Shuno Privacy Policy
Last updated: August 26, 2026 Effective date: August 26, 2026
Shuno is a product of Bentley Digital Solutions LLC, a Utah limited liability company ("Shuno," "we," "us," or "our"). Shuno helps you photograph, catalog, label, and find the things you store.
This Privacy Policy explains what personal information we collect when you use the Shuno website, applications, and related services (the "Service"), how and why we use it, who we share it with, how long we keep it, and the choices you have. It also explains what we do and do not do with the photographs you submit for item detection.
This policy is incorporated into our Terms of Service.
1. The Short Version
- We collect your account details, the folders and items you catalog, the photographs you upload, your payment and usage records, and basic technical data.
- Photographs you submit for item detection are sent to third-party AI providers for automated analysis. Some of those providers process data outside the United States.
- We do not use your content to train AI models. We do review detection requests and their results to improve the instructions we send the model. See Section 6.
- We do not sell your personal information, and we do not share it for cross-context behavioral advertising.
- Folders you mark public, or whose QR code someone photographs, can be viewed by anyone with that link. That is a feature you control.
- We do not perform facial recognition on your photographs.
- You can access, correct, export, or delete your information. Email [email protected].
2. Scope
This policy applies to personal information we process about users of the Service, people invited to shared groups, visitors to our websites, and people who contact us for support. It does not apply to information you provide directly to a third party (for example, your payment card details, which go to our payment processor), or to how another user or organization handles content in their own accounts.
If someone else catalogs your belongings. Professionals such as organizers, movers, and estate or property managers may use Shuno to catalog property that belongs to their clients. In that case we process that content on the professional's instructions, they decide what is collected and who may see it, and you should direct requests about that content to them. See "Professional and business use" in Section 11 of our Terms of Service.
3. Your Rights and Choices
We do not train AI models on your content. Your photographs and catalog data are not used to train, fine-tune, or otherwise build machine learning models, ours or anyone else's, and we do not authorize the providers who process your images to use them that way. What we do instead — reviewing detection requests and results to improve the instructions we write — is described in Section 6.
Regardless of where you live, you can:
- Access and correct your account information in the app;
- Export your catalog data by emailing [email protected];
- Delete individual folders, items, and photographs, or your entire account;
- Revoke sharing by turning off public viewing for a folder, rotating its QR code, or removing a member from a shared group;
- Opt out of marketing email using the unsubscribe link or by emailing us. You cannot opt out of transactional and service messages while you have an account.
Depending on where you live, you may also have the rights described in Section 13 (regional privacy rights), including the rights to know, delete, correct, obtain a portable copy, limit certain processing, and appeal our decision on a request.
How to exercise a right. Email [email protected]. We will verify your identity — normally by confirming control of the email address on your account — and respond within the time the law requires. You may use an authorized agent where the law permits, and we may ask for proof of that authorization.
4. Information We Collect
A. Information you give us
| Category | Examples |
|---|---|
| Account information | Username, first and last name, email address, password (stored only as a hash), email verification status |
| Content you create | Folder names, notes, folder kinds, item descriptions, brands, categories and sub-classifications, quantities, item attributes, labels, and the condition, estimated value, retail value, and SKU you record for an item |
| Photographs | Images of your folders and their contents that you upload or capture, and the previews we generate from them |
| Sharing and group data | Groups you create or join, members you invite, the roles you assign, and the email addresses or usernames of people you invite |
| Plan and payment information | Plan and seat records, credit balances and transaction history. Card payments are handled by our payment processor; we receive a transaction record and limited details such as the last four digits of the card and billing country — we never receive or store your full card number |
| Communications | Support requests, bug reports, feedback, and survey responses |
B. Information collected automatically
| Category | Examples |
|---|---|
| Device and technical data | IP address, browser type, operating system, device type, app version, language, network information |
| Usage data | Screens and pages viewed, features used, searches run, detections requested, credits consumed, timestamps, referring URLs |
| Diagnostic data | Error logs, crash reports, performance metrics, job and queue records |
| Cookies and similar technologies | Session and authentication cookies; see Section 10 |
C. Records of your consent
When you create an account, we record which version of the Terms of Service and Privacy Policy you accepted, a cryptographic hash of that exact text, the time you accepted it, and the IP address and browser user-agent used to accept it. This is evidence of consent, so we keep these records even after an account is deleted (see Section 9).
