Privacy Policy

Last modified: September 19, 2026

GroceryTrack, a product of Slash Dev Slash Null LLC, is committed to protecting your privacy and personal information. This Privacy Policy explains how we collect, use, protect, and disclose the information we collect when you use the GroceryTrack services (the "Services") through our website, mobile applications on devices ("Apps"), and through APIs.

IF YOU DO NOT ACCEPT THE TERMS OF THIS PRIVACY POLICY, PLEASE DO NOT USE THE SERVICES.

Changes to this Privacy Policy: If we make a material change to this Privacy Policy with respect to how we collect and use your personal information, we will provide at least 30 days' prior written notice to you by email, so that you have sufficient time to evaluate the change.

The Information We Collect and Store

Information You Provide

You create an account by signing in with Google, with Sign in with Apple, or with an email address and password. Depending on the method you choose, you may provide the following personally identifiable information ("Personal Information"):

  • Email address (from your Google or Apple account, or the address you register with). If you use Sign in with Apple and choose to hide your email, we receive only Apple's private relay address
  • Display name (from your Google or Apple profile, or as you set it)
  • Profile photo (from your Google profile, where available)
  • Receipt images and their contents ("User Content")
  • Grocery Snap photos — pictures of grocery items themselves (bags, counter, fridge, etc.) uploaded in place of a receipt so AI can identify the products
  • Forwarded receipt emails and their contents, when sent to our receipt ingestion address
  • Alternative email addresses for household receipt forwarding
  • Budget preferences and questionnaire responses
  • Trip notes — free-form text you attach to a receipt (e.g., product quality observations, price comparisons, packaging differences)
  • Manual corrections to extracted data, including store names, item names, prices, totals, receipt type (Grocery/Restaurant), and non-grocery exclusions
  • Feedback messages and optional screenshots
  • Pantry data — stock levels, storage locations, and shelf-life expectations you record or confirm for items inferred from your receipts
  • Shopping lists you create or accept from our suggestions
  • Referral codes you share or redeem
  • Subscription and payment information (see "Payment Information" below)

Email-Forwarded Receipts

When you forward a receipt email to our ingestion address (receipts@updates.grocerytrack.food), we receive and process:

  • Sender email address (used to match your account or household alternative emails)
  • Email subject line
  • Email body content (HTML and plain text) — when an email carries no usable attachment, the body text itself is what we read the receipt from
  • Attachments (receipt photos and PDF receipts), including the contents of an email forwarded as an attachment

We keep the original attachment or a snapshot of the email content alongside the receipt it produced, so you can open it later and so we can re-run extraction. If a forwarded email cannot be turned into a receipt, we reply to the sending address with the reason.

Email forwarding is handled by Resend, our transactional email provider. Resend receives and temporarily stores the inbound email to deliver it to our webhook endpoint. Resend Privacy Policy

Receipt Files and Links You Share

When you upload a PDF receipt, or share a file or a receipt web link (for example a Square or Toast receipt page) into GroceryTrack, we receive and process the file or fetch the page on your behalf. We store the original file, or a snapshot of the page, alongside the receipt it produced. Receipt files and page snapshots are kept and deleted on the same terms as receipt images.

AI-Extracted Data

When you upload a receipt image or forward a receipt email, our AI processing extracts the following information:

  • Store name and date of purchase
  • Individual item names, cleaned names, prices, and categories
  • Item quantity and unit price, when available
  • Item weight with unit (e.g., "1.5 lb"), when sold by weight
  • Item flags: whether an item is organic and whether it is perishable
  • Receipt total amount

Grocery Snap (AI-Estimated Data)

When you use Grocery Snap to photograph grocery items instead of a receipt, our AI identifies the products and creates a receipt entry that includes estimated prices (marked with a hasPriceEstimates flag so you can tell estimates from receipt-accurate totals). Prices are inferred from general market data, not from any individual retailer, and you should treat them as approximations. You can edit or delete any Grocery Snap receipt from the receipt detail view just like a scanned receipt.

