Privacy Policy
Last updated: September 8, 2026
The short version
The Shrunk iOS app has no accounts or logins, analytics or advertising SDKs, ads, or cross-app tracking. The app stores the minimum needed to look up a product, alert you about something you asked us to watch, and honour a subscription you bought from Apple. This website uses the limited, non-advertising measurement described below.
Website measurement
The Shrunk website uses Vercel Web Analytics and Speed Insights to measure page views, web performance, and whether an App Store call to action was clicked. Our custom CTA events contain the page path, CTA placement, and outbound destination with its query string and fragment removed. They never contain barcodes, store or location data, email addresses, form input, the app's device id, or app activity.
These tools run only on this website. They are not included in the Shrunk iOS app, are not used for advertising, and are not used to follow you across other apps or websites.
What Shrunk stores
The barcode you scanned (a 13-digit product number)
- When
- Every scan
- Where
- Sent to our API to look the product up. Not stored as a record of your scanning.
- How long
- Not retained
A random device id (a UUID generated on your phone at first launch)
- When
- First launch
- Where
- On your device, and in a
devicesrow in our database - How long
- Until you ask us to delete it
Your Apple push token
- When
- Only if you allow notifications
- Where
- Same
devicesrow - How long
- Until you turn notifications off or ask us to delete it
The Kroger store you picked (a store id, not your location)
- When
- When you pick a store
- Where
- On your device and in the
devicesrow - How long
- Until you change or clear it
Your approximate location
- When
- Only when you tap Use Current Location to find stores
- Where
- Processed transiently on your device through Apple Location Services; never sent to or stored by Shrunk
- How long
- Discarded after nearby stores are ranked
Your category and notification preferences
- When
- Onboarding and Settings
- Where
- On your device and in the
devicesrow - How long
- Until you change them
Your watchlist (product barcodes and brands)
- When
- When you add a product
- Where
- On your device and in a
watchesrow - How long
- Until you remove the item
A label photo you choose to contribute
- When
- Uploaded to our server with every contribution
- Where
- Written to Cloudflare R2 in a private human-review queue
- How long
- Deleted the moment it is reviewed, whether accepted or rejected
Your submission record (the barcode, the size you reported, the label text Shrunk read, your device id, and whether it was accepted)
- When
- When you contribute
- Where
- In a
submissionsrow in our database - How long
- Until you ask us to delete it
The net weight read from a label
- When
- When you contribute
- Where
- Stored as product data (
observations) - How long
- Kept as part of the product's size history
Your subscription status
- When
- After a purchase or restore
- Where
- Apple's signed transaction is verified and reduced to an expiry date in the
devicesrow - How long
- Until it expires or you ask us to delete it
Your recent scans
- When
- Every scan
- Where
- On your device only (
UserDefaults), never uploaded - How long
- Until you tap “Clear scan history” or delete the app
Shrunk never collects: your name, email address, postal address, phone number, device location, contacts, photo library, health data, payment details, or any advertising identifier. If you tap Use Current Location, Apple Location Services processes a one-time location on your device to find and rank nearby stores; Shrunk does not transmit or retain the coordinate. There is no advertising SDK and no analytics SDK in the app.
Label photos
Contributing a photo is optional and free. On your phone, Shrunk reads the label with Apple's on-device Vision framework to make an initial read. When you submit, the photo is uploaded to our server along with that reading, every time— not only when the reading is unclear. Every contribution is written to a private review queue so a human can compare the submitted reading with the label. The photo is deleted as soon as that review is accepted or rejected. No crowd reading becomes public and no alert is sent before this review. The number that survives review becomes part of the product's public size history and is not attributed to you.
Barcode scanning is separate, and no image ever leaves your phone: camera frames are read on device to extract the barcode digits, and only those digits are sent to our API to look the product up.
Notifications
If you allow notifications, Apple issues a push token for this install and we store it so watchlist alerts and the weekly digest can reach you. Turning notifications off in iOS Settings stops delivery; asking us to delete your device row removes the token.
Purchases
Shrunk Pro is an auto-renewable subscription sold by Apple. Apple handles payment; we never see your card, your Apple Account, or your billing details. Our server receives Apple's cryptographically signed transaction, verifies it, and stores an expiry date plus the random purchase token the app generated, so your subscription survives a reinstall — alongside two internal bookkeeping fields (a timestamp and a notification id) that only make sure Apple's renewal updates are applied in the right order and are never applied twice. Neither identifies you beyond what the purchase token already does.
Who else sees this data
- Cloudflare — hosts our API, database, photo storage and cache (United States).
- Vercel — hosts this website and provides the page-view, performance, and CTA measurement described above. It does not receive activity from the Shrunk iOS app.
- Apple — delivers push notifications, processes subscriptions, and resolves an optional one-time location or typed place on your device into a ZIP and coordinate. The coordinate ranks stores on-device and is then discarded.
- Kroger— when you have a store selected, we ask Kroger's Products API for that store's price and size for the barcode you scanned; we send the barcode and the store id. To find stores, we send only the ZIP resolved from your location or place search to Kroger's Locations API. To find alternatives, we send the product's category as a search term to Kroger's Products API. Neither the ZIP nor the category is stored by us, and we never send Kroger your device id, push token, coordinate, or search text.
- USDA FoodData Central and Open Food Facts — queried by barcode when a product is new to us, to fill in a name and image.
We do not sell or rent data, or share it with advertisers or data brokers. Website measurement is limited to the Vercel services described above.
Data sources and attribution
- U.S. Department of Agriculture, FoodData Central — Branded Foods package sizes. Public domain data; USDA does not endorse Shrunk.
- Kroger Products API— live store prices and sizes, shown in the app with the attribution “Prices from Kroger”. Shrunk is not affiliated with, endorsed by, or sponsored by The Kroger Co.
- Open Food Facts — product names and images, licensed under the Open Database License (ODbL). Open Food Facts is a nonprofit, community-maintained project and does not endorse Shrunk.
- Shoppers — label photos and net-weight readings contributed through the app.
- Brand and product names are trademarks of their owners, used to identify products.
Your choices
- Stop everything: delete the app. Nothing further is sent.
- Delete what is on the server: email us the Device ID shown in Settings → About → Device ID and we will erase the device record, your watchlist, your notification settings, and any submissions tied to it. Accepted size observations stay, because they are product facts and carry no identifier.
- Turn off alerts: Settings → Notification preferences, or iOS Settings → Notifications → Shrunk.
- Clear local scan history: Settings → Clear scan history.
- Manage or cancel Pro: iOS Settings → your name → Subscriptions. Apple handles cancellations and refunds.
Children
Shrunk is not directed at children under 13 and we do not knowingly collect data from them. There is nothing in the app that asks for a name or an age.
Security
Everything travels over HTTPS. The API stores no credentials for you, because there are none. Our own service credentials live in encrypted secret storage, never in the app.
Changes
If this policy changes materially, we will update the date at the top and note the change in the app's release notes. The current version always lives at this URL.
Contact
Shrunk is a product of Stack Curious, LLC · Florida, USA