Effective Date: September 17, 2026
Provider (Controller): Next Level Order Engineering UG (haftungsbeschränkt)
Applies to: the Containd mobile and web application, the containd.space publishing website, the containd.app product and catalog websites, the nextlevelorder.com company website, and the other websites, web apps, mobile apps, and related online services operated by Next Level Order Engineering UG (haftungsbeschränkt) that link to this Privacy Policy
This Privacy Policy explains how personal data is collected, used, and shared when you use our apps, websites, and related online services. Sections 1–14 describe our general practices. The Annexes at the end describe specific products and features in detail, including the Containd app, Containd Cloud Sync, publishing to containd.space, and Google Sign-In. If you do not agree with this policy, please do not use those services.
Next Level Order Engineering UG (haftungsbeschränkt) ("we", "our", "us") respects your privacy and is committed to protecting it. This Privacy Policy describes how we process personal data when you use websites, web apps, mobile apps, and other digital services that we own or operate and that link to this Privacy Policy (collectively, the "Services").
Containd is our inventory and list application. It is accompanied by several distinct websites, which have different purposes and different data practices:
| Surface | What it is | Described in |
|---|---|---|
| Containd app iOS, Android, and the web version |
The inventory and list application itself. Stores your data locally by default. | Annex A, Annex B |
| containd.space | The publishing website. Displays the Spaces that Containd users choose to publish, the public directory, and public user profiles. Also hosts our content report and contact forms. | Annex C |
| catalog.containd.app | The template and category catalog, and public developer documentation. Content here is curated by us. | Annex E |
| templates.containd.app | The template editor, used to author templates. | Annex E |
| containd.app | Product information and download pages for Containd. | Annex E |
| nextlevelorder.com | Our company website, including the imprint. Hosted on Squarespace. | Annex E |
| nextlevelorderengineering.com | Where this Privacy Policy, the Terms of Service, the EULA, and the account deletion instructions are published. | — |
We may operate the Services across further domains, subdomains, country-specific domains, branded domains, and application endpoints. This Privacy Policy applies to those Services when they reference or link to this policy, even if the specific domain changes over time.
Local-first by default. Containd stores your inventory data locally on your device by default. Data is only transmitted to online services when required to provide the Service, when you enable an optional feature, or when you consent where consent is required.
Depending on how you use the Services and your privacy choices, we may collect the following types of information:
We use personal data for the following purposes:
If you are located in the European Economic Area (EEA), the UK, or Switzerland, we rely on these legal bases where applicable:
We do not sell your personal data. We may share data in the following cases:
You can control how your data is handled in several ways:
We retain personal data only as long as necessary to provide the Services, fulfill the purposes described in this policy, and comply with legal obligations.
Website cookies, local storage entries, and consent records may remain on your browser or our systems for different periods depending on their purpose, your consent choices, and the default expiration periods set by our providers.
Cloud Sync. If you enable Cloud Sync, we retain synced content, sharing records, metadata, quota records, and related technical data only as long as necessary to provide the feature, maintain account integrity, comply with legal obligations, resolve disputes, and prevent abuse. If you disable Cloud Sync, delete shared content, or delete your account, we stop the relevant processing and delete or de-identify the associated service data within a reasonable period, subject to technical backups and legal or security retention requirements.
We do not promise unlimited or indefinite cloud storage. Cloud storage and bandwidth cost us money on an ongoing basis, and we are still learning what the real costs are. We therefore reserve the right to introduce storage limits, bandwidth limits, version limits, and inactivity limits — for example, removing cloud copies or published pages belonging to accounts that have been inactive for an extended period. Where we introduce such a limit, we will give you reasonable advance notice through the app or by email before data is removed, so you can sync, download, or back up your data first.
Cloud Sync and publishing are convenience and distribution features, not an archive or backup service. Please keep your own backups using the app's built-in Backup & Restore feature.
Published content. Published pages and their media remain stored and available for as long as the publication exists. When a publication is deleted (by you, by us, or through account deletion), the stored page, snapshot, and media are removed. Please note the important distinction between unbinding and deleting a publication described in Annex C: removing an item from your device does not by itself take the published page offline. Staging data from failed or abandoned publish attempts is deleted automatically within about one hour. Retired page addresses may be retained so they cannot be reused by someone else.
Local reminders. Reminder records and related scheduling data remain on your device until you delete them, remove the app data, or replace them through backup/restore or similar device-level actions.
