Privacy policy
Last updated 27 July 2026 · Applies to useshelflife.com and the ShelfLife apps for iOS and Android
Short version: your grocery inventory lives on your device. We do not sell data, we do not run ads, and you can export or delete everything at any time.
1. Who we are
ShelfLife is operated by Andrew Turth, an independent developer. For anything in this policy, contact useshelflifeapp@gmail.com.
2. What we collect
You give us
- Email address when you join the waitlist or create an account.
- Grocery items you add manually, by barcode, or by scanning a receipt.
- Household details if you create or join a shared household: a household name and the invite code.
Collected automatically
- Basic app diagnostics: crash reports, device model, OS version. Not linked to your identity.
- Aggregate usage counts: how many scans and rescues happen per day, in total, not per person.
We never collect
- Precise location, contacts, photos beyond the single frame you scan, advertising identifiers, or payment card numbers (Apple and Google handle billing).
3. Receipt scanning specifically
When you scan a receipt, the image is sent to Google Cloud Vision for text recognition and the resulting text lines are sent to an AI model to be cleaned and categorised. The image itself is not stored by us and is discarded as soon as the text comes back. Item names may be stored in a shared shelf-life cache in a de-identified form (for example “baby spinach 5oz”) so the next person does not have to pay for the same lookup. Store names, prices, card digits and totals are stripped before anything leaves your device.
4. Where your data lives
ShelfLife is local-first. Your inventory is written to your device first and works with no connection. If you sign in, it also syncs to Supabase (hosted in the United States) so you can use more than one device and share a household. If you never sign in, nothing syncs.
5. Sub-processors
- Supabase — account storage and sync
- Google Cloud Vision — receipt text recognition
- Google Gemini and NVIDIA NIM — item cleanup and shelf-life estimation
- Apple App Store and Google Play — subscriptions and billing
We do not sell or rent personal data to anyone, and we never will.
6. Your rights
Wherever you live, you can:
- Export everything to CSV or JSON from Settings, on every plan including free.
- Delete your account and all server-side data from Settings. It is removed within 30 days, including backups.
- Correct anything that is wrong, or ask us to do it.
- Object to any processing, or withdraw consent, by emailing us.
If you are in the EEA or UK, GDPR applies and our legal basis is contract (running the app) and legitimate interest (keeping it working). If you are in California, CCPA applies. We have not sold personal information in the past 12 months.
7. Retention
Inventory items are kept until you delete them or delete your account. Diagnostic logs are kept 30 days. Waitlist emails are kept until you unsubscribe, which every email links to.
8. Children
ShelfLife is not directed at children under 13 and we do not knowingly collect their data.
9. Changes
If this policy changes in a way that matters, we will email everyone with an account before it takes effect. The date at the top always reflects the current version.
10. Contact
useshelflifeapp@gmail.com. A real person reads it.