groceryAI plans your week's meals, builds the shopping list, and keeps track of what is in your pantry. This policy explains what it stores, why, and what you can do about it.
The short version: it holds your email address, the meals you plan, and the pantry items you add. It does not sell anything to anyone, it does not track you across other apps, and you can delete all of it from inside the app.
1. What we collect
Things you give us
| Data | Why | Kept |
|---|---|---|
| Email address | It is your account. Signing in is a 6-digit code sent to it — there is no password to lose. | Until you delete your account |
| Meal plans — which recipes you chose, which you cooked, thumbs up/down | The app suggests future weeks from what you have actually cooked and liked | Until you delete your account |
| Shopping lists and what you ticked off | So the list survives closing the app | Until you delete your account |
| Pantry items | To leave things you already own off the shopping list | Until you delete your account |
Things created as you use the app
| Data | Why | Kept |
|---|---|---|
| Photos you choose to add to your pantry | Read once to extract item names | Not stored. Processed and discarded |
| Crash diagnostics — error message, stack trace, app version, iOS version | To find and fix crashes | 90 days, then deleted automatically |
| AI operational records — which AI call ran, whether it succeeded, how long it took | To tell "the AI is broken" apart from "the AI is working" | 90 days, then deleted automatically |
The AI operational records contain no prompts and no responses — no recipe text, no pantry contents, nothing you typed or said.
2. Speech stays on your device
If you dictate your pantry instead of typing it, the recording is transcribed by iOS's own on-device speech recognition. No audio is sent to us or to anyone else. The resulting text is then handled exactly like text you typed.
3. Photos are read, not kept
When you add a pantry photo, the image is sent to Anthropic's Claude API to extract item names, and those items are shown to you for confirmation before anything is saved.
- The photo itself is never written to our database or file storage
- What is saved is the item names you confirm
- Anthropic does not train models on API inputs
4. What we do not do
- No selling or sharing of personal data, in any sense — including the meanings those words carry under the CCPA/CPRA
- No advertising, no ad identifiers, no cross-app or cross-site tracking. The app does not use App Tracking Transparency because it does not track
- No analytics SDKs — no Google Analytics, Firebase, Facebook SDK or similar
- No location data, ever
- No contacts, calendar, or health data
- No profiling or automated decisions with legal effects. The meal suggestions are suggestions
5. Who processes your data
| Processor | What they handle | Where |
|---|---|---|
| Supabase | Database, authentication, file storage, server functions | United States (us-east-1) |
| Anthropic (Claude API) | Pantry text and photos; recipe names for list grouping and meal suggestions | United States |
| Apple | Purchases and receipt validation. We never see your payment details | Per Apple's policy |
Anthropic processes API inputs to return a result and does not use them to train models. Apple handles all payment information — groceryAI never receives your card number, and no part of this app can read it.
6. Purchases
Recipe packs are one-off purchases through the App Store.
We store which pack you bought, Apple's transaction identifier, and when. We do not store your name, card, or billing address — Apple does not give them to us.
Purchase records outlive account deletion, deliberately. Apple ties a purchase to your Apple ID, and keeping the record is what lets you sign up again and restore a pack you paid for. The record is unlinked from your deleted account and holds no personal data — only Apple's transaction identifier.
7. Your choices
Delete everything. Settings → Delete account. This permanently removes your account, meal plans, cooking history, shopping lists and pantry. It cannot be undone. Packs you bought remain restorable through Apple.
Export. Email us and we will send your data in a machine-readable format.
Correct. Most of it is editable in the app. For the rest, email us.
Withdraw permissions. Microphone and photo access are revocable at any time in iOS Settings; typing keeps working without them.
Depending on where you live you may have further rights — access, correction, deletion, portability, objection, restriction, and the right to complain to a supervisory authority — under the UK GDPR, EU GDPR, CCPA/CPRA or similar laws. Exercising them will never make us treat you worse.
8. Security
Data is encrypted in transit (HTTPS) and at rest. Every table enforces row-level security scoped to your account, so one customer's data is not reachable by another — this is enforced by the database itself rather than by the app, and is covered by automated tests. Recipe images live in a private bucket served through short-lived signed URLs. Server credentials are never shipped inside the app.
No system is perfectly secure. If we discover a breach affecting your data we will notify you and the relevant authorities as required by law.
9. Children
groceryAI is not directed at children under 13 (under 16 in the UK and EEA) and we do not knowingly collect their data. If you believe a child has created an account, email us and we will delete it.
10. Contact
Operator: Adam Robbie
Email: support@groceryai.app
We aim to respond to privacy requests within 30 days.
11. Changes
If this policy changes materially, the app will tell you before the change takes effect. The date at the top always reflects the current version.