Remote push tokens. If remote push is enabled, we may retain the current push token, platform, associated account identifier (if any), and related registration timestamps while the token remains active and reasonably needed for delivery, fraud prevention, troubleshooting, or compliance. If you opt out in the app, we attempt to deactivate the token. If you delete your account, we also deactivate or remove push-token records linked to that account as part of account cleanup. Invalid or stale tokens may also be deactivated operationally when delivery receipts indicate they no longer work.
AI and barcode data. Images, text, or other content you submit for AI or barcode processing is deleted from our servers upon completion of the request, or if the request cannot be fulfilled, within at most 48 hours. Our current AI request records are set to expire automatically after 24 hours. The inputs sent to our AI sub-processor are not used by that provider to train or improve its foundation or generalized AI models.
Purchase and billing records. After account deletion, subscription and billing records may be archived for a limited period (currently up to approximately 32 days) before being purged, so that we can handle refund, chargeback, and accounting matters. Statutory bookkeeping retention obligations may require us to keep certain transaction records longer.
Moderation and abuse records. Content reports, moderation decisions, and related evidence may be retained for as long as needed to handle the matter, defend against claims, prevent repeat abuse, and comply with legal obligations.
If you disable tracking, we limit processing to the minimal technical data required for the Services to function and remain secure, except where certain strictly necessary cookies or storage technologies are required.
We do not currently sell products or services through Squarespace checkout on our company website. As a result, Squarespace-specific commerce processing such as store checkout data, customer account data, shipping data, invoicing data, or Squarespace Payments processing does not currently apply to that website unless and until we enable those features in the future. Purchases of Credits for Containd are made through Apple or Google in-app billing, not through Squarespace — see Annex A.
If we later enable Squarespace commerce or related transaction features, we may update this Privacy Policy to describe the additional categories of data collected and the third parties involved.
We use reasonable technical and organizational measures to protect your data from unauthorized access, loss, misuse, or alteration. These include account authentication, server-side access rules that scope cloud data to the owning account, encrypted transport, and least-privilege access for our own staff and systems. However, no system can be guaranteed 100% secure.
Content you deliberately publish to containd.space as a public Space is, by design, not protected by access controls. Please read Annex C before publishing.
Please note that network communications may be logged by infrastructure providers as part of standard operations. We take steps to reduce and protect such data where feasible.
Our Containd backend, Cloud Sync storage, and containd.space publishing infrastructure are currently configured to run in European Google Cloud regions. However, because we use service providers such as Google Cloud, Firebase, Squarespace, RevenueCat, Expo, Cloudflare, Typesense, and providers for AI, barcode lookup, and analytics, some data may still be processed on servers located outside your country, including in the United States, for example for support, security, and platform operations.
AI processing — transfer to Google's global endpoints. Our AI features (the in-app Assistance chat and inventory image analysis described in Annex A) are delivered through Google's global AI endpoints. When you use them, the potentially personal data you submit — your chat inputs and uploaded inventory images, together with limited context — is transferred to and processed by Google LLC (Google Cloud, including Google Gemini via Vertex AI and Google Cloud Vision), which may process it in the United States and other countries outside the EEA, the UK, and Switzerland.
Legal basis for the Google transfer. For these transfers we rely on Google LLC's active certification under the EU-U.S. Data Privacy Framework (DPF), together with the European Commission's adequacy decision under Article 45 GDPR for certified recipients. For transfers from the United Kingdom we rely on the UK Extension to the EU-U.S. DPF, and for transfers from Switzerland on the Swiss-U.S. Data Privacy Framework. Google LLC holds an active certification under all three frameworks; you can verify this, and any provider's current status, at dataprivacyframework.gov.
For any recipient or transfer that is not covered by a DPF certification, we rely on appropriate safeguards for cross-border transfers, in particular the EU Standard Contractual Clauses (and their UK and Swiss equivalents) together with supplementary contractual and technical protections, and we assess those transfers as required.
Our Services are not directed to children under the age of 16. We do not knowingly collect personal data from children. When creating an account you are asked to confirm that you are at least 16 years old. If we learn we have collected such data, we will delete it.
Depending on your location, you may have rights such as access, correction, deletion, restriction, objection, and data portability. You may also withdraw consent at any time where processing is based on consent (e.g., optional analytics, AI features, push notifications), without affecting processing that occurred before withdrawal.
