Cataloguing your belongings can be light-hearted – your data is where we stop joking and get serious. Here is, honestly, how we protect it, where it lives and who can see it.
Security FAQs
Security details
Access
The OWNAMIC team does not access the content of your account as part of normal operations. The only exceptions are when you explicitly ask us to – for example to solve a problem in a support case – or when we are required to by law.
Because OWNAMIC encrypts on the server, this is an organisational commitment rather than a purely technical barrier. That is why access to production systems and keys is restricted to a few people, and our administration interface requires a code from an authenticator app in addition to the password and locks out after repeated failed attempts. How we evaluate usage statistics in aggregated form is described in our Privacy Policy.
Encryption
Your content is encrypted before it reaches the database or the file store: object names, descriptions, brands, serial numbers, values and purchase prices, valuations, events, transactions, the activity log and your conversations with OWNY, as well as photos, documents and exports. We use AES-256-GCM – a scheme that does not only encrypt but also detects any later tampering.
Every record and every file gets a randomly generated key of its own. Those keys are in turn protected by a master key that lives in Azure Key Vault and never leaves it – unwrapping happens inside the vault. Database backups are additionally encrypted with a key of their own.
Details we need in readable form to run the service are not additionally encrypted – such as your e-mail address for signing in, categories, timestamps and billing data. They are kept in our database in Frankfurt, which cannot be reached from the internet. And to say it plainly once more: encryption happens on the server; it is not end-to-end encryption.
Password and sign-in
We never store your password in plain text, only as a salted hash computed with PBKDF2 (HMAC-SHA512) over 100,000 iterations. Even someone who stole our database would not know your password – they would have to guess it (very slowly!), one attempt at a time.
Passwords must be at least 10 characters long. Signing in with a passkey is safer still – with your fingerprint, face or device PIN and no password that could be stolen. You can also turn on two-factor sign-in with an authenticator app.
Against password guessing, we lock an account for 15 minutes after five wrong attempts, and we allow only a limited number of sign-in attempts from any single address. New accounts are confirmed with a six-digit code by e-mail that expires after 10 minutes and allows only five wrong attempts. If you have set up a passkey, you confirm it again on each device at least every 24 hours.
Account deletion
When you delete your account, we really delete it – we do not just mark it as inactive. First we remove every stored file: photos, thumbnails, documents, AI scans and exports. Then your account, objects, events, valuations, activity log and your conversations with OWNY are removed from the database in one step, and your account's keys are destroyed. A running subscription is ended, and your personal details are also removed at our payment provider Stripe.
This only happens when you explicitly ask for it. If your subscription lapses, we do not assume you mean DELETE EVERYTHING – that would be a horrible assumption. Tax law requires us to keep invoices for ten years, so they remain even after a deletion.
Data retention
When a trial or subscription ends, your account is kept in read-only mode: you can still view, export or delete your data – unless you have deleted your account as described above.
Exports you create stay available for download, encrypted, for 30 days. Database backups are made twice a day, encrypted, and deleted after 30 days; if we ever have to restore one, account deletions made in the meantime are carried out again. More on retention periods is in our Privacy Policy.
Infrastructure
OWNAMIC runs on its own virtual servers at Hostinger in Frankfurt am Main. The database cannot be reached from the internet and accepts encrypted connections only.
Photos, documents, exports and backups are stored – additionally encrypted by us – in Microsoft Azure Storage in Frankfurt, the keys in Azure Key Vault. Microsoft's data centres are audited against ISO/IEC 27001, SOC 1 and SOC 2 and the German BSI C5 catalogue, among others.
Which service providers take part in the processing, and which data they receive, is set out in our Privacy Policy.
Artificial intelligence
The AI features – recognition on photos, valuations, OWNY News and the OWNY assistant – run on Google Gemini in Google Cloud's Gemini Enterprise Agent Platform, processed on servers in the EU. Only what the feature in question needs is sent: for example the photo you have analysed, or your question to OWNY.
Under this paid enterprise service, Google does not use your inputs, files or the answers to train its models. Google may log requests for a limited time to detect abuse. OWNAMIC itself does not train an AI of its own on your data.
You decide: choose “Without OWNY” in the settings to switch the AI features off for your account. AI-generated images and texts are labelled visibly and – for images – machine-readably as well, as the European AI Act requires.
Payments
Payments are handled by Stripe, a payment provider certified to PCI DSS Level 1. You enter your card details on Stripe's checkout page – they never reach our servers.
No bank logins
OWNAMIC does not connect to your bank account, and we never ask for your online-banking credentials. Instead, you can import transactions as a CSV or PDF file – you decide what you upload. The automatic reading of such files follows the AI rules above.
Traffic
All data between your device and OWNAMIC travels over HTTPS, encrypted with TLS. Unencrypted requests are redirected automatically, and HSTS instructs your browser to only ever reach OWNAMIC over an encrypted connection.
Social engineering
All this encryption is useless if someone tricks you into handing over your sign-in details. So, two rules:
1. No one from the OWNAMIC team will ever contact you and ask for your password, a confirmation code or your recovery codes – neither by e-mail nor by phone. If someone asks you for them, it is not us.
2. Only enter your sign-in details on pages under ownamic.com, and check the address in your browser before signing in from a link in an e-mail. A passkey does that for you: it only works on the genuine OWNAMIC site.
Reporting a vulnerability
Found a vulnerability? Please report it confidentially to info@ownamic.com with the subject “Security”. We acknowledge every report, look into it promptly and keep you posted on the fix. Please do not access other people's data while testing, and hold back details until the issue is fixed.