Last Updated: September 22, 2026
This policy applies to QuantumShelf for Android and QuantumShelf for iPhone, iPad, Mac, and Apple Watch. Where the two differ, the difference is called out explicitly.
QuantumShelf is operated as a sole proprietorship based in Arizona, United States. Questions about this policy or about your data: feedback@quantumshelf.com.
When you create an account we collect your email address and display name. If you sign in with Google or with Apple, we receive the account identifier and the email address that provider releases to us — if you use Apple's Hide My Email, we only ever see the relay address. We never receive or store your password for any provider; passwords for email accounts are handled by Firebase Authentication and are not visible to us.
Content you create in the app: items and their details (names, brands, quantities, prices, barcodes, notes, expiration dates, batch and lot numbers, serial and model numbers, warranty dates, custom fields), storage locations, categories, shopping lists, recipes and projects, check-out records, and the change history of all of it.
Household records: the household name, its members, each member's role, and invite codes and their expiration.
Every change is attributed to the user who made it, so household members can see who added, edited, or removed something.
The app uses your camera and photo library for barcode scanning, QR scanning, and AI analysis, and it can attach a photo to an item.
Photos attached to items are stored on your device only. They are not uploaded to our cloud storage and are not synced to other household members. Photos you submit for an AI scan are transmitted to Google for that analysis (see section 4) and are not retained by us afterward.
If you subscribe, your store — Google Play on Android, Apple's App Store on Apple platforms — tells the app which plan is active. We never receive your payment card, billing address, or any financial account information. Those are handled entirely by the store.
On Apple platforms, when you use an AI feature the app also sends our server the subscription record Apple signed for your purchase, so the server can confirm your plan before applying the weekly AI allowance. That record identifies the product and its status, not you or your payment method. If you own a household and have a paid plan, the plan level (Free, Pro, or Family) is also saved on the household record so the household's item and location limits apply to every member.
The Android app has Google Analytics for Firebase and Firebase Crashlytics enabled. These collect:
This is used to find bugs and understand which features get used. It is not used for advertising, is not sold, and is not linked to your inventory contents.
The Apple app does not include analytics or crash reporting. No usage or diagnostic data is collected there.
The app counts how many AI actions (scans and Plan with AI requests) you have used in the current week to enforce the free plan's weekly allowance. On Android this counter is stored only on your device. On Apple platforms the count is kept by our server in a record tied to your account (aiUsage), so the allowance survives reinstalling the app; the app can read it but not change it.
If you turn on reminders, the app schedules expiration, low-stock, and project due-date notifications locally on your device from the inventory already stored there. No push token is created and nothing is sent to a server to deliver them. You can turn each type off in Settings, or revoke notification permission in your device settings.
We do not sell your personal information, and we do not share it for cross-context behavioral advertising.
On your device. Your full inventory is held in a local database — Room on Android, SwiftData on Apple platforms. The app is fully functional with no network connection: you can add, edit, search, scan barcodes, read NFC tags, and generate reports offline.
In the cloud, when you are signed in. Your inventory, household, and history are synced to Google Cloud Firestore, scoped to your household, so that household members see each other's changes and so your data survives a lost or replaced device. Cloud sync is available on every plan, including the free plan.
You can use the app without signing in and without cloud sync. You can also export your data and keep your own copies.
Firebase servers are operated by Google and may be located in the United States or other countries where Google operates data centers.
The AI features — package scanning, receipt scanning, recipe scanning, shopping-list recognition, category suggestions, and (on Apple platforms) Plan with AI — are powered by Google Gemini.
How the request travels. On Android, the app sends AI requests to Gemini through Google's Firebase AI Logic service. On Apple platforms, the app sends them to a QuantumShelf server function hosted on Google Cloud Functions for Firebase. That function checks your sign-in token and your plan, forwards the request to Gemini, returns the answer, and adds one to your weekly count. It does not store the images, text, or answers. Error logs are kept by Google Cloud's standard logging and don't include your images.
What is sent for a scan. The image you captured is transmitted for analysis and the extracted text comes back to the app. For recipe-from-URL, Android fetches the page you pasted and sends its text; Apple platforms send the link itself. Only the content of that specific scan is sent. Your inventory, your account details, and your other photos are not.
What is sent for Plan with AI (Apple platforms). Planning only works if the AI knows what you have, so a planning request sends the text you typed plus a list of up to 300 of your inventory items — each item's name, package size, quantity, and category. It does not include locations, prices, notes, photos, barcodes, serial numbers, or anything about other household members. The answer, a set of suggested projects, comes back to your device and is saved only if you choose to create them.
