Legal

Privacy Policy

Last updated: August 31, 2026

Every sentence here is checked against what the app actually does. Where WORN sends something off your device, this says so plainly, including the parts that are less flattering.

Who we are

WORN is a watch collection app made by Rishab Gupta, trading as Arthex. This policy covers the iOS app and this website. If you want to ask about anything in it, write to rishab0611@gmail.com.

What stays on your device

Your watches, wear sessions, journal entries, style pairings, wishlist, Credit history, saved try-on renders and heartbeat recordings live on your phone, in the app's own store. If iCloud sync is on, they also go to the private database of your Apple Account, which belongs to you. We are not a party to that. We cannot read it.

Heartbeat audio never leaves the device. The 30-second recording of your movement is analysed on your phone and stored there, and is not uploaded to us or to anyone else. The accounts you block in the community are remembered on your device only, so we never learn who you have blocked.

The app also keeps a week of rotating diagnostic logs on the device, which can contain a watch name. They stay there. Nothing sends them anywhere unless you use Export Diagnostic Logs in Profile and choose where to share them yourself.

What leaves your device, and when

  • Photos, when you use an AI feature. Identifying a watch, matching an outfit, logging a wrist check, or rendering a try-on sends that photo to Google Gemini through our server, which returns the result. Each of those is something you tap, so no photo goes without a deliberate action, whether or not the action costs Credits. You can also switch AI Photo Analysis off in Settings, and then no photo is sent from anywhere in the app.
  • Watch details, when an AI feature is answering about one. The prompt behind a valuation, a pairing, a journal reflection or an accuracy insight contains the brand, model and reference of the watch it is about. Text-only requests like these are not covered by the AI Photo Analysis switch, because that switch is about photographs.
  • Your brand list, when you open Community. Collector Talk searches public forums for the brands you own, so those brand names go to Reddit. It happens on opening the tab, before you tap anything, which we should have gated better. Turning off Collector Insights in Settings stops it.
  • A photo and caption, when you post to the Showcase. Covered in its own section below.
  • Usage and crash data, always. Analytics events and, in App Store builds, crash reports. Neither has an off switch in the app today.
  • A catalogue file, once a day. The swipe deck downloads a slice of the watch catalogue. It is a plain download and sends nothing about you.

Every service we use

This is the complete list. If a company is not named here, WORN does not send it anything.

Apple

Apple iCloud (CloudKit) Syncs your collection between your own devices. The data lands in the private database of your Apple Account. We have no access to it and cannot read what is in it. You can turn WORN's iCloud sync off in the iOS Settings app.
Apple App Store (StoreKit) Handles every payment. Apple tells the app what was bought and never gives us your card details, billing address, or name.
Sign in with Apple Gives us an account identifier and, only if you allow it, an email address. Our server also exchanges Apple's one-time authorisation code for a refresh token, which it stores against your account. That token exists so that deleting your account can actually revoke WORN's access with Apple rather than just forgetting it locally.
App Store Server API Our server sends a StoreKit transaction identifier to Apple to confirm a purchase really happened before Credits are granted.

Google

Firebase Authentication Turns your Apple or Google sign-in into a WORN account identifier. Receives the identity token from whichever provider you used, and your email address if that provider shared it.
Cloud Firestore Our database. Holds your account record (display name, @handle, avatar colour, referral code, Credit balance), your Credit ledger entries, Showcase posts and their captions, moderation reports you file, and messages you send through the in-app feedback form.
Cloud Storage for Firebase Stores the photo attached to a Showcase post. It also serves the watch catalogue the swipe deck reads, and app artwork. Nothing else you photograph is uploaded here.
Cloud Functions for Firebase Our server code. Every AI request, referral redemption, handle claim, Credit ledger write, and account revocation passes through it. Its logs record what kind of request was made, which model answered, how long it took and how many bytes moved. They do not record your prompts, your photos, your captions, or your email address.
Firebase Crashlytics Crash and error reports, in App Store builds only. A report carries the stack trace, a short diagnostic log of what the app did beforehand (which can contain a watch name), your device model and OS version, and three numbers we attach on purpose: how many watches you own, whether you are signed in, and your Credit balance. There is no way to switch this off inside the app.
Firebase App Check (App Attest) Asks Apple's App Attest service to confirm this is a genuine copy of WORN before the server answers it. Runs at launch. Carries no information about you.
Google Sign-In Only if you choose to sign in with Google. Returns your Google account identifier, email address and profile name.
Google Gemini API Every AI feature. Receives the photo you just took and the prompt built around it, which contains details of the watch in question: brand, model, reference, and for a valuation your region's currency. It also screens Showcase photos and captions for unsafe or off-topic content before anyone else can see them. Google processes the request and returns the answer. Neither we nor Google keep the image afterwards. See Google's AI terms.
Google Search Identifying an unusual watch runs the Gemini request with live web search attached, so the model can look the piece up instead of guessing. The search terms are the watch details in the prompt.
Google Cloud Vertex AI When adding a watch we cannot match by name, the cropped picture of the watch is turned into a numeric fingerprint so it can be compared against the catalogue. The fingerprint, not the photo, is what gets stored.

