Privacy Policy
Last updated: August 1, 2026
Operated by Stralen Digital LLC
1. Introduction
Welcome to ShelfCents ("we," "our," or "us"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website at shelfcents.com and our mobile application (collectively, the "Service").
ShelfCents is a direct-to-consumer application. We are NOT a healthcare provider, health plan, or healthcare clearinghouse, and we do NOT operate on behalf of any such entity. HIPAA (the Health Insurance Portability and Accountability Act) does not apply to ShelfCents. However, we take the protection of your personal information seriously and comply with other applicable privacy laws, including the FTC Act, the FTC Health Breach Notification Rule, the California Consumer Privacy Act (CCPA), the Virginia Consumer Data Protection Act (VCDPA), the Colorado Privacy Act (CPA), the Connecticut Data Privacy Act (CTDPA), the General Data Protection Regulation (GDPR), and other applicable data protection laws.
By using our Service, you agree to the collection and use of information in accordance with this policy. If you do not agree, please do not use the Service.
2. Information We Collect
We collect the following categories of information:
2.1 Information You Provide Directly
- Account Information: Email address, name, and password used for account creation and login.
- Pantry Data: Food items you add to your digital pantry, including names, quantities, categories, and expiration dates.
- Meal Preferences: Dietary restrictions, allergies, cuisine preferences, household size, and budget limits.
- Grocery Lists: Items you add to shopping lists, including estimated costs.
- Wellness Data: Water intake logs, mood entries, sleep patterns, and food waste journal entries you manually enter.
- Subscription Information: Billing status, plan type, and payment history (processed through Stripe; we do not store credit card numbers).
- Support Communications: Messages you send to us via email or contact forms.
2.2 Information Collected Automatically
- Device Information: Operating system version, device model, app version, and browser type.
- Usage Analytics: Anonymized data about feature usage, page views, session duration, and navigation patterns to help us improve the Service.
- Crash Reports: Error logs sent only when the app crashes, containing no personal data.
- Log Data: IP address, access times, pages viewed, and referring URLs, collected automatically by our hosting infrastructure.
2.3 Camera and Image Data
When you use the AI Fridge Scanner feature, you may take or upload photos of your fridge or pantry. These images are:
- Transmitted to our AI processing service (Groq) to identify food ingredients.
- Processed in real-time and not permanently stored on our servers.
- Never shared with third parties for marketing or advertising purposes.
- Used solely for the purpose of generating ingredient identification and recipe suggestions.
When you use the Exercise Tracking feature, your device camera is used for real-time pose detection. Camera feed is processed locally on your device using on-device machine learning (MediaPipe) and is never transmitted to our servers or any third party.
2.4 AI-Generated Content
Our AI features generate meal plans, recipes, grocery optimizations, and exercise form analysis. These AI outputs are:
- Suggestions only and do not constitute medical, nutritional, or fitness advice.
- Generated based on the input data you provide and general AI models.
- Not stored permanently unless saved by you within the app.
3. How We Use Your Information
- Provide, maintain, and improve the Service (meal planning, pantry tracking, grocery lists, exercise tracking, wellness tools).
- Process AI analysis of fridge photos and exercise form.
- Send expiry reminders and task notifications you have opted into.
- Process subscription payments and manage billing.
- Respond to support requests and communicate about your account.
- Detect, prevent, and address technical issues and fraud.
- Comply with legal obligations.
4. Legal Basis for Processing
Under applicable data protection laws, we process your data based on the following legal grounds:
- Consent: When you create an account, subscribe, opt into notifications, or upload photos.
- Contract: When processing is necessary to provide the Service you requested.
- Legitimate Interest: To improve our service, prevent fraud, and ensure security.
- Legal Obligation: When required by law (e.g., tax records, fraud prevention).
5. Data Retention
- Account data: Retained until you delete your account, then removed within 30 days.
- Fridge photos: Processed in real-time and not permanently stored. Transient images are discarded immediately after processing.
- Transaction data: Retained for 7 years for tax and accounting purposes (as required by law).
- Usage analytics: Anonymized after 12 months.
- Support communications: Retained for 3 years.
- Consent records: Retained for 5 years as evidence of consent.
- Security logs: Retained for 2 years for security auditing.
When you delete your account, we delete or anonymize your personal data within 30 days, except where retention is required by law.
6. Data Sharing and Disclosure
We do not sell your personal information to third parties. We do not share your personal information with third parties for their direct marketing purposes.
