Privacy Policy
Last updated: October 1, 2026
English onlySolo en inglésApenas em inglêsEn anglais uniquementNur auf EnglischSolo in inglese英語のみकेवल अंग्रेज़ी में
Whateren is a personal inventory app. This document explains exactly what data the app stores, where it lives, what we send off your device, and to whom. It is intentionally short and concrete; nothing here is filler.
TL;DR
- What you put into Whateren stays on your device, except for the cases listed under "Data sent off-device" below, and except for what you ask Siri or a Shortcut to do, which stays on the device but passes through the operating system.
- The app does not collect analytics, does not show ads, and we do not sell any data. The website, whateren.com, counts visits with Google Analytics on some pages, as described under "This website" below.
- Whateren has no user accounts and no tracking. Your inventory is stored on your device and, if enabled, in your own iCloud account. Optional Premium AI and some product lookups use Whateren's relay server, as described below.
What Whateren stores
All inventory data is stored locally in Core Data:
- The items you create (name, description, quantity, category, status, custom fields)
- The locations and the location hierarchy
- The photos you attach to items and locations (downsampled JPEGs)
- The change-history timeline: when an item is added, moved or removed, and when its status, quantity or collection changes
- Your preferences (categories, icons, accent color, default status, currency)
- Insurance reports you generate: a PDF per place, with your full legal name (if you set one), the insurer, policy and claim numbers you typed in, and an itemized list of everything inside that place, with photos, serial numbers and prices. With iCloud Sync on, these reports sync to your own iCloud like the rest of your inventory, and never to a shared property (see below).
- When you last printed a QR label for a place: a date, so the app can offer to print only the places that do not have one yet.
- With iCloud Sync on, a copy of your own inventory, with its photos and documents, kept on your device so that you can get it back if signing out of iCloud removes it from the app. It includes the contents of places you locked with a PIN, with their locks, and iOS protects the copy like the rest of the app's data. It never leaves your device: it is not uploaded, not shared and excluded from device backups. It is updated about every ten minutes while the app is open, once more as you leave it, and right after a lock changes, so the last few minutes of changes may not be in it yet, and something you delete leaves the copy at its next update; if writing it would leave the device almost out of space, the update is skipped and Settings > iCloud Status says so. If your inventory disappears after an iCloud account change, the app offers to recover it from this copy and never does so by itself. Recovering puts the inventory back in the app, and iCloud then syncs it to whichever account is signed in, now or later, which may not be the account it came from; the app says so and asks first. Places locked with a PIN are uploaded too, and stay locked with the same PIN. The copy is deleted when you turn off iCloud Sync, when you delete everything in the app, and by Reset Data. A copy kept after an iCloud account change is no longer updated, so it still holds what you deleted since then until you recover from it or delete it in Settings > iCloud Status.
Printed labels
Whateren can print a QR label for a place. Making one and reading one both happen on your device: no server is involved and nothing is sent anywhere.
Scanning a printed label opens that place in the app, and that too is resolved on your device against your own inventory, without a request to anyone. The one exception is a phone that does not have Whateren installed: there the code has nowhere to open, so the browser loads a page on whateren.com explaining what the label is. That request carries the label's anonymous identifier, because it is part of the address, and that page cannot say which place it names either, since no server holds your inventory.
The code itself carries only an anonymous identifier and the address whateren.com. It holds no name, no path and no list of contents, so someone who photographs a label learns nothing about what is inside, and it resolves to a place only in an app that already has your inventory.
What you choose to print BESIDE the code is a different matter. The largest label size can optionally print the place's name, the places it sits inside, how many objects it holds, their categories, or their names, each stamped with the date it was printed. That is ink on paper: anyone who can see the label can read it, and a label cannot be recalled once it is printed. The app says this at the moment you choose, not only here.
Data sent off-device
The following features send data from your device to servers. Each one follows from something you chose to do: enabling sync, identifying a photo, scanning a barcode, looking a board game or an album up. The one exception is the welcome-credits check described under Premium AI, which runs by itself, once, when the app first opens. Siri and Shortcuts are covered in their own section below, because that data reaches the operating system on the same device rather than a server.
