Saro

Privacy Policy

Effective date: TBD (App Store go-live)

1. Who we are

Vitrus BV, a private limited company organized under the laws of Belgium, with registered office at Vossekotstraat(Z) 117, 3271 Scherpenheuvel-Zichem, registered with the Crossroads Bank for Enterprises under number 0785.610.126 ("we," "us," or "our") operates the Saro iOS application (the "App") and the public collection viewer at https://saro.gallery (the "Website," and together with the App, the "Service" or "Saro") and acts as the controller of your personal data.

This Privacy Policy explains what information we process when you use the Service, for what reason, and what rights you have. This policy applies to all users of the Service.

2. The short version

3. Scope of the Privacy Policy

This privacy policy (hereinafter "Privacy Policy") applies to you for your personal data that we collect and process through Saro. It contains important information on how and for what purposes we collect and process personal data and clarifies which rights you can exercise as a data subject. Therefore, please read this Privacy Policy carefully.

We are committed to protecting your (personal) data with the utmost care and to process it only in a fair and lawful manner in accordance with the provisions of the GDPR (Regulation (EU) 2016/679), including any current national or international act or regulation in execution or future act or regulation in replacement of the GDPR (hereinafter together referred to as "Applicable Data Protection Law").

4. Information we process

4.1 Personal data

Personal data can be defined as any information by which a natural person can be directly or indirectly identified. You may provide us with your personal data in the context of the following activities, for the corresponding purposes and based on the stated legal basis:

Contact form / correspondence

Device identifier (random UUID)

Name (optional)

In-app preferences

The following categories apply to anyone who opens a share link, whether or not you use the Saro app. When you open a link, our hosting provider processes the technical data needed to deliver the page and to keep the Service secure, and we count the number of views for the benefit of the person who created the link. We do not identify individual visitors and we do not tell the person who created the link who has viewed it.

Delivering the shared collection page

Aggregated view counts

Cookies and similar technologies

We do not use cookies or similar technologies on saro.gallery.

4.2 Other information

We also process other information through our app, such as:

Non-personal information you choose to put into Saro

Information processed by AI features

When you tap an AI feature (Identify and value, value refresh, suggest fields with AI, draft listings, bulk-draft listings), the relevant inputs are sent to our AI provider, Anthropic, for inference. Specifically:

Each AI request includes the device identifier so our backend can apply per-installation rate limits. We do not store the photo or text content of these requests on our own infrastructure beyond what is needed to return the response.

Information processed when you opt in to cloud backup

If you enable Cloud Backup in Settings, Saro periodically uploads a ZIP archive of your collection (items, categories, photos as bytes) to a private Supabase Storage bucket. The associated metadata record stores the device identifier, the item and photo count, the backup size in bytes, the Saro app version, and the timestamp of the upload.

Only the most recent backup is retained: each upload replaces the previous one. The archive is accessible only via short-lived signed URLs minted by our backend on request from the same device identifier.

You can delete your cloud backup at any time via Settings → Data → Delete cloud backup. Doing so removes both the backup zip and the associated metadata record from our infrastructure. Your on-device collection is untouched.

Information processed when you publish a share link

When you tap "Share this collection" in Settings, Saro creates a public, read-only snapshot of your collection (limited to the fields and items you have on the device) and stores it in our database keyed to a random 8-character token. The link expires automatically thirty (30) days after creation. You can revoke a share link at any time before the 30-day expiry via Settings → Data → Manage sharing; the URL stops working immediately for anyone still holding it.

5. How we use this information

We use the information (including personal data) you have uploaded for the following purposes:

6. Third-party service providers

We use the following processors to deliver the Service. Each acts as a data processor on our behalf under a written agreement, and (where applicable) we rely on the EU Standard Contractual Clauses or equivalent transfer mechanisms for international transfers. See also section 12.

6.1 Anthropic

6.2 Supabase

6.3 Apple

6.4 RevenueCat

7. What we do NOT do

8. Data retention

9. Your rights

Subject to the conditions and limitations set out under Applicable Data Protection Law, you may exercise the data subject rights set out below.

To exercise any of these rights, contact us at [email protected]. Because Saro does not require an account, the easiest way for us to find your cloud-backup or share-link records is for you to also include the device identifier shown in Settings → About → Diagnostics. Without that identifier, we may be unable to locate your records.

