Horologia Privacy Policy
Effective date: October 10, 2026.
Horologia is a private vault for your watch collection. This policy explains what data the Horologia app and its server handle, why, and what you can do about it. The short version: your collection stays on your device, and when it syncs, it's end-to-end encrypted so we can't read it. We don't show ads, don't use third-party analytics and don't track you.
1. Who we are
Horologia is made by Farrukh Khakimov, an individual developer ("we", "us").
- Postal address: Okhunboboev 2-tor 1-2, Tashkent 111800, Uzbekistan
- Email: support@horologia.app
We are the controller of the personal data described in this policy.
2. Summary
| What | Where it goes | Can we read it? |
|---|---|---|
| Your collection: watches, photos, documents, wear, service, values, notes, settings | Stays on your device. If you sign in, it's synced to our server encrypted with your key | No |
| Photos you choose for AI identification | Through our server to Anthropic, only after you agree | Our server passes them on without storing them |
| Account: a random account ID and the identifier Sign in with Apple gives us | Our server | Yes. We never ask for your email or name |
| Pro purchases | Apple handles payment; if you're signed in, our server links your purchase to your account | Yes: transaction IDs, product, dates. No payment details |
| Count of AI scans | Our server, keyed by an App Store ID of your app download | Yes: only the number of scans |
3. Data that stays on your device
Horologia works fully without an account. Everything you add (watches, photos, documents, wear log, service log, values, notes and settings) is stored on your iPhone or iPad, protected by Data Protection in iOS and iPadOS. Text recognition on warranty cards and tags, PDF dossiers, statistics and reminders all run on your device. Reminders are scheduled locally; we don't run a push notification server.
Without an account, none of your collection leaves your device unless you export or share it yourself, or use AI identification (section 5).
Camera and photo library access are used only to add photos and documents you choose. Face ID is handled by iOS; we never receive biometric data.
4. Account and sync (optional)
If you sign in with Apple, Horologia syncs your collection between your devices and keeps a backup on our server.
End-to-end encryption. Before anything leaves your device, the app encrypts each record and file with your collection key (AES-256-GCM). The key is created on your device. It is stored in your iCloud Keychain, which Apple end-to-end encrypts, and can be restored with your recovery code. We never have the key or the recovery code, so we can't decrypt your collection. If you lose all your devices and your recovery code, nobody, including us, can restore the data on the server. Your local copy and any exports you made are not affected.
What our server stores for a signed-in account:
- a random account ID and the date it was created;
- the stable user identifier from Sign in with Apple. We don't request your email address or name, so Apple doesn't share them with us;
- a token from Apple that we keep only to revoke Sign in with Apple when you delete your account;
- sessions: device platform (for example iOS), when you signed in and when the session was last used, and a hash of the session token;
- your encrypted records and files, plus what the server needs to sync them: random record and file IDs, change numbers, deletion markers, sizes (rounded up to 256 bytes for records) and which files belong to which record;
- your collection key, encrypted with a key derived from your recovery code, and a value that lets your devices check the key;
- Pro status (section 6) and how much of your storage quota you use.
The server can't see the type or content of your records: brands, models, serial numbers, prices, dates, notes, photos, documents and settings are all encrypted.
5. AI identification (optional, with your consent)
When you identify a watch from photos, the app first asks for your consent. If you agree:
- The app sends only the 1–3 photos you choose, resized and stripped of location and other metadata, along with your language and, optionally, a brand you already picked. It never sends serial numbers, prices, notes or anything else from your collection.
- The photos go through our server to Claude, an AI model by Anthropic, PBC (USA), which returns suggested brands, models and references. Our server doesn't store the photos or the answers.
- Anthropic processes the photos as our service provider. Under its commercial terms, it doesn't use them to train its models and deletes them within 30 days, unless it needs to keep them longer to enforce its Usage Policy or to comply with the law.
- To apply scan limits (3 free scans, monthly limits for Pro), the app sends a signed App Store record of your app download. Our server stores the
appTransactionIDfrom it with the number of scans you used. We don't send this ID to Anthropic.
You can withdraw consent at any time in Settings. It stops future scans; photos already sent can't be recalled from Anthropic, but are deleted as described above.
