Privacy Policy
Last Updated: July 2026
1. Information We Collect
- Tracking numbers you enter, scan, or import from Gmail
- A device token, if you enable push notifications, so we can deliver delivery alerts
- A per-installation identifier used by our tracking proxy to prevent abuse (see Section 6)
WhereIsIt contains no analytics, advertising, attribution, or crash-reporting software. We do not build a profile of you, and we do not track you across apps or websites.
2. Device Permissions
WhereIsIt requests the following permissions, which are used only on your device:
- Camera — used only when you choose to scan a shipping label or receipt. Images are processed on your device to read the tracking number and are never uploaded or stored by us.
- Location — optional. Used only on your device to center the map and show where your packages are relative to you. Your location is not transmitted to us or to any third party.
3. Google User Data (Gmail)
Connecting a Google account is entirely optional. WhereIsIt works fully without it, and the feature is off until you turn it on. This section describes exactly what Google user data WhereIsIt accesses, how it is used, what is shared, how it is protected, and how it is retained and deleted. It applies both to raw Google user data and to anything we derive from it.
3.1 What we access
WhereIsIt requests one Google API permission: gmail.readonly, which is read-only access to your Gmail. Google's sign-in library additionally requests openid, userinfo.email, and userinfo.profile as part of signing in. We use your email address only to show you which account is connected; we do not use your Google profile information.
WhereIsIt is read-only. It never sends, composes, replies to, forwards, labels, archives, imports, trashes, or deletes mail, and it never changes any Gmail setting. It does not download attachments.
When you connect an account, WhereIsIt searches your mail for shipping-related messages and reads the matching messages — their subject, sender, date, and body — in order to find tracking numbers. Because search operates on words rather than meaning, a message that merely mentions a phrase like "tracking number" can match; when the app reads it and finds no shipment, it discards it immediately. Scans run when you ask for one, when you open the app, and periodically in the background while an account is connected, so that new shipments appear without you having to do anything.
3.2 How we use it
Your email is used for exactly one purpose: finding package tracking numbers so your shipments appear in the app automatically. This happens entirely on your device, using fixed pattern-matching rules. Your email is never uploaded to us for processing, and there is no server of ours that receives it.
If a message yields a shipment, WhereIsIt saves four things derived from it: the tracking number, the carrier, a merchant or retailer name worked out from the message, and the Gmail message ID (an identifier, not content) so you can tap "View Original Email" to reopen that message later. It does not save the email's subject, body, sender, or recipient. Those exist only in your device's memory while the message is being examined, and are discarded immediately afterward.
3.3 What we share, and with whom
A tracking number is useless without asking the carrier what happened to the parcel. So when a tracking number is found in your mail, that tracking number is sent off your device — through our proxy (Section 6) to the carrier or tracking service that holds the shipment's status: UPS, DHL, or Ship24, a multi-carrier tracking aggregator. This is the same thing that happens when you type a tracking number in by hand.
Ship24 stores the tracking numbers it receives, under its own privacy policy, in order to keep delivering status updates for the life of the shipment. This means a tracking number that originated in your Gmail is retained by Ship24. We consider this important enough to state plainly rather than bury.
These parties receive only the tracking number and, where relevant, a carrier hint. They never receive your email's subject, body, sender, recipient, your Google account identity, your email address, your name, or your Google credentials. Nothing else derived from your Gmail is shared with anyone.
If iCloud sync is on — it is on by default, and you can turn it off in Settings — the package records described in 3.2, including the Gmail message ID and the derived merchant name, sync to your own private iCloud account. Apple stores this on your behalf; we have no access to it.
We do not sell Google user data, transfer it to data brokers or advertisers, or use it for advertising, credit, lending, insurance, employment, or any purpose beyond showing you where your packages are.
3.4 How we protect it
All traffic to Google, to our proxy, and onward to carriers is encrypted with HTTPS/TLS. Your Gmail requests go directly from your device to Google — they do not pass through any server of ours.
Your Google sign-in tokens are held in the iOS Keychain, encrypted by the operating system and readable only by WhereIsIt. They are never sent to us, never written to iCloud, and no server we operate can read your mail.
