` in its place. DEPLOYED 2026-08-07 to the separate rom3odelta.github.io repo (commit 115b322); live at https://rom3odelta.github.io/store-and-forget/ . v1.8.0 — EDITED 2026-08-11, NOT DEPLOYED. Adds the "Share all photos and files" paragraph to the sharing section and retires the "attached documents are never uploaded to our servers" line (see the markdown master's header for the full rationale). Bump the Effective date on push. This one also needs the Play data-safety re-file (Files and docs, No -> Yes) FIRST. -->

Privacy Policy — Store & Forget

Effective date: 2026-08-21
App: Store & Forget (Android)
Operator: Hyper Koala Studio
Contact: hyperkoalastudio@gmail.com

What this app is

Store & Forget is an Android inventory tracker that helps you remember where you put physical items in your home. You take a photo of something, optionally tag and describe it, and the app records which area and spot it went into. Your inventory lives on your device by default. Everything that sends data anywhere — AI features, sign-in, ads, cloud backup, buying scan credits, and sharing an inventory with other people — is optional, and each one is described below.

Data we collect

The app collects only what you actively put into it:

If you choose to sign in (see "Signing in" below), we also receive your Google account email, name, and profile photo from Google Sign-In, and the app is assigned a user ID that identifies your account to our scan-credit service.

We do not collect:

Where your data is stored

Everything you enter — photos, attached documents, text, prices, dates, item records — is stored locally on your device inside the app's private storage area.

There are exactly two ways any of it leaves your device, and you have to turn on each one:

If you use neither, we hold no copy of your inventory at all.

Optional features that use the network

The app works fully offline for manual entry, photos, attachments, browsing, and search-by-name. These features reach out over the network, and only when you use them:

Smart Scan, quick snap, and search indexing (Google Gemini)

When the app's Smart features are active, the app sends data to Google's Gemini API:

Which route a scan takes depends on whose key it uses:

The app never uploads an attached document (a receipt, warranty card, or manual you added to an item) to Gemini. (Attached documents are only ever uploaded to our own servers, encrypted, and only if you turn on "Share all photos and files" for a shared inventory — see the sharing section below.) Google's handling of data sent to the Gemini API is governed by Google's privacy policy and the Gemini API terms of service.

Using your own Gemini API key (BYOK — optional)

Instead of using the app's scan allowance, you can supply your own Google Gemini API key, from the app's "BYOK — Bring Your Own Key" screen. This is optional and off unless you set it up. When it is on:

Why the app asks you to sign in for this. Bringing your own key is normally a paid unlock, and the unlock is held against your Google account rather than against a particular handset, so it survives a reinstall or a new phone. Signing in is how the app attaches the unlock to an account. The request that does this records exactly one thing on our server — that this account holds the unlock — and carries no other content and never your key.

Sharing an inventory with other people (Share & Forget)

Sharing is optional and off until you use it. It requires signing in. When you create a shared inventory, you choose which areas of your inventory it carries, and you invite people with a code or a QR code. Members you invite as viewers can see the shared inventory; members you invite as editors can also change it.

What leaves your device. For the areas you put in the shared inventory, the app uploads to our servers, and makes available to every member of that group:

"Share all photos and files" — off unless you turn it on. There is a setting that widens what a shared inventory carries. With it on, the app also uploads every other photo on those items (extra shots, brand and specification close-ups) and the documents you attached to them — receipts, warranty cards, manuals. With it off, which is how it starts, none of those leave your device. These extra files are encrypted on your device in exactly the same way as everything else described below, and they cost credits to upload, so the app tells you what a sync will cost before it sends anything. Turning the setting back off stops future uploads; it does not remove files already sent to a group, and members who already received them keep their copies. If you were already sharing before this setting existed, your shared inventories used to carry every photo on an item; from now on they carry one per item unless you turn this setting on, and nothing that was already sent is taken back.

What deliberately stays on your device, even for an item inside a shared inventory:

Encryption. The uploaded inventory snapshot and the photos are encrypted on your device before they are sent, with a key held only by the members of that group. Our servers store ciphertext and cannot read your items or view your photos. The display name you set for yourself is encrypted the same way. The encryption key is stored on your device and, so that you can get your shared inventories back on a new phone, a copy is saved in the same private Google Drive app-data folder your backup uses — in your Google account. We never receive the key.

What is not encrypted, and what we can see. In plain terms, we can see:

Where it is stored. On Cloudflare (a Cloudflare Worker and Cloudflare R2 object storage), which processes it as our service provider.

Charging. Uploading photos to a shared inventory spends the same credits as Smart Scans. The app tells you the price before an upload runs and never bills you silently.

