Privacy Policy
My Orderly Home ("we", "our", "the app") is a personal inventory management application. This privacy policy explains what data we collect, how we use it, the third-party services we use, and your rights regarding your information.
1. Information We Collect
a) Account Information (Required)
- Email address — used for authentication and account identification
- Display name — shown within the app to identify you
- User ID — a unique identifier assigned to your account
You may sign in using Google, Apple, or email/password. When using Google or Apple sign-in, we receive only your email and name from those services. We do not access your contacts. If you choose to use the optional lending-reminder feature, the app will ask your permission to add reminder events to your Google Calendar — see Section 1(k) below.
b) Inventory Data (User-Created)
- Storage areas, containers, and items you create
- Item names, descriptions, tags, notes, categories, and other details you enter
- Lending records you create to track borrowed items
- Favorites and organizational preferences
c) Media (Optional)
- Photos — item photos you choose to upload (requires camera or gallery access)
- Videos — item videos you choose to upload
Media is uploaded only when you explicitly choose to attach it to an item. We compress images before upload to reduce storage usage.
d) Voice Input (Optional)
If you use the bulk voice entry feature, your spoken words are processed on-device using speech recognition. The transcribed text may be sent to a cloud service (a third-party AI processing service) for parsing into structured item data. Audio recordings are not stored.
e) Photo Bulk Entry (Optional)
If you use the photo bulk entry feature, photos you take or select are sent to a cloud service (a third-party AI processing service) for parsing into structured item data. The photos are processed for item recognition only and are not stored by that service.
f) Location Data (Optional)
Location data (approximate and/or precise) is collected only when you explicitly tap "Add Location" when sending an access request to a container owner. Location is never collected in the background or automatically. The location data is attached to that specific access request notification and stored on our servers.
g) Purchase History (Automatic)
If you subscribe to a paid plan, your subscription status and purchase history are processed through our subscription-management provider. We store your subscription tier, status, and entitlements. We do not store credit card numbers or payment method details — these are handled entirely by Google Play.
h) App Usage and Performance Data (Automatic)
- Analytics — We collect app interaction data (screens visited, features used, in-app search history) to understand how the app is used and improve it. See Section 4 for details on our two-mode analytics approach.
- Crash logs and diagnostics — We collect crash reports, error logs, and performance data to identify and fix bugs.
- Instance identifiers — Anonymous instance IDs generated by third-party SDKs (our analytics, error-monitoring, subscription-management, and push-notification providers) for their respective functions. These IDs are random, not tied to device hardware, and are managed by those services — we do not store them in our database.
i) In-App Messages and Notifications
We store in-app notifications related to sharing activity, access requests, and system messages. Push notification tokens (via our push-notification provider) are stored to deliver notifications to your device.
j) Device Verification (Automatic)
To prevent fraudulent re-signups and protect the trial program, when you sign up we verify your device using a device-integrity and anti-fraud verification service and store a one-way salted hash of your Android device identifier (Settings.Secure.ANDROID_ID combined with an app-specific salt, then SHA-256). The hash is pseudonymous — it cannot be reversed to identify your device or you, and we do not store the raw device identifier. We use it only to detect repeat signups from the same device. Hashes are retained for up to 2 years and then automatically deleted. If verification fails (e.g., on emulators, rooted devices, or sideloaded app installations) the trial is denied. You can contact support if you believe this happened in error.
k) Google Calendar (Optional)
If you choose to add a return reminder for an item you have lent or borrowed, the app asks your permission to access your Google Calendar using the calendar.events scope (https://www.googleapis.com/auth/calendar.events). With your consent, we create a single reminder event on your primary Google Calendar containing the item name, the other person's name, and the expected return date. We only write the reminder events you explicitly create — we do not read, modify, or delete any of your existing calendar events, and we do not copy the contents of your calendar onto our servers. You can revoke this access at any time from your Google Account permissions page.
My Orderly Home's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
2. How We Use Your Data
- To provide and maintain the inventory management service
- To authenticate your identity and secure your account
- To enable sharing of containers with other users via QR codes or direct invites
- To send in-app and push notifications about sharing activity and access requests
- To manage your subscription and enforce plan limits
- To analyze app usage and improve functionality
- To detect and fix crashes, errors, and performance issues
- To enforce usage limits and prevent abuse
3. Data Storage and Security
- All data is stored with our cloud hosting provider (managed PostgreSQL database, authentication, and object storage)
- Data is encrypted in transit (TLS/HTTPS) and at rest
- Data is hosted in the United States (US West — Oregon)
- Your password is never stored in plain text — our cloud hosting provider's authentication service handles secure credential storage
- Row-level security (RLS) policies ensure users can only access their own data and data explicitly shared with them
- The app also maintains a local offline cache on your device using an encrypted SQLite database, which syncs with the cloud when connectivity is available
4. Third-Party Services and Data Sharing
We use the following third-party services to operate the app. Each receives only the minimum data necessary for its function:
| Service | Data Shared | Purpose |
|---|---|---|
| Cloud hosting & database | All account and inventory data | Primary database, authentication, and file storage |
| Subscription management | Purchase history, anonymous device ID | Subscription and in-app purchase management |
| Product analytics | App interactions, search history, device ID; optionally user identity if analytics consent is given | Product analytics and feature flags |
| Error monitoring | Crash logs, diagnostics, device info | Error tracking and performance monitoring |
| Push notifications | Device push token | Push notification delivery |
| AI processing (voice & photo entry) | Voice transcription text or photos (for bulk entry only) | Parsing spoken/photographed items into structured data |
| Device integrity & anti-fraud | Signed device verification token at signup; salted hash of Android ID | Fraud prevention — detects emulators, rooted devices, tampered apps, and repeat signups from the same device |
We do not sell, trade, or rent your personal data to any third party. We do not use advertising SDKs. Your inventory data is visible only to you and users you explicitly share it with.
