Privacy Policy
StorSmart
Last updated: July 24, 2026
1. Who We Are
StorSmart is operated by Data Stream Consulting ("we," "us," or "our"), the data controller for personal information collected through this App. Our app helps you photograph, identify, and track your personal and business assets using AI.
Contact: support@datastreamconsulting.org
2. What We Collect
2.1 Information you provide directly
- Account information — email address and password when you sign up
- Photos and videos — images and short videos you capture or upload of your items
- Item data — names, descriptions, estimated values, room assignments, notes, and other fields you enter or edit
- Voice notes — text notes you attach to items
- Documents — if you use the Documents & Records feature, you may attach photos or PDF files of physical documents (receipts, warranties, manuals, and — if you choose — sensitive personal documents). See Section 4.1 for how document data is handled.
- Property survey data — if you use the Property Survey feature, room-by-room photos and notes you capture during a survey
- Location data — if you scan an item's QR code, we record the location at that moment (with your permission) to show where the item was last seen. We do not track your location in the background or at any other time.
2.2 Information collected automatically
- Usage data — which features you use, scan counts, session duration
- Device information — device type, operating system version, app version
- Crash reports — error logs when the app encounters a problem
2.3 Information collected by third-party services on our behalf
- RevenueCat collects your Apple-assigned subscriber ID, purchase history, and subscription status to manage your subscription. We also provide RevenueCat with your account email address and display name so that your subscription can be identified and supported across your devices. RevenueCat does not receive your password, photos, item data, or documents.
2.4 Information we do NOT collect
- We do not access your contacts or calendar
- We do not use your camera or microphone except when you actively initiate a capture
- We do not track your location in the background — only when you actively scan an item QR code
- We do not receive or store your payment card details (handled entirely by Apple)
2.5 Information shared with other users (Household sharing)
If you create or join a household in the App, members of that household can view and edit shared inventory data — including item photos, videos, descriptions, values, notes, and last-known locations — for items in shared spaces. Removing a member or leaving a household stops their access to future changes, but does not retroactively remove data they already viewed or exported.
2.6 Sensitive personal documents — your responsibility
StorSmart's Documents & Records feature allows you to store scans of personal documents for your own reference. We strongly advise against photographing or uploading government-issued identification (driver's licenses, passports, Social Security cards), financial account documents (bank statements, tax returns), medical records, legal documents (wills, deeds, contracts), or any other highly sensitive documents unless you understand and accept the following:
- Sensitive documents stored in StorSmart are encrypted in transit and at rest and are accessible only to your authenticated account
- Inventory exports while you have full access include your items in the formats the App offers (CSV, JSON, and — on paid plans — formatted PDF deliverables). Treat shared export files like any other copy of personal data
- Despite these protections, no digital storage system is completely risk-free
- You are solely responsible for deciding whether to store sensitive documents in the App
3. How We Use Your Information and Our Legal Basis
| Purpose | Data used | Legal basis (GDPR) |
|---|---|---|
| AI item identification and valuation | Photos you submit for scanning | Contract performance |
| Storing your inventory | Item data, photos, notes | Contract performance |
| Authenticating your account | Email address | Contract performance |
| Processing your subscription | Handled entirely by Apple | Contract performance |
| Improving the app | Anonymized usage and crash data | Legitimate interests |
| Responding to support requests | Email address and relevant account data | Legitimate interests |
|---|
Legitimate interests disclosure: Where we rely on legitimate interests, we have balanced those interests against your rights and determined they do not override your privacy interests. You may object to processing based on legitimate interests at any time (see Section 9).
4. AI Processing
When you scan an item using SnapSense, your photo is transmitted to Anthropic's API (the maker of Claude AI) for processing. Under Anthropic's API usage policy, data submitted through the API is not used to train Anthropic's models. Anthropic processes your photo solely to return the identification response. For details, see Anthropic's privacy policy at anthropic.com/privacy.
Important: SnapSense AI estimates are not professional appraisals. See our Terms of Service for the full disclaimer.
4.1 Documents and AI processing
StorSmart's content moderation rules reject photos of government-issued identification, Social Security cards, passports, financial account documents, and medical records. This moderation runs as part of the AI processing itself, so the photo is transmitted to Anthropic's API in order to be evaluated. When a photo is rejected, we do not store the image or any identification data from it, and — under Anthropic's API usage policy — it is not used to train Anthropic's models.
If you do not want a document transmitted to Anthropic at all, use the manual "Add Document" flow described below, which performs no AI processing.
When you use the manual "Add Document" flow (without SnapSense scanning), your document file is stored directly in Supabase without any AI processing. It is never transmitted to Anthropic.
4.2 Prompt injection protection
StorSmart includes technical measures to prevent malicious content embedded in scanned images from manipulating the AI system. All AI outputs are validated against a strict schema before being stored or displayed.
4.3 Sensitive items
Items you mark as "sensitive" are stored in your private vault and are accessible only when you are signed in to your account. This protection applies within the App only — it does not affect how data is stored at rest.
