1. Scope and who we are
This Privacy Policy applies to the Rattib mobile application, the Rattib Cloud service, rattib.com, and related support communications (together, the “Service”).
Rattib is responsible for the personal information it processes for its own purposes. In data-protection terms, Rattib acts as the controller of account and service data. A Cloud space Owner also decides which people receive access to the inventory they share.
Plain-language summary: Rattib requires Sign in with Apple or Google and stores inventory in Cloud so synchronization and sharing can work. A protected device snapshot can keep previously synchronized metadata visible while Rattib reconnects, but Cloud remains authoritative.
2. Cloud inventory and the saved device copy
Cloud inventory
Inventory is transmitted to and stored by Rattib so the Service can synchronize records automatically, recover content, and enable account-based sharing. Cloud records are associated with your account and may be visible to Owners and Guests who receive access.
Encrypted saved metadata
After a successful synchronization, Rattib may save an encrypted read-only snapshot of inventory metadata on the device so records can appear faster after restart and remain visible during a temporary outage. The snapshot does not include inventory photo bytes, is not a separate inventory, and cannot accept offline changes.
The snapshot is bound to the refresh session, account environment, API endpoint, contract, and server generation. It is rejected and removed when those checks fail and is cleared when you sign out or delete the account. Device operating-system backups are handled under your agreement with the platform and your settings.
3. Information we collect
| Category | Examples | When collected |
|---|---|---|
| Account and profile | Provider-verified email address, display name, username, optional phone, role, base location, account status, and Apple or Google sign-in identifiers | When you create, link, or update a Cloud account |
| Inventory content | Storage-space names, unique space identifiers, display labels, statuses, locations, notes, categories, item names, descriptions, quantities, tags, estimated values, conditions, retrieval state, and movement history | When you create or synchronize Cloud inventory |
| Photos and files | Storage-space and item photos, filenames, file type, dimensions, size, and integrity checksum | When you choose to upload a photo to Cloud inventory |
| Sharing and collaboration | Invited username, membership, Owner or Guest permission, invitation status, QR share request, Owner decisions, and shared activity | When Cloud sharing is used |
| Device and synchronization | Device identifier and name, platform, app version, last-seen and sync times, change status, saved-snapshot binding metadata, and notification registration information when enabled | When a device connects to Cloud services or saves a last-synced view |
| Authentication and consent | Session and security records, linked Apple or Google identity, policy versions accepted, minimum-age confirmation, app build, and acceptance time | When you sign in, maintain a session, or accept legal terms |
| Service and security records | Timestamps, service status, network address, temporary operation records, and error information | When the Service receives or protects a request |
| Communications | Email address, message content, and information you choose to provide | When you contact Support or receive a service email |
Apple or Google may provide a verified email address for account purposes. Rattib stores that address with the Cloud account where provided, but sharing invitations use the Rattib username—not the email address.
Camera, photos, and QR scanning
Rattib asks for camera or photo-library access only through device permissions and only when a related feature is used. We do not receive your full photo library. Photos you select for Cloud inventory are uploaded to the Cloud service.
QR scanning uses the camera to read a space’s unique identity. The identity may be sent to the Cloud service to locate the exact record, check authorization, or create a share request for an Owner. Display labels such as SPACE_001 are not unique sharing identities. A QR label never replaces account permission.
Information we do not use for advertising
Rattib does not sell personal information, run third-party advertising, or use personal inventory content for cross-context behavioral advertising. We do not collect payment-card details, precise GPS location, contacts, health data, or the contents of your full photo library through the current Service.
4. How we use information
We use information to:
- create and operate Cloud accounts, sessions, and profiles;
- store, automatically synchronize, search, display, move, retrieve, and restore Cloud inventory;
- process photos, create thumbnails, maintain QR identities, and deliver requested files;
- send, accept, decline, and administer username invitations, QR share requests, and Owner or Guest permissions;
- show activity and synchronization state;
- authenticate users through Apple or Google and revoke provider access after account deletion;
- respond to support, privacy, deletion, security, and legal communications;
- protect accounts and data, limit abuse, diagnose failures, maintain integrity, and recover the Service;
- comply with law, enforce our Terms, and establish or defend legal claims; and
- improve reliability and usability using operational information that does not require us to inspect personal inventory for advertising.
We do not use inventory names, search terms, photos, notes, values, or support-message content for advertising profiles.
5. Legal bases for processing
Where applicable law requires a legal basis, we rely on:
- Contract: processing necessary to provide the Cloud account, synchronization, sharing, support, and other requested features.
- Legitimate interests: securing the Service, preventing abuse, maintaining reliability, improving performance, and protecting users, provided those interests are not overridden by your rights.
- Consent: device permissions, optional information, and processing where consent is required. You can withdraw consent through device settings or the relevant in-app control, without affecting earlier lawful processing.
- Legal obligation: records and actions required to comply with applicable law or valid legal process.
