Plum.

Privacy Policy

Last updated: TBD at submission

Plum is made by Craftish, a one-person studio run by Tyler Craft in Aotearoa NZ. This page describes exactly what the app does with your information.

The short version. Your kits, lists, items, photos and notes are stored in your own iCloud account and on your own devices. They are never sent to a Plum server, because there is no Plum server and no Plum account. Two services receive anonymous technical data so I can see which features get used and fix what breaks. Neither ever receives the contents of your lists.

What Plum stores, and where

Everything you create in Plum — kits, lists, items, quantities, notes, photos, locations, sections and emoji — is stored on your device and, if you have iCloud enabled, synced through your own iCloud account using Apple’s CloudKit.

There is no account to create, no password, and no server belonging to Craftish that holds your content. I cannot read your lists. Apple’s handling of iCloud data is governed by Apple’s Privacy Policy.

Sorting happens on your device

Plum sorts groceries into aisles and packing items into categories using a dictionary bundled inside the app. That runs entirely offline, on every device, and involves no network request.

On devices that support Apple Intelligence, an on-device model handles items the dictionary does not recognise and can suggest a new section. This uses Apple’s on-device Foundation Models. Item names are not sent anywhere for this, nothing you write is used to train any model, and sorting works without it. If it puts something in the wrong place, move it and the correction sticks.

Sharing a list or kit

If you share a list or kit, that specific content becomes accessible to the people you share it with, through Apple’s CloudKit sharing. Sharing is per list or per kit: nothing else in your account travels with it. You can stop sharing at any time from within the app. Craftish is not a party to the share and cannot see the contents.

What does leave your device

Two third-party services receive technical data. Neither receives the contents of your kits, lists or items, your photos, or your name.

TelemetryDeck — product analytics
Receives event names such as “a list was created” or “an item was checked”, plus small non-identifying attributes like a list’s type or a count. Events are grouped under an anonymous, hashed identifier. It never receives kit, list or item text, photos, or the identity of anyone you share with. Purpose: to see which parts of the app are actually used, so I know what to improve.
Sentry — crash and error reporting
Receives crash and error reports, which include the device model, operating system version, app version and a technical stack trace. Personally identifying information is explicitly disabled in the configuration, and reports are only sent when something fails more than once. Purpose: to find and fix crashes I would otherwise never hear about.

These are the only two. There are no advertising SDKs, no tracking across other apps or websites, no data brokers, and nothing is ever sold or shared for marketing. Plum does not ask for tracking permission because it does not track you.

Craftish operates from Aotearoa NZ, and both services process data on servers outside Aotearoa NZ. Their own privacy policies apply to that processing: TelemetryDeck and Sentry.

Deleting your data

Because your content lives in your own iCloud, you control it directly. Delete individual kits and lists in the app, or delete the app and remove its iCloud data from your device settings, and it is gone.

Analytics and crash data cannot be traced back to an individual, which means it also cannot be selectively deleted on request. That is the cost of collecting it anonymously in the first place, and it is the trade I chose.

Children

Plum is not directed at children under 13 and does not knowingly collect information from them.

Your rights

Depending on where you live, you may have rights to access, correct or delete personal information held about you. Craftish is subject to the New Zealand Privacy Act 2020, and you may have equivalent or broader rights under your own local law. Since your content is in your own iCloud and the technical data described above is anonymous, there is very little for me to hold. If you have a question about any of it, write to plum@craftish.dev and I will answer.

Changes

If what Plum collects ever changes, this page changes with it and the date at the top is updated. Material changes will also be noted in the app’s What’s New.

Contact

Craftishplum@craftish.dev