Legal
Privacy Policy
Keeper of Things
Last Updated: 2026-07-27
Effective: 2026-06-28
We do not sell your personal information. We never have and we never will.
1. Introduction
Keeper of Things ("KOT", "we", "us", "our") is a mobile inventory management app that helps you track, organise, and manage your belongings. This Privacy Policy explains what personal information we collect, why we collect it, how we use and share it, and what rights you have over it.
Data Controller / Agency: Keeper of Things — operated by Stubbydigits Ltd, a New Zealand limited company (NZBN 9429045838583).
Contact: [email protected]
Privacy contact: [email protected]
This policy applies to:
- The Keeper of Things mobile application (currently Android; iOS if and when we offer it)
- Our associated cloud services (backend infrastructure and server-side services)
- Any web interface we operate
This Privacy Policy should be read together with our Terms of Service, which govern your use of the Service.
Keeper of Things is operated by a New Zealand limited company and is the agency / data controller responsible for your personal information. This policy is primarily governed by the New Zealand Privacy Act 2020 and the Information Privacy Principles (IPPs). Because we also make the Service available in Australia and the United States, this policy additionally addresses the Australian Privacy Act 1988 and the Australian Privacy Principles (APPs) and US state privacy laws (including the California CCPA/CPRA) for residents of those markets. See the country-specific rights sections below.
Where Keeper of Things is available
Keeper of Things is offered only in the countries where we make it available through Google Play (and the Apple App Store, if and when we launch there) — currently New Zealand, Australia, the United States, and other selected countries; the authoritative list is the set of countries in which the app is listed on those stores. We do not target, market, or actively offer the Service in the European Union, the European Economic Area, or the United Kingdom, and we restrict availability accordingly through the app stores' country settings. If you access the Service from outside the countries where we offer it, you do so on your own initiative; regardless of where you are, we will honour reasonable requests to access, correct, or delete your personal information sent to [email protected].
2. What Information We Collect
2.1 Account and Authentication Data
When you create an account we collect:
| Field | Source | Purpose |
|---|---|---|
| Email address | You provide it | Account creation and login |
| Password (hashed) | You provide it | Authentication — we never see your plaintext password |
| Display name | Optional, you provide it | Personalisation |
| Profile photo | Optional, you provide it | Personalisation |
| Account identifier | Auto-generated | Uniquely identifies your account across our services |
| Email verified status | Firebase | Security |
| Account creation timestamp | Firebase | Account management |
| Last active timestamp | Our systems | Security and abuse prevention |
| Google account information | Google, if you choose "Continue with Google" | Sign-in — we receive your name, email address, Google account identifier, and (if set) profile photo URL |
We support two ways to sign in: email and password, or "Continue with Google". If you choose Google sign-in, Google shares your basic profile information with us — your name, email address, Google account identifier, and profile photo URL — which we use to create and identify your account. We do not receive your Google password, and we do not offer Apple or Facebook login. Google's handling of your information is governed by Google's Privacy Policy.
If you choose a profile photo in the app, we crop and resize it before upload, store it in your
private account area, and associate its protected access URL with your account record. Replacing or
removing the photo schedules the superseded stored copy for secure deletion.
2.2 Inventory Content
Everything you add to your inventory is stored and associated with your account:
| Data | Description |
|---|---|
| Item names, descriptions, tags | The details you enter for each item |
| Categories, locations | How you organise your items |
| Item metadata | Brand, colour, model number, serial number, and other optional fields |
| Quantity | How many of an item you own |
| QR codes | Codes you generate or scan for items/locations |
| Warranty information | Warranty expiry date — entered by you |
| Timestamps | When items and locations were created or updated |
This is the core content of the app. Without it, the app cannot function.
2.3 Photos and Images
When you photograph items or upload images:
- Profile photos are cropped and resized to JPEG, stored in your private account area, and
retained until you replace or remove them or delete your account. - Item photos are stored in secure cloud storage in a private area accessible only to your account.
- AI detection photos are source images sent to our AI pipeline. They are stored in your private Storage area while the related review batch exists, and are deleted when the batch is deleted and no accepted items still reference that source image.
