Privacy Policy
Version 2.0 — 7 July 2026 (replaces Version 1.0 — May 2026)
1. Who We Are
TidyBox is a service for smart QR storage labels. It helps people and businesses label boxes, containers, shelves and other storage spaces, then view and manage their contents through https://tidybox.eu.
The data controller for personal data processed through TidyBox is RMX Tek Ltd (4 Sv. Ivan, A27, Bansko, Bulgaria 2770), a company registered in Bulgaria ("we", "us", "our"). You can reach us about anything in this policy at privacy@tidybox.eu.
We operate in the European Union and process personal data in accordance with Regulation (EU) 2016/679 (the General Data Protection Regulation, "GDPR") and applicable Bulgarian data protection law.
2. Data We Collect
- Account data: Email address, a securely hashed password (we never store passwords in plain text), display name, language preference, plan and subscription status. If you sign in with Google, we receive your name, email address and Google account identifier from Google.
- Content you upload: Photos of boxes, shelves and stored items, box and item names, descriptions, notes, locations and related inventory information, stored on our servers.
- Anonymous scanner identifier: A random identifier (tidybox_guest_id cookie) that links contributions made by visitors who scan a QR code without an account, used for editing continuity and abuse prevention.
- Technical data: IP address and browser/device information (user agent), used for security, rate limiting, anti-vandalism controls and abuse prevention.
- Cookies: See the cookie table at the end of this page for a complete list.
- Payment data: Payments are processed by Stripe. We never see or store your full card number. We store only your plan, subscription status and invoice/transaction metadata.
- Notification identifiers: Email address, Telegram chat ID and/or browser push subscription tokens — only for the notification channels you enable.
- API tokens: If you use the TidyBox API or MCP integration, we store the tokens you generate and basic usage logs.
- Consent records: Your cookie consent choice, together with a timestamp, session identifier and IP address, kept as legally required proof of consent.
- Support communications: Messages you send us and the contact details you provide with them.
3. Purposes and Legal Bases (Article 6 GDPR)
- Providing the service — storing and displaying your boxes, photos and item lists to you and to people you authorise: performance of a contract, Art. 6(1)(b).
- AI photo recognition — run only when you explicitly request it for a photo: performance of a contract at your request, Art. 6(1)(b). See section 4.
- Payments, invoicing and tax records: performance of a contract, Art. 6(1)(b), and compliance with legal obligations, Art. 6(1)(c).
- Notifications you enable (email, push, Telegram): performance of a contract, Art. 6(1)(b); you can disable them at any time.
- Security, rate limiting, abuse prevention and content moderation: our legitimate interests in keeping the service safe and lawful, Art. 6(1)(f).
- Analytics and marketing cookies (see section 8): your consent, Art. 6(1)(a), which you may withdraw at any time via "Cookie settings" in the footer.
- Keeping consent records: compliance with legal obligations, Art. 6(1)(c) and Art. 7(1) GDPR.
4. AI-Assisted Photo Recognition
TidyBox can suggest item names from a photo. This happens only when you explicitly press the recognition button for a specific photo — we do not run AI analysis on your photos in the background.
- The photo is transmitted to Google Gemini API (Google) for recognition; if that fails, to Anthropic Claude API (Anthropic) as a fallback.
- Text content may be screened with the OpenAI Moderation API, and images may be screened with Google Gemini, to detect content that violates our Terms of Use.
- Under the commercial API terms of these providers in force at the date of this policy, content submitted via their APIs is not used to train their models.
- AI output is a suggestion only. You review, correct and approve the final content. TidyBox makes no automated decisions producing legal or similarly significant effects about you (Art. 22 GDPR).
- Please do not photograph people, faces, documents or other sensitive materials for recognition — the feature is designed for household and business items only.
5. Processors and Recipients
We share personal data only with processors needed to run specific parts of the service, under data processing agreements, and only for the purposes listed:
- Hosting provider (EU): Server infrastructure where your account data, content and photos are stored.
- Google (Google Ireland Ltd / Google LLC, USA): AI photo recognition (Gemini API), optional Google Sign-In, and — only with your consent — Google Analytics (see section 8).
- Anthropic PBC (USA): AI photo recognition fallback.
- OpenAI LLC (USA): Text content moderation.
- Stripe (Stripe Payments Europe Ltd, Ireland / Stripe Inc., USA): Payment processing and invoicing.
- Resend (Resend Inc., USA): Transactional email delivery.
- Telegram (Telegram FZ-LLC, UAE): Bot notifications — only if you link Telegram yourself.
- Meta Platforms Ireland Ltd: Advertising measurement (Meta Pixel) — only if enabled and only with your marketing consent (see section 8).
We do not sell personal data and we do not share it with third parties for their own independent marketing.
6. International Transfers
Some processors listed above are located in, or may transfer data to, countries outside the European Economic Area, in particular the United States. Where this happens, we rely on:
- the EU–US Data Privacy Framework for providers certified under it (this currently includes Google, Anthropic, OpenAI, Stripe and Meta), and/or
- the European Commission's Standard Contractual Clauses with supplementary measures where needed.
