Privacy Policy
Valuables — a product of Wishabit, LLC Version 1.0 | Effective Date: March 5, 2026
This Privacy Policy describes how Wishabit, LLC ("we," "us," or "our"), the company behind the Valuables mobile application, collects, uses, and protects your information when you use the Valuables mobile application and related services (the "Service"). This policy is intended as a notice to help you understand our data practices.
1. Information We Collect
1.1 Account Information
When you create an account through Apple Sign-In, we receive:
- Your name (as provided by Apple)
- Your email address (which may be an Apple relay address if you choose to hide your email)
- A unique user identifier
We do not receive or store your Apple ID password.
1.2 Inventory Data
Information you provide when cataloging items, including:
- Item names, descriptions, brands, models, serial numbers, and colors
- Purchase dates, purchase prices, current values, and estimated resale values
- Categories, conditions, warranty information, and insurance status
- Custom notes and tags
- Category-specific details (author and ISBN for books, material for jewelry, size for clothing, etc.)
1.3 Photos and Media
- Photographs you capture using the camera or import from your photo library
- Processed image variants (thumbnails, background-removed versions)
- Image metadata such as dimensions, file size, and capture source (the app, not EXIF GPS data)
1.4 Location Data
- Addresses you manually enter for organizing items by location (e.g., "123 Main St" or "Home")
- Optional latitude and longitude coordinates you provide
Important: We do not access your device's GPS, track your real-time location, or collect location data in the background. All location information is manually entered by you.
1.5 Device and Technical Data
- App version and build number
- Device model (e.g., "iPhone 15 Pro")
- Operating system version
- Push notification registration status
We do not use third-party analytics services, behavioral tracking, advertising identifiers, or cookies.
1.6 Communication Preferences
- Whether you have opted in to push notifications
- Your email communication preferences
2. How We Use Your Information
We use your information for the following purposes:
- Provide the Service: Store and organize your inventory, display your items, and enable features you use
- AI-Powered Features: Analyze photographs to identify items, scan rooms, group photos, and estimate values (see Section 4 for details)
- Notifications: Send push notifications and emails you have opted in to receive, such as sharing invitations and account activity
- Data Export: Generate CSV and PDF exports of your inventory when you request them
- Sharing: Facilitate sharing of inventory data with users you designate
- Service Operation: Maintain, secure, and improve the Service
- Debugging: Diagnose and fix technical issues (access restricted to authorized personnel only)
3. Legal Basis for Processing
Where applicable (such as under the European General Data Protection Regulation), we process your data on the following bases:
- Contract Performance: Processing necessary to provide the Service you signed up for, including core features such as inventory management, AI-powered item analysis, room scanning, and data storage
- Legitimate Interest: Service improvement, security, and debugging, where our interests do not override your rights
- Consent: Push notifications, email communications, and future optional features that we may introduce. You can withdraw consent for these at any time
4. Service Providers
We use third-party service providers in the following categories to operate the Service. These providers process data on our behalf under contractual obligations and are not permitted to use your data for their own purposes:
- Cloud Infrastructure & Database Hosting: Storage, retrieval, and management of your Service data
- Authentication Services: Secure sign-in and account verification
- AI Processing Services: Image analysis for item recognition, room scanning, and photo organization
- Notification Delivery: Sending push notifications and transactional emails you have opted in to receive
- Marketplace Data Providers: Product search and value estimation based on item details (no photos)
- Image Processing Services: Photo enhancement such as background removal
We may change or add service providers from time to time as we improve the Service. The categories of data processed and the purposes described above will remain consistent regardless of specific provider changes.
5. Data Sharing and Disclosure
5.1 We Do Not Sell Your Data
We do not sell your personal data to third parties for their own marketing purposes.
5.2 Service Providers
The service provider categories listed in Section 4 process data on our behalf to operate the Service. These are not third-party data sales or sharing arrangements.
5.3 User-Directed Sharing
When you choose to share inventory data with other users (such as household members), those users can access the shared items, locations, rooms, and associated photos based on the permission level you set. You control all sharing and can revoke access at any time.
5.4 Legal Requirements
We may disclose your information if required to do so by law, or if we believe in good faith that such action is necessary to comply with a legal obligation, protect our rights or safety, or respond to a valid legal process such as a court order or subpoena.
5.5 Future Data Programs
In the future, we may:
- Derive anonymized, aggregate insights from usage patterns (no individual user data would be identifiable)
- Offer opt-in programs where you may choose to share specific data with third parties in exchange for benefits such as product discounts, extended warranties, or other perks. Participation in any such program would require your separate, explicit consent and would not be a condition of using the Service
These features are not currently available. We will update this policy and obtain any necessary consent before introducing them.
