Shrunk

Privacy Policy

Last updated: September 8, 2026

The short version

The Shrunk iOS app has no accounts or logins, analytics or advertising SDKs, ads, or cross-app tracking. The app stores the minimum needed to look up a product, alert you about something you asked us to watch, and honour a subscription you bought from Apple. This website uses the limited, non-advertising measurement described below.

Website measurement

The Shrunk website uses Vercel Web Analytics and Speed Insights to measure page views, web performance, and whether an App Store call to action was clicked. Our custom CTA events contain the page path, CTA placement, and outbound destination with its query string and fragment removed. They never contain barcodes, store or location data, email addresses, form input, the app's device id, or app activity.

These tools run only on this website. They are not included in the Shrunk iOS app, are not used for advertising, and are not used to follow you across other apps or websites.

What Shrunk stores

The barcode you scanned (a 13-digit product number)

When
Every scan
Where
Sent to our API to look the product up. Not stored as a record of your scanning.
How long
Not retained

A random device id (a UUID generated on your phone at first launch)

When
First launch
Where
On your device, and in a devices row in our database
How long
Until you ask us to delete it

Your Apple push token

When
Only if you allow notifications
Where
Same devices row
How long
Until you turn notifications off or ask us to delete it

The Kroger store you picked (a store id, not your location)

When
When you pick a store
Where
On your device and in the devices row
How long
Until you change or clear it

Your approximate location

When
Only when you tap Use Current Location to find stores
Where
Processed transiently on your device through Apple Location Services; never sent to or stored by Shrunk
How long
Discarded after nearby stores are ranked

Your category and notification preferences

When
Onboarding and Settings
Where
On your device and in the devices row
How long
Until you change them

Your watchlist (product barcodes and brands)

When
When you add a product
Where
On your device and in a watches row
How long
Until you remove the item

A label photo you choose to contribute

When
Uploaded to our server with every contribution
Where
Written to Cloudflare R2 in a private human-review queue
How long
Deleted the moment it is reviewed, whether accepted or rejected

Your submission record (the barcode, the size you reported, the label text Shrunk read, your device id, and whether it was accepted)

When
When you contribute
Where
In a submissions row in our database
How long
Until you ask us to delete it

The net weight read from a label

When
When you contribute
Where
Stored as product data (observations)
How long
Kept as part of the product's size history

Your subscription status

When
After a purchase or restore
Where
Apple's signed transaction is verified and reduced to an expiry date in the devices row
How long
Until it expires or you ask us to delete it

Your recent scans

When
Every scan
Where
On your device only (UserDefaults), never uploaded
How long
Until you tap “Clear scan history” or delete the app

Shrunk never collects: your name, email address, postal address, phone number, device location, contacts, photo library, health data, payment details, or any advertising identifier. If you tap Use Current Location, Apple Location Services processes a one-time location on your device to find and rank nearby stores; Shrunk does not transmit or retain the coordinate. There is no advertising SDK and no analytics SDK in the app.

Label photos

Contributing a photo is optional and free. On your phone, Shrunk reads the label with Apple's on-device Vision framework to make an initial read. When you submit, the photo is uploaded to our server along with that reading, every time— not only when the reading is unclear. Every contribution is written to a private review queue so a human can compare the submitted reading with the label. The photo is deleted as soon as that review is accepted or rejected. No crowd reading becomes public and no alert is sent before this review. The number that survives review becomes part of the product's public size history and is not attributed to you.

Barcode scanning is separate, and no image ever leaves your phone: camera frames are read on device to extract the barcode digits, and only those digits are sent to our API to look the product up.

Notifications

If you allow notifications, Apple issues a push token for this install and we store it so watchlist alerts and the weekly digest can reach you. Turning notifications off in iOS Settings stops delivery; asking us to delete your device row removes the token.

Purchases

Shrunk Pro is an auto-renewable subscription sold by Apple. Apple handles payment; we never see your card, your Apple Account, or your billing details. Our server receives Apple's cryptographically signed transaction, verifies it, and stores an expiry date plus the random purchase token the app generated, so your subscription survives a reinstall — alongside two internal bookkeeping fields (a timestamp and a notification id) that only make sure Apple's renewal updates are applied in the right order and are never applied twice. Neither identifies you beyond what the purchase token already does.

Who else sees this data

  • Cloudflare — hosts our API, database, photo storage and cache (United States).
  • Vercel — hosts this website and provides the page-view, performance, and CTA measurement described above. It does not receive activity from the Shrunk iOS app.
  • Apple — delivers push notifications, processes subscriptions, and resolves an optional one-time location or typed place on your device into a ZIP and coordinate. The coordinate ranks stores on-device and is then discarded.
  • Kroger— when you have a store selected, we ask Kroger's Products API for that store's price and size for the barcode you scanned; we send the barcode and the store id. To find stores, we send only the ZIP resolved from your location or place search to Kroger's Locations API. To find alternatives, we send the product's category as a search term to Kroger's Products API. Neither the ZIP nor the category is stored by us, and we never send Kroger your device id, push token, coordinate, or search text.
  • USDA FoodData Central and Open Food Facts — queried by barcode when a product is new to us, to fill in a name and image.

We do not sell or rent data, or share it with advertisers or data brokers. Website measurement is limited to the Vercel services described above.

Data sources and attribution

  • U.S. Department of Agriculture, FoodData Central — Branded Foods package sizes. Public domain data; USDA does not endorse Shrunk.
  • Kroger Products API— live store prices and sizes, shown in the app with the attribution “Prices from Kroger”. Shrunk is not affiliated with, endorsed by, or sponsored by The Kroger Co.
  • Open Food Facts — product names and images, licensed under the Open Database License (ODbL). Open Food Facts is a nonprofit, community-maintained project and does not endorse Shrunk.
  • Shoppers — label photos and net-weight readings contributed through the app.
  • Brand and product names are trademarks of their owners, used to identify products.

Your choices

  • Stop everything: delete the app. Nothing further is sent.
  • Delete what is on the server: email us the Device ID shown in Settings → About → Device ID and we will erase the device record, your watchlist, your notification settings, and any submissions tied to it. Accepted size observations stay, because they are product facts and carry no identifier.
  • Turn off alerts: Settings → Notification preferences, or iOS Settings → Notifications → Shrunk.
  • Clear local scan history: Settings → Clear scan history.
  • Manage or cancel Pro: iOS Settings → your name → Subscriptions. Apple handles cancellations and refunds.

Children

Shrunk is not directed at children under 13 and we do not knowingly collect data from them. There is nothing in the app that asks for a name or an age.

Security

Everything travels over HTTPS. The API stores no credentials for you, because there are none. Our own service credentials live in encrypted secret storage, never in the app.

Changes

If this policy changes materially, we will update the date at the top and note the change in the app's release notes. The current version always lives at this URL.

Contact

Shrunk is a product of Stack Curious, LLC · Florida, USA