SpiceRack ("the app", "we") is a spice-pantry organizer. We built it to be private by
default. This policy explains what data the app handles and what leaves your device.
The short version
An account is optional. You can use the whole app with no account โ
your data stays on your device only. You can choose to sign in (with Apple) to
sync your pantry across your devices and keep Premium wherever you log in.
Without an account, your spice data never leaves your device (except the
specific cases below, like barcode lookups).
With an account, your pantry is also stored in your private account so
your devices can share it.
We don't sell your data and we don't show ads.
What's stored on your device
Saved locally on your phone and (without an account) never sent to us:
Your spices and their details (name, brand, category, quantity, stock level, location,
expiry date, notes, favorite status).
Categories and racks you create.
Your shopping list.
Photos you add to a spice (stored as a local file reference on your device).
If you create an account (optional)
Signing in enables cross-device sync. When you do:
Sign-in identity. We use Sign in with Apple to identify your account. We
receive an account identifier and, if you allow it, your email address. We use this only to
operate your account and sync.
Your pantry, synced. The spice data above (excluding photos, which stay on
your device) is stored in your private account so your other signed-in devices can load it.
Where it's stored. Account data is hosted on our behalf by
Supabase, our backend provider, protected so that
only your signed-in account can read or write it.
Shared pantries (Premium). If you create or join a shared/family pantry, its
contents are visible to and editable by every member of that household. Anyone with the invite
code can join, so only share it with people you trust. If you leave, you keep a copy on your own
account and the shared pantry stays for the remaining members.
Deleting your account. You can permanently delete your account and its synced
data any time from Settings โ Account & Sync โ Delete Account.
Information that leaves your device
Beyond account sync (above), SpiceRack sends data off your device only in these cases:
Barcode lookups (Open Food Facts). When you scan a barcode, the barcode
number is sent to the Open Food Facts API to fetch product details. No personal information is
attached. See their policy.
Purchases (RevenueCat + Apple). If you start a Premium subscription, purchase
processing is handled by the App Store and by RevenueCat, our subscription provider. RevenueCat
receives an identifier (your account id if signed in, otherwise an anonymous one) and
purchase/receipt information to manage your subscription. It does not receive your spice data.
See their policy.
Apple Reminders export (optional). If you tap "Send to Apple Reminders", the
app creates reminders in your own Apple Reminders. This stays within Apple's ecosystem on your
device/iCloud; we don't receive it.
Device permissions we request
Camera โ to scan barcodes and (optionally) take a photo of a spice.
Photo Library โ to let you choose an existing photo for a spice.
Notifications โ to remind you (locally, on your device) before a spice expires.
Reminders โ only if you use the optional "Send to Apple Reminders" feature.
Each permission is requested only when you use the related feature, and the app
works without granting them.
Children's privacy
SpiceRack is not directed at children under 13 and does not knowingly collect personal
information from them.
Data retention & deletion
On-device data: deleting the app removes the app's local data.
Account data: use "Delete Account" in Settings to remove your account and its
synced copy, or email us to request deletion.
Subscription records held by Apple/RevenueCat are governed by their policies.
Changes to this policy
If we change this policy, we'll update the "Last updated" date above.
Contact
Questions about privacy? Email: spicerackappsupport@gmail.com