Legal
Privacy Policy
Last updated: 17 July 2026
This policy covers the Intento mobile app (Google Play & App Store) and the joinintento.com website.
1. Who we are
Intento is a mindful purchasing companion. We are the data controller for personal data collected through the Intento mobile app and this website. Contact: hello@joinintento.com.
2. Summary — what we collect
We keep data collection to what the app needs to work. Below is a plain-English summary; details follow in section 3.
- Anonymous account identifier — a random ID we create so your data belongs to your device (no email, name, or phone required).
- Content you save in the app — products you add, notes, decisions, reflections, purchase reviews.
- Photos you attach — screenshots or photos of products you add. Stored only if you attach them.
- Push notification token — if you enable notifications, so we can send you check-ins for products you saved.
- Crash and diagnostic data — anonymised technical logs when the app crashes, so we can fix bugs.
- Waitlist email — only if you subscribe on the website.
We do not collect: contacts, precise location, health, financial account details, or advertising identifiers. We do not sell or share your data for advertising.
3. What we collect and why
3.1 Anonymous account (App)
When you first open Intento, we create an anonymous account using Supabase Auth. You are not asked for an email or phone number. We generate a random user ID (UUID) that stays with your app install. If you delete the app or your account, this ID and the data linked to it are removed. Purpose: to sync your data across app sessions and (in the future) across your devices.
3.2 Personal content (App)
Products you add, decisions and reflections you write, purchase reviews you leave — all stored on our servers and linked to your anonymous ID. Purpose: this is the app content; without it the app can't show you your own history.
3.3 Photos and files (App)
You may attach product photos from your camera or photo library, or receive them via Android/iOS share into Intento. We only access the specific photos you select — we do not scan your library. Files are stored in our Supabase storage, linked to your anonymous ID.
3.4 Notifications (App)
If you allow notifications, we store an Expo push token so we can send check-in reminders (e.g. “how do you feel about that product now?”). You can turn notifications off at any time from your OS settings; the token is discarded once you do.
3.5 Crash reports (App)
We use Sentry to receive anonymised crash reports and technical diagnostics when the app misbehaves. Reports include device model, OS version, app version, stack traces, and breadcrumbs of screens visited. They do not contain your personal content. Purpose: fix bugs and stability issues.
3.6 Waitlist (Website)
If you subscribe on joinintento.com, we store your email address and (optional) name to send occasional product updates. You can unsubscribe from any email or by writing to us.
3.7 Server logs
Our hosting provider (Vercel) keeps short-lived server access logs (IP, path, user agent) for security and reliability. These are automatically deleted after a few days.
4. How we use permissions (Android & iOS)
- Camera — only when you tap the camera control to take a product photo.
- Photos / Media (READ_MEDIA_IMAGES) — only when you tap to pick a photo from your library. We do not read the whole library.
- Notifications (POST_NOTIFICATIONS) — only if you opt in, to send check-in reminders.
- Internet — to sync your content with our servers.
We do not request contacts, precise location, background location, SMS, phone, microphone, calendar, health, or accessibility permissions.
5. Who we share data with (sub-processors)
We use a small set of trusted services to run Intento. We do not sell your data or share it for advertising. Each service processes your data only on our instructions:
- Supabase (EU) — hosts the database, authentication, and file storage.
- Vercel (US/EU edge) — hosts this website and the app's API.
- Sentry (US/EU) — crash and error reporting for the app.
- Resend (US) — sends waitlist emails from the website.
- Expo Push Service (US) — delivers push notifications to your device (via Apple APNs and Google FCM).
- Google Play Services — required by Android to deliver push notifications.
Some of these providers may transfer data outside the EU. Where they do, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission for lawful transfer.
6. Legal basis (GDPR / UK GDPR)
- Contract (Art. 6(1)(b)) — to provide the app you asked to use.
- Consent (Art. 6(1)(a)) — for waitlist emails and, on Android 13+, push notifications.
- Legitimate interest (Art. 6(1)(f)) — for crash reports and short-lived security logs. You can object.
7. How long we keep your data
- App content — until you delete an item, delete your account, or uninstall and ask us to erase server-side data.
- Waitlist — until you unsubscribe or the app is fully launched, whichever comes first.
- Crash reports — 90 days.
- Server access logs — up to 30 days.
8. Your rights and how to delete your account
You have the right to access, correct, export, restrict, or delete your personal data, and to withdraw consent at any time.
Delete your account and data:
- In the app: Profile → Settings → Delete account. This immediately removes your account and all associated content from our servers.
- Or use our dedicated form at joinintento.com/data-deletion.
- Or email hello@joinintento.com from the address you registered with, or include your anonymous user ID (visible in the app under Profile → About). We respond within 30 days.
Deletion is permanent and cannot be undone. Backups are overwritten within 30 days. If you are in the EEA/UK and believe we've handled your data incorrectly, you can also complain to your local data protection authority.
9. Security
Data is transmitted over TLS and stored encrypted at rest by our providers. Access to production data is restricted to authorised staff on a need-to-know basis. No system is perfectly secure — if you believe your account has been compromised, contact us immediately.
10. Children
Intento is not directed at children under 13 (or under 16 where applicable local law requires higher age). We do not knowingly collect data from children. If you are a parent and believe your child has used Intento, contact us to have the data removed.
11. Cookies (Website only)
The website does not use tracking, analytics, or advertising cookies. Only strictly necessary cookies are used (e.g. session state on the waitlist form).
12. Changes to this policy
We may update this policy. Material changes will be announced in the app and to waitlist subscribers by email. The “Last updated” date at the top shows when the current version took effect.
13. Contact
Questions or requests: hello@joinintento.com.