Privacy Policy
Effective date: July 12, 2026 · Last updated: September 23, 2026 (how a specialist can learn of an item you would consider selling — §2, §6)
Joseph Lint, doing business as Heirloom ("Heirloom," "we," "us," or "our") operates the Heirloom mobile and web application (the "App" or "Service"), which helps you photograph, identify, value, catalogue, and plan the inheritance of art, antiques, and collectibles using artificial intelligence and, where you choose, connections to independent expert businesses.
This Privacy Policy explains what personal information we collect, how we use it, who we share it with, how long we keep it, and the choices and rights you have. Please read it together with our Terms of Service.
By using Heirloom, you agree to the collection and use of information as described in this Policy. If you do not agree, please do not use the App.
1. Who we are
Heirloom is provided by Joseph Lint, doing business as Heirloom, located at 21716 Lakeshire, Saint Clair Shores, MI 48081, USA. For any privacy question, or to exercise your rights, contact us at hello@heirloomapp.io.
If you are in the European Economic Area (EEA), the United Kingdom, or Switzerland, our representative / Data Protection contact is hello@heirloomapp.io (we have not appointed a formal EEA/UK representative or Data Protection Officer).
2. Summary — the short version
- We collect the information you give us (your account details, the photos and descriptions of your items, and any estate-planning information you enter) and some technical information about your device.
- To identify and value your items, we send your item photos and descriptions to third-party artificial-intelligence and image-search providers (currently OpenAI, plus reverse-image and market-research search services). AI results are estimates, not professional appraisals.
- If you ask us to connect you with an expert (an appraiser, dealer, gallery, or auction house), we share a snapshot of that item — including its photos — with the businesses we match you to.
- If you say you would consider selling an item, specialists in its field may see a short card about it — never your name, photos, value or address — and nothing more is shared unless you accept an introduction. Heirloom does not list or sell anything.
- We use a privacy-friendly analytics tool (TelemetryDeck) and send email and push notifications through service providers.
- We do not sell your personal information, and we do not use it for cross-app advertising.
- You can access, export, and delete your data from within the App.
The rest of this Policy gives the detail.
3. Information we collect
3.1 Information you provide
Account and profile information. When you create an account we collect your email address and a password, or, if you use Sign in with Apple or Sign in with Google, the identity information those services return to us. You may also add a name, username, phone number, profile photo (avatar), bio, and preferences (language, currency, measurement and date formats, and privacy settings).
Your item content. This is the heart of the Service. For each object you catalogue we collect:
- Photographs of the item (taken with your camera or selected from your library);
- Descriptions and notes, including text you dictate by voice (see Section 4);
- Details such as title, artist/maker, period, material, condition, dimensions, provenance, serial or model number, tags, acquisition date, purchase price, value estimates, related links, and any custom fields;
- The physical location of the item if you record it (for example "home," "storage unit," or a specific address, which may include a street address and, if you enter it, precise coordinates);
- File attachments you upload, such as receipts, certificates, insurance documents, or voice notes.
Estate-planning information. If you use our estate-planning features, you may provide personal information about other people, including:
- Beneficiaries (name, relationship to you, email, phone, and notes);
- Your attorney and executor (names and contact details);
- Estate-sharing list (the email address and role you record; no access is granted from this list in the current version);
- Bequests (which items you designate to which beneficiaries) and related notes and reminders.
Because this information concerns other individuals, you are responsible for having a lawful basis to provide it to us and, where required, for informing those individuals (see Section 12).
Expert-lead and messaging content. When you request help from an expert business, we collect the request type and any note you write, and we store the messages exchanged between you and that business through the App.
Community content. Comments, community-group posts, likes, reports, personal contacts you add to your directory, insurance-policy details you record, and any collections you choose to make public or share.
Payment information (future). Paid subscriptions are not yet active. When they launch, payments will be processed by Stripe, and Stripe — not Heirloom — will handle your card details. We would then store only limited billing status information (such as plan and subscription state).
3.2 Information we collect automatically
- Device and technical data: IP address, user-agent/browser and device type, and, for push notifications, a device push token and your platform (iOS/Android/web).
- Security and login data: login method, success/failure, approximate location derived from your IP address, the devices signed in to your account, and an activity log of key actions you take in the App.
- Usage/analytics data: through TelemetryDeck we record a small set of product events (for example, sign-up, completing onboarding, saving or analysing an item) together with a coarse item-category label. Your user identifier is hashed on your device before it is sent. We do not send your photos, item descriptions, or other free text to our analytics provider.
3.3 Information from third parties
- Apple and Google provide identity information when you use their sign-in options.
- Independent expert businesses in our network may have profiles containing their own publicly available business contact information, some of which is sourced from public directories.
We do not knowingly collect precise financial account numbers, government identifiers, or special-category data beyond what you voluntarily enter in free-text fields.
