and are removed on the next request.
- Audit log: the acting person's email, network address and browser identification are blanked after 24 months; the action, its target, its technical details and the date remain.
- Photo processing diagnostics: 90 days.
- Email queue: the link token is removed on sending; the entry is deleted after 90 days.
- Backups: 35 days on GitHub.
- Second copy of the photographs in Cloudflare R2: kept until we delete them (a 180-day rule is planned).
Your rights
You have the right to access your data, to correct it, to have it erased, to restrict or object to its processing, and to receive a copy of it in a portable format. To exercise any of these rights, write to privacy@HomeItemFinder.com. We answer within one month; if the request is complex, we tell you within that month that we need more time (up to two months more).
What you can already do in the app: change your language; export a project's items as CSV or Excel when your plan includes it — if it does not, ask us for the copy by email; delete boxes, items, photographs and projects; and manage your two-step verification.
What you can do on your own in Settings: change the display name, the phone number and the email address — the last one asks who you are and only changes once confirmed at both addresses, the new one and the current one. What you must ask us for by email, today: to receive a full copy of your data; to have data permanently erased; and to close your account. Closing an account is not yet available in the app. When you ask, we close it so it can no longer sign in. We delete your email address, your display name, the secret of your two-step verification and your recovery codes. What stays: your name in the history of the projects where you acted, your email address in the audit log for up to 24 months, and the content of shared projects.
If you believe we are processing your data unlawfully, you may complain to the data protection authority of the country where you live, or to the Portuguese supervisory authority (CNPD).
What stays on your device
The app works offline. To do that, it keeps a copy of the projects you have access to in your browser's storage (IndexedDB): projects, boxes, items, history, thumbnails of the photographs, photographs waiting to be uploaded, and pending changes. If a photograph could not be processed, its original file stays on your device until the problem is resolved; it is never uploaded. Your session is kept in the browser's local storage so you stay signed in. Your AI preferences are kept per device.
When you sign out, the app deletes all of this from the device and turns the AI options off for whoever uses the device next.
Security
- Two-step verification with an authenticator app (TOTP) is optional and recommended, with recovery codes in case you lose the app. Once an account turns it on, that account is required to use it: the password alone no longer opens it. It is mandatory for the people who administer the platform and for accounts on business plans.
- When an account has no second step, the password alone is enough to sign in, so other guards take its place: the session ends after five days without use, and after thirty days in any case; you receive an email when a new device signs in; and turning two-step verification off, changing your email address or your password, deleting a project, closing your account and exporting everything all ask for your password again.
- When you set or change your password, it is checked against the Have I Been Pwned list of leaked passwords using k-anonymity: only the first five characters of a hash are sent, never the password.
- Photographs are stored in a private bucket; database access is restricted by row-level rules so members only see their own projects.
- Backups are encrypted (AES-256) on the machine that makes them, before they are stored.
- If you lose the authenticator app, one of your recovery codes lets you set up a new one, on the two-step verification recovery screen when you sign in. If you lose both the app and the codes, write to privacy@HomeItemFinder.com: we confirm your identity before restoring access. The change is recorded, the old recovery codes are deleted, and you receive an email saying that a verification method was removed.
Changes to this policy
This is version 2. When the app changes what it collects or who processes it, this policy is updated with a new version and date, and you will be asked to accept the new version the next time you sign in.
Contact
HomeItemFinder
privacy@HomeItemFinder.com