1. iCloud Sync (Apple)
If you enable Settings → iCloud Sync, your inventory and photos are synced through your personal iCloud account using Apple's NSPersistentCloudKitContainer. Apple is the data processor; Whateren's developer has no access to anything in your iCloud container.
If you also share a property through iCloud (a CKShare), the participants you invite can read and (if you grant edit permission) modify that property and its descendants. They cannot see anything else in your inventory. Someone you grant edit permission can also move an item out of the shared property into their own inventory: from then on it is stored in their iCloud account, not yours, and stopping sharing does not bring it back. Someone you grant edit permission can also attach documents, such as a receipt, an invoice or a manual, to that property's items. A document attached to an item in a property someone shared with you is stored in the owner's iCloud account, not yours, and everyone the property is shared with can open it, including people who can only view. A receipt can show the store, the prices, loyalty numbers and the last digits of a payment card, so attach only what you are comfortable showing them. If you leave the share, or the owner stops sharing the property, the document stays with the property and you can no longer open it. When you add an item to a shared property, the display name you optionally set (Settings → Your Information → Shared Capture Name) and your iCloud user identifier are synced with that item so other participants can see who added it. Leave the name blank to add items without it. The same is true of the name you record when you lend an item: it syncs with the item like any other field, and any participant of that shared property can read it, whether or not that person uses Whateren.
When you lock a place with a PIN, the place keeps a verifier derived from its PIN (a salted, deliberately slow hash, never the PIN itself), and with iCloud Sync on it syncs with the place like any other field. The lock therefore applies on all your devices and, in a shared property, to every participant, who needs the PIN to see what is inside. A 4- or 6-digit PIN can be worked out by someone who holds the verifier, such as a person the place is shared with, so use one you don't use anywhere else. Locking hides a place's contents inside Whateren; it does not encrypt them, and they sync like the rest of your inventory. If you turn on Face ID or Touch ID for a locked place, a key derived from its PIN is kept in this device's Keychain, usable only after Face ID or Touch ID, and it never leaves the device.
Insurance reports are the one exception to sharing. If you enable iCloud Sync, a report you generate syncs to your own private iCloud account like everything else, including the full legal name printed on it, but it never becomes part of a shared property's data: nobody you share a property with, including someone you have granted edit permission to, can see a report generated from it. Apart from that sync to your own account, a report reaches other people only if you send it yourself, using the share button on the report itself.
If, when you turn iCloud Sync on, you choose Keep What Is on This Device, Whateren deletes what it had stored in your iCloud, including the properties you share, and replaces it with a copy of this device. It asks twice before doing so.
You can disable iCloud Sync at any time in Settings. To delete the cloud copy entirely, clear the Whateren container in iOS Settings → Apple Account → iCloud → Manage Storage → Whateren.
2. Premium AI Identification (Anthropic)
Choosing Don’t Use AI saves photos without sending them to an AI provider. Barcode scans and explicit catalogue searches can still contact enabled product connectors, as described below.
Ordinary Premium AI identification sends one photo per request to Anthropic (the provider of Claude) to identify it. With Premium selected in an add or edit form, each photo you confirm is sent for identification, including additional photos. Changing the mode or buying credits does not send a photo. In fast capture modes, like Speed Add or Burst, each photo is sent as soon as you take it, with no separate selection step. Credit-funded requests are forwarded through Whateren's relay server, which holds the API key and does not store the photos. Like any server your device contacts, the relay sees your network address; it uses it only to limit how many requests can be made, and stores nothing. If you use your own Anthropic API key, the photo goes directly from your device to Anthropic and the relay is not involved. Anthropic returns a structured identification result (name, brand, category, description). Anthropic keeps what the API receives for up to 30 days and then deletes it, longer only for a request flagged as a violation of its Usage Policy (up to two years) or where the law requires; the terms are its Usage Policy (https://www.anthropic.com/legal/aup) and the retention page of its privacy center (https://privacy.claude.com/en/articles/7996866-how-long-do-you-store-my-organization-s-data).
