Supply Closet

Privacy

This describes what the software actually does. Where something depends on how an operator has configured their server, it says so.

Last updated 2 October 2026.

Who runs this

Supply Closet is operated by Aidan Overpeck, contactable at overpeck.aidan@gmail.com. The software can also be self-hosted, in which case whoever runs that server is the operator of it and this document describes the software rather than their practices.

What is stored

Everything below lives in one database on the server. Nothing is stored that is not on this list.

  • Your account: email address, a display name if you give one, and a password hash. Passwords are hashed with scrypt and never stored in a form that can be read back.
  • Your stock: the properties you create, the items in them, counts, par levels, where things are kept, and the categories you define. An item keeps the barcode you scanned, the name, brand and size, a product image address if the lookup returned one, and whether it came from a barcode, a photo or was typed in.
  • A ledger of changes: every quantity change, with what changed, by how much, why, when, and whether it was you or someone using a crew link. Stock moved between properties is recorded the same way. This is what the usage and activity screens are built from.
  • Cleaner logins you create: each cleaner’s email address, display name and password hash, plus the list of properties that login may see. A cleaner login belongs to your account and is removed with it.
  • Messages: the message threads between you and your cleaners, one thread per property. Each message keeps the author’s name and role as they were when it was written, so a thread still reads after that person has been removed. The server also records how far into each thread each login has read, which is how unread counts work.
  • Sessions: a hash of your login token, when it was created, when it expires, when it was last used, and the browser user-agent string that created it, so you can recognise and revoke a session you do not want. A session lasts 30 days unless you end it sooner.
  • Password reset tokens: when you ask for a reset, a hash of the reset token is stored for one hour and marked used once you have set a new password. If the operator has pointed reset delivery at a messaging service, the reset link and your email address are handed to that service to deliver; if not, the link is only printed on the server’s own console.
  • Billing, only if the operator has switched it on: your plan, its status, a trial end date if you are on a trial, and the Stripe customer id and subscription id that connect your account to your subscription. Never card numbers: Stripe holds those and this server never sees them. The server also keeps a record of each billing event Stripe sends it (the event type and the event body, cut to 4,000 characters) so a repeat delivery is not applied twice.
  • A barcode cache: the product details returned for a barcode are kept so the same barcode is not looked up again. The cache is keyed by barcode only and is not linked to any account.

What leaves the server

Three things, and nothing else:

  • Barcodes you scan are sent to Open Food Facts, Open Products Facts and Open Beauty Facts to look up the product. Only the barcode number is sent. Nothing identifies you or your account, and the result is cached so the same barcode is not looked up repeatedly.
  • Photos, only if you take one and only if the operator has enabled photo identification, are sent to Anthropic’s API to be identified. If that feature is off, no image ever leaves the server. The photo is never written to the database or to disk: it is forwarded, the answer comes back, and the image is discarded.
  • Payment details, on the hosted service, go directly to Stripe. Card numbers never touch this server, and we store only the Stripe identifiers needed to know which plan you are on.

What is not collected

No analytics, no tracking pixels, no ad trackers, no advertising identifiers, no third-party scripts, and no sale or sharing of anything you put in. The app does not ask for your location, does not read your contacts, and does not fingerprint your device. The camera is used only while you are scanning or taking a photo, and the frames stay in your browser: a barcode number is all that is sent on. The only cookie is the one that keeps you signed in: closet_session, marked HttpOnly, Secure and SameSite=Lax, which cannot be read by scripts and is not used to follow you anywhere.

We do not sell personal data, and we do not share it with anyone other than the three services named above, each only in the way described.

A share link lets someone count stock at one site without an account. Anyone holding the link can see and change counts for that site until it is revoked, which takes effect immediately. The link is a long random token and is not guessable, but treat it as a key: whoever has it, has that access. Actions taken through a link are recorded in the ledger as crew rather than as you.

Getting your data out

Every site has CSV export for both its current stock and its full change history, on the Activity screen. There is no request to make and nobody to ask. If you self-host, the whole database is a single SQLite file you already have.

Deleting things

Deleting a site removes it and everything recorded against it. To close an account entirely, write to overpeck.aidan@gmail.com and it will be deleted along with its sites, items and ledger. Backups are overwritten on their normal cycle, so a copy may persist in a backup for a short period after deletion. You can also delete the account yourself from inside the app; the steps are on the account deletion page.

How long it is kept

Account data is kept for as long as the account exists, and no longer. There is no retention of anything after the account is gone, apart from the backup window above.

  • While the account exists: properties, items, counts, the ledger, cleaner logins and messages stay until you delete them. Deleting a property removes its stock, its ledger and its message thread at once.
  • Sessions expire 30 days after sign-in, or sooner if you sign out, sign out everywhere, or change your password. Expired rows are swept.
  • Password reset tokens expire one hour after they are issued.
  • When the account is deleted: the account, its cleaner logins, properties, items, counts, ledger, messages, sessions and reset tokens are removed from the live database immediately and permanently. The database enforces this itself: everything hangs off the account row, and deleting it cascades. The only thing that outlives the account is the billing event log, if billing was ever on, which keeps the event with its link to the account cleared. Stripe keeps its own records of any payments under its own policy.
  • Backups roll off on their normal cycle, so a copy of deleted data may persist in a backup for a short period before it is overwritten.

Where it runs

The hosted service runs on servers in the United States, in Oracle Cloud’s US East region (Ashburn, Virginia). If you self-host, it runs wherever you put it.

Security and breach notice

Passwords are hashed with scrypt and salted per account; the plain password is never stored and cannot be recovered from the hash. The hosted service is reached over HTTPS, so everything between your device and the server is encrypted in transit. Login tokens are stored only as hashes, so a copy of the database does not contain anything that signs in. Every session can be revoked from inside the app: Sign out everywhere, in the app’s menu, ends every session on every device at once, and changing your password does the same.

If a breach of security affecting your personal information is discovered, the people affected will be told by email, at the address on the account, as quickly as practicable and no later than 30 days after the breach is determined, which is what Florida’s Information Protection Act (section 501.171, Florida Statutes) requires. The only ground for a longer delay is a written request from law enforcement, and the notice follows as soon as that is lifted. The notice will say what happened, when, what information was involved and what you can do about it.

Children

This is a tool for adults running a business. It is not directed at anyone under 13, and nobody under 13 should create an account or be given a cleaner login. We do not knowingly collect personal information from children. If we learn that an account or a login belongs to someone under 13, it is deleted along with everything recorded under it. If you believe that has happened, write to overpeck.aidan@gmail.com.

Your choices

  • Export: every property has Export stock (CSV) and Export activity (CSV) on the Activity screen. The files are plain CSV and open in any spreadsheet.
  • Delete the account: see how to delete your account. Everything recorded under it goes with it, as described under How long it is kept.
  • Sign out everywhere: in the app’s menu, next to your account name. It ends every session, including the one you are using.
  • Remove a cleaner or revoke a crew link: both take effect immediately, from the Manage cleaners screen and the property’s share link settings respectively.
  • Anything else: write to overpeck.aidan@gmail.com, whether that is a copy of what is held about you, a correction, or a question this page does not answer.

Changes

If this changes in a way that affects what is collected or where it goes, the date above changes and account holders are told by email before it takes effect.

Start free Pricing