D. AI interaction data
When you use item detection, we collect and retain the request itself, the image it referenced, the AI-generated output, which model and prompt version produced it, token counts and cost, error information, and what you subsequently did with the suggestions — whether you accepted, edited, verified, or deleted them. See Section 6.
E. Information from third parties
We receive limited information from our service providers, such as payment and subscription status from our payment processor and delivery status from our email provider. If someone invites you to a shared group, we receive the email address or username they used to invite you.
F. Inferences
We may draw inferences from the information above — for example, which features you find useful or how accurate our detection is for a given category of item — and use them to improve the Service and to decide what to build next.
G. What we do not collect
We do not collect precise geolocation, contact lists, health data, government identification numbers, or biometric identifiers, and we do not perform facial recognition on your photographs.
Note on photographs. Photographs of a home and its contents can reveal a great deal: room layouts, valuables, documents, medications, and sometimes people. Image files can also contain embedded metadata such as capture time and, if your device records it, GPS coordinates. Assume that any image you upload may reveal more than its visible subject. Please do not upload photographs of other people without their consent, and do not upload identification documents, financial records, or confidential business information.
5. How We Use Information
We use the information we collect to:
- create, maintain, and secure your account, and authenticate you;
- store, organize, index, search, and display your folders, items, and photographs;
- generate QR codes, public links, previews, and printable label PDFs;
- run item detection and return suggestions to you;
- operate credits, plans, and seats, process purchases and renewals, and prevent payment fraud;
- provide customer support and respond to your requests;
- send transactional messages (verification, receipts, security alerts, service notices) and, subject to your choices, product news and offers;
- monitor, debug, secure, measure, and improve the Service, including developing new features;
- review detection requests and their results to improve the instructions and output formats we send to AI providers, measure accuracy, and diagnose failures (Section 6);
- create aggregated and de-identified data as described in Section 8;
- detect and prevent abuse, unauthorized access, and violations of our Terms; and
- comply with legal obligations, respond to legal process, and enforce our agreements.
6. AI Features and Automated Image Analysis
A. How detection works
When you request item detection, the photograph you select and related instructions are transmitted to one or more third-party AI providers, which analyze the image and return suggested items, descriptions, brands, categories, attributes, quantities, and regions within the image. We may run a lower-cost analysis first and, depending on the result, submit the same image for a second, more detailed analysis.
Your photographs are stored privately. When you request detection, our servers retrieve the image from that private storage and send its content to the provider as part of our request. We do not make your images publicly readable in order to have them analyzed.
B. Who processes your images
Our AI providers as of the effective date of this policy are Google (Gemini), Cloudflare (AI Gateway and Workers AI), OpenRouter, and Alibaba Cloud (Qwen). We may add, remove, or change providers as the Service develops, and we will update this policy when we do.
Some of these providers process data outside the United States, including in jurisdictions whose data protection laws differ from those of the United States.
We instruct providers to process your content only to return results to us, and we do not authorize any provider to use your content to train its own models. A provider may retain content briefly for its own service operation, security, or abuse monitoring under its own terms, which we do not control. Each provider's handling of your content is also governed by its own privacy policy, and we encourage you to review them.
C. We do not train models on your content
Your photographs, item descriptions, and catalog data are not used to train, fine-tune, or otherwise build machine learning models — ours or anyone else's. We do not authorize the providers we send your images to to use them for that purpose, and we do not place your content into the instructions we send the model, so nothing you upload is shown to another customer's detection request.
What we do instead. The models we call are built by other companies. What we control is the instructions and output formats we send them, and improving detection means improving those. To do that, we review detection requests and the results they produced — the photograph, the suggested items, anything that came back in an unusable form, and the corrections you made afterwards — so we can see where the instructions fall short, measure accuracy, diagnose failures, control cost, and investigate abuse. Access is limited to people who need it for that work, and the underlying records are kept and deleted on the schedule in Section 9.
This is product work on our own instructions. Nothing of yours ends up inside a model or anything else we ship, and deleting the records genuinely removes your content from it.
