Privacy Policy
Effective October 11, 2026 · Applies to the StuffDNA iOS app and stuffdna.com
Your equipment records are primarily stored on your device. Optional AI, purchases and ads involve clearly described service providers.
Who operates this service
StuffDNA is the mobile application and public website at stuffdna.com. Contact privacy@stuffdna.com for data questions. This notice describes the current app and website; it does not describe unrelated applications.
Information you store on your device
By default, your inventory item records, descriptions, make/model/serial numbers, photos, documents, receipts, warranties, maintenance logs, and saved scan answers are stored on the device. You select what to add. App-provided storage and device-level backup settings may affect whether these records appear in your device backups. We do not automatically upload your full local inventory to StuffDNA Cloud.
Private cloud identifiers and operational records
When you use connected cloud features, the service issues a random app account identifier and a session token that is stored using the device secure storage system. The backend stores the account identifier, a hash of the session token, credit and scan-usage records, rewarded-ad progress, purchase transaction identifiers, entitlement information, Day Pass eligibility and expiry, and security/operational data. A name, email address, or phone number is not currently required for the app session.
AI-assisted repair and parts questions
When you choose to run a cloud AI scan, StuffDNA sends your typed question and selected item text fields, such as name, make, model, serial number, condition, notes, and recent maintenance entries, to its secured backend. The backend transmits this content to OpenAI to generate a response. AI requests in this version do not upload the saved item photo, document, or receipt. Do not include passwords, payment information, or other sensitive data in an AI request. Answers may be incomplete or inaccurate, and part compatibility is not independently verified.
Purchases and subscriptions
Apple handles App Store billing. RevenueCat may receive the random app account identifier and transaction, product, subscription and entitlement information to validate and restore purchases. StuffDNA uses associated records to grant or refuse token and Pro access. We do not receive complete payment-card numbers from Apple. Apple and RevenueCat have their own privacy policies.
Advertising and consent
Free versions may display ads through Google AdMob, including rewarded advertising. Ad networks can process advertising identifiers, device and interaction data, approximate network information, and diagnostics in accordance with their policies and consent settings. StuffDNA uses Google consent mechanisms where applicable and may request non-personalized ads; non-personalized advertising is not the same as no data processing. Revenue from advertising helps support the free service.
Website visits
The public website is a static site hosted on Cloudflare. Cloudflare may process IP addresses, request metadata, security events and standard operational logs in order to deliver the pages and protect them from abuse. The site does not itself require an account, use a contact form, or intentionally place analytics or advertising cookies. Essential edge and browser behavior may still generate technical data.
Purpose, providers and disclosure
We use information as needed to provide the requested app functions, operate AI scans, handle purchases, credit balances, prevent fraudulent scan claims, maintain service security and comply with law. Relevant processors may include Cloudflare, Railway, OpenAI, Apple, RevenueCat and Google AdMob. We do not offer user inventory records for sale. We do not claim to control the independent data practices of those processors.
Retention and your options
Local content generally remains until you remove it, reset the local workspace, or uninstall the app, subject to device backup behavior. Operational server records can be retained as needed for verified balances, transaction history, fraud prevention, legal or tax duties, and service reliability. Clearing the local workspace does not necessarily delete cloud transaction and accounting records. Email privacy@stuffdna.com to request access, deletion, or help identifying the random app account; requests may require verification and may be subject to legal retention requirements. See Data and deletion.
Security and international processing
StuffDNA cloud endpoints use HTTPS and store hashed session tokens server-side. No online service is completely secure. Service providers may process information in the United States and elsewhere under their own safeguards and contractual terms. Report concerns to security@stuffdna.com.
Children and applicable rights
StuffDNA is not directed at children, and we do not knowingly solicit a child’s identity for app registration. Depending on where you live, applicable law may give you rights concerning access, correction, deletion, and other processing choices. Contact the privacy address to make a request; we will assess it under applicable law.
Policy changes
We may revise this policy to reflect changes in features, partners, or legal requirements. The effective date above will be updated when changes are published. Material changes will be communicated in a manner required by law.