Pantry, Shopping Lists, Recipes, and Grocery Memory

Beyond individual receipts, the Services derive further information from your purchase history:

  • Pantry — an inferred view of what you likely have on hand, based on what you have bought and how recently, combined with any stock levels or storage details you record yourself
  • Restock recommendations and shelf-life estimates — generated by Google Gemini AI from your pantry snapshot and repeat-purchase patterns
  • Shopping lists — items you add, plus AI-suggested items based on your recent purchases
  • Recipe suggestions — generated by Google Gemini AI from your current pantry contents
  • Grocery Memory — a periodic AI-generated recap of your household's grocery activity, built from your receipts for the relevant period and stored on your account

These features send the relevant slice of your receipt and pantry data to Google Gemini AI for processing. They are conveniences, not advice — see our Terms of Service for the limits that apply, particularly around food safety and dietary restrictions.

AI Quality Monitoring

To measure the accuracy of our AI features and fix their mistakes (for example a misread price or a receipt that failed to process), we keep a record of each AI request we make on your behalf with Langfuse, our AI monitoring provider. A record contains what we sent to the AI model and what it returned (for example the text and extracted items of a receipt, or the pantry items used to suggest recipes), along with your user ID, the app you used, the AI model, and timing and usage figures. Receipt images and files are not copied into these records; a record links to the copy we already store. Email addresses and payment card numbers are masked before a record leaves our servers.

Langfuse stores these records in the United States and does not use them to train AI models. We keep them while your account is active and delete them when you delete your account.

Mobile App and On-Device Data

Our mobile apps are offline-first. A copy of your receipts and a queue of pending uploads are stored in a database on your device so the app works without a connection, and are synchronised with our servers when connectivity returns. This on-device copy is removed when you sign out or delete the app.

The mobile apps also collect or use:

  • Device and app information — device model, operating system version, and app version, used for diagnostics and compatibility
  • Time zone — your IANA time zone identifier, so the server can correctly determine what "today" means for you
  • Network connectivity status — to decide when to sync
  • Push notification tokens — see "Push Notifications" below

Biometric app lock. You may optionally protect the app with Face ID, Touch ID, or your device's equivalent. This check is performed entirely by your device's operating system. We never receive, see, or store your biometric data — the app only learns whether the device reported a successful unlock, and only a simple on/off preference is stored on the device.

Push Notifications

If you enable notifications, we register a push token for your device with Firebase Cloud Messaging and store it on your account (under users/{uid}/fcmTokens) so we can deliver reminders and periodic summaries. Tokens are removed when you sign out or disable notifications, and you can turn notifications off at any time in your device settings.

Device Integrations (Apple Reminders and Widgets)

With your permission, the iOS app can write your shopping list into Apple Reminders on your device. This happens locally on your device; the reminders you create belong to you and to Apple's Reminders service, and are not sent back to us. Home screen widgets display a summary of your own data drawn from the app's on-device storage. Both are optional and can be revoked in your device settings.

Third-Party AI Assistant Access (MCP)

GroceryTrack exposes a Model Context Protocol (MCP) server at /api/mcp that lets you grant third-party AI clients (such as Claude, ChatGPT, or any other MCP-compatible assistant) authorized access to your data. When you connect a client:

  • You complete an OAuth 2.1 authorization flow (with PKCE) signed in to your GroceryTrack account
  • A scoped, time-limited access token is issued (default expiry: one hour) and stored in Cloud Firestore
  • Your OAuth client registration details (client ID, redirect URI, registration metadata) are stored in Cloud Firestore
  • While the token is valid, the authorized client can call read-only MCP tools to retrieve your receipts, line items, trip notes, and spending summaries; the nutrition catalog is public and does not require authentication

You can revoke access at any time by contacting support. Once access is connected, any data returned through the MCP tools is transmitted to and processed by the third-party AI client according to that client's own privacy policy — GroceryTrack does not control what they do with your data after it leaves our systems.

