Skip to content
Legal

Privacy Policy

Last updated: August 1, 2026

The short version

We collect what shElf needs to work for you: your email, the food on your shelf, the recipes you save, and enough usage and crash data to fix what's broken. Photos you scan and voice you record are processed and then deleted — we don't keep them. We don't sell your data, we don't share it with advertisers, and there is no tracking. You can delete everything from inside the app, in about four taps.

The rest of this page is the same thing, in detail. It covers the app and this website separately, because they behave differently.

What the app collects

  • Account: email address, a hashed password, and optionally a display name. If you sign in with Apple or Google, we get the identifier and email address they hand us — never your password.
  • Your kitchen: the items on your shelf, quantities, expiry dates, shopping lists, recipes you save, cook and rate, meal plans, custom ingredients, and anything you type into a note or a list name.
  • Diet and allergens: the diets you follow and the allergens you want kept out of recipe suggestions. Allergens are health information, so we treat them as such: they're used to filter your recipes and nothing else.
  • Photos: pictures you take of groceries or receipts to add them to your shelf, and a profile picture if you set one. See scanning and voice below.
  • Voice: what you say when you add items by speaking, and the text it turns into.
  • Receipts: when you scan one, what the app reads off it — shop, date, items, prices.
  • Usage data: which screens you open and which features you use, tied to your account id so we can tell one person's journey from another's. Never your name or your email.
  • Diagnostics: crashes, performance, error logs and your IP address, so a bug report can be traced to a real session. This includes a screen recording of roughly one in ten sessions, and of any session that hits an error — see below.
  • Device info: OS and app version, language, region, time zone, and a push token if you allow notifications.

About that screen recording

Our error-tracking tool can replay a session so we can see what a bug actually looked like. Every piece of text, every image and every icon is masked before it leaves your phone: what we get back is a wireframe of blocks and taps, not your shelf, your email address or your notes. We can see that you tapped the third row; we can't see what was in it.

Scanning and voice: nothing is kept

These two features send data to AI services, so they get their own section.

Photo and receipt scanning. Your phone resizes the picture and uploads it to our image host. Anthropic's Claude reads it and returns a list of what it saw. The moment that comes back, the picture is deleted. What stays is the result — "milk, 1L, expires Friday" — not the photo.

Voice. Where your phone can transcribe speech itself, it does, and no audio leaves the device at all. Where it can't, the recording goes to OpenAI's Whisper for transcription and is deleted from our server the second the transcript comes back — including when something goes wrong. We keep the transcript, because it's the record of what the app then did to your shelf.

Neither request carries your name, your email or your account id. The AI services see a picture or an utterance, and nothing about whose it is.

Sharing a shelf

A shelf can be shared with the people you live with. Anything on a shared shelf — items, expiry dates, shopping lists — is visible to every member of that household, and stays with the household if you leave it. Your own account is not shared: your saved recipes, achievements, preferences and settings stay yours.

What we don't collect

  • Your location, your contacts, your calendar, or your photo library beyond the pictures you deliberately pick or take.
  • Payment or financial details. The app is free and takes no payments.
  • Advertising identifiers. There is no IDFA, no ad SDK, no ad network, and no tracking across other apps or websites — so iOS never has to ask you about tracking on our behalf.
  • Your searches inside the app. Recent searches live on your phone and are never sent to us.

How we use it

To run the service: keep your shelf, warn you before food expires, suggest recipes from what you have, and send the emails and notifications you've agreed to. To fix and improve the app: usage, crash and performance data, read in aggregate. That's the whole list. We don't build advertising profiles and we don't sell anything to anyone.

In GDPR terms: running your account is performance of a contract; diagnostics and product analytics rest on our legitimate interest in a working app; optional emails and allergen data rest on your consent, which you can withdraw at any time in the app.

