Privacy Policy
Last updated: August 2026
Who we are
StuffProof (stuffproof.djump.io) is operated by MB Djump, Šilutės pl. 35G-36, LT-94105 Klaipėda, Lithuania (registration code 307521980). Contact: start@djump.io. We are the data controller for everything described below.
This policy covers two things: this website, and the StuffProof mobile app for iOS and Android. They collect different data, so they are described separately.
The website
- Waitlist form — your email address, the time you signed up, and, if present
in the page URL, campaign parameters (
utm_*) and the referring page. - Contact form — your name, email address and the message you write. It is delivered to us by email through Resend, our email provider.
- Page views — we use Vercel Web Analytics, which is cookieless and collects no personal data and no cross-site identifiers.
This website uses no advertising trackers and no cookies.
The mobile app
The app collects the following, and nothing else:
- Your account — an email address and password, or your Google or Apple account if you sign in that way. You can also start anonymously, in which case we hold no email address for you at all. Optionally, a display name.
- Your inventory — the rooms and items you file: names, descriptions, categories, brands, serial numbers, estimated values, purchase dates and prices, warranty expiry dates, and your insurance policy renewal date if you enter one.
- Your photos — the room, item and receipt photos you take or pick. They are stored in a private bucket that only your account can read.
- Subscription state — whether you have an active subscription, handled for us by RevenueCat. Your card details go to Apple or Google and never reach us.
- A notification token — only if you turn on warranty reminders, so we can send them.
- App settings — language, theme, and whether you finished onboarding.
- Usage events and crash reports — which screens you open and which actions you take (PostHog), and diagnostics when the app errors or crashes (Sentry). These record that a screen was viewed or an export was run; they never carry the contents of your inventory or your photos. When you are signed in, usage events are tied to your account identifier, so they are not anonymous; your email address is not sent to our analytics provider. Crash reports are not tied to your account at all.
The AI room scan
When — and only when — you run a room scan, that one photo is sent to OpenAI
(model gpt-4o-mini) together with the room's name, so it can return a list of
items it recognises. You then confirm or discard that list. This is a transfer to the United
States, and it is processed under OpenAI's API terms, which state that data submitted through
the API is not used to train its models. We keep no server-side copy of the scan beyond a
counter of how many scans you have run, which exists to enforce plan limits. If you never run
a scan, no photo of yours ever leaves our storage.
Who else processes your data
- Supabase — database, sign-in and photo storage. European Union.
- OpenAI — the room scan described above. United States.
- RevenueCat — subscription status. United States.
- PostHog — product analytics, on its EU host.
- Sentry — crash and error reporting, on its German host.
- Expo — delivery of push notifications, if you enable them.
- Apple and Google — payment processing for subscriptions.
- Vercel and Resend — hosting of this website, and delivery of contact-form email.
Each of these acts on our instructions for the purpose listed. We do not sell your data, we do not share it with data brokers or advertisers, and we do not use it to track you across other companies' apps or websites.
Why we are allowed to hold it
- Your inventory, photos, account and subscription — performance of our contract with you (GDPR Art. 6(1)(b)). Without them the app cannot do its job.
- Waitlist email — your consent (Art. 6(1)(a)), given when you submit the form.
- Usage events and crash reports — our legitimate interest in fixing bugs and improving the app (Art. 6(1)(f)).
Where it is stored, and for how long
- Your app data lives in a Supabase (PostgreSQL) database and private storage bucket hosted in the European Union, protected by row-level security so that no other user can read it. It is kept until you delete it or delete your account.
- Anonymous accounts that never file a room or item are deleted automatically after 30 days.
- Waitlist emails are kept until StuffProof launches and the waitlist is retired, or until you ask us to delete yours — whichever comes first.
- Usage events and crash reports are kept by PostHog and Sentry under their standard retention periods and are not linked to your inventory.
All data is encrypted in transit.
Deleting your data
In the app, open Settings → Delete account. That removes your account, your rooms and items, and your photos. You can also email start@djump.io and we will do it for you.
Your rights
You may request access to, correction of, deletion of, or a portable copy of your data, and you may object to or restrict processing, at any time by emailing start@djump.io. You may also lodge a complaint with your local data protection authority.
Children
StuffProof is not directed at children and is not intended for use by anyone under 16.
Changes
If we change what we collect or who processes it, we will update this page and the date at the top. Material changes will be announced in the app.