Legal
Privacy Policy
Every sentence here is checked against what the app actually does. Where WORN sends something off your device, this says so plainly, including the parts that are less flattering.
Who we are
WORN is a watch collection app made by Rishab Gupta, trading as Arthex. This policy covers the iOS app and this website. If you want to ask about anything in it, write to rishab0611@gmail.com.
What stays on your device
Your watches, wear sessions, journal entries, style pairings, wishlist, Credit history, saved try-on renders and heartbeat recordings live on your phone, in the app's own store. If iCloud sync is on, they also go to the private database of your Apple Account, which belongs to you. We are not a party to that. We cannot read it.
Heartbeat audio never leaves the device. The 30-second recording of your movement is analysed on your phone and stored there, and is not uploaded to us or to anyone else. The accounts you block in the community are remembered on your device only, so we never learn who you have blocked.
The app also keeps a week of rotating diagnostic logs on the device, which can contain a watch name. They stay there. Nothing sends them anywhere unless you use Export Diagnostic Logs in Profile and choose where to share them yourself.
What leaves your device, and when
- ●Photos, when you use an AI feature. Identifying a watch, matching an outfit, logging a wrist check, or rendering a try-on sends that photo to Google Gemini through our server, which returns the result. Each of those is something you tap, so no photo goes without a deliberate action, whether or not the action costs Credits. You can also switch AI Photo Analysis off in Settings, and then no photo is sent from anywhere in the app.
- ●Watch details, when an AI feature is answering about one. The prompt behind a valuation, a pairing, a journal reflection or an accuracy insight contains the brand, model and reference of the watch it is about. Text-only requests like these are not covered by the AI Photo Analysis switch, because that switch is about photographs.
- ●Your brand list, when you open Community. Collector Talk searches public forums for the brands you own, so those brand names go to Reddit. It happens on opening the tab, before you tap anything, which we should have gated better. Turning off Collector Insights in Settings stops it.
- ●A photo and caption, when you post to the Showcase. Covered in its own section below.
- ●Usage and crash data, always. Analytics events and, in App Store builds, crash reports. Neither has an off switch in the app today.
- ●A catalogue file, once a day. The swipe deck downloads a slice of the watch catalogue. It is a plain download and sends nothing about you.
Every service we use
This is the complete list. If a company is not named here, WORN does not send it anything.
Apple
Other companies
Images and outbound links
What you post to the Showcase
Submitting a post uploads that photo to our storage and writes the caption, tags, watch reference, your @handle and your account identifier to our database. Before anyone sees it, the image and caption are screened automatically by Gemini for unsafe or off-topic content. Once approved, the post is public: it can be read by anyone, not only by other WORN users.
Two things you should know before you post. The uploaded image sits at a public web address from the moment it is uploaded, including while it is waiting to be screened and even if it is then rejected. And the app currently gives you no way to delete a post you have made. If you want a post and its photo removed, email us and we will do it by hand. Both of these are being fixed.
Purchases and Credits
Credit packs and WORN Premium are billed by Apple. We are told what was bought and when, through the App Store and through RevenueCat, and we are never told how you paid. Your Credit balance lives on your device and in your private iCloud. Individual Credit entries are also sent to our server, along with the App Store transaction identifier, so that a purchase or a referral bonus can be checked against the store rather than taken on trust. Those entries are readable by us. Checking them is the reason they are sent.
Redeeming a referral code also sends a one-way hash of your device identifier. It exists to stop one person claiming the same bonus on a stack of fresh accounts. It cannot be turned back into the identifier, and we never see the identifier itself.
The feedback form
Sending feedback from the Profile screen writes your message to our database along with the app version and build, your device model, your OS version and your locale. Those five are listed on the screen before you tap send. Your account identifier is attached too, so we can reply through the app, and your email address only if you choose to type one in. No photo and nothing from your collection is attached.
What we never collect
- ✕Your location. WORN never asks for it and has no location code.
- ✕Your contacts, calendar, health data or photo library at large.
- ✕Any advertising identifier. There are no ads, no ad networks, and no cross-app tracking, so the app never shows the App Tracking Transparency prompt.
- ✕Your watch photos, journal entries, wear history or valuations, other than the moment an AI feature you asked for is answering about them.
- ✕Your heartbeat recordings.
- ✕Your payment details.
Deleting your data
Deleting the app removes everything held on the device. What is in your iCloud is managed from your device's iCloud settings, under WORN.
Delete Account in the Profile screen signs you out and, for an account created with Apple, asks our server to revoke WORN's access with Apple and delete your account record. Being honest about the limits: for an account created with Google it currently only disconnects the app locally and does not delete anything on our server. In neither case does it yet remove your Credit ledger, your Showcase posts and their photos, your @handle reservation, or your referral record.
Until that is complete, email rishab0611@gmail.com from the address on your account, or with your @handle, and we will delete all of it by hand and confirm when it is done. You have the right to ask for a copy of what we hold, or for it to be corrected or erased, at that same address.
How long we keep things
Showcase posts and their photos stay until removed. Account records, Credit ledger entries and referral records stay for as long as the account exists, and Credit entries are kept afterwards where we need them as a record of a purchase. Crash reports and analytics are retained by Crashlytics and TelemetryDeck on their own schedules. Feedback messages are kept until they are dealt with. Watch entries you contribute to the shared catalogue that nobody else ever confirms are deleted automatically after 14 days.
Where your data goes
Our Firebase project and its Cloud Functions run in the United States, and the services above are operated by companies in the United States and the European Union. If you use WORN from elsewhere, your data is transferred and processed there.
Children
WORN is not for children under 13, and the Showcase is not for anyone under 16. We do not knowingly collect anything from a child under 13. If you believe a child has given us data, write to us and we will delete it.
Changes to this policy
When the app changes what it sends, this page changes with it, and the date at the top moves. Continued use of the app after a change means you accept the revised policy.
Contact
Questions about your privacy, or a deletion request, go to rishab0611@gmail.com. We read every message.