Privacy, mapped clearly
BoxDex Privacy Policy
BoxDex helps you organize what you own and where it lives. This policy explains what information is handled, where it goes, and the controls available to you.
- Effective
- August 31, 2026
- Operator
- DossDev
- Location
- Ontario, Canada
Overview and scope
This Privacy Policy applies to the BoxDex iOS application, related BoxDex web pages, and support communications that link to this policy (together, the “Service”). BoxDex is operated by DossDev in Ontario, Canada. For privacy questions, DossDev is the organization responsible for the personal information it controls.
This policy does not replace the privacy terms of Apple, Google, Supabase, your mobile carrier, or any other service you choose to use with BoxDex. Those organizations handle information under their own terms when acting independently.
Your inventory can be personal
Photos, receipts, notes, serial numbers, values, locations, and household details can reveal sensitive facts about you. Add only information you are comfortable storing in the Service, and protect access to your device and cloud accounts.
Information we handle
The information handled depends on the features you use. BoxDex may handle the following categories:
Account and profile information
When you sign in with Apple or Google, BoxDex receives the identifiers and profile fields the provider makes available based on your settings. These may include a provider account identifier, email address, display name, avatar URL, sign-in provider, and account creation date. Apple may provide a private relay email address instead of your regular address.
Household and sharing information
Household names, member identifiers, roles, invitations, invite status, invited email addresses, share tokens or links, and related membership records used to coordinate shared access.
Inventory content
Rooms, boxes, items, categories, quantities, purchase and estimated values, brands, models, serial numbers, warranty information, notes, tags, QR payload identifiers, and the relationships among those records.
Photos, receipts, and attachments
Images you capture or select for items, boxes, receipts, recognition, reports, or other app features. Images can include metadata and incidental personal information visible in the frame.
Device preferences and exports
App preferences, onboarding state, display choices, feature settings, and files you ask BoxDex to generate, such as CSV, JSON, or PDF exports and reports.
Support and service information
Messages and attachments you send to support, plus limited technical, security, authentication, and service logs produced by DossDev or its providers when needed to operate, protect, or troubleshoot the Service.
BoxDex does not intentionally collect precise location, contacts, health data, or advertising identifiers as part of its core features. Information visible in a photo or written into a free-text field may nevertheless include those details if you choose to add them.
Data on your device and in iCloud
BoxDex stores app data locally so the Service can work on your device. When iCloud sync is available and enabled for your Apple account, inventory records and photo assets are designed to synchronize through Apple CloudKit. Personal inventory generally uses your private CloudKit database; content you intentionally share may use a shared CloudKit database.
Apple processes that information as the iCloud provider under its agreements with you. DossDev does not routinely receive or maintain a separate copy of your complete private CloudKit inventory on a DossDev-operated server. DossDev may still receive limited account, household, support, security, or technical information described in this policy.
If you join a household or accept a CloudKit share, authorized members may be able to see, add, change, or delete shared content according to their role and the capabilities of the Service. A member may also make independent copies or exports that BoxDex cannot later retrieve.
Files you export are created at your direction. Once an export leaves BoxDex, its handling depends on where you save or send it and on the people and services that receive it.
Learn more about Apple privacy and iCloud.
Optional AI item recognition
BoxDex offers an optional feature that can suggest item details from a photo. The feature runs only after you choose to submit an image for recognition.
- Prepare. The selected image is resized so its longest edge is no more than 1024 pixels and compressed for transmission.
- Transmit. The image is sent over the internet to a DossDev-managed Supabase function and then to Google's paid Gemini API service.
- Suggest. The service may return suggested fields such as item name, brand, model, serial number, category, estimated price, and currency symbol.
- Review. You decide whether to use, edit, or discard the suggestions before saving them.
AI-generated suggestions may be incomplete, inaccurate, or unsuitable for your purpose. Review and correct every suggestion before relying on it, including any suggested value, category, model, or serial number.
Do not submit images containing information you do not want processed by these providers. Crop out faces, addresses, financial information, access codes, identity documents, and other sensitive details when they are not needed to identify the item.
Google's treatment of data submitted through a paid Gemini API service is governed by its then-current Gemini API Additional Terms of Service and related privacy terms. Google states that paid-service content is not used to improve its products, but limited information may still be processed or retained for security, abuse prevention, legal compliance, and service operation. Provider terms and practices can change.
How we use information
DossDev and its service providers use information only as reasonably necessary to:
- create and authenticate your account;
- sync, organize, search, display, and share inventory at your direction;
- manage household membership, roles, invitations, and access;
- provide optional AI recognition and generate requested labels, reports, and exports;
- maintain, troubleshoot, secure, monitor abuse of, and improve the reliability of the Service;
- respond to support requests and communicate important service or policy information;
- enforce the Terms of Service, protect users and others, and prevent fraud or misuse; and
- meet legal, regulatory, tax, accounting, or valid law-enforcement requirements.
Depending on where you live and the context, these activities may rely on your consent, performance of a contract with you, compliance with law, or legitimate interests in operating and protecting the Service that do not override your rights. You may withdraw consent for future processing where consent is the applicable basis, although doing so may prevent some features from working and does not make earlier lawful processing invalid.
When information is shared
DossDev does not sell or rent personal information. BoxDex does not use personal information for behavioural advertising and does not include third-party analytics SDKs. Information may be disclosed in these limited circumstances:
Apple and iCloud
For App Store distribution, Sign in with Apple, device services, CloudKit synchronization, private storage, and user-directed sharing.
Supabase
For account authentication, limited profile and household records, invitations, secure backend functions, and operational security. See the Supabase Privacy Policy.
For Google sign-in when selected and for optional image recognition through the paid Gemini API. See the Google Privacy Policy.
