Privacy Policy — Dentro
Data we collect
To use Dentro you need an account. You can sign in with Google, with Apple, or with email and password. During sign-in we receive:
- A unique account identifier (never your password: we never see it — it is verified by Firebase Authentication, which stores it encrypted)
- The name and email associated with the account, if you choose to share them.
If you sign in with Apple you may hide your address: in that case we receive a
@privaterelay.appleid.comforwarding address, not your real one
The content you create in the app — box names, categories, item descriptions, and the photos you take or select — is stored on Firebase (Google Cloud), a cloud service operated by Nicolò Ferloni, and is linked to the account you signed in with — much like documents on Google Drive are linked to the Google profile that created them. This is what lets you find the same boxes on any device, from the app or the website, by signing in with the same account. Signing in with a different account opens a separate, empty space; if you lose access to your Google/Apple account, we cannot reassign your data to a different account.
The only other data that leaves your device is what is needed for advertising to work:
- The device advertising identifier, shared with Google AdMob to display ads inside the app (a bottom banner and a full-screen ad on launch).
- Your IP address, sent to AdMob with each ad request. AdMob also uses it to estimate the device's approximate location (roughly the city) in order to show relevant ads. The app never requests or uses GPS and does not know your precise location.
- Diagnostic data about ad delivery (for example launch time, hangs, energy use), collected by Google's advertising component to verify that ads work correctly.
- App interactions related to ads (app opens, ad taps, views), used by AdMob for ad counting and measurement.
These four items are collected by Google's advertising component and shared with Google: they are not used by NiFe Studio and are not linked to your boxes or your account. They are described in Google AdMob's official documentation.
Object recognition with artificial intelligence
Dentro offers an optional feature that, from a photo of a box's contents, proposes a list of the items it recognises. The list is generated by an artificial intelligence system and is a suggestion to review and correct, not a certain result.
The feature is off by default and does not work unless you connect, from the app's settings, your own access to an artificial intelligence service, choosing between Google Gemini, OpenAI and Anthropic Claude. This means that:
- the access key stays on your device, held in the operating system's protected store (Keychain on iOS, Keystore on Android), and is never transmitted to NiFe Studio;
- when you request a recognition, the photo is sent directly from your device to the provider you chose, using your credentials and under the agreement between you and that provider. For this purpose the photo does not pass through NiFe Studio's servers;
- NiFe Studio neither receives nor stores the photos sent to the provider, nor the item lists returned: those are saved into the box only if and when you confirm them;
- depending on the plan you choose, the provider may use the content you send to improve its models, and its staff may review it. On free plans this is the rule, not the exception. That processing is governed by the provider's own privacy policy.
Before the first upload the app asks for explicit, separate consent, distinct from connecting the key, and explains that the photo will leave the device. Consent can be withdrawn at any time from the Account screen, as can the key connection; withdrawing it switches the feature off and items continue to be added by hand. If you connect no access at all, every other feature of Dentro works without restriction.
Legal basis: the data subject's consent (Art. 6(1)(a) GDPR). The providers' privacy policies are available here: Google, OpenAI, Anthropic.
Permissions we request
- Camera: used to photograph the boxes and items you choose to save, and to scan QR codes.
- Photo library: used only if you choose to select an existing image instead of taking a new one.
Where your data is stored
Data is stored on Firebase (Google Cloud) servers. Private boxes (the default) are accessible only by the account that created them: the database security rules prevent any user from seeing another user's private data.
You may choose to make a box public: in that case its contents (name, items, descriptions and photos) become visible to anyone who scans its QR code or opens its link, even without an account. The choice is reversible at any time from the box settings.
Shared boxes and change history
A public box can be made editable: in that case anyone who knows its code or scans its QR can add and remove items. Anyone opening a public box can also save it among their own: no copy is created, there is still only one box, so if the owner deletes it, it disappears for everyone who saved it as well.
Every addition, change or removal of an item is recorded in a history showing the date, the action, the item name and the account name of the person who performed it. This history is visible to the box owner and to the people who are allowed to edit the box. Only the name associated with the account is shown: email addresses are never shown to other users. A box's history is deleted together with the box, and the entries signed by an account are deleted when that account is deleted.
The owner of a box can at any time remove items added by others and block a person, withdrawing their permission to edit that box.
Optional communications ("news")
On first launch, the app asks whether you would like to occasionally receive Dentro news by email (new features, tips). Emails are sent only with your explicit consent, which is recorded with date and time. Consent can be withdrawn at any time by writing to nifestudio.app@gmail.com; withdrawal stops the emails. Your email address is not shared with third parties for marketing purposes.
Advertising
Dentro displays ads through Google AdMob: a banner at the bottom of the screen and a full-screen ad on launch. Users in the European Union are shown a personalized-ads consent form on first launch (Google's messaging platform); if they decline, non-personalized ads are shown instead. AdMob may use device identifiers to personalize ads, as described in Google's privacy policy. You can manage your advertising preferences in your phone's privacy settings (iOS: Settings → Privacy → Advertising; Android: Settings → Google → Ads).
Data retention and deletion
Your account and all linked data can be deleted from in the app itself, with no need to contact us: Home → profile icon top right → Account → Delete account. You are asked to confirm your sign-in, and then boxes, items, photos and profile are all removed; codes and QR labels already printed stop working. It is immediate and cannot be undone.
If you cannot sign in to the app, you can instead write to nifestudio.app@gmail.com and we will comply within 30 days. Full instructions, with the exact list of what gets deleted, are on the Delete your account page.
Your rights
You may at any time request access to, correction of, or deletion of your data by writing to nifestudio.app@gmail.com.
Contact
For any questions about this policy: nifestudio.app@gmail.com.