Privacy Policy
stuft.in ("we", "us", "our") built this product with a local-first philosophy: by default, your data lives on your machine, not ours. This policy explains what we collect, why, and how we handle it in both Local Mode and Cloud Mode.
1. The Short Version
- Local Mode: We collect nothing. Your photos, items, and tags never leave your hardware.
- Cloud Mode: We store only what's necessary to provide the service β your account email, subscription status, and the inventory data you choose to sync.
- We do not sell your data. We do not serve ads. We never will.
2. What We Collect and Why
Account information
When you register, we collect your email address. We use it to: authenticate your account, send transactional emails (receipt confirmations, password resets, policy updates), and contact you if there is a problem with your account. We do not add you to a marketing list without your explicit opt-in.
Subscription and billing data
Payments are handled by Stripe. We receive and store: your subscription plan, status, and billing period end date. We do not receive or store your full payment card number. Stripe's own privacy policy applies to data they process.
Inventory data (Cloud Mode only)
If you enable cloud sync, your item records, photos, tags, recordings, and bin structure are stored on our servers (via Turso / LibSQL). This data is associated with your user account. You own it and can export or delete it at any time.
Usage data
We collect minimal server logs (IP address, request path, timestamp, HTTP status code) to diagnose errors and monitor performance. Logs are retained for 30 days and are not used for profiling.
Cookies and sessions
We use a single session cookie to keep you logged in. It contains no personal information β only a session identifier. We do not use tracking cookies, analytics pixels, or third-party advertising scripts.
3. How We Share Your Data
We do not sell, rent, or trade your personal data. We share it only with:
- Stripe β to process subscription payments.
- Turso / ChiselStrike β for cloud database storage when Cloud Mode is enabled.
- Law enforcement β if required by a valid legal process. We will notify you to the extent permitted by law.
Our infrastructure providers are bound by contractual data processing agreements and are not permitted to use your data for their own purposes.
4. Data Retention
We retain your account data as long as your account is active. If you delete your account:
- Your inventory data is deleted within 30 days.
- Your email address is retained for up to 90 days in backup systems, then purged.
- Billing records required by law (e.g., tax records) are retained for up to 7 years.
5. Your Rights
Depending on your location, you may have the right to:
- Access β request a copy of the data we hold about you.
- Correction β ask us to correct inaccurate data.
- Deletion β ask us to delete your data ("right to be forgotten").
- Portability β receive your data in a machine-readable format. You can export your inventory from the Settings page at any time.
- Objection β object to certain types of processing.
To exercise any of these rights, email jamie@stuft.in. We will respond within 30 days.
6. Security
We use industry-standard practices to protect your data, including TLS encryption in transit and encryption at rest for cloud-stored data. However, no system is perfectly secure, and we cannot guarantee absolute security.
If we become aware of a data breach that affects your personal information, we will notify you by email within 72 hours of discovery.
7. Children's Privacy
The Service is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, contact us and we will delete it promptly.
8. International Users
If you access the Service from outside the country where our servers are located, your data may be transferred to and processed in that country. By using the Service, you consent to this transfer.
9. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or by posting a notice in the Service. The "Effective date" at the top will always reflect the most recent revision.
10. Contact
Privacy questions, data requests, or concerns: jamie@stuft.in. We respond within 30 days.