Privacy Policy
Last updated 17 August 2026. Describes Intendant 1.6.0 for Android and iOS.
Overview
Intendant is local-first: your inventory lives in a database on your device, and nothing leaves it until you switch on a feature that needs the network. This policy lists every case where data does leave your device, and what we never collect at all.
Data stored on your device
Item names, notes, categories, storage locations, attached photos, and the search index are stored locally in the app database. If you enable neither cloud sync nor cloud AI, none of it is ever transmitted anywhere.
Optional cloud sync
Cloud sync is off by default and requires signing in with Google or Apple. Once enabled, the app uploads your items and locations, the photos you attach, and a compressed snapshot of the whole app database to our sync server (sync.compoza.net) over HTTPS, so you can restore after a reinstall or use a second device. Every change also carries a random identifier the app generates for the device; it distinguishes your devices from each other and is neither an advertising nor a hardware identifier. Signing in means Google or Apple, and Firebase Authentication, receive your email address and display name in order to authenticate you.
Sharing a place with someone
Once sync is on, you can share a storage location by handing out an invite code or QR. Whoever accepts it gets editor access to that location and everything inside it, so the items, locations, and photos in that subtree become readable and writable by them. Sharing is never public — nobody can find your data without a code you gave them — and you can revoke a share at any time.
Optional cloud AI
Cloud AI is off by default. If you switch it on, you supply the address of an OpenAI-compatible endpoint and your own API key, and the app sends the text you type or dictate when adding an item directly to that endpoint. We neither operate nor proxy it: the request goes from your device to the provider you chose — OpenAI, OpenRouter, or a server you run yourself — and that provider's own privacy terms govern what happens to the text. Your API key is kept in the device keystore (Android Keystore / iOS Keychain) rather than in ordinary app settings. Your photos and the contents of your database are never sent to a cloud AI provider. To be explicit: once you have consented to send text to a third-party cloud service, that data is outside our control. We do not process, store, or have access to it, we cannot delete it on your behalf, and we accept no responsibility or liability for how that provider handles, retains, discloses, or uses it — including for training its models. Your relationship there is governed solely by that provider's own terms and privacy policy, which you should read before enabling the feature; you can switch cloud AI off at any time, which stops any further transmission.
On-device AI and voice
Speech recognition, semantic search, text recognition, and the local language model all run on your device. Microphone audio is transcribed locally and never uploaded — where the system speech recognizer is used, the app explicitly demands on-device recognition. Be aware that with cloud AI enabled, the text produced by a dictation then follows the same path as typed text, described above.
Model downloads
The app contacts our model repository (repo.compoza.net) at launch to check the item category list, and downloads AI model packs from it when you choose to install them. These are ordinary HTTPS requests carrying no account, device, or usage information; as with any web request, our server sees the originating IP address. We collect no download analytics.
What we never collect
The app contains no analytics, crash reporting, advertising, or attribution SDK. We do not collect your device location, contacts, calendar, messages, or browsing history, we ask for no financial or health information, and we neither read nor generate an advertising identifier.
No sale of personal data
We do not sell your personal information, and we do not use your inventory contents for advertising or to train AI models.
Permissions
Camera, microphone, Bluetooth, and NFC permissions are requested only when you use the feature that needs them — barcode scanning, voice input, label printing, and tag reading respectively. Bluetooth scanning is declared as not being used to derive your location.
Deleting your data
You can erase everything cloud sync holds for you from inside the app: Settings → Cloud sync → "Delete all cloud data". See Delete your data for the full procedure and for what deletion does and does not cover.
Contact
Privacy questions: [email protected]