Freshli · Legal
Freshli Privacy Policy
Effective: 24 May 2026 · Last updated: 24 May 2026
This Privacy Policy applies specifically to the Freshli iOS application and any related Freshli services (together, "Freshli"). It is published by Alderframe Ltd ("Alderframe", "we", "us", "our"), a company incorporated in England and Wales. It sits alongside the main Alderframe Privacy Policy; where this Freshli-specific Policy gives more detail or differs, this Policy prevails for Freshli.
Freshli keeps your kitchen in your Freshli account, and does its thinking on your device. Recipe suggestions, barcode reading and receipt scanning all run locally on your iPhone through Apple’s on-device models — those never reach us. Your account and the items you add are stored on our database in the European Union so that Freshli works across your devices and can send you an expiry reminder when the app is closed. We do not sell any of it, we do not advertise, and we do not use third-party tracking.
1. Controller
The controller of personal data processed in connection with Freshli is Alderframe Ltd, registered in England and Wales. For Freshli privacy matters, contact [email protected]. Our supervisory authority is the UK Information Commissioner’s Office (ICO).
2. What stays on your device
These never leave your iPhone, and we have no way to see them:
- Recipe suggestions. Generated by Apple Intelligence on your device from the items you hold. Your requests and the suggestions produced are not sent to Alderframe and are not used to train any model.
- Barcode and receipt reading. The camera image is processed on your device by Apple’s vision and text-recognition frameworks. The photo itself is not uploaded unless you choose to attach a picture to an item (see below).
- App settings that are purely local, and any data held while you are offline before it syncs.
3. What we process, and where
Freshli has an account, and the kitchen you build is stored in it. That is what lets your items survive a phone upgrade and lets us send you a reminder when the app is not open. Our database is operated for us by Supabase, Inc. and hosted in the European Union (Paris region). Every table is protected by row-level security, so your rows are readable only by your own authenticated account.
We process:
- Your account — the email address you register with and an encrypted (hashed) password. We never see your password in readable form.
- Your profile — display name, username, household size, preferred language, reminder preferences, and the running totals Freshli shows you (food and money saved, streaks, achievements).
- Your items — name, quantity and unit, category, whether it is in the fridge, freezer or pantry, expiry and purchase dates, any barcode, your notes, and any photo you attach to an item. Photos you attach are stored in our file storage in the same EU region.
- Push notification tokens — the Apple Push Notification service token for your device, its locale and bundle identifier, used only to deliver the expiry reminders you have asked for. Turn notifications off and we stop using it.
- Product analytics — first-party events recording which features are used and how the app performs, with your account identifier, app version and platform. These are our own events on our own database; they are not shared with any advertising or analytics company, and we do not record the contents of your kitchen in them.
- Community features — if you choose to share surplus food with people near you, the listing you create and the neighbourhood area you select. This is optional and off unless you use it.
- Diagnostic data — crash reports and performance metrics Apple may share with us through App Analytics and Xcode Organizer, if you have allowed that in Settings → Privacy & Security → Analytics & Improvements.
- Purchase metadata — if you buy anything in Freshli, Apple processes the payment and gives us transaction metadata (product identifier, purchase date, subscription status, receipt). We never see your card details.
- Support communications — whatever you send to [email protected], including your email address and any screenshots you attach.
Freshli does not use the device advertising identifier (IDFA), does not track you across other apps or websites, and contains no third-party advertising or analytics SDKs. If that were ever to change we would ask your permission through Apple’s App Tracking Transparency prompt first.
3a. Deleting your account and your data
You can delete your Freshli account from inside the app, in Profile → Account → Delete account. Deleting the account removes your profile, your items, your attached photos and your push tokens from our database. You can also email [email protected] and we will do it for you. Deleting an individual item removes it immediately; backups roll off within 30 days.
4. Why we process this data & legal basis (UK GDPR)
- Operating Freshli — to provide the App’s features and any purchase you make. Legal basis: performance of a contract with you (Art. 6(1)(b)).
