Privacy Policy — Store & Forget
What this app is
Store & Forget is an Android inventory tracker that helps you remember where you put physical items in your home. You take a photo of something, optionally tag and describe it, and the app records which area and spot it went into. Your inventory lives on your device by default. Everything that sends data anywhere — AI features, sign-in, ads, cloud backup, buying scan credits, and sharing an inventory with other people — is optional, and each one is described below.
Data we collect
The app collects only what you actively put into it:
- Photos you take with the camera or pick from your photo library and attach to items.
- Text you type — item names, descriptions, specifications, tags, notes, and the names you give to areas and spots.
- Documents you attach to an item — receipts, warranty cards, manuals, and other files (JPEG, PNG, WebP, HEIC, or PDF), together with the label you choose for each one.
- Optional item details — a price and currency, and an expiry or "use by" date.
If you choose to sign in (see "Signing in" below), we also receive your Google account email, name, and profile photo from Google Sign-In, and the app is assigned a user ID that identifies your account to our scan-credit service.
We do not collect:
- Your location.
- Your contacts, calendar, SMS, call logs, or any other personal data on your device.
- Audio recordings (the camera permission does not record audio in this app).
- Crash reports of our own.
- Usage analytics unless you are signed in and turn them on (see "Usage analytics" below). They are off by default and off entirely while you are signed out.
Where your data is stored
Everything you enter — photos, attached documents, text, prices, dates, item records — is stored locally on your device inside the app's private storage area.
There are exactly two ways any of it leaves your device, and you have to turn on each one:
- Cloud backup copies your inventory into your own Google Drive, not to us (see "Cloud backup" below).
- Sharing an inventory uploads the areas you choose to our servers, in encrypted form, so the people you invite can see them (see "Sharing an inventory" below).
If you use neither, we hold no copy of your inventory at all.
Optional features that use the network
The app works fully offline for manual entry, photos, attachments, browsing, and search-by-name. These features reach out over the network, and only when you use them:
Smart Scan, quick snap, and search indexing (Google Gemini)
When the app's Smart features are active, the app sends data to Google's Gemini API:
- Auto-describe a scanned item (on tap): when you tap "Smart Scan," the photo of the item plus any text you've already entered for that item is sent to Google's Gemini vision model so it can suggest a name, description, and tags. This happens only when you tap the scan button.
- Quick snap of a price or a date (on tap): when you use the camera button beside the price or expiry-date field, the app takes a single photo of the price tag, receipt, or label, sends it to Google's Gemini vision model to read that one value, fills the field in, and then deletes the photo from your device. That photo is never added to your inventory and never becomes an attachment — if you want to keep the receipt, you attach it separately and deliberately.
- Search-index an item (automatic, on save): when you save a new item or edit an existing one, the item's text (name, description, specs, tags, notes) is sent to Google's Gemini embedding model. The model returns a numerical search vector that the app stores locally on your device. The vector itself is meaningless without the original text and is stored only on your device. Prices, dates, and attached documents are not part of this text and are never sent for indexing.
- Smart Find semantic search (on tap): when you run a Smart Find search, your search query text is sent to Google's Gemini embedding model to produce a query vector. That vector is then compared locally, on your device, against the item vectors stored there — your inventory itself is never sent for the search, only the words you typed into the search box.
Which route a scan takes depends on whose key it uses:
- Signed out (free trial scans) — the app uses an API key bundled in the app and calls Google directly. Our server is not involved.
- Signed in (both your free per-account allowance and credit-backed scans) — the photo and text for that scan are routed through our scan-credit server (see "Scan-credit service") on their way to Google, together with your user ID so the scan can be metered. The server forwards them and does not store them.
- Using your own Gemini API key — the scan goes straight from your device to Google. Our server is not in the path at all (see "Using your own Gemini API key" below).
The app never uploads an attached document (a receipt, warranty card, or manual you added to an item) to Gemini. (Attached documents are only ever uploaded to our own servers, encrypted, and only if you turn on "Share all photos and files" for a shared inventory — see the sharing section below.) Google's handling of data sent to the Gemini API is governed by Google's privacy policy and the Gemini API terms of service.
Using your own Gemini API key (BYOK — optional)
Instead of using the app's scan allowance, you can supply your own Google Gemini API key, from the app's "BYOK — Bring Your Own Key" screen. This is optional and off unless you set it up. When it is on:
- The key is stored only on your device, in the operating system's encrypted key store (the Android Keystore). It is never sent to our servers, is not included in your Google Drive backup, is not included in analytics, and is never shared with anyone.
- We never receive it. The key is only ever attached to requests the app sends directly to Google at
https://generativelanguage.googleapis.com. It appears in no request to any server we operate. - Your scans skip our server entirely. While your own key is active, the photo and text for a scan travel straight from your device to Google. Our scan-credit server is not in the path, so we do not receive, forward, or see the contents of those scans, and we cannot count them.
- Google meters and bills those calls against your own Google account, under Google's Gemini API terms. What Google does with what you send it is covered by Google's privacy policy; we are not a party to that exchange.
