WhatsWhere Open the app
Trust & architecture

Properties of the system, not promises.

A record people will rely on for a claim, an audit or a handover has to be built differently from a notes app. These are the design rules WhatsWhere is held to.

R-01

Nothing has a location field

Where a thing is equals the last placement event with a destination. Caches are derived in the same transaction, never written by hand. The ledger can always show how an item got where it is.

R-02

The ledger is append-only

Placement events cannot be updated or deleted; the database enforces it. A correction is a new event. Deleting a container soft-deletes it and keeps the history.

R-03

Exactly one writer

One process writes the ledger. Repairs run inside it, never as a second script, so two writers can never race on the same record.

R-04

Drive holds snapshots, never the live file

Every commit schedules a consistent snapshot to the customer’s Google Drive as a new revision. Photographs go to Drive first; if Drive refuses, nothing is recorded and the phone retries.

R-05

Client-minted identities, idempotent writes

Every record is given its identifier on the device. A resend is recognised and returns success without writing twice. Offline queues drain exactly once.

R-06

AI proposes, never asserts, never discarded

Vision proposals are labelled and counted separately until a person confirms. Manifests and claims exclude them. “Nothing found” is said only when the model found nothing.

Data handling

We hold account data. We hold no content.

Full-size photographs and the master copy of the ledger live in the customer’s own Google Drive, in a folder the app creates. The Drive scope is drive.file: the app can open only files it created, never the rest of the Drive. Our server holds the account, membership, a working copy of the ledger, thumbnails and a search index so the app is fast. Photographs transit the server and Google’s Gemini models to be read.

  • Sign-in with Google; no passwords held
  • Only the owner holds the Drive connection and manages members
  • Record or look-only, per person; viewers never see a recording control
  • Delete in the app removes the Drive files too; delete the folder or write to us for the rest

Privacy policy · Terms of use

Evidence model

Every answer cites its photograph.

Proof is the photographs from the strongest matching tier only. A compartment is lit on the photograph of its cabinet only when exactly one place matches. Unconfirmed rows are flagged and named as such.

Condition photographs at seal and at arrival are kept side by side for a damage report. Timestamps are recorded in UTC and ordered by when things happened, never by when they arrived at the server.

How the platform works →

Operating conditions

Designed for one free hand, bad light and no signal.

Offline-first

Photographs queue on the device and upload when connectivity returns. A client error parks the item for retry; a server error pauses the queue.

Nothing waits on the AI

No screen blocks on a model response. Fresh shots go to the front of the queue; results arrive when they arrive.

Built for every age

Targets at least 44 pixels, text at least 12, high contrast, voice in and out.

Back always works

One rule for every sheet and overlay, so a phone’s back button never loses work.

Self-repairing

Container states are reconciled from the ledger at every cold open; caches can never drift from the record.

Tested by gesture

Every interaction is tested by performing it, and every new test is proven by putting the bug back.

Put your physical layer on a ledger you can audit.

Start with Google, or write to us about a deployment for your team.