6. Purchases
Purchases are processed by Apple. We never receive your payment details. The app checks your purchases with Apple's StoreKit. If you're signed in, the app sends the signed transaction to our server, which links Pro to your account so it works on your other devices. We store the original transaction ID, the product, the plan, the expiry date, whether it was refunded or revoked, and when it was signed. Purchases shared through Family Sharing are not linked to an account.
7. Server logs and hosting
Our server runs on Cloudflare, Inc. (USA): Cloudflare Workers, Durable Objects, D1 and R2 storage. Cloudflare processes your IP address and technical request data to deliver traffic and protect the service from abuse. We don't store IP addresses in our databases.
Our request logs contain only the route, the response code, the duration, the type of error if a request fails and, for AI scans, technical figures such as the plan type (Free or Pro), the model and token counts. They never contain request contents, photos, AI answers, record or file IDs, serial numbers or amounts. Logs are deleted after 7 days.
8. Links to other websites
Check price opens a marketplace website, such as Chrono24 or eBay, with the brand and reference in the search. Links you save in your wishlist open in Safari. Those websites receive what any website receives from your browser, and their own privacy policies apply. We don't receive anything back and use no affiliate tracking.
9. Why we process data (legal bases)
If you're in the European Economic Area, the United Kingdom or Switzerland, we rely on:
- performance of a contract (Art. 6(1)(b) GDPR): your account, sync, backup and Pro on your account;
- consent (Art. 6(1)(a)): AI identification;
- legitimate interests (Art. 6(1)(f)): securing the service, preventing abuse and applying scan limits and storage quotas.
10. Who receives data
We don't sell your personal data and don't share it for advertising. We use these service providers:
| Provider | Role | Data |
|---|---|---|
| Cloudflare, Inc. (USA) | Hosting, databases, file storage | Everything in sections 4, 6 and 7; your collection only in encrypted form |
| Anthropic, PBC (USA) | AI identification | Photos you choose to scan |
| Apple Inc. | Sign in with Apple, App Store purchases, iCloud Keychain | Apple acts under its own privacy policy |
We may disclose data if required by law. Because your collection is end-to-end encrypted, we can't disclose its contents.
11. International transfers
Our providers process data in the United States and other countries. Where data protection law requires it, transfers rely on the European Commission's standard contractual clauses in the providers' data processing terms or, where available, the EU-U.S. Data Privacy Framework.
12. How long we keep data
| Data | Kept |
|---|---|
| Account, sign-in identifier, encrypted records and files | Until you delete your account |
| Files you deleted or replaced | Up to 30 days, to protect against sync errors |
| Sessions | Until you sign out or 90 days after last use |
| Purchase records | Until you delete your account |
| AI scan counts | While we operate the service, so that reinstalling doesn't reset free scans |
| Request logs | 7 days |
| Photos sent for AI identification | Not stored by us; Anthropic, see section 5 |
When you delete your account, we delete your account data, records, files, sessions and purchase links right away and revoke Sign in with Apple. Copies in our hosting provider's recovery backups expire within 30 days.
13. Your choices and rights
- Export: Settings → Your data exports a spreadsheet or a full archive with photos and documents.
- Delete everything: Settings → Your data → Delete all data removes your collection from the device and from the server.
- Delete your account: Settings → Sync → Delete account.
- AI consent: turn AI identification off in Settings at any time.
Depending on where you live, you also have the right to access, correct, delete, restrict or object to the processing of your personal data, to data portability and to withdraw consent. Email support@horologia.app. Because we don't know your name or email, we may ask for details that let us find your account, such as information about an App Store purchase. You can also complain to your local data protection authority.
14. Security
Your collection is encrypted on your device before it's sent. Connections use HTTPS. Session tokens are stored only as hashes. Optional Face ID or Touch ID lock, hidden prices and masked serial numbers protect the app on your device.
15. Children
Horologia is a tool for adult watch collectors and isn't directed at children. We don't knowingly collect personal data from children under 13, or under 16 in the European Economic Area.
16. Changes
If we change this policy, we'll publish the new version here with a new effective date. If the changes are significant, we'll also tell you in the app.
17. Contact
Questions or requests: support@horologia.app