Privacy Policy
Last updated
This policy explains how Grocer handles your account, shopping lists, photos, dictated text, purchases, and app usage. Privacy questions can be sent to grocer.support@gmail.com.
Summary
Basic lists can stay on your device. Signing in enables cloud sync and sharing. Optional AI features send selected photos, recognized text, or your draft text through our backend to Google Gemini after your permission. Dictation audio stays on your device. We do not sell your data or use advertising SDKs or cross-app tracking.
1. Your Lists and Account
Local lists and cloud sync
Without signing in, basic list data is stored on your device. When you sign in, Supabase hosts your account and stores your lists, items, sharing memberships, invitations, and related timestamps for sync and collaboration. The app also caches data locally for offline use.
Sign-in information
You can sign in with Apple, Google, or email. We use your account identifier, email address when provided, and display name when provided to authenticate you and identify collaborators. Your sign-in provider also processes information under its own privacy policy.
Shared lists
People with access to a shared list can see its contents and collaborator information. Share invitations only with people you trust. Other people may retain copies of content you shared, even after you remove it from Grocer.
2. Photos, Voice, and AI
Camera and selected photos
Grocer uses your camera when you choose to take a photo and uses the images you select for import. For Smart Scan (Find groceries), selected images and text recognized from them are sent to our Supabase processing service. Google Gemini receives the image, recognized text, or both, depending on the scan, to return editable grocery items.
On-device text recognition
The Read text path uses on-device text recognition. That path does not send your photo to Gemini. Any resulting items you save are handled like your other list data, including cloud sync when you are signed in.
Dictation
Dictation requires microphone and speech-recognition permission and uses Apple's on-device speech recognition on supported devices and languages. Audio is not sent to Grocer's backend or Google Gemini. You can edit the resulting draft before saving it or choosing Smart Organize.
Smart Organize
When you choose Smart Organize and grant permission, the current draft text, including your edits, is sent through our Supabase processing service to Google Gemini to identify grocery items and quantities. The request contains text, not your dictation audio. You review the results before adding them to a list.
Permission and choice
The app asks separately before the first AI photo scan and the first Smart Organize request, and remembers those choices on the device. Choose Not Now to decline. You can keep using manual lists and on-device dictation without AI processing. Stop using Find groceries and Smart Organize to stop future AI submissions; contact us to request help with consent or deletion. See AI & Photo Processing for details.
AI retention and training
Grocer does not save submitted images or draft text as a server-side AI content history. Our processing service handles them to return results. We use Google's paid Gemini API; under its paid-service terms, Google does not use prompts or responses to improve its products. This does not mean zero retention: Google's abuse-monitoring policy describes 55-day retention of prompts, context, and responses, with authorized review for policy enforcement and legal obligations. See Gemini API terms and Google's abuse-monitoring policy.
Usage records
We store account-linked AI request status, timing, usage, and cost information to enforce subscription quotas, prevent abuse, and operate the service. These records are separate from the grocery items you choose to save.
3. Other Services and Data
Purchases
Apple processes App Store payments. RevenueCat helps validate purchases, restore access, manage subscription status, and understand subscription performance using account identifiers, purchase history, and entitlement information. Grocer does not receive your full payment-card details. See RevenueCat's privacy policy.
Analytics
When Usage Analytics is enabled in Grocer 1.0.1, PostHog receives feature-use events, app and device information, app-generated identifiers, your IP address and approximate location derived from it, and your Grocer account identifier when signed in to help us understand usage and reliability. We do not intentionally include grocery item names, list contents, raw photos, or dictated text in analytics events. Events can include error details. See PostHog's privacy policy.
Diagnostics
When Diagnostics is enabled in Grocer 1.0.1, Sentry processes crash, performance, and error information, including app state, device information, network request details, and diagnostic identifiers, to help us fix problems. Automatic screenshot attachment is disabled. Error details may contain incidental personal information. See Sentry's privacy policy.
Notifications
If you enable notifications, we store Apple's push notification token and use Apple's push service to deliver shared-list updates to your device. Notifications may reveal list activity on your lock screen depending on your iPhone settings.
Website and support
Cloudflare delivers this website and processes connection and security information such as IP addresses and browser details. Some Grocer website pages load fonts from Google Fonts, which receives your connection information when your browser requests them. If you contact support, we receive your email address, message, and any attachments you send. Avoid sending passwords, payment details, or sensitive photos.
Service providers
Providers process information for the purposes described here under their applicable service and data-protection terms. Processing may occur outside your country. See Supabase, Cloudflare, and Google for further information. We may also disclose information when required by law or necessary to protect the service and its users.
4. Retention and Your Choices
Account data
Cloud list and account data remains until you delete it or your account. Signing out or uninstalling the app does not delete cloud data. Deletion from the live service does not necessarily immediately remove information from backups, security logs, support correspondence, or provider records. Those records may remain as needed for recovery, security, legal obligations, purchase records, and resolving disputes.
Optional analytics and diagnostics
In Grocer 1.0.1, open Settings → Share with Developers to control Usage Analytics and Diagnostics separately. Both are off until you enable them on your device. Turning a setting off stops future collection by that optional service; it does not delete records already received. Account sync, security, AI usage limits, and purchase validation are separate operations needed to provide the features you use.
Delete your account
In Grocer 1.0.1, use Settings → Data & Account → Delete Account after signing in. In older versions, find Delete Account in Settings. This removes your account, lists you own and their items, invitations, memberships, AI usage records, push tokens, and local subscription entitlement records from the live Grocer service. Items in someone else's shared list may remain without a link to your profile. Provider analytics, diagnostic, and purchase records are separate; contact us for help requesting deletion of personal data held by those services.
Device permissions
You can change microphone, speech recognition, camera, photo, and notification permissions in iPhone Settings. Permission changes affect future access; they do not delete information already processed. You can edit or delete list items in the app.
Subscription cancellation
Deleting your account or uninstalling Grocer does not cancel your Apple subscription. Manage or cancel it in your Apple subscription settings. See our Terms of Use.
Privacy requests
Contact grocer.support@gmail.com to request access, correction, a copy, or deletion of your personal data, or to ask about consent and object to processing. Your rights depend on where you live. We may need to verify that a request relates to your account. Where applicable, you may also complain to your local data-protection authority.
Policy updates
We update this page when our practices change and show the revision date on this page. New data uses that require permission will be explained before we ask for that permission.