Effective: 2026-07-12 · Last updated: 2026-09-16 (cloud sync)
This app is built around offline-first, local storage. The data you enter is stored on your device by default. There are three exceptions, each explained below:
If you turn on cloud sync, your records are kept on a storage server (section 2 · off by default)
The app shows ads (Google AdMob) so it can be free (sections 3–4)
If you turn on barcode nutrition lookup, the scanned barcode number is sent to a third party (Open Food Facts) (section 5)
1. Data you enter (stored on your device)
Unless you turn on cloud sync, there is no sign-up or login and the data you enter is never sent to or stored on a server. The data below is stored on your device (if you turn on sync, some of it is also kept on a server — section 2).
With cloud sync off there is no account and no login. We do not collect identifying information such as your name, email address or phone number.
The account created when you turn it on, and what is kept on the server, are described separately in section 2.
2. Cloud sync (optional · off by default)
This works only if you turn it on yourself. If you do not, none of the transfers or storage in this section happen, and the app behaves exactly as in section 1. You can turn it off at any time under Settings → Cloud sync.
2.1 What it is for
To keep your own devices (for example a phone and a tablet) showing the same records.
App settings, learning progress and guide bookmarks are not kept on the server (they are per-device values, not shared ones).
2.3 Account
Turning sync on creates an anonymous account automatically. It has no name or email — only a random identifier — and can be used only from that device.
To see the same records on another device, or to recover them if you lose your device, you can link an email address (optional). From then on your email address is collected, solely to verify and recover the account.
2.4 Processor (where data is stored)
Storage and authentication use Supabase (AWS Seoul region, ap-northeast-2). We do not sell or hand your data to third parties; this is a processor relationship for operating the app.
Deletes your records on the server and this app's account link. Records on this device stay.
Settings → Erase all data
Records disappear from the server and from all of your devices. This cannot be undone; a backup file is saved on this device first.
Turning sync off is not deletion. It stops further uploads; records already on the server remain and resume when you turn it back on.
Uninstalling the app does not delete server records — use the menus above before uninstalling.
The sign-in itself may remain. One sign-in system is shared by several of our apps, so “Delete account” in the app is a withdrawal from this app (all records plus this app's account link). If you also want the sign-in account and linked email deleted, ask us by email — we will delete everything.
Full instructions, including how to ask when you no longer have the app, are on the Account & Data Deletion page.
3. Ads (Google AdMob)
To keep the app free we show Google AdMob ads. A full-screen ad appears once for every hour of accumulated time you spend in the app; it does not appear when you open a particular menu.
AdMob may collect and process the advertising identifier (AAID) and device/app interaction data for ad delivery, frequency capping, measurement and fraud prevention. This is processed by Google under the Google Advertising Policies and Google's privacy policy.
Consent (EEA/GDPR): in applicable regions the app requests consent for personalised ads through Google UMP at launch, and serves personalised or non-personalised ads accordingly.
Removing ads: you may purchase permanent ad removal as an in-app purchase. The ad-free status is stored only on your device.
4. In-app purchase (permanent ad removal)
Permanent ad removal is handled by Google Play in-app billing. Payment, refund and account information is handled by Google Play; this app runs no payment server.
The app records only the fact that a purchase completed, and you can restore the purchase (same Google account) after changing or reinstalling on a device.
5. Other external communication
Climate indicators: public data (NASA GISTEMP and similar) is downloaded read-only for reference. No personal data is sent, and the app works from cached values if the request fails.
Barcode nutrition lookup: when turned on in settings (on by default), scanning a barcode sends the scanned barcode number to Open Food Facts (a third-party service run by a French non-profit, privacy policy) to fetch product nutrition data and pre-fill the entry form. Values are not saved straight away — they fill the form and you confirm or edit before saving.
What is sent: only the barcode number. No name, account, stock history or location is sent. As with any internet request, your IP address and an app-identifying User-Agent reach the receiving server and are handled under that service's policy.
When offline: no request is attempted. If a previous result is stored on the device, the form is filled from that alone.
Retention: results are stored on your device for up to 90 days so the same product can be reused without another request, and are not sent back to any server.
Turning it off: Settings → Barcode nutrition lookup at any time; with it off no transfer occurs at all. The app notifies you once before the first transfer.
Apart from section 2 (cloud sync, when on), sections 3–4 (ads, payment) and the climate and barcode lookups above, the data you enter is not sent to any external server.
6. Permissions
Permission
Purpose
Camera
Used only for barcode scanning (identifying items). Photos and video are not taken, stored or transmitted.
Internet
Public climate data, barcode nutrition lookup (Open Food Facts), ad delivery (AdMob), in-app purchases, and — if cloud sync is on — syncing records between your devices.
Share sheet
Used only when you export data (Excel/CSV) to a location you choose.
7. Sharing and transfer
The stock and record data you enter is never sold or handed to third parties.
Cloud sync (when on): your records are stored with Supabase (AWS Seoul region). This is a processor relationship for running the app, not a sale or disclosure; retention and deletion follow section 2.
Barcode nutrition lookup (when on): the scanned barcode number is passed to Open Food Facts (French non-profit, third party) for the lookup (section 5). No information identifying you is included (for unavoidable transport data such as IP address, see section 5), and nothing is passed while it is off or you are offline.
Advertising identifiers and similar may be passed to Google AdMob for ads (section 3). Payments are handled by Google Play (section 4).
Exporting data happens only when you export it yourself through the operating system's share function.
8. Retention and deletion
Your entered data, settings and ad-free status are held on the device and are removed when you uninstall the app.
Barcode lookup results are held in the device cache for up to 90 days, then expire; they are removed when the app is uninstalled.
If cloud sync is on, server records remain even after you uninstall the app. We set no separate retention period — records are kept until you delete them. See 2.5 and the Account & Data Deletion page.
You can delete individual entries inside the app.
Resetting or deleting the advertising identifier is done in your device settings (Settings → Google → Ads).
In-app purchase history stays in your Google Play account; manage or request refunds through Google Play.
9. Children's data
We do not separately collect children's personal data. The “child” household member type is a classification used for calorie calculation, not identifying information.
10. Notice
This app is a reference tool for personal preparedness and record keeping. It does not provide emergency rescue, medical or disaster response services. In a real emergency, use official emergency services.