Expiry Tracker – Privacy Policy

Company: Exponential Dog
Effective: August 6, 2026
Previous version: May 10, 2026

1. Introduction

Exponential Dog developed Expiry Tracker as a mobile application for tracking food expiry dates. This document explains what personal data we collect, why we collect it, with whom we share it, and your rights regarding that data.

By using Expiry Tracker you consent to the practices described in this policy. If you do not agree, please discontinue use of the app.

Note for existing users: This version of the privacy policy has been updated to reflect the introduction of the Shared Fridge feature. When Shared Fridge is enabled, food data and photos are uploaded to cloud storage and shared with other household members. All relevant changes are described in detail below.

2. Information We Collect

2.1 Data You Provide

Data Where stored Purpose
Food item photos (taken with camera) Locally on device. Uploaded to Firebase Storage only if you enable Shared Fridge. Identify items visually in the fridge grid
Product names / notes Locally on device. Synced to Firebase Firestore only if you enable Shared Fridge. Label and recall items
Expiry dates Locally on device. Synced to Firebase Firestore only if you enable Shared Fridge. Urgency alerts, sorting, widgets
Shopping list items (names only) Locally on device only. Never uploaded to the cloud. Shopping session tracking
Display name (Google account or anonymous) Firebase Authentication. Shown to household members in Shared Fridge. Identify who added each item in a shared fridge
Email address (if you sign in with Google) Firebase Authentication. Used as fallback display name if no display name is set. Account identification

2.2 Data Collected Automatically

Firebase Analytics
Google Firebase Analytics collects anonymised usage information, including app launches, feature interactions, and navigation patterns. We use this to understand how users interact with the app and to prioritise improvements. Firebase may collect a device identifier, approximate location (country/region derived from IP address), device model, and OS version. Google LLC processes this data under their privacy policy.

Examples of events we log: barcode scan completed, expiry date entry method used (camera OCR / voice / manual), filter and sort selections in the fridge view, recipe difficulty selected, shopping session completed, shared fridge created or joined. We do not log the content of individual items (e.g. specific food names) in analytics.

Firebase Crashlytics
Firebase Crashlytics automatically collects crash reports when the app encounters unexpected errors. Reports may include device model, OS version, app version, and a stack trace. No personally identifiable information is intentionally included in crash reports. Crashlytics is disabled in debug builds.

RevenueCat
RevenueCat manages in-app purchases and subscription entitlements. RevenueCat may collect your device identifier and purchase history to verify your subscription status. Your payment details are handled entirely by the Google Play Store and are never accessible to RevenueCat or to us.

Google Gemini AI (recipe feature)
When you use the AI recipe suggestions feature, the names of your expiring food items are sent to the Google Gemini API to generate personalised recipe ideas. No photos, exact quantities, or personal identifiers are included in these requests. Generated recipes are cached locally on your device. Google LLC processes Gemini API requests under their privacy policy.

Open Food Facts
When you scan a product barcode, the barcode number is sent to the Open Food Facts public API to retrieve the product name and photo. Open Food Facts is an open-source, non-profit food database. No personal data is sent alongside the barcode lookup request.

3. The Shared Fridge Feature

The Shared Fridge feature allows you to synchronise your fridge in real time with other members of your household. This feature is entirely opt-in and is not enabled by default. When you choose to enable it, the following applies.

3.1 What data is uploaded to the cloud

Data Cloud service Visible to
Item expiry dates Firebase Firestore All fridge members
Product names / notes Firebase Firestore All fridge members
Date item was added Firebase Firestore All fridge members
Display name of user who added each item Firebase Firestore All fridge members
Food item photos (compressed JPEG) Firebase Storage All fridge members
Fridge membership list (user IDs and display names of all members) Firebase Firestore All fridge members
Firebase Auth user ID (UID) of each member Firebase Firestore Used internally for access control; not displayed to users
Timestamps of all item and fridge changes Firebase Firestore Used internally; not displayed

3.2 Account sign-in for Shared Fridge

To use the Shared Fridge feature you must sign in with a Google account. All users receive an anonymous Firebase UID automatically on first launch (no action required). Signing in with Google links your display name and email address to this UID so that other fridge members can see who added each item.

Data received from Google Sign-In and stored in Firebase Authentication:

3.3 Invite links

When a fridge owner shares an invite link, the link contains an encoded token that encodes the fridge identifier and the owner's display name. The token is transmitted via standard Android share mechanisms (SMS, messaging apps, etc.) and is not logged by us. Joining via the link grants read and write access to the shared fridge in Firebase Firestore.

3.4 How to stop sharing and delete your cloud data

4. Camera Permission

android.permission.CAMERA

The app uses your camera to photograph food items and to scan barcodes and expiry date labels. Camera access is used only while you are actively using the scan or manual entry screens. The app does not access your camera in the background.

