Privacy Policy
Last updated: September 10, 2026
English onlySolo en inglésApenas em inglêsEn anglais uniquementNur auf EnglischSolo in inglese英語のみकेवल अंग्रेज़ी में
Whateren is a personal inventory app. This document explains exactly what data the app stores, where it lives, what we send off your device, and to whom. It is intentionally short and concrete; nothing here is filler.
TL;DR
- What you put into Whateren stays on your device, except for the cases listed under "Data sent off-device" below, and except for what you ask Siri or a Shortcut to do, which stays on the device but passes through the operating system.
- We do not collect analytics, do not show ads, and do not sell any data.
- Whateren has no user accounts and no tracking. Your inventory is stored on your device and, if enabled, in your own iCloud account. Optional Premium AI and some product lookups use Whateren's relay server, as described below.
What Whateren stores
All inventory data is stored locally in Core Data:
- The items you create (name, description, quantity, category, status, custom fields)
- The locations and the location hierarchy
- The photos you attach to items and locations (downsampled JPEGs)
- The change-history timeline (created / updated / moved / removed events)
- Your preferences (categories, icons, accent color, language, default status, currency)
- Insurance reports you generate: a PDF per place, with your full legal name (if you set one), the insurer, policy and claim numbers you typed in, and an itemized list of everything inside that place, with photos, serial numbers and prices.
- When you last printed a QR label for a place: a date, so the app can offer to print only the places that do not have one yet.
Printed labels
Whateren can print a QR label for a place. Making one and reading one both happen on your device: no server is involved and nothing is sent anywhere.
Scanning a printed label opens that place in the app, and that too is resolved on your device against your own inventory, without a request to anyone. The one exception is a phone that does not have Whateren installed: there the code has nowhere to open, so the browser loads a page on whateren.com explaining what the label is. That request carries the label's anonymous identifier, because it is part of the address, and that page cannot say which place it names either, since no server holds your inventory.
The code itself carries only an anonymous identifier and the address whateren.com. It holds no name, no path and no list of contents, so someone who photographs a label learns nothing about what is inside, and it resolves to a place only in an app that already has your inventory.
What you choose to print BESIDE the code is a different matter. The largest label size can optionally print the place's name, the places it sits inside, how many objects it holds, their categories, or their names, each stamped with the date it was printed. That is ink on paper: anyone who can see the label can read it, and a label cannot be recalled once it is printed. The app says this at the moment you choose, not only here.
Data sent off-device
The following features send data from your device to servers. Each one follows from something you chose to do: enabling sync, identifying a photo, scanning a barcode, looking a board game or an album up. Siri and Shortcuts are covered in their own section below, because that data reaches the operating system on the same device rather than a server.
1. iCloud Sync (Apple)
If you enable Settings → iCloud Sync, your inventory and photos are synced through your personal iCloud account using Apple's NSPersistentCloudKitContainer. Apple is the data processor; Whateren's developer has no access to anything in your iCloud container.
If you also use Family Sharing for a property (a CKShare), the participants you invite can read and (if you grant edit permission) modify that property and its descendants. They cannot see anything else in your inventory. When you add an item to a shared property, the display name you optionally set (Settings → iCloud Sync → Your Name) and your iCloud user identifier are synced with that item so other participants can see who added it. Leave the name blank to add items without it. The same is true of the name you record when you lend an item: it syncs with the item like any other field, and any participant of that shared property can read it, whether or not that person uses Whateren.
Insurance reports are the one exception to sharing. If you enable iCloud Sync, a report you generate syncs to your own private iCloud account like everything else, but it never becomes part of a shared property's data: nobody you share a property with, including someone you have granted edit permission to, can see a report generated from it. A report leaves your device only if you choose to send it, using the share button on the report itself.
You can disable iCloud Sync at any time in Settings. To delete the cloud copy entirely, clear the Whateren container in iOS Settings → Apple ID → iCloud → Manage Storage → Whateren.
2. Premium AI Identification (Anthropic)
The free, on-device AI option uses Apple's Vision framework and (when available) Apple Intelligence. No data leaves the device in free mode.
The optional Premium AI mode sends one photo per request to Anthropic (the provider of Claude) to identify it. In fast capture modes, like Speed Add or Burst, each photo is sent as soon as you take it, with no separate selection step. Credit-funded requests are forwarded through Whateren's relay server, which holds the API key and does not store them; if you use your own Anthropic API key, the photo goes directly from your device to Anthropic and the relay is not involved. Anthropic returns a structured identification result (name, brand, category, description, estimated price). This is governed by Anthropic's Privacy Policy and Usage Policy (https://www.anthropic.com).
The first time you use Premium AI, Whateren shows a consent sheet that names Anthropic, links to this Privacy Policy, and requires you to tap "I Agree" before any photo is sent.
Scanning a receipt sends its photo, or several photos for a multi-page receipt, to Anthropic in the same way, to read the purchased items. A receipt can show the store, the prices, loyalty numbers and the last digits of a payment card, so review what you scan. The scanned receipt is then stored on your device, and in your iCloud if sync is on, as a document attached to the imported items, where it syncs and is reshared like a photo you took yourself.
Whateren does not send your inventory data, item names, locations, change history, photos you have not identified with Premium AI, or any device identifier alongside the photo. Identifying an object also sends your category and subcategory names, so the AI can match your own organization; identifying a location does not.
When you enhance an item you already added, its current name, description, category and subcategory are sent along with the photo, as what you had filled in so far, so the AI can improve it.
If you provide your own Anthropic API key (BYOK), it is stored in the iOS Keychain on your device only. It is not synced to iCloud and is not included in unencrypted iTunes/Finder backups.
