Privacy policy

Last updated: 19 August 2026

Things of Mabob™ ("we", "us", "the app") helps you organise your belongings by putting them in boxes and cataloguing them with photos, voice notes, and AI. This policy explains what personal data we collect, why, who we share it with, and the choices and rights you have. It covers both the app and this website (thingsofmabob.com). We've tried to write it in plain language.

The short version

1. Who we are

The data controller responsible for your personal data is Popcode Studio, LLC, located at 2530 Hosea L. Williams Dr. NE, Suite B, Atlanta GA 30317. You can reach us about any privacy matter at support@thingsofmabob.com.

2. Information we collect

Information you provide

Trying the app without an account

You can try Things of Mabob before creating an account. A trial still syncs your items to our servers — under a temporary account with no email address — so everything works, including AI cataloguing. That temporary account is tied to your installation: if the app is deleted or its session is lost, nobody (including us) can sign back into it. Creating an account keeps the same data and makes it yours. Trial accounts that are abandoned are automatically and permanently deleted, along with all their photos and data, about 30 days after the trial ends.

Information created by using the app

Information collected on our website

Our marketing website (thingsofmabob.com) runs the Google Ads tag (gtag.js) so we can measure which advertisements lead people to install the app. When you visit a page on the website, the tag may set cookies in your browser and send Google your IP address, browser and device type, the page you're on, the page that referred you, and — if you arrived from one of our ads — an advertising click identifier. Google uses this to attribute conversions and, where permitted, for remarketing.

Your choice. The tag runs Google Consent Mode. If you are in the European Economic Area, the United Kingdom, or Switzerland, it is set to store nothing until you agree: a banner asks first, and until you choose Accept no advertising or analytics cookie is written and any advertising click identifier is stripped. Choosing Reject leaves it that way. We remember your answer in your browser so you are only asked once — clearing your browser storage makes the banner appear again.

This tag has no access to your account, your items, your photos, or your voice notes. Wherever you are, you can block it with any browser cookie or tracker blocker, and you can turn off ad personalisation in Google's Ad Settings. The app's separate measurement is described next.

Ad measurement in the app

The app includes Google Analytics for Firebase, which exists for one purpose: telling us which advertisements led people to install Things of Mabob. It reports five things to Google — that the app was opened for the first time, that a no-account trial was started, that the create-account button was tapped, that an account was created, and that a subscription was purchased — along with your device type, operating system version, and general region.

It does not read your advertising identifier. The app is built with the version of Google's measurement library that cannot access the iOS advertising ID (IDFA) at all, and we never show the "allow tracking" prompt, because we don't track you across other companies' apps and websites. It also has no access to your items, photos, voice notes, or anything else in your account.

Your choice. In the European Economic Area, the United Kingdom, and Switzerland the app starts in Google's denied consent state and stays there: no advertising or analytics identifier is stored on your device, and the events above are sent without any identifier attached, so Google can only estimate advertising performance in aggregate. Everywhere else, measurement is on. In either case you can turn it off entirely under Preferences → Privacy → Usage measurement, which stops the app sending anything at all.

On-device matching (iOS). Where measurement is on — so not in the EEA, UK, or Switzerland — the app may pass the email address you signed up with to Google's measurement library so it can check, on your device, whether you arrived from one of our ads. Your email address is not sent to Google by this process and it does not leave your phone; only the yes-or-no result contributes to an aggregate count of installs. We never see which individual people came from which ad.

A count we keep ourselves. The first time the app is opened after being installed, and when the try-it-first button or the create-account button is tapped, the app also records that moment in our own database — the date and time, whether it came from iOS, Android, or the web, and the app's version number. Nothing else: no identifier for you or your device, no address, no link to any account. It is a tally mark, and it exists so we can see how many people opened the app at all, started a trial, or started signing up compared with how many finished, which the Google figures above cannot tell us. It is covered by the same switch: turning off Preferences → Privacy → Usage measurement stops it as well. When an abandoned trial is automatically deleted, our server adds one to a count of deleted trials at the same time — again only a tally mark, with no identifier and no connection to the deleted data. And if you turn a trial into a real account, we keep the date that happened as part of your account record, so we can see how well the trial works overall; like the rest of your account, it is permanently deleted when your account is.

Apple's own reporting. Separately from anything the app does, Apple's operating system sends Google an aggregated, delayed report of how many installs each advertising campaign produced (a system called SKAdNetwork). This happens outside the app, contains no identifier for you, and is not something we can switch on or off.

What we do not collect

3. How we use your information

4. AI processing of your content

A core feature of the app is automatic cataloguing. To make it work, we send the relevant content to Google (the Gemini and Vertex AI services):

This processing happens through our secure backend — your content is never sent to Google directly from third-party ad networks, and the results are returned only to us and stored against your account. Google processes this content to perform the requested operation and return the result. We do not use AI to make decisions that have legal or similarly significant effects on you. For more on how Google handles API data, see Google's Gemini API terms.