We may share information in the following limited circumstances:
- Service Providers: With vendors who perform services on our behalf (hosting, payment processing, AI processing), subject to contractual obligations to protect your data.
- Legal Requirements: If required by law, subpoena, or government request, or to protect our rights, privacy, safety, or property.
- Business Transfers: In connection with a merger, acquisition, or sale of assets (you will be notified before your data is transferred).
- Aggregated/Anonymized Data: We may share aggregated, non-identifying information for research or analytics purposes that cannot be used to identify you.
7. Third-Party Service Providers
We use the following third-party services that may process your data:
- Supabase (supabase.com, United States) — Database hosting and authentication. SOC 2 Type II certified.
- Stripe (stripe.com, United States) — Payment processing. PCI DSS Level 1 certified.
- Vercel (vercel.com, United States) — Web hosting and application infrastructure.
- Groq (groq.com, United States) — AI processing for meal planning and fridge scan features. Images are processed transiently and not retained.
- Google Analytics (analytics.google.com, United States) — Anonymized website usage analytics. Data is aggregated and does not identify individual users.
- Google AdMob (ads.google.com, United States) — Serves advertisements to free-tier users. AdMob may use device identifiers and advertising ID for ad personalization. You can opt out via your device settings.
- Sentry (sentry.io, United States) — Error monitoring and crash reporting. Collects anonymous diagnostic data (stack traces, device info) to help us fix bugs. No personally identifiable information is stored.
These providers process data on our behalf and are contractually obligated to protect your information. A full list of subprocessors is available upon request.
8. International Data Transfers
ShelfCents is based in the United States. If you access our service from the European Economic Area (EEA), United Kingdom, or Switzerland, your personal data will be transferred to and processed in the United States.
When we transfer data outside the EEA, we ensure appropriate safeguards are in place in accordance with GDPR Chapter V (Articles 44-49):
- Standard Contractual Clauses (SCCs): We rely on EU-approved Standard Contractual Clauses for data transfers.
- Data Processing Agreements: All service providers have signed data processing agreements that include SCCs.
- EU-US Data Privacy Framework: Where applicable, our US-based service providers participate in the EU-US Data Privacy Framework.
You may request a copy of the Standard Contractual Clauses by contacting us at shelfcents@gmail.com.
9. Your Rights Under GDPR (EEA, UK, Switzerland Residents)
If you are located in the EEA, UK, or Switzerland, you have the following rights under data protection law:
- Right of Access (Art. 15): Request a copy of the personal data we hold about you.
- Right to Rectification (Art. 16): Request correction of inaccurate personal data.
- Right to Erasure (Art. 17): Request deletion of your personal data ("Right to be Forgotten").
- Right to Restrict Processing (Art. 18): Request restriction of processing of your personal data.
- Right to Data Portability (Art. 20): Receive your personal data in a structured, machine-readable format.
- Right to Object (Art. 21): Object to processing of your personal data based on legitimate interests.
- Right to Withdraw Consent: Where processing is based on consent, you may withdraw consent at any time.
- Right to Lodge a Complaint (Art. 77): You have the right to lodge a complaint with a supervisory authority in your country of residence.
To exercise these rights, contact us at shelfcents@gmail.com. We will respond within 30 days. If we need additional time, we will notify you of the extension (up to 60 additional days for complex requests).
10. Your Rights Under CCPA/CPRA (California Residents)
If you are a California resident, the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA) gives you the following rights:
- Right to Know: Request disclosure of the categories and specific pieces of personal information we collect, the sources, and the purposes.
- Right to Delete: Request deletion of your personal information, subject to certain exceptions.
- Right to Correct: Request correction of inaccurate personal information.
- Right to Opt-Out of Sale/Sharing: We do NOT sell your personal information. If this changes, we will provide a "Do Not Sell or Share My Personal Information" link. You may submit an opt-out request at any time by emailing shelfcents@gmail.com.
- Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA/CPRA rights.
- Right to Limit Use of Sensitive Personal Information: If we collect sensitive personal information (e.g., health data), you may limit its use to providing the Service.
To exercise these rights, contact us at shelfcents@gmail.com. We will verify your identity before processing your request and respond within 45 days. We will not discriminate against you for exercising your rights.
11. Other U.S. State Privacy Laws
Residents of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and other states with applicable privacy laws have similar rights including the right to access, delete, correct, and opt out of targeted advertising or the sale of personal information. We do not sell personal information or engage in targeted advertising.