3. Product lookup APIs (barcode)
When you scan a barcode Whateren makes requests to one or more of the following public catalog APIs to retrieve product metadata:
- Open Library (books)
- Google Books (books)
- Open Food Facts (food / packaged goods)
- Open Beauty Facts (cosmetics and personal care), only if you switch that connector on in Settings, because unlike the three above it is off until you do. It is asked last, so a code the others resolve never reaches it, and it is asked only for a name, brand and size: it is never asked for a picture.
The barcode digits are sent. Whateren does not add your name, account or device identifier. The services can observe your network address when your device contacts them directly.
When one of these catalogs has a picture of the product, Whateren downloads it and attaches it to the item, so a scanned item is not left anonymous. That picture is then stored and synced exactly like a photo you took yourself, which means it also reaches anyone you share that property with. Speed Add uses the same catalogs the same way when it enriches an AI-identified item. Fetching a picture sends nothing about you or your inventory: the request carries the barcode, or the product name the AI proposed, and nothing else.
4. BoardGameGeek (board game details)
Board Games is a connector you switch on yourself, and nothing below happens until you do.
Two actions send a game's name. When you tap Find on BoardGameGeek and search, the words you typed are sent to Whateren's relay server, which asks BoardGameGeek on your behalf and returns the matching titles. And when Premium AI identifies a board game while this connector is on, the identified name is sent the same way, so the match can be offered to you right on the result, already found. If you then choose a game, the relay fetches that game's cover picture and its published facts, meaning the number of players, the playing time and the minimum age, and returns them to your device.
BoardGameGeek never receives your device address or anything about your inventory: no photo you took, no location, no other item. The relay sees only the name being searched and the identifier of the game you chose, and stores neither. Nothing is saved to an item until you confirm it, and with the connector off nothing is sent at all, from either flow.
The cover picture is then stored and synced exactly like a photo you took yourself, which means it also reaches anyone you share that property with. It is added alongside your own photos rather than replacing them.
If you later switch the connector off, the title, the picture and the facts you accepted stay on your item. The switch controls whether anything is sent, not what you already made yours.
5. MusicBrainz (album details)
Music is a connector you switch on yourself, and nothing below happens until you do.
Three actions send data. When you tap Find on MusicBrainz and search, the words you typed are sent directly to MusicBrainz, which returns the matching releases: title, artist, year and format. When Premium AI identifies a CD, a vinyl record or a cassette while this connector is on, the identified name is sent the same way, so the match can be offered to you right on the result, already found. And when you scan a barcode on an item you have already set to one of those types, the code is sent to look the exact release up. If a release you choose has a cover picture, it is fetched from the Cover Art Archive.
There is no server of Whateren's in between: your device talks to MusicBrainz directly, so MusicBrainz observes your device's network address, as any service contacted directly does. Nothing else about your inventory is sent: no photo you took, no location, no other item. Whateren identifies itself to MusicBrainz as an application, not as you.
Nothing is saved to an item until you confirm or save it, and with the connector off nothing is sent at all, from any of the three flows.
The cover picture is then stored and synced exactly like a photo you took yourself, which means it also reaches anyone you share that property with. It is added alongside your own photos rather than replacing them.
If you later switch the connector off, the title, the picture and the facts you accepted stay on your item. The switch controls whether anything is sent, not what you already made yours.
Handoff (Apple)
When you have an item or a place open, Whateren offers it to your other devices through Handoff, so it appears in the Dock and the app switcher there and you can carry on where you left off. What travels is the item's or place's identifier and its name, and nothing else: no photos, no prices, no serial numbers, and no location beyond the name you gave the place.
Handoff moves between your own devices, signed in to your own iCloud account, over Apple's own transport. It never reaches Whateren's relay server or Anthropic, and Whateren's developer never sees it. You can turn it off for every app in Settings, under General, then AirPlay and Handoff.
Siri and Shortcuts (Apple)
If you ask Siri to find, add, move or relabel something, or build a Shortcut that does, Whateren hands Siri the names, categories, locations and a thumbnail of the items and places that request involves, so it can answer or act without opening the app. None of this goes to Whateren's relay server or to Anthropic, and Whateren's developer never sees it.
Two things are worth knowing about it.
What you say to Siri is handled by Siri under Apple's own privacy terms, the same as any other Siri request, whether or not you use Whateren. That part is between you and Apple.
And Siri answers out loud, so an answer that names where you keep something can be heard by whoever is near the device. For that reason every Whateren action that reads or changes your inventory requires the device to be unlocked first: a locked phone on a table will not tell the room where your things are kept.
Data we do NOT collect
- No analytics, no telemetry, no crash reporting SDKs
- No advertising identifiers
- No continuous location tracking. With your permission, Whateren can use your location to place a pin. Saved addresses and coordinates belong to your inventory and sync or share with their place when those features are enabled. Address lookup and maps use Apple's location and map services.
- No third-party SDKs of any kind
In-App Purchases
Premium credit packs are sold through Apple's StoreKit. Whateren never sees your payment details. Apple processes the transaction and returns a verified entitlement.
Credit grants, spending and refunds are stored on your device and synced through iCloud key-value storage when available, so your remaining balance can recover after reinstalling. Previously spent or refunded credits are not restored as available credit.
Children
Whateren has no analytics or advertising and does not sell personal data. The optional processing described above also applies when a child uses those features. If you are a parent or guardian and have questions, contact us at the address below.
Account deletion
Whateren has no account. To remove all Whateren data:
- Settings → Reset Data in the app, then
- Optionally remove Whateren from iCloud → Manage Storage to delete the cloud copy.
Changes
If we change this policy in any material way, we will update the "Last updated" date and surface the change in-app.
Contact
If you have any questions about this policy, please contact us at info@whateren.com.