Some parts of the app also read text without any network connection: barcode recognition and printed-text recognition run on your device (ML Kit on Android, the Vision framework on Apple platforms). Those images never leave the device.
Google's handling of data sent to the Gemini API is governed by Google's own terms and privacy policy: https://ai.google.dev/gemini-api/terms and https://policies.google.com/privacy
When you scan a barcode, the app may send the barcode number only to public product databases to look up the product:
No account information, device identifier, or other inventory data is sent with these lookups.
If you choose to connect Dropbox, the app backs your inventory up to your own Dropbox account using Dropbox's official OAuth authorization. We never see your Dropbox credentials and have no access to your Dropbox account or its contents. You can disconnect at any time from the app, and revoke the app's access from your Dropbox account settings.
Data in your Dropbox is governed by Dropbox's privacy policy: https://www.dropbox.com/privacy
| Service | Purpose | Platforms | Their policy |
|---|---|---|---|
| Firebase Authentication (Google) | Accounts and sign-in | Both | https://firebase.google.com/support/privacy |
| Cloud Firestore (Google) | Cloud sync and household sharing | Both | https://firebase.google.com/support/privacy |
| Google Gemini | AI image and text analysis | Both | https://ai.google.dev/gemini-api/terms |
| Firebase AI Logic (Google) | Delivers AI requests to Gemini | Android only | https://firebase.google.com/support/privacy |
| Cloud Functions for Firebase (Google) | Our AI server: checks sign-in and plan, forwards to Gemini | Apple only | https://firebase.google.com/support/privacy |
| Google Analytics for Firebase | Anonymous usage statistics | Android only | https://firebase.google.com/support/privacy |
| Firebase Crashlytics | Crash and error diagnostics | Android only | https://firebase.google.com/support/privacy |
| Google Sign-In | Optional sign-in method | Both | https://policies.google.com/privacy |
| Sign in with Apple | Optional sign-in method | Both | https://www.apple.com/legal/privacy |
| Google Play Billing | Subscription purchases | Android only | https://policies.google.com/privacy |
| Apple StoreKit | Subscription purchases | Apple only | https://www.apple.com/legal/privacy |
| Open Food Facts | Barcode product lookup | Both | https://world.openfoodfacts.org/privacy |
| UPC Database | Barcode product lookup | Apple only | https://upcdatabase.org |
| Dropbox | Optional backup to your own account | Both, optional | https://www.dropbox.com/privacy |
Each service handles data under its own privacy policy.
With your household. This is the point of the app. Everyone in your household can see the household's inventory, and can see who created or changed each item. Members with the Viewer role can see everything but change nothing. If you do not want to share something, do not add it to a shared household.
With the service providers listed above, only as needed to make the corresponding feature work.
For legal reasons, if we are required by law to disclose information, or need to do so to protect our rights or someone's safety.
We do not sell your personal information to anyone, for any purpose.
Regardless of where you live, you can:
If you are in the European Economic Area or the United Kingdom, you additionally have the right to access, correct, restrict, or object to processing of your personal data, to data portability, and to lodge a complaint with your supervisory authority. Our legal bases for processing are performance of a contract (providing the app you asked for), legitimate interests (keeping the app working and fixing crashes), and consent where you have given it.
If you are a California resident, you have the rights to know, delete, correct, and to opt out of sale or sharing of personal information. We do not sell or share personal information, so there is nothing to opt out of. We will not discriminate against you for exercising any of these rights.
To make any request, email feedback@quantumshelf.com. We will respond within the time your local law requires, and within 30 days in any case. We may need to confirm the email address on your account before acting on a request.
Your cloud data is retained while your account is active. When you delete your account, its data is removed from our Firebase project. Household data that other members still rely on — items they can also see — remains with the household; your account and your personal record are removed.
Local data stays on your device until you delete it in the app or uninstall the app. Backups you have made to Dropbox or exported to a file remain under your control and are not deleted by us; delete those yourself.
Crash and analytics data collected in the Android app is retained by Google under Firebase's retention settings.
No system is perfectly secure. Please use a device lock screen and a unique password for your account.
QuantumShelf is not directed to children under 13, and we do not knowingly collect personal information from anyone under 13. If you believe a child under 13 has given us personal information, email feedback@quantumshelf.com and we will delete it.
We may update this policy. When we do, we will change the "Last Updated" date above and, for material changes, notify you in the app. Continued use after a change means you accept the updated policy.
Email: feedback@quantumshelf.com