Privacy Policy
Last updated: July 23, 2026
Boxely (“Boxely,” “we,” “us”) is an inventory tracking service operated by HMB Software. This Privacy Policy explains what information we collect, how we use it, and the choices you have. It applies to the Boxely website, web app, and our Android and iOS apps.
Information we collect
- Account information. When you create an account we collect your email address and name. Authentication is handled by our identity provider (Keycloak); if you sign in with Google, we receive your basic Google profile (name, email) to create or link your account. We never see your Google password.
- Inventory content. The data you add to organize your belongings — containers, items, locations, descriptions, quantities, QR label identifiers, and any photos you attach to items.
- Photos. Images you capture or upload for items are stored in our object storage and shown back to you in the app. The camera is used for taking item photos, scanning QR labels (on-device), and — if you choose AI item detection — preparing a photo for that optional feature (see AI-assisted image processing below).
- AI detection submissions. If you use AI item detection, we receive the photo you select for that request (typically a compressed image), transmit it to Google Gemini as described below, and return suggested item labels (and optional location boxes) to your device. We do not add your email or account identifiers to the Gemini request.
- Billing information. Paid plans are processed by Stripe and, on mobile, by Apple App Store or Google Play Billing where applicable. Payment card details for web checkout are entered into and handled by Stripe — Boxely does not receive or store full card numbers. We retain your subscription tier, status, and related entitlement information.
- Push notification tokens.If you enable notifications, we store a device push token (via Firebase Cloud Messaging / Apple Push Notification service) so we can deliver notifications you’ve opted into.
- Technical and diagnostic data. We collect limited technical information needed to operate and secure the service (for example request metadata and operational logs that do not include raw photo bytes), and crash/diagnostic reports (via Firebase Crashlytics on Android) to find and fix problems.
AI-assisted image processing
Boxely offers an optional AI-assisted item detection feature for eligible plans (Pro and Enterprise). It is not run on every photo you store. AI processing starts only when you choose a detection action in the app or website (for example after selecting or capturing a photo and confirming detection). You can always add and edit inventory manually without using AI.
What happens.Your client prepares a compressed image and sends it to Boxely’s servers. Boxely then transmits that image, together with a fixed catalog instruction prompt we supply (not your personal message), to Google Gemini(Google’s generative AI service) using Google’s paid Gemini API. Google returns AI-generated suggestions such as item names and, when available, approximate regions in the photo. Boxely shows those suggestions so you can review, edit, accept, or discard them. AI results may be inaccurate; you should review them before saving.
What may be in the image. The photo is whatever you select. It may show household belongings and may also incidentally include personal or sensitive details you did not intend to share — for example people or faces, documents, receipts, mailing labels, addresses, serial numbers, financial information, or the interior of a home or business. Boxely does not require those details for detection, but they may still appear in the image and therefore may be processed by Google for that request.
What we send to Google. For detection, Google receives the image bytes (and MIME type) and our fixed prompt. We do notinclude your email address, display name, or internal account identifiers in the Gemini request. We do not use Google’s File API, URL-based image fetch, grounding with Search/Maps, or multi-turn conversation storage for this feature.
Google as processor; training and retention.Google acts as a third-party service provider that processes the detection request on our behalf under Google’s applicable Gemini API terms. Under our paid production Gemini configuration, Google does not use those prompts, images, or responses to train or improve its models. Separately, Google may still process or log prompts and responses for a limited period for abuse monitoring, security, legal, or regulatory purposes under its terms. We have requested an exception (zero data retention / abuse logging exception) for our Google project; until that request is approved, you should assume limited provider-side abuse monitoring may apply. We do not claim that Google never stores or logs detection images.
Boxely retention of detection photos. The image used only for a detection request is held in memory on our servers for the duration of that request and is not stored by Boxely as a separate AI archive. If you later save a photo on an item (including a crop from detection), that saved photo is ordinary inventory content and is retained as described under photos and retention below. We may keep limited technical logs about detection (for example that a request succeeded or failed, model name, approximate image size, or token counts) that do not include the photo itself.
Sensitive-content caution. Before using AI detection, review the frame and avoid including information that is unnecessary for cataloging items — for example payment cards, government IDs, medical records, passwords or recovery codes, private documents, or full mailing labels — when you can crop or choose a different photo.
Your choices. You can decline AI detection and enter items manually. You can dismiss AI suggestions without saving them. You can delete saved item photos and inventory data in the app. A first-use in-app notice may also explain AI detection before you use it for the first time.
How we use your information
- Provide, maintain, and improve the Boxely service.
- Authenticate you and keep your account secure.
- Store and display the inventory content and photos you create.
- When you use AI item detection, process the selected image via Google Gemini to suggest inventory labels for you to review.
- Process subscriptions and manage your plan.
- Send notifications you have enabled.
- Diagnose crashes, operate the service, and prevent abuse.
We do not sell your personal information. We do not use your inventory content or photos for advertising, facial recognition, biometric identification of people, or unrelated profiling. We do not use your photos to train Boxely machine-learning models.
How information is shared
We share information only with service providers that help us run Boxely:
- Keycloak — authentication and identity management.
- Stripe — subscription billing and payment processing (web and related billing flows).
- Apple / Google Play — native in-app purchases and subscriptions where you buy through the stores.
- Google Firebase / Apple — push notifications and crash reporting.
- Google Gemini — optional AI item detection: processes the image and prompt for that feature as described above.
- Cloud hosting and object storage — to host the service and store your data and saved photos.
We may also disclose information if required by law or to protect the rights, safety, and security of Boxely and its users.
Data retention and deletion
- Account and inventory. We keep your account and inventory data while your account is active.
- Saved item photos. Photos you attach to items are stored until you remove the photo, delete the item, or delete your account (subject to ordinary backup and operational recovery windows after deletion).
- AI detection images.Photos submitted only for AI detection are not kept by Boxely as a long-lived AI copy; they are discarded after the request completes. Provider-side retention is governed by Google’s terms and any exception we obtain (see AI section).
- AI suggestions. Labels or boxes returned for a detection session live on your device until you save inventory from them; once you create or update items, that content is inventory data under your account.
- Operational logs. Limited technical logs are retained according to our infrastructure log-retention practices and do not include full image contents.
You can delete containers, items, and photos in the app. To delete your account and associated data, use the in-app account deletion flow where available, or contact us at support@boxelyapp.com. Deletion from Boxely does not guarantee that Google has already discarded any short-term abuse-monitoring or security records it may hold under its terms for a prior detection request.
International processing
Boxely and its service providers may process data in the United States and other countries where they operate. Google may process Gemini requests in locations supported by its Gemini API service. Where required, we use appropriate safeguards for cross-border transfers.
Security
We use industry-standard measures to protect your information, including encrypted connections (HTTPS), authenticated access to APIs, access controls, private object storage for saved photos, and secure handling of service credentials (for example the Gemini API key is held only on our servers). No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
Children's privacy
Boxely is not directed to children under 13, and we do not knowingly collect personal information from them. The service is not intended for individuals under 18 where that is restricted by local law.
Your choices
- Access and edit your inventory content directly in the app.
- Use or skip AI item detection; add items manually instead.
- Review and discard AI suggestions before saving.
- Delete photos, items, and containers in the app.
- Turn notifications on or off in your device and app settings.
- Manage or cancel your subscription from your account or the applicable store.
- Request account deletion in the app or by contacting us.
Changes to this policy
We may update this Privacy Policy from time to time — for example if Google approves zero data retention for our Gemini project, or if we change AI providers or features. When we do, we will revise the “Last updated” date above.
Contact us
Questions about this policy or your data? Email support@boxelyapp.com.