Who else sees it

Companies that process data on our behalf, under contract, strictly to provide their service to us. No one on this list may use your data for their own purposes:

  • Hetzner (Germany) — the servers and database everything lives on.
  • Cloudinary — stores and delivers images: profile pictures, and scan photos for the seconds they exist.
  • Anthropic — reads scan photos and interprets what you said.
  • OpenAI — transcribes voice recordings when your phone can't, and powers ingredient matching.
  • Resend — delivers our email.
  • Expo — delivers push notifications to Apple and Google.
  • PostHog (EU region) — product analytics.
  • Sentry (EU region) — crash and error tracking.
  • Google Analytics — this website only, and only if you accept it. See below.

Our servers, our analytics and our error tracking are all in the EU. Some of the processors above are US companies, so some data is transferred outside the EEA under the standard contractual clauses in their terms.

How long we keep it

Your account data stays for as long as your account does — a shelf you haven't opened in a year is still your shelf. Scan photos and voice recordings are deleted immediately, as described above. Crash and error reports age out on our error tracker's own schedule, currently 90 days.

When you delete your account, the deletion is immediate and permanent — there's no waiting period and nothing to undo. It takes with it your profile, preferences, saved recipes, achievements, custom ingredients, voice transcripts, scan history, notification settings, tokens and profile picture, and your waitlist entry if you had one. If you were the only person on your shelf, the shelf goes too.

Two things survive by design. Contributions you made to the shared food catalogue, and recipes of yours that were published to everyone, stay — with your name removed. And on a shared shelf, the shelf itself stays for the people still using it.

We also keep an anonymous row of counters — how long the account existed, how many items it held — with no id, no email and no free text in it.

This website, cookies, and analytics

This section is about this website — the pages you're reading now — as distinct from the app.

The site sets no cookies of its own and needs none to work. Fonts are served from our own servers, so simply reading a page doesn't announce your visit to anyone else.

We do use Google Analytics 4 to see which articles are worth writing more of. Because that means Google receives your IP address and sets cookies in your browser, we don't load it unless you say yes:

  • Nothing from Google is requested until you press Accept on the banner. Declining, or ignoring it, means no analytics script is ever loaded on your device.
  • If your browser sends a Global Privacy Control or Do Not Track signal, we treat that as a decline and don't even show the banner.
  • Advertising, ad personalisation, and ad-measurement storage are switched off regardless of what you choose.
  • What we get is aggregate: pages viewed, rough location by country, browser and device type, and where you arrived from. Not your name, and not anything you typed.

Changed your mind? Clear this site's data in your browser settings and the banner returns, defaulting to no analytics. Google explains its own handling in its privacy policy.

If you join the waitlist, we store the address you gave us along with your IP address and browser string — that pair is how we tell a person from a script. It's deleted when you unsubscribe, and when you delete a shElf account with the same address.

Email and notifications

Email that the service owes you — confirm your address, reset your password — has no unsubscribe link, because you can't opt out of being told your password changed. Everything else is optional, carries an unsubscribe link in every message, and honours your mail client's one-click unsubscribe button.

Push notifications have a master switch and per-category switches in the app, plus quiet hours. Turning them off in your phone's settings works too.

Your rights

  • Delete: in the app, Me → Delete account. Immediate and permanent. You can also ask us and we'll do it for you.
  • Export: ask for a full copy of your data and we'll send it. This one is handled by a human, so give us a few days.
  • Correct: fix or update anything we have wrong.
  • Object or restrict: tell us to stop processing your data for analytics or diagnostics.
  • Withdraw consent: opt out of optional emails, notifications or website analytics at any time.
  • Complain: if we've handled this badly, you can take it to your local data protection authority.

Reach us via the contact page for any of the above. We respond within 30 days.

Children

shElf isn't designed for children under 13. We don't knowingly collect data from them. If you believe we have, email us and we'll delete it.

Changes

If we change this policy, we'll update the date at the top and — for any material change — email you in advance.

Contact

Questions? Reach us via the contact page. We'll reply.