Privacy policy
Last updated: 19 August 2026
Things of Mabob™ ("we", "us", "the app") helps you organise your belongings by putting them in boxes and cataloguing them with photos, voice notes, and AI. This policy explains what personal data we collect, why, who we share it with, and the choices and rights you have. It covers both the app and this website (thingsofmabob.com). We've tried to write it in plain language.
The short version
- We collect the account details you give us, plus the photos, audio, and text you add to your items.
- Your photos, voice notes, and item text are sent to Google's AI to generate titles, descriptions, keywords, transcripts, and to spot duplicates.
- On this website, and in the app, we measure which ads brought people to Things of Mabob. The app reports installs, trial starts, signup starts, account creations, purchases, and item-creation counts (how many items, never their contents) to Google, plus three once-per-install milestones: that measurement began after install, that a first item was added, and that a tenth item was added. It does not read your advertising ID, it never asks to track you across other companies' apps, and it has no access to your items, photos, or voice notes. You can switch it off in Preferences.
- We don't collect your location, and we never sell your data.
- We use a crash-reporting tool (Sentry) to capture errors and diagnose crashes so we can fix them — not to track you or your behaviour.
- If you share a household, your data is visible to the other members of that household.
- You can permanently delete your account at any time from inside the app. See how to delete your account.
1. Who we are
The data controller responsible for your personal data is Popcode Studio, LLC, located at 2530 Hosea L. Williams Dr. NE, Suite B, Atlanta GA 30317. You can reach us about any privacy matter at support@thingsofmabob.com.
2. Information we collect
Information you provide
- Account & sign-in: your email address and a password (passwords are stored only in hashed form by our authentication provider, never in plain text).
- Profile: an optional display name and avatar image, and your chosen language.
- Household: a household name, the members you invite, and each member's role within the household.
- Your item content: the photos you take, the voice notes you record, and the text you write — item titles, descriptions, tags, notes, and the rooms and boxes you organise items into.
- Invitations: if you invite someone by email, the email address you enter so we can send them the invitation.
- Support: anything you send us when you contact support.
Trying the app without an account
You can try Things of Mabob before creating an account. A trial still syncs your items to our servers — under a temporary account with no email address — so everything works, including AI cataloguing. That temporary account is tied to your installation: if the app is deleted or its session is lost, nobody (including us) can sign back into it. Creating an account keeps the same data and makes it yours. Trial accounts that are abandoned are automatically and permanently deleted, along with all their photos and data, about 30 days after the trial ends.
Information created by using the app
- AI-generated content: titles, descriptions, keywords, estimated physical size, and audio transcripts produced from your photos and voice notes (see section 4).
- Image and text "fingerprints" (embeddings): numeric vectors derived from your photos and text, used to detect duplicate items and match lost items. These are not human-readable.
- Subscription data: if you buy a subscription, your purchase, plan tier, and renewal status, managed through our payments provider. We also keep our own record of the subscription events our payments provider reports to us — the event type (purchase, renewal, cancellation, expiration), the product and plan involved, the transaction dates, and the price and currency — so we can answer billing questions, detect problems, and run revenue reporting. This record never includes your payment card or bank details, which we never see (payment is handled entirely by Apple or Google).
- Promo codes & referrals: if you redeem a promo or referral code, we record which code was redeemed, when, by which household, and what it granted. If the code belongs to a referral partner, we also record that your household was referred by that partner (so we can credit them). We share only aggregate information with partners — never your name, email, or item content.
- Affiliate program participants: if you join our referral program as a partner, we additionally store your business contact details, your commission rate, and a record of payouts we make to you. Your partner dashboard shows only aggregate statistics about referred households — counts and revenue totals, never their identities.
- Device & push tokens: if you enable notifications, a push token for your device and whether it's iOS or Android, so we can deliver notifications.