Household members
When you create, join, or use a household, information is shared according to the household's roles and your actions.
Recipients you choose
When you export, print, save, or send labels, reports, data files, photos, or other content.
Legal and safety needs
When reasonably necessary to comply with law or valid process; protect rights, safety, and property; investigate abuse; or establish, exercise, or defend legal claims.
If the BoxDex business or relevant assets are reorganized, financed, sold, or transferred, information may be reviewed or transferred as part of that transaction, subject to appropriate confidentiality measures, applicable law, and continued protection consistent with this policy. DossDev will provide notice where legally required.
International processing
DossDev is based in Ontario, Canada. Apple, Supabase, Google, and their subprocessors may process information in Canada, the United States, or other countries where they operate. Those locations may have privacy and government-access laws that differ from the laws where you live.
Where required, DossDev uses contractual or other lawful safeguards for cross-border processing under its control. Information may still be accessible to courts, law enforcement, national security authorities, or regulators in a processing country when lawfully required.
Retention and deletion
Retention depends on the type of information, where it is stored, why it is needed, and your actions:
- Local and CloudKit inventory: generally remains until you delete the relevant content, remove the app's data, leave or end a share, close the account, or Apple removes it under your iCloud settings and terms.
- Account and household records: generally remain while your account or household relationship is active and for a limited period afterward when needed to complete deletion, secure the Service, resolve disputes, prevent fraud, or meet legal obligations.
- Support records: may be retained for as long as reasonably needed to address the request, document the response, and protect legal rights.
- Provider logs and backups: may remain for limited periods under the provider's retention schedule, security practices, and legal obligations.
- AI processing: the paid Gemini API and Supabase process submitted content under their then-current terms. Limited security, abuse-prevention, and operational logs may be retained even when submitted content is not used to improve models.
DossDev may retain de-identified or aggregated information that cannot reasonably identify you. DossDev may also preserve specific records when reasonably necessary for legal compliance, fraud prevention, safety, dispute resolution, or enforcement.
Deletion has practical limits
Deletion is designed to remove account-linked data from BoxDex-controlled systems, but no cloud deletion is instantaneous or absolute. Limited copies may remain temporarily in provider backups, security logs, records required by law, exports held by you or others, and content retained by household members with whom it was shared.
Security
DossDev uses reasonable administrative, technical, and organizational measures intended to protect information under its control. These include relying on provider authentication, encrypted network connections, platform access controls, and limited backend access appropriate to the Service.
No app, device, transmission, or cloud system is completely secure. DossDev cannot guarantee that information will never be accessed, lost, altered, or disclosed without authorization. You are responsible for securing your device, email, Apple or Google account, passcodes, household invitations, exports, and any backup copies.
If DossDev becomes aware of a breach involving personal information under its control, DossDev will investigate and provide notices required by applicable law.
Your choices and controls
- Edit or delete content: change or remove inventory records and images within BoxDex where the feature is available.
- Control sharing: manage household roles, invitations, and shared content, subject to the rights of other members and copies already made.
- Decline AI recognition: enter item information manually instead of sending an image for recognition.
- Manage sign-in providers: review or revoke BoxDex access in your Apple or Google account settings. Revocation may not delete the BoxDex account or information already provided.
- Export: create supported reports or data files for your own records.
- Delete your account: use the account-deletion control in the app. The process attempts to delete BoxDex account records, local app data, and the app's CloudKit zone or related records where technically available.
Account deletion is intended to be permanent and may remove access to inventory, household membership, and other content. Export anything you need first. Technical errors, provider availability, shared ownership, backups, legal duties, and data held independently by other people can limit or delay complete deletion. If in-app deletion fails, contact DossDev for assistance.
Children
BoxDex is not directed to children under 13, and a person must meet any higher minimum age required to consent to data processing where they live. A parent or legal guardian must authorize use when local law requires it. DossDev does not knowingly seek personal information from a child who cannot legally provide it.
If you believe a child provided personal information without valid authorization, email support@dossdev.com so the matter can be reviewed and appropriate action taken.
Your privacy rights
Depending on where you live and subject to legal exceptions, you may have rights to request access to personal information DossDev controls; ask for correction or deletion; receive a portable copy; withdraw consent; object to or restrict certain processing; or appeal a denied request. You may also have the right to complain to a privacy regulator and to receive information about applicable cross-border processing.
DossDev will not unlawfully discriminate against you for exercising a privacy right. Before completing a request, DossDev may need information reasonably necessary to verify your identity, authority, account, and jurisdiction. DossDev may deny or limit a request where permitted by law, including when information belongs to another person, cannot be verified, is protected by privilege, or must be retained.
Send a request to the Privacy Contact at support@dossdev.com. Describe the right you want to exercise and the BoxDex account involved. An authorized agent may submit a request where local law permits, subject to proof of authority.
Canadian users may contact the Office of the Privacy Commissioner of Canada or the applicable provincial privacy authority. Québec users may also contact the Commission d'accès à l'information du Québec. You are encouraged to contact DossDev first so there is an opportunity to address the concern.
Changes to this policy
DossDev may update this Privacy Policy to reflect changes to BoxDex, providers, law, or privacy practices. The “Last updated” date identifies the current version. If a change is material, DossDev will provide notice through the app, this page, email, or another appropriate channel as required by law. Where consent is legally required for a new use, DossDev will request it.
Contact the Privacy Contact
Privacy questions and requests
DossDev
Ontario, Canada
Privacy Contact: DossDev
Use the subject line “BoxDex Privacy” and do not email passwords, full identity documents, payment card details, or sensitive inventory photos. DossDev may request limited verification information through an appropriate channel.