- Exported PDFs are stored in your private storage area and are accessible only via a short-lived (7-day) access link. Exports are deleted when you delete your account.
- Standard item/manual uploads support JPEG, PNG, WebP, and GIF up to 15 MB per file.
- AI detection source uploads are JPEG-only and capped at 8 MB per file.
2.4 AI Processing Data
When you use the AI item detection feature:
- Your photo is sent to the Google Gemini API for analysis. The analysis request contains no personally identifying information about you.
- Gemini returns detected item names, descriptions, tags, and bounding boxes. This data is stored securely in your account until you complete the review.
- To power duplicate detection, we use Gemini to generate a numerical representation of each item's characteristics (name, description, category, brand, colour, model, and tags). This representation is stored with the item and contains no photos or identifiable information.
- Gemini AI is operated by Google. See Google's AI/ML Privacy.
2.5 Subscription and Billing Data
We use RevenueCat to manage subscriptions:
- We pass your account identifier to RevenueCat to link your subscription to your KOT account. We do not pass your name or email to RevenueCat.
- RevenueCat independently collects device identifiers and your purchase receipt from the App Store or Google Play. We do not receive or store your payment card number or full purchase receipts.
- We receive subscription status updates from RevenueCat and store the following in your user record: plan ID, subscription status, product ID, store (App Store/Google Play), entitlement ID, billing period end date, and cancellation status.
- For lifetime purchases and credit packs, we also keep a server-only transaction record. It uses a one-way hash of the store and transaction identifier rather than the raw identifier, and records the product, store, refund status, credit lifecycle, and the KOT account currently linked to access or credits. This prevents duplicate fulfilment and lets us process later transfers or refunds.
- See RevenueCat's Privacy Policy.
2.6 Usage and System Data
| Data | Description |
|---|---|
| AI credit usage ledger | A log of how many AI credits were granted, used, or refunded per transaction. The log contains no item-level PII. |
| Item and location counts | Running totals stored in your user record to enforce plan limits |
| Storage usage (MB) | Counter used to enforce storage limits |
| Security/audit log | Internal server-side log of security-relevant operations (account changes, plan enforcement, abuse prevention). May include your IP address where collected for security purposes. Readable only by KOT administrators. |
| Crash diagnostics | If the app crashes or encounters a serious error, Firebase Crashlytics (a Google service) collects a crash report: the crash stack trace, device model and operating system version, and app version. Crash reports are linked to your account identifier only — never your email address or name. Firebase Crashlytics retains crash reports for 90 days. |
| Performance / diagnostics data | To understand how the app performs on real devices, Firebase Performance Monitoring (a Google service) collects performance measurements: app start-up and screen-render timings, the duration, size, and outcome of the app's own operations (for example how long an item save or image upload takes), and network request timings (including the request URL/domain, response size, and success/failure). Firebase Performance Monitoring also uses your IP address at collection time to attribute performance events to the country they originate from. This data describes performance only — it carries no email address, name, item content, or photo data. It is collected from production app builds and retained by Firebase Performance Monitoring per Google's default retention. |
| Product analytics / usage events | To understand how the app is used so we can improve it, Firebase Analytics (Google Analytics for Firebase, a Google service) collects in-app events and interactions — for example screen views and coarse actions such as signing in, capturing a photo for AI detection, confirming detected items, saving or deleting an item, creating a collection, running a search, starting an export, or viewing and subscribing to a plan — together with your device model, operating-system version, app version, and pseudonymous app-instance / Firebase identifiers. Each event carries only counts, category labels, and true/false flags; it never carries your email address, name, item content, photo data, or the text you type into search. Firebase Analytics also derives an approximate, city-level location from a masked (truncated) IP address at collection time; the full IP address is not logged or stored, and we do not collect precise (GPS) location. It is collected from production app builds and retained by Firebase Analytics per Google's default retention. |
For product analytics we use Firebase Analytics (Google Analytics for Firebase); for crash diagnostics we use Firebase Crashlytics; and for app performance diagnostics we use Firebase Performance Monitoring — all operated by Google, the same provider that hosts our core infrastructure (see Section 4.1). We do not use any other third-party analytics SDKs (no Amplitude, Mixpanel, or similar), we do not use advertising SDKs, and we use no other crash-reporting SDK (no Sentry or similar). We use analytics only to understand product usage and improve the Service — never for advertising, cross-context behavioural profiling, or selling your data.