Usage Data

When you use our Services, the following types of information may be logged automatically ("Usage Information"):

  • Client application type (web, iOS, Android) and version number
  • Analytics events such as sign-in, receipt uploads, tab navigation, and feature usage
  • Date and time stamps associated with actions
  • Technical information about your device and browser
  • Error, crash, and performance data, including stack traces and device and browser metadata (collected via Sentry and, in the mobile apps, Firebase Crashlytics). We do not record session replays. Session replay is disabled in both our web and mobile applications

Payment Information

How your payment is handled depends on where you subscribe. In every case, GroceryTrack never collects or stores your credit card number, CVV, or full payment card details.

  • On the web, payments are processed by Stripe in accordance with Stripe's Privacy Policy.
  • In the iOS app, subscriptions are sold and billed by Apple as In-App Purchases. Apple processes the payment; we receive only a purchase receipt and your resulting subscription status. See Apple's Privacy Policy.
  • In the Android app, subscriptions are sold and billed by Google through Google Play Billing. See Google's Privacy Policy.

We use RevenueCat to validate purchase receipts and keep your subscription status consistent across your devices and the web. RevenueCat receives an anonymous app-user identifier linked to your account and the store's purchase receipt; it does not receive your payment card details. See RevenueCat's Privacy Policy.

The following payment-related data is stored by GroceryTrack for account management and record-keeping:

  • The billing platform your subscription came from (Stripe, App Store, or Play Store)
  • Stripe customer ID and subscription ID, or the store transaction identifier
  • Subscription status (active, canceled, in trial, etc.)
  • Payment amounts, currency, and billing period dates
  • Invoice URLs for your payment history, where the platform provides them

How We Use Your Information

We use your information to:

  • Provide and improve our Services, including AI-powered receipt extraction, AI product identification with estimated prices via Grocery Snap, spending analytics, budget insights, and organic/perishable item tracking
  • Display your personalized dashboard, receipt history, spending charts, and item-level details such as quantity, weight, and freshness indicators
  • Surface your own trip notes in context (e.g., on the relevant receipt and on the store profile page for the store the note was attached to); trip notes are private to your account and are not shared with other users
  • Summarize your trip notes on request via Google Gemini AI when you click "Summarize" — the notes you have saved for a given store are sent to Gemini to produce a short recap
  • Build public, de-identified store directory pages (/store and /store/[slug]) that aggregate only canonicalized store names from receipts across all users; no receipt contents, notes, prices, or user identifiers are included in the public directory
  • Maintain your pantry view, generate restock recommendations, shelf-life estimates, shopping list suggestions, and recipe suggestions, and produce your periodic Grocery Memory recap
  • Send you push notifications and periodic email summaries that you have not opted out of
  • Operate the referral programme, including attributing a referral to the account that shared the code
  • Generate and cache AI item images for faster loading across all users
  • Administer your account and process your requests
  • Monitor service health and usage patterns via aggregated analytics
  • Process subscription payments and maintain your billing history
  • Communicate with you about updates, changes, or issues with the Services

If you submit Personal Information to us, we will only use it for the purpose for which it was collected or for any purpose you subsequently authorize. GroceryTrack will never sell your information or use it to build a marketing profile.

How We Collect Usage Data

GroceryTrack collects some information using Firebase Analytics to track anonymous and identified usage across users. We use this information to monitor and analyze use of our Services, for technical administration, and to increase functionality and user-friendliness.

