1. Introduction
This Privacy Policy applies to the Registry Rescue iOS app, its support website, and related support communications. “Registry Rescue,” “we,” and “our” refer to the product and its publisher; the product name is not a claim that a separate corporation exists.
Registry Rescue helps users organize and review baby-registry choices. It is not a medical, pediatric, certification, or product-safety service. This policy does not expand the app’s technical permissions.
2. Information Registry Rescue processes
Depending on what you use, Registry Rescue may process:
- screenshots you select, local OCR evidence, import drafts, confirmed and manually added registry items, retailer labels or URLs visible in those screenshots, and your corrections;
- optional context choices, deterministic findings, evidence and scope, game-plan content, user actions, review versions, and re-check history;
- locally cached AI explanations and feedback, if an AI explanation is eligible and successfully persisted;
- purchase and subscription state processed by Apple and RevenueCat when you use commerce;
- bounded product-behavior events and a random installation identifier if you separately enable anonymous analytics in a build where it is available; and
- the email address and message content you choose to send to support.
No Registry Rescue account is required for V1. Pseudonymous service identifiers can still correlate activity across sessions and are not automatically the same as “unlinked” under every platform definition.
3. Registry screenshots and PhotosPicker
Registry Rescue uses Apple’s PhotosPicker so you choose specific images. The app does not request unrestricted browsing of your full photo library for this flow. Selected images are copied into protected, app-owned temporary storage for local import processing.
Raw registry screenshots are not uploaded to Registry Rescue’s AI service, analytics provider, or commerce provider. They are removed after successful confirmation, cancellation, explicit deletion, or bounded cleanup of abandoned temporary files.
4. OCR and import review
Apple Vision performs optical character recognition on the device. Local application logic turns observations into a guarded draft. OCR can be incomplete or wrong, so the app asks you to confirm, correct, remove, or manually add items before saving a registry.
Raw OCR text and raw import evidence are not sent to the AI provider or analytics provider. A parser draft is not treated as a confirmed fact without your review.
5. Local registry data
Confirmed registry items, manual items, context responses, deterministic audit records, findings, review and re-check history, local consent state, and locally persisted AI artifacts are stored in the app’s local database or app-owned files. The app’s SwiftData store is configured without CloudKit synchronization.
This local data remains until you edit or delete it, an applicable lifecycle replaces it, or you remove the app. Device backups and operating-system behavior are controlled by Apple and your settings.
6. Registry Review and deterministic processing
Canonical Registry Rescue findings are determined by versioned application logic applied to confirmed facts. AI does not decide which canonical finding appears, change finding eligibility, decide purchase access, or replace Evidence & Scope.
Findings and summaries are organizational observations. They do not guarantee completeness or compatibility and are not a diagnosis, safety certification, recall check, retailer endorsement, or substitute for current manufacturer and qualified professional guidance.
7. AI-assisted explanations
AI assistance is optional infrastructure for explaining already validated findings. When an explanation is eligible, Registry Rescue may send a pseudonymous commerce identifier and a bounded, sanitized claim ledger through a Registry Rescue Cloudflare service, Cloudflare AI Gateway, OpenRouter, and a selected model provider.
The bounded facts may include semantic context such as whether this is a first-time-parent context, whether multiples are expected, and a selected feeding-plan category. They can therefore be sensitive even when they do not include a name. Raw screenshots, raw registry OCR, registry URLs, product titles or descriptions, free-form registry text, and natural-identity fields are excluded from the provider prompt.
The selected provider or model can change after controlled validation. Registry Rescue requests restricted provider handling, but we do not promise a provider retention period that has not been independently verified. A successfully persisted explanation can remain locally available with its completed review. If AI is unavailable, the deterministic review remains usable.
8. Purchases and subscriptions
Apple processes App Store payment and account information. RevenueCat processes a pseudonymous App User ID, product and entitlement identifiers, and purchase/subscription lifecycle information needed to validate access, restore purchases, and show subscription state. Registry Rescue does not receive your full payment-card details from Apple.
Apple controls billing, subscription cancellation, and refund decisions. Buying Full Registry Pass does not automatically cancel an existing Weekly Registry Review subscription. Local deletion does not erase Apple purchase history or automatically delete Apple or RevenueCat commercial records.
9. Optional anonymous product analytics
Anonymous product analytics are optional, independent from purchasing, and off by default. When both the feature and your setting are active, PostHog may receive only allowlisted product-behavior events with bounded values and a random installation identifier.
Analytics exclude registry and review identifiers, screenshots, filenames, OCR, product titles or descriptions, retailer data, URLs, questions or notes, AI prompts and narratives, transaction IDs, email, and arbitrary free text. Autocapture, session replay, screen capture, advertising attribution, and error autocapture are disabled.
If enabled, the installation identifier can correlate allowlisted events across sessions and may be written as a RevenueCat attribute. Turning analytics off stops future capture but does not guarantee synchronous removal of already queued or provider-held records. The native RevenueCat-to-PostHog server integration remains disabled unless separately approved.
