Privacy Policy

Effective date: August 13, 2026

GroceryOS ("we," "our," or "the app") is built around a simple idea: your grocery data belongs to you, on your device. This policy explains what information the app handles, where it lives, and the choices you have.

The short version

Information the app stores on your device

All of this is stored in the app's private database on your device. Deleting the app removes that local database. To also clear Keychain credentials and attempt to revoke connected OAuth grants, use Settings → Delete account & data or disconnect the account before uninstalling.

Sign in with Apple

Creating an account is optional — you can use GroceryOS without one. If you choose Sign in with Apple, we receive only the identifier Apple provides (and your name/email if you elect to share them). This is stored on your device and is used solely to recognize you when you return. We never see your Apple ID password.

Camera and photo library

GroceryOS uses your camera and photo library only to scan receipt images. Text recognition (OCR) runs entirely on your device using Apple's Vision framework. Receipt images are not transmitted anywhere.

Optional features that send data off your device

Purchases and subscriptions

GroceryOS Pro subscriptions are processed by Apple through the App Store. We do not receive or store your payment details. Apple's handling of your purchase information is described in Apple's privacy policy.

Notifications

Expiration reminders and price alerts are scheduled locally on your device. We do not operate push-notification servers.

Website hosting and analytics

The jtrlabs.com website is delivered by Cloudflare and uses Cloudflare Web Analytics to measure aggregate page views and performance. Cloudflare states that its browser beacon does not use cookies or local storage and does not fingerprint visitors; the source IP address received during normal HTTP transport is discarded at the nearest Cloudflare data center rather than stored in its analytics databases. Website analytics do not access data stored inside the GroceryOS app. See Cloudflare's Web Analytics privacy information and Cloudflare's Privacy Policy.

Data retention and deletion

Your locally stored content stays on your device until you delete it. You can:

Children

GroceryOS is not directed at children under 13, and we do not knowingly collect personal information from children.

Security

OAuth tokens are stored in the iOS Keychain. App data is protected by iOS's built-in encryption and sandboxing. The Muse Spark credential remains on GroceryOS's server and is not embedded in the app. Requests to the managed AI service require an active Pro transaction and Apple App Attest verification and are subject to account and subscription usage limits.

Your rights

You can access, correct, and delete locally stored content directly in the app. The managed AI service retains pseudonymous metering and security records as needed to enforce subscription limits, prevent abuse, and maintain service security; these server records are not removed by the in-app local-data deletion. Contact us with questions about these records.

Changes to this policy

If we change this policy, we'll update the effective date above and, for material changes, note it in the app's release notes. Continued use of the app after a change means you accept the updated policy.

Contact

Questions or concerns: [email protected]