For data portability, the app's built-in export and Backup & Restore features let you obtain your inventory data directly, in addition to any request you make to us.
To exercise rights, contact us using the details below. We may need to verify your identity before fulfilling requests. You also have the right to lodge a complaint with your local data protection authority.
If a Service offers user accounts and account deletion, you can request deletion using the instructions provided in that Service or on the relevant support page. For services that use the Containd deletion flow, the current instructions are available here: Information about account deletion .
Deleting your Containd account removes your cloud-side data, including cloud-synced items, lists, tags, settings and files, your published Spaces on containd.space, your public profile if you created one, AI request records, achievement records, push-token records, and your authentication record — subject to the limited billing and moderation retention periods described in section 7.
Account deletion does not delete the data on your device. Your local Containd database, images, and documents stay on your phone, tablet, or computer until you delete the app data or uninstall the app. Conversely, deleting the app from your device does not delete your cloud account or any Space you published.
For Containd services that support remote push notifications, account deletion also triggers deactivation of the current push token before the account is deleted, and we also clean up any remaining account-linked push-token records on the backend within a reasonable period.
Because we operate across multiple domains and products, account deletion workflows may differ by Service.
We may update this Privacy Policy from time to time. Any changes will be communicated within the relevant Service, on our website, and/or by updating this page. The “Effective Date” at the top will reflect the latest version.
If you have questions or concerns about this Privacy Policy, please contact:
Next Level Order Engineering UG (haftungsbeschränkt)
Email: policies@nextlevelorderengineering.com
This annex describes the Containd mobile and web application. It supplements sections 1–14 above.
Containd stores your inventory data — items, lists, canvases, templates, categories, tags, custom fields, images, and documents — in a local database and local file storage on your device. No account and no internet connection is required for this core functionality. Each feature that sends data off the device is optional and has its own switch in the app's privacy settings.
An account is only needed for metered and online features (AI processing, barcode lookup, Credit purchases, Cloud Sync, account sharing, and publishing). We use Firebase Authentication, and you can sign in with:
From your sign-in provider we receive and store an account identifier (UID), your email address, email verification status, and — where the provider supplies them — your display name and profile picture URL, plus which provider you used. We use this to identify your account, associate your Credit balance and cloud data with you, contact you about your account, and prevent fraud and abuse.
We do not receive your password when you use Google or Apple sign-in. If you use Apple's option to hide your email address, we only receive Apple's relay address.
Containd can lock private content behind your device's biometric or passcode authentication (for example Face ID or Touch ID). This check is performed by your operating system on your device. We never receive your biometric data, and biometric data is never transmitted or stored by us.
The following optional AI features require an account and your consent, and consume Credits:
| Feature | What is sent | Processed by |
|---|---|---|
| AI item recognition / AI-assisted item creation | The photo(s) you select or capture, plus limited context such as the target category or template | Our backend on Google Cloud, then Google Gemini via Vertex AI |
| Multi-object detection and text recognition (e.g. shelf scanning) | The image you submit | Our backend, then Google Cloud Vision |
| Text-based product information extraction | The text you submit | Our backend, then Google Gemini via Vertex AI |
| In-app Assistance chat | Your question and the conversation history. If and only if you explicitly grant inventory access for the question, a summary of your non-private inventory items is also sent so the assistant can answer questions about your library. | Our backend, then Google Gemini via Vertex AI |
Items you have marked as private are excluded from the inventory summary sent to the Assistance chat. Images and request data are deleted from our servers on completion, and in any case within at most 48 hours (current configuration: automatic expiry after 24 hours). Processing by Google Cloud is governed by our agreement with Google as a processor.
AI sub-processor. The sub-processor that performs the AI processing for the features above is Google LLC, operating as Google Cloud (including Google Gemini via Vertex AI and Google Cloud Vision). We send only the specific inputs shown in the table above: your user-provided chat inputs and conversation history, uploaded inventory images, submitted text, and limited context such as the target category or template.
Security and data minimization. These inputs are pseudonymized: we do not transmit your account identifier, email address, or other account identifiers alongside the images, chat inputs, or text. Items you have marked as private are excluded from any inventory summary. Google processes this data under our instructions as our processor, and data sent to the AI provider is not used to train or improve Google's foundation or generalized AI models. Images and request data are deleted from our servers on completion, and in any case within at most 48 hours (current configuration: automatic expiry after 24 hours); the data is not retained by the AI provider for model training. Our agreement with Google as processor also governs the transfer described in section 9.
