Privacy Policy
Effective date: 2026-08-11Last updated: 2026-08-24
The short version
Serial & Story has no accounts, no sign-in, and no analytics. Every piece of information you enter — descriptions, photos, values, serial numbers, the stories behind your things — is encrypted on your own device before it’s ever stored or synced anywhere. If you turn on iCloud sync, Apple’s servers hold a copy of that encrypted data so it reaches your other devices, but Apple cannot read it, and neither can we. Nothing is sold, shared with advertisers, or used to track you. The rest of this document explains that in full, and covers the few features (subscriptions, notifications, camera) that touch data in ways worth spelling out precisely.
Who this policy covers
This policy covers Serial & Story, an iOS app published by Anchorwright. It applies to the app itself and to Apple’s own services the app relies on (iCloud/CloudKit, StoreKit). It does not cover any other app, website, or service.
Contact
Questions about this policy or how the app handles your information: hello@anchorwright.com.
What the app stores, and where
Everything you enter into Serial & Story — item descriptions, room/location, make and model, serial numbers, purchase price and current value, retailer, warranty date, photos (item, serial closeup, receipt, and for vehicles, an additional document photo), and the optional “Story” fields (how you got it, the memory behind it, who you’d want to have it) — is stored as a Item record on your device.
Every one of those fields is encrypted on your device, using AES-256-GCM, before it is ever written to disk or synced anywhere. The encryption key is generated on-device and never leaves it in readable form (see “How the encryption key is protected,” below). This happens automatically; there is nothing to turn on.
iCloud sync is part of Serial & Story+, the app’s subscription. With an active subscription, your encrypted item data is also stored in your own private iCloud account, via Apple’s CloudKit service, so it reaches your other devices signed into the same Apple ID. Apple’s servers only ever receive and store the encrypted ciphertext — not the underlying descriptions, photos, or values. Without a subscription — or if iCloud is unavailable (not signed in, sync disabled, or restricted by your device’s settings) — the app stores data locally only, on that one device, and nothing leaves it.
Your own contact information (optional)
If you fill in the optional owner profile (Settings) — your name, email, phone, and address, used to stamp the insurance/police and attorney exports with who the inventory belongs to — that information is stored and protected exactly like your item data: encrypted on your device before it’s written anywhere, synced to your own private iCloud account only with an active subscription, and readable by no one else, including us. It appears in the documents the app generates for you (that’s what it’s for); the app itself never transmits it anywhere else.
Neither Anchorwright nor Apple can read your item data. The encryption happens before the data is handed to CloudKit, using a key Apple’s servers never receive.
How the encryption key is protected
The key that encrypts your data is stored in your device’s Keychain and syncs across your own devices via iCloud Keychain — the same end-to-end encrypted mechanism Apple uses for your saved passwords and Wi-Fi credentials. Apple has stated it cannot read synced Keychain data. This is how a second device signed into your Apple ID is able to decrypt data an earlier device encrypted, without the key ever being transmitted in a form Apple, or anyone else, can read.
You can also view and export your own recovery key from within the app (Settings), for cases where you need to restore access independent of iCloud Keychain. That export is your responsibility to store safely — anyone who has that key can decrypt your item data.
Subscriptions and purchases
Serial & Story+ is offered as an auto-renewable subscription through Apple’s App Store, via StoreKit. Apple handles the transaction — Serial & Story never receives or stores your payment details. The app only checks with Apple whether you currently hold an active subscription, in order to unlock the features that come with it. Refunds, billing, and subscription management are handled entirely through your Apple ID account settings, not by us.
Camera, photo library, and voice dictation
- Camera and Photos: if you choose to add a photo to an item (item photo, serial closeup, receipt, or document), the app asks for camera access (to take a photo directly) or uses Apple’s system photo picker (to choose an existing one, which needs no separate permission). Either way, the resulting photo is encrypted the same way as every other field before it’s stored.
- Voice dictation: if you use the microphone button on a Story field, speech-to-text happens entirely on your device, using Apple’s on-device speech recognition. Your voice is never sent to Apple’s or anyone else’s servers for this feature.
- Receipt and serial scanning: the on-device camera-text-recognition feature that helps fill in a serial number or receipt detail from a photo also runs entirely on-device. No image or extracted text is sent anywhere for this purpose.
Notifications
If an item has a warranty expiration date, the app can remind you shortly before it expires, using Apple’s local notification system. This is scheduled entirely on your device — no server, and no third party, is involved in delivering it.