As of the date this policy went into effect, we use:

  • Firebase Analytics — to collect and analyze usage data. Firebase Privacy Policy
  • Firebase Crashlytics — to collect crash reports from our mobile apps. Firebase Privacy Policy
  • Firebase Cloud Messaging — to deliver push notifications to your device. Firebase Privacy Policy
  • Sentry — to monitor application errors and performance for debugging. Sentry may collect your IP address, device and browser information, user ID, and actions leading up to an error. We do not use Sentry's session replay feature. Sentry Privacy Policy
  • Google Gemini AI — to process receipt and grocery images, PDF receipts, the text of forwarded receipt emails, and receipt pages you share with us, and to generate item images, recommendations, recipes, summaries, and recaps. Google AI Terms
  • Langfuse — to record the AI requests we make on your behalf and their results, so we can measure the quality of our AI features and debug failures. See "AI Quality Monitoring" above. Langfuse Privacy Policy
  • RevenueCat — to validate app store purchase receipts and keep subscription status in sync. RevenueCat Privacy Policy
  • Resend — to receive forwarded receipt emails and deliver transactional emails. Resend processes sender email addresses, email content, and attachments. Resend Privacy Policy
  • Google BigQuery — our analytics warehouse, which receives an export of analytics events for aggregate reporting. Google Cloud Privacy Notice

Data Ownership

All data remains your property and is solely owned and controlled by you. You grant GroceryTrack a non-exclusive, royalty-free license to use your data solely for the purpose of providing, maintaining, and supporting you with the Services. GroceryTrack may use and distribute de-identified, aggregated data for analytics and service improvement purposes.

Data Storage

Your data is stored using Google Cloud services:

  • Cloud Firestore — account data, receipts (including trip notes and manual corrections), pantry records, shopping lists, Grocery Memory entries, budget profiles, item catalog, referral records, push notification tokens, feedback, MCP OAuth client registrations, and MCP access/refresh tokens
  • Cloud Storage — receipt images, Grocery Snap photos, and AI-generated item images
  • Firebase Authentication — account credentials and session management
  • Google BigQuery — analytics events, used for aggregate product reporting

In addition, our mobile apps keep a copy of your receipts and a pending-upload queue in a local database on your own device, along with small app preferences (such as whether the biometric lock is enabled). This on-device data is under your control and is removed when you sign out or delete the app.

Data on our servers is stored in the United States and protected by Google Cloud's security infrastructure. If you reside outside the U.S., the information we collect will be transferred to the U.S. and processed and stored there under U.S. privacy standards.

Information Sharing and Disclosure

We do not sell your personal information. Your data may be shared with the following third parties solely for the purpose of providing the Services:

Service Providers used for the technical infrastructure:

  • Google Cloud Platform — Firestore, Cloud Storage, and Firebase Authentication for data storage and account management
  • Google Gemini AI — receipt processing (images, PDFs, forwarded email content, and shared receipt pages) and item image generation
  • Langfuse — AI quality monitoring: records of the AI requests we make on your behalf and their results, with email addresses and payment card numbers masked. Langfuse Privacy Policy
  • Firebase Analytics — usage tracking and analytics
  • Sentry — error monitoring and performance tracking for debugging. Sentry Privacy Policy
  • Stripe — payment processing for subscriptions purchased on the web. Stripe Privacy Policy
  • Apple — payment processing and subscription management for In-App Purchases made in the iOS app. Apple Privacy Policy
  • Google Play — payment processing and subscription management for purchases made in the Android app. Google Privacy Policy
  • RevenueCat — purchase receipt validation and subscription status synchronisation. RevenueCat Privacy Policy
  • Resend — inbound email processing for receipt forwarding and transactional email delivery. Resend Privacy Policy

Third-Party AI Clients You Authorize via MCP:

If you connect a third-party MCP client (e.g., Claude, ChatGPT) to your GroceryTrack account, receipts, line items, trip notes, and spending summaries retrieved by that client through our MCP tools are transmitted to the client you authorized. These clients are not our service providers — they are independent parties acting under your direction — and their handling of your data is governed by their own terms and privacy policies. You can stop this sharing at any time by revoking the client's access (contact support).

We may disclose information about you if we become subject to a subpoena or court order, or if we are otherwise legally required to disclose information. We may also use and disclose information about you to establish or exercise our legal rights, to enforce the Terms of Service, to assert and defend against legal claims, or if we believe such disclosure is necessary to investigate, prevent, or take other action regarding actual or suspected illegal or fraudulent activities.

If we are involved in a merger, acquisition, or sale of all or a portion of our assets, your information may be transferred as part of that transaction, but we will notify you of any change in control or use of your Personal Information.

Non-private or Non-Personal Information. GroceryTrack may disclose your non-private, aggregated, or otherwise non-personal information, such as usage statistics of our Services. In such cases, your usage data is aggregated with the usage data of others and does not identify you individually.

Data Security

GroceryTrack takes reasonable steps to help protect information against loss, misuse, unauthorized access, or disclosure. Our security measures include:

  • Firebase Security Rules ensuring users can only access their own data
  • Server-side authentication via Firebase ID tokens for all API requests
  • HTTPS encryption for all data in transit
  • Gemini API key stored server-side only, never exposed to client applications
  • Email addresses and payment card numbers masked before records of AI requests are sent to our AI monitoring provider
  • An optional biometric lock on the mobile apps, enforced by your device's operating system

GroceryTrack expressly disclaims any representation or warranty, whether express or implied, with respect to offering any definitive promise of security in connection with the information we collect.

Your Rights and Choices

You have the following rights with respect to your data:

  • Access: View all your stored data through the app, including receipts, trip notes, items, and budget profile
  • Export: Export your receipt data via the CSV export feature in Receipt History
  • Delete: Delete individual receipts at any time through the app
  • Edit trip notes: Add, edit, or clear the free-form notes on any receipt from the receipt detail view — clearing a note removes it from our records
  • Revoke MCP client access: Disconnect any third-party AI client you previously authorized by contacting support; this invalidates their access tokens so they can no longer read your data
  • Manage your subscription: Cancel at any time — on the web through your account settings, on iOS through Settings → your name → Subscriptions, and on Android through the Google Play Store → Subscriptions
  • Notifications: Turn push notifications off at any time in your device settings, and unsubscribe from periodic email summaries using the link in any such email
  • Device permissions: Grant or revoke camera, photo library, biometric, notification, and Apple Reminders access at any time in your device settings
  • On-device data: Remove the local copy of your data by signing out of or deleting the mobile app
  • Account deletion: Request complete deletion of your account and all associated data by contacting support, or use the account deletion option in the app where available
  • Correction: Update your display name and budget settings through the Profile page, and correct AI-extracted store names, item names, prices, totals, and item flags directly from the receipt detail view

Deleting Your Information

You may delete individual receipts directly within the app. To delete your entire account and all associated data, please contact us at privacy@grocerytrack.app. Upon receiving such a request, we will delete your account information from our live databases and all information and data stored for such account, including the records of AI requests held by our AI monitoring provider. When we delete Personal Information, it will be deleted from our active databases but may remain in our archives and backups for a reasonable period.

Our Policy Toward Children

The Services are not intended for children under 13 years of age. We do not knowingly collect personally identifiable information from children under 13. If we become aware that a child under 13 has provided us with Personal Information, we will take steps to delete such information. If you are a parent or guardian and you are aware that your child has provided us with Personal Information, please contact us at privacy@grocerytrack.app.

Linked Sites

Our Services may contain links to other websites whose privacy practices may differ from those of GroceryTrack. If you submit personal information to any of those sites, your information is governed by their privacy statements. We encourage you to carefully read the privacy statement of any website you visit.

Special Considerations by State

California — GroceryTrack will not use your data for any purpose beyond the indicated purposes in the Terms of Service and this Privacy Policy. This includes GroceryTrack's policy to never use personal information to engage in targeted advertising. In accordance with the California Consumer Privacy Act (CCPA), California residents have the right to request disclosure of data collection practices, request deletion of personal information, and opt out of the sale of personal information (note: GroceryTrack does not sell personal information).

Contact

GroceryTrack is a product of Slash Dev Slash Null LLC.

Slash Dev Slash Null LLC
1111B S Governors Ave #20050
Dover, DE 19904
United States

For privacy-related questions, contact us at privacy@grocerytrack.app.

Document version 2026-09-19