Skip to content

Privacy

How Wheredai handles your information. Wheredai is made by Zinnia Development LLC; the company privacy policy applies to Wheredai, and this page adds the details specific to it.

Version 1.4 · Effective September 29, 2026 · Zinnia Development LLC · Read the full privacy policy on zinnia.dev

In short

Wheredai is in development. This page covers whered.ai and the early-access list today and describes the app as it is designed. It is updated before the first public release, and the version history at the end records each change.

1. Who we are and what this covers

Wheredai is an app published by Zinnia Development LLC (“Zinnia”, “we”, “us”), a limited liability company in the State of New Jersey, United States. Zinnia is the controller of the personal information described here. This page applies to:

  • This website, whered.ai, including the early-access list.
  • Guest pages at go.whered.ai, which hosts open to their guests with a QR code or link.
  • The Wheredai app on iOS, Android and the web, once released.

Everything in the company privacy policy (version 1.0, effective September 8, 2026) applies to Wheredai, including the notices for California, other US states, the EEA, the UK and Switzerland, unless this page says otherwise.

2. What we collect

On this website, today

  • Early-access sign-up. Your email address, which page you signed up from, and the source tag in the link you followed (which of our posts brought you here). We store the address with our email delivery provider and record one analytics event that carries a one-way hash of the address, never the address itself.
  • Messages to us. Whatever you write when you email us.
  • Server logs. The IP address, requested page and time of each request, kept by our hosting provider for security.

On guest pages

The guest link or QR-code token you arrive with and, when the guest surface launches, the questions you ask. Answers come only from what the host chose to share. Guest pages load no analytics, no error reporting and no third-party scripts.

In the app, as designed

  • Account. Your email address, a display name and a one-time sign-in code, or the name and email that Apple or Google share when you sign in with them (a private relay address is fine). We do not use passwords.
  • Content you add. Places, spaces, containers and items; facts, documents, contacts and events; notes, how-to text, labels and photos; the people you invite and the audience you choose for each thing; and the observations that record who last saw something where, and when.
  • Voice, photos and video. Audio while you speak to the app, the photos you take or upload, and the frames of a shelf or room you film. Section 5 explains how they are processed and how long they exist.
  • Purchases. When you buy a subscription, Apple, Google or Stripe processes the payment and tells us the product, price, currency, date, status and a transaction identifier. We never receive your full card number.
  • Device, usage and diagnostics. Device model, operating system, app version, language and time zone; which features you use and whether they succeeded, collected without cookies or advertising identifiers; crash reports with account content redacted where technically possible.
  • Assistant connections. If you connect an AI assistant (section 6), we keep a record of the connection: which assistant it is, when you connected it, and whether it can only read or can also make changes. Each change an assistant makes is recorded with the connection that made it, so you can see it and undo it within an hour. If you create a personal access token, we store only a one-way hash of it and its last four characters; the token itself is shown to you once.

We do not collect precise location in the background, biometric identifiers, health data or government identification numbers. A place address is stored only if you type it in, and only the people you share that place with can see it. We do not buy data about you.

3. Device permissions the app asks for

Each permission is requested only when you use a feature that needs it, is optional, and can be turned off later in your device settings; the rest of the app keeps working.

PermissionWhy we askWhat we do with it
CameraPhotograph an item, scan a label or QR code, film a shelf or roomImages are stored with the record you create and, if you use recognition features, analysed as in section 5. Location metadata is removed first.
MicrophoneSay where something is, ask a question by voiceAudio is streamed for transcription and discarded; only the transcript is kept, attached to the record it produced.
Photo libraryAttach an existing photoOnly the photos you select are uploaded. We do not scan your library.
NotificationsInvitations and the digests you turn onWe store the push token Apple or Google issues for your device.

4. How we use information

  • To provide Wheredai: create and secure your account, store and sync your content, answer your questions, share a place with the people you invite, process purchases.
  • To respond to you: support, privacy requests and complaints.
  • To keep the service secure and reliable: detect abuse, rate-limit requests, debug crashes, make backups.
  • To improve the product, using aggregate feature usage, never the content of your places.
  • To send service messages: sign-in codes, invitations, the digests you turn on, receipts, security alerts and changes to these documents.
  • To tell you when Wheredai launches, if you joined the early-access list. That list receives launch and testing invitations only; there is no newsletter.
  • To comply with law and defend legal claims.

The legal bases for each purpose are the ones in section 4 of the company policy. We do not use personal information for targeted advertising, build marketing profiles, or make automated decisions with legal or similarly significant effects.

5. AI features and your data

  • Your content is never used to train models. Not by us, and not by the AI providers we use: we send your content to an AI provider only after its terms, or its settings for our account, rule out training on it. How long each provider keeps what it receives is in section 6.
  • Audio is ephemeral. Voice is streamed for transcription and discarded from our servers once the transcript exists. Recordings made offline are encrypted on your device and deleted after they are uploaded and transcribed.
  • Images are minimised. Location and camera metadata is stripped before a photo is stored or analysed.
  • Secret facts stay out of models. A value you mark as secret (a lock code, a Wi-Fi password) is encrypted separately, never sent to a model, never indexed for search, and never copied to the offline database on your devices.
  • Answers can be wrong. Wheredai infers where something probably is and shows how confident it is. Verify anything that matters.