2.7 Household / Account Sharing Data
If you create or join a shared household:
- We store the household name, your role (owner or member), the display name and email address of each member (denormalised for display), and join timestamps.
- Invitations store the invited email address, a secure invitation token, and the inviting user's account identifier.
2.8 Feedback and Support Communications
If you submit in-app feedback or contact support:
- We store: your message (up to 5,000 characters), your user ID, your email address, the feedback type, your platform (iOS/Android), and app version.
- Feedback may be shared with our development team for review and action. If you submit a bug report, the content of your report may be shared internally with third-party developer tools used to track issues. No personal information beyond the report content is shared.
- Feedback is readable only by KOT administrators.
2.9 Push Notifications
Push notifications are local only. We do not register your device with APNs or FCM, and we do not store any device push tokens on our servers. All notification scheduling happens on your device.
3. How We Use Your Information
| Purpose | Data Used | Why we process it |
|---|---|---|
| Providing the app — account creation, authentication, and syncing your inventory | Account data, inventory data, photos | To perform our agreement with you and deliver the Service you request |
| AI item detection and duplicate identification | Photos, item embeddings | To deliver the features you request |
| Subscription management and plan enforcement | Subscription/billing data, usage counters | To deliver the features you request |
| Account sharing (household feature) | Household and member data | To deliver the features you request |
| Security — detecting abuse, enforcing usage limits, maintaining audit trails | Usage data, credit ledger, security/audit logs, timestamps, IP addresses (where collected) | Our legitimate interest in keeping the Service secure and preventing abuse |
| Customer support and responding to feedback | Feedback, email | To respond to you and support the Service |
| Service improvement — understanding how features are used | Pseudonymous in-app analytics events (Firebase Analytics) and aggregated usage patterns | Our legitimate interest in improving the Service |
| Legal compliance — responding to lawful requests | As required | To meet our legal obligations |
We do not use your data for advertising, behavioural profiling, or any purpose unrelated to providing and improving the Keeper of Things service.
4. How We Share Your Information
4.1 Third-Party Service Providers
We share data only with the providers necessary to operate the app:
| Provider | What Is Shared | Why |
|---|---|---|
| Google Firebase | All data described in Section 2 | Core infrastructure — authentication, database, file storage, server-side processing, product analytics (Firebase Analytics), crash diagnostics (Crashlytics), and app performance diagnostics (Performance Monitoring) |
| RevenueCat | Account identifier only | Subscription billing and entitlement management |
| Google Gemini API | Photos submitted for AI detection; item text fields for duplicate detection | AI item detection and duplicate detection |
4.2 Household Members
If you are in a shared household, other members of that household can see:
- Items and locations you choose to share (based on the household configuration)
- Your display name and email address as shown in the member list
4.3 Legal Requirements
We disclose personal information when required to do so by law or in good faith belief that such action is necessary to comply with a legal obligation, protect the rights or safety of KOT or our users, or investigate fraud.
4.4 We Do Not Sell Your Data
We do not sell, rent, trade, or otherwise share your personal information with any third party for their own commercial purposes. This applies to every user, and includes the "sale" and "sharing" (cross-context behavioural advertising) concepts used in US state privacy laws such as the California CCPA/CPRA.
5. Data Transfers
Keeper of Things is operated by a New Zealand company, and the services we rely on are operated primarily in the United States. Wherever you use the Service, your personal information is stored and processed in the United States by our service providers:
| Transfer | Recipient | Why |
|---|---|---|
| All app data | Google Firebase / Google Cloud (Google LLC, USA) | Core infrastructure |
| Subscription data | RevenueCat Inc., USA | Subscription billing and entitlements |
| AI processing | Google Gemini API (Google LLC, USA) | AI item detection and duplicate detection |
New Zealand (home jurisdiction — IPP 12): We disclose, under Information Privacy Principle 12 of the Privacy Act 2020, that your personal information is disclosed to overseas service providers (Google and RevenueCat) in the United States. We take reasonable steps to ensure those providers are required to protect your information with safeguards comparable to those under the New Zealand Privacy Act 2020.
