Privacy Policy
Effective date: July 15, 2026
The short version
- Your inventory lives on your device and, if you enable sync, in your own private iCloud. We can't read it.
- Receipt images you scan are parsed and not stored by us. We log only metadata, never content.
- Receipts you email to your forwarding address pass through our servers only until your device picks them up (30 days at most), then they're deleted.
- Beyond that mailbox-in-transit, the only personal data we hold is the email address you give the waitlist — double opt-in, unsubscribe anytime.
- Anonymous usage analytics only — a random ID, no names, no content, no IP. No ads, no selling data, no cross-site tracking. Ever.
1. Who we are
Everynook is a home-inventory app for iOS and the everynook.app website, operated by its developer ("we," "us"). Contact: hello@everynook.app.
2. Your inventory stays with you
Everything you catalog in the App — items, photos, receipts, serial numbers, values, notes — is stored on your device. If you turn on iCloud sync, it's also stored in your personal, private CloudKit database, operated by Apple and tied to your Apple ID. We do not run user accounts and have no server that holds your inventory. We cannot see, access, recover, or delete it.
3. Receipt parsing
When you choose to scan a receipt, the App sends the receipt image to our parsing service (a Cloudflare Worker we operate), which forwards it to OpenAI's API to extract text like store, price, and purchase date. The results come straight back to your device as suggestions you confirm.
- We do not store the receipt image or the extracted content on our servers.
- Our service logs metadata only — timestamps, request sizes, token counts — never receipt content.
- Per OpenAI's API data-usage policy, API inputs are not used to train their models and are retained only briefly for abuse monitoring. See OpenAI's policy.
4. Email receipt forwarding
If you turn on email forwarding, the App gives you a personal, randomly generated address ending in @in.everynook.app. Emails sent to that address are received by a service we operate on Cloudflare. For each email, we process the message text and any PDF or image attachments, and send that content to OpenAI's API (under the same policy linked in section 3) to extract the receipt details.
- Storage is temporary, by design. The original email content, the sender's address, the subject line, and the extracted receipt details are held on our servers only until your device downloads them — at which point they are deleted — or for a maximum of 30 days, whichever comes first. Your receipts live on your device, not with us.
- Mail to unrecognized addresses is rejected during delivery and never stored. Emails that don't look like receipts are deleted immediately.
- No account is created. Your forwarding address is tied to an anonymous credential synced through your own iCloud Keychain — we never learn your name or email address from enabling the feature. (The sender address on mail you forward is typically your own; we hold it only as part of the message, as described above.)
- Notifications: to tell you a receipt has arrived, we store a push-notification token for your device, used only for these alerts. It's removed when it stops working or you turn forwarding off.
- Emails you forward may include other people's information (for example, a gift sender's name). Only forward mail you're comfortable processing this way; you can turn the feature off or get a fresh address at any time in Settings.
5. Device attestation
To keep the parsing service from being abused, the App uses Apple's App Attest to prove requests come from a genuine copy of Everynook. This involves a device-specific attestation identifier that is not tied to your name, Apple ID, or inventory, and is used solely for abuse prevention and rate limiting — not tracking.
6. The waitlist (this website)
If you join the waitlist at everynook.app, we collect and store, in a database we operate on Cloudflare:
- your email address and its confirmation status (we use double opt-in — you're only added after clicking the link we email you);
- timestamps of signup, confirmation, and unsubscribe;
- a salted, irreversible hash of your IP address used briefly for rate limiting — we never store the raw IP.
We use this list solely to email you about Everynook's launch and closely related product news. Every email includes an unsubscribe link that works immediately. To have your address deleted entirely, use the unsubscribe link or email us.
7. Purchases
Subscriptions are processed by Apple through the App Store. Apple handles payment details; we never see your payment information. We receive only anonymized transaction confirmation from Apple's systems needed to unlock features.
8. Analytics and tracking
To understand which features are used and where the App fails, we collect anonymous usage analytics using PostHog (PostHog, Inc., US). Analytics events are routed exclusively through our own servers — the App and Site never connect to PostHog's domains directly.
- What we send: which screens and features are used (for example, "a receipt scan succeeded"), coarse counts and timing, app version, device model class, country/region, and a random identifier generated on your device. That identifier is not tied to your name, email, Apple ID, device attestation identity, or anything in your inventory, and it is reset if you delete the App.
- What we never send: item names, prices as you entered them, photos, receipt or email content, search text, email addresses, or your IP address — which is discarded on receipt and never stored.
- We do not build user profiles, we do not use session recording, and analytics data is never used for advertising, sold, or shared for cross-site tracking. The Site sets no analytics cookies.
The Site uses Cloudflare Turnstile on the waitlist form to distinguish humans from bots. Cloudflare processes requests to the Site and parsing service as our infrastructure provider. If you object to anonymous analytics, email hello@everynook.app.
9. Retention and deletion
- Inventory data: under your control — delete items, delete the App, or remove iCloud data via your device's iCloud settings.
- Receipt images you scan: not retained by us (see section 3).
- Emailed receipts: deleted from our servers when your device downloads them, or after 30 days at most (see section 4).
- Push-notification tokens: kept while email forwarding is on; removed when it's turned off or the token stops working.
- Waitlist emails: kept until you unsubscribe or ask us to delete them; unconfirmed signups are periodically purged.
- Service logs (metadata): kept for a limited period for reliability and abuse prevention, then deleted.
10. Your rights
Depending on where you live (including under Canada's PIPEDA and the EU/UK GDPR), you may have rights to access, correct, delete, or export personal data we hold about you, and to withdraw consent. Beyond emailed receipts in transit (which delete themselves — see section 4), the only personal data we hold long-term is waitlist information, so most requests can be handled instantly — email hello@everynook.app.
11. Children
The Service is not directed at children under 13, and we do not knowingly collect personal information from them. If you believe a child has provided us an email address, contact us and we'll delete it.
12. Changes to this policy
We may update this policy as the Service evolves. Material changes will be flagged in the App or on the Site, and the effective date above always reflects the current version.
13. Contact
Privacy questions or requests: hello@everynook.app.