If this changes. If we ever decide to train models on customer content, we will amend this policy and our Terms, give you notice before the change takes effect, and obtain any consent the law requires before your content is used that way.
D. Detection results are suggestions
Detection output is automated, approximate, and frequently wrong. It is a starting suggestion you are expected to review and correct, not a statement of fact about your property. See Section 8 of our Terms of Service.
7. Sharing You Control
With people you invite. If you invite someone to a group, they can see the folders, items, and photographs in that group according to the role you assign them (owner, editor, or viewer). Owners and editors can also change and delete that content.
With anyone holding a link or QR code. If you enable public viewing for a folder, anyone with the link or QR code can see that folder's contents without logging in — including anyone who photographs a printed label on a physical box or shelf. You control this; we do not make anything public on your behalf. Turning public viewing off or rotating a QR code prevents future access through the old link but does not recall printed labels already in circulation or retrieve anything already seen.
Members of a shared plan can see plan-level information such as the member list and the shared credit balance and its usage history.
8. How We Share Information
We do not sell your personal information, and we do not share it for cross-context behavioral advertising (as those terms are defined under California and other U.S. state privacy laws). Nor may a service provider take what we hand it and market to you off the back of it.
We share information only as described here.
With service providers. We use vendors to run the Service. Each one sees only what it needs to do its job for us, under a contract that obliges it to safeguard that information and bars it from putting the information to its own uses. Current categories and providers:
| Purpose | Provider(s) |
|---|---|
| Application and database hosting | Cloud infrastructure providers |
| Image and file storage, delivery, and caching | Cloudflare (R2, CDN) |
| Automated image analysis | Google, Cloudflare, OpenRouter, Alibaba Cloud (see Section 6) |
| Payment processing and subscription billing | Stripe |
| Transactional and product email | Resend |
| Real-time updates in the app | Centrifugo |
| Error monitoring, logging, and product analytics | Diagnostics and analytics providers |
For legal reasons. We may disclose information if we believe in good faith that it is necessary to comply with a law, regulation, subpoena, court order, or governmental request; to enforce our Terms; to detect, prevent, or address fraud, abuse, or security issues; or to protect the rights, property, or safety of Shuno, our users, or the public.
With professional advisors and in collections. We may share information with lawyers, accountants, auditors, insurers, and collections providers as necessary to run our business, collect amounts owed, and protect our legal interests.
In a business transfer. If Bentley Digital Solutions LLC is involved in a merger, acquisition, financing, reorganization, or sale of assets, information about you may move with the business as part of that deal, so far as the law allows. Should that ever put your information under a materially different privacy policy, we will tell you first.
Aggregated and de-identified data. We may create aggregated and de-identified data from the information described in this policy, and we may use, disclose, license, sell, or otherwise commercialize that data for any lawful purpose, including analytics, benchmarking, and market-insight products, and including after your account is closed. Data counts as de-identified here only once it can no longer be traced to a particular person or household — not on its own, and not by combining it with other information we could reasonably lay hands on. We keep technical and organizational controls in place to hold that line, and we do not work backwards from de-identified data to a person, apart from periodic checks that those controls still do their job. De-identified and aggregated data is not personal information under this policy.
With your consent or at your direction. We share information for other purposes when you ask us to or agree to it.
9. Data Retention
We keep information for as long as your account is active and as long as needed for the purposes described in this policy, based on the nature and sensitivity of the information, our legal and contractual obligations, and our need to resolve disputes and enforce agreements. In particular:
- Account and content data — kept while your account is active; deleted or anonymized within 90 days of account deletion, except as noted below.
- Backups — copies may persist for up to 90 additional days before rotating out.
- Content you shared — content you shared with another user or group, or made public, may remain visible to those people, and copies they retained remain theirs.
- AI interaction data (detection requests, outputs, model and cost records) — kept while your account is active, then for a further 18 months, counted from whichever falls later: your last detection request or the day the account closes. We hold it that long to measure quality, improve the instructions we send the model, investigate security and abuse, control cost, and meet legal obligations.
- Aggregated and de-identified data — retained indefinitely, since it can no longer reasonably be attributed to you.