Separately, the app can display short announcements from us (for example, a note about a new version) inside the app. These are fetched from a public, read-only Apple CloudKit database that contains only the announcement text itself — never anything about you or your data — and the app may use Apple’s silent push mechanism as a “check for new announcements” signal. No visible push notifications are sent, no alert/badge/sound permission is requested for this, and nothing about you travels in either direction beyond the standard Apple infrastructure involved in any iCloud-using app.
Exports (PDF and CSV)
The app can generate PDF and CSV documents from your data — an insurance/police report, a story to share, a bulk export, or an attorney handoff document. These are generated entirely on your device. When you export one, iOS’s standard share sheet opens so you can choose where it goes (Mail, Files, AirDrop, Messages, or anywhere else you pick) — the app itself does not transmit the export anywhere. Temporary copies used to generate the export are deleted from the app’s storage once the share sheet is dismissed.
What we don’t do
- No accounts, no sign-in, no password of any kind — including Sign in with Apple, which the app doesn’t offer because there’s no account system for it to sign into.
- No analytics, telemetry, crash-reporting, or advertising SDKs of any kind. Nothing about your use of the app is tracked or sent anywhere for those purposes. If the app crashes or hangs, Apple’s MetricKit framework may deliver a diagnostic report — a technical stack trace and device state, never your items or their content — which the app records on your device only; it is never transmitted by the app, and no third-party service is involved.
- No third-party SDKs at all. The only outside code the app depends on is Anchorwright’s own first-party library.
- We do not sell, rent, or share your data with advertisers or data brokers. There is nothing to sell — Anchorwright cannot read the encrypted data in the first place.
- No barcode, VIN, or product-catalog lookups against any external database. Every field is either something you typed or something read from a photo you took, entirely on your device.
Apple’s App Privacy disclosure
Apple’s own “App Privacy” nutrition label for this app, shown on its App Store product page, declares six categories as collected, for App Functionality only, and never used to track you: Photos or Videos, Other User Content, and — grouped under Apple’s Contact Info heading — Name, Email Address, Phone Number and Physical Address. The four Contact Info categories are the optional owner details described above, which the app prints on the reports and handoff documents you generate. Every one of the six is marked linked to your identity under Apple’s specific definition of that term (which turns on whether data has been de-identified/anonymized, not on whether the developer can technically read it) — your data is encrypted, but it is still your own data, tied to your own Apple ID and devices, not anonymized in Apple’s sense. This policy is consistent with that label, not a substitute for it.
Children’s privacy
Serial & Story is a general-purpose personal-property documentation tool, not directed at children, and does not knowingly collect information from children under 13. If you believe a child has provided information through this app, contact us at the address above.
Your choices and controls
Because there’s no account for us to hold, most of the usual “your rights” mechanics work differently here — you already have direct control:
- Access and export your data: every export feature in the app (insurance report, story share, CSV, attorney handoff) is available to you at any time, and produces a copy of the underlying data in a portable format.
- Delete data: deleting an item removes it from the app. Deleting the app removes everything stored locally; if iCloud sync was on, you can also remove the app’s data from iCloud through your device’s iCloud storage settings, the same way as any other iCloud-syncing app.
- Turn off sync: if iCloud sync isn’t available or is turned off at the device/account level, the app simply stores data locally on that device instead.
If you’re in a jurisdiction that grants specific statutory rights (for example, GDPR or California’s CCPA/CPRA), the mechanisms above are how those rights are exercised in practice for this app, since there’s no separate account or backend record to request access to or deletion from beyond what’s described here. If you have a request this document doesn’t clearly answer, contact us at the address above.
Data retention
Item data persists for as long as you keep it in the app. There is no separate retention period we impose — you control how long anything is kept, and deletion (of an item, or of the app) is immediate and local, propagating to your other synced devices the same way any other change does.
One deliberate exception: if you have used the attorney handoff export, the app keeps a small encrypted snapshot of each exported item’s legal-essential fields (description, intended recipient, value, and valuation date/basis) even after that item is deleted — that’s what lets your next attorney handoff honestly report “removed since your last export,” which someone handling an estate needs to know. These snapshots are encrypted and synced exactly like item data, and deleting the app removes them along with everything else.
International users
Serial & Story is distributed through the App Store worldwide. If you use the app outside the United States, your encrypted data may be processed on Apple’s infrastructure in the United States or other countries where Apple operates iCloud/CloudKit, as part of the sync described above — the same infrastructure any iCloud-syncing app uses. Because the data reaching that infrastructure is already encrypted on your device, Apple’s processing of it is limited to storing and relaying ciphertext.
Changes to this policy
If this policy changes in a way that affects how your data is handled, we’ll update the “Last updated” date above and, for a material change, note it within the app.