Grocerly
Privacy Policy
This Privacy Policy explains what information Grocerly (the “Application”), built by Daniel Kalo (the “Service Provider”), collects, how it’s used, and who it’s shared with. It’s written to reflect exactly what the app does, not a generic template.
Information We Collect
Account information. You sign in with Google, Apple, or email/password via Firebase Authentication. Your public profile (display name, an optional username, and a profile photo) is stored so friends can find and add you — your email address itself is never stored in that profile.
Content you create. Pantry items, recipes, grocery lists, custom categories, and preferences sync to your account, including any dietary restrictions, allergies, or health goals you optionally set to personalize AI suggestions.
Chat messages. Conversations with Grocerly’s AI chef (“Sous”) are saved to your account and sent to our AI provider to generate responses.
Recipe imports. A URL you submit to import a recipe — including from TikTok or Instagram — is sent to the relevant service to extract the recipe.
Push notifications. If you enable notifications, a device push token is stored privately (never visible to other users) to deliver alerts you’ve opted into, such as friend requests.
Friends and households. If you add a friend, share a recipe, or join a household, the relevant connection and shared content becomes visible to that friend/household as described below.
The Application does not collect precise device location, and does not use any analytics, advertising, or crash-reporting SDKs — nothing about how you use the app is tracked beyond what’s described here.
How We Use It
- To run the core features: pantry tracking, recipe management, grocery lists, and AI chat suggestions
- To sync your data across your devices
- To power features you opt into: friends, recipe sharing, and households
- To verify and manage your Grocerly Pro subscription
- To send notifications you’ve enabled
- To provide customer support when you contact us
Who We Share It With
The Application uses the following third-party services, and only shares what each one actually needs to function:
- Firebase (Google) — Authentication, cloud data sync (Firestore), photo storage, and push delivery. Firebase hosts your account and synced data.
- Anthropic — receives the content you send to the AI chat and recipe features (pantry items, recipe text, chat messages) to generate a response.
- RevenueCat — receives your account identifier to verify your subscription/purchase status.
- Recipe-import services (a TikTok metadata API, TikTok’s own oEmbed endpoint, and direct Instagram page access) — receive only the specific URL you submit for import, never your account identity.
- Apple App Store / Google Play — process subscription payments directly; the Application never receives or stores your payment details.
We do not sell your personal information. We may disclose it if required by law, to protect rights or safety, or to investigate fraud.
What other users can see: your display name, username, and photo are visible to any signed-in user (so friend and recipe-share search works). Recipes you explicitly share are visible only to the recipient. If you join a household, its shared pantry and grocery-list content is visible to all current household members.
Data Retention & Deletion
We retain your data for as long as you keep an account. You can permanently delete your account and its data at any time from Account → Delete Account (typing “DELETE” to confirm). Deleting your account removes:
- your profile, recipes, pantry, grocery lists, preferences, and chat history
- your friendships and any pending friend requests
- recipes you’ve shared with or received from friends
- your stored push-notification token
If you belong to a household, deleting your account removes you from its membership; the household’s own shared content isn’t individually attributed per member, so it remains available to the other current members rather than being retroactively edited.
If you’re unable to access the Application, you can request deletion by emailing grocerlysupport@kalotech.dev.
Children
The Application is not directed at children under 13, and the Service Provider does not knowingly collect personal information from them. If you believe a child has provided personal information, contact us at grocerlysupport@kalotech.dev and we’ll remove it.
Security
Data is transmitted over encrypted connections and stored behind access-scoped database rules — your synced content, private tokens, and server-managed records are each only reachable by you or by server-side code, never by other users directly.
Changes
This Privacy Policy may be updated from time to time. We’ll update the effective date above when it changes — continued use of the Application after an update means you accept the revised policy.
Contact Us
Questions about this policy or your data? Email grocerlysupport@kalotech.dev.