Our Shelf privacy policy

Publisher: Nathan Fogelson Ballard
Last updated: September 30, 2026
Privacy contact: natfo.apps@gmail.com

This policy explains how Our Shelf handles information when you use the iPhone or iPad app or contact its publisher. Our Shelf helps people invited to a private shelf share product photos and shopping information.

Information the app handles

The app uses shelf content and shopping history to display products, organize shelves, and synchronize changes. Sharing information lets it create invitations, manage membership, and check access. Support messages let the publisher answer questions, investigate problems or abuse, and handle privacy requests.

Our Shelf does not create a separate account or ask for your Apple Account password. Shared shelves use the iCloud account already signed in on your device. The sample shelf is separate: its content and changes stay on that device and are not uploaded to CloudKit.

Photos, permissions, and screening

You choose whether to take a product photo or select one through Apple's photo picker. The camera requires your permission; the photo picker supplies the image you select rather than giving the app general access to your library. You can change camera permission in your device's Settings.

New shared text and photos are screened on your device before upload. The photo model does not send images to a separate moderation service. Screening can make mistakes. Photos that you successfully share are stored in CloudKit for shelf members to view. The Test photo screening tool checks your chosen image locally without saving it to a shelf or uploading it.

The current app contains no advertising, analytics SDK, cross-app tracking, location-access feature, or contact-book access. It has no data-sale feature or advertising-data sharing integration.

Storage and sharing

Apple iCloud/CloudKit stores shared shelf content and the information needed to provide invitations and synchronization. The app also stores shelf records and photos on your device so you can browse offline and queue supported changes. Background iCloud notifications help refresh data; they are not user-visible advertising or message alerts.

People who accept an invitation can view and edit that shelf's content. The owner controls invitations and can remove members. Share only information you have permission to share. Members can save screenshots or other copies outside the app.

There is no separate publisher-operated server receiving shelf content from the app. The publisher receives information you send directly by email, or content from a shelf to which you choose to invite the publisher. Gmail handles emails sent to the contact address under Google's privacy policy. Apple handles its services under Apple's privacy policy.

Apple and Google may process information outside your province or country under their service terms and privacy policies. Information processed abroad may be subject to the laws of those locations. This policy does not promise a particular storage country or deletion schedule for those providers.

Retention and deletion

Shelf content remains in CloudKit while the shelf exists unless members delete individual records. Deleting or reporting a product removes its local product information and shopping history, and requests CloudKit deletion of the product and known Needed/Bought records. Deletion retries after reconnection. If another device later synchronizes older status records for a deleted product, the app queues those for deletion too. Records not yet encountered by an updated app can remain until synchronization catches up or the owner deletes the shelf. The owner can delete the whole shelf, including its CloudKit record zone and sharing information.

Any member can choose Report and remove for a product. The app immediately hides it on that member's device and queues deletion from the shared shelf without human review. An offline report is retried when the device reconnects. Other members' copies update when their devices synchronize.

When you leave a shelf, the app removes it from your local catalog and attempts to delete its managed photo files. It retains limited shelf and deleted-product identifiers and pending departure information to finish synchronization and prevent delayed changes from restoring deleted content. If the owner removes you, local cleanup happens after your app reconnects and detects loss of access. Unused photo files are checked again when the app launches. The app removes its older catalog file after a successful migration. Failed file cleanup, older app versions, and backups can still leave residual copies. Deleting the app removes its current local app storage; device backups are managed separately by Apple.

Members can choose Block owner and leave to leave all joined shelves from that owner and refuse future invitations from them on that device. The block lists store iCloud identifiers and display/shelf labels locally until you unblock them, remove the app, or the app clears local data following an iCloud sign-out/account switch. The app also keeps locally cached record-contributor identities and limited shelf identifiers to apply blocks and finish pending departures or removals. Blocks do not automatically carry over to another device. Unblocking does not automatically rejoin shelves, invite someone back, or cancel pending departures/removals.

In app versions with People and blocking, you can block a member or known contributor. If you own a shelf, their known content is hidden on your device and the app queues their removal from your owned shelves through CloudKit; existing content is not automatically deleted for other members. If you are a member, the app leaves known joined shelves with that person and rejects invitations to those blocked shelves or invitations that show a blocked person. CloudKit may not reveal every participant in advance. If the app later discovers a blocked contributor in a joined shelf, it leaves before displaying that contributor's incoming records. Blocks cannot stop someone using another account, revoke copies already saved, or ban them from other people's shelves.

Leaving or being removed does not delete your earlier contributions from the shelf used by remaining members. Delete those contributions while you still have access, or ask the owner to remove them. The app cannot erase screenshots, exported photos, or other copies saved outside it. Offline devices and Apple-managed backups may retain copies after a deletion; changes do not reach every copy immediately.

The publisher deletes support and privacy emails from the managed mailbox within 90 days after the request is resolved, including attachments and mailbox Trash. Unresolved requests remain while being handled. Google's service-level backups and any copies held by the sender are governed separately by Google and the sender.

Your choices and privacy requests

You can view, edit, and delete shared product information while you have access, decline invitations by ignoring them, leave a joined shelf, and delete shelves you own. You can withdraw camera permission in Settings. Removing the app stops its future activity on that device but does not delete existing CloudKit shelves or other members' copies. Our Shelf cannot delete your Apple Account.

Email natfo.apps@gmail.com to ask about access, correction, deletion, retention, or a privacy complaint. Identify the relevant shelf or issue without sending unnecessary private photos, passwords, or identity documents. We may need enough information to confirm the request relates to you and to understand what information the publisher can access. Because the publisher has no separate copy of every shelf, some requests need to be carried out by you or your shelf's owner through the app. We will explain that if it applies.

Audience and protecting your information

Our Shelf is intended for a general audience and is not specifically directed at children. It does not ask for dates of birth or verify ages. Avoid placing sensitive personal information in product photos or notes. If a child's personal information has been shared inappropriately, contact the publisher and the shelf owner to arrange removal.

The app relies on Apple's app storage, iCloud account controls, and CloudKit sharing permissions. Protect your device and Apple Account, and invite only people you trust. No service can guarantee absolute security or recover copies another member has saved.

The privacy and support website

Cloudflare Pages hosts the public privacy and support pages. Cloudflare processes technical request information, such as IP addresses, browser details, and requested URLs, to deliver and protect the website under Cloudflare's privacy policy. The pages contain no submission forms, advertising, or analytics scripts added by the publisher. Cloudflare may use its own security mechanisms and cookies. Its service records and retention are managed under its own policies. The website does not receive your shelf photos or shopping records.

Policy changes and contact

This policy may change when app features or information practices change. The published policy will show its last-updated date. For questions or complaints, contact Nathan Fogelson Ballard at natfo.apps@gmail.com.