3.5 How long we keep it, and how to delete it
Raw email content is never retained: subjects, bodies, senders, and recipients are discarded as soon as a message has been examined. The four derived fields in 3.2 are kept on your device (and in your own iCloud, if sync is on) until you delete them. You are always in control:
- Delete a package — removes that package and everything derived from its email.
- Settings → Gmail → Disconnect Gmail — revokes WhereIsIt's access with Google, deletes the stored sign-in tokens from your device, and erases the tracking numbers WhereIsIt cached from your mail.
- Settings → Delete All Data — erases every package and all Gmail-derived data held by the app.
- Uninstalling the app removes its data from your device.
- You can also revoke WhereIsIt's access at any time at myaccount.google.com/permissions.
3.6 No AI or machine-learning use
WhereIsIt does not use artificial intelligence or machine-learning models to read, classify, or interpret your email. Tracking numbers are found using fixed, hand-written pattern-matching rules that run on your device. Your Google user data — raw or derived — is never used to develop, train, improve, or evaluate any AI or machine-learning model, and is never sent to any third-party AI service.
4. How We Use Your Information
- To provide package tracking services
- To send push notifications about delivery updates
- To sync your data across your devices via your own private iCloud account
5. Data Storage
Your package list, names, addresses, and delivery history stay on your device, and sync to your own private iCloud account (on by default; you can turn it off in Settings). We do not store any of it on our servers. Email content is never stored at all — see Section 3.
6. Tracking Proxy
To look up shipment status, the app sends the tracking number and carrier name to our secure proxy service (hosted on Cloudflare), which forwards them to the relevant carrier or tracking service and returns the result to your device. The proxy exists so that carrier API credentials are never embedded in the app.
The proxy uses Apple App Attest to confirm requests come from a genuine copy of the app, and keeps only minimal, anonymous abuse-prevention data: a per-installation identifier (not linked to your name, email, or Apple ID) and request counts. It does not store your package history, names, addresses, or email content.
7. Third-Party Services
To retrieve delivery status, tracking numbers are sent to third-party carrier and tracking-data services: UPS, DHL, and Ship24, a multi-carrier tracking aggregator. These services receive only the tracking number and, where relevant, a carrier hint — never your name, address, email, or other package details.
Ship24 acts as our tracking-data provider for carriers we do not integrate with directly. To deliver continuous status updates, Ship24 stores the tracking number for the life of the shipment. Each of these services processes the tracking number under its own privacy policy, linked above for Ship24.
8. Data Sharing
We do not sell, trade, or share your personal information with third parties for marketing purposes. Tracking numbers are shared only with the carrier and tracking-data services described in Section 7, solely to retrieve delivery status.
9. Data Retention
Your data is retained on your device until you delete it or uninstall the App. iCloud data follows Apple's retention policies. You can delete individual packages, or erase everything, from within the app. Retention and deletion of Google user data specifically is described in Section 3.5.
10. Children's Privacy
The App is not directed to children under 13. We do not knowingly collect personal information from children.
11. Google API Services User Data Policy (Limited Use)
WhereIsIt's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. This applies to raw Google user data and to any data we derive from it.
Specifically:
- We use Google user data only to provide and improve the package-tracking features you can see in the app — finding tracking numbers in your mail and showing you where your parcels are.
- We do not use Google user data for advertising, market research, credit or lending decisions, or any purpose unrelated to package tracking.
- We do not transfer Google user data to others except as needed to provide those features (the tracking-number lookups described in Section 3.3), to comply with applicable law, or as part of a merger or acquisition — and never to data brokers, advertisers, or information resellers.
- We do not allow humans to read your Google user data, except where you have given explicit permission, where it is necessary for security purposes such as investigating abuse, or where required by law. In normal operation, no one at CR Industries LLC ever sees your email.
- We do not use Google user data to develop, improve, or train generalized artificial-intelligence or machine-learning models, and we do not transfer it to any third-party service that would.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new policy in the App and on this page.
13. Contact
For questions about this Privacy Policy, contact us at support@whereisit.now.