A limited AI trial may be available without signing in. In that case we use a randomly generated identifier stored on your device to apply the free quota and prevent abuse, instead of an account.
Scanning a barcode or QR code with the camera happens entirely on your device, and the scanned value is simply stored in the item. If you additionally request a product lookup for a barcode, the barcode number (and in some flows an image) is sent to our backend, which queries third-party product databases. These currently include BarcodeLookup.com, EANData.com, EAN-Search.org, Open Library, Open Food Facts, and Open Products Facts. Those providers receive the barcode number and standard request metadata such as an IP address of the requesting server. Product lookups consume Credits.
For metered features we maintain an account record on our backend containing your Credit balance, entitlements, a limited history of your service requests (request type, timestamp, Credits used, image count, request identifier, and status), and identifiers of your Credit purchase transactions. We keep this to operate your balance, support you, and detect fraud. In-app purchases are processed by Apple or Google billing and managed through RevenueCat; we do not receive your payment card details. A limited number of free Credits may be granted per month.
For Cloud Sync we additionally record metered usage (for example counts and sizes of uploads and downloads) so we can understand and, where applicable, charge for the actual cost of the service.
In-app analytics is off by default and split into separate opt-in levels:
Automatic analytics collection is disabled in the app build and only activated after you consent. You can withdraw consent at any time, and you can request deletion of the analytics data associated with your account from within the app.
Advertising. Containd does not currently display advertisements and does not include an advertising network. The app's privacy settings contain advertising preference switches; today these only set the corresponding consent signals for Google Analytics and are used to decide whether notification content may be personalized. We do not currently read the Apple Advertising Identifier (IDFA) or the Google Advertising ID, and we do not build advertising profiles. If we introduce advertising in the future, it will require your opt-in, we will request App Tracking Transparency permission on iOS where applicable, and we will update this Privacy Policy first.
Local reminders are scheduled and delivered by your operating system from data stored on your device. Optional remote push notifications require your consent and OS permission, and register a push token with our backend for delivery through Expo's push service and then APNs or FCM. Push notifications are not available on the web version of Containd.
Containd requests device permissions only for the feature that needs them: camera (photos of items, barcode and QR scanning), photo library (choosing existing images), biometrics (local unlock), Bluetooth (connecting to a label printer), and file access (import and export). Data captured through these permissions stays on your device unless you use an online feature that sends it.
Cloud Sync is optional, off by default, requires an account, and requires your separate consent to cloud processing.
Cloud Sync has three independent levels, each of which you enable separately. Turning on one level never turns on the next:
When Cloud Sync is enabled, the following data is uploaded to our cloud infrastructure:
Not uploaded by Cloud Sync:
Item and list records and metadata are stored in Cloud Firestore; files are stored in Google Cloud Storage, and are transferred using short-lived signed URLs. Access is scoped to your account by server-side security rules. Our Firestore and Cloud Functions are currently configured for European regions.
You can optionally share a list with other Containd accounts, either through a link or by invitation, and either read-only or collaborative. When you do this, the shared content and its metadata become accessible to the accounts you grant access to, and — for collaborative shares — those accounts can change the content, which is then visible to you and to the other participants. We process the grant records, the invited identifiers, and access state needed to operate the share. You can revoke a share at any time; revoked share records are cleaned up after a limited period (currently around 30 days).
Containd does not implement presence, "online status", availability broadcasting, live timer sharing, or current-activity sharing between users.
You can disable Cloud Sync at any time; your local data is unaffected. You can remove individual items or files from the cloud by deleting them in the app while sync is enabled, or by marking them private. Deleting your account removes your cloud library as described in section 12. Please also read the retention notice in section 7 about future storage, bandwidth, and inactivity limits.
Publishing is optional and off by default. It requires an account and your consent to cloud processing. This annex is important: please read it before you publish.
When you publish a list or canvas, Containd creates a snapshot of that content on your device and uploads it, together with the relevant images and graphics, to our servers. We then generate a web page for it on containd.space. The published page is a frozen copy: it does not continue to read your device, and it only changes when you publish again.
| Visibility | Address | Who can access it |
|---|---|---|
| Public | containd.space/s/<name>/ |
Anyone. No account is needed to view it. The page is built to be readable by search engines and may be listed in the containd.space directory (subject to our approval). |
| Private link | containd.space/share/<token>/ |
Anyone who has the link. The page is excluded from search-engine indexing and from the public directory. |
A private link is not a password. Anyone who receives, guesses, forwards, or finds that link — for example in a browser history, a chat log, or a forwarded message — can open the page. Do not use publishing for anything you need to keep confidential.