10. Third-party service providers
| Provider | Purpose and activation | Relevant data boundary |
|---|---|---|
| Apple | iOS, PhotosPicker, App Store commerce, optional App Attest | Selected-photo access, purchase lifecycle, device integrity |
| RevenueCat | App Store commerce and entitlement verification | Pseudonymous user ID, products, entitlements, purchase history |
| Cloudflare | Public website hosting; conditional AI gateway, rate limits, and security | Basic web/security request data and an essential anti-bot security cookie; conditional sanitized AI request and security state |
| OpenRouter and selected AI provider/model | Only for eligible, activated AI explanations | Sanitized semantic claim ledger; no raw registry media or text |
| PostHog | Only if analytics is available and you opt in | Allowlisted behavior events and random install identifier |
| Email provider | Only when you choose to email support | Your email address, message, and attachments you send |
These providers process data under their own terms and privacy practices. Registry Rescue does not claim an unverified data-processing agreement, zero-retention promise, or deletion right on their behalf.
11. Data retention
- Temporary screenshots: until confirmation, cancellation, deletion, or abandoned-file cleanup, generally within 24 hours for abandoned app-owned files.
- Local registry and review data: until you delete the registry, delete all local app data, or remove the app, subject to device backup behavior.
- Local AI artifacts: with the applicable review until registry or complete local deletion removes them.
- Conditional remote AI narrative artifact: designed for a 90-day expiry in Registry Rescue’s Cloudflare state; operational security, App Attest, entitlement, and quota records have different lifecycles and are not promised to disappear on local deletion.
- Commerce, analytics, website security, and support data:according to operational need, configured provider settings, and the providers’ applicable policies. A final retention setting is required before optional analytics activation.
12. Data deletion
Delete one registry
The per-registry action removes that registry and its associated local products, import evidence, deterministic reviews, re-check history, feedback, and locally persisted AI artifacts under the certified lifecycle. It does not reset the installation-level analytics identity and does not cancel an Apple subscription.
Delete all local app data
The complete deletion action removes local Registry Rescue records and app-owned temporary files and resets local analytics consent, dedupe, and installation identity state. A failed required cleanup is reported rather than presented as success.
Neither deletion path erases Apple purchase history, cancels a subscription, synchronously purges provider queues, or promises removal of provider commercial, security, abuse-prevention, or integrity records that the app cannot identify or control.
13. Privacy choices
You can:
- select only the screenshots you want to import;
- correct, remove, or manually add import items before saving;
- decline or disable anonymous product analytics in Settings;
- use deterministic review content when AI is unavailable;
- delete one registry or all local Registry Rescue data; and
- manage an Apple subscription separately through Apple.
See Privacy Choices for concise in-app instructions.
14. Security and abuse prevention
Registry Rescue uses app sandboxing, protected app-owned storage, path validation, local database isolation, bounded request contracts, and fail-closed feature configuration. For eligible remote AI requests, pseudonymous identifiers, App Attest material, rate limits, quotas, and entitlement checks may be processed to prevent abuse and verify access.
This public site has no account or consent wall and Registry Rescue code does not set a marketing or analytics cookie. The Cloudflare hosting edge may set an essential, HttpOnly bot-management cookie named __cf_bm for short-lived security and abuse prevention and may inject a same-origin Cloudflare challenge script under /cdn-cgi/challenge-platform/. Neither control is added by Registry Rescue application code or used by Registry Rescue for product analytics or advertising. Blocking or not retaining the cookie does not prevent the public policy and support pages from being requested, although Cloudflare may apply its own abuse checks.
No system is perfectly secure. Do not send sensitive registry content to the support email unless support specifically asks for the minimum necessary information.
15. Advertising and tracking
Registry Rescue does not use the IDFA, advertising attribution SDKs, cross-app advertising tracking, data-broker sharing, or targeted ads. The website contains no marketing analytics, advertising pixel, session replay, heatmap, chat widget, or marketing/tracking cookie. The essential Cloudflare security cookie described above is a hosting security control, not a Registry Rescue analytics identifier.
The current intended V1 architecture does not require an AppTrackingTransparency prompt. This determination must be revisited before any future tracking or advertising architecture change.
16. Children’s privacy
Registry Rescue is designed for expecting parents and other adults organizing a registry. It is not directed to children and is not designated as a Made for Kids app. Registry content may describe baby products or family context, but V1 does not offer a child account or ask a child to provide personal information.
If you believe a child has sent personal information through support, contact us so the issue can be reviewed. This policy does not invent an age threshold beyond applicable law or substitute for owner/legal review.
17. International and service-provider processing
Apple, RevenueCat, Cloudflare, OpenRouter, selected AI providers, PostHog, and email infrastructure may process data in countries other than where you live if the relevant feature is used. Their legal bases, transfer mechanisms, retention, and regional rights are governed by applicable law and their verified service terms; Registry Rescue does not invent contractual guarantees that have not been confirmed.
18. Changes to this policy
We may update this policy when the app, providers, legal requirements, or activation state changes. The updated page will show a new “Last updated” date. A material change to AI, analytics, commerce, tracking, or data use requires a new code-to-policy and App Store privacy review before release.
19. Contact
For privacy questions, contact Registry Rescue at owlyglobal@gmail.com. This is also the product support address; do not send more personal or registry information than needed.
The final legal publisher/controller name and postal address remain an owner confirmation required before App Store submission. No corporation or address is implied by the Registry Rescue product name.
For Apple’s current license terms, see the Apple Standard EULA (opens in a new tab).