Privacy Policy — ARchive
Effective date: 3 September 2026
Last updated: 3 September 2026
This policy explains what data ARchive ("the app", "we", "us") collects, why, where it goes, and what you can do about it. It is written to match what the app actually does today. When the app changes, this page changes.
ARchive is operated by Three Eyed Emu (ABN 60 976 457 601) (the operator). Contact: xraycontainervision@threeeyedemu.com.au.
1. The short version
- ARchive works offline and without an account. Your inventory and photos live on your device.
- If you sign in and turn on sync, a copy is stored on our backend (Supabase) so your other devices and household members can see it.
- We collect crash reports (Sentry) so we can fix bugs. Product analytics (PostHog) are off unless you switch them on.
- We do not sell your data, show ads, use advertising identifiers, or use your photos to train AI.
- You can export everything, wipe your device data in the app, and have your account and cloud data deleted — see Delete your account and data.
2. What we collect
Account data — only if you sign in
- Email address (email sign-up) or the identity your provider shares (Google or Apple sign-in)
- A random user ID
- Sign-up date and last sign-in date
- Passwords are handled by Supabase Auth and stored as salted hashes. We never see your plaintext password.
If you tap Continue without account, no email is collected. The app may create an anonymous random ID so sync can work later; it contains nothing about you.
Inventory data — you create this
- Photos of containers and of their contents
- Labels, notes, categories, quantities, rooms
- Recognition metadata (which recogniser suggested an item, with what confidence)
- Timestamps of when things were added, edited or removed
This data stays on your device unless you enable sync or household sharing.
Diagnostics
- Crash reports and performance traces via Sentry: stack traces, app version, device model, OS version. Personal data is scrubbed before sending; anything that looks like an API key or credential is redacted.
- Product analytics via PostHog — opt-in only. Off by default. If you turn it on (Settings › Privacy & Data › Share anonymous usage data) we receive event names and counts such as "search performed" or "container added", never item names, photos, or your email. Turn it off at any time; we stop immediately and reset the anonymous ID.
What we do not collect
- Location. ARchive requests no location permission.
- Audio recordings. Voice search uses your device's own speech-recognition service (for example Google's or Samsung's); the app receives only the recognised text. That service's privacy policy governs how it handles audio.
- Contacts, messages, calendar, browsing history
- Advertising identifiers
- Face or person detection. The app contains no face-detection or person-detection feature.
3. How we use your data
| Purpose | Data | Basis (GDPR / UK GDPR, where they apply) |
|---|---|---|
| Running your account | Email, user ID | Contract |
| Sync between your devices | Inventory data, photos | Contract |
| Household sharing you set up | Inventory data, household membership | Contract |
| Recognising items in a photo you scan | Photo bytes — see Section 5 | Contract (on-device); Consent (cloud providers) |
| Fixing bugs | Crash reports | Legitimate interest |
| Improving the product | Analytics events — only if you opt in | Consent |
| Replying to you | Contract / legitimate interest |
We do not use your data for advertising, profiling, or automated decisions about you, and we do not use your photos or content to train any AI model.
4. Where your data lives
- Your device — the primary store. The local database is the source of truth.
- Supabase — only if sync is enabled: a copy of your inventory in a PostgreSQL database and your photos in Supabase Storage, protected by per-user row-level security so only you and the household members you invite can read them. Supabase runs on cloud infrastructure it manages.
- Sentry — crash reports, on Sentry's infrastructure.
- PostHog (EU-hosted) — analytics events, only if you opt in.
All traffic between the app and these services uses HTTPS (TLS 1.2 or better). Data at rest on Supabase is encrypted by Supabase.
5. Recognition and third parties
ARchive recognises items in a photo in stages. Where each stage runs matters:
| Stage | Where it runs | Who sees the photo |
|---|---|---|
| Google ML Kit | On your device | No one — nothing leaves the phone |
| ARchive's on-device detector (TensorFlow Lite) | On your device | No one |
| Google Cloud Vision | Our server passes the photo to Google's API and returns the result | Google (transiently), our server (transiently, not stored) |
| OpenAI or Anthropic vision | Only if you paste your own API key in Settings; your device calls the provider directly | That provider. We never see the photo or the key. |
Your API keys are stored in hardware-backed secure storage on your device (Android Keystore / iOS Keychain), are never synced, never logged, never included in crash reports, and never sent to ARchive servers.
Third-party services we use, and their policies:
| Provider | Purpose | Policy |
|---|---|---|
| Supabase | Backend: database, storage, sign-in, sync | https://supabase.com/privacy |
| Sentry | Crash and performance monitoring | https://sentry.io/privacy/ |
| PostHog | Product analytics (opt-in) | https://posthog.com/privacy |
| Google ML Kit | On-device recognition — no data leaves the device | https://developers.google.com/ml-kit/terms |
| Google Cloud Vision | Cloud recognition fallback | https://cloud.google.com/terms/cloud-privacy-notice |
| OpenAI | Optional, with your own key | https://openai.com/policies/privacy-policy |
| Anthropic | Optional, with your own key | https://www.anthropic.com/legal/privacy |
Sign-in with Google or Apple is governed by those providers' policies for the identity data they share with us.
6. Household sharing
If you create a household and invite someone by QR code, they can see the inventory you share and, depending on the role you give them, edit it. You control who is in your household and can remove members at any time. Invites are single-use and expire after ten minutes.
7. Your rights and controls
Whatever country you are in, you can:
- Export your data — Settings › Privacy & Data › Export Data produces a JSON export of rooms, containers and items.
- Correct it — edit anything in the app.
- Wipe your device data — Settings › Delete All Data removes every container, item and photo from the device.
- Delete your account and cloud data — Settings › Account › Delete Account removes everything immediately, or follow /delete-account if you no longer have the app (completed within 30 days, confirmed by email).
- Withdraw consent — turn off analytics, sync, or cloud recognition in Settings at any time.
If you are in Australia, the Privacy Act 1988 and the Australian Privacy Principles apply; you can complain to the Office of the Australian Information Commissioner (https://www.oaic.gov.au). If you are in the UK or EU, the UK GDPR / GDPR rights of access, rectification, erasure, restriction, objection and portability apply, and you can complain to the ICO (https://ico.org.uk/make-a-complaint/) or your local supervisory authority.
To exercise any right, email xraycontainervision@threeeyedemu.com.au. We reply within 30 days.
8. Retention
- Account and cloud data — kept while your account exists; deleted immediately when you delete your account in the app, or within 30 days of an emailed request.
- Device data — yours, on your device, until you delete it or uninstall the app. The app automatically purges its internal detection-session logs after 30 days.
- Crash reports — retained by Sentry for 90 days.
- Analytics events — retained by PostHog per its default policy, and only collected while you have opted in.
9. Children
ARchive is not directed at children and is intended for users aged 18 and over. We do not knowingly collect data from anyone under 18. If you believe we have, email us and we will delete it.
10. International transfers
Our backend providers may store or process data outside your country. Where GDPR or UK GDPR applies, those providers rely on Standard Contractual Clauses or equivalent safeguards, described in their policies linked above.
11. Changes to this policy
We update this page when the app changes. The "Last updated" date at the top moves when we do. For material changes — a new third party, a new category of data — we will tell you in the app at least 14 days before the change takes effect.
12. Contact
Email: xraycontainervision@threeeyedemu.com.au
Operator: Three Eyed Emu · ABN 60 976 457 601, Australia