Horologia Privacy Policy

Effective date: October 10, 2026.

Horologia is a private vault for your watch collection. This policy explains what data the Horologia app and its server handle, why, and what you can do about it. The short version: your collection stays on your device, and when it syncs, it's end-to-end encrypted so we can't read it. We don't show ads, don't use third-party analytics and don't track you.

1. Who we are

Horologia is made by Farrukh Khakimov, an individual developer ("we", "us").

We are the controller of the personal data described in this policy.

2. Summary

What Where it goes Can we read it?
Your collection: watches, photos, documents, wear, service, values, notes, settings Stays on your device. If you sign in, it's synced to our server encrypted with your key No
Photos you choose for AI identification Through our server to Anthropic, only after you agree Our server passes them on without storing them
Account: a random account ID and the identifier Sign in with Apple gives us Our server Yes. We never ask for your email or name
Pro purchases Apple handles payment; if you're signed in, our server links your purchase to your account Yes: transaction IDs, product, dates. No payment details
Count of AI scans Our server, keyed by an App Store ID of your app download Yes: only the number of scans

3. Data that stays on your device

Horologia works fully without an account. Everything you add (watches, photos, documents, wear log, service log, values, notes and settings) is stored on your iPhone or iPad, protected by Data Protection in iOS and iPadOS. Text recognition on warranty cards and tags, PDF dossiers, statistics and reminders all run on your device. Reminders are scheduled locally; we don't run a push notification server.

Without an account, none of your collection leaves your device unless you export or share it yourself, or use AI identification (section 5).

Camera and photo library access are used only to add photos and documents you choose. Face ID is handled by iOS; we never receive biometric data.

4. Account and sync (optional)

If you sign in with Apple, Horologia syncs your collection between your devices and keeps a backup on our server.

End-to-end encryption. Before anything leaves your device, the app encrypts each record and file with your collection key (AES-256-GCM). The key is created on your device. It is stored in your iCloud Keychain, which Apple end-to-end encrypts, and can be restored with your recovery code. We never have the key or the recovery code, so we can't decrypt your collection. If you lose all your devices and your recovery code, nobody, including us, can restore the data on the server. Your local copy and any exports you made are not affected.

What our server stores for a signed-in account:

The server can't see the type or content of your records: brands, models, serial numbers, prices, dates, notes, photos, documents and settings are all encrypted.

When you identify a watch from photos, the app first asks for your consent. If you agree:

You can withdraw consent at any time in Settings. It stops future scans; photos already sent can't be recalled from Anthropic, but are deleted as described above.

6. Purchases

Purchases are processed by Apple. We never receive your payment details. The app checks your purchases with Apple's StoreKit. If you're signed in, the app sends the signed transaction to our server, which links Pro to your account so it works on your other devices. We store the original transaction ID, the product, the plan, the expiry date, whether it was refunded or revoked, and when it was signed. Purchases shared through Family Sharing are not linked to an account.

7. Server logs and hosting

Our server runs on Cloudflare, Inc. (USA): Cloudflare Workers, Durable Objects, D1 and R2 storage. Cloudflare processes your IP address and technical request data to deliver traffic and protect the service from abuse. We don't store IP addresses in our databases.

Our request logs contain only the route, the response code, the duration, the type of error if a request fails and, for AI scans, technical figures such as the plan type (Free or Pro), the model and token counts. They never contain request contents, photos, AI answers, record or file IDs, serial numbers or amounts. Logs are deleted after 7 days.

Check price opens a marketplace website, such as Chrono24 or eBay, with the brand and reference in the search. Links you save in your wishlist open in Safari. Those websites receive what any website receives from your browser, and their own privacy policies apply. We don't receive anything back and use no affiliate tracking.

If you're in the European Economic Area, the United Kingdom or Switzerland, we rely on:

10. Who receives data

We don't sell your personal data and don't share it for advertising. We use these service providers:

Provider Role Data
Cloudflare, Inc. (USA) Hosting, databases, file storage Everything in sections 4, 6 and 7; your collection only in encrypted form
Anthropic, PBC (USA) AI identification Photos you choose to scan
Apple Inc. Sign in with Apple, App Store purchases, iCloud Keychain Apple acts under its own privacy policy

We may disclose data if required by law. Because your collection is end-to-end encrypted, we can't disclose its contents.

11. International transfers

Our providers process data in the United States and other countries. Where data protection law requires it, transfers rely on the European Commission's standard contractual clauses in the providers' data processing terms or, where available, the EU-U.S. Data Privacy Framework.

12. How long we keep data

Data Kept
Account, sign-in identifier, encrypted records and files Until you delete your account
Files you deleted or replaced Up to 30 days, to protect against sync errors
Sessions Until you sign out or 90 days after last use
Purchase records Until you delete your account
AI scan counts While we operate the service, so that reinstalling doesn't reset free scans
Request logs 7 days
Photos sent for AI identification Not stored by us; Anthropic, see section 5

When you delete your account, we delete your account data, records, files, sessions and purchase links right away and revoke Sign in with Apple. Copies in our hosting provider's recovery backups expire within 30 days.

13. Your choices and rights

Depending on where you live, you also have the right to access, correct, delete, restrict or object to the processing of your personal data, to data portability and to withdraw consent. Email support@horologia.app. Because we don't know your name or email, we may ask for details that let us find your account, such as information about an App Store purchase. You can also complain to your local data protection authority.

14. Security

Your collection is encrypted on your device before it's sent. Connections use HTTPS. Session tokens are stored only as hashes. Optional Face ID or Touch ID lock, hidden prices and masked serial numbers protect the app on your device.

15. Children

Horologia is a tool for adult watch collectors and isn't directed at children. We don't knowingly collect personal data from children under 13, or under 16 in the European Economic Area.

16. Changes

If we change this policy, we'll publish the new version here with a new effective date. If the changes are significant, we'll also tell you in the app.

17. Contact

Questions or requests: support@horologia.app