Short version
- Your pantry, photos, and shopping lists stay on your device by default.
- We do not run a server that stores your inventory.
- We do not show ads, embed tracking SDKs, or sell your data.
- Scanning a barcode may look that code up on Open Food Facts, a third-party product database.
- Household sharing, if you enable it, uses Apple iCloud / CloudKit — not an account of ours.
Who we are
ShelfLife Crisis is a paid, one-time-purchase iPhone app. “We” means the developer of ShelfLife Crisis. There is no separate login, no ShelfLife Crisis user ID, and no analytics firehose.
Questions: support@shelflifecrisis.com (placeholder until mail on shelflifecrisis.com is live).
Information stored on your device
The app is local-first. Typical data on the phone includes:
- Pantry items: name, quantity, unit, location, notes, optional expiration date, optional barcode
- Photos you attach to items or capture for “scan from photo”
- Shopping list entries
- A local cache of barcode lookups so the same UPC is not fetched again and again
- JSON backups you export, if you choose to save them
- App preferences, such as whether expiration alerts are enabled
This lives in on-device storage (SQLite in the native app). Uninstalling the app deletes local data unless you previously enabled iCloud sync or kept an export.
Photos and camera
You may grant access to the camera and/or photo library so you can attach item photos, photograph a shelf, scan a live barcode, or scan a barcode from a still image.
- Photos remain on the device unless you turn on iCloud household sync or include them in an export you create.
- We do not operate a photo-upload server. There is no ShelfLife Crisis cloud album.
- You can refuse camera or library permission and still type items by hand.
Notifications
Optional expiration alerts use Apple’s local notification system on your device. They require your permission. We do not send remote push notifications from our own servers, because we do not run that infrastructure.
Open Food Facts network calls
When you scan or enter a barcode and the app is online, it may request public product information from
Open Food Facts (for example world.openfoodfacts.org).
- Sent: the barcode / product code, plus an identifying User-Agent such as
ShelfLifeCrisis/1.0 (support@shelflifecrisis.com). - Received: public catalog fields we use to suggest a product name and, sometimes, a pack image URL.
- Purpose: fill in the item so you do not have to type the name.
- Not sent: your pantry list, notes, photos, Apple ID, or identity.
Successful lookups are cached on device. The client rate-limits requests (product reads stay within Open Food Facts’ published per-user limits; we do not search-as-you-type against their API). If you are offline, the lookup fails, or the code is unknown, you can still save the barcode and type a name.
Open Food Facts is an independent project with its own terms and privacy practices. We do not scrape or bulk-download their catalog through the live API.
Apple iCloud / CloudKit (optional)
Household sync, when built and enabled, uses Apple iCloud / CloudKit so partners or roommates can share a pantry and shopping list. Membership uses Apple’s share or Family flow — not OAuth we host, and not a ShelfLife Crisis password.
- Sync is optional. The app is fully usable offline for inventory and lists without iCloud.
- If you enable it, Apple processes the synced records under Apple’s privacy policy and your iCloud account.
- We do not receive a copy of that data on a server of ours.
App Store purchases
The app is a one-time purchase processed by Apple. We do not receive your full payment card number. Restoring a purchase on another device uses Apple’s standard restore flow and your Apple ID.
This website
shelflifecrisis.com is a static marketing site (home, this policy, and support). We do not embed advertising pixels, analytics SDKs, or cookie banners for trackers we do not use.
The host that serves the files (for example Cloudflare Pages, Vercel, Netlify, or GitHub Pages) may keep ordinary web logs such as IP address, user agent, and requested URL as part of running a CDN. That is their infrastructure, not a tracker we added to the pages.
What we do not do
- No third-party advertising
- No behavioral or cross-app tracking SDKs
- No sale of personal information
- No ShelfLife Crisis user accounts or password database
- No subscriptions or in-app feature paywalls
Children
The app is a general-purpose pantry utility. We do not target children and we do not knowingly collect personal information from children. Age rating in App Store Connect will match that use.
Data retention and your choices
- On device: until you delete items, clear app data, or uninstall.
- iCloud: until you disable sharing or delete the data from iCloud, subject to Apple’s retention.
- Open Food Facts: we do not keep lookup history on a server of ours.
- Support email: if you write support@shelflifecrisis.com, we keep the thread only as long as needed to reply.
You can refuse camera, photos, or notification permission; leave iCloud sync off; skip barcode lookup; and export JSON before deleting the app.
International transfers
We do not operate a global user database. Information that leaves the device goes only to Open Food Facts (when you look up a barcode) or Apple iCloud (when you enable household sync), each under their own terms.
Changes
If this policy changes, we will update this page and the last-updated date. Material changes that affect App Store Privacy Nutrition Labels will be reflected there as well.
Contact
ShelfLife Crisis
support@shelflifecrisis.com
shelflifecrisis.com
This page is written for App Store review and for people who actually read policies. It is not legal advice.