Privacy Policy
Last updated: 28 September 2026
Hysa Tech (HYSA TECH SH.P.K., "we", "our", or "us") publishes Amberjar (the "App"), an iPhone app that keeps track of when your food, medicines and household things expire. This Privacy Policy explains what the App keeps, what leaves your iPhone and why, which providers are involved, and the rights you have. It applies to the App and to this website's Amberjar pages. By installing or using the App, you acknowledge the practices described here. If you do not agree with them, please do not use the App.
1. The Short Version
- There is no account. We never ask for your name, email address, phone number or a password.
- Your shelf stays on your iPhone. The things you add, their dates, notes and photos, your places and your reminders are stored on the device. We do not have a server copy, and we cannot see them.
- Label photos are read on your iPhone first. Only when the iPhone cannot read a label itself is a downsized copy of that photo sent to Google's Gemini model to be read. Neither we nor the App keep it. Things you type in or add by their code never send a photo.
- Nothing on your shelf is used for advertising, and medicine information is never shared with advertisers, RevenueCat, Meta or our analytics tools.
- We use Google Analytics for Firebase and Firebase Crashlytics to see which parts of the App are used and to fix crashes. They receive counts and fixed labels, never what is on your shelf, and you can turn them off in the App's Settings (section 5.4).
- We do receive subscription and advertising attribution data through Apple, RevenueCat and Meta, described in section 5. The advertising identifier (IDFA) is only shared if you allow tracking.
- We do not sell your personal information.
2. Who We Are
The controller responsible for personal data processed through the App is HYSA TECH SH.P.K., trading as Hysa Tech, based in Tirana, Albania. You can reach us about anything in this policy at [email protected].
3. What Stays On Your iPhone
The App creates and keeps the following on your device so that it can do its job. None of it is sent to us.
- Your shelf: each thing you add, with its name, brand, category, dates (such as "use by" or "best before"), whether it has been opened or frozen, lot number, notes, the place you keep it, and what happened to it (used, tossed or disposed of). For a medicine, also what you record about it: what it is for, its form and strength, who it is for, how to take it and whether it is a prescription.
- Photos you take in the App of labels, products and shelves, and any photo you choose from your library to be read. Photos are stored inside the App's own storage, not in your photo library.
- Your settings and reminders, including your digest time and which reminders are on. Reminders are scheduled on the device as local notifications; they are not sent from a server.
- Widgets and shortcuts read a summary of your shelf from storage shared between the App and its widgets on the same device.
A small amount is kept in the iOS Keychain, which iOS preserves even if you delete the App:
- a flag recording that you have finished onboarding, so a reinstall skips it;
- the times of your recent cloud reads, used for a fair daily limit on cloud reading (section 4.1);
- a random identifier used for your subscription (section 5.1). It is not derived from you, your Apple Account or your hardware.
None of these contain anything about what is on your shelf. If you export your shelf as a CSV file, the file goes wherever you choose to send it, and that transfer is yours rather than ours.
4. How Labels Are Read
Barcodes and 2D codes on packs are decoded on your iPhone. Where your iPhone supports Apple Intelligence, label photos are also read on the device by Apple's on-device model, and nothing leaves the iPhone.
4.1 The Cloud Reader (Google Gemini)
When the iPhone cannot read a label itself, the App sends to Google, through Firebase AI Logic:
- a downsized copy of the photo you just took or chose;
- text already recognised on the device from that photo;
- today's date and your language, so dates are read correctly.
Google's model returns the product name, the date and similar details, which the App shows you to confirm. The request carries no name, account or identifier of yours. We do not receive, store or view these photos, and the App does not keep the copy it sent. We use the paid Gemini API; under Google's terms for paid use, Google does not use these requests or its answers to improve its products, and may keep them for a limited period to detect abuse and meet legal obligations. See the Gemini API terms and Google's privacy policy.
To protect the service from misuse, each request is verified with Firebase App Check, which uses Apple's App Attest to confirm that it comes from a genuine copy of the App. Firebase also receives technical information that any internet request carries, such as your IP address and an app instance identifier. A photo of a medicine label is read only to tell you what it is and when it expires.
A quiet daily limit applies to cloud reads so that the service stays affordable and cannot be abused. It is counted on your iPhone (section 3), not on a server.
4.2 Product Names (Open Food Facts)
When the App reads a barcode, it may look up the product's name in Open Food Facts, an open product database. Only the barcode number is sent, with your IP address as part of the connection. Nothing else about you or your shelf is included.
5. Subscriptions, Measurement and Crash Reports
5.1 Purchases and Subscriptions
Payments are handled by Apple. We never see your card details or your Apple Account email. We use RevenueCat to know whether you have Amberjar Plus. RevenueCat receives:
- the random identifier described in section 3;
- your purchase and subscription status: the plan, when it started, whether it renewed, lapsed or was refunded, and Apple's transaction records for it;
- device and app information such as device model, iOS version, App version, storefront country, language and IP address;
- the attribution identifiers described in section 5.2.
