Last updated: September 19, 2026
Privacy Policy
Shoes Organizer ("the App") is an iPhone and iPad application developed and operated by Vadim Katenin ("I", "me"). This Privacy Policy explains what the App does and does not do with your information.
1. The short version
The App has no user accounts and no advertising. Your collection — the names, sizes, colours, seasons, notes, and photos of your pairs — stays on your devices and, if enabled, in your private iCloud database. I cannot access it. Starting with version 2.1, the App uses pseudonymous product analytics through Mixpanel to understand how the App is used and improve its reliability and usability. The analytics never include the names, sizes, colours, notes, or photos of your pairs — only coarse facts such as a pair's built-in category and whether it has a photo — and they are not used for advertising or cross-app tracking.
2. Information stored on your device
Everything you put into the App — the name of a pair, its category, colour, size, the seasons you marked it for, your notes, and its photo — is stored in the App's own storage on your device, using standard Apple frameworks (Core Data). This content stays under your control and is removed when you delete the App.
3. iCloud sync
If you are signed in to iCloud on your device, the App synchronizes your collection across your own devices using Apple's CloudKit private database. This data is stored in your personal iCloud account. I have no access to it — I cannot read, export, or recover it, and neither can anyone else with whom you have not shared your Apple Account.
To make sync work, the App registers for Apple's silent push notifications, which is how iCloud tells it that something changed on another device. These carry no message and are never shown to you; the App does not send you notifications of any other kind, and it has no way to send you a marketing message.
Apple's handling of iCloud data is governed by Apple's Privacy Policy. You can turn syncing off at any time in Settings → [your name] → iCloud by disabling iCloud for the App. If you are not signed in to iCloud, the App simply works locally and nothing is synced.
4. Camera and photo library
The App asks for permission to use the camera only so that you can take a picture of a pair of shoes. To add an existing picture instead, the App uses the standard iOS photo picker, which runs outside the App: you choose one photo, the App receives that photo and nothing else, and it never gains access to the rest of your library. Pictures you take or choose are copied into the App's own storage (and, if iCloud sync is enabled, into your private iCloud database). The App does not send photos anywhere else.
You can grant or revoke camera access at any time in Settings → Privacy & Security → Camera. Declining it only means you cannot take pictures inside the App; choosing existing photos and the rest of the App keep working.
5. Location, contacts, and other sensitive data
The App does not request or use your location, contacts, calendars, health data, microphone, or any advertising identifier.
6. Product analytics
Starting with version 2.1, the App sends limited product-usage analytics to Mixpanel, Inc. from app launch. These analytics are pseudonymous and are kept separate from the names, sizes, colours, notes, and photos of your pairs. Earlier versions send no analytics.
The App sends the following categories of information:
- a random, pseudonymous identifier for this installation of the App;
- product interactions, such as opening the App or moving it to the background (including which screen was open), finishing the introduction, opening a shelf, a pair, its full-size photo, or Settings, switching between the men's and women's collections, changing which side the App opens on, adding a pair through Quick Add or a shelf, attaching or removing a photo and whether it came from the camera or the photo library, saving, editing, or deleting pairs, leaving the editor without saving, reaching the free-pair limit, viewing and closing the PRO screen, and requesting a rating prompt;
- collection measurements, such as the current number of pairs in the collection and on the open shelf, the number of pairs created during the lifetime of this installation, and the free-pair allowance of this installation;
- limited pair characteristics: the built-in category, the men's or women's collection, whether a pair has a photo, size, colour, or note, how many seasons are marked, and a coarse name-length range (empty, short, medium, or long) — never the photo, name, size, colour, or notes themselves;
- status information, such as the iCloud status shown in Settings (for example, syncing or not signed in), whether the App had to fall back to storage on this device only, the number of pairs moved and skipped when a collection from version 1.x is migrated, and a coarse category when saving a pair fails;
- commerce interaction results, such as whether the product loaded and whether an in-app purchase or restore completed, was cancelled, became pending, or failed; and
- technical context such as the App version and build, iOS version, event time, how long an action took, the product identifier, and the price and currency shown for it.
The App never sends Mixpanel the names, sizes, colours, marked seasons, notes, or photos of your pairs, Core Data or CloudKit record identifiers, Apple Account information, receipts, transaction identifiers, payment details, an advertising identifier, precise location, or the text of error messages. It does not send your device model, screen size, mobile carrier, or network type. Automatic event capture, session replay, advertising tracking, user profiles, IDFV-based identity, and IP-based geolocation are disabled. As with any online service, Mixpanel may process basic network information as necessary to receive and secure a request, but the App instructs Mixpanel not to derive or store event location from the IP address.
