Privacy Policy
Last updated: August 17, 2026
1. Overview
itmly (“we,” “our,” or “us”) is operated by Holy Schmitt Studios LLC. This Privacy Policy explains how we collect, use, and protect your information when you use itmly — the website at itmly.app and the itmly mobile app (together, the “Service”).
2. Information We Collect
Account information: When you sign up via Google OAuth through Clerk, we receive your name, email address, and profile picture. We do not receive or store your Google password.
Item data: Information you provide about your items, including names, descriptions, photos, values, categories, and any custom metadata fields. This is your content and you own it.
Images: Photos you upload are stored in a private Supabase Storage bucket and are reachable only through authenticated requests — unless you publish a collection, in which case the images on that collection become publicly viewable for as long as the share link is live. See Public Sharing below.
Usage data: We collect basic usage analytics to improve the Service, including page views, feature usage, and error logs. We do not use third-party advertising trackers.
Feedback you send us: If you use the suggestion box, we store your message along with the page you sent it from and your browser's user-agent string, so we can reproduce what you were looking at.
Camera and photo library (mobile): The mobile app asks for camera access to photograph items and scan barcodes, and for photo library access when you pick an existing picture. Both are used only when you choose the action, and neither is read in the background.
Session recordings: We record session replays so we can see how people move through the Service — where a flow breaks down, what gets clicked, where people give up. All text is masked before it leaves your browser, on every page: item names, values, notes, and anything you type are replaced with placeholder characters. What a recording shows us is the shape of the page and where you moved and clicked, not what it said. Session recordings are processed by PostHog (see Third-Party Services below).
3. How We Use Your Information
We use your information to:
- Provide and operate the Service
- Power smart features such as auto-fill, photo recognition, and URL extraction
- Store and serve your item data and images
- Send transactional emails related to your account
- Improve the Service and fix bugs
4. Intelligent Processing
When you use smart features (auto-fill, URL extraction, photo recognition), your input is sent to a third-party processing provider for analysis. This may include item names, descriptions, URLs, and images you choose to analyze. The provider's data retention and usage policies apply to this processing. We do not use your data to train machine learning models.
5. Third-Party Services
We use the following third-party services:
- Clerk — Authentication and user management
- Supabase — Database and file storage (hosted on AWS)
- Anthropic — Intelligent data processing
- Stripe — Payment processing and subscription billing
- eBay Browse API — Market value lookups
- Serper — Product image search
- Vercel — Application hosting and anonymous page-view analytics
- PostHog — Product analytics (pageviews, CTA clicks, signup and activation funnel, session replay). All text in recordings is masked, everywhere.
- Resend — Transactional and scheduled email: warranty reminders, the weekly digest, and inventory reports you ask us to email you. A report you email yourself contains the item details in it, including purchase prices.
- UPCitemdb and Open Food Facts — Barcode lookups. When you scan a barcode we send the number to these services to identify the product. We send the barcode and nothing else, and the request comes from our servers rather than your device.
When you click an outbound “buy” link on a publicly shared item page, you are redirected to a third-party marketplace (such as eBay, Amazon, Discogs, StockX, or similar). Those marketplaces are not operated by us and their own privacy policies apply once you leave itmly.
When a barcode lookup returns a product image, that image is displayed directly from the provider's own servers, so your browser contacts them to load it.
Each service has its own privacy policy and data handling practices. This list is complete as of the date at the top of this page; if we add a service that receives your data, we will add it here.
6. Public Sharing and Shared-Page Analytics
If you enable sharing on a collection, that collection and its items become publicly accessible via a unique URL. Publicly visible fields include: item names, images, categories, conditions, current values, brand and model, descriptions, and any custom metadata fields. Fields excluded from public view include: purchase prices, purchase dates, notes, locations, merchants, warranty details, and lend/borrow information.
Shared pages are indexable by search engines by default. You can revoke a share link at any time from the collection's Share dialog, which immediately removes public access. Copies already cached by browsers, search engines, or social platforms are outside our control and may persist for a while after that.
For shared collections, we collect basic analytics so you can see how your shares perform: view count, outbound link click count, and the domain of the referring site (e.g., “reddit.com”). We never store full referrer URLs. Visitor IP addresses are SHA-256 hashed before storage and are not associated with any user account.
7. Cookies and Local Storage
We use cookies and browser local storage for the following purposes:
- Authentication — cookies set by Clerk to keep you signed in
- Preferences — local storage to remember your selected currency, view mode, theme, and similar settings
- Analytics dedup — short-lived cookies (24 hours) on publicly shared pages to avoid double-counting views from the same visitor
- Product analytics — PostHog stores a
distinct_idin local storage to correlate pageviews and funnel events, and sets a session cookie when session replay is active. It is a random identifier while you are signed out; once you sign in it becomes your account id. These identifiers are not shared with advertisers, and are cleared when you sign out. - Gift reservations — if you reserve a gift on someone's shared registry without an account, we set a cookie for one year so the reservation stays yours and you can change it later.
- Referral attribution — two 30-day cookies recording which link or shared page brought you to itmly, so we can tell what is working.
We do not set third-party advertising cookies or cross-site tracking cookies.
8. Data Storage & Security
Your data is stored in a PostgreSQL database hosted by Supabase with row-level security enabled. Images are stored in private storage buckets and served through authenticated API endpoints. All data is transmitted over HTTPS.
9. Data Retention & Deletion
We retain your data for as long as your account is active. Deleted items are soft-deleted (moved to trash) and can be permanently deleted by you at any time.
Deleting your account removes your items, photographs, receipts, attachments, preferences and analytics profile, and cancels any paid subscription so you are not charged again. This happens straight away rather than on a schedule — we say “within 30 days” only as an outer bound for retries and backups.
Two things deliberately survive, and we would rather say so than write a promise we do not keep:
- Suggestions you sent us are kept, with your account id and email stripped off, so the note remains but is no longer linked to you. Product feedback is often the reason a feature exists, and losing it when someone leaves would cost us the reason.
- Email delivery records held by our email provider, and payment records held by Stripe, remain on their systems. Payment records in particular we are required to keep.
10. Your Rights
You have the right to:
- Access all data associated with your account
- Export your data at any time
- Delete your data and account
- Opt out of non-essential communications
11. Children
Our Terms of Service require you to be at least 16 to create an account. The Service is not intended for children, and we do not knowingly collect personal information from anyone under 13.
12. Changes
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the new policy on this page and updating the “Last updated” date.
13. Contact
Questions about this policy? Contact us at help@itmly.app.