Privacy Policy
Effective date: August 13, 2026
GroceryOS ("we," "our," or "the app") is built around a simple idea: your grocery data belongs to you, on your device. This policy explains what information the app handles, where it lives, and the choices you have.
The short version
- Your receipts, pantry, lists, budgets, and meal plans are stored locally on your device.
- We do not use advertising or general behavioral-analytics SDKs, sell data, or track you across apps and websites. The managed AI service retains limited security and usage-metering records as described below.
- Optional Gmail import connects directly to Google. Optional Pro AI sends limited meal-planning inputs through GroceryOS's service to Meta, as described below.
Information the app stores on your device
- Receipts and purchases: store names, items, prices, dates, optional receipt photos, and the raw OCR, PDF, or receipt-email text used to parse an imported receipt.
- Pantry and lists: pantry items, expiration estimates, shopping lists, meal plans, and consumption history.
- Profile basics: the display name you enter (or your name from Sign in with Apple, if you choose to use it) and your household name.
- Preferences: budgets, notification settings, diet preferences, and app settings.
All of this is stored in the app's private database on your device. Deleting the app removes that local database. To also clear Keychain credentials and attempt to revoke connected OAuth grants, use Settings → Delete account & data or disconnect the account before uninstalling.
Sign in with Apple
Creating an account is optional — you can use GroceryOS without one. If you choose Sign in with Apple, we receive only the identifier Apple provides (and your name/email if you elect to share them). This is stored on your device and is used solely to recognize you when you return. We never see your Apple ID password.
Camera and photo library
GroceryOS uses your camera and photo library only to scan receipt images. Text recognition (OCR) runs entirely on your device using Apple's Vision framework. Receipt images are not transmitted anywhere.
Optional features that send data off your device
- AI meal suggestions (optional, Pro purchaser): when the subscription purchaser requests managed AI meal ideas, the app sends pantry item names, quantities, units and expiration dates plus the household size, diet style, allergies, excluded foods, preparation-time preference, and preferred cuisines they supplied. It also sends a signed App Store transaction and an Apple App Attest proof so GroceryOS can verify Pro access, protect the service, and enforce usage limits. These inputs pass through GroceryOS's service and the meal-planning prompt is sent to Meta's Muse Spark service. GroceryOS's application database stores pseudonymous hashed subscriber identifiers, App Attest security records, and usage counters; it is not designed to store the meal-planning payload. Network and AI service providers may process or retain information under their own terms and policies, including Meta's Privacy Policy. Family members receiving Pro through Apple Family Sharing use the on-device Pro recipe library and do not send a managed Muse Spark request. If managed AI is unavailable, the purchaser may also see on-device suggestions.
- Email receipt import (where available): if you connect Gmail, the app fetches candidate grocery-receipt messages directly from Google over an encrypted connection and parses them on your device. Gmail message contents are not sent through GroceryOS's AI service. Login uses Google's OAuth flow; we never receive your Google password, and OAuth tokens are stored in the iOS Keychain. Disconnect attempts to revoke the Google grant and remove its local token; the app reports any revocation, Keychain, or local-storage failure so you can take corrective action.
Purchases and subscriptions
GroceryOS Pro subscriptions are processed by Apple through the App Store. We do not receive or store your payment details. Apple's handling of your purchase information is described in Apple's privacy policy.
Notifications
Expiration reminders and price alerts are scheduled locally on your device. We do not operate push-notification servers.
Website hosting and analytics
The jtrlabs.com website is delivered by Cloudflare and uses Cloudflare Web Analytics to measure aggregate page views and performance. Cloudflare states that its browser beacon does not use cookies or local storage and does not fingerprint visitors; the source IP address received during normal HTTP transport is discarded at the nearest Cloudflare data center rather than stored in its analytics databases. Website analytics do not access data stored inside the GroceryOS app. See Cloudflare's Web Analytics privacy information and Cloudflare's Privacy Policy.
Data retention and deletion
Your locally stored content stays on your device until you delete it. You can:
- delete individual items, receipts, or lists at any time;
- use Settings → Delete account & data to permanently erase the app's local receipts, pantry, lists, preferences, sign-in state, and stored tokens or keys. The app also attempts to revoke connected Gmail grants. This is immediate and irreversible on the device;
- or delete the app to remove its local database. Because iOS may preserve Keychain items across reinstalls, use the in-app deletion or disconnect controls first if you also want stored credentials cleared.
Children
GroceryOS is not directed at children under 13, and we do not knowingly collect personal information from children.
Security
OAuth tokens are stored in the iOS Keychain. App data is protected by iOS's built-in encryption and sandboxing. The Muse Spark credential remains on GroceryOS's server and is not embedded in the app. Requests to the managed AI service require an active Pro transaction and Apple App Attest verification and are subject to account and subscription usage limits.
Your rights
You can access, correct, and delete locally stored content directly in the app. The managed AI service retains pseudonymous metering and security records as needed to enforce subscription limits, prevent abuse, and maintain service security; these server records are not removed by the in-app local-data deletion. Contact us with questions about these records.
Changes to this policy
If we change this policy, we'll update the effective date above and, for material changes, note it in the app's release notes. Continued use of the app after a change means you accept the updated policy.
Contact
Questions or concerns: [email protected]