Subject to legitimate exceptions under Applicable Data Protection Law, we undertake to respond to your request within one month of receipt. We may first request additional information to confirm your identity and ensure that the request comes from you.

9.1 Right of access to your personal data

The right to request access to your personal data, to request a copy of the personal data that we collect about you, and to additional information on how we process your personal data.

9.2 Right to rectification

The right to have incorrect personal data corrected or incomplete personal data we hold about you completed.

9.3 Right to data erasure ("right to be forgotten")

The right to have your personal data deleted from our systems.

The request to erase your personal data cannot always be granted due to e.g. contractual or legal obligations. We will observe these obligations when responding to your request.

9.4 Right to object

The right to object to the processing of your personal data if the processing is based on our legitimate interest or on grounds of public interest. We will stop processing unless we can demonstrate compelling legitimate grounds for further processing or for the exercise of legal claims.

You may also object in case we process your data for direct marketing purposes, so that personal data will no longer be processed for these purposes.

9.5 Right to withdraw your consent

For the processing of your personal data collected by us with your consent, you may withdraw your consent at any time. However, withdrawing your consent does not affect the lawfulness of the processing based on consent before its withdrawal.

9.6 Right to restriction of processing

In certain cases, you have the right to obtain the restriction of the processing of your personal data. If you successfully exercise this right, we will continue to store your data, but we will limit its use. For example, you can make this request if you believe your personal data is inaccurate or if the processing by us is not justified. We only have to fulfil these requests in specific cases, as stipulated by law.

9.7 Right to data portability

The right to obtain the personal data concerning you processed by us in a structured, commonly used and machine-readable format and/or to have such data transmitted or copied to another controller.

9.8 Right to lodge a complaint

If you believe that we are infringing your data protection rights, you have the right to lodge a complaint with the Belgian Data Protection Authority: Data Protection Authority, Rue de la Presse 35, 1000 Brussels, Tel +32 (0) 2 274 48 00, e-mail: [email protected].

10. Security

11. Children

You must be at least 13 to use Saro, and at least 18 to enter into our Terms of Service. If you are under 18, you may use Saro with the involvement and consent of a parent or guardian, who is responsible for your use of the Service. Users under 18 cannot publish a share link.

Where a parent or guardian consents on behalf of a child, we rely on that consent and will make reasonable efforts to verify it. If you believe a child has provided us with personal data without the required consent, contact us at [email protected] and we will delete it.

12. International transfers

Some of our processors (Anthropic, Supabase, Apple, RevenueCat) may process your information outside the EEA, the UK, or your country of residence. We will comply with Applicable Data Protection Law in terms of providing adequate protection for the transfer of personal data to recipients in countries outside of the European Economic Area ("EEA").

In case we transfer your personal data to a third country or international organization outside the EEA, we will make sure that your personal data is either transferred to third countries that are deemed to be offering an "adequate" level of protection by the European Commission, or, alternatively, where your personal data is not sent to a country that provides an adequate level of protection, we will put in place appropriate safeguards with the entity receiving your personal data (e.g. the EU standard contractual clauses or binding corporate rules, taking into account additional requirements regarding international transfers such as supplementary measures) to ensure that your personal data remains protected in accordance with Applicable Data Protection Law.

If you wish to receive more information or a copy of these safeguards, please contact us at [email protected].

13. Retention of your personal data

We will retain your personal data for no longer than is strictly necessary to fulfil the purposes for which we received the data. The retention periods differ in terms of the type of processing activity and the purpose for which the personal data was collected.

Personal data that we collect based on your consent is retained by us for as long as your consent remains valid.

In all cases, personal data may be retained for a longer period if there is a legal or regulatory reason to do so, or for a shorter period if you object to the processing of your personal data and there is no longer a legitimate reason to retain it. We guarantee that your personal data will be deleted or anonymised once the retention period has expired.

If you wish to receive more information about the retention periods we apply, please contact us at [email protected].

14. Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices regarding the processing of your personal data or changes in applicable law. We will do so by posting the updated version on the App. If we make material changes, we will notify you in-App or by another reasonable means before the change takes effect, and we will update the Effective Date at the top of this document.

15. Contact us

Questions, requests, or complaints about this Privacy Policy: