Winder

Your watch box, organised.

Privacy Policy

Effective 1 June 2026 · Winder for iOS and Android

01The short version

We cannot see your watch collection. If you turn on iCloud sync, your collection is stored in your own iCloud account under your Apple ID — not on our servers. We have no access to it and no ability to read it.

We do collect a limited amount of technical data, and only with your permission: optional diagnostics and analytics, which are switched off until you turn them on, and purchase information needed to unlock and restore the premium features you buy.

We do not sell your data, we do not advertise in the App, and we do not build advertising profiles. The sections below set out precisely what is collected, by whom, on what legal basis, and how to turn it off.

02Who we are

Perpetio OÜ (registry code 14661567, VAT EE102136393), Kaupmehe tn 7-120, Kesklinna linnaosa, 10114 Tallinn, Harju maakond, Estonia, is the data controller for the processing described in this policy.

Contact for privacy matters: contact@perpet.io.

This policy takes effect on 1 June 2026 and applies to the Winder mobile app for iOS and Android.

03What is stored on your device

The following is written to local storage on your device:

  • Watch records — brand, model, reference, movement details, case details, purchase date and price, dealer, warranty, serial number if you choose to enter one, and notes.
  • Photographs you add, stored in the App's private storage area.
  • Service and maintenance records, and the intervals you set.
  • Strap and accessory records and their assignments.
  • Valuation figures and valuation history that you enter.
  • App settings — currency, units, reminder defaults, consent choices, and whether the app lock is enabled.

You can edit or delete any record in the App, and deleting the App removes this data from your device.

04iCloud sync

On iOS you may optionally enable iCloud sync. When you do, your collection data is stored in the private database of your own iCloud account, using Apple's CloudKit service.

This is an important distinction: the data is held under your Apple ID, in Apple's infrastructure, subject to your agreement with Apple. It does not pass through our servers, we hold no copy of it, and we have no technical means of reading it. Neither we nor Apple use your collection data for advertising.

Sync is off unless you turn it on. You can disable it at any time in the App's settings, and you can remove synced data through your device's iCloud storage settings.

Apple's handling of iCloud data is described in Apple's Privacy Policy at apple.com/legal/privacy.

Cloud sync is not currently available on Android.

05Diagnostics and crash reporting

We use Firebase Crashlytics, a service provided by Google, to understand why the App crashes so we can fix it. This is optional and switched off by default. Crash reporting is only enabled if you turn it on.

If you enable it, the following may be sent to Google when the App crashes or encounters an error:

  • A crash trace showing where in the code the failure occurred.
  • A Crashlytics installation UUID — a randomly generated identifier for your installation of the App, which is not your name or account and which resets if you reinstall.
  • Your device model, operating system version, language, and device state at the time of the crash, such as free memory and orientation.
  • Your IP address, which Google receives as part of the transmission.
  • Recent non-personal diagnostic log messages written by the App.

Crash reports do not include your watch records, photographs, valuations, or notes.

Legal basis: your consent (Article 6(1)(a) GDPR). You can withdraw consent at any time in the App's privacy settings, which stops further collection.

More information: firebase.google.com/support/privacy.

06Analytics

We use Firebase Analytics, a service provided by Google, to understand in aggregate how the App is used — which features people use and where they get stuck — so we can improve it. This is optional and switched off by default.

If you enable it, the following may be collected:

  • Events describing your interaction with the App, such as screens opened and features used.
  • A Firebase installation identifier, which is app-specific and resets if you reinstall.
  • Device and technical information — model, operating system version, language, and country derived from IP address.
  • App version and session information.

Analytics events describe how you use the App, not what is in your collection. We do not send your watch records, photographs, valuations, serial numbers, or notes to any analytics service.

We have not enabled Google Signals, advertising personalisation, or advertising identifier collection. Analytics data is not used to build advertising profiles.

Legal basis: your consent (Article 6(1)(a) GDPR). You can withdraw consent at any time in the App's privacy settings.

More information: firebase.google.com/support/privacy and policies.google.com/privacy.

07Purchases and the premium unlock

Payments are processed by Apple's App Store or Google Play. We never see your payment card, billing address, or store account credentials, and neither does Adapty.

We use Adapty (Adapty Tech Inc.) to validate purchases, manage your premium entitlement, and let you restore purchases across your devices. Adapty acts as our processor under a data processing agreement. In connection with a purchase it processes:

  • Purchase and transaction history for the App — what was bought, when, in what currency, and the store receipt used to verify it.
  • A de-identified device or installation identifier used to link your entitlement to your device.
  • Technical device information such as platform, operating system version, app version, and locale.

We have configured Adapty not to collect advertising identifiers (IDFA or Google Advertising ID) and not to collect IP addresses.

This processing is necessary to deliver the premium features you have purchased and to restore them on your devices. Legal basis: performance of a contract (Article 6(1)(b) GDPR). Because it is required to make a paid feature work, it is not optional and is not covered by the analytics consent toggle.

More information: adapty.io/end-users-privacy. Apple: apple.com/legal/privacy. Google: policies.google.com/privacy.

08What we still do not collect

To be explicit, we do not collect, receive, or have access to:

  • Your watch collection, photographs, valuations, service history, serial numbers, or notes.
  • Your name or email address — the App has no accounts and no sign-up.
  • Your precise location.
  • Advertising identifiers (IDFA / Google Advertising ID).
  • Your contacts, calendar, photo library beyond the images you deliberately add, or other apps' data.

Winder contains no advertising SDKs and no social login. We do not sell or rent personal data, and we do not engage in cross-context behavioural advertising.

09App lock and biometrics

If you enable the optional app lock, authentication is performed entirely by your device's operating system.

Your fingerprint, face data, and passcode never leave your device, are never transmitted, and are never accessible to Winder. The App receives only a yes-or-no result from the operating system.

10Notifications

Service, battery, and warranty reminders are scheduled as local notifications directly on your device. They are not push notifications, they do not pass through any server, and they require no device token.

You can revoke notification permission at any time in your device settings.

11Exports and sharing

Exports to CSV, JSON, or PDF are generated on your device and handed to your operating system's share sheet. You choose the destination — a file, an email, a cloud drive, or another app.

Once you send an export somewhere, it is governed by that destination's terms and privacy practices, not ours. Exports may contain sensitive information including valuations and serial numbers, so consider where you send them.

12If you contact us

If you email us for support, we receive your email address and whatever you choose to put in the message. We use it only to answer you.

Legal basis: our legitimate interest in providing support, and in some cases performance of our agreement with you (Articles 6(1)(f) and 6(1)(b) GDPR).

We retain support correspondence for up to 24 months, then delete it. Please do not send us screenshots or exports containing information you would rather we did not hold.

13Who processes data for us

We share data only with the following providers, each under a data processing agreement, and only for the purposes described above:

  • Apple Inc. — iCloud/CloudKit sync (data held in your own account), app distribution, and payment processing. Ireland and United States.
  • Google Ireland Limited / Google LLC — Firebase Crashlytics and Firebase Analytics, where you have consented. Ireland and United States.
  • Adapty Tech Inc. — purchase validation and entitlement management. United States.
  • Our email provider — support correspondence only.

We do not sell personal data and we do not share it with advertisers or data brokers.

14How long data is kept

Data on your device is kept until you delete it or uninstall the App. Data in your iCloud account is kept until you delete it there.

  • Crash reports: retained by Google in line with Crashlytics defaults, generally up to 90 days for detailed reports.
  • Analytics events: retained for a maximum of 14 months, after which they are deleted or aggregated.
  • Purchase and entitlement records: retained for the life of the entitlement and afterwards as required for accounting and tax purposes under Estonian law, generally seven years.
  • Support email: up to 24 months.

15International transfers

Google and Adapty process data in the United States as well as the European Union. Apple processes iCloud data in several regions.

Where personal data is transferred outside the European Economic Area, it is protected by appropriate safeguards under Chapter V of the GDPR — the European Commission's Standard Contractual Clauses, the EU–US Data Privacy Framework where the recipient is certified, or a combination of these, together with supplementary technical measures such as encryption in transit.

You can request further information about these safeguards at contact@perpet.io.

16Your rights under the GDPR

If you are in the European Economic Area or the United Kingdom, you have the following rights in respect of personal data we hold about you:

  • Access — to obtain a copy of the personal data we hold about you.
  • Rectification — to have inaccurate data corrected.
  • Erasure — to have your data deleted.
  • Restriction — to limit how we process your data.
  • Portability — to receive your data in a structured, machine-readable format.
  • Objection — to object to processing based on legitimate interests.
  • Withdrawal of consent — to withdraw consent for analytics or crash reporting at any time, without affecting processing already carried out.

Much of this you can exercise directly: your collection data is in your own hands, exportable at any time from within the App, and deletable by removing records, disabling sync, or uninstalling. Analytics and diagnostics can be switched off in the App's privacy settings.

For anything else, contact contact@perpet.io. We will respond within one month. Because the App has no accounts, we may need the identifier shown in the App's privacy settings to locate any data associated with your installation.

You also have the right to lodge a complaint with a supervisory authority. In Estonia this is the Data Protection Inspectorate (Andmekaitse Inspektsioon, aki.ee). You may also complain to the authority in your own country of residence.

17Children

Winder is intended for adults and is not directed at children. We do not knowingly collect personal data from children under 16. If you believe a child has provided us with personal data, contact contact@perpet.io and we will delete it.

18Security

Data in transit is encrypted using TLS. Data at rest on your device is protected by your device's own encryption, and your iCloud data by Apple's.

Keeping your collection in your own iCloud account rather than in a central database of our own removes an entire category of risk: there is no consolidated store of collectors' watches and valuations at Perpetio OÜ to breach.

We recommend keeping your operating system updated, using a device passcode, and enabling Winder's app lock. No system is perfectly secure, and we cannot guarantee absolute security.

19This website

Our website is served without advertising or tracking cookies. Our hosting provider may keep short-lived server logs, including IP addresses, for security and to keep the site running. These are retained for a limited period and are not used to profile visitors.

20Changes to this policy

We may update this policy as the App develops. Where changes are material — a new processor, a new category of data, or a new purpose — we will give clear notice in the App before they take effect, and where the change requires consent we will ask for it.

The current version is always available at winder.app/privacy.

21Contact

Privacy questions and rights requests: contact@perpet.io

Perpetio OÜ, registry code 14661567, VAT EE102136393, Kaupmehe tn 7-120, Kesklinna linnaosa, 10114 Tallinn, Harju maakond, Estonia.