- You can remove the key at any time using "Clear" on that screen, which deletes it from your device. Scans then fall back to the app's own allowance.
Why the app asks you to sign in for this. Bringing your own key is normally a paid unlock, and the unlock is held against your Google account rather than against a particular handset, so it survives a reinstall or a new phone. Signing in is how the app attaches the unlock to an account. The request that does this records exactly one thing on our server — that this account holds the unlock — and carries no other content and never your key.
Sharing an inventory with other people (Share & Forget)
Sharing is optional and off until you use it. It requires signing in. When you create a shared inventory, you choose which areas of your inventory it carries, and you invite people with a code or a QR code. Members you invite as viewers can see the shared inventory; members you invite as editors can also change it.
What leaves your device. For the areas you put in the shared inventory, the app uploads to our servers, and makes available to every member of that group:
- the area and spot names and their structure,
- item names, descriptions, specifications, tags, and notes,
- expiry / "use by" dates on those items,
- one photo per item — the item's first photo, the one you see in your lists.
"Share all photos and files" — off unless you turn it on. There is a setting that widens what a shared inventory carries. With it on, the app also uploads every other photo on those items (extra shots, brand and specification close-ups) and the documents you attached to them — receipts, warranty cards, manuals. With it off, which is how it starts, none of those leave your device. These extra files are encrypted on your device in exactly the same way as everything else described below, and they cost credits to upload, so the app tells you what a sync will cost before it sends anything. Turning the setting back off stops future uploads; it does not remove files already sent to a group, and members who already received them keep their copies. If you were already sharing before this setting existed, your shared inventories used to carry every photo on an item; from now on they carry one per item unless you turn this setting on, and nothing that was already sent is taken back.
What deliberately stays on your device, even for an item inside a shared inventory:
- prices and currencies — these are removed before anything is uploaded,
- attached documents, unless you turn on "Share all photos and files" above,
- everything in areas you did not put in the shared inventory,
- the search vectors described above.
Encryption. The uploaded inventory snapshot and the photos are encrypted on your device before they are sent, with a key held only by the members of that group. Our servers store ciphertext and cannot read your items or view your photos. The display name you set for yourself is encrypted the same way. The encryption key is stored on your device and, so that you can get your shared inventories back on a new phone, a copy is saved in the same private Google Drive app-data folder your backup uses — in your Google account. We never receive the key.
What is not encrypted, and what we can see. In plain terms, we can see:
- the name you give a shared inventory — this is stored in plain text on our servers, because the server has to be able to list the inventory for you before you hold its key. Do not put anything private in the name.
- which accounts are members of which group, and their roles,
- how many photos and how many bytes have been uploaded, and when — we use this to bill shared uploads against your credit balance and to detect abuse.
Where it is stored. On Cloudflare (a Cloudflare Worker and Cloudflare R2 object storage), which processes it as our service provider.
Charging. Uploading photos to a shared inventory spends the same credits as Smart Scans. The app tells you the price before an upload runs and never bills you silently.
Leaving, and deletion. If you leave a shared inventory you were invited to, the app asks whether to keep the copy on your device or delete it, and either way your membership and the copy of the snapshot you had uploaded are removed from our server. If you own a shared inventory, you can stop sharing it, which removes it for everyone else. Encrypted photo blobs already uploaded to a group are not automatically erased from our storage — they stay so that a member joining later can still load the pictures. To have a group's stored data deleted outright, email us at the address at the bottom of this policy.
Signing in (Google Sign-In / Firebase Authentication)
Signing in is optional. You need an account to buy scan credits, to earn extra scans by watching a rewarded ad, to back up your inventory to your Google Drive, or to share an inventory. When you sign in, Google Sign-In provides the app with your Google account's email, name, and profile photo, and Firebase Authentication issues a user ID that identifies your account to our scan-credit service. We do not receive your Google password. You can use the entire core app without ever signing in.
Usage analytics (optional — off unless you opt in)
To understand which features people use and where the app is rough, you can optionally share anonymous product analytics. This is off by default. It is available only when you are signed in, and only after you turn on Advanced Settings → "Share usage analytics." While you are signed out, no analytics are collected at all.
When you opt in, the app uses Google Analytics for Firebase to record anonymous, behavior-only events:
- Which actions you take — e.g. starting a scan, saving an item, purchasing scan credits, or earning credits from a rewarded ad — plus standard app-lifecycle events (first open, session start).
- Basic technical context — your app version and general device/OS information.
Each event is tied only to a random, app-generated analytics instance ID. We do not send your name, email, or account ID to analytics, and we never link these events to your identity.
We do not send your inventory to analytics. Item names, photos, attached documents, descriptions, specs, tags, notes, prices, dates, and the names of your areas and spots are never included in any analytics event — analytics see that you saved an item, never what the item is. You can turn analytics back off at any time from Advanced Settings → "Share usage analytics," which stops further collection. Analytics data is processed by Google under Google's privacy policy.
Cloud backup to your own Google Drive (optional)
If you turn on cloud backup, the app copies your inventory (item text and photos, and your attached documents if you leave that option on) into a private, app-specific folder in your own Google Drive (the Drive "app data" area). This data lives in your Google account, under your control — we cannot see or access it, and it is not visible in your normal Drive file list. You can disconnect backup or delete the backup folder at any time from your Google account. This uses Google Drive, governed by Google's privacy policy.