Public pages are intended to be found. Once a public page has been visited or indexed, third parties such as search engines, social networks, and archiving services may keep their own copies, previews, or cached versions. We cannot delete those third-party copies for you.
The published snapshot contains, for the list or canvas you selected and the items inside it:
Not included: document attachments on items are never uploaded to containd.space. Item fields that your published layout does not display are not part of the snapshot — this normally includes purchase and current values, currency, storage location, owner and loan information, comments, item history, procurement data, product codes, and weight and dimension data.
Publishing captures what your layout shows. Because custom field values can be baked into the page when the layout displays them, and because publishing follows the whole sub-tree beneath the item you selected, please open the published page and review it after publishing, and before sharing the address. Do not rely on an item's private marking to keep content out of a publication: the private marking governs Cloud Sync, and the publish feature is a separate, deliberate action by you.
A published page shows an alias and a display name for the publisher, and — if you have created a public profile — a link to that profile. Your email address and your internal account identifier are not shown on published pages.
On our servers, and not visible to visitors, we store the account identifier of the owner, the publication's history and version numbers, timestamps, and the IP address from which a publish request was made where available. We keep this for security, abuse prevention, handling content reports, and responding to legal notices.
Published images are uploaded at full resolution rather than as small in-app thumbnails, so the page looks good on large screens. Images larger than roughly 1.2 MB are re-encoded and reduced to a maximum edge of about 1200 pixels; animated images are accepted up to 8 MB. Our servers generate smaller preview versions (maximum edge about 720 pixels) which are what visitors normally load first; the full image is loaded when a visitor opens it larger.
Embedded image metadata. Photos can contain hidden metadata (EXIF), which may include the time the photo was taken, the camera used, and — if your camera or phone saved it — the GPS coordinates of where the photo was taken. Images that we re-encode have this metadata removed as a side effect of processing, but images small enough to be published unchanged may retain it, and it would then be readable by anyone who downloads the published image. If a photo's location or capture metadata is sensitive, remove it before publishing, or disable location tagging in your camera app.
This is the most important part of this annex, because two different actions have very different effects:
| What you do | Where | Effect on the live page |
|---|---|---|
| Delete published Space | In the Containd app, in the publishing section of the item | Taken offline and deleted. The page, snapshot, media, and search entry are removed. |
| Delete permanently | Signed in on containd.space | Taken offline and deleted, same as above. Use this if you no longer have the device or the app. |
| Delete your account | Containd app or containd.space | All of your published Spaces are deleted. |
| Switch visibility to private link | App or containd.space | The public address is removed and the page becomes reachable only via the private link, and is no longer indexed. |
| Abandon publication | Containd app | The page stays online. Only the connection between your local item and the publication is removed. |
| Delete the item on your device, empty the trash, or wipe the local database | Containd app | The page stays online. Local deletion only removes the connection. To take the page down you must use "Delete published Space", "Delete permanently" on containd.space, or delete your account. |
If you lose your device or reinstall the app, you can sign in and use Connect to existing Space to reconnect a list to a publication you own, so that you can update or delete it again. If you publish again after abandoning a publication, a new address is created; the old page is unaffected until you delete it.
We may also remove or restrict a publication ourselves — for example in response to a valid content report or legal notice, or to protect the platform. Retired addresses may be kept in a reserved list so they cannot be taken over by someone else.
Where you are a visitor to containd.space rather than a publisher, we process:
There are no public comment threads on published pages. Signing in on containd.space uses the same account as the app (Google, Apple, or email and password) and requires you to confirm that you are at least 16 years old.
If you believe a published page contains unlawful content, infringes your rights, or discloses your personal data, you can report it using the
report function on the page (when signed in) or the notice form at containd.space/legal/report/. You can also write to
legal@containd.app or abuse@containd.app. We process the
information you supply in order to assess and act on the report, to inform the affected publisher where appropriate, and to keep a record of the
decision. If your report concerns your own personal data appearing in someone else's publication, please tell us the page address and the specific
content, so we can act quickly.
containd.space can host an optional public profile for you at containd.space/u/<alias>/. A profile is
not public by default: until you switch it to public, the address returns "not found" to visitors. You choose what the profile
contains, and only a public profile is visible to anyone.