6. Who we share it with

  • People you share with. Members of a place see what its visibility settings allow. Anything you mark “Only me” is hidden from everyone else, including the place owner. Guests see exactly what you chose to share with guests.
  • Assistants you connect. When you connect an AI assistant such as Claude or ChatGPT, it can look up what you can see in your places and, if you allowed changes, add and update items for you. It never receives a value you mark secret. What it receives is then handled by that assistant’s provider under the provider’s own terms and privacy policy, not ours. We email you each time a new assistant is connected, and you can disconnect it, or revoke a token, at any time in Settings; access ends at once.
  • AI providers. Today one AI provider receives your content: Cohere (Canada; data may be processed in Canada, the United States and other countries). It turns the text of your items and your searches into numbers that let search find things by meaning. It receives names, aliases, tags, notes and similar descriptive text, and never a value you mark secret. Cohere doesn’t train on it, and deletes what it logs within 30 days unless the law requires longer or its abuse checks flag the request. If that changes, this page will say so. Any other AI provider, for example for speech, photos or questions, is named here before it receives your content.
  • Service providers, under written contracts that limit them to our instructions. For this website today: Vercel (hosting, United States), Amazon Web Services (DNS and application hosting, United States), Resend (email delivery and the early-access list, United States), PostHog (cookieless product analytics, United States) and Sentry (error monitoring, United States). For the app, as designed: Apple and Google (sign-in, distribution and payments), Stripe and RevenueCat (web payments and subscription status), and PowerSync (sync between your devices).
  • When the law requires, or to protect the rights and safety of you, us or others. We tell you about a request for your data unless we are legally prevented from doing so.
  • In a business transfer, with notice before a different policy would apply, and with your consent for anything else.

We do not sell personal information, share it for cross-context behavioural advertising, or disclose it to data brokers.

7. How long we keep it

InformationRetention
Early-access email addressUntil we invite you or you ask us to remove it, whichever comes first.
Account and content you createFor as long as your account exists, then deleted within 30 days of account deletion. Items you move to Trash are purged 30 days after you trash them.
Assistant connectionsWhile they are connected. Disconnecting an assistant ends its access at once and deletes its tokens. Revoking a personal access token ends its access at once. A token’s record (its name, its last four characters, its one-way hash and its dates) is kept after it is revoked or expires, until you delete your account. The record of which connection made a change stays with that change in your history.
Voice audioDiscarded from our servers immediately after transcription.
Photos and video framesFor as long as the record they belong to exists; copies made for analysis are deleted when processing completes.
“Only me” content you leave behind when you leave a shared placeAvailable for you to export for 14 days, then purged.
Raw usage events90 days, then only aggregates.
Crash reports and error logs90 days.
BackupsEncrypted backups rotate within 90 days; deleted data leaves them on that schedule.
Purchase and subscription records7 years, as required for tax and accounting.
Support and privacy-request correspondence3 years.

8. Your rights and choices

Wherever you live, you can:

  • Access and export your information and content in a portable format, from inside the app or by asking us. An export contains what you can see; content other members hid from you is not in it.
  • Correct inaccurate information in the app or by asking us.
  • Delete your account and data (section 9).
  • Object to or restrict processing based on legitimate interests, and withdraw consent at any time.
  • Turn off usage analytics in the app’s settings.
  • Complain to us, and to your data protection authority or attorney general.

To exercise a right, use the controls in the app or email contact@zinnia.dev with the subject “Privacy request” and the word Wheredai. We verify requests, usually by sending a code to the address on the account. We confirm receipt within 5 to 7 business days and respond within 30 days. The company policy sets out verification, agents, appeals and the regional notices; they apply to Wheredai unchanged.

9. Deleting your account and exporting your data

From the app’s first public release, open Settings, then Account, then Delete account. Wheredai offers an export first. You can also email contact@zinnia.dev from the address on the account with the subject “Delete my Wheredai account”; you do not need the app installed to ask. Step-by-step instructions are on the support page.

Deletion removes your account, profile, the content you own, device tokens and analytics identifiers within 30 days, and from backups within 90 days. Content you added to a place owned by someone else stays visible to that place’s members unless you delete it before you leave; “Only me” content is purged after a 14-day export window. We keep only what section 7 says we must. Deleting the app from your device does not delete your account, and does not cancel a subscription bought through a store.

10. Children

Wheredai is not directed to children under 13, and we do not knowingly collect personal information from them. In the European Economic Area and the United Kingdom the minimum age to create an account is 16. A parent or guardian may add a child’s belongings to their own account; that information belongs to the parent’s account. If you believe a child has given us personal information, contact us and we will delete it promptly.

11. Changes and version history

We update this page as the app, its providers or the law change, with a new version number and effective date here. For material changes that reduce your rights or expand how we use data already collected, we notify you by email or in the app at least 30 days before they take effect.

  • Version 1.4, September 29, 2026. Updates section 6’s list of providers.
  • Version 1.3, September 29, 2026. Updates section 5, AI features and your data.
  • Version 1.2, September 26, 2026. Names the AI provider that receives your content today (Cohere, for search), what it receives and how long it keeps it, and states the no-training rule precisely (sections 5 and 6).
  • Version 1.1, September 25, 2026. Adds assistant connections: what an assistant you connect can see and do, what we record, and how to disconnect it (the summary and sections 2, 6 and 7).
  • Version 1.0, September 10, 2026. First published version, covering whered.ai, the early-access list and the app as designed before its first public release.

12. Contact

Questions, requests and complaints about this page go to: