Privacy Policy
Effective October 1, 2026
The short version
- Your inventory (places, spots, items, photos, notes and dates) is stored only on your iPhone.
- There is no Sésame account and no Sésame server. We, SXP Studio, never receive your data.
- The app has no analytics, no ads and no tracking.
- It goes online in two cases only: looking up a barcode, and, if you add your own API key, asking an AI provider to read a photo.
Who we are
Sésame is made by SXP Studio (“we”). This policy covers the Sésame app for iPhone, its widgets, and this website.
What stays on your iPhone
Everything you put into Sésame is saved in the app’s storage on your device:
- Places and spots, their names, icons, colors and notes.
- Items, with their photos, barcodes, amounts, expiry dates, reminders and notes, including notes like who you lent something to.
- Your settings, and any AI provider API key you add. The key is kept in the iOS Keychain.
The widgets read a small summary (the next items to expire and a few counts) that the app saves in a space shared only with its own widgets, on the same device.
Sésame doesn’t sync to iCloud and doesn’t upload your inventory anywhere. Like other app data, it is included in your iPhone’s own backups (iCloud Backup, or a backup to your computer) if you have those turned on. Those backups are handled by Apple under Apple’s privacy policy, not by us.
When Sésame goes online
The app connects to the internet only in these situations, each started by you:
1. Looking up a barcode
When you scan or type a barcode, Sésame sends the barcode number to the free, open databases of Open Food Facts, Open Beauty Facts and Open Products Facts, run by the non-profit Open Food Facts. It may also download the product photo they have. Only the barcode number is sent, with a request header naming the app. Nothing about you or your inventory is included. Their handling of requests is covered by the Open Food Facts privacy policy.
2. AI fill-in, only with your own API key
This is off by default. If you add an API key for Anthropic (Claude), OpenAI (ChatGPT) or Google (Gemini) in Settings and then ask Sésame to fill in an item from a photo, the app sends to that provider, directly from your iPhone:
- the item photo you chose,
- today’s date, so it can work out expiry dates,
- and, for food, whether it’s kept in the fridge or the freezer.
Spot names, other items and notes are not sent. The request uses your key and your account with that provider, so their terms and privacy policy apply to it: Anthropic, OpenAI, Google. We never see the request, the reply or your key. You can remove the key in Settings at any time.
Without a key, the quicker on-device fill-in and find-by-photo matching run entirely on your iPhone using Apple’s built-in image and text recognition.
Permissions the app asks for
| Permission | What it’s used for |
|---|---|
| Camera | Photographing items, scanning barcodes, expiry dates and QR labels. Images stay on the device unless you use AI fill-in. |
| NFC | Reading and writing the tags you stick on spots. A tag holds only a link to the spot, never its contents. |
| Photos (no permission) | When you pick a photo from your library, the iOS photo picker hands over only the photo you chose. Sésame never gets access to your whole library. |
| Notifications | Expiry reminders. These are scheduled on your iPhone; no server sends them. |
You can change any of these in the iPhone’s Settings app.
What we don’t do
- No accounts, sign-in or email collection in the app.
- No analytics, crash-reporting or advertising SDKs.
- No selling or sharing of data. We have none to share.
Apple may give developers aggregated, anonymous App Store figures (such as downloads) and crash reports from people who chose to share them with developers in their iPhone’s settings. We use those only to improve the app.
Deleting your data
Delete items, spots or places inside the app, or delete the app to remove everything it stored on your iPhone. Copies may remain in your existing device backups until those are replaced.
This website
This site has no cookies, no analytics and no forms. Our web host may keep standard server logs (such as IP address and pages requested) for security and to keep the site running.
Children
Sésame doesn’t collect personal information from anyone, children included.
Changes
If this policy changes, we’ll update it here and change the date at the top. If a future version of the app starts sending data anywhere new, this page will say so before that version is released.
Contact
Questions about privacy: nimbus.positronium@gmail.com