Privacy Policy

Last Updated: July 2026

1. Information We Collect

WhereIsIt contains no analytics, advertising, attribution, or crash-reporting software. We do not build a profile of you, and we do not track you across apps or websites.

2. Device Permissions

WhereIsIt requests the following permissions, which are used only on your device:

3. Google User Data (Gmail)

Connecting a Google account is entirely optional. WhereIsIt works fully without it, and the feature is off until you turn it on. This section describes exactly what Google user data WhereIsIt accesses, how it is used, what is shared, how it is protected, and how it is retained and deleted. It applies both to raw Google user data and to anything we derive from it.

3.1 What we access

WhereIsIt requests one Google API permission: gmail.readonly, which is read-only access to your Gmail. Google's sign-in library additionally requests openid, userinfo.email, and userinfo.profile as part of signing in. We use your email address only to show you which account is connected; we do not use your Google profile information.

WhereIsIt is read-only. It never sends, composes, replies to, forwards, labels, archives, imports, trashes, or deletes mail, and it never changes any Gmail setting. It does not download attachments.

When you connect an account, WhereIsIt searches your mail for shipping-related messages and reads the matching messages — their subject, sender, date, and body — in order to find tracking numbers. Because search operates on words rather than meaning, a message that merely mentions a phrase like "tracking number" can match; when the app reads it and finds no shipment, it discards it immediately. Scans run when you ask for one, when you open the app, and periodically in the background while an account is connected, so that new shipments appear without you having to do anything.

3.2 How we use it

Your email is used for exactly one purpose: finding package tracking numbers so your shipments appear in the app automatically. This happens entirely on your device, using fixed pattern-matching rules. Your email is never uploaded to us for processing, and there is no server of ours that receives it.

If a message yields a shipment, WhereIsIt saves four things derived from it: the tracking number, the carrier, a merchant or retailer name worked out from the message, and the Gmail message ID (an identifier, not content) so you can tap "View Original Email" to reopen that message later. It does not save the email's subject, body, sender, or recipient. Those exist only in your device's memory while the message is being examined, and are discarded immediately afterward.

3.3 What we share, and with whom

A tracking number is useless without asking the carrier what happened to the parcel. So when a tracking number is found in your mail, that tracking number is sent off your device — through our proxy (Section 6) to the carrier or tracking service that holds the shipment's status: UPS, DHL, or Ship24, a multi-carrier tracking aggregator. This is the same thing that happens when you type a tracking number in by hand.

Ship24 stores the tracking numbers it receives, under its own privacy policy, in order to keep delivering status updates for the life of the shipment. This means a tracking number that originated in your Gmail is retained by Ship24. We consider this important enough to state plainly rather than bury.

These parties receive only the tracking number and, where relevant, a carrier hint. They never receive your email's subject, body, sender, recipient, your Google account identity, your email address, your name, or your Google credentials. Nothing else derived from your Gmail is shared with anyone.

If iCloud sync is on — it is on by default, and you can turn it off in Settings — the package records described in 3.2, including the Gmail message ID and the derived merchant name, sync to your own private iCloud account. Apple stores this on your behalf; we have no access to it.

We do not sell Google user data, transfer it to data brokers or advertisers, or use it for advertising, credit, lending, insurance, employment, or any purpose beyond showing you where your packages are.

3.4 How we protect it

All traffic to Google, to our proxy, and onward to carriers is encrypted with HTTPS/TLS. Your Gmail requests go directly from your device to Google — they do not pass through any server of ours.

Your Google sign-in tokens are held in the iOS Keychain, encrypted by the operating system and readable only by WhereIsIt. They are never sent to us, never written to iCloud, and no server we operate can read your mail.

3.5 How long we keep it, and how to delete it

Raw email content is never retained: subjects, bodies, senders, and recipients are discarded as soon as a message has been examined. The four derived fields in 3.2 are kept on your device (and in your own iCloud, if sync is on) until you delete them. You are always in control:

3.6 No AI or machine-learning use

WhereIsIt does not use artificial intelligence or machine-learning models to read, classify, or interpret your email. Tracking numbers are found using fixed, hand-written pattern-matching rules that run on your device. Your Google user data — raw or derived — is never used to develop, train, improve, or evaluate any AI or machine-learning model, and is never sent to any third-party AI service.

4. How We Use Your Information

5. Data Storage

Your package list, names, addresses, and delivery history stay on your device, and sync to your own private iCloud account (on by default; you can turn it off in Settings). We do not store any of it on our servers. Email content is never stored at all — see Section 3.

6. Tracking Proxy

To look up shipment status, the app sends the tracking number and carrier name to our secure proxy service (hosted on Cloudflare), which forwards them to the relevant carrier or tracking service and returns the result to your device. The proxy exists so that carrier API credentials are never embedded in the app.

The proxy uses Apple App Attest to confirm requests come from a genuine copy of the app, and keeps only minimal, anonymous abuse-prevention data: a per-installation identifier (not linked to your name, email, or Apple ID) and request counts. It does not store your package history, names, addresses, or email content.

7. Third-Party Services

To retrieve delivery status, tracking numbers are sent to third-party carrier and tracking-data services: UPS, DHL, and Ship24, a multi-carrier tracking aggregator. These services receive only the tracking number and, where relevant, a carrier hint — never your name, address, email, or other package details.

Ship24 acts as our tracking-data provider for carriers we do not integrate with directly. To deliver continuous status updates, Ship24 stores the tracking number for the life of the shipment. Each of these services processes the tracking number under its own privacy policy, linked above for Ship24.

8. Data Sharing

We do not sell, trade, or share your personal information with third parties for marketing purposes. Tracking numbers are shared only with the carrier and tracking-data services described in Section 7, solely to retrieve delivery status.

9. Data Retention

Your data is retained on your device until you delete it or uninstall the App. iCloud data follows Apple's retention policies. You can delete individual packages, or erase everything, from within the app. Retention and deletion of Google user data specifically is described in Section 3.5.

10. Children's Privacy

The App is not directed to children under 13. We do not knowingly collect personal information from children.

11. Google API Services User Data Policy (Limited Use)

WhereIsIt's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. This applies to raw Google user data and to any data we derive from it.

Specifically:

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new policy in the App and on this page.

13. Contact

For questions about this Privacy Policy, contact us at support@whereisit.now.