Skip to content
ThingyProof

Legal

Privacy

This notice explains what ThingyProof stores. Operator: David Gillespie, Whangarei, New Zealand.

What we store

Your email address, optional name from Google, a session cookie, the rooms and item cards you create or accept, usage counts, and subscription status including a Stripe customer id when you pay. Photos are private JPEGs, compressed in your browser to at most 1280 pixels.

Why

To run the inventory, produce exports, enforce free limits, and keep the account signed in. We do not sell personal information. We do not use your photos to train our own models.

Who else sees a photo

Cloudflare hosts the app, the database, and the photo bucket. When a Gemini key or AI Gateway token is configured, the JPEG is sent to Google Gemini Flash-Lite, preferably through Cloudflare AI Gateway, so the model can read it and return JSON. We ask for text only. We do not call image-generation models. If those keys are absent, a practice extractor runs on the server and the photo is not sent to Google.

Stripe processes payments. Resend sends magic-link email when that key is set. Google handles Google sign-in when you use it. Cloudflare Turnstile runs on signup and upload when its keys are set. Marketing pages use fonts already on your device, so they do not call Google Fonts. The signed-in app loads self-hosted Inter files from our own site.

Cookies

The session cookie is essential, HTTP-only, and lasts 30 days. A short-lived cookie holds the Google sign-in state. We do not run a third-party analytics pixel.

Retention and deletion

We keep the account until you delete it. Deletion removes the user, home, rooms, items, sessions, and photo objects. Export the zip first if you want a copy. Privacy requests that export and deletion cannot finish: privacy@thingyproof.com.

Security

Photos are not public URLs. Session tokens are stored hashed. No system is perfect. Export a copy to a place you control.

Updated 6 October 2026.