- Records of your acceptance of our legal documents (Section 4.C) — retained indefinitely, because their purpose is to prove what you agreed to and when, which must survive account deletion.
- Transaction, billing, and tax records — retained as long as required by law, typically seven years.
- Log and diagnostic data — retained for up to 90 days, longer where needed for a security or abuse investigation.
- Usernames and email addresses — remain reserved after account deletion until a permanent purge, so that a deleted account's identifier is not immediately reissued.
10. Cookies and Tracking
We use cookies and similar technologies for:
- Essential purposes — keeping you logged in, maintaining your session, and security. These cannot be disabled while using the Service.
- Analytics — understanding which features are used, so we can improve them.
We do not use advertising cookies or third-party ad networks, and we do not participate in cross-site behavioral advertising.
Most browsers let you block or delete cookies, but blocking essential cookies will prevent you from logging in. We do not currently respond to "Do Not Track" browser signals. We honor Global Privacy Control signals where legally required.
11. Security
We use measures designed to protect your information, including encryption in transit (HTTPS/TLS), encryption at rest for stored data and images, passwords stored only as salted hashes using an industry standard algorithm, access controls that limit internal access to what is necessary, and time-limited signed URLs for image access rather than openly readable storage.
Some of this sits on your side of the line. Choose a strong, unique password, keep it to yourself, and think twice before making a folder public or printing a label for one.
No system is perfectly secure. We cannot guarantee the security of your information, and transmission over the internet is never entirely secure. If we become aware of a breach affecting your personal information, we will notify you and the appropriate regulators as required by law.
If you believe you have found a security vulnerability, please report it to [email protected]. We will not pursue legal action against researchers who report issues in good faith and who do not access, modify, or destroy other users' data.
12. Children
The Service is intended for adults. You must be at least 18 to create an account. We do not knowingly collect personal information from children under 13. If you believe a child has provided us information, contact [email protected] and we will delete it.
13. Regional Privacy Rights
A. California
This section provides additional disclosures required by the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA/CPRA"). Where the CCPA defines a term, that definition governs here too, and this policy uses "personal information" and "personal data" to mean the same thing.
Categories collected. In the preceding 12 months we have collected the following categories of personal information, as described in Section 4: identifiers (name, username, email address, IP address, account and device identifiers); commercial information (plans, purchases, credit balances and usage); internet or other electronic network activity (usage, diagnostics, browsing within the Service); audio, electronic, visual, or similar information (photographs you upload); professional information (only if you provide it); and inferences drawn from the above.
Sources. We collect this information from you, automatically from your device as you use the Service, from other users who invite you or share with you, and from our service providers.
Purposes. Section 5 sets out why we collect and use it; Section 8 sets out the business purposes for which we disclose it.
Categories disclosed for a business purpose. In the preceding 12 months we have disclosed each of the categories listed above to the categories of service providers listed in Section 8.
No sale or sharing. We do not sell personal information, and we do not share it for cross-context behavioral advertising. We have not done so in the preceding 12 months, including with respect to anyone we know to be under 16.
Sensitive personal information. We do not set out to collect the categories the CPRA calls sensitive personal information, and we do not put them to any use that would give you a right to limit that use. If something in that category reaches us incidentally — because it happens to appear in a photograph you upload — we neither use it nor pass it on beyond what the law allows.
Your rights. California residents have the right to know what personal information we collect, use, and disclose; to request a copy in a portable form; to request correction or deletion; to opt out of sale or sharing (we do neither); to limit the use of sensitive personal information; to appeal a decision on a request; and not to be discriminated against for exercising any of these rights. To exercise them, email [email protected]. We will verify your request and respond within 45 days, extendable by another 45 days where permitted.
California residents who believe we have fallen short can also raise it with the California Privacy Protection Agency, or with the state Attorney General's office.
B. Other U.S. states
If you live in Utah, Colorado, Connecticut, Virginia, Texas, Oregon, Montana, or another state with a comprehensive consumer privacy law, you have similar rights to access, delete, correct, and obtain a portable copy of your personal data, to opt out of targeted advertising and profiling that produces legal or similarly significant effects (we do neither), and, where the law provides it, to appeal our decision on your request. Use the same contact address above. If we deny your request and you wish to appeal, reply to our response and we will review the appeal and inform you of the outcome within the time the law requires.