- Keeping Freshli secure and reliable — to detect and fix crashes, prevent abuse, and enforce these terms. Legal basis: our legitimate interests in providing a reliable App (Art. 6(1)(f)) and legal obligation where applicable.
- Improving Freshli — to understand which features work and which do not, from aggregate crash and performance metrics. Legal basis: your consent (Art. 6(1)(a)) where iOS asks; otherwise our legitimate interests.
- Responding to support requests — to reply to your message. Legal basis: our legitimate interests in providing customer service, or performance of a contract.
- Compliance and legal claims — to meet legal obligations and to establish or defend claims. Legal basis: legal obligation (Art. 6(1)(c)) and legitimate interests.
5. Children
Freshli is not directed to children under 13 (or the minimum age of digital consent in your country, whichever is higher). We do not knowingly collect personal data from such children. If you believe a child has provided us with personal data, contact [email protected] and we will promptly delete it.
6. Who we share Freshli data with
We do not sell personal data. We share only with:
- Apple — for App Store distribution, in-app purchases, subscriptions, App Analytics, TestFlight (for any beta testing), App Store Connect privacy reporting, push notifications (APNs), and (only if you opt in) iCloud / CloudKit storage of your pantry data under your iCloud account. Apple’s own Privacy Policy applies to its processing.
- Email / support tools — to receive and reply to messages you send us.
- Hosting and content-delivery providers — for the Freshli web pages on alderframe.co.uk.
- Professional advisers — lawyers, accountants and insurers, bound by confidentiality.
- Authorities and successors — where lawfully compelled or in connection with a corporate transaction (with personal data transferred subject to the protections in this Policy).
7. International transfers
Some service providers are located outside the United Kingdom. Where personal data is transferred internationally, we rely on the legal mechanisms set out in the main Alderframe Privacy Policy — UK adequacy regulations, the UK International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses — together with encryption in transit and at rest where appropriate.
8. Retention
- On-device pantry content — kept until you delete it or uninstall Freshli. iCloud copies follow Apple’s sync rules.
- Diagnostics & crash data — typically up to 12 months.
- Purchase records — at least 6 years from the end of the relevant financial year, to meet UK tax and accounting obligations.
- Support correspondence — up to 3 years after the issue is closed.
9. Your rights
Subject to applicable law, you have rights of access, rectification, erasure, restriction, portability, objection, and the right to withdraw consent. You also have the right to complain to the UK Information Commissioner’s Office or your local supervisory authority. To exercise any right relating to Freshli, email [email protected]. We may need to verify your identity and will respond within one month, extendable by two months for complex requests.
10. Security
Pantry data sits on your iPhone, protected by your device passcode, Face ID / Touch ID, and Apple’s platform security. For data we do process, we maintain appropriate technical and organisational measures including TLS in transit, encryption at rest where appropriate, least-privilege administration, and routine review of vendors. No system is perfectly secure; if you believe your account or data has been compromised, contact us immediately.
Complaints about how we use your personal information
If you are unhappy with how Alderframe Ltd has handled your personal information, you have the right to complain to us under section 164A of the Data Protection Act 2018. You can:
- use our data protection complaint form;
- email [email protected] with “Data protection complaint” in the subject line; or
- write to us at Alderframe Ltd, 66 Paul Street, Hackney, London EC2A 4NA, United Kingdom.
You do not have to use the form — we will accept a complaint made in any clear way. We will acknowledge your complaint within 30 days of receiving it, look into it, keep you informed of progress, and tell you the outcome without undue delay.
You can also complain to the Information Commissioner’s Office at any time, under section 165 of the Data Protection Act 2018: ico.org.uk/make-a-complaint — Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF; telephone 0303 123 1113. If you are in the EEA, you may also complain to the supervisory authority in your country.
11. Changes to this Policy
We may update this Policy from time to time. The "Effective" and "Last updated" dates above show when it was last revised. Material changes will be flagged in the App, on this page, or by email where appropriate.
12. Contact
For Freshli privacy questions, write to [email protected]. For broader matters, see the main Alderframe Privacy Policy.