DALBOE
Privacy Policy
LAST UPDATED 17 SEPTEMBER 2026
DALBOE records what you own and where you keep it. That is worth being careful with, so this page is written to be read rather than survived: what is stored today, what will change when accounts arrive, and which commitments hold either way.
Accounts and syncing do not exist yet. Everything under "Today" is how the app works now. Everything under "When accounts arrive" is a commitment about how it will work, written down before it is built, so that nobody installs DALBOE on one understanding and finds themselves living under another.
Today
- Your inventory is stored on your device. There is no account, no server and no copy anywhere else.
- Photographs you ask to have identified are sent to an AI provider for that one request.
- Floor plans, addresses and map placement are not sent anywhere unless you allow it, one plan at a time.
- No advertising, no analytics SDK, no tracking, nothing sold or shared with data brokers.
What is held on your device
- Your inventory
- Item names, categories, notes, attributes, condition, quantity, barcodes and the photographs you attach.
- Your locations
- The hierarchy you build, including properties, buildings, rooms, shelves and containers, with any floor plans you import and any map placement you set.
- Settings and counts
- Your preferences, and a count of identifications used this month so the app can tell you when you are near the limit.
What leaves your device
Photographs sent for identification. When you ask DALBOE to identify an item, the photograph and a short text prompt go to Google's Gemini API, which returns a proposed name, category and details. No account identifier, location, address or inventory data is included in that request.
Floor plans and addresses, only when you say so. DALBOE can have a floor plan read by the same kind of service, and that is never automatic. You are asked for that specific plan, at the moment it happens. Agreeing to send a floor plan is not agreeing to send an address, and neither carries over to the next one.
When accounts arrive
An inventory is only worth building if it survives, and losing a phone should not mean rebuilding a house from scratch. So DALBOE will be able to hold your inventory for you, and reach it from your phone, your tablet, your computer, or any device you sign in from.
You will be asked, and there is no default
The first time it matters, DALBOE asks where your inventory should live. Neither answer is preselected, because neither is right for everyone.
- Keep it on this device
- Nothing is uploaded, and there is no backup. If the device is lost, broken or wiped, the inventory is gone with it. Moving to a new phone is a direct transfer you run yourself.
- Sync it to your account
- Your inventory travels with you, encrypted, with a second choice about who is able to unlock it, described below.
Then a second question: who holds the key
Either way, your inventory is encrypted on your device, before it is uploaded, and stored encrypted. That covers item names, notes, attributes, photographs, your location hierarchy and your floor plans. What differs is whether DALBOE is able to unlock it.
- Recoverable - DALBOE can get you back in
- We keep a way to unlock your key, so that forgetting a password is an inconvenience rather than a catastrophe. Your data is protected against a stolen database, a lost laptop, or anyone without our keys. It is not protected against us: because we are able to unlock it, we could also be required to by a valid legal order. This is what most services mean when they say "encrypted", and for most people it is the sensible choice.
- Only you hold the key - end-to-end encrypted
- We keep nothing that can unlock your data. We cannot read it, cannot troubleshoot it, cannot produce it for anyone who asks, and cannot be compelled to, because there is nothing to compel. The cost is exact and we will not pretend otherwise: if you lose both your password and your recovery key, your inventory is gone. Not gone pending appeal. Gone. That is not a policy we could choose to waive; it is arithmetic.
You are not locked into either one. You can start recoverable and switch to holding the key yourself later, or the reverse. When you switch to holding it yourself, the copy that let us unlock your data is destroyed rather than set aside.
What the server can see
Encryption hides contents, not the fact that something exists. In both modes our servers know that an account exists, roughly how much encrypted data it holds, and when it last synced.
In recoverable mode they hold the means to decrypt your inventory, and we will use it for exactly one thing: restoring your access when you ask us to. In end-to-end mode they hold ciphertext and nothing else.
We do not index your inventory on our servers in either mode. Searching, sorting and filtering happen in the app, on your device, after your data syncs down. In end-to-end mode that is forced; in recoverable mode it is a choice, and we are making it deliberately.
Identification, and the shared product catalogue
Identification happens before an item is saved: the photograph is sent, a result comes back, you confirm or correct it, and only then is the item encrypted and stored. So identification works normally and the stored result is still unreadable to us.
From those identifications DALBOE builds a catalogue of products, not people, recording that a particular drill is a drill, its category, its usual attributes, its barcode. That catalogue is how DALBOE will eventually answer most identifications itself instead of paying a third party for every one. It records facts about objects that exist in the world. It is not linked to you, it does not know who asked, and anything that identifies a specific individual object rather than a product, such as a serial number, an engraving or a one-off handmade thing, is not added to it.
If you list something for sale
A marketplace is planned but not built. When it exists, listing an item will be an explicit act with an obvious consequence: the details and photographs you choose to publish are decrypted by your device and uploaded as a listing that buyers, and therefore we, can read. That is what a listing is.
Listing one item does not decrypt anything else. Your inventory stays encrypted; only what you publish becomes readable, and only the parts of it you publish.
What does not change
- Nothing is sold, and nothing is shared with data brokers.
- No advertising network, no analytics or attribution SDK, no tracking across apps or sites.
- Your inventory is never used to build a profile of you, and never shared with anyone because they asked nicely.
- Sending something to an AI service to be read stays a separate decision from storing it. Syncing a floor plan to your own account is not permission to send it anywhere.
- You can delete your account and its contents.
Who else is involved
- Google (Gemini API)
- Processes images and floor plans you submit for identification and returns a result. Google's handling of API data is governed by their own terms.
- Apple, and in future Google Play
- Distribute the app and handle purchases. They may provide aggregate, anonymised download statistics. DALBOE does not receive information from them that identifies you.
- Our hosting provider
- Runs the servers that store encrypted data and serve the product catalogue. They hold the same ciphertext we do and can read it no better than we can.
Children
DALBOE is not directed at children and does not knowingly collect information from anyone under 13.
Your control
While your data is on your device, you control it directly: deleting an item deletes it, and deleting the app removes everything it stored. Once syncing exists, you will be able to export your inventory, delete your account and its contents, change which mode you are in, or switch back to device-only storage. Switching back means the server copy is deleted, not merely hidden.
If you are in recoverable mode and lose your password, contact us and we will get you back in. If you hold the key yourself, we cannot, and no amount of proving who you are will change that. It is the trade you chose, and it is the one thing on this page we are unable to be flexible about.
Changes to this policy
This page is updated before a change ships, not after, and the date at the top says when. A change that materially affects what leaves your device will also be surfaced in the app rather than only here. If a future version of DALBOE ever needs to weaken something promised above, it will say so plainly and ask, rather than quietly revising this page.
Contact
Questions about any of this go to privacy@dalboe.app.