6. Data Security
We implement technical and organizational measures to protect your data:
- Encryption in Transit: All data transmitted between the app and our servers uses TLS (HTTPS) encryption
- Encryption at Rest: Data stored on our servers is encrypted at rest
- Client-Side Encryption: Sensitive fields — including financial values, serial numbers, personal notes, and location details — are encrypted on your device before transmission. Encryption keys are generated and stored locally; Valuables cannot access this data in plaintext
- Row-Level Security: Database-level access controls ensure your data is isolated from other users' data at the query level
- No Password Storage: We use Apple Sign-In exclusively, so we never store, process, or have access to passwords
- Secure Credential Storage: Authentication tokens are stored in the iOS Keychain, protected by the device's hardware security
- Restricted Access: Internal access to user data is restricted to authorized personnel for debugging and support purposes only
While we strive to protect your data, no method of electronic storage or transmission is 100% secure. We cannot guarantee absolute security.
7. Your Rights
You have the following rights regarding your data:
- Access: View all your data within the app at any time
- Correction: Edit any information in the app at any time
- Deletion: Request deletion of your account and associated data through Settings. See Section 8 for details
- Portability: Export your data in CSV or PDF format through Settings
- Withdraw Consent: Opt out of push notifications and email communications at any time through your device settings or the app
- Object to Processing: Contact us if you wish to object to specific processing activities
How to Exercise Your Rights: You can exercise most rights directly within the app. For requests that cannot be handled in the app, contact us at privacy@valuables.app. We will respond to verifiable requests within 30 days.
8. Data Retention and Deletion
8.1 Active Accounts
We retain your data for as long as your account is active and as needed to provide the Service.
8.2 Account Deletion
When you request account deletion:
- Your personal data is removed from our active systems
- Your items, locations, rooms, media, and associated data are deleted
- References to you in shared data (such as "shared by" fields) are nullified to protect your identity while preserving the integrity of other users' data
- Your authentication credentials are removed
Some data may persist in encrypted backups for a limited period consistent with our backup retention schedule. Backups are automatically rotated and older backups are permanently deleted.
8.3 Consent Records
Records of your legal consent actions (such as accepting the Terms of Service) are retained as part of our compliance obligations, even after account deletion.
9. Automated Decision-Making and AI
9.1 AI Suggestions
Our AI features analyze photographs to suggest item names, descriptions, categories, and estimated values. These are suggestions only and are not binding.
9.2 User Control
You can review, modify, or override any AI-generated information at any time. AI outputs are never finalized without your ability to edit them.
9.3 No Significant Automated Decisions
We do not use AI or automated processing to make decisions that have legal or similarly significant effects on you. AI features are assistive tools designed to save you time, not to make determinations about you.
10. Children's Privacy
The Service is not directed at children under 13. We do not knowingly collect personal data from children under 13. If we become aware that we have collected data from a child under 13, we will disable the account and delete the associated data promptly.
11. Biometric Data
The app supports Face ID for device-level authentication. Face ID processing is handled entirely by Apple on your device. We never receive, store, transmit, or process biometric data of any kind.
12. State-Specific Privacy Rights
12.1 California Residents (CCPA/CPRA)
If you are a California resident, you have the right to:
- Know what personal information we collect about you and how it is used
- Delete your personal information
- Correct inaccurate personal information
- Non-Discrimination for exercising your privacy rights
Categories of Personal Information Collected: Identifiers (name, email), commercial information (item descriptions, values), internet or electronic network activity (app usage data), geolocation data (user-entered addresses only), and visual information (photographs).
Sale and Sharing: We do not sell your personal information as defined by the CCPA. The data transfers to service provider categories listed in Section 4 are for the purpose of providing the Service and are not "sales" or "sharing" as those terms are defined under the CCPA.
12.2 Virginia, Colorado, and Connecticut Residents
Residents of Virginia (VCDPA), Colorado (CPA), and Connecticut (CTDPA) have similar rights to access, correct, delete, and obtain a copy of their personal data. To exercise these rights, contact us at privacy@valuables.app.
12.3 Other States
We are committed to complying with applicable state privacy laws. If you have questions about your rights under your state's laws, please contact us.
13. International Data Transfers
Your data is stored and processed in the United States. Our service providers may process data in other countries. Where data is transferred internationally, we rely on contractual safeguards and the service providers' commitments to data protection.
If you are located outside the United States, by using the Service you acknowledge that your data will be transferred to and processed in the United States, where data protection laws may differ from those in your jurisdiction.
14. Data Breach Notification
In the event of a data breach that affects your personal data, we will notify you in a timely manner as required by applicable law. Notification will be provided via email and/or through the app, and will include the nature of the breach, the data affected, and steps we are taking in response.
15. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you through the app and, where possible, via email. The updated policy will indicate the new effective date.
You will be asked to acknowledge new versions of this Privacy Policy before continuing to use the Service. Prior versions will remain accessible for your reference.
16. Contact Information
If you have questions or concerns about this Privacy Policy or our data practices, please contact us at:
- Privacy Inquiries: privacy@valuables.app
- General Legal: legal@valuables.app
- App: Use the Feedback feature in Settings