App Store ready

Privacy Policy

Last updated September 17, 2026

This policy describes how the ShelfLife Crisis iPhone app and this website (shelflifecrisis.com) handle information. We do not operate a custom backend or user accounts. If something never leaves your phone, we say so.

Short version

Who we are

ShelfLife Crisis is a paid, one-time-purchase iPhone app. “We” means the developer of ShelfLife Crisis. There is no separate login, no ShelfLife Crisis user ID, and no analytics firehose.

Questions: [email protected] (placeholder until mail on shelflifecrisis.com is live).

Information stored on your device

The app is local-first. Typical data on the phone includes:

This lives in on-device storage (SQLite in the native app). Uninstalling the app deletes local data unless you previously enabled iCloud sync or kept an export.

Photos and camera

You may grant access to the camera and/or photo library so you can attach item photos, photograph a shelf, scan a live barcode, or scan a barcode from a still image.

Notifications

Optional expiration alerts use Apple’s local notification system on your device. They require your permission. We do not send remote push notifications from our own servers, because we do not run that infrastructure.

Open Food Facts network calls

When you scan or enter a barcode and the app is online, it may request public product information from Open Food Facts (for example world.openfoodfacts.org).

Successful lookups are cached on device. The client rate-limits requests (product reads stay within Open Food Facts’ published per-user limits; we do not search-as-you-type against their API). If you are offline, the lookup fails, or the code is unknown, you can still save the barcode and type a name.

Open Food Facts is an independent project with its own terms and privacy practices. We do not scrape or bulk-download their catalog through the live API.

Apple iCloud / CloudKit (optional)

Household sync, when built and enabled, uses Apple iCloud / CloudKit so partners or roommates can share a pantry and shopping list. Membership uses Apple’s share or Family flow — not OAuth we host, and not a ShelfLife Crisis password.

App Store purchases

The app is a one-time purchase processed by Apple. We do not receive your full payment card number. Restoring a purchase on another device uses Apple’s standard restore flow and your Apple ID.

This website

shelflifecrisis.com is a static marketing site (home, this policy, and support). We do not embed advertising pixels, analytics SDKs, or cookie banners for trackers we do not use.

The host that serves the files (for example Cloudflare Pages, Vercel, Netlify, or GitHub Pages) may keep ordinary web logs such as IP address, user agent, and requested URL as part of running a CDN. That is their infrastructure, not a tracker we added to the pages.

What we do not do

Children

The app is a general-purpose pantry utility. We do not target children and we do not knowingly collect personal information from children. Age rating in App Store Connect will match that use.

Data retention and your choices

You can refuse camera, photos, or notification permission; leave iCloud sync off; skip barcode lookup; and export JSON before deleting the app.

International transfers

We do not operate a global user database. Information that leaves the device goes only to Open Food Facts (when you look up a barcode) or Apple iCloud (when you enable household sync), each under their own terms.

Changes

If this policy changes, we will update this page and the last-updated date. Material changes that affect App Store Privacy Nutrition Labels will be reflected there as well.

Contact

ShelfLife Crisis
[email protected]
shelflifecrisis.com

This page is written for App Store review and for people who actually read policies. It is not legal advice.