Telegram notifications are sent through Telegram's infrastructure only if you actively link a Telegram account; the data transferred is limited to your chat ID and the notification text, and the transfer is necessary to perform the notification service you request (Art. 49(1)(b) GDPR where no other safeguard applies).
7. Cookies and Similar Technologies
We use a small number of essential cookies to operate the service, plus — only with your consent — analytics and marketing cookies. A complete, up-to-date table of the cookies we set, their purpose, type and duration is shown at the end of this page.
Essential cookies (session, language, guest identifier, consent choice) are strictly necessary and do not require consent. Analytics and marketing cookies are set only after you opt in via the consent banner. You can change or withdraw your choice at any time via the "Cookie settings" link in the page footer; withdrawing is as easy as consenting.
8. Analytics and Advertising Tools
Google Analytics 4 (Google Ireland Ltd): When enabled on the site, Google Analytics runs only after you consent to analytics cookies. We configure Google Consent Mode v2 so that all analytics and advertising storage is denied by default and enabled only by your choice. Google Analytics uses cookies (e.g. _ga) and collects pseudonymous usage statistics; data may be transferred to the USA under the Data Privacy Framework.
Meta Pixel (Meta Platforms Ireland Ltd): When enabled on the site, the Meta Pixel runs only after you consent to marketing cookies. It helps us measure the effectiveness of advertising campaigns. For data collected via the Pixel, Meta and we may act as joint controllers for the collection and transmission of event data; Meta's processing is described in its own privacy policy.
If you do not consent, these tools are not loaded at all, and no analytics or advertising cookies are set. We may additionally use privacy-friendly aggregate statistics that do not use cookies and do not identify you.
9. Open-Code Model Notice
Before a TidyBox code is claimed by a registered user, anyone who scans it can view, add or edit its contents. This is a documented design feature that allows use without an account. It also means:
- Do not store personal or sensitive information in unclaimed boxes.
- Contributions from anonymous scanners are linked to a random guest identifier and IP address solely for editing continuity and abuse prevention.
- Once a code is claimed, access is controlled by the owner through privacy and sharing settings.
10. Data Retention
- Photos and content: Retained until you delete them or reset the box/code.
- Account data: Retained while your account exists; after a deletion request, removed within 30 days except where law requires longer retention.
- Rate-limit counters: Retained for 24 hours.
- Security and operational logs: Retained for up to 30 days.
- Consent records: Retained for 3 years as proof of consent (legal obligation).
- Payment and invoice records: Retained for the period required by tax and accounting law (up to 10 years in Bulgaria).
- Backups: Deleted data disappears from rotating backups within 35 days at the latest.
11. Security
We protect personal data with technical and organisational measures appropriate to the risk, including TLS encryption in transit, password hashing, access controls, upload screening and audit logging. No online service can guarantee absolute security, but in the event of a personal data breach likely to result in a risk to your rights, we will notify the supervisory authority within 72 hours and, where the risk is high, notify you directly, as required by Articles 33 and 34 GDPR.
12. Your Rights (GDPR)
You can exercise any of these rights by writing to privacy@tidybox.eu. We respond within one month.
- Access — receive a copy of the personal data we hold about you (Art. 15).
- Rectification — have inaccurate data corrected (Art. 16).
- Erasure — have your data deleted ("right to be forgotten", Art. 17). You can also delete your account and content directly in the app.
- Restriction — restrict processing in the situations set out in Art. 18.
- Portability — receive your data in a structured, commonly used, machine-readable format (Art. 20).
- Objection — object to processing based on legitimate interests (Art. 21).
- Withdraw consent — at any time, without affecting prior processing (Art. 7(3)); for cookies, use "Cookie settings" in the footer.
- Complain — to the Bulgarian Commission for Personal Data Protection (CPDP, www.cpdp.bg) or the supervisory authority in your EU country of residence (Art. 77).
13. Children
TidyBox is not directed at children and is intended for users aged 16 or over. We do not knowingly collect personal data from children under 16. If you believe a child has provided us personal data, contact us and we will delete it.
14. Changes to This Policy
We will notify registered users of material changes by email before they take effect. The current version and date are indicated at the top of this page. Earlier versions are available on request.
15. Contact
RMX Tek Ltd, Bulgaria
Privacy requests: privacy@tidybox.eu · Legal notices: legal@tidybox.eu · Abuse reports: abuse@tidybox.eu
Registered address: Sveti Ivan St. 4, A-27, 2770 Bansko, Bulgaria
Cookies
This site uses the following cookies:
| Cookie name |
Purpose |
Type |
Duration |
| PHPSESSID |
User authentication |
Essential |
Browser session |
| lang |
Interface language |
Essential |
1 year |
| tidybox_guest_id |
Anonymous identification of guests who scan codes and edit unclaimed boxes |
Essential |
1 year |
| consent_choice |
Stores your cookie consent choice |
Essential |
1 year |
| _ga, _ga_* |
Google Analytics — anonymous usage statistics (only with your consent) |
Analytics (consent) |
2 years |
| _fbp |
Meta Pixel — advertising measurement (only with your consent) |
Marketing (consent) |
3 months |