Australia (APP 8): We disclose, under Australian Privacy Principle 8, that your personal information is transferred to and processed by Google and RevenueCat in the United States, and we take reasonable steps to ensure these overseas recipients handle it consistently with the Australian Privacy Principles.
United States: For US users, your information is stored and processed within the United States by the providers above.
By using the app, you acknowledge these cross-border transfers. Our service providers' own data-processing agreements include the European Commission's Standard Contractual Clauses; we note this only as a feature of those providers' contracts, and we do not rely on the SCCs as our own transfer mechanism.
6. Data Retention
| Data Category | Retention Period |
|---|---|
| Account data (email, display name, settings) | Until you delete your account, plus our cloud provider's standard backup window (typically up to 7 days) |
| Custom profile photo | Until you replace or remove it, or delete your account |
| Inventory items and locations | Until you delete them individually or delete your account |
| Item photos and AI source images | Item photos remain until you delete the item or your account; AI detection source images remain while their review batch exists and are deleted when the batch is deleted and no accepted items still reference the source image |
| AI review batches (detected items, results) | Until you complete the review or delete your account |
| Subscription/billing data | Account-linked subscription and credit data is kept until you delete your account. After deletion, the account link is removed from one-time purchase records; a minimal, non-identifying transaction tombstone is retained for refund handling, fraud/replay prevention, and transaction integrity. |
| AI credit usage ledger | Until you delete your account |
| Exported PDFs | Until you delete your account |
| Household data | Your membership is removed on account deletion; shared household and other members' data may persist |
| In-app feedback | Retained by administrators; no automatic deletion. Contact [email protected] to request deletion. |
| Transactional emails (household invitation emails) | Processed by our email delivery service; metadata retained per that service's defaults. Contact [email protected] to request deletion. |
| System and audit logs | Retained per our service provider's defaults (typically 30–365 days depending on service) |
| Crash diagnostics | Retained by Firebase Crashlytics for 90 days |
| Performance / diagnostics data | Retained by Firebase Performance Monitoring per Google's default retention |
When you delete your account, we initiate deletion of your account credentials, all inventory data, stored photos, and associated usage records. Due to asynchronous deletion processes and backup windows, complete deletion may take up to 30 days.
7. Your Rights
Everyone, in every country where the Service is available, can access, correct, and delete their personal information — you can edit most data directly in the app, delete your account in-app (see Section 8), or email us at [email protected]. The sections below set out the additional, country-specific rights that apply in our served markets.
7.1 New Zealand (Privacy Act 2020 / Information Privacy Principles)
New Zealand is our home jurisdiction and the primary privacy regime for this policy. The agency responsible for your personal information is Stubbydigits Ltd (NZBN 9429045838583), contactable at [email protected].
Under the Privacy Act 2020 and the Information Privacy Principles (IPPs):
- Access (IPP 6): You may request confirmation of, and access to, the personal information we hold about you. Email [email protected].
- Correction (IPP 7): You may request correction of personal information that is inaccurate, out of date, incomplete, or misleading. You can edit most details directly in the app, or ask us. If we decline a correction, you may ask us to attach a statement of the correction sought.
- Overseas disclosure (IPP 12): As described in Section 5, your personal information is disclosed to overseas service providers (Google and RevenueCat) in the United States. We take reasonable steps to ensure those providers are required to protect it with comparable safeguards.
- Notifiable privacy breaches: If a privacy breach occurs that is likely to cause serious harm, we will notify the Office of the New Zealand Privacy Commissioner and affected individuals as required by the Privacy Act 2020 (see Section 10).
If you are not satisfied with how we handle your information or a request, you may complain to the Office of the New Zealand Privacy Commissioner (privacy.org.nz).
7.2 Australia (Privacy Act 1988 / Australian Privacy Principles)
Australia is a market we serve from New Zealand. Where the Australian Privacy Act 1988 and the Australian Privacy Principles (APPs) apply to our handling of your information:
How we comply with the APPs:
- APP 1 (Transparency): This Privacy Policy is publicly available and clearly describes our data practices.
- APP 3 (Collection): We collect only personal information that is reasonably necessary to provide the Service. See Section 2.
- APP 5 (Notification of collection): We notify you of what we collect, why, and who we disclose it to via this Policy, presented before or at the time of collection.
- APP 6 (Use and disclosure): We use your information only for the purposes described in Section 3 and do not disclose it except as described in Section 4.
- APP 8 (Cross-border disclosure): We transfer your data to overseas recipients (Google and RevenueCat in the USA) and take reasonable steps to ensure they protect it consistently with the APPs. See Section 5.
- APP 11 (Security): We take reasonable technical and organisational measures to protect your information. See Section 10.
Your rights under the APPs:
- You have the right to access personal information we hold about you (APP 12).
- You have the right to request correction of personal information that is inaccurate, out of date, incomplete, irrelevant, or misleading (APP 13).
- You have the right to complain to us about a breach of the APPs; we will respond within a reasonable time.
- If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
To exercise your rights, contact [email protected].
7.3 United States (state privacy rights)
The United States is a market we serve. Several US states have comprehensive privacy laws that give their residents rights over personal information. Depending on your state of residence — including California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and other states with laws in force — you may have the right to:
- Know / access: Confirm whether we process your personal information and obtain a copy of it.
- Delete: Request deletion of personal information we have collected from you (subject to limited exceptions).
- Correct: Request correction of inaccurate personal information.
- Opt out of sale, "sharing"/targeted advertising, and certain profiling: We do not sell your personal information, do not "share" it for cross-context behavioural advertising, and do not use it for targeted advertising or profiling that produces legal or similarly significant effects — so there is nothing to opt out of.
- Non-discrimination / no retaliation: We will not discriminate against you for exercising any of these rights.
To exercise any of these rights, email [email protected] with the subject line "US Privacy Request". We will verify and respond within the timeframe required by your state's law (generally 45 days, extendable where permitted). Where your state's law provides an appeal process for a declined request, our response will explain how to appeal.
California (CCPA/CPRA) — additional detail
If you are a California resident, the rights above are provided under the California Consumer Privacy Act, as amended by the CPRA:
- Right to Know the categories and specific pieces of personal information collected about you, the sources, the purposes, and the categories of recipients.
- Right to Delete personal information we collected from you (subject to certain exceptions).
- Right to Correct inaccurate personal information.
- Right to Opt-Out of Sale or Sharing: we do not sell or share personal information, so there is nothing to opt out of.
- Right to Limit Use of Sensitive Personal Information and the Right to Non-Discrimination.
Sensitive personal information under the CCPA: Photos of your belongings and warranty receipts may qualify as sensitive personal information. We use photos only to provide the AI detection feature and inventory storage you request. We do not use or disclose them to infer characteristics or for targeted advertising, and therefore do not use sensitive personal information beyond the purposes permitted without a right to limit.
To submit a California request, email [email protected] with the subject line "California Privacy Request". We will respond within 45 days.
7.4 Other countries, including the EU/EEA and United Kingdom
Keeper of Things is not offered in the European Union, the European Economic Area, or the United Kingdom, and we do not target, market, or actively offer the Service to users there (see "Where Keeper of Things is available", above). We restrict availability accordingly through the app stores' country settings. If you nonetheless access the Service from the EU, EEA, UK, or any other country where we do not offer it, you do so on your own initiative. Regardless of where you are, we will honour reasonable requests to access, correct, or delete your personal information — just email [email protected].
8. Account Deletion
In-App Deletion
You can delete your account directly within the app:
- Open the app's account/profile menu and choose Delete Account.
- Confirm the deletion.
- We immediately initiate deletion of your account, all inventory data, stored photos, and associated usage records.
Deletion via Support
If you are unable to delete your account in-app, email [email protected] with the subject line "Account Deletion Request". We will process your request within 7 business days.
What Happens After Deletion
- Your authentication record, inventory data, photos, and usage data are deleted.