- Protection of rights: processing necessary to establish, exercise, or defend legal claims and protect people or the Service.
7. Retention and deletion
We keep personal information only for as long as reasonably necessary for the purposes described in this Policy, including providing the Service, protecting it, meeting legal obligations, and resolving disputes.
| Information | Typical retention |
|---|---|
| Active Cloud account and inventory | While the account remains active, until you delete the relevant data, or as otherwise required for the Service |
| Session and device records | While needed to maintain or secure the session; revoked or removed when no longer needed or when the account is deleted |
| Encrypted saved device snapshot | Until replaced by a newer valid snapshot, invalidated by a safety check, or cleared at sign-out or account deletion |
| Temporary upload records | Approximately 24 hours |
| Temporary deletion-status records | Up to approximately 48 hours so the app can confirm completion |
| Synchronization reliability records | Up to approximately 180 days for reliable retry and conflict handling; removed for an account-deletion request |
| Changed or deleted username reservation | Up to approximately 90 days to reduce confusion or impersonation |
| Encrypted backups | Rotating 7 daily, 4 weekly, and 3 monthly snapshots; residual deleted data may remain for up to approximately three months |
| Security and legal records | As reasonably necessary for security, compliance, dispute resolution, or legal claims |
Backups are isolated from ordinary access and used for disaster recovery. When recovery requires restoring an older snapshot, subsequent deletion state is reapplied where technically feasible before normal service resumes.
The app provides Delete all Cloud data and Delete account and all data. Sign-out and account deletion clear the encrypted saved device snapshot and independently attempt to remove its encryption key. See Account & Data Deletion for the steps and impact.
8. Security
Rattib uses administrative, technical, and physical safeguards designed for the nature of the Service. These include HTTPS connections, scoped authorization checks, time-limited sessions, protected provider credentials, controlled file access, encrypted device snapshots, abuse prevention, encrypted backups, integrity checks, and deletion and recovery procedures.
No method of storage or transmission is completely secure. You are responsible for protecting your device, Apple or Google sign-in method, printed QR labels, and the people and permissions you choose for sharing. Learn more on our Security page.
9. Your privacy rights and choices
Depending on where you live, you may have the right to:
- know whether and how we process personal information;
- access or receive a portable copy of eligible information;
- correct inaccurate information;
- delete information or your account;
- restrict or object to certain processing;
- withdraw consent where processing relies on consent;
- appeal or complain to a competent data-protection authority; and
- receive equal service without unlawful discrimination for exercising privacy rights.
Many choices are available directly in Profile, including profile editing, session controls, Delete all Cloud data, and Delete account and all data. Cloud synchronization is automatic. Device Settings controls camera, photo-library, and notification permissions.
To submit another request, email support@rattib.com. Describe the request and use the provider-verified email connected to your account when possible. We may verify your identity and authority before disclosing or deleting information. An authorized agent may submit a request where permitted by law, subject to proof of authorization.
California and similar U.S. state rights
Rattib does not sell personal information and does not share it for cross-context behavioral advertising. We do not use sensitive personal information to infer characteristics about you. If these practices change, this Policy and required choice mechanisms will be updated before the new use begins.
EEA, United Kingdom, and Switzerland
You may contact the competent supervisory authority in your country. You may also object to processing based on legitimate interests and request restriction or portability where the applicable conditions are met.
United Arab Emirates
Applicable rights may include access, correction, restriction or cessation of processing, and controls relating to cross-border transfer under the UAE Personal Data Protection Law.
10. International data transfers
Rattib and its providers may process information in countries other than where you live. Those countries may have different data-protection laws. Where required, we use an approved transfer mechanism or another lawful safeguard and limit providers to information needed for their service.
11. Children
Rattib is a general-audience organization service and is not directed to children under 13. A person must be at least 13, and at least the minimum digital-consent age required in their country, to create a Cloud account without a parent or legal guardian where parental consent is legally permitted.
We do not knowingly collect Cloud account information from a child under 13. If you believe a child has provided personal information contrary to this section, contact support@rattib.com so we can investigate and take appropriate action.
12. Website privacy
The public Rattib website does not currently use advertising trackers, analytics cookies, account cookies, or contact forms. Standard web requests necessarily transmit technical information such as an IP address, requested page, browser details, and time to the hosting system for delivery and security.
If analytics, forms, or non-essential cookies are introduced, this Policy and any required consent controls will be updated before use.
13. Changes to this Policy
We may update this Policy as the Service, providers, or law changes. The version and effective date appear at the top. If a change materially affects how existing personal information is used, we will provide notice appropriate to the change and obtain renewed consent where required.
14. Contact
For privacy questions, rights requests, deletion assistance, or complaints, contact:
Rattib Support
support@rattib.com
https://rattib.com/privacy/
Use a clear subject such as “Privacy or data request” and include the provider-verified email connected to your Cloud account when possible. For general product help, visit Rattib Support.
