Zero-Knowledge Vault Architecture
At Ownly Technologies Inc. ("Ownly", "we", "us"), we engineer our products with an uncompromising security-first philosophy: Privacy by Design and by Default.
Unlike legacy inventory or spreadsheet tools, Ownly utilizes Zero-Knowledge Client-Side Encryption:
AES-256-GCM Encryption
Your asset records, serial codes, invoice PDFs, and photos are encrypted directly on your device before synchronization.
Zero Platform Access
Our backend servers store encrypted blobs. Our engineers, automated services, and third-party hosts have zero means to view your unencrypted vault.
Client-Held Cryptographic Keys
Your master encryption keys are derived on-device and protected by hardware hardware keystores (iOS Secure Enclave / Android KeyStore).
Information We Collect & Process
To deliver our digital custody and warranty tracking services, we collect limited categories of data:
- Identity & Account Credentials: Email address, hashed authentication credentials (managed via Firebase Auth), creation timestamp, and account status.
- Encrypted Vault Records: Encrypted payloads containing asset names, purchase dates, warranty expiration dates, replacement values, serial numbers, and uploaded image documents.
- Subscription & Purchase Tokens: Receipt validation tokens provided by Apple StoreKit or Google Play Billing to confirm your active Pro Vault entitlement. (We never handle raw credit cards or bank accounts).
- Technical Diagnostics: Anonymized crash logs, operating system build (iOS/Android), and app release version (e.g., v2.4.0) to identify stability regressions.
Data We Strictly Never Collect or Sell
Ownly was deliberately designed without advertising SDKs or data broker integrations. We believe your high-value belongings and home security assets should never be monetized.
We specifically pledge that Ownly does NOT collect, monitor, or trade:
- Advertising Identifiers: We do not track Apple IDFA, Google AAID, or commercial marketing trackers.
- Physical Location or GPS: We do not request or track precise or coarse GPS coordinates.
- Unencrypted Receipt OCR Data: OCR processing on receipts is performed on-device or within ephemeral, memory-only sandboxes without persistent logging.
- Third-Party Commercial Sale: We never sell, rent, or lease user records to insurers, marketing aggregators, or credit bureaus.
Device Locale & Currency Autodetection
Ownly inspects your device's native system locale configuration (e.g., en_US, de_DE, en_GB, ja_JP, en_IN) strictly for the purpose of:
- Default Valuation Currency: Displaying appropriate currency symbols (e.g., $, €, £, ¥, ₹) on your asset valuation dashboards without requiring manual setup.
- Date Formatting: Formatting purchase dates and warranty expiration reminders according to your regional calendar standards.
This process occurs entirely locally on your client device. Your geographic location is never tracked or triangulated. You may override your preferred vault currency at any time in Settings > App Preferences > Default Currency.
Biometric Authentication & Hardware Isolation
When you enable Face ID, Touch ID, or Android Biometric Authentication in Ownly:
- The authentication challenge is processed exclusively by your device operating system via Apple's LocalAuthentication framework or Android's BiometricPrompt API.
- Ownly only receives a cryptographic boolean confirmation (success or failure) and an unlock token from the hardware enclave.
- At no point does Ownly have access to your facial scan, fingerprint template, or biometric markers.
Purposes & GDPR Legal Bases for Processing
Under the European Union General Data Protection Regulation (GDPR Article 6), we process your data under the following lawful bases:
| Processing Purpose | Data Categories | Lawful Basis (GDPR Art. 6) |
|---|---|---|
| Account Creation & Vault Sync | Email, Hashed Auth Credentials, Encrypted Records | Performance of Contract (Art. 6(1)(b)) |
| Warranty Expiration & Push Radar | Device FCM Token, Encrypted Reminder Dates | Performance of Contract (Art. 6(1)(b)) |
| Pro Vault Subscription Management | App Store / Play Store Transaction Token | Performance of Contract & Legal Obligation (Art. 6(1)(b), (c)) |
| Crash Diagnostics & App Hardening | De-identified OS Crash Traces | Legitimate Interests (Art. 6(1)(f)) |
Third-Party Infrastructure & Subprocessors
We work exclusively with SOC-2 and ISO-27001 certified cloud infrastructure partners bound by strict Data Processing Agreements (DPAs):
- Google Cloud Platform / Firebase: Secure authentication tokens, cloud datastore for encrypted records, and encrypted document storage (AES-256 at rest).
- Apple App Store & Google Play Billing: In-app purchase verification and transaction lifecycle management.
- Firebase Cloud Messaging (FCM) & APNs: End-to-end encrypted notification dispatch for critical warranty expiration reminders.
Your GDPR Rights (European Union & United Kingdom)
If you are an individual residing in the European Economic Area (EEA), Switzerland, or the United Kingdom, you hold fundamental rights under GDPR:
- Article 15 (Right of Access): You have the right to request a complete record of personal data processed by Ownly.
- Article 16 (Right to Rectification): You can modify your email and profile credentials at any time in the app settings.
- Article 17 (Right to Erasure / "Right to be Forgotten"): You have the right to obtain the immediate, permanent deletion of your account and encrypted vault (see Section 09).
- Article 18 (Right to Restriction): You may restrict the processing of your data under statutory conditions.
- Article 20 (Right to Data Portability): You can export your full asset inventory, photos, and valuation breakdown anytime via
Settings > Data Management > Export Vault Archive (JSON / CSV / PDF). - Article 21 (Right to Object): You may object to any processing based on legitimate interests.
Article 17 "Request Account Deletion" Portal
When an account deletion is initiated, your encrypted vault database, cloud file storage, invoice attachments, and authentication credentials will be permanently destroyed. This operation cannot be reversed.
Method A: In-App Self-Service Deletion (Instant)
- Open the Ownly application on your mobile device.
- Tap on Settings in the navigation bar.
- Scroll to the Privacy & Data Security section.
- Tap on the red line item labeled "Request Account Deletion".
- Review the warning dialog, confirm your identity via biometric or password challenge, and confirm deletion.
Method B: Web / Email Erasure Request
If you have uninstalled the app or lost your device, you can trigger an Article 17 erasure request directly using the automated form below or by emailing our Data Protection Officer:
Data Retention & Automated Purge Timelines
We retain data only as long as necessary to fulfill the services requested by you:
- Active Vault Records: Stored continuously during your active account lifecycle.
- Deleted Assets: When you delete an individual item from within the app, its record and associated receipt images are permanently shredded from our database immediately.
- Account Erasure: Following confirmation of an Article 17 account deletion, data is removed from active caches immediately and completely cleared from automated immutable backup cycles within thirty (30) calendar days.
California Privacy Rights (CCPA / CPRA)
Under the California Consumer Privacy Act as amended by the CPRA, California residents are entitled to specific disclosures:
- Notice of Non-Sale: Ownly does not sell or share personal information for cross-context behavioral advertising and has not done so in the preceding 12 months.
- Right to Know & Delete: You may submit requests to know what personal information has been collected, and request deletion via privacy@ownly.app.
- Non-Discrimination: We will not discriminate against you in pricing, service tier, or responsiveness for exercising any of your CCPA/CPRA rights.
Data Protection Officer (DPO) & Regulatory Inquiries
We have designated an independent Data Protection Officer to supervise compliance with this Privacy Policy and EU/UK GDPR mandates.
Office of the Data Protection Officer (DPO)
Ownly Technologies Inc. — Data Privacy & Cryptographic Governance
Address: 548 Market Street, Suite 89201, San Francisco, CA 94104, USA
Direct DPO Email: dpo@ownly.app
General Privacy Support: privacy@ownly.app