5. Third-Party Services
| Service | Purpose | Their privacy policy |
|---|---|---|
| Supabase | Database and file storage | supabase.com/privacy |
| Anthropic (Claude) | AI item identification | anthropic.com/privacy |
| RevenueCat | Subscription management | revenuecat.com/privacy |
| Apple App Store | Payment processing and IAP | apple.com/legal/privacy |
|---|
We do not sell your data to any third party. We do not share your data with any third party except as described in this table, or as required by law.
6. International Data Transfers
Our services are hosted in the United States. If you are located in the EEA, UK, or another jurisdiction with data transfer restrictions, your personal data will be transferred to and processed in the United States. We rely on Standard Contractual Clauses approved by the European Commission as the transfer mechanism for any such transfers. You may request a copy of the applicable safeguards by contacting us at support@datastreamconsulting.org.
7. Data Storage and Security
Your inventory data and photos are stored on Supabase servers in the United States. We implement row-level security so your data is accessible only to your authenticated account. All connections are encrypted in transit (TLS 1.2+) and data is encrypted at rest. We conduct periodic security reviews and apply security patches promptly.
No method of transmission or storage is 100% secure. In the event of a data breach that affects your rights and freedoms, we will notify you and relevant authorities as required by applicable law.
8. How Long We Keep Your Data
While your account exists. We retain your inventory records for as long as your account exists, including after a subscription lapse (see below).
When a subscription ends. Ending or lapsing a paid subscription does not delete your item records. Access becomes locked as described in our Terms of Service — you cannot browse or use paid features until you resubscribe. Billing owners may export item records as CSV from the lock screen. Household members and business staff seats cannot export the owner's workspace; they must contact the billing owner.
Photos and documents. Full-resolution photos and document files may be purged 12 months after subscription lapse. We email you before purge. Item metadata records remain.
Inactive accounts. If an account has not been accessed for 24 consecutive months, we may delete it and its associated data. We will email the address on the account at least 30 days before any such deletion, so you have the opportunity to sign in or export your data.
Deleting your account. You can delete your account at any time from Profile → Delete Account. Deletion permanently and immediately removes your inventory, photos, documents, and account record from our systems. Some information may persist briefly in encrypted backups and is overwritten on our normal backup rotation. We may retain limited records where required by law (for example, transaction records for tax purposes).
Subscription and payment records. Purchases are processed by Apple. We receive and retain a record of your subscription status, but we never receive or store your payment card details.
Anonymized, aggregated usage analytics that cannot be linked back to you may be retained longer for product improvement purposes.
9. Your Rights
All users
- Access — while your subscription is active, export your inventory from the app (CSV, JSON, and — on paid plans — formatted PDF deliverables). If you are the billing owner and your subscription has lapsed, export item records as CSV from the lock screen (see Terms of Service §4.7)
- Correction — edit any item in your inventory at any time
- Deletion — delete individual items or your entire account (see Section 10)
California residents (CCPA / California Privacy Rights Act)
Under California law (Cal. Civ. Code §1798.100 et seq.), you have the right to:
- Know what personal information we collect, use, disclose, and sell
- Delete your personal information (subject to certain exceptions)
- Correct inaccurate personal information
- Opt out of sale — we do not sell your personal information
- Non-discrimination — we will not penalize you for exercising your rights
To submit a verifiable consumer request, email support@datastreamconsulting.org with the subject line "CCPA Privacy Request." We will respond within 45 days. You may designate an authorized agent to submit a request on your behalf.
EEA and UK residents (GDPR / UK GDPR)
You have the right to:
- Access a copy of your personal data
- Rectify inaccurate personal data
- Erase your personal data ("right to be forgotten")
- Restrict processing in certain circumstances
- Object to processing based on legitimate interests
- Data portability — receive your data in a machine-readable format
- Withdraw consent where processing is based on consent
- Lodge a complaint with your local supervisory authority (in the EU: your national Data Protection Authority; in the UK: the Information Commissioner's Office at ico.org.uk)
Our legal bases for processing are set out in Section 3. To exercise any of these rights, contact support@datastreamconsulting.org.
10. How to Delete Your Account and Data
In-app: Go to Profile > Delete Account and All Data. This permanently and immediately deletes your account, inventory data, and photos — this action cannot be undone and there is no grace period to recover your data afterward.
By email: Send a request to support@datastreamconsulting.org with the subject line "Delete My Account." Include the email address associated with your account. We will confirm deletion within 5 business days.
Deleting your account does not automatically cancel your subscription. Cancel separately through iPhone Settings > Apple ID > Subscriptions to stop future billing.
11. Children's Privacy
StorSmart is not directed at children under 13. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us with personal information, contact us immediately and we will delete it promptly.
12. Changes to This Policy
We may update this policy from time to time. We will notify you of material changes by posting a notice in the App or sending an email to your registered address at least 14 days before the change takes effect. Continued use of the App after changes take effect constitutes acceptance of the updated policy.
The date of the most recent revision is shown at the top of this page.
13. Contact and Complaints
For questions about this policy or your data:
Data Stream Consulting
Email: support@datastreamconsulting.org
EEA/UK residents who are not satisfied with our response have the right to lodge a complaint with their local data protection authority.