The first time you use Premium AI, Whateren shows a consent sheet that names Anthropic, links to this Privacy Policy, and requires you to tap "I Agree" before any photo is sent. Identification and Enhance require the current disclosure version, so a person who accepted an older text sees the current notice again before their next request. You can withdraw your consent at any time in Settings, under Premium AI: nothing more is sent to Anthropic until you agree again, and new photos are added without AI. To stop using your own Anthropic API key, remove it in Settings → Premium AI.
Scanning a receipt sends its photo, or several photos for a multi-page receipt, to Anthropic in the same way, to read the purchased items. A receipt can show the store, the prices, loyalty numbers and the last digits of a payment card, so review what you scan. The scanned receipt is then stored on your device, and in your iCloud if sync is on, as a document attached to the imported items, where it syncs and is reshared like a photo you took yourself.
Ordinary object identification also sends your category and subcategory names, so the AI can match your organization; ordinary location identification sends only the photo. Identifying an item photo again from an add or edit form also sends its current name, description, category and subcategory.
Enhance, the explicit Premium action on an item or location detail screen, sends that selected record's current details and up to four eligible saved photos to Anthropic in one request. For an item, the details are its name, description, category and subcategory, with your category and subcategory names. For a location, they are its name, description, type and subtype. Suggestions can change only those: the name, the description and the classification. You review the current and suggested values and choose whether to apply them. Nothing is saved before acceptance.
Enhance does not send barcodes, serial numbers, quantities, statuses, prices, purchase or warranty dates, addresses, coordinates, location hierarchies, contained items, change history, documents, catalogue summaries or photos tagged as catalogue artwork. Other inventory records and device identifiers are not sent to Anthropic. Photos tagged as catalogue artwork remain stored with their attribution and are not sent by Enhance. Photos with no recorded source cannot be distinguished from a photo you added yourself.
If you provide your own Anthropic API key (BYOK), it is stored in the iOS Keychain on this device only. It is never sent to Whateren, is not synced to iCloud, and never moves to another device, not even through an encrypted backup restored elsewhere. When you save it, Whateren sends it once to api.anthropic.com to check that Anthropic accepts it, with nothing else. Reset Data deletes it. Deleting the app does not remove Keychain items, so Whateren removes it the first time it opens after a reinstall.
Credit-funded requests are also signed on your device with Apple's App Attest, so that the relay can tell requests from genuine copies of Whateren from others: your device makes a key in its Secure Enclave, and Apple certifies, once per installation, that it belongs to this app. The relay receives the key's public half and its identifier, a random value made for this installation and not linked to you or your Apple Account, checks each request's signature, and stores neither. Requests made with your own API key go to Anthropic directly and are not signed.
The five welcome credits are given once per device. To know whether this device already had them, including after the app is deleted and installed again, Whateren asks Apple's DeviceCheck service through the relay, once, when the app first opens (and once after this update, for a device that already had them). DeviceCheck records the answer in the two bits it keeps for Whateren on each device. The request carries only the token DeviceCheck issues for this purpose, which tells Whateren whether this device already received the credits and nothing about you; like any server, the relay sees your network address, and it stores nothing.
3. Product lookup APIs (barcode and product QR)
When you scan a barcode or a supported product QR code, Whateren makes requests to one or more of the following public catalog APIs to retrieve product metadata:
- Open Library (books)
- Google Books (books)
- Open Food Facts (food / packaged goods)
- Open Beauty Facts (cosmetics and personal care), only if you switch that connector on in Settings, because unlike the three above it is off until you do. It is asked last, so a code the others resolve never reaches it, and it is asked only for a name, brand and size: it is never asked for a picture.
The product code is sent. A supported product QR is normalized to its product identifier; its URL is not opened, and any URL query data is discarded. Whateren labels resolve locally and never become product queries. Whateren does not add your name, account or device identifier. The services can observe your network address when your device contacts them directly.