Other companies

RevenueCat Reconciles what you bought with what the app unlocks: Credit packs, WORN Premium, restores and refunds. Receives your App Store transaction history, your WORN account identifier, and your device and OS. Never your payment details.
TelemetryDeck Usage analytics: which features get used, how often, and where people drop out of a flow. Some of those events carry the brand of a watch you add, edit, archive or delete. They never carry the model, the reference, your photos, your notes, or what anything is worth. TelemetryDeck hashes the device identifier before it is sent. Like crash reporting, there is currently no switch for this in the app.
Buttondown Our mailing list. Receives your email address, and only if you type it in and tap subscribe.
Reddit Collector Talk shows public forum posts filtered to the brands you own. To do that, the app sends the list of brand names in your collection to Reddit's public search, along with your IP address as any web request would. No account, handle, photo or other collection detail goes with it. Turn Collector Insights off in Settings and nothing is sent.
Wikidata Looks up movement and caliber specifications. Receives the brand and model of the watch being looked up. Only runs when you ask the app to fill in caliber specs.

Images and outbound links

Watch catalogue images Catalogue photos are loaded from the retailers and databases that host them, mainly cdn.watchbase.com, img.chrono24.com, static.helioswatchstore.com, cdn2.jomashop.com, citizenwatch.widen.net, seikowatches.com and orientwatchusa.com. Those hosts see your IP address and which watch image was requested, the same as any image on any web page. They receive nothing from your collection.
Pexels A handful of stock photographs and background videos used as illustration in the app are loaded from images.pexels.com. Nothing about you is sent.
Chrono24, eBay and Amazon The Where to Buy links. Nothing is sent until you tap one, and then it opens in your browser as an ordinary search for that watch. Some of these links can carry an affiliate tag, which means we may earn a commission if you buy. It never changes what you pay.

What you post to the Showcase

Submitting a post uploads that photo to our storage and writes the caption, tags, watch reference, your @handle and your account identifier to our database. Before anyone sees it, the image and caption are screened automatically by Gemini for unsafe or off-topic content. Once approved, the post is public: it can be read by anyone, not only by other WORN users.

Two things you should know before you post. The uploaded image sits at a public web address from the moment it is uploaded, including while it is waiting to be screened and even if it is then rejected. And the app currently gives you no way to delete a post you have made. If you want a post and its photo removed, email us and we will do it by hand. Both of these are being fixed.

Purchases and Credits

Credit packs and WORN Premium are billed by Apple. We are told what was bought and when, through the App Store and through RevenueCat, and we are never told how you paid. Your Credit balance lives on your device and in your private iCloud. Individual Credit entries are also sent to our server, along with the App Store transaction identifier, so that a purchase or a referral bonus can be checked against the store rather than taken on trust. Those entries are readable by us. Checking them is the reason they are sent.

Redeeming a referral code also sends a one-way hash of your device identifier. It exists to stop one person claiming the same bonus on a stack of fresh accounts. It cannot be turned back into the identifier, and we never see the identifier itself.

The feedback form

Sending feedback from the Profile screen writes your message to our database along with the app version and build, your device model, your OS version and your locale. Those five are listed on the screen before you tap send. Your account identifier is attached too, so we can reply through the app, and your email address only if you choose to type one in. No photo and nothing from your collection is attached.

What we never collect

  • Your location. WORN never asks for it and has no location code.
  • Your contacts, calendar, health data or photo library at large.
  • Any advertising identifier. There are no ads, no ad networks, and no cross-app tracking, so the app never shows the App Tracking Transparency prompt.
  • Your watch photos, journal entries, wear history or valuations, other than the moment an AI feature you asked for is answering about them.
  • Your heartbeat recordings.
  • Your payment details.

Deleting your data

Deleting the app removes everything held on the device. What is in your iCloud is managed from your device's iCloud settings, under WORN.

Delete Account in the Profile screen signs you out and, for an account created with Apple, asks our server to revoke WORN's access with Apple and delete your account record. Being honest about the limits: for an account created with Google it currently only disconnects the app locally and does not delete anything on our server. In neither case does it yet remove your Credit ledger, your Showcase posts and their photos, your @handle reservation, or your referral record.

Until that is complete, email rishab0611@gmail.com from the address on your account, or with your @handle, and we will delete all of it by hand and confirm when it is done. You have the right to ask for a copy of what we hold, or for it to be corrected or erased, at that same address.

How long we keep things

Showcase posts and their photos stay until removed. Account records, Credit ledger entries and referral records stay for as long as the account exists, and Credit entries are kept afterwards where we need them as a record of a purchase. Crash reports and analytics are retained by Crashlytics and TelemetryDeck on their own schedules. Feedback messages are kept until they are dealt with. Watch entries you contribute to the shared catalogue that nobody else ever confirms are deleted automatically after 14 days.

Where your data goes

Our Firebase project and its Cloud Functions run in the United States, and the services above are operated by companies in the United States and the European Union. If you use WORN from elsewhere, your data is transferred and processed there.

Children

WORN is not for children under 13, and the Showcase is not for anyone under 16. We do not knowingly collect anything from a child under 13. If you believe a child has given us data, write to us and we will delete it.

Changes to this policy

When the app changes what it sends, this page changes with it, and the date at the top moves. Continued use of the app after a change means you accept the revised policy.

Contact

Questions about your privacy, or a deletion request, go to rishab0611@gmail.com. We read every message.