ShelfSense App Privacy Policy
Last updated: 21 August 2026
This policy covers the ShelfSense mobile app for iOS and Android, published by NoordWell B.V. (Netherlands). It does not cover the noordwell.com shop — that is covered by our store privacy policy.
The short version: ShelfSense works without an account, most of what it knows about you never leaves your phone, and we do not run advertising or analytics SDKs of any kind. We do not sell your data, and we never have.
What the app keeps on your device
These never leave your phone. We cannot see them:
- Your routine — the goal you chose, which evenings you scheduled, and which steps you have ticked off.
- Treatments you built yourself, and any notes attached to them.
- Looks you saved as favourites.
- Cropped product pictures cut out of your shelf photos, cached so your stash loads instantly.
- Virtual try-on results.
- Expiry and routine reminders. These are scheduled by your phone, on your phone — no server is involved and no reminder is sent to us.
What we store in the cloud
One thing: your stash. For each product you keep, that is the brand, product name, category and type, the date you opened it, the price you entered if you entered one, and any note you added. It is stored in Google Cloud Firestore under an account identifier, so it survives reinstalling the app and follows you to a new phone.
Nobody but you can read it. Our security rules only allow reads and writes where the account identifier matches the signed-in account, and those rules are deployed from version control, not edited by hand.
Photos, and what the AI sees
ShelfSense uses Google's Gemini models through Firebase AI Logic. Two kinds of photo are sent:
- Shelf photos. When you scan, the photo is sent to Gemini so it can read the labels and tell us what products are in the picture. We use the returned product names; the photo is not stored on our servers.
- Selfies, only if you ask for a virtual try-on. If you use try-on, the photo you pick is sent to Gemini along with the look's reference image, and a new picture is generated of you wearing that look. The result is cached on your device. We do not keep the selfie, and we do not use it to identify you — no face recognition, no face template, no matching you against anything.
We never send photos anywhere else, and we do not use your photos to train models. Google processes them as our service provider under the Firebase data-processing terms; see also Google's Gemini API terms. Camera and photo-library access is requested only when you first use a feature that needs it, and you can refuse or revoke it in your phone's settings — the rest of the app keeps working.
Your account
You do not need to sign in to use ShelfSense. On first launch the app creates an anonymous account — a random identifier with no name, no email and no link to you — purely so your stash has somewhere to live.
You can optionally upgrade that account to Sign in with Apple (iOS) or Google (Android) so your stash syncs across your devices. If you do, we receive the email address and display name that Apple or Google chooses to share with us. If you use Apple's "Hide My Email", we only ever see the relay address. We use it to keep your account attached to you, and to answer you if you contact support. Nothing else.
Authentication is handled by Firebase Authentication. We never see or store a password.
Deleting your account and data
In the app: open the profile screen, then the menu in the top-left, then Account → Delete Account.
That permanently erases, with no recovery:
- your stash in Firestore;
- your sign-in record, including the link to your Apple or Google identity (on iOS the Apple token is also revoked);
- your routine, custom treatments, favourites, cached pictures and scheduled reminders on the device.
Data on other devices you were signed into is removed from the cloud immediately; the local copy on those devices clears when the app next opens. Deleting the app without deleting your account leaves the stash in the cloud so a reinstall can restore it.
If you would rather we did it, or you no longer have the app installed, email info@noordwell.com from the address on the account and we will delete it within 30 days.
The shared product catalogue
When a product is identified for the first time, we look up a picture of it once and store it in a shared catalogue, filed under the brand and product name. The next person to scan the same bottle gets the picture without another lookup.
This catalogue holds only the brand, product name, category, type and picture URL. It contains no account identifier and nothing about who scanned it, so it cannot be traced back to you and is not deleted when your account is.
Links to shops
Where the app suggests buying something, the link may be an affiliate link, which means we may earn a commission if you buy. Following one takes you out of the app to that retailer, where their privacy policy applies. We do not pass your stash, your photos or your account details to any retailer.
What we do not do
- No advertising. No ad SDKs, no ad identifier, no ad profile.
- No analytics or crash-reporting SDKs. The app ships with Firebase Authentication, Firestore, AI Logic and App Check, and nothing else.
- No tracking you across other apps or websites.
- No selling or sharing of personal data, in the sense given to those words by the GDPR or by US state privacy laws.
Anti-abuse
The app uses Firebase App Check (App Attest on iOS, Play Integrity on Android) so our servers can tell a real install of our app from a script pretending to be one. It attests the app, not you.
Where your data is held, and for how long
Data is processed by Google Cloud on our behalf, and may be processed outside the European Economic Area. Those transfers rely on the European Commission's Standard Contractual Clauses, which form part of our agreement with Google.
We keep your stash for as long as your account exists. Delete the account and it goes, as described above.
Your rights
If you are in the EEA or the UK, you have the right to access, correct, export or erase your personal data, to restrict or object to processing, and to complain to a supervisory authority — in the Netherlands, the Autoriteit Persoonsgegevens. Our legal basis is performance of a contract for the parts needed to run the app you asked for, and consent for camera and photo access, which you can withdraw at any time in your phone's settings.
Similar rights apply under California and other US state privacy laws. We do not sell or share personal information, so there is nothing to opt out of.
Children
ShelfSense is for adults and is listed as 18+. It is not directed at children and we do not knowingly collect data from them. If you believe a child has given us data, email us and we will remove it.
Changes
If we change this policy in a way that materially affects you, we will say so in the app before the change takes effect. The date at the top always shows the current version.
Contact
NoordWell B.V.
Email: info@noordwell.com
Support (WhatsApp): +31 20 214 6660