The short version
Your shelf lives on your device, not on our servers. Credenza has no accounts and no user database today. The server functions see only what one feature needs for one request. They keep no content.
What stays on your device
Credenza stores these records in your browser's local storage:
- Your shelf: saved items, photos, notes, sizes, prices, hauls, and QC records.
- Your preferences: theme, currency, fit settings, and your default agent.
- Your body measurements, if you enter them: height, weight, chest, waist, hip, and related measures. These never leave your device.
- An outbound click log: which agent and which marketplace you opened, with a time stamp. It holds at most 500 entries. It has no item names and no links.
The browser extension stores its own saves in the extension's local storage on your device. The service worker keeps offline copies of the app itself in the browser's cache storage.
What the server functions see
Some features call Credenza server functions because marketplaces block direct browser requests. A request carries only what that feature needs:
- Link enrichment: the one marketplace or album URL you asked about.
- Size-chart scan: the album photo URLs you asked to scan.
- Reddit import: the one post URL you asked to read.
- Ask: your question and a compact summary of up to 25 shelf items you chose to search.
Each function logs one outcome line per request: the route, a hashed client key, the status code, and the latency. The log never contains URLs, queries, item titles, or post text. Function logs follow Netlify's retention.
What Anthropic processes
Ask, the size-chart scan, and listing translation send the request content to the Anthropic API to produce an answer. Anthropic processes this data under its own privacy policy and retention terms. Credenza sends no body measurements and no click log to Anthropic.
Referral links
Buy links may include a referral code. Credenza may earn a commission on agent shipping fees. A referral never changes your item price. Your stored links always keep the original marketplace address; the code attaches only when you tap Buy.
Retention
- On-device records stay until you erase them.
- Server functions keep no content after a request ends.
- Anthropic's retention follows the Anthropic API terms.
Export and deletion
Export: open Profile → Import & backup and download your shelf as a .json file.
Delete: open Profile → Erase my data. This removes every Credenza record on the device: the shelf, the preferences, the body measurements, the click log, and the offline caches.
Contact
Questions and deletion requests: wenselllc@gmail.com. One person reads this address.