Privacy
Privacy Policy
PeacefuLLList keeps emergency-supply information on the user's device unless the user deliberately enables an optional sharing or lookup feature described below.
Information stored on the device
Inventory names, categories, quantities, units, expiration dates, barcodes, storage locations, readiness metadata, AirTag display-name notes, storage photos, and the widget's small expiration snapshot are stored locally using Apple frameworks. This information is not used for advertising or tracking.
Camera and on-device recognition
The camera scans product barcodes and photographs printed expiration dates or storage locations. Expiration-date OCR uses Apple Vision on the device. Expiration-date capture images are not retained or uploaded. A storage photo is retained only when the user adds it to an item.
Optional family sharing
When a user creates or joins an invited household, selected inventory fields and storage photos synchronize through an invite-only Apple CloudKit share. Invited members with read/write permission can add, update, and delete shared items. Offline deletions are retried when a connection is available.
Optional community barcode contribution
If no provider recognizes a product, the manually confirmed entry stays local by default. Only when the user explicitly enables community submission does PeacefuLLList send the barcode, product name, category, submission time, and pending status to a separate public CloudKit review queue after the inventory item is saved locally. It is not returned by shared lookup unless an operator approves it. Quantities, expiration dates, storage locations, photos, AirTag notes, and household details are never included.
Third-party product lookup
A scanned barcode may be sent solely for product identification to Rakuten Web Service for Japanese JAN codes and to Open Food Facts or Open Products Facts for global barcodes. Rakuten requests pass through a narrow Cloudflare Pages Function so retailer credentials are not stored in the app. The function does not write lookup requests to an application database. Cloudflare processes network metadata such as IP address and routing information while delivering and protecting the endpoint, and product responses may be cached temporarily at the edge; see Cloudflare's Privacy Policy. The user's name, email, household inventory, storage location, photos, and AirTag information are not included.
Calendar, widgets, and AirTag notes
Full Calendar access is requested only when the user enables expiration-event creation and is used only to create, update, or remove the linked event as an inventory item changes. Widget data remains in the shared local App Group container. PeacefuLLList stores only a user-entered AirTag display name; live AirTag controls remain in Apple's Find My app.
Retention and deletion
Local records remain until the user deletes them or removes app data. Shared CloudKit records follow the household owner's sharing and iCloud controls. Pending barcode submissions may remain until operator review or deletion; approved product-identification records may be retained for community lookup. Product-data concerns or deletion requests can be sent to the contact below.
Children, sale, and tracking
PeacefuLLList does not knowingly collect personal information from children, sell personal data, create advertising profiles, or perform cross-app tracking.
Contact and changes
This policy will be updated if the app's features or providers materially change. For product support, privacy requests, or product-data concerns, email [email protected].