Scope and account identity
This policy explains how Nintek (“we”, “us”) handles information inShopKeep, a workshop inventory and tool-lifecycle service.
Microsoft and Apple sign-in create separate ShopKeep accounts, even when both providers use the same email address. Each account has its own database, media, exports, deletion generation, and recreation history. ShopKeep does not automatically merge them.
ShopKeep contains no third-party advertising, analytics, attribution, crash-reporting, or tracking SDK. First-party activity records describe account operations inside ShopKeep; they are not used for cross-app tracking or advertising.
Information ShopKeep processes
- Account information. A stable provider identifier and basic profile fields Apple or Microsoft makes available, such as name and email. Apple may provide a private relay address. Credentials needed for Apple revocation are stored encrypted.
- Inventory. Tools, categories, brands, locations, identifiers, valuations, checkout and loan state, maintenance and warranty history, notes, trash state, and settings.
- Private media. Tool photos, manuals, warranties, receipts, invoices, and other documents attached to the account.
- AI-selected content. Receipt or invoice text and images, tool context, enrichment requests, and natural-language questions needed for the feature you invoke.
- Operations. First-party activity, AI-call status, request timing, errors, account-lifecycle events, and recovery metadata needed to run, secure, restore, and troubleshoot the service.
Per-user SQLite and private media
ShopKeep stores each account in an isolated per-user SQLite database hosted on Microsoft Azure. Photos and documents are SQLite BLOBs in that database; Azure Blob Storage is not the authoritative live-media store.
Media routes derive the database only from the verified bearer identity. They reject unauthenticated, expired, tampered, or cross-user requests and return private, no-store responses that vary on authorization. Raw storage paths are not public product links, and rejected requests are not made cacheable.
The native client keeps media only in nonpersistent caches and revokes temporary object URLs when they are no longer needed. Device caches, widgets, and search indexes are not independent inventory backups.
AI processing
Anthropic processes the receipt, invoice, selected tool context, or question needed for parsing, enrichment, or natural-language inventory search. Review extracted models, prices, dates, serial numbers, warranty details, and suggested categories before saving them. An AI result can be incomplete or wrong.
We do not sell personal information. Microsoft provides identity and Azure hosting, Apple provides Apple sign-in and revocation, and Anthropic processes scoped AI requests. Each provider handles its part under its own terms.
Export, deletion, recreation, and retention
ShopKeep offers different portability formats for different needs: CSV for inventory rows, a separate location-label CSV, a PDF insurance dossier, and a downloadable database backup. The database copy can contain sensitive inventory and in-database media, so protect it accordingly.
Account deletion is implemented as a server-confirmed lifecycle operation. It invalidates older session generations, revokes stored Apple credentials where applicable, drains database use, purges the selected database, and records a secret-free lifecycle event. A repeated deletion request is idempotent.
Signing in again after deletion is a new recreation event, not recovery of the deleted inventory. Microsoft recreation requires a fresh authentication newer than the deletion tombstone; Apple recreation requires a fresh authorization exchange. Old sessions cannot reopen the deleted generation.
| Data or control | Where it lives | Export or backup | Deletion and retention |
|---|---|---|---|
| ShopKeep account identity | A per-provider ShopKeep identity derived from Microsoft or Apple. The two providers create separate accounts unless a future linking feature explicitly joins them. | Exports contain inventory data, not the underlying Apple or Microsoft account. | Deleting the selected ShopKeep account does not delete the provider account or a ShopKeep account created with the other provider. |
| Tools, categories, locations, history, and activity | A private per-user SQLite database hosted on Microsoft Azure. | ShopKeep offers inventory CSV, location-label CSV, an insurance PDF dossier, and a downloadable SQLite database backup. | Tool trash is restorable until permanently purged. Account deletion purges the selected per-user database and invalidates its older session generation. |
| Photos and documents | Binary data stored as BLOBs inside the same private per-user SQLite database and served only through authenticated, account-scoped, no-store media responses. | The downloadable database backup carries in-database media. A CSV does not. Keep original documents when they matter independently. | Trashed-tool media remains owner-readable until permanent deletion. Account deletion purges the database and its BLOB media after required lifecycle checks succeed. |
| Recovery bundles | Operator recovery storage retains up to 14 local bundles. A protected managed-identity exporter can publish off-host copies to private Azure Blob storage when enabled. | These recovery artifacts are separate from user CSV, PDF, and database downloads. | Restore merges the newest lifecycle authority first. A database is omitted unless its generation matches an active account; deleting, deleted, missing-authority, and generation-mismatched copies cannot be restored. |
| AI inputs, outputs, and activity records | Scoped receipt, invoice, tool, or search context can be sent to Anthropic; ShopKeep stores first-party activity and AI-call records needed for history and operations. | Relevant inventory and reports follow the export formats above; there is no separate provider-transcript export. | Deleting the selected account removes its ShopKeep activity and AI records. Anthropic may retain provider-side records under its own commercial terms and legal obligations. |
| Provider and support records | Apple, Microsoft, Azure, Anthropic, and Nintek support may hold records needed for their part of sign-in, hosting, processing, security, or support. | Use provider controls for provider-held data and keep any support mail you send. | Provider retention is independent. Nintek can review support correspondence but cannot delete the Apple or Microsoft account. |
Scroll horizontally to read all four columns →
Native readiness boundary
Build 35 is VALID and attached to an editable App Store version. That does not mean the native app is publicly released: physical-device Apple and Microsoft sign-in and deletion checks, App Privacy publication, reviewer credentials, review submission, and release remain open. There is no public App Store listing or TestFlight acquisition link.
Children, changes, and contact
ShopKeep is intended for a general adult audience and is not directed to children. We do not knowingly create ShopKeep accounts for children.
We may update this policy when the service, providers, exports, lifecycle, or release state changes. The dates at the top identify this version.
Privacy and data questions can be sent toprivacy@nintek.com. Product help is available on ShopKeep Support. Use of ShopKeep is subject to theNintek Terms of Use.
Evidence note. Reviewed against the current ShopKeep service and immutable ShopKeepNative build 35 authority b1a757b on August 23, 2026. Physical-device, App Privacy, reviewer, and public-release gates remain open.
