Privacy Policy
This policy explains how Expiron handles information on Android, iPhone, and iPad. It covers the free, ad-supported app and any paid ad-removal feature. Some services are platform-specific.
1. Who is responsible
The controller and app publisher is Shokhrukh Akhmatov, operating under the developer name ShokhLabs ("ShokhLabs," "we," "us," or "our"). For privacy questions or requests, email shohlabs.dev@gmail.com.
This policy applies to the Expiron mobile application (the "App") and the Expiron legal/download website. It does not govern another app you choose through the system share sheet or the independent practices of an app store or advertising provider.
2. Information and how it is used
| Category | What it includes | Purpose and handling |
|---|---|---|
| Reminder content | Product name, production and expiration dates, shelf-life values, notification timing, and optional product photo. | Used to calculate dates, display reminders, create notifications, and make a share card when you ask. Stored locally; not sent to a ShokhLabs server. |
| Preferences | Language, sorting, consent signals, ad-provider fallback state, and purchase-entitlement cache. | Used to preserve settings, respect privacy choices, choose an available ad provider, and keep ads disabled while a store entitlement is recognized. |
| Advertising and app activity | IP address and general location inferred from it; advertising or device identifiers where permitted; device, app, and operating-system details; app launches, taps, ad views or video views; consent signals; diagnostics; and fraud-prevention signals. | Processed by the advertising services in section 4 to request, deliver, limit, measure, and secure ads and to diagnose SDK performance. |
| Purchase information | Product identifier, transaction or purchase token, purchase state, and entitlement status. The store retains account, payment, tax, and refund records. | Used to complete and restore an ad-removal purchase and prevent fraud. We do not receive your full payment-card number. |
| Support messages | Your email address and anything you include in a support email. | Used to answer you, troubleshoot, prevent abuse, and keep records where legally required. Do not send sensitive information that is unnecessary for support. |
3. Local storage, permissions, and backups
Expiron does not require an account and does not upload reminder content to a ShokhLabs server. The App uses private local storage. On Android, Expiron disables Android cloud backup. On iPhone and iPad, Apple may include local app data in an encrypted iCloud or computer backup depending on your device settings and Apple's rules; ShokhLabs does not operate or access that backup.
- Camera: requested only when you choose to take a product photo.
- Photo picker: used only when you choose a photo. The system grants access to the selected item rather than the full library where the platform supports that behavior.
- Notifications: requested so the operating system can show reminders you schedule.
- Network: used for advertising, consent messages, store purchases, and links you open.
Expiron does not request precise device location. In the Android implementation, Yandex SDK location tracking is disabled. Advertising providers may still infer a broad location from an IP address.
4. Advertising, consent, and tracking
The free version may use:
- Google AdMob / Google Mobile Ads SDK to request and display ads;
- Google User Messaging Platform (UMP) to request and store region-appropriate privacy choices; and
- Yandex Mobile Ads SDK, including its required AppMetrica component, to request, display, measure, secure, and diagnose Yandex ads.
These providers may receive the advertising and app-activity information listed in section 2. They act under their own terms and privacy notices and may independently determine some purposes and retention periods. We require integrated providers to handle information consistently with this policy, their contractual obligations, and applicable data-protection law.
Expiron does not deliberately pass reminder names, entered dates, or product photos to an advertising SDK API. Provider SDKs may automatically collect technical and app-use events as described above and in their notices.
Where consent is required, the Android app uses one UMP privacy message. No ad SDK is initialized and no ad request is made until the consent check for that launch allows ads. Expiron applies conservative defaults first, passes available IAB consent signals to both ad systems, sends Yandex a negative user-consent value unless the relevant signal permits it, and keeps Yandex location tracking disabled. Refusing personalized advertising does not necessarily remove all ads; a provider may serve non-personalized, contextual, or limited ads where lawful.
On Apple platforms, Expiron must also obtain permission through App Tracking Transparency before accessing the advertising identifier or tracking you across other companies' apps or websites. You may deny that permission and still use the App.
Provider information: Google partner apps, Google advertising, Google Privacy Policy, Yandex Privacy Policy, and AppMetrica Terms.