When your profile is public, it can display:
Because a public profile is a public web page, it may be read by search engines and other automated services in the same way as a published Space. Your email address and your internal account identifier are never shown on a profile.
You can switch your profile back to non-public at any time, which makes it inaccessible to visitors, and you can edit or remove individual fields. Deleting your account deletes the profile entirely, as described in section 12.
containd.space is delivered through Firebase Hosting and Google Cloud Functions (currently configured in the
europe-west1 region), with page data in Cloud Firestore (currently a European multi-region configuration) and media in
Google Cloud Storage. The directory search index is provided by Typesense.
This annex applies if you choose to sign in to Containd with your Google Account.
Containd requests only the basic identity information needed to sign you in. When you use Google Sign-In we receive from Google:
Containd does not request, access, or store any other Google user data. In particular, Containd requests no access to Google Drive, Google Calendar, Gmail, Google Contacts, Google Photos, or any other Google service data, and no such scopes are configured for the application. Earlier versions of our documentation referred to a Google Drive synchronization feature; that feature was removed and is not part of Containd. Containd's own synchronization uses our own cloud infrastructure, described in Annex B, and does not touch your Google Drive.
Google Sign-In data is processed by Firebase Authentication and our own backend on Google Cloud, acting as our processors, for the purposes above. Your email address may be processed by our support email provider if you contact us. We do not share Google Sign-In data with any other third party, and we do not sell it.
Containd's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Specifically:
Apple Sign-In works the same way: we receive an account identifier and an email address (which may be an Apple relay address), and a name on first sign-in where Apple provides it. You can revoke access in your Apple ID settings.
The publishing website containd.space is described separately in Annex C.
Our company website, including the imprint, is hosted and delivered through Squarespace. Squarespace may place cookies that are strictly necessary for security, navigation, consent management, and core site functions, and — after you consent — analytics and performance cookies. Squarespace may receive information about your browser, network, and device, the pages you visited before arriving, the pages you view, your IP address, and site activity such as clicks, internal links, searches, scrolling, and timestamps, in order to provide, secure, and improve its platform.
Contact form submissions and newsletter signups made on this website are processed by Squarespace and any connected email or mailing-list provider we configure, so we can receive, store, and respond to your message or manage your subscription. Web fonts may be delivered by third-party font services, which receive technical information such as your browser, device, page, and IP address in order to render the fonts. Pages may embed or link to third-party content such as video players; those providers may receive information from your browser when the content is loaded.
Our Containd product and download pages provide information about the app and link to the app stores and to these legal documents. Visiting them involves standard server log data as described in section 2, and any cookies or analytics used are subject to the consent controls presented on the site. Following a link to the Apple App Store or Google Play takes you to that platform, which processes your data under its own privacy policy.
The catalog presents template packs, category packs, author downloads, and public developer documentation. Catalog content is curated by us; it is not a place where users publish their own content directly. Browsing the catalog and reading the developer documentation does not require an account.
The catalog uses the same consent banner and the same Google Analytics 4 measurement configuration as containd.space. Analytics is loaded only after you consent to it; until then only strictly necessary functionality runs. Your consent choice is stored in your browser's local storage.
Template hearts (favourites). If you are signed in, you can mark a catalog template with a heart. We then store your account identifier together with the template identifier and its title and preview image, in a favourites collection belonging to your account. The total number of hearts on a template is public; who gave a heart is not shown to other visitors. Note that if you choose to make your favourites collection public on your profile, the templates you have hearted become visible there — see Annex C, section C.9. You can remove a heart at any time, and your favourites are deleted when you delete your account.
Catalog access from inside the app. Browsing and installing catalog content from within Containd is a separate opt-in setting that is off by default. When you enable it, the app requests catalog content from catalog.containd.app, and our servers process the standard request data described in section 2. A further, separate opt-in setting allows aggregate, anonymized information about which official templates are installed to be used for catalog statistics; this is not linked to your inventory content.
The template editor is a separate web tool for authoring Containd templates. Templates you author there are not published to the catalog automatically: publication requires review and release by us. Where the editor requires an account or stores drafts, the account and processing described in Annex A apply.
Last updated: September 17, 2026