Privacy
Privacy
This page explains the current implemented privacy boundaries in plain language.
Account and profile data
Znaide uses verified phone authentication. Profiles store display name, locale and onboarding state. The verified phone is read-only in Profile.
Circles, memberships and shared items
Circles are private. Circle members can see circle membership and active items shared with that circle. Drafts, archived items and owner-only items stay outside member catalogues.
Contact preferences
Contact preferences are self-only. Another member sees only enabled contact methods for an eligible item, and a target is resolved only after an explicit item-scoped choice.
Private item photos
Item photos are stored privately and delivered through an authenticated no-store route that rechecks authorization. They are not intentionally cached by the service worker or Next image optimizer.
Borrowing records
Borrowing records, borrower identity, notes and completed history are owner-private. Other catalogue viewers may see only the public Borrowed state. A linked borrower may see a minimal current Home relationship while the handoff is active.
Account deletion
Delete account removes your profile, owned items, memberships and verified owned private photo objects after active borrowings are resolved. Populated circles you own may require ownership transfer first. Other users' items/accounts are not deleted, and factual completed borrowing snapshots in another owner's private history may remain.
Invitations
Invitation links contain a raw token. The database stores only its hash and invite metadata. A valid token preview exposes only limited circle information before joining.
AI-assisted recognition
When an owner deliberately requests recognition, Znaide may send one normalized private photo and instructions to the configured AI provider with server-only credentials and no automatic retry. The owner reviews suggestions before publication.