Leaving, and deletion. If you leave a shared inventory you were invited to, the app asks whether to keep the copy on your device or delete it, and either way your membership and the copy of the snapshot you had uploaded are removed from our server. If you own a shared inventory, you can stop sharing it, which removes it for everyone else. Encrypted photo blobs already uploaded to a group are not automatically erased from our storage — they stay so that a member joining later can still load the pictures. To have a group's stored data deleted outright, email us at the address at the bottom of this policy.

Signing in (Google Sign-In / Firebase Authentication)

Signing in is optional. You need an account to buy scan credits, to earn extra scans by watching a rewarded ad, to back up your inventory to your Google Drive, or to share an inventory. When you sign in, Google Sign-In provides the app with your Google account's email, name, and profile photo, and Firebase Authentication issues a user ID that identifies your account to our scan-credit service. We do not receive your Google password. You can use the entire core app without ever signing in.

Usage analytics (optional — off unless you opt in)

To understand which features people use and where the app is rough, you can optionally share anonymous product analytics. This is off by default. It is available only when you are signed in, and only after you turn on Advanced Settings → "Share usage analytics." While you are signed out, no analytics are collected at all.

When you opt in, the app uses Google Analytics for Firebase to record anonymous, behavior-only events:

Each event is tied only to a random, app-generated analytics instance ID. We do not send your name, email, or account ID to analytics, and we never link these events to your identity.

We do not send your inventory to analytics. Item names, photos, attached documents, descriptions, specs, tags, notes, prices, dates, and the names of your areas and spots are never included in any analytics event — analytics see that you saved an item, never what the item is. You can turn analytics back off at any time from Advanced Settings → "Share usage analytics," which stops further collection. Analytics data is processed by Google under Google's privacy policy.

Cloud backup to your own Google Drive (optional)

If you turn on cloud backup, the app copies your inventory (item text and photos, and your attached documents if you leave that option on) into a private, app-specific folder in your own Google Drive (the Drive "app data" area). This data lives in your Google account, under your control — we cannot see or access it, and it is not visible in your normal Drive file list. You can disconnect backup or delete the backup folder at any time from your Google account. This uses Google Drive, governed by Google's privacy policy.

Ads (Google AdMob)

Store & Forget shows ads after a number of free scans, unless you hold purchased scan credits. Ads are served by Google AdMob, which may collect and use a device advertising ID and related device/ad information to serve and measure ads. This data is processed by Google as an advertising partner. You can reset or limit your advertising ID in your device's Google settings. See how Google uses information from apps that use its services and Google's privacy policy.

Scan-credit service (our server)

To meter free and paid scans, the app talks to a small server we operate (a Cloudflare Worker). It receives your Firebase user ID to track how many scans your account has left, and the rewarded-ad reward callback that grants you credits. On paid/credit-backed scans it also receives the photo and text for that scan — including the single photo of a price tag or expiry date when you use quick snap — and immediately forwards it to Google's Gemini API to produce the result. It does not store your photos or item text. We keep only a per-account scan/credit balance, not your inventory.

When you are signed in, the app also sends this server anonymous counts of how many AI search-index operations your account has performed (plain numbers, grouped as search / save / re-index — never your item text, photos, or locations). This lets us keep the shared free AI tier healthy and detect abuse. These counts are sent whenever you are signed in, and are separate from the optional product analytics above (which stay off until you turn them on). Signed out, nothing is sent.

The same server handles shared inventories, as described under "Sharing an inventory" above — that is the one case where it stores content, and it stores it encrypted.

Buying scan credits (Google Play Billing)

If you buy a scan-credit pack, the purchase is handled by Google Play Billing. Google processes the payment; we receive a purchase confirmation (a token/event and the user ID it applies to) so we can add the credits to your balance. We do not receive your card number or other payment details.

How the app updates itself

Store & Forget updates over two channels, and neither one asks you to install anything from outside Google Play:

What an update check sends. On launch, the app asks Expo's update service whether a newer bundle exists. That request carries the platform ("android"), the app's runtime version and release channel, the ID of the bundle it is currently running, and an EAS client ID — a random identifier generated the first time the app runs and kept in the app's own private storage. It is not your device's advertising ID, not a hardware identifier, and is not linked to your Google account, your name, or your inventory; clearing the app's data or uninstalling the app discards it. No inventory data of any kind is sent in an update check. Expo processes this as our service provider, under Expo's privacy policy.

Notifications

If you turn on reminders (for items you have lent out, or for items about to expire), the app schedules those notifications on your device. Nothing about them is sent to us or to anyone else, and no reminder is delivered through a server.

Permissions the app requests

How to delete your data

Your inventory lives on your device for as long as you keep it there. You can delete it at any time:

Children

This app is not directed at children under 13, and we do not knowingly collect any data from children.

Changes to this policy

If we materially change how the app collects, uses, or shares data, we will update this policy and update the in-app and Play Store listing references to it. The "Effective date" at the top reflects the most recent change.

Contact

Questions about this policy, or requests to delete data we hold for your account, can go to hyperkoalastudio@gmail.com.