Ads (Google AdMob)
Store & Forget shows ads after a number of free scans, unless you hold purchased scan credits. Ads are served by Google AdMob, which may collect and use a device advertising ID and related device/ad information to serve and measure ads. This data is processed by Google as an advertising partner. You can reset or limit your advertising ID in your device's Google settings. See how Google uses information from apps that use its services and Google's privacy policy.
Scan-credit service (our server)
To meter free and paid scans, the app talks to a small server we operate (a Cloudflare Worker). It receives your Firebase user ID to track how many scans your account has left, and the rewarded-ad reward callback that grants you credits. On paid/credit-backed scans it also receives the photo and text for that scan — including the single photo of a price tag or expiry date when you use quick snap — and immediately forwards it to Google's Gemini API to produce the result. It does not store your photos or item text. We keep only a per-account scan/credit balance, not your inventory.
When you are signed in, the app also sends this server anonymous counts of how many AI search-index operations your account has performed (plain numbers, grouped as search / save / re-index — never your item text, photos, or locations). This lets us keep the shared free AI tier healthy and detect abuse. These counts are sent whenever you are signed in, and are separate from the optional product analytics above (which stay off until you turn them on). Signed out, nothing is sent.
The same server handles shared inventories, as described under "Sharing an inventory" above — that is the one case where it stores content, and it stores it encrypted.
Buying scan credits (Google Play Billing)
If you buy a scan-credit pack, the purchase is handled by Google Play Billing. Google processes the payment; we receive a purchase confirmation (a token/event and the user ID it applies to) so we can add the credits to your balance. We do not receive your card number or other payment details.
How the app updates itself
Store & Forget updates over two channels, and neither one asks you to install anything from outside Google Play:
- Google Play in-app updates. When a newer version is on the Play Store, the app can show Google's own update panel. The update is downloaded and installed by Google Play, through Google's official update mechanism. We never download or install an app package ourselves, and the app never asks you to sideload one.
- Over-the-air JavaScript updates (Expo / EAS Update). Smaller fixes ship as a JavaScript bundle downloaded from Expo's update service, which is the standard update mechanism for React Native apps. This can change the app's JavaScript only — it cannot add native code, cannot add or change an Android permission, and cannot change what the app is allowed to do on your device. When one has downloaded, the app tells you, and it applies the next time you restart the app.
What an update check sends. On launch, the app asks Expo's update service whether a newer bundle exists. That request carries the platform ("android"), the app's runtime version and release channel, the ID of the bundle it is currently running, and an EAS client ID — a random identifier generated the first time the app runs and kept in the app's own private storage. It is not your device's advertising ID, not a hardware identifier, and is not linked to your Google account, your name, or your inventory; clearing the app's data or uninstalling the app discards it. No inventory data of any kind is sent in an update check. Expo processes this as our service provider, under Expo's privacy policy.
Notifications
If you turn on reminders (for items you have lent out, or for items about to expire), the app schedules those notifications on your device. Nothing about them is sent to us or to anyone else, and no reminder is delivered through a server.
Permissions the app requests
- Camera — to let you photograph items as you store them, to photograph a document you want to attach, and to quick-snap a price tag or expiry date. Photos are saved to the app's private storage on your device; a quick-snap photo is deleted after it is read.
- Photos / Media library — to let you attach existing photos from your library to an item.
- Files / documents — to let you pick a receipt, warranty card, or manual from your device and attach it to an item. The app only reads the file you choose, and copies it into its own private storage; it does not browse or scan your files.
- Notifications — to deliver the optional lend and expiry reminders described above.
- Internet / network — for the optional features above (AI, sign-in, ads, cloud backup, sharing, buying credits).
How to delete your data
Your inventory lives on your device for as long as you keep it there. You can delete it at any time:
- Delete individual items, areas, spots, or attachments — use the delete actions inside the app on each detail screen. Deleting an attachment removes the file from your device, not just the entry.
- Erase everything in the app at once — open Advanced Settings → Erase all data. This wipes the local database (all areas, spots, items) and removes every photo and attached document from the app's private storage.
- Delete the app entirely — uninstall Store & Forget from your device. Android will remove the app's private storage, including the SQLite database, all photo files, and all attached documents.
- Delete your cloud backup — remove the app's data folder from your own Google Drive account.
- Leave or stop a shared inventory — from the sharing screen. This removes your membership and your uploaded snapshot from our server; see "Sharing an inventory" above for what remains and how to have it erased.
- Delete your scan-credit balance and any shared-inventory data we hold — email us at the address below.
Children
This app is not directed at children under 13, and we do not knowingly collect any data from children.
Changes to this policy
If we materially change how the app collects, uses, or shares data, we will update this policy and update the in-app and Play Store listing references to it. The "Effective date" at the top reflects the most recent change.
Contact
Questions about this policy, or requests to delete data we hold for your account, can go to hyperkoalastudio@gmail.com.