Legal

Privacy Policy

Effective date: August 2026

Hardtack is a home inventory app built to work offline. Your data stays stored locally on your device. No account, no forced cloud, no analytics, no ads, no tracking, no data selling.

In short

  • None of your inventory data leaves your device.
  • No account to create, no sign-in, no online profile.
  • No analytics, no advertising trackers, no usage telemetry.
  • Your data is encrypted locally at rest (SQLCipher / AES-256).
  • Two technical exceptions, both anonymous and both unrelated to the contents of your inventory: crash reports, which you can turn off in the app, and anti-tampering diagnostics. Each is detailed below.

Data controller

Hardtack is published by an independent developer. Data protection contact: atech.contact@proton.me.

What data is processed, and where

All data you enter in the app is stored only on your device, in a local database. It is never sent to our servers (we operate no server that receives your data) nor to any third party. This includes:

  • Your inventory items (name, quantity, notes, expiry dates).
  • Your storage locations and categories.
  • Household member profiles and their needs.
  • Spending tracking and your app preferences.

You retain full control of this data. At any time you can export it (CSV / JSON) or back it up locally through your system's native share sheet (Files, Drive, iCloud Drive). In that case you choose the destination yourself, and it is governed by the provider you select.

Local encryption

Your inventory is encrypted at rest on the device with SQLCipher (AES-256). The encryption key is kept in the system's secure enclave (iOS Keychain / Android Keystore) and never leaves the device. The PIN code or biometric lock (Face ID / Touch ID / fingerprint) protects access to the app. Local shares (QR) are encrypted with AES-GCM using a key derived from your passphrase.

No server-side collection, no analytics

The app contains no analytics tooling, no advertising SDK, no usage tracker. We measure neither your screens nor your sessions nor your habits, we do not profile users, and we neither sell nor rent any data. The only components that talk to a third party are the two described in the next sections, and neither one observes your usage. Barcode product lookups query public databases (Open Food Facts, USDA FoodData Central, UPCitemdb) only when you scan an item. We send the barcode and strictly nothing else: no identifier, no account, no fragment of your inventory. The request reaches those databases from your IP address, as any network request would, and their own policies then apply to it. Each result is cached on the device, so a given barcode is never looked up twice.

Technical crash reports

To fix bugs, the app can send technical crash reports through Firebase Crashlytics, a service operated by Google (United States, certified under the EU-US Data Privacy Framework). A report carries technical information only: device model, operating system version, error stack trace, and the app's own recent diagnostic log lines. It never contains the contents of your inventory, and we attach no user identifier to it, so it is not linked to your identity. In App Store terms, this is "Diagnostics / Crash Data", collected for app functionality only.

You can turn these reports off at any time, in Settings → Privacy inside the app. Once the switch is off, nothing is transmitted. Be aware that Crashlytics still records a crash locally on the device, and would only upload it if you turned the reports back on.

Legal basis: our legitimate interest in keeping the app working correctly. The switch above is how you exercise your right to object.

App integrity and anti-tampering

Hardtack is a one-time purchase with no account and no server of ours behind it, which makes repackaged copies (an app recompiled, re-signed and redistributed) the main abuse to guard against. Two components handle that, and both send anonymous technical signals outside the device:

  • freeRASP, from Talsec (Lynx SFT s.r.o.), checks that the app has not been modified and reports integrity diagnostics: device state (rooted or jailbroken device, emulator, attached debugger), the app's signature, plus an anonymous app-instance identifier and device identifier. It carries no personal data and nothing from your inventory. On the free edition of this component, which is the one we use, these diagnostics cannot be turned off. The app states this on its privacy screen as well.
  • Firebase App Check (Google), backed by Play Integrity on Android and App Attest on Apple devices, confirms that a request comes from a genuine, unmodified installation. It transmits an attestation token and an anonymous installation identifier, never your data.

Legal basis: our legitimate interest in protecting the app against fraud and tampering. These signals describe the device and the binary, not you, and they are never cross-referenced with your inventory, which never leaves the device in the first place.

System permissions

  • Camera: used only to scan barcodes and QR codes. No image is transmitted, the camera feed stays on the device.
  • Local notifications: used to alert you as expiry dates approach. They are generated and scheduled locally, with no push notification server.

Every permission is optional: the app remains usable if you decline it (manual entry instead of scanning, for example). You can revoke any permission in your system settings at any time.

In-app purchases and restore

Hardtack offers a one-time purchase. Purchases and their restoration are handled by the app stores (Apple App Store, Google Play) and by our billing provider, RevenueCat (United States), which receives an anonymous purchase identifier and the technical details of the transaction. We neither receive nor store your payment details, and none of these parties receives your inventory. Transaction processing is governed by those providers' privacy policies.

Contacting us

If you contact us by email, we process the message you send and your email address solely to reply to you and improve the app. None of this information is used for advertising.

Your rights (GDPR)

Because your data is stored locally and stays under your sole control, you can view, edit or delete it directly in the app, with no intermediary:

  • Access and portability: export your data as CSV / JSON.
  • Rectification: edit any item at any time.
  • Erasure: delete your data in the app, or uninstall the app to wipe all local data.
  • Objection / restriction: turn off crash reports in Settings → Privacy. The anti-tampering diagnostics have no switch, as stated above.

Because your data stays on your device, most of these rights are exercised directly in the app. For a request that requires us, use the data protection contact listed above. You also have the right to lodge a complaint with your data protection authority.

Children

Hardtack is not intended for children and does not knowingly collect any data about them.

Changes to this policy

We may update this policy to reflect changes to the app or to applicable regulation. The effective date above indicates the latest version. In case of a significant change, we will indicate it in the app or on this site.