Because the identifier is kept in the Keychain, reinstalling the App on the same iPhone brings your subscription back without you doing anything. RevenueCat processes this data on our behalf. See the RevenueCat privacy policy.
5.2 Advertising Attribution (Meta and Apple Ads)
We advertise Amberjar and need to know which adverts work. The App includes the Meta (Facebook) SDK, and RevenueCat sends subscription events to Meta from its servers. Between them, Meta receives:
- App events: that the App was installed and opened, and that a subscription started, renewed, was cancelled or refunded, with its price and currency. What is on your shelf is never part of an event.
- Identifiers: an anonymous Meta identifier, the identifier for vendors (IDFV), your IP address and basic device information, and, only if you allow tracking, the advertising identifier (IDFA).
Because this is tracking as Apple defines it, the App asks for your permission once, through Apple's App Tracking Transparency prompt, after you have started using your shelf. If you decline, the advertising identifier is not collected and events are marked as not permitted for tracking. Declining changes nothing else: every feature works exactly the same. You can change your answer at any time in iOS Settings, under Privacy & Security, then Tracking. Meta's own automatic purchase logging is switched off in the App. See Meta's privacy policy; you can also review and disconnect activity that businesses share with Meta in Meta's "Your activity off Meta technologies" settings.
We also use Apple Ads attribution: the App passes RevenueCat a token from Apple that tells us whether an install came from an Apple Ads campaign. Apple provides this without identifying you, and it needs no permission.
5.3 No Adverts Inside the App
Amberjar shows no advertising and contains no advertising network. We do not sell, rent or trade your personal information, and we never use your shelf, your photos or anything about your health to target advertising.
5.4 Usage Analytics and Crash Reports (Google Firebase)
To learn which parts of the App are used and to fix what breaks, the App uses Google Analytics for Firebase and Firebase Crashlytics, both provided by Google. They are on unless you turn them off in the App under Settings, then Your data, then "Share usage and crash reports". With the switch off, nothing is sent, and crash reports still waiting on your iPhone are deleted.
Google Analytics for Firebase receives:
- the screens you open, and events such as something being added, used or tossed, a Sweep being finished, the Plus screen being shown and whether a purchase went through. Each event carries only counts and fixed labels, for example how a label was read, how many days it had left, or whether it was food;
- an app instance identifier created by Firebase, session times, your device model, iOS version, App version, language and country, and an approximate location that Google derives from your IP address.
When the App crashes, or runs into an error it recovers from, Firebase Crashlytics receives the technical trace of what the App was doing, the type of error and its code (never its message), your device model, iOS version, free memory and storage, App version, an installation identifier, and the analytics events that led up to it. Firebase also records when the App starts and how long it runs, to measure its stability.
Neither receives the name, brand, barcode, lot, date, notes or photo of anything on your shelf, anything you type, or anything that tells a medicine apart from the other things you keep. The App uses the version of Google Analytics that does not collect the advertising identifier (IDFA), and does not give it the identifier for vendors (IDFV). Analytics is not linked to any advertising product, its advertising and personalisation features are off, and it is not shared with Google for benchmarking or support. Google processes this data on our behalf; see Privacy and Security in Firebase.
6. Medicines and Health Information
The medicines you track can say something about your health, so we treat them with extra care:
- They are stored only on your iPhone, like the rest of your shelf, together with what you record about them, such as what each is for, who it is for and how to take it.
- A medicine label photo leaves the iPhone only in the case described in section 4.1, and only to be read. To keep it on your iPhone, type the medicine in or add it by its code instead.
- Medicine information is never sent to RevenueCat or Meta, never used for advertising, and never sold or licensed to anyone. Usage analytics and crash reports (section 5.4) cannot tell a medicine apart from anything else on your shelf.
- Amberjar shows dates and general storage guidance. It is not medical advice; ask a pharmacist or doctor about your medicines.
Residents of Washington, Nevada and other US states with consumer health data laws can read our Consumer Health Data Privacy Policy.
7. Permissions and Why They Are Asked
- Camera: to photograph labels, codes and shelves. Without it you can still choose a photo or type things in.
- Notifications: for the daily digest and medicine and safety reminders. Decline it and the App works the same, without reminders.
- Tracking: only for advertising attribution, as described in section 5.2.
The App does not ask for your location, contacts, calendar or health records. Every permission can be refused or revoked in iOS Settings, and refusing one never changes what you have paid for.
8. Legal Bases (EEA, UK and Switzerland)
- Performance of our contract with you: providing the App, reading labels you ask it to read, and providing and restoring your subscription.
- Consent: advertising attribution that involves tracking (you give or refuse it through the App Tracking Transparency prompt), and notifications. Withdrawing consent does not affect processing that happened before.
- Label photos that could reveal something about your health: you take and submit such a photo yourself, for the single purpose of having it read. It is processed only for that, is not linked to you, and is not kept. You can avoid it at any time by typing the thing in or adding it by its code instead.
- Legitimate interests: measuring which of our adverts work at the level that needs no tracking, understanding how the App is used and fixing crashes (section 5.4, which you can object to at any time with the switch in Settings), protecting the cloud reader from abuse, keeping the service secure, and answering support requests.
