WhereThat?! Privacy Policy
WhereThat?! is operated by DeadBeet LLC. It helps you remember your belongings and where they live. This policy covers the WhereThat app and website. WhatDo has a separate privacy policy.
What stays on your device
You can keep an inventory without creating a shared house. Local records can include rooms and places, item names, categories, notes, quantities, photos, receipts, documents, purchase details, reminders, and item check-in history. WhereThat stores these records on your device. Your device or computer backups may also contain app data, depending on your Apple backup settings.
Capturing a photo does not by itself publish it. Supported photo recognition, text recognition, search, and house commands run on the device. Optional cloud services are described below. Exported backups and files go to the destinations you choose; WhereThat cannot remove copies you or someone else exports.
Accounts and shared houses
Sign in with Apple supplies an account identifier and, if provided by Apple, a name and email address. You can use Apple’s private relay address. DeadBeet does not receive your Apple password.
When you connect a shared house, household-visible inventory, location structure, activity, and eligible photo or document originals are sent to DeadBeet’s service, hosted on Cloudflare. Invited housemates can access shared content. This can include receipt details, item descriptions, and item check-in history. Only share information you want those people to see. Protect your invitation key and replace it if it has been disclosed.
Items marked private and private document records are excluded from household sharing. Private item attributes are excluded from shared records. Making something private can remove its shared version after a successful sync; it cannot recall a photo, export, or copy another person already downloaded. A failed or offline sync may delay changes reaching other devices.
If you link a WhatDo kitchen, the service uses your signed-in account and kitchen permissions to retrieve kitchen information for the connection or family search you request. A kitchen connection does not make your house inventory public.
Dustwick and optional Cloud AI
Dustwick can handle supported searches and house commands locally. Optional Cloud AI requires your permission in the app. When allowed and used, your message, relevant house context, and selected recent conversation context may be sent through DeadBeet’s Cloudflare service to OpenAI to produce a response. Context can include household item names, locations, quantities, and other details needed for the request. Do not put passwords or other secrets in a message.
Voice dictation requires separate microphone and speech permissions. Supported speech recognition can run on your device; Apple’s speech services may process speech when an on-device recognizer is unavailable. If you choose a cloud voice session, audio and relevant conversation context are sent to OpenAI through the voice service. Permission for Cloud AI does not automatically grant microphone access.
Turning Cloud AI off prevents new optional Cloud AI requests. It does not reverse a completed request or delete provider records from earlier requests. OpenAI’s API data controls describe provider processing and retention. WhereThat does not claim that every provider request has zero retention.
Dustwick check-ins use local prompts to help you review a few belongings. Answers update your saved item details or history only through the actions you choose. An item not recently opened is not proof that it has not been used.
Product information and cover images
When you request product or title information, public catalogue services such as Wikidata and Open Library receive the search text or identifier needed for that lookup. Loading a selected cover also contacts its image host. These requests expose normal connection information, including your IP address, to that service. WhereThat does not need to send a photo of your room to retrieve a matching book or game cover. Source links identify catalogue information where available.
Purchases
Apple processes App Store payments. RevenueCat helps validate purchases and subscription access, including shared Pro access with WhatDo when you use the same account. Those services process transaction and entitlement identifiers and information needed to associate access with your account. DeadBeet does not receive your full payment card details. Apple and RevenueCat may retain transaction records to operate purchases, restore access, prevent fraud, and meet legal requirements.
Optional device integrations
You control camera, photo selection, microphone, speech, notifications, and Home access through iOS or iPadOS permissions. Notifications can remind you about items or optional check-ins. Lock-screen visibility depends on your notification settings.
If enabled, Apple search and Siri integrations can make eligible item information available through your device’s Apple features. Private records are excluded from the app’s search-index export. Home integration reads the home information you authorize. Room capture uses supported device sensors to create a room model. These integrations are optional and do not make your house publicly searchable.
Service operation and support
Cloudflare and our diagnostics provider, Axiom, receive technical connection information needed to deliver requests, secure the service, and diagnose failures. Operational records can include request times, requested URLs, response status, model or feature identifiers, and service usage. A requested URL may include text supplied to a lookup. Support messages contain the information you choose to send. Please avoid sending private documents unless they are needed to address your request.
We use information to provide the features you request, synchronize shared houses, manage purchases, respond to support requests, and protect the service. We do not sell personal information or use inventory content for targeted advertising. Providers may process data in countries other than where you live under their applicable terms and safeguards.
The WhereThat website
The website is hosted on Cloudflare and loads its font from Google Fonts. Those services receive normal connection information, including IP address and browser request details. Following an outbound link takes you to that service. This website currently provides product information and does not offer a separate web inventory account.
Storage, retention, and deletion
Local data remains until you remove it from the app or delete the app’s stored data. Signing out is different from deleting an account: WhereThat can retain a local copy for continued use. Removing the app does not delete a shared house stored on the server. Removing a cloud record does not delete independently saved backups or exports.
The planned account-deletion feature will remove your WhereThat account and associated WhereThat data without deleting your WhatDo kitchens. It will not automatically cancel Apple subscriptions. This feature is not yet available. Shared-house ownership consequences, deletion completion timing, and operational backup retention are being finalized before launch. The final policy will describe the implemented in-app deletion route and any limited records retained for legal or transaction purposes.
For privacy questions or a data request during testing, contact support@wherethatapp.com and identify WhereThat. Do not include your Apple password. We may need to verify your identity before providing or deleting account information.
Your choices and rights
You can edit your inventory, choose what to share, export a backup, change Cloud AI permission, and manage device permissions. Depending on where you live, you may have additional rights to access, correct, delete, or receive a copy of personal information, restrict or object to processing, or complain to a relevant privacy authority. Contact us to exercise those rights. Applicable law determines the response period and any permitted exceptions.
Children, security, and changes
WhereThat is not directed to children under 13. Contact us if you believe a child has provided personal information without appropriate permission. We use access controls and encrypted network connections to protect information, but no service or device can guarantee absolute security.
We will update the effective date when this policy changes and provide notice of material changes as appropriate. Contact DeadBeet LLC at support@wherethatapp.com.