- Diagnostics & crash reports: error and event logs we keep in our own private database, plus crash reports — the technical details of an error or crash, such as the error type and stack trace, the app version, and your device model and operating system — which we also send to our crash-reporting provider, Sentry, so we can diagnose and fix problems. When you send a bug report, or when the app detects a problem such as data failing to sync, we also attach a technical snapshot of the app's state: your plan and usage counts, how many rooms/boxes/items you have and how many are waiting to sync, the reason a sync failed (the database error code and message), and a short trail of recent technical events (for example “went offline”, “sync pass finished”, “tapped retry”). This snapshot contains only counts, settings, and technical codes — never the contents of your items (no titles, notes, audio transcripts, or photos). These are not used for advertising or behavioural profiling.
Information collected on our website
Our marketing website (thingsofmabob.com) runs the Google Ads tag (gtag.js) so we can measure which advertisements lead people to install the app. When you visit a page on the website, the tag may set cookies in your browser and send Google your IP address, browser and device type, the page you're on, the page that referred you, and — if you arrived from one of our ads — an advertising click identifier. Google uses this to attribute conversions and, where permitted, for remarketing.
Your choice. The tag runs Google Consent Mode. If you are in the European Economic Area, the United Kingdom, or Switzerland, it is set to store nothing until you agree: a banner asks first, and until you choose Accept no advertising or analytics cookie is written and any advertising click identifier is stripped. Choosing Reject leaves it that way. We remember your answer in your browser so you are only asked once — clearing your browser storage makes the banner appear again.
This tag has no access to your account, your items, your photos, or your voice notes. Wherever you are, you can block it with any browser cookie or tracker blocker, and you can turn off ad personalisation in Google's Ad Settings. The app's separate measurement is described next.
Ad measurement in the app
The app includes Google Analytics for Firebase, which exists for one purpose: telling us which advertisements led people to install Things of Mabob. It reports five things to Google — that the app was opened for the first time, that a no-account trial was started, that the create-account button was tapped, that an account was created, and that a subscription was purchased — along with your device type, operating system version, and general region.
It does not read your advertising identifier. The app is built with the version of Google's measurement library that cannot access the iOS advertising ID (IDFA) at all, and we never show the "allow tracking" prompt, because we don't track you across other companies' apps and websites. It also has no access to your items, photos, voice notes, or anything else in your account.
Your choice. In the European Economic Area, the United Kingdom, and Switzerland the app starts in Google's denied consent state and stays there: no advertising or analytics identifier is stored on your device, and the events above are sent without any identifier attached, so Google can only estimate advertising performance in aggregate. Everywhere else, measurement is on. In either case you can turn it off entirely under Preferences → Privacy → Usage measurement, which stops the app sending anything at all.
On-device matching (iOS). Where measurement is on — so not in the EEA, UK, or Switzerland — the app may pass the email address you signed up with to Google's measurement library so it can check, on your device, whether you arrived from one of our ads. Your email address is not sent to Google by this process and it does not leave your phone; only the yes-or-no result contributes to an aggregate count of installs. We never see which individual people came from which ad.
A count we keep ourselves. The first time the app is opened after being installed, and when the try-it-first button or the create-account button is tapped, the app also records that moment in our own database — the date and time, whether it came from iOS, Android, or the web, and the app's version number. Nothing else: no identifier for you or your device, no address, no link to any account. It is a tally mark, and it exists so we can see how many people opened the app at all, started a trial, or started signing up compared with how many finished, which the Google figures above cannot tell us. It is covered by the same switch: turning off Preferences → Privacy → Usage measurement stops it as well. When an abandoned trial is automatically deleted, our server adds one to a count of deleted trials at the same time — again only a tally mark, with no identifier and no connection to the deleted data. And if you turn a trial into a real account, we keep the date that happened as part of your account record, so we can see how well the trial works overall; like the rest of your account, it is permanently deleted when your account is.
Apple's own reporting. Separately from anything the app does, Apple's operating system sends Google an aggregated, delayed report of how many installs each advertising campaign produced (a system called SKAdNetwork). This happens outside the app, contains no identifier for you, and is not something we can switch on or off.
What we do not collect
- We do not collect your location or GPS data.