- Legal obligations: keeping transaction records for accounting and tax purposes.
9. Your Rights and Choices
9.1 What You Can Do Yourself
- Delete any thing on your shelf, with its photo, from the App.
- Export your whole shelf as a CSV file from Settings.
- Keep every photo on your iPhone by typing things in or adding them by their code.
- Allow or refuse tracking, and notifications, in iOS Settings.
- Turn usage analytics and crash reports off in the App's Settings (section 5.4).
- Delete the App, which deletes your shelf and its photos from the device.
- Manage or cancel your subscription in your Apple Account. Cancelling stops future renewals and your access continues until the end of the period you have paid for. Refunds are handled by Apple.
9.2 Requests to Us
Depending on where you live, including under the GDPR in the EEA, the UK GDPR, Swiss law, Albania's law on personal data protection, and California and other US state privacy laws, you may have the right to access, correct, delete or receive a copy of personal data about you, to object to or restrict certain processing, to withdraw consent, to opt out of the sale or sharing of personal information, to appeal a decision we make about your request, and not to be treated differently for exercising any of these rights.
Almost everything lives on your iPhone, where you control it directly. For the subscription and attribution records held by our providers, write to [email protected] or follow the steps on our Data Deletion page. Because we hold no name or email for you, please include the Order ID from Apple's purchase receipt email, or the approximate date of purchase, so we can find the record. We may ask for information to confirm that a request is yours before acting on it. We respond within 30 days, or sooner where the law requires, and tell you if we need more time and why.
If you are not satisfied with our answer, you can appeal by replying to it, and you have the right to complain to a data protection authority, such as the one where you live or work. In Albania this is the Information and Data Protection Commissioner.
9.3 California and Other US States
In the last 12 months, through the App, we have collected these categories of personal information, from you and your device, for the purposes described in this policy: identifiers (the random subscription identifier, IDFV, IDFA if you allow it, the anonymous Meta identifier, the Firebase app instance and installation identifiers, and IP address); commercial information (your subscription and purchase history); internet or other electronic activity (App installs and opens, how the App is used, and crash reports); approximate location derived from your IP address; and, only transiently for reading a label, photos that may include health-related information. We disclose them only to the providers named in sections 4 and 5, for the business purposes described there.
We do not sell personal information, and we have no actual knowledge of selling or sharing the personal information of anyone under 16. Sending identifiers and App events to Meta to measure our adverts may be considered "sharing" for cross-context behavioural advertising under California law. You can opt out at any time by refusing or turning off tracking for Amberjar in iOS Settings, and by writing to [email protected] with the subject "Do Not Sell or Share", after which we will remove the attribution identifiers RevenueCat holds for you. We use sensitive personal information only to provide the App, not to infer characteristics about you.
10. How Long Data Is Kept
- On your iPhone: until you delete it or delete the App. The Keychain values in section 3 remain after deletion; they hold nothing about your shelf.
- Cloud reader requests: not kept by us or by the App; kept by Google only as its terms for paid API use allow (section 4.1).
- Subscription records: kept by RevenueCat and Apple while you have a subscription and afterwards as long as needed for accounting, tax and dispute purposes.
- Attribution events: kept by Meta under its own retention schedule, which we do not control.
- Usage analytics: event data is kept in Google Analytics for up to 14 months.
- Crash reports: kept by Firebase Crashlytics for 90 days.
- Support emails: kept as long as needed to resolve your request and keep a record of it.
11. International Transfers
Hysa Tech is based in Albania. Our providers, including Apple, Google, RevenueCat and Meta, process data on infrastructure that may be located outside your country, including in the United States. Where such transfers occur, they rely on appropriate safeguards such as adequacy decisions, the EU-US Data Privacy Framework where the provider is certified, or Standard Contractual Clauses approved by the European Commission, and their UK and Swiss equivalents. Your shelf does not cross any border unless you carry your iPhone there.
12. Children
Amberjar is not directed at children and is not intended for anyone under 13, or under the age of digital consent where you live without a parent's permission. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us and we will delete it.
13. Security
Data on your iPhone is protected by the iOS sandbox and device encryption, and the values in section 3 are held in the iOS Keychain. Every connection the App makes uses encrypted HTTPS. Cloud reader requests are checked with Firebase App Check so that only the genuine App can use it. No method of storage or transmission is perfectly secure, but the strongest protection here is structural: your shelf never leaves your iPhone, so there is no database of it for anyone to breach.
14. Changes to This Policy
We may update this Privacy Policy, for example when the App gains a feature or a provider changes. We will update the "Last updated" date above and, for material changes that affect how your data is handled, tell you in the App before the change applies. Where the law requires your consent to a change, we will ask for it.
15. Contact Us
- Email: [email protected]
- Company: HYSA TECH SH.P.K. (Hysa Tech), Tirana, Albania
- Website: hysa-tech.com
- Data deletion: hysa-tech.com/amberjar/account-and-data-deletion-request