- The account link is removed from our global one-time purchase records. We retain only a minimal, non-identifying record of the store, product, one-way transaction hash, refund status, and lifecycle history needed to prevent duplicate fulfilment and process a later store refund.
- Household membership: you are removed from any shared household. Items you contributed to a household may persist for remaining members if they are considered shared resources under the household configuration.
- Feedback you submitted to us is retained unless you separately request its deletion.
- System and audit logs may retain anonymised references for up to 30 days per our service provider's defaults.
9. Children's Privacy
Keeper of Things is not intended for children under the age of 13. We do not knowingly collect personal information from children under 13, and our app-store age ratings reflect a 13+ audience.
If we learn that we have collected personal information from a child under 13 without verifiable parental consent, we will delete that information as quickly as possible. If you believe we may have collected information from a child under 13, contact us at [email protected].
10. Data Security
We take reasonable technical and organisational measures to protect your personal information:
| Measure | Detail |
|---|---|
| Encryption in transit | All data transmitted between the app and our servers is encrypted using TLS 1.2 or higher |
| Encryption at rest | Your data is encrypted at rest by our cloud storage provider using industry-standard AES-256 encryption |
| Access controls | Each user's data is protected by server-side access controls that restrict read and write access strictly to the authenticated account holder |
| Server-side integrity | Sensitive fields — subscription status, plan data, AI credit balances — are managed exclusively by our server infrastructure and cannot be modified by the app directly |
| Credential security | API credentials are stored in a dedicated secure secrets management service and are never embedded in the app |
| Time-limited access links | Exported files are accessible only via short-lived (7-day) access links, not permanent public URLs |
| Minimal data principles | We do not send personally identifying information to AI providers. Photo metadata (EXIF) is not intentionally extracted or stored by KOT. |
No method of electronic transmission or storage is 100% secure. While we use commercially reasonable measures to protect your information, we cannot guarantee absolute security.
If a privacy/data breach occurs that is likely to cause serious harm (or otherwise meets the applicable notification threshold), we will notify affected users without undue delay and notify the relevant regulators as required by the laws of our served markets, including:
- New Zealand (home): the Office of the New Zealand Privacy Commissioner, for notifiable privacy breaches under the Privacy Act 2020.
- Australia: the Office of the Australian Information Commissioner (OAIC) "as soon as practicable", under the Notifiable Data Breaches scheme.
- United States: affected individuals (and any regulators) in accordance with the applicable US state data-breach-notification laws.
11. Changes to This Policy
We may update this Privacy Policy from time to time. When we make changes, we will:
- Update the "Last Updated" date at the top of this document.
- For material changes (new data types collected, new third-party sharing, new purposes, or reduced rights), notify you via an in-app notice or email before the change takes effect.
- For minor, non-substantive changes (clarifications, formatting, corrections), update the policy without separate notification.
A "material change" is any change that meaningfully affects your privacy rights, the categories of data we collect, or the parties with whom we share your data.
Continued use of the app after the effective date of a material change constitutes acceptance of the updated policy. If you do not agree to the updated policy, you should stop using the app and delete your account.
12. Contact Us
For any privacy questions, requests, or complaints:
Keeper of Things — operated by Stubbydigits Ltd (NZBN 9429045838583)
Email: [email protected]
Privacy: [email protected]
Please include "Privacy Request" in the subject line so we can route your enquiry promptly.
New Zealand Privacy Complaints (home regulator)
If you are not satisfied with our response to a privacy concern, you may complain to the Office of the New Zealand Privacy Commissioner:
Website: privacy.org.nz
Australian Privacy Complaints
If you are in Australia and not satisfied with our response to a privacy complaint, you may contact:
Office of the Australian Information Commissioner (OAIC)
Website: oaic.gov.au
Phone: 1300 363 992
Other countries (including the EU/EEA and UK)
Keeper of Things is not offered in the EU, EEA, or UK. If you access the Service from outside the countries where we offer it, we will still honour reasonable access, correction, and deletion requests sent to [email protected] (see Section 7.4).
Version history
| Version | Effective date | Status |
|---|---|---|
| v0.1 | 28 June 2026 | Current |