AisleAI Privacy Policy

Your privacy matters.

SAME CURIOSITY · DIFFERENT IDEAS · A BRIGHTER TOMORROW

Last updated:

Who provides AisleAI

AisleAI is provided by Lars van der Veen under the smopeh name. This policy explains the app’s data handling, information you choose to send for support, and the website services involved.

For privacy questions or requests, email [email protected]. For app support, use AisleAI Support or email [email protected].

App data stored on your device

AisleAI stores the content you enter to organize your shopping: list and product names, quantities, units, categories, purchased status, assignments and barcodes; pantry items and expiry dates; recipes, ingredients and meal plans; price history; and store names, addresses and layouts you enter. It also stores preferences such as appearance, units, currency, selected list or store, and your family display name.

These records are stored locally. Pantry, recipes, meal plans, price history, store layouts and device preferences such as appearance, units, currency and the selected list or store are not synchronized through AisleAI’s shared-list service. If you copy ingredients or pantry items into a shared shopping list, the copied shopping-list information is shared as described below. Device backups may contain local app data, depending on your Apple settings.

You can use local lists without creating a separate AisleAI account. Sharing and connecting to existing shared lists require an available iCloud account.

iCloud and shared shopping lists

When you choose to share a list, AisleAI uploads that list to Apple’s CloudKit service while preparing the invitation, before the sharing sheet opens. Accepting an invitation downloads the shared list. Connecting to iCloud can also find lists already shared with your account.

Shared records include the list name, grocery items and their quantities, units, categories, purchased state, assignments and barcodes, together with record identifiers, dates and synchronization information. Sharing also uses your chosen display name and account-related participant identifiers. Apple participant names may be available through the sharing service.

Invited participants can see and edit the shared list and see names associated with participants and assignments. Content is stored in the owner’s private CloudKit database and made available to invited participants through Apple’s sharing system; AisleAI does not publish these lists to a public database. Only share content you intend other participants to see.

CloudKit and Apple push notifications are used to check for shared changes. Apple handles the account and notification delivery infrastructure. Apple describes its service processing in its Privacy Policy.

Optional barcode lookup

When you look up a scanned or typed barcode, AisleAI may request product information from Open Food Facts. The request sends the barcode, identifies the app and its version, and exposes ordinary connection information such as your IP address to that service. It does not upload camera images or the rest of your shopping list or pantry.

Product results are cached locally to reduce repeat requests and support offline use. Older results can remain cached; the cache’s refresh interval is not a promise of deletion. You can enter product details manually instead of using barcode lookup. See the Open Food Facts privacy notice for its handling of service data.

Optional voice entry and local processing

Voice entry requests microphone and speech-recognition permission. AisleAI uses Apple’s on-device speech recognition when it is supported. Otherwise, audio may be sent to Apple’s speech-recognition service for transcription. AisleAI does not save a recording of your voice; you review the recognized items before saving them as app content.

You can type instead and change microphone or speech permissions in device Settings. Apple explains its processing and controls in Ask Siri, Dictation & Privacy, including transcription in third-party apps.

Product categorization, parsing and shopping-route calculations run locally. The current app does not send your lists or recipes to an external generative-AI service.

Permissions and notifications

Camera permission is used to read barcodes when you start scanning. Microphone and speech permissions are used for voice entry. Notification permission allows alerts about shared-list updates. These feature permissions can be changed in device Settings. Background shared-list updates use Apple’s CloudKit notification infrastructure.

AisleAI does not request your device’s location. Store addresses and layout diagrams are information entered or selected in the app, rather than a live record of your location.

Analytics, diagnostics, advertising and tracking

The current app has no advertising or tracking integration and no third-party analytics SDK. It writes local operational diagnostics, such as synchronization status, timing, counts and error codes, to help diagnose problems. It does not include an automatic developer log-upload service.

Apple may separately process device or app diagnostics according to your device’s analytics and privacy settings and Apple’s notices. This is distinct from information you deliberately send when asking for support.

Retention and deletion

App data has no general automatic expiry. You can edit your content and remove pantry items, recipes and planned meals using the app’s controls.

Deleting a grocery item removes it from the active list but retains its original fields in a record marked as deleted. For shared lists, that record is also synchronized so other devices can apply the deletion. The current app does not automatically purge these retained records, including those in local-only lists.

Deleting a whole local shopping list removes that list and its grocery records from local app storage, but separate price history remains. A shared list must first be stopped or left through Manage sharing before the local list can be deleted.

Stopping or leaving sharing ends that list’s synchronization in the app and keeps a local copy. It does not guarantee erasure of Apple-stored records, backups, or copies other participants already have. Signing out of iCloud is not deletion. Removing the app may remove its local storage, but does not guarantee deletion of cloud data or other participants’ copies.

AisleAI has no single control that purges all local and cloud records. For data held by Apple or another service, its own controls and retention practices also apply. You can contact us about privacy concerns; this does not give the developer remote access to erase data from your devices or other participants’ devices.

Support and contact information

If you contact us, we receive the information you choose to provide, such as your name, email address, selected topic, message, and any screenshot you attach to an email. This information is used to respond to your request and address the issue you report. Do not include passwords or unnecessary private information.

As described in the General Privacy Policy, correspondence may be retained for as long as reasonably necessary to respond to your request or maintain relevant records. This support correspondence is separate from the app’s local or shared shopping data.

Website services and external providers

The smopeh website uses Cloudflare for hosting and security, Formspree to process and deliver contact messages, and Cloudflare Turnstile to help prevent spam and automated abuse. The contact form sends the name, email address, topic and message you enter to Formspree. Hosting and security services may process IP addresses, browser and request details, and verification information.

The General Privacy Policy explains the website’s contact-form and infrastructure processing. These services are not a mechanism for uploading your AisleAI shopping database.

External providers handle information under their own service terms and privacy notices. Their processing can involve countries outside your own, including outside the European Economic Area. This policy does not promise EU-only storage or a fixed deletion period for their service records. See Apple, Open Food Facts, Formspree and Cloudflare for their notices.

Your choices and privacy rights

You choose the content you enter, whether to share a list, whether to use barcode lookup or voice entry, and whether to contact us. Withdrawing a device permission stops future access through that permission; it does not erase information already processed.

Depending on applicable law, you may have rights to access, correct, erase or receive a copy of personal information, restrict or object to processing, and withdraw consent where processing relies on it. These rights have conditions and limits. To ask about information you have provided to the developer, contact [email protected]. For data controlled by a service provider, its request process may also be relevant.

You may complain to your local data-protection authority. In the Netherlands, this is the Autoriteit Persoonsgegevens.

Changes to this policy

This policy may be updated when AisleAI’s features or data handling change. The date above identifies the latest update.