MineralShelf — Privacy Policy
Effective date: [EFFECTIVE DATE] · Applies to: MineralShelf for iPhone, version 1.0 and later
The short version
MineralShelf keeps your collection on your iPhone.
There is no MineralShelf account, no MineralShelf server, and no analytics, advertising or tracking of any kind. I never receive your specimens, photos, prices, sales, buyers, localities or notes — not in summary, not anonymously, not at all.
The only information that leaves your iPhone is information you send yourself: a backup you export, a label you save, a report you share, an email you write — plus the ordinary requests Apple's own services make on the app's behalf to draw a map, find a place you searched for, or complete a purchase.
Everything below is the long version of those two paragraphs.
1. Who this policy comes from
MineralShelf is made and published by [LEGAL NAME], an individual developer in Ontario, Canada ("I", "me", "my"). There is no company, no staff and no third party with access to anything.
For the purposes of Canada's Personal Information Protection and Electronic Documents Act (PIPEDA), I am the person accountable for this policy. Because the app collects nothing, there is very little for me to be accountable for — but the address above is where questions go.
2. What MineralShelf stores, and where it stores it
Everything the app records is written to the app's own storage area on your iPhone: a database file (SwiftData) and a folder of JPEG photo files. That storage is inside the app's sandbox. It is protected by your device passcode through iOS Data Protection, it is not readable by other apps, and it is deleted when you delete the app.
| What | Examples of what you might put in it |
|---|
| Specimens | Name, category, species, variety, catalogue number, chemical formula, hardness, lustre, streak, transparency, fluorescence, crystal system, size, weight, condition, colour, locality, region, country, map coordinates, dates collected and acquired, how it was acquired and from whom, purchase price, estimated value, storage location, tags, notes |
| Photos | Up to five images per specimen, plus expedition and wishlist photos, stored as JPEG files |
| Expeditions | Trip name and type, site, locality, region, country, map coordinates, dates, fees, the people you went with (as tags), notes, photos |
| Wishlist | What you are looking for, priority, budget, a reference photo, notes |
| Market tools (Pro) | Market encounters, sales records, sale prices, purchase prices, profit, payment method, the names of buyers you choose to type, sale dates and notes |
| Preferences | Currency, default units, appearance, label and poster choices, sort orders, which sections are open, the highest catalogue number ever issued, and whether MineralShelf Pro is unlocked (stored by iOS in UserDefaults) |
Printed QR labels contain a link and nothing else: mineralshelf://specimen/<identifier>. The identifier is a random UUID created on your device. A label carries no name, no price and no locality, so a label left on a shelf or sent to a buyer reveals nothing about your collection.
2.1 Photos have their metadata removed
When you add a photo, MineralShelf re-encodes it before storing it: it draws a fresh image and writes that out as JPEG. EXIF metadata — including GPS coordinates of where the photograph was taken, the camera and lens, and the timestamp — does not reach the app's storage. The original in your photo library is untouched and keeps its own metadata.
The only location data MineralShelf holds is a coordinate you deliberately set as a map pin on a specimen or an expedition.
2.2 Information about other people is your responsibility
The Market tools let you record buyers' names. Expeditions let you record the people you collected with. That information is typed by you, about other people, and stored on your device.
If you are recording it in the course of commercial activity — selling at a show, for instance — then under PIPEDA and equivalent provincial laws you are the organization responsible for that personal information, not me. In practice that means: collect only what you actually need, tell people what you are recording if they ask, keep your device locked, and be careful where you send a backup or an exported report. See section 7 of the Terms and Conditions.
3. Permissions the app asks for
| Permission | When it is asked for | What it is used for | If you say no |
|---|
| Camera | The first time you photograph a specimen or open the QR scanner | Taking specimen and expedition photos; reading MineralShelf QR labels | You can still choose photos from your library; the scanner will not work |
| Photo library — add only | The first time you save a label or poster to Photos | Writing a finished label, poster or label sheet into your Photos library | Everything else works; use Share instead of Save |
| Location — while using the app | Only when you tap "Use current location" on a map pin | Writing one coordinate into the specimen or expedition you are editing | You can still set a pin by searching for a place or dragging the map |
Three notes on what these do not allow:
- MineralShelf has no permission to read your photo library. Choosing an existing photo uses iOS's own picker, which runs outside the app and hands over only the image you pick.
