Privacy policy

Last updated: 12 June 2026

Things of Mabob™ ("we", "us", "the app") helps you organise your belongings by putting them in boxes and cataloguing them with photos, voice notes, and AI. This policy explains what personal data we collect, why, who we share it with, and the choices and rights you have. We've tried to write it in plain language.

The short version

1. Who we are

The data controller responsible for your personal data is Popcode Studio, LLC, located at 2530 Hosea L. Williams Dr. NE, Suite B, Atlanta GA 30317. You can reach us about any privacy matter at support@thingsofmabob.com.

2. Information we collect

Information you provide

Information created by using the app

What we do not collect

3. How we use your information

4. AI processing of your content

A core feature of the app is automatic cataloguing. To make it work, we send the relevant content to Google (the Gemini and Vertex AI services):

This processing happens through our secure backend — your content is never sent to Google directly from third-party ad networks, and the results are returned only to us and stored against your account. Google processes this content to perform the requested operation and return the result. We do not use AI to make decisions that have legal or similarly significant effects on you. For more on how Google handles API data, see Google's Gemini API terms.

5. How your information is shared

With other members of your household

Things of Mabob™ is built for shared households. If you create or join a household, the items, photos, voice notes, text, tasks, and member list in that household are visible to the other members of that household. Admins can invite and remove members. Think of a household like a shared folder: everything in it is shared with the people in it.

With our service providers (sub-processors)

We use a small number of trusted providers to run the app. They may process your data only on our instructions and only to provide their service to us:

Provider Purpose Data involved
Supabase Cloud database, file storage, and authentication — our core infrastructure All account data and item content (photos and audio are kept in private storage)
Google (Gemini / Vertex AI) AI analysis, transcription, and duplicate/lost-item matching Item photos, voice notes, and item text
RevenueCat In-app subscription management A household identifier and subscription status (no name or email)
Expo, Apple (APNs), Google (FCM) Delivering push notifications Your device push token and the notification content
Sentry Crash and error reporting, to diagnose and fix problems Crash diagnostics — error details and stack traces, app version, and device model and operating system
Resend Sending invitation emails (only when you invite someone by email) The recipient's email address and invitation details
Netlify Hosting our website (including this page) Standard web server logs

For legal reasons or business transfers

We may disclose data if required by law, to enforce our terms, or to protect the rights and safety of our users and others. If we're involved in a merger, acquisition, or sale of assets, your data may be transferred as part of that deal; we will notify you of any change in control of your data.

6. Legal bases for processing (EEA / UK)

If you are in the European Economic Area or the United Kingdom, we rely on:

7. Data retention & deletion

We keep your personal data for as long as your account is active. When you delete your account, your login and all data that belongs only to you is permanently erased. Content you contributed to a shared household is anonymised (your authorship is removed) so the household can keep functioning for its other members.

You can delete your account at any time from inside the app — see the step-by-step guide. Deletion is immediate. Residual copies may persist in encrypted backups for up to 7 days, after which they are unrecoverable. We may retain a minimal record where the law requires it (for example, tax records relating to a purchase).

8. Security

We protect your data with encryption in transit (HTTPS/TLS), database-level access controls that restrict each user to their own household's data, and private file storage that is reachable only through short-lived, signed links. No system is perfectly secure, but we work to protect your information using industry-standard measures.

9. International data transfers

Our providers (including Supabase, Google, RevenueCat, and Sentry) may process and store data on servers in the United States and other countries. Where data is transferred out of the EEA or UK, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses. By using the app, you understand your data may be processed in these locations.

10. Your privacy rights

Depending on where you live (including under the EU/UK GDPR and the California Consumer Privacy Act), you may have the right to:

We do not "sell" or "share" your personal information as those terms are defined under California law. To exercise any right, email support@thingsofmabob.com; we may need to verify your identity first. EEA/UK users also have the right to lodge a complaint with their local data protection authority.

11. Children's privacy

Things of Mabob™ is not directed to children, and we do not knowingly collect personal data from children under 13 (or under 16 in the EEA where applicable). If you believe a child has provided us with personal data, contact us and we will delete it.

12. Changes to this policy

We may update this policy from time to time. When we make material changes, we'll update the "last updated" date above and, where appropriate, notify you in the app. We encourage you to review this page periodically.

13. Contact us

Questions, requests, or concerns about your privacy? Email us at support@thingsofmabob.com and we'll aim to respond within 2 business days.