- We do not track you across other companies' apps and websites. The app does not read your advertising identifier, and does not contain an advertising SDK that shows you ads or builds a behavioural profile. The measurement described above counts installs, signups, and purchases — it does not follow what you do elsewhere.
- We do not record how you use the app screen by screen. There is no product-analytics tool such as Amplitude or Mixpanel. The one diagnostics tool, Sentry, captures crash and error reports only. The single count we keep for ourselves — taps on the create-account button, with no identifier attached — is described above.
- We do not combine advertising data with the contents of your account, and we do not sell your data.
3. How we use your information
- To provide the core service — storing, organising, and showing your items, boxes, and households across your devices.
- To generate AI titles, descriptions, keywords, and transcripts, and to detect duplicate and lost items.
- To enable household collaboration — sharing items, tasks, and notifications between members.
- To process subscriptions and manage your plan.
- To send notifications you've asked for (e.g. a household task, or a possible match for a lost item).
- To provide customer support and to keep the app secure, prevent abuse, and fix bugs.
- To comply with our legal obligations.
4. AI processing of your content
A core feature of the app is automatic cataloguing. To make it work, we send the relevant content to Google (the Gemini and Vertex AI services):
- Photos you capture are sent to Google to generate a title, description, and keywords, and to create a fingerprint used for duplicate and lost-item matching.
- Voice notes you record are sent to Google to produce a text transcript.
- Item text (such as a lost-item description) may be sent to Google to create a text fingerprint for matching.
This processing happens through our secure backend — your content is never sent to Google directly from third-party ad networks, and the results are returned only to us and stored against your account. Google processes this content to perform the requested operation and return the result. We do not use AI to make decisions that have legal or similarly significant effects on you. For more on how Google handles API data, see Google's Gemini API terms.
5. How your information is shared
With other members of your household
Things of Mabob™ is built for shared households. If you create or join a household, the items, photos, voice notes, text, tasks, and member list in that household are visible to the other members of that household. Admins can invite and remove members. Think of a household like a shared folder: everything in it is shared with the people in it.
With our service providers (sub-processors)
We use a small number of trusted providers to run the app. They may process your data only on our instructions and only to provide their service to us:
| Provider | Purpose | Data involved |
|---|---|---|
| Supabase | Cloud database, file storage, and authentication — our core infrastructure | All account data and item content (photos and audio are kept in private storage) |
| Google (Gemini / Vertex AI) | AI analysis, transcription, and duplicate/lost-item matching | Item photos, voice notes, and item text |
| RevenueCat | In-app subscription management | A household identifier and subscription status (no name or email) |
| Expo, Apple (APNs), Google (FCM) | Delivering push notifications | Your device push token and the notification content |
| Sentry | Crash and error reporting, to diagnose and fix problems | Crash diagnostics — error details and stack traces, app version, and device model and operating system |
| Resend | Sending invitation emails (only when you invite someone by email) | The recipient's email address and invitation details |
| Netlify | Hosting our website (including this page) | Standard web server logs |
| Google Ads (gtag.js) | Measuring which advertisements bring visitors to our website | Website cookies, IP address, browser and device type, pages visited, referring page, and any advertising click identifier |
| Google Analytics for Firebase | Measuring which advertisements led to app installs — in the app, on iOS and Android | First app open, a once-per-install measurement-start marker, trial start, signup start, account creation, item-created counts (with first-item and tenth-item milestones — a number of items only, never their contents), and purchase events; device type, operating system version, and general region. No advertising identifier. In the EEA, UK, and Switzerland these are sent without any identifier attached |
For legal reasons or business transfers
We may disclose data if required by law, to enforce our terms, or to protect the rights and safety of our users and others. If we're involved in a merger, acquisition, or sale of assets, your data may be transferred as part of that deal; we will notify you of any change in control of your data.
6. Legal bases for processing (EEA / UK)
If you are in the European Economic Area or the United Kingdom, we rely on:
- Performance of a contract — to provide the app's core features you've signed up for.
- Legitimate interests — to keep the app secure, prevent abuse, fix bugs, and improve our service, balanced against your rights.