- Location is while in use only. The app has no background location access, and it never watches where you are — it asks iOS for one fix at the moment you tap the button.
- No permission is ever asked for contacts, microphone, health data, Bluetooth, calendars, reminders, the local network or notifications.
You can change any of these at any time in iOS Settings › MineralShelf.
4. What leaves your iPhone
4.1 Nothing comes to me
MineralShelf has no server. There is no endpoint anywhere that receives your data, and no mechanism in the app that could send it to me. If you want me to see something, you have to send it yourself, by email.
4.2 Apple services the app relies on
The app makes network requests, but only to Apple, and only for these four things. Apple's handling of them is governed by the Apple Privacy Policy, not by this one.
| Apple service | What is sent | What is not sent |
|---|
| App Store / StoreKit — buying or restoring MineralShelf Pro | Your purchase request, handled entirely by Apple in Apple's own sheet | I never see your Apple Account, name, email or payment details. Apple gives me sales reports that count units and revenue by country — never who bought |
| Apple Maps (MapKit) — drawing any map | The map region being displayed, so Apple can send back the map tiles for it | None of your specimen or expedition data travels with the request |
| Apple Maps place search — the search box on a map pin | The text you type in that search box | Nothing else from your collection |
| App Store review prompt — "Rate MineralShelf" in Settings | Handled by iOS; I receive only the public review, if you leave one | Your identity is Apple's business, not mine |
If a map or a search is a privacy concern for you, set map pins by dragging the map, or leave them unset — every other part of the app works without touching the network.
4.3 Crash reports and TestFlight
- If you have iOS Settings › Privacy & Security › Analytics & Improvements › Share with App Developers turned on, Apple may send me crash logs and aggregate performance statistics. These contain technical information about the crash — they do not contain your specimens, photos or sales.
- While MineralShelf is distributed through TestFlight, Apple additionally reports installs, sessions and crashes to me, and any feedback you submit through TestFlight comes to me with a screenshot and your device details attached — because that is what you asked TestFlight to send. Apple's TestFlight terms apply to that programme.
4.4 Things you choose to send
These leave your device only when you tap Share, Save or Export:
- Backups (
.mineralshelf files). A backup is a plain ZIP archive. It is not encrypted. It holds your prices, your buyers' names, your map pins, your notes and — if you include them — your photos, all in readable form. Whatever you do with that file is governed by wherever you put it: iCloud Drive, Files, AirDrop, a messaging app, an email. Keep backups somewhere you would be content to keep your collection's price list, because that is what they are. - Labels, label sheets and posters you save to Photos or share.
- Market reports exported as Excel (
.xlsx) files. - Email to support. If you write to me, I see your message, your email address and anything you attach. Please do not attach a backup unless I have asked for one; if you do, I delete it as soon as the problem is resolved.
4.5 Your own device backups
If iCloud Backup, or an encrypted backup to a computer, is turned on, your MineralShelf data is included in it, because it lives in the app's container. That copy is Apple's to hold under Apple's terms, and it is one of the better ways to make sure you do not lose your collection.
5. What MineralShelf never does
- No account, no sign-in, no email address required to use the app.
- No analytics. No Firebase, no Mixpanel, no Sentry, no home-made event logging.
- No advertising. No ads, no ad networks, no advertising identifier (IDFA).
- No tracking, as Apple's App Tracking Transparency defines it. The app's privacy manifest declares
NSPrivacyTracking as false and lists no collected data types, and the App Store privacy label says "Data Not Collected". - No third-party SDKs of any kind. The app has no dependencies outside Apple's own frameworks.
- No selling, renting or sharing of your information, now or ever. There is nothing to sell.
- No profiling, no automated decision-making, no machine learning on your data.