Analytics Privacy Controls
We use a two-mode analytics approach:
- Anonymous analytics — Always active. Collects non-identifiable usage data (screens visited, features used) to help us improve the app. No personal information is attached.
- Identified analytics — Opt-in only. You can choose to share your identity with analytics in Settings > Privacy. When enabled, your usage data is linked to your account to provide a more personalized experience. You can disable this at any time.
5. Data Retention and Deletion
a) Deleting Individual Data
You can delete your data at any time without deleting your account:
- Items — Open the item and tap the delete button. The item and all its attached photos/videos will be removed.
- Containers — Open the container, go to settings or options, and tap delete. All items within the container will also be deleted.
- Storage Areas — Open the storage area, go to settings or options, and tap delete. All containers and items within will also be deleted.
- Categories and Tags — Remove them from the relevant management screens.
- Shared Access — Revoke sharing from the container's sharing settings.
Deleted items, containers, and storage areas are soft-deleted (hidden from the app immediately) and permanently purged from our servers within 7 days. Associated media files (photos and videos) are removed from storage immediately upon deletion.
b) Exporting Your Data
You can export all your data at any time via Settings > Export My Data. This generates a JSON file containing your profile, storage areas, containers, items, categories, tags, lending records, shared access records, favorites, and notifications.
c) Deleting Your Account
You can delete your entire account via Settings > Delete Account. Account deletion works as follows:
- Your account is immediately marked for deletion and you are signed out
- All your stored media files (photos and videos) are deleted immediately
- There is a 30-day grace period during which you can cancel the deletion by signing back in
- After 30 days, your account and all associated data are permanently and irreversibly deleted
d) Anonymized Data Retention
After account deletion, we may retain the following anonymized (non-identifiable) records for legal and fraud prevention purposes:
- Billing archive records — retained for up to 10 years (tax/legal compliance)
- Fraud prevention records (hashed email and hashed device identifier) — retained for up to 2 years
- Consent log records — retained for up to 6 years
6. Permissions We Request
| Permission | Purpose | Required |
|---|---|---|
| Internet | Sync data with cloud and access online features | Yes |
| Camera | Take photos and videos of items; scan QR codes | Optional |
| Microphone | Voice input for bulk item entry | Optional |
| Location | Attach your location to access requests (user-initiated only) | Optional |
| Notifications | Receive push notifications about sharing activity | Optional |
| Photo/Video Library | Select existing photos or videos to attach to items | Optional |
7. Subscriptions and Payments
My Orderly Home offers subscription plans (Basic, Pro, Premium) managed through Google Play and processed by our subscription-management provider. We do not directly handle payment information — all billing is managed by Google Play. Your subscription status and tier are stored in our database to enforce feature access and usage limits.
New users receive a 7-day free trial with premium-level access. After the trial, a subscription is required to continue using the app.
8. Container Sharing and QR Codes
When you share a container, other users can view its contents based on the access level you set. Sharing is controlled through:
- QR codes — You can generate a QR code for a container. Scanning users may be granted access based on your QR access mode settings (open, label-only, or closed).
- Direct sharing — You can invite users directly by granting them view-only or full access.
- Access labels — You can organize shared users into groups with specific permissions.
You retain full control over who can access your shared containers and can revoke access at any time.
9. Age Requirement
This app is intended for users aged 18 and older. We do not knowingly collect data from anyone under 18. If you believe a minor has provided us with personal information, please contact us and we will delete it.
10. Your Rights
You have the right to:
- Access your personal data — use the Export My Data feature in Settings
- Delete individual data — delete specific items, containers, or storage areas at any time within the app
- Delete your account — request complete account and data deletion via Settings > Delete Account
- Control analytics — manage identified analytics opt-in via Settings > Privacy
- Withdraw consent for optional features (camera, microphone, location, notifications) at any time via device settings
- Data portability — export all your data in JSON format via Settings > Export My Data
11. Changes to This Policy
We may update this privacy policy from time to time. Changes will be reflected by updating the "Last Updated" date above. Continued use of the app after changes constitutes acceptance of the updated policy.
12. Contact Us
If you have questions about this privacy policy, wish to exercise your data rights, or need assistance with data deletion, contact us at:
Email: support@myorderlyhome.com