Photos taken within the app are saved to app-private storage on your device. If you have enabled the Shared Fridge feature, photos are additionally compressed and uploaded to Firebase Storage so that other fridge members can see them. If Shared Fridge is not enabled, photos never leave your device.

5. Microphone Permission

android.permission.RECORD_AUDIO

The app optionally allows you to speak expiry dates as an alternative to manual entry. Voice input is processed entirely on-device using the Android Speech Recognition API. The app does not record, store, or transmit your voice.

6. Notifications

android.permission.POST_NOTIFICATIONS

With your permission, Expiry Tracker sends local notifications to remind you of items expiring within the next seven days. Notifications show only the count of expiring items, not their names or photos. Notification data is not transmitted anywhere — it is generated locally on your device by a background WorkManager job.

7. Internet Access

Expiry Tracker requires internet access to:

8. Data Storage and Retention

8.1 Local storage (all users)

Fridge items, shopping lists, and app preferences are stored locally in a private Room database and SharedPreferences on your device. This data is not accessible to other apps and is permanently deleted when you uninstall Expiry Tracker. You can also clear all local data by going to Android Settings → Apps → Expiry Tracker → Clear Data.

8.2 Cloud storage (Shared Fridge users only)

When Shared Fridge is enabled, item data is synced to Firebase Firestore and food photos are stored in Firebase Storage. This data:

Firebase Authentication records (your UID, email, and display name) are retained by Google until you request account deletion through Firebase or contact us.

8.3 Analytics and crash data

Firebase Analytics data is retained according to Google's standard analytics retention period (default 2 months for user-level data, up to 14 months for event data). Firebase Crashlytics retains crash reports for 90 days. These retention periods are governed by Google's policies and are not directly controlled by us.

9. Third-Party Services

Service Purpose Data shared Privacy policy
Google Firebase Authentication Account identity for Shared Fridge Email, display name, UID policies.google.com/privacy
Google Firebase Firestore Shared fridge data sync Item data, member list, timestamps policies.google.com/privacy
Google Firebase Storage Food photo sync in shared fridge Compressed food photos policies.google.com/privacy
Google Firebase Analytics Usage analytics Anonymised app usage events policies.google.com/privacy
Google Firebase Crashlytics Crash reporting Device info, stack traces policies.google.com/privacy
Google Gemini API AI recipe generation Food item names (no personal identifiers) policies.google.com/privacy
RevenueCat Subscription management Device ID, purchase history revenuecat.com/privacy
Open Food Facts Product name lookup Barcode number only world.openfoodfacts.org/privacy

10. Data Sharing With Other Users

When you use the Shared Fridge feature, certain personal data — specifically your display name and the food items you add — is shared with other members of your household fridge. This sharing is limited to members you have explicitly invited or whose invitation you have accepted. We do not share your data with any other users or third parties beyond what is described in this policy.

11. Children's Privacy

Expiry Tracker is not directed at children under the age of 13. We do not knowingly collect personal information from children under 13. If you believe your child has provided personal information through the app, please contact us and we will take steps to delete it promptly.

12. Your Rights

Depending on your jurisdiction, you may have the right to access, correct, delete, or export personal data held about you, and to object to or restrict certain processing.

12.1 European Union / EEA (GDPR)

Where the GDPR applies, our legal bases for processing are: contractual necessity (running the core app and Shared Fridge features you request), consent (optional features such as usage analytics, which you can withdraw at any time via the Settings toggle), and legitimate interest (crash reporting and security, to keep the App working and safe). You have the right to access, rectify, erase, restrict, or port your data, to object to processing based on legitimate interest, and to lodge a complaint with your local data protection authority.

12.2 California (CCPA/CPRA)

We do not sell or share your personal information for money or for cross-context behavioral advertising, and we have not done so in the preceding 12 months. California residents have the right to know what personal information we collect, to request deletion of it, to correct inaccurate information, and to not be discriminated against for exercising these rights. To exercise any of these rights, use the in-app options described below or contact us at motoharujap@gmail.com.

12.3 International data transfers

Google Firebase and the other third-party services listed in Section 9 may process and store your data on servers located outside your country of residence, including in the United States. Where required, such transfers rely on the safeguards those providers make available (for example Google's participation in recognised data transfer frameworks and its standard contractual terms) — see each provider's privacy policy linked in Section 9 for details.

Deleting your data

13. Security

All data transmitted between the app and Firebase services is encrypted in transit using TLS. Data stored in Firebase Firestore and Firebase Storage is encrypted at rest by Google. Local data on your device is protected by Android's app sandboxing. We do not implement additional end-to-end encryption on shared fridge data, meaning that Google can technically access it as the cloud service provider.

14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. Material changes — such as the introduction of new data collection or new third-party services — will be reflected by updating the effective date at the top of this document. We encourage you to review this policy periodically. Continued use of the app following any changes constitutes acceptance of the updated policy.

15. Contact Us

Exponential Dog
Email: motoharujap@gmail.com