5. How your information is shared

With other members of your household

Things of Mabob™ is built for shared households. If you create or join a household, the items, photos, voice notes, text, tasks, and member list in that household are visible to the other members of that household. Admins can invite and remove members. Think of a household like a shared folder: everything in it is shared with the people in it.

With our service providers (sub-processors)

We use a small number of trusted providers to run the app. They may process your data only on our instructions and only to provide their service to us:

Provider Purpose Data involved
Supabase Cloud database, file storage, and authentication — our core infrastructure All account data and item content (photos and audio are kept in private storage)
Google (Gemini / Vertex AI) AI analysis, transcription, and duplicate/lost-item matching Item photos, voice notes, and item text
RevenueCat In-app subscription management A household identifier and subscription status (no name or email)
Expo, Apple (APNs), Google (FCM) Delivering push notifications Your device push token and the notification content
Sentry Crash and error reporting, to diagnose and fix problems Crash diagnostics — error details and stack traces, app version, and device model and operating system
Resend Sending invitation emails (only when you invite someone by email) The recipient's email address and invitation details
Netlify Hosting our website (including this page) Standard web server logs
Google Ads (gtag.js) Measuring which advertisements bring visitors to our website Website cookies, IP address, browser and device type, pages visited, referring page, and any advertising click identifier
Google Analytics for Firebase Measuring which advertisements led to app installs — in the app, on iOS and Android First app open, a once-per-install measurement-start marker, trial start, signup start, account creation, item-created counts (with first-item and tenth-item milestones — a number of items only, never their contents), and purchase events; device type, operating system version, and general region. No advertising identifier. In the EEA, UK, and Switzerland these are sent without any identifier attached

For legal reasons or business transfers

We may disclose data if required by law, to enforce our terms, or to protect the rights and safety of our users and others. If we're involved in a merger, acquisition, or sale of assets, your data may be transferred as part of that deal; we will notify you of any change in control of your data.

6. Legal bases for processing (EEA / UK)

If you are in the European Economic Area or the United Kingdom, we rely on:

7. Data retention & deletion

We keep your personal data for as long as your account is active. When you delete your account, your login and all data that belongs only to you is permanently erased. Content you contributed to a shared household is anonymised (your authorship is removed) so the household can keep functioning for its other members.

You can delete your account at any time from inside the app — see the step-by-step guide. Deletion is immediate. Residual copies may persist in encrypted backups for up to 7 days, after which they are unrecoverable. We may retain a minimal record where the law requires it (for example, tax records relating to a purchase).

Diagnostic and error logs and bug reports are technical records (counts, settings, and error codes — never the contents of your items). We keep them for a limited time to fix problems; when you delete your account we strip the identifiers linking them to you, so they remain only as de-identified debugging records.

When a household is deleted, its subscription-event records, promo-code redemptions, and any referral attribution are deleted along with it (subject to the legal-retention note above). Affiliate-program business records (contact, commission rate, payout history) are retained while the partnership is active and afterwards as required for accounting.

8. Security

We protect your data with encryption in transit (HTTPS/TLS), database-level access controls that restrict each user to their own household's data, and private file storage that is reachable only through short-lived, signed links. No system is perfectly secure, but we work to protect your information using industry-standard measures.

9. International data transfers

Our providers (including Supabase, Google, RevenueCat, and Sentry) may process and store data on servers in the United States and other countries. Where data is transferred out of the EEA or UK, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses. By using the app, you understand your data may be processed in these locations.

10. Your privacy rights

Depending on where you live (including under the EU/UK GDPR and the California Consumer Privacy Act), you may have the right to:

We do not "sell" your personal information for money. The advertising cookies on our website may count as "sharing" for cross-context behavioural advertising under California law. To opt out on the website, block cookies for this site in your browser, use a tracker blocker, or turn off ad personalisation in Google's Ad Settings. To opt out in the app, switch off Preferences → Privacy → Usage measurement. Nothing in your account is involved either way. To exercise any right, email support@thingsofmabob.com; we may need to verify your identity first. EEA/UK users also have the right to lodge a complaint with their local data protection authority.

11. Children's privacy

Things of Mabob™ is not directed to children, and we do not knowingly collect personal data from children under 13 (or under 16 in the EEA where applicable). If you believe a child has provided us with personal data, contact us and we will delete it.

12. Changes to this policy

We may update this policy from time to time. When we make material changes, we'll update the "last updated" date above and, where appropriate, notify you in the app. We encourage you to review this page periodically.

13. Contact us

Questions, requests, or concerns about your privacy? Email us at support@thingsofmabob.com and we'll aim to respond within 2 business days.