Legal

Privacy Policy

Effective date: May 19, 2026  ·  Last updated: June 25, 2026
The short version

Your photos and inventory data are yours. We never sell your data, never share it with third parties for marketing, and never use it to train AI models — not ours or anyone else's. You can export or delete everything at any time.

1. Who we are

Identithing is an AI-powered home inventory service operated by Mike Ferrari ("we," "us," or "our"). Our registered contact address for privacy matters is [email protected].

This policy applies to information collected through our website at www.identithing.com and our web application at app.identithing.com.

2. What we collect and why

Account information

When you create an account, we collect your email address. We use it to authenticate you, send transactional emails (processing complete, export ready, account alerts), and communicate about your subscription. We do not collect your name unless you choose to provide it.

Photos and videos you upload

When you photograph a room, those images are uploaded to your private, encrypted storage bucket on Amazon S3. Images are processed by our AI pipeline using Google's Gemini vision model to identify items and estimate values. After processing, thumbnails are stored; original files are retained for your review and for re-processing if you request it.

Your photos are never used to train any AI model — ours or any third party's. They are never shared with other users and never made accessible to other accounts.

Inventory data

The items we identify — names, brands, models, estimated values, room assignments — are stored in your inventory database, isolated to your account. This is the core data Identithing exists to manage on your behalf.

Billing information

Payments are processed by Stripe. We never see or store your full credit card number. We receive a Stripe Customer ID and subscription status, which we use to enforce plan limits and send billing notifications. You can manage your payment method at any time via the billing portal in the app.

Usage and technical data

We collect server-side logs (IP address, request path, timestamp, HTTP status) for security monitoring and debugging. These logs are retained for 30 days and are not used for advertising or behavioral profiling.

Data type Why we collect it Retention
Email address Authentication, transactional email, account recovery Until account deletion
Photos / videos AI item identification; your visual inventory record Until you delete them or your account
Inventory items Core service: your structured home inventory Until you delete them or your account
Stripe customer ID Subscription management, billing portal Until account deletion
Server logs Security monitoring, debugging 30 days

3. How we store and protect your data

All data is stored on Amazon Web Services (AWS) infrastructure located in the United States (us-west-2 region). We use the following safeguards:

  • Encryption at rest: DynamoDB tables and S3 buckets are encrypted with AWS-managed keys (AES-256).
  • Encryption in transit: All connections use TLS 1.2 or higher. No data is transmitted unencrypted.
  • Account isolation: Every database query is scoped to your account. It is architecturally impossible for one user's data to appear in another user's inventory.
  • Authentication: Accounts are protected by Amazon Cognito with email verification. Passwords are never stored in plaintext.
  • Access controls: AWS IAM policies restrict which services can access your data, following the principle of least privilege. No employee has standing access to production user data.

Despite these measures, no system is 100% secure. We will notify you promptly in the event of a breach affecting your data.

4. What we never do

  • We never sell your personal information or inventory data to anyone.
  • We never share your data with advertisers or data brokers.
  • We never use your photos, inventory items, or usage patterns to train AI or machine learning models.
  • We never share your data across accounts without your explicit action — your inventory is yours alone. (Business plan users may choose to grant location-scoped access to specific other users via cross-tenant sharing; those grants are always initiated by you and can be revoked at any time.)

5. Third-party services

Identithing uses the following third-party services to operate. Each has its own privacy policy and data processing terms:

Amazon Web Services

AWS hosts all infrastructure: compute (Lambda, EC2), storage (S3, DynamoDB), and authentication (Cognito). AWS processes your data as a data processor on our behalf, under their service terms.

Google (Gemini)

We use Google's Gemini vision API to identify items in your uploaded photos. Image data is sent to Google for inference and is not used to train Google's models (per their paid-tier API terms). We do not send your email, account ID, or any other personally identifying information alongside the image.

Mailgun

Mailgun (Sinch) sends our transactional emails — processing complete, export ready, team invites, billing notifications. They receive your email address and the message body. Their privacy policy governs their handling of this data.

Stripe

Stripe processes subscription payments. When you subscribe, Stripe collects your payment card information directly and provides us only with a customer reference ID and subscription status. Stripe's privacy policy governs their data practices.

Google Fonts

Our landing pages load fonts from Google Fonts, which may log your IP address. You can review Google's privacy policy for details. Font data is not linked to your Identithing account.

PostHog

With your consent, we use PostHog for first-party product analytics. We send an opaque account identifier and limited product events such as onboarding completion, uploads, exports, and checkout outcomes. We do not send inventory contents, photos, form fields, or your email address to PostHog. We do not use advertising networks or social media tracking pixels.

6. Cookies and local storage

The Identithing app uses browser-managed authentication tokens (via Amazon Cognito) stored in your browser's local storage to keep you signed in. These are strictly necessary for the service to function. We do not use advertising cookies or third-party tracking cookies.

Our landing pages do not set any cookies.

7. Your rights and choices

You have the following rights with respect to your data:

Export

You can export your entire inventory at any time from within the app (Account → Export Inventory). Exports are available as JSON or CSV and include all items, valuations, and metadata. Your export file belongs to you — when you cancel, you keep it.

Delete items or photos

You can delete individual items or photos from the app at any time. Deleted items are permanently removed from our database and storage within 24 hours.

Delete your account

You can delete your account in-app at any time from Account Settings → Delete Account. This triggers immediate, permanent deletion of all data associated with your account — items, photos, profile, subscription, and billing records. The action is irreversible and takes effect within 24 hours.

If you prefer, you can also request deletion by emailing [email protected] with the subject "Delete my account." Email requests are processed within 30 days.

Access and correction

You can view and edit all inventory data directly within the app. To request a summary of what personal information we hold about you, contact us at [email protected].

Opt out of transactional email

You can disable processing-complete and notification emails in Settings → Notifications. Note: critical account emails (billing receipts, security alerts) cannot be disabled while your account is active.

8. California residents — Do Not Sell or Share My Info

Under the California Consumer Privacy Act (CCPA, as amended by the CPRA), California residents have the right to opt out of any "sale" or "sharing" of their personal information.

Identithing does not sell or share your personal information. We do not exchange your data with third parties for monetary or other valuable consideration, and we do not share your data for cross-context behavioral advertising. Because no sale or sharing takes place, there is nothing to opt out of — but the disclosure is required by law, and we are happy to confirm in writing on request.

California residents also have rights to know what personal information we hold about them, to request deletion, and to be free from discrimination for exercising these rights. To exercise any of these rights, contact us at [email protected] with the subject "CCPA request — Identithing." We will respond within 45 days as required by law.

9. Children's privacy

Identithing is not directed to children under 13. We do not knowingly collect personal information from anyone under 13. If you believe a child has created an account, contact us at [email protected] and we will delete the account promptly.

10. Changes to this policy

We may update this policy from time to time. Material changes — changes that affect how we use or share your data — will be communicated by email to your registered address at least 14 days before taking effect. The "Last updated" date at the top of this page always reflects the current version.

Continued use of Identithing after a policy change takes effect constitutes acceptance of the updated policy.

11. Contact us

For any privacy-related questions, requests, or concerns, reach us at:

We aim to respond to all privacy inquiries within 5 business days.