When one of these catalogs has a picture of the product, Whateren downloads it and attaches it to the item, so a scanned item is not left anonymous. That picture is then stored and synced exactly like a photo you took yourself, which means it also reaches anyone you share that property with. Speed Add uses the same catalogs the same way when it enriches an AI-identified item. Fetching a picture sends nothing about you or your inventory: the request carries the barcode, or the product name the AI proposed, and nothing else.
4. BoardGameGeek (board game details)
Board Games is a connector you switch on yourself, and nothing below happens until you do.
Two actions send a game's name. When you tap Find on BoardGameGeek and search, the words you typed are sent to Whateren's relay server, which asks BoardGameGeek on your behalf and returns the matching titles. And when Premium AI identifies a board game while this connector is on, a specific identified name is sent the same way. A clear match may fill your draft automatically; ambiguous matches let you choose. For a clear match or a game you choose, the relay fetches that game's cover picture and its published facts, meaning the number of players, the playing time and the minimum age, and returns them to your device.
BoardGameGeek never receives your device address or anything about your inventory: no photo you took, no location, no other item. The relay sees only the name being searched and the identifier of the matched or chosen game, and stores neither. Nothing is saved to an item until you confirm or save it, and with the connector off nothing is sent at all, from either flow.
The cover picture is then stored and synced exactly like a photo you took yourself, which means it also reaches anyone you share that property with. It is added alongside your own photos rather than replacing them.
If you later switch the connector off, the title, the picture and the facts you accepted stay on your item. The switch controls whether anything is sent, not what you already made yours.
5. MusicBrainz (album details)
Music is a connector you switch on yourself, and nothing below happens until you do.
Three actions send data. When you tap Find on MusicBrainz and search, the words you typed are sent directly to MusicBrainz, which returns the matching releases: title, artist, year and format. When Premium AI identifies a CD, a vinyl record or a cassette while this connector is on, a specific identified name is sent the same way. A clear match may fill your draft automatically; ambiguous matches let you choose. And when you scan a barcode on an item you have already set to one of those types, the code is sent to look the exact release up. If a clear match or a release you choose has a cover picture, it is fetched from the Cover Art Archive.
There is no server of Whateren's in between: your device talks to MusicBrainz directly, so MusicBrainz observes your device's network address, as any service contacted directly does. Nothing else about your inventory is sent: no photo you took, no location, no other item. Whateren identifies itself to MusicBrainz as an application, not as you.
Nothing is saved to an item until you confirm or save it, and with the connector off nothing is sent at all, from any of the three flows.
The cover picture is then stored and synced exactly like a photo you took yourself, which means it also reaches anyone you share that property with. It is added alongside your own photos rather than replacing them.
If you later switch the connector off, the title, the picture and the facts you accepted stay on your item. The switch controls whether anything is sent, not what you already made yours.
Spotlight (Apple)
Whateren adds your own items and places to your device's Spotlight index so you can find them from the Home Screen: their name, category, the path of places they sit in and their first photo. Serial numbers and the names of people you lend things to can be searched but are not shown. The index stays on your device. It does not include drafts, anything inside a place locked with a PIN, or things someone else shared with you.
Handoff (Apple)
When you have an item or a place open, Whateren offers it to your other devices through Handoff, so it appears in the Dock and the app switcher there and you can carry on where you left off. What travels is the item's or place's identifier and its name, and nothing else: no photos, no prices, no serial numbers, and no location beyond the name you gave the place.
Handoff moves between your own devices, signed in to your own iCloud account, over Apple's own transport. It never reaches Whateren's relay server or Anthropic, and Whateren's developer never sees it. You can turn it off for every app in Settings, under General, then AirPlay & Continuity (AirPlay & Handoff before iOS 18).
Siri and Shortcuts (Apple)
If you ask Siri to find, add, move or relabel something, or build a Shortcut that does, Whateren hands Siri the names, categories, locations and a thumbnail of the items and places that request involves, and an item's status and, for something you lent, the name you recorded for who has it, so it can answer or act without opening the app. None of this goes to Whateren's relay server or to Anthropic, and Whateren's developer never sees it.
Two things are worth knowing about it.
