Privacy Policy
Effective August 4, 2026
This Privacy Policy explains how WHER (“WHER,” “we,” “us,” or “our”) handles information when you use our website, mobile applications, web application, labels, and related services (collectively, the “Services”).
Information we collect
Depending on how you use WHER, we may collect:
- Account information, such as your name, email address, authentication provider identifiers, and profile details.
- Inventory and workspace content, including item names, descriptions, photos, documents, labels, storage locations, voice or text queries, and content you choose to share.
- Device and usage information, such as device type, operating system, browser, IP address, app interactions, diagnostics, crash data, and approximate location derived from your IP address.
- Camera, microphone, NFC, and sensor information only when you enable a feature that needs it and grant permission. These inputs may be used to capture items, scan labels, support voice features, or provide spatial features.
- Transaction information. Payment providers process payment card details; we may receive purchase status, product, amount, and billing identifiers.
- Communications you send to us, including support requests and feedback.
How we use information
We use information to provide, secure, maintain, and improve the Services; authenticate users; organize and search the content you store; process transactions; provide customer support; communicate service updates; detect fraud or abuse; comply with law; and develop new features. Where AI-powered features are used, relevant prompts and content may be processed to return the requested result.
How we share information
We do not sell your personal information. We may share information with service providers that help us operate WHER, such as cloud hosting, authentication, analytics, AI processing, communications, crash reporting, and payment providers. We may also share information when you direct us to, with members of a workspace you join, during a business transaction, or when required to protect rights, safety, and legal compliance.
Optional AI features and OpenAI
WHER asks for explicit consent before an optional AI feature sends content to OpenAI. Depending on the feature you choose, that content can include selected photos or image crops, prompts or chat messages, inventory names and metadata needed to answer your request, or audio from a Realtime Voice session. OpenAI processes the selected content to identify belongings, generate requested text or images, create search embeddings, synthesize speech, or provide the voice interaction you requested.
OpenAI states that data sent through its API is not used to train or improve its models unless the API customer explicitly opts in. Under OpenAI's default API controls, abuse-monitoring logs may contain prompts, responses, images, audio, or derived metadata and are generally retained for up to 30 days, unless longer retention is required by law or reasonably necessary to protect OpenAI's services or others from harm. Endpoint-specific exceptions and approved reduced-retention controls may apply. See OpenAI's API data-controls documentation.
You can decline AI data sharing and continue using non-AI inventory features. You can also withdraw consent at any time in Settings > Privacy > AI data sharing. Withdrawal stops new OpenAI transmissions from WHER but does not retroactively remove content from provider logs that remain within an applicable retention or legal period.
Storage, security, and retention
We use administrative, technical, and organizational safeguards designed to protect information. No system is completely secure. We retain information for as long as needed to provide the Services, meet legal obligations, resolve disputes, and enforce agreements. Retention periods vary by the type of information and why it is processed.
Privacy-minimized product analytics events are generally retained for up to 13 months. Aggregated funnel and campaign measurements may be retained for up to 25 months so we can compare performance over time. Analytics payloads are designed to exclude inventory names, search text, prompts, photos, email addresses, precise locations, and payment identifiers.
Your choices and rights
You can turn off product analytics from WHER's Settings > Privacy controls. You can also manage device permissions in your operating system and update certain account or inventory information in WHER. You may request access, correction, deletion, or a copy of personal information, subject to applicable law and legitimate retention requirements. Residents of some jurisdictions may have additional rights, including the right to object to or restrict certain processing and to appeal a denied request.
Account and data deletion
You can permanently delete your account in the WHER app under Settings > Profile & security > Delete account. WHER requires a recent sign-in and an exact confirmation before deletion. If other active members still depend on your personal household workspace, you must transfer or remove those members first so their shared data is not destroyed. You may also email support@wher.ai from the address connected to your account for assistance.
You may also request deletion of specific content without deleting your account by identifying the inventory records, photos, documents, workspace content, or other data you want removed. WHER also provides in-app controls for deleting supported inventory content.
After verification, WHER deletes private inventory, photos and files, chat history, preferences, notification registrations, access tokens, and authentication credentials. WHER releases or deletes claimed label mappings and removes the account from other workspaces. Payment, tax, order, subscription, fraud-prevention, consent, and immutable audit records may be retained where required or reasonably necessary, but direct account identifiers and contact or delivery fields are replaced or removed according to the deletion policy. Open orders may remain in anonymized records for fulfillment or returns.
Deleting a WHER account does not automatically cancel a subscription billed by Apple, Google Play, Stripe, or another payment platform. Cancel the subscription through the platform used to purchase it to stop future renewals.
Children
The Services are not directed to children under 13, or the minimum age required by local law. We do not knowingly collect personal information from children below that age.
International processing
Information may be processed in countries other than where you live. Those countries may have different data-protection laws. Where required, we use appropriate safeguards for international transfers.
Changes to this policy
We may update this policy as WHER evolves. We will post the revised policy here and update the effective date. If changes are material, we may provide additional notice through the Services.
Contact us
For privacy questions or requests, email support@wher.ai.