5. Purchases
Google Play Billing processes purchases in the Google Play build. Apple's in-app purchase system processes purchases in an iOS or iPadOS build. The relevant store receives and retains payment, account, tax, fraud-prevention, refund, and transaction information under its own privacy terms. Expiron receives only the information needed to determine whether the ad-removal entitlement is active and may cache that status locally. A store-specific entitlement is not guaranteed to transfer to a different platform or store account.
6. Sharing initiated by you
When you tap Share, Expiron creates a card image and accompanying text in temporary local storage and opens the operating system's share sheet. Nothing is sent until you choose a destination. The app or person you select then receives the shared name, dates, photo (if included), and app link. Their handling is governed by their own terms. Share-card files are eligible for automatic cleanup after about 24 hours and may be removed sooner by the operating system.
7. Purposes and legal bases
Where the GDPR, UK GDPR, or similar law applies, we use information on these bases:
- Contract: to provide calculations, reminders, requested sharing, support, and a purchased entitlement.
- Consent: for personalized advertising, storage/access to device information, and cross-app tracking where the law requires consent. Consent may be withdrawn.
- Legitimate interests: to secure the App, prevent fraud, diagnose failures, provide limited or contextual advertising where permitted, and establish or defend legal claims, balanced against your rights.
- Legal obligation: for tax, accounting, consumer-protection, law-enforcement, or regulatory duties that apply to us or a store provider.
8. Retention and deletion
- Readable reminders more than 30 days past their expiration date and their app-owned photos are removed when Expiron next performs its cleanup. Other reminder content remains until you delete it, clear app data, or uninstall the App.
- Temporary camera and share files are normally removed within about 24 hours or sooner when no longer needed. A local recovery copy of an unreadable reminder file may be retained to avoid destructive data loss until app data is cleared or the App is uninstalled.
- Local consent, settings, and entitlement caches remain until replaced, reset, app data is cleared, or the App is uninstalled.
- Support correspondence is normally kept for no longer than 24 months after the last contact, unless a longer period is reasonably necessary for security, a dispute, or a legal obligation.
- Google, Yandex, Apple, and app stores retain provider-controlled records under their own published policies and legal duties.
You can delete individual reminders in Expiron. You can remove all App-controlled local data by clearing its storage or uninstalling it. Device or store backups and provider-held records must be managed through that provider's controls.
9. Your privacy choices and rights
Use Settings > Privacy choices when that entry is displayed to revisit an applicable UMP choice. You can also use Android advertising privacy settings, iOS Settings > Privacy & Security > Tracking, and the controls offered by Google, Yandex, Apple, or your app store.
Depending on where you live, you may request access, correction, deletion, portability, restriction, or objection; withdraw consent; opt out of targeted advertising or sale/sharing as those terms are legally defined; or appeal a denied request. You may also complain to your local data-protection authority. We do not discriminate against you for exercising a privacy right.
We do not sell personal information for money. Advertising disclosures may be considered "sharing," "sale," or targeted advertising under some U.S. state laws even where no money changes hands. Use the controls above to opt out where applicable.
Submit a request to shohlabs.dev@gmail.com. Describe the right and jurisdiction involved. We may ask for limited information needed to verify and fulfill the request. Because reminder content is local, we usually cannot retrieve it for you.
10. International transfers
Advertising, store, and email providers may process data in countries other than yours. Where required, they use transfer mechanisms described in their policies, such as adequacy decisions, standard contractual clauses, or other lawful safeguards. Contact us if you need information about safeguards relevant to our integration.
11. Children
Expiron is a general-audience utility and is not directed to children under 13 or the higher minimum age required by local law. We do not knowingly ask a child for personal information. The App must not be listed or configured as child-directed unless the store declarations, age screens, advertising restrictions, and SDK settings required by applicable law have first been implemented. If you believe a child supplied information through support, contact us so it can be deleted.
12. Security
We use private app storage, system photo pickers, scoped sharing permissions, data minimization, conservative ad-consent defaults, and transport security provided by the integrated services. No storage or transmission method is completely secure. Keep your device and store account protected and avoid putting sensitive information in product names or photos.
13. Changes
We may update this policy to reflect App, provider, or legal changes. The updated date will change, and material notices or renewed consent will be provided when required. Earlier versions should be retained in the release records.
14. Contact
Shokhrukh Akhmatov, publishing as ShokhLabs
Email: shohlabs.dev@gmail.com