Legal
Privacy Policy
Short version. The app keeps a list of the emergency supplies in your home, plus four numbers about your household, in a database in the EU. It is tied to an account that starts out anonymous: no email, no name, nothing you had to type. Scanning a barcode sends those digits to Open Food Facts, an open food database run by a French non-profit, so the app can name the product. You can photograph an item, and you can point the camera at a printed best-before date to have it read for you. Crashes go to an EU error-tracking service with personal data switched off. Usage analytics are off until you switch them on yourself. There is no ad network. We do not sell any of it, and you can have all of it deleted by asking.
1. Who we are
My Supply Shelf is a product of Nisshagen Advisory AB (Org.nr 559526-6742), a company registered in Stockholm, Sweden. We are the data controller for personal data collected through the mysupplyshelf.com website and through the My Supply Shelf app.
Contact hello@mysupplyshelf.com for any privacy question, including data subject requests under the GDPR.
This policy covers both the website and the app. Where a section applies to only one of them, it says so.
2. The app
Your account
The app creates an anonymous account the first time you open it. That account has no email address, no name and nothing that identifies you as a person. It is an identifier that lets your own shelf come back to you the next time you open the app. You are not asked to sign up, and you can use the app indefinitely without ever creating a real account.
If you later choose to create a real account so your shelf survives a new phone, we store what you give us for that purpose:
- Email and password: your email address, and a password we never see in readable form. It is hashed by our authentication provider.
- Sign in with Google: your email address and the account identifier Google returns. We do not receive your Google password, your contacts or anything else in your Google account.
- Sign in with Apple: the account identifier Apple returns, and the email address you choose to share. If you use Apple’s Hide My Email, we only ever see the relay address, never your real one.
Adding an email address to the anonymous account you already have keeps the same account, so nothing on the shelf moves and nothing is lost. Signing in with Apple, or with a password you already had, switches you to that other account instead. The app counts what is on the anonymous one first and warns you before you leave it behind.
Your household
The app asks four things about your home, once, in a form you fill in yourself. There is no default row: if we hold these numbers, it is because someone typed them.
- How many adults and how many children live there. The app’s one job is a day count, and the day count is a division. Litres of water divided by three litres per person per day; kilocalories divided by 2200 per person per day. Without the number of people there is no number to report. What we store is a count. No names, no ages, no dates of birth, no identifier of any kind belonging to any child, and no field in the database to put one in.
- How many pets. Stored, and not used. The national guidance the app reports sets no per-animal figure for water or food, and we would rather leave the number out of the calculation than invent a weight for it. It sits on the household row until there is a published figure to use.
- Which country you are in. Two letters, which select the national preparedness profile you are measured against: Sweden’s, or one of six others. The app pre-fills the picker from the region setting your phone already has, and that reading happens on the device. The country reaches us only when you save the form.
- How many days you are aiming for. Your own target, between 1 and 365.
Put together, that is a statement of how many people, including children, live at one address, sitting next to a list of the emergency supplies kept there. We are telling you what it amounts to rather than filing it under “profile settings”. We hold it because the calculation cannot run without it, we hold one row per account, and database access rules restrict that row to the account that created it.
What you put on the shelf
- The items you hold: the name you gave them, the category, the unit, and the barcode digits if you scanned one. The barcode is kept on the item so the app can match it again without asking you to rescan.
- Where you keep them, if you fill that in. It is a free-text box, so it holds whatever you typed. Most people write a room or a cupboard. It is worth knowing that a room name next to a stockpile is a sentence about your home, and you can leave it empty.
- Batches: how many, the expiry date and whether it is a use-by or a best-before, where that date came from, whether the pack is sealed or open, when you opened it, when you acquired it and when you finished it.
Batches are the part to look at twice. Read in a row they are a dated record of when a household opened and used things. They exist because rotation is the feature: the app cannot tell you what passes its best-before in March without knowing what you have and when it was packed.
All of this is private to your account. There is no feed, no public profile and no sharing. Other users cannot see your shelf, and database access rules restrict every row to the account that created it.
The reference material the app measures you against is a different thing entirely. The item catalogue, the national guidance profiles, the barcode product records and the retailer links are the same for everyone, are read-only, and hold nothing about you.
The camera
The camera does three things, and only when you ask it to.
Reading a barcode. The scanner is limited in code to product barcode formats, so a QR code will not register. No photograph is taken for this, nothing is uploaded, and the video frame is discarded the moment the digits are decoded.
Reading a best-before date. If you tap to scan the printed date, a single still is taken and sent to our own server, which passes it to Google’s Gemini service to turn the printed characters into a date. We do not keep the image: our function returns the date and holds nothing but a record that a scan happened, whether it found anything, and how confident it was. Google receives the picture of the packaging. It receives nothing about you, your account or your shelf.
Photographing an item. If a product has no picture, you can take one. That photograph is uploaded and kept, in a private storage area where each account can reach only its own files. It is attached to the item, it is never public and no other user can see it, and it is deleted when you delete your account. This is the one place the app stores a picture, and it happens only because you chose to take one.
Barcode digits then have to become a product name, and that is the point where the app leaves your phone. If we already hold that barcode, the answer comes from our own database and nothing goes anywhere else. If we do not, your phone sends a request straight to Open Food Facts, an open food database run by a French non-profit association. For Swedish products we also ask Dabas, a Swedish product database, and that request goes through our server rather than from your phone, so Dabas sees our server and not you.
That request carries the barcode digits, the app’s name and version, a contact address for us, and your IP address, which any web request reveals to the server answering it. It carries nothing else: not your account, not your household, not your shelf, not the session token the app uses with our own database. Open Food Facts is told which product was asked about. It is not told who asked.
Reminders
Expiry reminders are scheduled on your device, by the operating system. Nothing about a reminder is sent from a server, and the app asks for notification permission at the moment it is useful, after your first item, rather than at launch. The reminder text names the item and its date, which means an item name can appear on your lock screen. You can turn reminders off in your phone’s settings at any time, and on Android they have their own named channel you can switch off on its own.
The shelf apps share a table for push tokens. Once you allow notifications, a token identifying your device is stored against your account so we can reach it. The reminders described above do not need it, because they are scheduled on the device itself. Delete your account and the token goes with it.
Errors and crashes
The app reports crashes and errors to Sentry, hosted in the EU. Sending personal data is switched off, so reports do not carry your IP address, your username or your cookies. They contain the technical detail of what failed: the error, where in the code it happened, the device model and the app version. We use them to fix bugs and for nothing else.
One report is an exception, and we would rather name it than let you find it. If asking for notification permission fails, the report attaches your account identifier, so we can tell one broken device from a broken build. That identifier is the random account ID described above, not your name or your email address.
Where to buy things
The shopping list and the picks pages can show links to retailers that stock an item, at Kjell & Company, Clas Ohlson, Outnorth, Granngården and Amazon.se. Tapping one hands the address to your browser and you leave the app.
Some of them are affiliate links, which means we may be paid a commission if you buy after following one. Every link that pays us is labelled Ad, or Annons in Swedish, inside the app, which Swedish marketing law requires. The rest are ordinary links to a search page and pay us nothing.
Either way we send the retailer nothing about you, your household or your shelf. What the retailer sees is a browser arriving, the same as if you had typed the address. An affiliate link carries a code that tells the retailer we sent you. It does not tell them who you are, and nothing comes back to us about what you looked at or bought.
Purchases
The app has a free plan and a paid one. Buying is handled entirely by Apple or Google: we never see your card, and no payment detail reaches us or our servers.
The subscription framework the shelf apps share is RevenueCat, and it starts when the app opens. It receives your account identifier along with the device and store details it uses to recognise a returning customer, and it tells the app whether you are subscribed. It receives nothing about your household, your supplies or your scans. One subscription covers every shelf app, which is why it is keyed to the account rather than to this app. RevenueCat is a US company, so this is a transfer outside the EEA; section 10 covers what that rests on.
What the app does not do
- No advertising, no advertising identifiers, no ad networks.
- No analytics unless you turn them on. The app can send usage events to Mixpanel, on its EU service, and the switch is off until you move it. You will find it under Profile, Privacy. Events record what happened in the app, for example that an item was added, together with your account identifier, which is a random ID and not your name or your email. They never carry what the item was. Your answer is stored against your account and is shared by every shelf app, so switching it off here switches it off everywhere.
- No location collection. The app does not ask for location access. It reads the region setting your phone already holds, on the device, to pre-fill the country picker.
- No contacts, calendar, microphone or health data.
- No selling, renting or sharing of personal data with data brokers, ever.
Analytics and the subscription were both added after the first version of this policy, and this page and the App Store privacy labels were updated to match before either shipped. Analytics remain off until you consent to them.
3. The website
mysupplyshelf.com carries this policy and the terms, and nothing else yet. There is no form, no sign-up and no account on the site, so reading it collects nothing about you personally.
The site uses Vercel Web Analytics for aggregate traffic measurement: page views, referrers, country-level location. It is cookieless, does not track individuals across sessions or sites, and does not build user profiles. There are no other tracking pixels and no non-essential cookies. If we add any, we will update this policy before they take effect.
4. Legal basis for processing
- Performance of a contract: your account, your household numbers and your shelf. That is the service the app provides, and it cannot be provided without them.
- Consent: the camera and notification permissions, and usage analytics. You are asked for each at the moment it is needed, never at launch. The permissions are withdrawn in your phone’s settings, and analytics with the switch under Profile, Privacy.
- Legitimate interests: keeping the service working and secure. Crash and error reporting, and looking a barcode up so the app can name a product without you typing it.
5. Third parties we use
- Supabase – database and authentication for the app. Hosted in the EU.
- Sentry – crash and error reporting, on its EU service, with personal data sending switched off.
- Open Food Facts – barcode lookups, run by a French non-profit association. It receives a barcode and your IP address, and nothing that identifies your account.
- Dabas – Swedish product data for Swedish barcodes. The request goes through our server, so Dabas receives a barcode from us and never your IP address.
- Mixpanel – usage analytics on its EU service, and only after you switch them on.
- Google (Gemini) – reads a photographed best-before date and returns the date. It receives the picture of the packaging and nothing about you. This is separate from Google sign-in below.
- RevenueCat – the shared subscription framework described in section 2. It receives your account identifier. United States.
- Google and Apple – only if you choose to sign in with one of them, and only for that sign-in. They also distribute the app.
- Vercel – hosting for this website, and its cookieless aggregate analytics.
Fonts on this website are served by Google Fonts, which means your browser requests the font files from Google’s servers and Google receives your IP address as part of that request. No font-related cookies are set. The app does not load fonts over the network; they ship inside it.
We do not sell your data to any third party, and none of these providers use your data for advertising.
6. How long we keep things
- Your account, your household and your shelf: for as long as the account exists. Ask us to delete the account and every item, batch, storage place, shopping list entry, household number and photograph held against it goes with it. There is no automatic expiry on any of it.
- Analytics events: if you turned analytics on, the events already sent are held by Mixpanel under your account identifier and are deleted on request.
- Anonymous accounts: these live on the device that created them, and no clean-up job removes them, so the record stays until someone asks us to delete it. What that means in practice is worth spelling out. If you delete the app before signing up, the session that proved the shelf was yours goes with it, and afterwards neither you nor we can point at that row, because no email was ever attached to it. Sign up if you want to be able to ask for it back, or ask us to remove it.
- Error reports: retained by Sentry on its standard retention schedule for our plan and then deleted automatically. They are technical records, not account records, and we do not use them to build a profile of you.
- Barcode product records: kept indefinitely, and not deleted with your account, because they are not about you. The record says that a product exists, not that you scanned it, and it has no column for a user.
- On your own phone: your language choice, a flag for whether you have ever had a real account, a flag for whether you have added a first item, and your sign-in session. Signing out erases all four from the device.
7. Your rights under the GDPR
As a user in the European Economic Area you have the right to:
- Access: request a copy of the data we hold about you
- Rectification: ask us to correct anything inaccurate
- Erasure: ask us to delete your account and everything on the shelf
- Portability: request your data in a portable format. Write to us and we will send you a file with everything held against your account.
- Withdraw consent: tell us to stop at any time, without giving a reason; withdrawal does not affect processing carried out before then
- Object and restrict: object to processing based on legitimate interests, or ask us to restrict it
To exercise any of these, write to hello@mysupplyshelf.com from the address on the account. We will respond within 30 days. You also have the right to lodge a complaint with your national supervisory authority; in Sweden that is Integritetsskyddsmyndigheten (IMY).
8. Deleting your account
The fastest route is in the app: open the Profile tab, tap Delete account and confirm. The app asks twice, because it cannot be undone. This erases the account and everything held against it: your household numbers, every item, every batch and any notification records. Deletion is permanent and we cannot restore it afterwards.
If you no longer have the app, email hello@mysupplyshelf.com and we will do the same within 30 days. Both routes are walked through on the account deletion page.
If you signed up with an email address, write from that address. If you never signed up and the account is still anonymous, we cannot find your row from an email, because there is no email on it. Write to us anyway and we will tell you what we can and cannot do.
One thing to know: the sign-in account is shared across the “my X shelf” apps. If the same login is also used for My Bar Shelf or another shelf app, we erase your My Supply Shelf data and keep the login itself, because deleting it here would destroy your other app’s account. Ask and we will remove the login too.
9. Children
My Supply Shelf is not directed at children. We do not knowingly collect data from anyone under 16, or under the age of digital consent in your country if that is higher. If you believe a child has given us personal data, contact us and we will delete it.
The household form records how many children live in your home. That is a number, entered by the adult who holds the account, and it exists because the day count divides by the number of people. We hold no name, age, date of birth or identifier for any child, and there is no field in the database for one.
10. International transfers
Our database, authentication and error reporting are hosted in the European Union.
Two things sit outside that boundary in different ways. Barcode lookups go to Open Food Facts, run by a French non-profit association, so the request stays inside the EU, but it goes to a party we do not control and it carries your IP address. RevenueCat, the subscription framework described in section 2, is a US company, and the account identifier it receives leaves the EEA; that transfer relies on the standard contractual clauses in RevenueCat’s data processing terms. Sign in with Apple and Google sign-in are handled by Apple and Google under their own terms and may involve processing outside the EEA.
If another provider ever needs to process data outside the EEA, we will only use one that relies on an adequacy decision or the European Commission’s standard contractual clauses, and we will say so here.
11. Changes to this policy
If we make material changes we will publish the updated version here and update the version number and effective date at the top of this page. If a change materially affects data we already hold about you, we will tell you before it takes effect.
What changed
- Version 1.1, 7 September 2026. Version 1.0 said that no photograph was ever taken and that no analytics event was ever sent. Both were true when it was written and both stopped being true when the app gained item photos, the best-before date scan and a usage-analytics switch. This version describes all three, names Google and Dabas as recipients, replaces the statement that there was nothing to buy with a description of the subscription, and corrects the retailer section: some of those links are affiliate links, they are labelled as advertising in the app, and they may pay us a commission.
- Version 1.0, 29 August 2026. First published.
12. Contact
Questions or concerns about your privacy? Write to hello@mysupplyshelf.com.
Nisshagen Advisory AB, Stockholm, Sweden.