4. How artificial intelligence and voice features work
AI identification and valuation. To identify and estimate the value of your items, we send the relevant item photos and descriptive text to third-party AI providers. Today we use OpenAI for image analysis and for the in-app research/advisor chat. For finding comparable sales, we submit the item's image and text queries to reverse-image and market-research search services (which may route to search engines such as Google). We may in the future use additional AI providers (for example Anthropic); if we do, they will receive the same categories of item data for the same purpose, and we will update this Policy.
Voice capture. When you dictate a description, your speech is transcribed to text. Depending on your device, transcription happens on the device using the operating system's speech recognition (which, on Apple and Google devices, may transmit audio to Apple or Google for processing under their own privacy policies) and/or through our backend using OpenAI's Whisper transcription service. Where audio is sent for transcription, the audio file is deleted immediately after transcription and only the resulting text is retained.
Please note: AI-generated identifications and valuations are automated estimates for your information only. They are not professional appraisals, authentications, or insurance valuations, and you should not rely on them for insurance, tax, legal, estate, or sale decisions without independent professional advice.
AI request logging. For quality, debugging, and abuse-prevention purposes, our backend temporarily logs the prompts, responses, and image references involved in AI requests. These logs are automatically deleted after a short period (currently about seven days).
5. How we use your information
We use your information to:
- Provide the Service — create and secure your account; store and display your collection; identify, research, and estimate the value of items; and enable estate planning, sharing, and community features.
- Run AI features — send photos and text to AI and image-search providers to produce identifications, valuations, and research (Section 4).
- Facilitate expert connections — match you with, and share item snapshots with, independent expert businesses when you request it, and carry your messages between you.
- Communicate with you — send transactional email and push notifications (for example, about leads, reminders, and account activity).
- Improve and secure the Service — analytics, troubleshooting, fraud and abuse prevention, and enforcing our Terms.
- Comply with law and respond to lawful requests.
Where we rely on legal bases under the GDPR/UK GDPR, they are typically: performance of a contract with you (providing the Service); your consent (for example, certain optional features, and where required, analytics and device permissions such as camera, microphone, photos, and notifications); our legitimate interests (securing and improving the Service, preventing abuse); and compliance with legal obligations.
6. How we share information
We do not sell your personal information, and we do not share it for cross-context behavioural advertising. We share information only as described here:
With service providers ("processors") who process data on our behalf under contract:
| Provider | What we share | Why |
|---|---|---|
| Cloud hosting & database provider | All account, item, estate, lead, community, and device data (hosting, database, storage, authentication) | Core infrastructure |
| OpenAI | Item photos, descriptions, notes, metadata, and (if used) audio | AI identification, valuation, chat, transcription |
| Reverse-image search services | Item photo (image URL) | Reverse-image comparable search |
| Market-research search services | Text queries derived from item details | Comparable-price research |
| Email delivery provider | Email addresses and email content (including lead item snapshots and photos) | Sending and tracking email |
| Push-notification delivery provider | Device push token and notification content | Push notifications |
| TelemetryDeck | Hashed user identifier and product event names | Analytics |
| Stripe (future) | Billing information | Subscription payments |
With independent expert businesses. When you request expert help for an item, we share a snapshot of that item — which may include its photos, category, maker, period, material, condition, description, estimated value range, and your note — with the businesses we match you to, and we relay the messages you exchange. These businesses are independent third parties and act as separate controllers of the information you send them; their use of your information is governed by their own privacy practices.
When you say you'd consider selling an item. If you turn on "I'd consider selling this" for an item, specialists in that item's field who hold an active account with us may see a short card about it: its category, object type, maker, period, material, a one-word condition, the country and region you chose, and your own note. The card never includes your name, your photographs, any estimated value, or your address. A specialist may ask to be introduced — one request at a time, which lapses after 14 days unanswered; you see who is asking and exactly what they would receive, and nothing more is shared unless you accept. If you accept, they receive the item snapshot described above and become an independent controller of it. Heirloom does not list your item, take part in any sale, or handle payment. You can turn the setting off at any time; a specialist who has already seen the card cannot un-see it, and the item shows how many have.
With people you choose. If you make a collection public, share it, or offer a transfer of an item record, the information you designate may become visible to those recipients. Transfer recipients who accept receive a frozen copy of the item record (identity fields only). Estate sharing is an intent list and does not grant access.
With identity providers. Apple and Google when you use their sign-in.
For legal and safety reasons. We may disclose information to comply with law, enforce our Terms, protect the rights, property, or safety of Heirloom, our users, or others, and in connection with a merger, acquisition, financing, or sale of assets (in which case we will require the recipient to honour this Policy).
7. International data transfers
Our providers may process your information in countries other than your own, including the United States. Where we transfer personal data out of the EEA, the UK, or Switzerland, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses (and the UK Addendum) with our sub-processors. You may contact us at hello@heirloomapp.io for more information about these safeguards.
8. How long we keep your information
We keep your information for as long as your account is active and as needed to provide the Service, then for any period required to comply with our legal obligations, resolve disputes, and enforce our agreements. In particular:
- AI request logs are deleted automatically after a short period (currently about seven days).
