Legal

Privacy Policy

Effective date: July 2026

Hardtack is a home inventory app built to work offline. Your data stays stored locally on your device. No account, no forced cloud, no analytics, no ads, no tracking, no data selling.

In short

  • None of your inventory data leaves your device.
  • No account to create, no sign-in, no online profile.
  • No analytics, no advertising trackers, no usage telemetry.
  • Your data is encrypted locally at rest (SQLCipher / AES-256).
  • Three things ever leave the device, and none of them describes what you store: anonymous crash reports, which you can turn off in the app, the purchase receipt handled by the store, and the barcode you scan when you look a product up. Each one is detailed below.
  • Two further paths use the network without Hardtack transmitting anything of yours: the support email, which the app only pre-fills as a draft in your own mail client and which leaves only if you press send, and the native rating dialog, which your operating system draws and which carries no app data at all.

Data controller

Hardtack is published by an independent developer. Data protection contact: atech.contact@proton.me.

What data is processed, and where

All data you enter in the app is stored only on your device, in a local database. It is never sent to our servers (we operate no server that receives your data) nor to any third party. This includes:

  • Your inventory items (name, quantity, notes, expiry dates).
  • Your storage locations and categories.
  • Household member profiles and their needs.
  • Spending tracking and your app preferences.

You retain full control of this data. At any time you can export it (CSV / JSON) or back it up locally through your system's native share sheet (Files, Drive, iCloud Drive). In that case you choose the destination yourself, and it is governed by the provider you select.

Local encryption

Your inventory is encrypted at rest on the device with SQLCipher (AES-256). The encryption key is kept in the system's secure enclave (iOS Keychain / Android Keystore) and never leaves the device. The PIN code or biometric lock (Face ID / Touch ID / fingerprint) protects access to the app. Local shares (QR) are encrypted with AES-GCM using a key derived from your passphrase.

No server-side collection, no analytics

The app contains no analytics tooling, no advertising SDK, no usage tracker. We measure neither your screens nor your sessions nor your habits, we do not profile users, and we neither sell nor rent any data. Three things, and three things only, ever leave the device, and none of them describes what you use the app for: the crash reports below, the purchase receipt handled by the store, and the barcode you scan when you look a product up. Barcode product lookups query public databases (Open Food Facts, USDA FoodData Central, UPCitemdb) only when you scan an item. We send the barcode and strictly nothing else: no identifier, no account, no fragment of your inventory. The request reaches those databases from your IP address, as any network request would, and their own policies then apply to it. Successful results are kept on the device, so an identified barcode is not looked up again.

Technical crash reports

To fix bugs, the app can send technical crash reports through Firebase Crashlytics, a service operated by Google (United States, certified under the EU-US Data Privacy Framework). A report carries technical information only: device model, operating system version, error stack trace, and the app's own recent diagnostic log lines. It never contains the contents of your inventory, and we attach no user identifier to it, so it is not linked to your identity. In App Store terms, this is "Crash Data" and "Other Diagnostic Data", collected for App Functionality only. On Google Play, it is declared as optional collection, which is exactly what the switch below makes it.

You can turn these reports off at any time, in Settings → Privacy inside the app. Once the switch is off, nothing is transmitted. That one switch covers everything the app sends on its own initiative: turn it off and Hardtack makes no outbound call you did not trigger yourself. Be aware that Crashlytics still records a crash locally on the device, and would only upload it if you turned the reports back on.

Legal basis: our legitimate interest in keeping the app working correctly. The switch above is how you exercise your right to object.

Writing to us from inside the app

Settings → About → Write to us sends nothing by itself. It opens a draft in your own mail client, pre-filled with the template you picked and a short technical block: app version and build number, Free or Pro, platform, operating system version, and the language the app is displaying. That block carries no identifier, no inventory, no storage location and no barcode history. It is shown on screen before the draft opens, so you can edit it or delete it. Hardtack makes no network request on this path, and nothing is sent until you press send yourself. Once you do, we process your message and your address for the sole purpose of replying to you.

The rating prompt

After a milestone, a kit reaching 100 % or your self-sufficiency target being met, the app may ask the operating system to show its native rating dialog (App Store review request, Google Play In-App Review). That dialog is drawn and handled entirely by the system. No application data is transmitted: we do not learn whether it appeared, and we do not learn what you answered. Both stores enforce their own quota on top of ours. A rating you then choose to leave is published on the store under your store account, which is between you and that store.

App integrity

Hardtack is a one-time purchase with no account and no server of ours behind it, which makes repackaged copies (an app recompiled, re-signed and redistributed) the main abuse to guard against. The check runs entirely on your device: on Android the app verifies its own signing certificate and the store it was installed from, on Apple devices its bundle identifier, its Team ID and its provisioning profile. Nothing is computed anywhere else and not a single byte is sent over the network for this. There is no attestation service, no integrity SDK, no third-party component involved. Because no data is processed outside your device, there is nothing here for you to object to or opt out of.

System permissions

  • Camera: used only to scan barcodes and QR codes. No image is transmitted, the camera feed stays on the device.
  • Local notifications: used to alert you as expiry dates approach. They are generated and scheduled locally, with no push notification server.

Every permission is optional: the app remains usable if you decline it (manual entry instead of scanning, for example). You can revoke any permission in your system settings at any time.

In-app purchases and restore

Hardtack offers a one-time purchase. Purchases and their restoration are handled by the app stores (Apple App Store, Google Play) and by our billing provider, RevenueCat (United States), which receives an anonymous purchase identifier and the technical details of the transaction. We neither receive nor store your payment details, and none of these parties receives your inventory. Transaction processing is governed by those providers' privacy policies.

Contacting us

If you contact us by email, we process the message you send and your email address solely to reply to you and improve the app. None of this information is used for advertising. The app can pre-fill that email for you, but it never sends it itself: see Writing to us from inside the app above.

Your rights (GDPR)

Because your data is stored locally and stays under your sole control, you can view, edit or delete it directly in the app, with no intermediary:

  • Access and portability: export your data as CSV / JSON.
  • Rectification: edit any item at any time.
  • Erasure: delete your data in the app, or uninstall the app to wipe all local data.
  • Objection / restriction: turn off crash reports in Settings → Privacy. That switch covers everything the app sends on its own initiative. What remains is what you trigger yourself: a barcode lookup when you scan, a support draft when you press send, a purchase when you buy.

Because your data stays on your device, most of these rights are exercised directly in the app. For a request that requires us, use the data protection contact listed above. You also have the right to lodge a complaint with your data protection authority.

Children

Hardtack is not intended for children and does not knowingly collect any data about them.

Changes to this policy

We may update this policy to reflect changes to the app or to applicable regulation. The effective date above indicates the latest version. In case of a significant change, we will indicate it in the app or on this site.