To exercise your rights under any applicable state law, contact us at shelfcents@gmail.com. We will respond within 45 days.
12. FTC Health Breach Notification Rule
ShelfCents is not covered by HIPAA. However, under the FTC Health Breach Notification Rule (16 C.F.R. Part 318), we are required to notify you and the FTC if there is a breach of your unsecured, individually identifiable health information.
A "breach" includes unauthorized access to, or disclosure of, health information — not just cybersecurity incidents. This means any sharing of your health-related data (wellness logs, exercise data, mood entries) without your authorization triggers notification obligations.
In the event of a breach, we will:
- Notify affected users within 60 days of discovering the breach.
- Notify the FTC if the breach affects 500 or more individuals.
- Notify the media if the breach affects 500 or more residents of a single state or jurisdiction.
- Provide a description of the information involved, steps users should take, and what we are doing to address the breach.
13. Automated Decision-Making and AI
ShelfCents uses artificial intelligence for meal planning, grocery optimization, food expiry predictions, fridge photo analysis, and exercise form analysis. Under GDPR Article 22, you have the right not to be subject to decisions based solely on automated processing, including profiling, which produce legal or similarly significant effects.
Our AI features:
- Generate meal plan suggestions based on your preferences and pantry items.
- Optimize grocery lists for budget savings.
- Predict food expiry dates.
- Identify ingredients from fridge photos.
- Analyze exercise form from camera feed.
These are suggestions only and do not produce legal effects. You can opt out of AI features by using the manual/algorithmic alternatives available in the app. No automated decision-making is used for any purpose that produces legal or similarly significant effects on users.
AI processing is performed by Groq (for fridge scans and exercise analysis) and our own algorithms. We do not use AI to make decisions about your account status, access, or pricing.
14. Cookies and Tracking
We use cookies and similar technologies for the purposes described below. For full details, see our Cookie Policy.
- Essential Cookies: Required for login, security, and core functionality. Cannot be disabled.
- Analytics Cookies: Google Analytics (anonymized). Only active with your consent.
- Marketing Cookies: Campaign tracking. Only active with your consent.
You can manage your cookie preferences through our cookie consent banner or your browser settings.
15. Children's Privacy (COPPA)
ShelfCents is not intended for children under 13 years of age (or under 16 in the EEA). We do not knowingly collect personal information from children under these ages.
If we become aware that we have collected personal information from a child under the applicable age without verification of parental consent, we will take steps to delete that information promptly. If you believe a child has provided us with personal information, please contact us at shelfcents@gmail.com and we will delete it within 30 days.
16. Data Security
We implement industry-standard security measures to protect your personal information:
- All data is encrypted in transit using TLS 1.2+ and at rest using AES-256.
- Authentication is handled by Supabase with secure session management.
- Payment processing is handled by Stripe (PCI DSS Level 1 certified); we never store credit card information.
- Access controls and role-based permissions limit who can access user data.
- Regular security monitoring and logging.
While we strive to use commercially acceptable means to protect your personal information, no method of transmission or storage is 100% secure. We cannot guarantee absolute security.
17. How to Delete Your Data
You can delete your account and all associated data at any time:
- In the app: Go to Settings > Account > Delete Account.
- By email: Send a request to shelfcents@gmail.com with the subject line "Delete My Account" and the email address associated with your account.
Upon deletion, we will delete or anonymize your personal data within 30 days, except where retention is required by law (e.g., transaction records retained for 7 years for tax purposes). Fridge photos that were already processed are not retained and cannot be deleted as they were never stored.
18. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by:
- Posting the updated policy on this page with a new "Last Updated" date.
- Sending an email notification to the address associated with your account.
- Displaying a prominent notice within the app.
Your continued use of the Service after changes are posted constitutes acceptance of the updated policy. We encourage you to review this policy periodically.
19. Contact Us
For any questions about this Privacy Policy or to exercise your data rights, contact us at:
- Email: shelfcents@gmail.com
- Subject line: "Privacy Request" or "Data Protection Inquiry"
- Website: https://www.shelfcents.com/contact
- Operated by: Stralen Digital LLC
- Data Protection Officer: ShelfCents Data Protection Team, shelfcents@gmail.com
We will respond to all privacy-related requests within 30 days (45 days for CCPA requests, 30 days for GDPR requests). If we need additional time, we will notify you of the extension.
