UC Exp Tracker

Privacy Policy

Effective date: August 6, 2026
UC Exp Tracker is a tool for tracking product expiry dates. It does not collect personal information for advertising, analytics, or profiling. It does record which staff member made each change, so that a shared inventory can be kept accurate across a team.

What the App Does

Staff scan a product barcode, confirm the product's details, and record its expiry date so items can be removed from the shelf before they expire.

Records are stored primarily on the device and can be synced through a private server with other team members.

Working Offline and Sync

The app works fully offline. Sync is optional, and is only active once a staff member enters their private access key (currently provided by the developer). Without a key, all data stays on the device and nothing is transmitted.

When sync is enabled, the app exchanges inventory records with the private server so that staff see the same up-to-date list. Sync runs when the app is opened, when the inventory list is pulled down to refresh, and when Sync Now is tapped.

Branches

Each access key is assigned to a single branch, and that assignment is held on the private server rather than chosen in the app.

Expiry records are exchanged only with other staff at the same branch. Product details — names, images, store section, shelf life, and supplier type — are shared across every branch, so a product recorded at one branch is recognised at the others.

A branch is an administrative label. It is not derived from the device's location and does not describe where the device is.

Record of Changes

When sync is enabled, the server keeps a record of who made each change. This is how a shared inventory stays trustworthy: it logs who did what.

Each entry records the name associated with the access key used, the branch that key is assigned to, a device label, the action taken, the item affected, and the time it reached the server.

Inside the app, staff names are visible to colleagues. An item shows the name of the staff member who added it and, once removed, the name of the staff member who removed it. These names are visible to other staff at the same branch.

The full record of changes is only visible to the private server's owner (the app developer). It is not shared with any third party, and is not used for advertising or analytics.

What Is Sent to the Private Server

No contact details, location data, advertising identifiers, or device identifiers assigned by Apple are collected or transmitted.

Access Keys

Each staff member receives an individual access key. The key is stored in the device's Keychain, is not included in iCloud or device backups, and is never sent anywhere except to the private server when authenticating.

Keys should not be shared. A shared key makes the record of changes inaccurate, since every action under it appears to come from one person. A key can be revoked by the private server's owner at any time, which immediately stops that device from syncing.

Because a key belongs to one branch, entering a different key on a device clears the expiry records stored on it — those records belong to the previous branch. Product details are shared across branches and are kept.

Where Data Is Held

No third-party cloud service, hosting provider, or analytics platform receives inventory data. The connection is routed through Cloudflare, which carries encrypted traffic to the server; inventory records are not stored there.

Deletion and Retention

Deleting an item in the app removes it for everyone once sync completes. The server keeps a record that the deletion happened, and who performed it, so mistakes can be identified and reversed.

The server also takes an automatic snapshot of expiry records every twelve hours and keeps the most recent seven days of snapshots. A deleted record can therefore remain inside those snapshots for up to seven days, after which the snapshot containing it is discarded. Snapshots are held on the same private server and are used only to recover from accidental data loss.

Deleting the app removes all data from that device. It does not remove records already shared with the team — those remain on the private server. Requests to remove or review records held there should be directed to the developer, who controls that server.

Camera Access

The camera is used solely to scan product barcodes. Frames are processed on-device in real time and are never saved or transmitted. Only retail barcode formats are recognised.

Product Lookups

When a barcode is not already known to the app, it is sent to the Open Food Facts API to retrieve a publicly available product name and images.

Only the barcode number is included in that request. No staff name, branch, device information, or location is sent. Open Food Facts is an open, non-profit database; their privacy policy is at openfoodfacts.org/privacy.

Third-Party Services

Changes to This Policy

If this policy changes, an updated version will be published with a new effective date. Continued use of the app after a change constitutes acceptance of the revised policy.

Contact

Questions about this policy can be directed to the app developer at skylightx510@gmail.com.