- Lead requests expire approximately 30 days after they are sent to a business.
- Temporary transcription audio is deleted immediately after transcription.
- When you delete your account, we begin deletion after a 30-day grace period during which you can cancel (see Section 9).
Backups and copies already delivered to independent third parties (for example, an expert business that received an item snapshot, or a transfer recipient who accepted a record) may persist under those parties' own retention practices. Our standard schedule: account data is retained while your account is active and is deleted within 30 days after a verified deletion request completes; operational AI-processing logs are retained for approximately 7 days; encrypted database backups cycle out on our infrastructure provider's standard schedule.
9. Your rights and choices
Depending on where you live, you may have some or all of the following rights. We honour these rights for all users where feasible, regardless of location.
- Access / know (GDPR Art. 15; CCPA): request a copy of the personal information we hold about you and details about how we use it.
- Portability (GDPR Art. 20): receive certain data in a portable format. You can export your data at any time. Settings → Export produces a file of your collection; the whole account, including everything listed in this policy, is on Settings → Account & Privacy. Both produce a machine-readable file containing your profile, items, collections, beneficiaries, bequests, transfers, backups, and activity logs.
- Correction / rectification (GDPR Art. 16): correct inaccurate information, most of which you can edit directly in the App.
- Deletion / erasure ("right to be forgotten," GDPR Art. 17; CCPA): request deletion of your account and associated data from Settings → Account & Privacy. Deletion is subject to a 30-day grace period, during which you may cancel the request; after that we delete your account and associated personal data, including your photographs, recordings and uploaded documents. Deletion runs as a background job; the screen shows its progress and tells you if it does not finish. We keep only what we are required or permitted to retain by law, and one thing you have already given away: a record someone has already accepted from you, which is theirs and stays with them, including the name you had when you sent it.
- Restriction and objection (GDPR Arts. 18, 21): ask us to limit or stop certain processing, including profiling; and object to processing based on legitimate interests.
- Withdraw consent: where processing is based on consent (including device permissions for camera, microphone, photos, and notifications), you can withdraw it, for example through your device settings, without affecting prior processing.
- Non-discrimination (CCPA): we will not discriminate against you for exercising your rights.
- Opt out of "sale"/"sharing" (CCPA/CPRA): we do not sell or share your personal information as those terms are defined, so there is nothing to opt out of; if this changes we will provide a mechanism.
To exercise any right that is not available in-app, email hello@heirloomapp.io. We may need to verify your identity before acting. You also have the right to lodge a complaint with your local data-protection authority.
Additional state disclosures (US): we do not sell or share personal information as those terms are defined under applicable US state privacy laws, and we do not process sensitive personal information for purposes that would require a right to limit — for California, Colorado, Virginia, Connecticut, and similar laws, you may designate an authorized agent and, where applicable, appeal a decision on your request.
10. Security
We use administrative and technical measures to protect your information, including encryption in transit, authentication with optional multi-factor authentication, private storage buckets with time-limited signed links for item photos, and row-level access controls that scope your data to your account. No method of transmission or storage is 100% secure, so we cannot guarantee absolute security.
Some content buckets (profile avatars, certain attachments, and message images) may be served from publicly readable URLs; do not upload documents to those areas that you would not want accessible to anyone who obtains the link.
11. Cookies and similar technologies
On the web, we use essential storage (such as local storage) to keep you signed in and to operate the Service. We use TelemetryDeck for privacy-focused analytics as described above. We do not use third-party advertising cookies.
12. Information about other people
Some features let you enter personal information about third parties — most notably beneficiaries, attorneys, and executors in estate planning, and contacts in your directory. By entering this information you confirm you are permitted to share it with us for these purposes and, where required by law, that you have informed those individuals. If you are one of those individuals and want to know how your information is used or ask us to remove it, contact hello@heirloomapp.io.
Independent expert businesses receive item snapshots you send them and become independent controllers of that information.
13. Children's privacy
Heirloom is not directed to children and is intended for users aged 13 and older (or the minimum age of digital consent in your jurisdiction, whichever is higher — for example, 16 in parts of the EEA). We do not knowingly collect personal information from children under that age. If you believe a child has provided us personal information, contact hello@heirloomapp.io and we will delete it.
14. Changes to this Policy
We may update this Policy from time to time. When we make material changes, we will update the "Effective date" above and, where appropriate, notify you in the App or by email. Your continued use of the Service after an update means you accept the revised Policy.
15. Contact us
Questions, requests, or complaints about this Policy or your personal information:
Joseph Lint, doing business as Heirloom
21716 Lakeshire, Saint Clair Shores, MI 48081, USA
Email: hello@heirloomapp.io
Governing jurisdiction for privacy matters: the State of Michigan, United States
This document is a draft and does not constitute legal advice. It must be reviewed and approved by qualified counsel before publication.