I use these events to understand how the App is used, identify parts of the experience that are not working as intended, diagnose technical failures, and improve reliability and usability. The legal basis for this processing is my legitimate interest in operating, diagnosing, and improving the App. I limit the collection to the product signals needed for those purposes and do not use them to advertise, track people across apps or websites, or identify a person. The App does not contain an analytics switch. Depending on where you live, applicable law may give you rights concerning this processing. Section 11 explains how the App's account-free, pseudonymous design affects my ability to act on an installation-specific request.
Mixpanel processes this information on my behalf as a data processor. Analytics from the App Store version of the App are sent to Mixpanel's European data-residency service. For more information, see Mixpanel's Privacy Statement, GDPR information, and Subprocessor List.
7. Purchases
The App offers a one-time in-app purchase that unlocks the PRO version. All purchases are processed entirely by Apple through the App Store. I never receive or store your payment details, card numbers, or billing address. The App reports the limited commerce interactions and product information described in section 6, but never sends a receipt or transaction identifier to Mixpanel. Apple separately provides me with aggregated, anonymized sales reports that cannot be used to identify an individual customer.
Purchase status is verified on your device through Apple's StoreKit. Your App Store purchase history is governed by Apple's Privacy Policy.
8. Collections from earlier versions
If you used version 1.x of the App, your existing pairs are migrated into the current storage format the first time you open the new version. That migration runs entirely on your device, and the shoes you had before are kept. Your pairs are never uploaded as part of it; the App reports only whether the migration finished, how many pairs were moved or skipped, and how long it took, as described in section 6.
9. Apple diagnostics and crash reports
The App does not contain a third-party crash-reporting SDK. If you have opted in to Share With App Developers in Settings → Privacy & Security → Analytics & Improvements, Apple may provide me with anonymized crash logs and performance metrics through App Store Connect. This is Apple's standard developer diagnostics program, it is aggregated and not linked to your identity, and you can opt out of it at any time in the same settings screen.
Mixpanel product analytics are separate from Apple's diagnostics and are described in section 6.
10. Children's privacy
The App is not directed at children under the age of 13, and I do not knowingly collect personal information from children. If you are a parent or guardian with a privacy concern, contact me using the details in section 14. Because the App has no accounts, I generally cannot associate an email request with a particular pseudonymous installation.
11. Retention and your rights
The content of your collection remains under your control on your device and in your private iCloud database. Pseudonymous analytics are retained only while reasonably necessary to understand product use, diagnose technical issues, and improve the App, subject to Mixpanel project retention settings and legal obligations. Data may be aggregated or deleted sooner.
Depending on where you live, privacy laws may give you rights to access, correct, delete, restrict, or obtain a copy of personal data, to object to processing, and to complain to your local data-protection authority. In practice:
- Analytics requests — you can email me at hello@katenin.dev. The App has no accounts, does not send your contact information, and does not expose its pseudonymous installation identifier. I therefore generally cannot associate an email request with one installation, remotely change that installation's analytics behaviour, or identify its previously sent events. Deleting the App stops future events from that installation and removes its local pseudonymous identifier; it does not automatically erase events already sent.
- Access and correction — your collection is already on your device, and every pair can be edited or removed inside the App.
- Deletion — deleting the App removes its local data. To also remove the synced copy, delete the App's data in Settings → [your name] → iCloud → Manage Account Storage.
- Do Not Sell or Share — I do not sell personal information, share it for cross-context behavioural advertising, use it for advertising, or permit Mixpanel to use it for those purposes.
12. Security
Local data is protected by iOS data protection and your device passcode. Synced data is transmitted and stored by Apple under iCloud's own encryption. Analytics are encrypted in transit and processed by Mixpanel. The names, sizes, colours, notes, and photos of your pairs are never sent to Mixpanel, and the App does not talk to any server of mine.
13. Changes to this policy
If this policy changes, the "Last updated" date at the top of this page changes with it. Material changes will be reflected in the App's release notes.
14. Contact and data controller
Vadim Katenin is the controller of the analytics data described in this policy.
Questions, privacy requests, or anything else about the App:
hello@katenin.dev