All posts

April 6, 2026 · 4 min read · The Sherpsy team

What we mean by "private by design"

"Privacy-first" is close to meaningless as a claim, because no company describes itself as privacy-second. The only version worth reading is the specific one: which decisions were made differently, and what they cost.

The photo that stays on the phone

Reading a receipt, a recipe card, or a serial plate is text recognition, and text recognition runs on the device. That is slower and slightly worse than sending the image to a server, and it means a photograph of your shopping or your paperwork never leaves your phone. Where a feature genuinely cannot run locally, the app says so before the shutter, not in a policy document.

The vault we cannot open

Documents in the vault are encrypted on the device with a key derived from a phrase we never receive. We cannot read them, cannot recover them, and cannot be compelled to produce them. The cost is real and non-negotiable: lose the phrase and the data is gone.

And no third parties in a child's account

No analytics SDKs, no advertising identifiers, no background location. A child's account exists to let them see their own schedule and their own chores, and it is not a data collection opportunity.

Give the household one place to look.