- Consent — for push notifications and for accessing your camera, microphone, and photos; you can withdraw consent at any time in your device settings. Consent is also the basis for the advertising cookies on our website: in the EEA, the UK, and Switzerland nothing is stored until you accept the banner, and you can withdraw by clearing your browser storage for this site, which brings the banner back.
- Legitimate interests, for ad measurement in the app — knowing which advertisements bring people to Things of Mabob is how a small team decides where to spend a limited budget. We rely on consent for this on the website, where cookies are stored in your browser. In the app we do not ask, because in the EEA, the UK, and Switzerland the app stores no advertising or analytics identifier on your device and sends nothing that identifies you — only unattributed counts Google can use to estimate campaign performance. You can object at any time by switching measurement off under Preferences → Privacy, which stops the reporting entirely.
- Legal obligation — where we must process data to comply with the law.
7. Data retention & deletion
We keep your personal data for as long as your account is active. When you delete your account, your login and all data that belongs only to you is permanently erased. Content you contributed to a shared household is anonymised (your authorship is removed) so the household can keep functioning for its other members.
You can delete your account at any time from inside the app — see the step-by-step guide. Deletion is immediate. Residual copies may persist in encrypted backups for up to 7 days, after which they are unrecoverable. We may retain a minimal record where the law requires it (for example, tax records relating to a purchase).
Diagnostic and error logs and bug reports are technical records (counts, settings, and error codes — never the contents of your items). We keep them for a limited time to fix problems; when you delete your account we strip the identifiers linking them to you, so they remain only as de-identified debugging records.
When a household is deleted, its subscription-event records, promo-code redemptions, and any referral attribution are deleted along with it (subject to the legal-retention note above). Affiliate-program business records (contact, commission rate, payout history) are retained while the partnership is active and afterwards as required for accounting.
8. Security
We protect your data with encryption in transit (HTTPS/TLS), database-level access controls that restrict each user to their own household's data, and private file storage that is reachable only through short-lived, signed links. No system is perfectly secure, but we work to protect your information using industry-standard measures.
9. International data transfers
Our providers (including Supabase, Google, RevenueCat, and Sentry) may process and store data on servers in the United States and other countries. Where data is transferred out of the EEA or UK, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses. By using the app, you understand your data may be processed in these locations.
10. Your privacy rights
Depending on where you live (including under the EU/UK GDPR and the California Consumer Privacy Act), you may have the right to:
- Access a copy of the personal data we hold about you.
- Correct inaccurate data (your name, email, and item content can be edited in the app).
- Delete your account and data (in-app deletion).
- Port your data — request an export in a portable format.
- Restrict or object to certain processing.
- Withdraw consent at any time, without affecting prior processing.
- Not be discriminated against for exercising your rights (CCPA).
We do not "sell" your personal information for money. The advertising cookies on our website may count as "sharing" for cross-context behavioural advertising under California law. To opt out on the website, block cookies for this site in your browser, use a tracker blocker, or turn off ad personalisation in Google's Ad Settings. To opt out in the app, switch off Preferences → Privacy → Usage measurement. Nothing in your account is involved either way. To exercise any right, email support@thingsofmabob.com; we may need to verify your identity first. EEA/UK users also have the right to lodge a complaint with their local data protection authority.
11. Children's privacy
Things of Mabob™ is not directed to children, and we do not knowingly collect personal data from children under 13 (or under 16 in the EEA where applicable). If you believe a child has provided us with personal data, contact us and we will delete it.
12. Changes to this policy
We may update this policy from time to time. When we make material changes, we'll update the "last updated" date above and, where appropriate, notify you in the app. We encourage you to review this page periodically.
13. Contact us
Questions, requests, or concerns about your privacy? Email us at support@thingsofmabob.com and we'll aim to respond within 2 business days.
This policy is provided to support compliance with the EU/UK GDPR, the California Consumer Privacy Act (CCPA), and the privacy disclosure requirements of the Apple App Store and Google Play. It is a template tailored to how the app works and should be reviewed by qualified legal counsel before publication.