6. "Required reason" APIs
Apple requires apps to declare why they use certain iOS interfaces. MineralShelf's PrivacyInfo.xcprivacy declares exactly two, and uses each only for the stated reason:
| API | Declared reason | What it is actually for |
|---|
UserDefaults | CA92.1 | Storing the app's own preferences, on your device, for your use only |
| File timestamps | C617.1 | Finding photo files no record refers to any more (the "Remove unused photos" tool), and rotating the automatic safety backup |
Neither is used for fingerprinting, identification or tracking, and neither leaves the device.
7. Children
MineralShelf is a cataloguing tool for collectors. It is not directed at children under 13, and it collects no personal information from anyone of any age. There is no age gate because there is nothing to gate.
Parents should know that the app offers a one-time in-app purchase (MineralShelf Pro). If you share a device with a child, iOS Screen Time › Content & Privacy Restrictions › In-App Purchases is the control you want.
8. Your rights, and how to exercise them yourself
Privacy law gives you rights to access, correct, delete and port your personal information. Because MineralShelf never sends your information anywhere, you exercise all of them directly, without asking me and without waiting:
| Right | How |
|---|
| Access and portability | Settings › Export writes a complete backup of everything the app holds, in an open ZIP/JSON format |
| Correction | Edit any record in the app |
| Deletion | Delete individual records; Settings › Remove unused photos; or Settings › Erase Everything, which deletes every specimen, expedition, wish, sale and photo and resets catalogue numbers. Deleting the app removes everything it stored |
| Withdraw a permission | iOS Settings › MineralShelf |
| Object / restrict processing | There is no processing to object to — nothing is sent, analysed or profiled |
If you send me a request under a privacy law, I will answer honestly and quickly, but the answer will be that I hold no copy of your data and cannot access, produce or delete it for you.
Canada. This policy is written to meet PIPEDA and the substantially similar provincial laws, including Quebec's Law 25. You may complain to the Office of the Privacy Commissioner of Canada (priv.gc.ca) if you believe I have mishandled personal information.
United States / California. I do not sell or share personal information, and I have no personal information to disclose, delete or correct on request. There is no financial incentive programme.
European Union, EEA, United Kingdom and Switzerland. MineralShelf is not offered for sale in these regions, and the App Store listing excludes them. If you obtain the app another way, the substance of this policy still applies: no data is collected, so no transfer, legal basis or representative arises.
9. Security
- Your data sits in the app's sandbox, protected by iOS Data Protection and your device passcode. Use a passcode and keep iOS up to date; that is the single most effective thing you can do.
- There is no server to breach, no database of users, and no credentials to steal — the whole category of "the app was hacked and my collection leaked" does not exist here.
- Exported backups are not encrypted. This is the one genuine soft spot, and it is deliberate: a backup you cannot open is a backup that cannot save you. Store them in a location that is itself protected (iCloud Drive with two-factor authentication, or an encrypted disk), and think before you AirDrop one at a show.
- Photos restored from a backup are written only under the app's own naming scheme, so an archive cannot place files anywhere else on your device.
- No method of storage or transmission is perfectly secure, and I cannot guarantee absolute security — but by holding nothing, the app removes most of the ways this usually goes wrong.
10. How long things are kept
| What | Kept for |
|---|
| Everything in the app | Until you delete it, or delete the app |
| Emails you send to support | Up to 12 months after the question is resolved, then deleted |
| Any file you send me for debugging | Deleted as soon as the issue is resolved |
| Apple's purchase and crash records | Apple's retention periods, under Apple's policies |
11. Changes to this policy
If the app ever changes what it does with information, this policy changes first and the effective date at the top is updated. Material changes — anything that would surprise you — will also be called out in the App Store release notes for the version that introduces them.
The current version always lives at mineralshelf.ca/privacy.
12. Contact
Questions, corrections, or anything in this policy that does not match what you see the app doing:
[LEGAL NAME] support@mineralshelf.ca [MAILING ADDRESS]
I read everything that arrives.