Last updated: September 28, 2026
1. Scope and development status
Orion Lattice provides InfraShelf and this website at orion-lattice.systems. This policy describes the current development version of InfraShelf and this informational website. InfraShelf is not yet a public production release. We will update this policy as the app’s behavior changes.
Local-first does not mean that every component is verified to make zero network requests. The Android scanner’s diagnostics and full database encryption remain release-review items.
2. Your inventory
InfraShelf stores devices, notes, locations, racks, connections, settings, and attachment names in the app’s private storage on your device. The current app has no InfraShelf account, inventory server, or active cloud synchronization. It does not automatically upload your inventory to Orion Lattice.
The inventory database is not currently separately encrypted; it relies on your device’s operating-system protections. Imported attachment contents and password-protected full backups have separate encryption. Full database encryption is required before production release.
3. Photos, documents, exports, and backups
The app imports only photos and documents you select. Imported attachment contents use AES-256-GCM encryption with a device-protected key. Full backups are encrypted using a password you enter; the app does not save that password.
CSV exports and individually exported documents are not encrypted by InfraShelf. The system file picker may offer local storage or third-party cloud providers. If you select an external provider or share an exported file, that provider’s terms, privacy policy, and settings apply. Original files remain in their original location.
Importing a file can create a temporary unencrypted copy. The app attempts cleanup after import and at startup, but cannot control all operating-system or provider caches. Keep backups and their passwords safe; losing the device key and backup password can make attachment contents unrecoverable.
4. Camera, scanning, and diagnostics
Camera permission is used for barcode and QR scanning. Scanned URLs are not opened automatically. The current iOS scanner uses Apple’s Vision framework.
The current Android scanner uses Google ML Kit through the mobile_scanner package. Google documents collection of device and app information, installation identifiers, and diagnostic and usage metrics. Actual network behavior in InfraShelf is still being verified; we do not make a zero-telemetry claim for this development version. See Google’s ML Kit data disclosure.
5. This website and email correspondence
This static website does not include analytics scripts, advertising trackers, account registration, contact forms, or browser-storage features. It does not receive your app inventory. Opening a link from the app loads the website in your browser.
The website is configured for Cloudflare Pages. When it is hosted there, Cloudflare processes ordinary web-request information, such as IP addresses, requested URLs, and browser information, to deliver and protect the site. See Cloudflare’s privacy policy for its processing practices.
If you email support or our privacy address, your email address, message, and any attachments are processed to respond to your request. Email delivery providers also process that correspondence. Please avoid sending sensitive inventory or credentials. Correspondence may be retained while needed to handle the request, maintain relevant support records, or satisfy legal obligations. Contact us to ask about or request deletion of correspondence.
6. Retention and your choices
You can edit and delete inventory and attachments in the app, manage camera permission through your device settings, and choose whether to import, export, or share files. Old encrypted attachment files may remain until startup cleanup. Deletion does not guarantee forensic erasure.
Exported copies, backups, original files, and copies held by providers must be managed separately. App storage is configured to be excluded from operating-system backup, but real-device verification remains outstanding. Make and verify an explicit password-protected backup before uninstalling the app or moving devices.
We cannot retrieve inventory stored only on your device. Depending on applicable law, you may have rights concerning personal information you send us, including access, correction, or deletion. Contact the privacy address to make a request; we may need enough information to verify and respond to it.
7. Changes and contact
Changes will be posted on this page with an updated date. A production release will need an updated policy reflecting its final behavior and services.
Privacy questions and requests: [email protected]
Product support: [email protected]