C. Canada
This section applies to individuals in Canada and supplements the rest of this policy.
Consent. We collect, use, and disclose your personal information with your knowledge and consent, for the purposes set out in Section 5. Consent is express where you give it directly — creating an account, subscribing to product email, submitting a photograph for detection — and implied where the purpose is obvious from the circumstances and you provide the information voluntarily, such as sending us a support message. Because photographs of a home can be revealing, we treat images and their detection results as sensitive and rely on your express consent for them.
Withdrawing consent. You may withdraw your consent at any time, subject to legal and contractual restrictions and to reasonable notice. Email [email protected]. Withdrawing consent for a purpose we need in order to run the Service means we can no longer provide it to you, and we will tell you so before acting on the request. Withdrawal does not undo processing that already took place lawfully, and does not release you from amounts you owe. If your concern is specifically the review of detection requests described in Section 6.C, tell us that and we will address it directly rather than closing your account.
Your information is processed in the United States. Our servers, our database, and most of our service providers are located in the United States, and some AI providers process data elsewhere (see Section 6.B). While your information is in another country, it is subject to that country's laws, and it may be accessible to that country's courts, law enforcement, and national security authorities under their legal processes. We use contractual and security measures to require a comparable level of protection from the providers who handle it, but we cannot exempt them from the law where they operate.
Access, correction, and accuracy. You may ask what personal information we hold about you, how we have used it, and to whom we have disclosed it; you may ask us to correct anything inaccurate or incomplete. Email [email protected]. We respond within 30 days, or tell you why we need an extension. There is no charge for a routine request. In limited cases the law lets us withhold information — for example, where releasing it would reveal someone else's personal information or compromise an investigation — and we will tell you the basis if we do.
Automated processing. Item detection produces suggestions that a person reviews, edits, and accepts or rejects. We do not make decisions about you based solely on automated processing, and detection output does not affect your rights, your account standing, or what you are charged.
Portability. You may ask us for a copy of the personal information you gave us, in a structured, commonly used technological format. Email the same address.
Commercial electronic messages. We send marketing email to Canadian recipients only with consent, identify ourselves in every message, and include an unsubscribe mechanism that works for at least 60 days after sending. Transactional messages about your account are not marketing and continue while your account is open.
Breaches. If a breach of our security safeguards creates a real risk of significant harm to you, we will report it to the Office of the Privacy Commissioner of Canada and notify you as soon as feasible, and we keep records of security breaches as required.
Privacy officer and complaints. Our privacy officer can be reached at [email protected] or at the mailing address in Section 17. Bring any concern to us first — we will investigate and respond in writing. If you are not satisfied, you may complain to the Office of the Privacy Commissioner of Canada (priv.gc.ca), and, depending on where you live, to the provincial regulator: the Commission d'accès à l'information du Québec, or the Office of the Information and Privacy Commissioner for Alberta or for British Columbia.
14. Where We Operate
We operate in the United States, and your information is stored and processed there, except where a service provider processes it elsewhere (see Section 6.B on AI providers).
The Service is offered to users in the United States and Canada. It is not offered to, or intended for, individuals in the European Economic Area, the United Kingdom, or Switzerland. If you access the Service from anywhere else, you do so on your own initiative, and you understand that your information will be transferred to, stored in, and processed in the United States, whose data protection laws may differ from those of your country.
15. Third-Party Links and Services
The Service may reference or link to third-party websites and services. We do not control them and are not responsible for their privacy practices. Review their policies before providing them information.
16. Changes to This Policy
We may update this policy as the Service develops. If we make material changes, we will post the updated policy with a new "Last updated" date and, where appropriate, notify you by email or in the app. Changes are effective when posted unless the notice states otherwise, and your continued use of the Service after that constitutes acceptance. Please review changes carefully; if you do not agree with them, you may close your account and stop using the Service.
17. How to Contact Us
For questions, requests, or complaints about this policy or your personal information:
Bentley Digital Solutions LLC Email: [email protected] Mailing address: [COMPANY MAILING ADDRESS]
Email is the fastest way to reach us. For a privacy rights request, please include the email address on your account and describe what you are asking for.