What you say to Siri is handled by Siri under Apple's own privacy terms, the same as any other Siri request, whether or not you use Whateren. That part is between you and Apple.
And Siri answers out loud, so an answer that names where you keep something can be heard by whoever is near the device. For that reason every Whateren action that reads or changes your inventory requires the device to be unlocked first, or the Apple Watch that starts the request: a locked phone on a table will not tell the room where your things are kept.
Reminders (notifications)
Reminders, if you allow notifications, are scheduled by iOS on each of your devices from your own inventory: the morning a loan is due back and before a warranty runs out. A reminder names the item and, for a loan, who has it, and may show on the Lock Screen like any notification. On a device that only receives such an item through iCloud and was never asked, Whateren asks iOS for quiet delivery, which iOS grants without a prompt: the reminder appears only in Notification Center, with no sound, banner or Lock Screen alert, and iOS offers there to keep or turn off these notifications. You can change this at any time in iOS Settings > Notifications > Whateren, which the app's own Settings opens from its Notifications row. A reminder never reaches Whateren's relay server or Anthropic. Items in a place locked with a PIN, and items in a property someone shares with you, send no reminders.
Data we do NOT collect
- The app has no analytics, no telemetry and no crash reporting SDKs
- No advertising identifiers
- No location tracking. Whateren never reads your device's location and never asks for that permission. An address you type for a place is looked up with Apple's map services, and the coordinates found are saved with that place; they belong to your inventory and sync or share with their place when those features are enabled.
- No third-party SDKs of any kind in the app
This website
whateren.com uses Google Analytics to count visits to its pages. It does not run on the page a printed label opens, on this Privacy Policy or on the Terms of Service. Where it runs, Google receives the address of the page, details of your browser and device, and your network address, and sets cookies to tell visits apart. In the European Economic Area, the United Kingdom and Switzerland it runs only if you allow it. Wherever it runs, you can change your choice at any time with Cookie Settings at the bottom of the website's pages. The app itself contains no analytics, and the requests the app sends to Whateren's relay, which runs on this site's server, are never counted or seen by Google Analytics.
In-App Purchases
Premium credit packs are sold through Apple's StoreKit. Whateren never sees your payment details. Apple processes the transaction and returns a verified entitlement.
Credit grants, spending and refunds are stored on your device and synced through iCloud key-value storage when available, so your remaining balance can usually recover after reinstalling while you are signed in to iCloud. Previously spent or refunded credits are not restored as available credit.
Children
The app has no analytics or advertising, and we do not sell personal data. The optional processing described above also applies when a child uses those features. If you are a parent or guardian and have questions, contact us at the address below.
Account deletion
Whateren has no account. To remove your Whateren data:
- Settings → Reset Data in the app erases your inventory, its history, the insurance reports you generated and the copy of your inventory kept on your device, and clears your settings, including your full legal name, your shared capture name, your Anthropic API key and your choices about AI and connectors. Your credits are kept, and iCloud Sync stays as it was. With iCloud Sync on, it also deletes your inventory from your iCloud and stops sharing the properties you own. If a place is locked, Whateren first asks you to confirm with your device passcode, Face ID or Touch ID.
- Deleting the app removes what it keeps on your device. Keychain items outlive an uninstall, so your Anthropic API key and the Face ID keys of locked places are removed by Whateren the first time it opens after a reinstall.
- Optionally remove Whateren from iCloud → Manage Storage to delete the cloud copy.
An item that someone with edit permission moved out of a property you shared is stored in that person's iCloud account, so removing your data does not delete it. The same is true of a document you attached to an item in a property someone shared with you: it is stored in the owner's iCloud account, so removing your data does not delete it. Delete it yourself while you still have edit permission, or ask the owner.
One mark outlives both, by design: the welcome-credits bit Apple's DeviceCheck keeps for Whateren on your device, which says only that this device already received the welcome credits. It holds nothing about you or your inventory, and Whateren cannot link it to you.
Changes
If we change this policy in any material way, we will update the "Last updated" date at the top.
Contact
If you have any questions about this policy, please contact us at info@whateren.com.