Whery
Privacy Policy
1. Who controls your data
The data controller is Fulvio Scichilone. Privacy enquiries can be sent to fulappios@gmail.com.
Whery is designed as a local-first app. It does not create a Whery account and does not operate an advertising or profiling server. The only data that leaves your device to the developer is anonymous usage statistics and crash reports, described in section 3, which you can switch off at any time.
2. Data Whery handles
Depending on the features you choose, Whery handles:
- the names, notes, tags, symbols, colours, dates, relationships, reminder details, and other free-form content you save about things and places
- photos you take or select, together with on-device results such as detected text, labels, crops, visual feature prints, and generated descriptions
- temporary microphone audio while you dictate, and the resulting transcribed text
- camera frames, depth and motion information used for augmented-reality pins and room scans, including a serialized spatial map associated with a place
- local notification schedules and, only if you enable the option, reminder data written to Apple’s Reminders database through EventKit
- purchase and entitlement information supplied and verified by Apple through StoreKit
- anonymous usage events, performance and crash reports, only while that option is on: which features you use, aggregate counts, device capabilities, and technical stack traces — never the content you save (see section 3)
- technical information that is placed in a support email draft only when you choose Contact Support: app version and build, iOS version, device model, current language, iCloud sync status, and counts of things and places. The draft does not automatically include the names, notes, photos, scans, or other content in your collection.
Whery does not request or use precise or approximate geographic location. AR positioning is relative to camera and device sensors; it is not GPS or network location.
3. Where processing happens
Speech transcription, Vision and Natural Language analysis, Apple Intelligence and Foundation Models features, photo understanding, search, and AR processing run on the device using Apple frameworks. Whery does not send prompts, photos, audio, transcripts, embeddings, or model output to a developer AI service. Microphone audio is used while dictation is active and is not saved by Whery; the resulting text is saved only when you choose to keep it.
Some features keep small on-device copies of your content so the system can show it outside the app, still without sending it to third parties: the things you save can be added to the on-device Spotlight index, so they appear in system search and can be recognized in Siri and Shortcuts phrases; a compact snapshot of recent things is written as a small JSON file in the app’s shared container (App Group) so Whery widgets and controls can display it; and icons you generate for things or places with Image Playground are created on the device by Apple Intelligence. These copies follow your collection: deleting a thing removes it from the Spotlight index, the widget snapshot is replaced as your collection changes, and Delete all data clears the index.
Whery includes one third-party SDK, PostHog, used for anonymous usage analytics and crash reporting. It records which features are used (for example that an item was saved by voice, that a search returned results, or that a purchase was completed), aggregate counts (such as how many things and places you keep), device capabilities (iOS version, device model, whether Apple Intelligence or AR are available), crash reports with technical stack traces, and basic performance data such as launch times and errors. It never receives the content you save: names of things and places, notes, photos, searches, dictated phrases, tags, reminders, or any identifier of your items. Events are keyed by a random identifier generated on the device, not by your Apple Account, email, or advertising identifier, and are not used to track you across other apps or websites. Data is processed on PostHog servers in the European Union (PostHog EU Cloud, Frankfurt). You can switch this off at any time in Settings → Privacy → Share anonymous usage data; Delete all data also discards the random identifier. Whery has no advertising or tracking SDK.
Diagnostic messages written with Apple’s unified logging remain subject to the operating system’s controls and are not uploaded by Whery.
4. Local storage and private iCloud sync
Your main collection is stored with SwiftData on your device. When iCloud is available for Whery, SwiftData synchronizes that collection through the app’s private CloudKit database, so it can appear on your devices signed in to the same Apple Account. Apple operates iCloud and CloudKit under your Apple service settings and terms.
Room scans use a separate local store. If you turn on Sync room scans, the serialized room map is also stored in a dedicated zone in your private CloudKit database and synchronized across your devices. A room scan is not made public or sent to other Whery users, but it can leave your device for private iCloud sync and for exports you explicitly initiate.
Whery may use Apple’s iCloud key-value store to keep small app-state values consistent across your devices. The iPhone can also send a verified Premium entitlement snapshot to your paired Apple Watch through WatchConnectivity; it does not send StoreKit prices or payment data to the Watch.
5. Notifications and Reminders
Whery schedules notifications through the operating system when you ask for a reminder. If you explicitly enable the Reminders option and grant access, Whery creates or updates the corresponding item in Apple’s Reminders database through EventKit. Those system services may synchronize according to your Apple Account and device settings. Whery does not use reminder data for advertising or analytics.
6. Purchases
Premium purchases, eligibility, restoration, renewal status, and subscription management are handled by Apple through StoreKit and the App Store. Whery receives only the product and verified transaction or entitlement information needed to show products, complete or restore a purchase, unlock features, and reflect access on a paired Watch. Whery never receives your payment-card details. Apple’s own processing is governed by Apple’s privacy policy and App Store terms.
7. Sharing, export, and import
You can export your collection as CSV and share or import individual things as .whery packages. A .whery package may include the content and media you select, and may include room-scan data when that export flow explicitly provides it. Whery gives the package to the Apple share sheet or to the destination you choose. From that point, the selected recipient or service controls its copy. Review the destination before sharing, especially when a package describes a home or other private space.
Imported .whery files are validated and processed locally. Temporary inbox copies are removed on a best-effort basis after import or during later cleanup.
8. Support communications
Contact Support opens an email draft addressed to the support address configured in the app (currently fulappios@gmail.com). You see and can edit or delete the entire message and its diagnostics before sending. Nothing is sent until you affirmatively send it through your email provider.
If you send a support message, its contents, sender address, attachments, and visible diagnostics are used only to respond, troubleshoot, prevent abuse, and meet legal obligations. Support communications are retained for 12 months, unless a longer period is required by law or an active dispute, and are then deleted or anonymized.
9. Retention and deletion
Collection data remains on your devices, and in private iCloud when sync is available, until you delete it in Whery or iCloud, or use Delete all data. Uninstalling Whery removes only the copy stored locally by the app; it does not by itself delete data stored in private iCloud. Deletions can take time to propagate to other devices and Apple services. If private room-scan deletion cannot complete, Whery reports that the reset is incomplete and keeps the sync state needed for you to retry; it does not report success while that private CloudKit zone may still exist.
Delete all data also discards the random analytics identifier, so later events cannot be linked to earlier ones. Usage events already sent are retained by PostHog under its own retention settings.
Copies you exported or shared are not controlled by Whery and must be deleted from their destination separately. System notifications and Reminders entries are managed under the corresponding Apple settings and apps.
10. Disclosure, tracking, and security
Whery does not sell personal data, show ads, track you across apps or websites, share data with data brokers, or use your content for marketing. Data can be disclosed only at your direction, to Apple services necessary for the features you enable, or when legally required.
Whery uses Apple platform protections such as application sandboxing, private CloudKit databases, StoreKit verification, and optional device authentication. No system can be guaranteed perfectly secure; keep your devices and Apple Account protected.
11. Your choices and rights
You can decline optional permissions, turn off Share anonymous usage data in Settings → Privacy, keep room-scan sync off, edit or delete saved content, remove scans from iCloud, export your data, restore purchases, manage subscriptions in the App Store, and use Delete all data. You can also manage iCloud, camera, microphone, notifications, Reminders, and authentication permissions in system settings.
Depending on where you live, you may have rights to access, correct, erase, restrict, object to, or receive a portable copy of personal data, and to complain to a data-protection authority. Contact fulappios@gmail.com to exercise applicable rights regarding data controlled by Fulvio Scichilone. Apple controls requests concerning Apple-operated services.
12. Children and changes
Whery is not directed to children for the purpose of collecting personal data and does not knowingly operate an account or behavioural advertising service for children. A parent or guardian who has a concern should contact fulappios@gmail.com.
This notice may change when Whery’s features or legal requirements change. The effective date above will be updated, and material changes will be communicated as required.