Legal

Privacy Policy

Originally published: 11 April 2026  ·  Last updated: 6 June 2026

At GrocaChef, your privacy matters. This policy explains what data we collect, how we use it, and the choices you have. We keep it simple and honest.

01 Introduction

Welcome to GrocaChef ("we," "our," or "us"). GrocaChef is a smart shopping list and AI-powered meal planning application available on iOS and Android. We are committed to protecting your personal information and your right to privacy.

This Privacy Policy describes how we collect, use, and share information about you when you use our mobile application ("App"). By using GrocaChef, you agree to the collection and use of information in accordance with this policy.

For any privacy-related enquiries, contact us at admin@grocaaichef.com.

02 Information We Collect

2.1 Information You Provide

  • Email address (used for account creation and authentication)
  • Display name (chosen by you during sign-up, max 12 characters)
  • Shopping list names, items, categories, and notes you create within the App
  • Barcode data scanned for product identification (processed locally — no images are stored)
  • List sharing relationships (who you've shared lists with)
  • Partner linking data — if you use the Partner Sharing feature, we store a household record containing the account IDs of the Owner and Partner, the invite code used, and the date the link was established
  • Support messages you send through the Contact Support feature

2.2 Information Collected Automatically

  • Authentication tokens and session identifiers
  • App usage data such as features accessed and actions performed (anonymised)
  • Device information including operating system version and device type
  • Error logs and crash reports to help us improve the App
  • In-app purchase and subscription status (via RevenueCat)

2.3 Information From Third Parties

  • We use Supabase for authentication and database services. Supabase may collect technical data as described in their privacy policy at supabase.com/privacy.
  • We use the Anthropic Claude API to power AI meal planning features. Messages sent to the AI feature are processed by Anthropic as described in their privacy policy at anthropic.com/privacy.
  • We use the Open Food Facts API to look up product names when you scan a barcode. Only the numeric barcode value is transmitted — no personal data, account information, or images are sent. Open Food Facts is a free, open-source, non-profit food database. See their privacy policy at world.openfoodfacts.org/privacy.

2.4 Data We Do Not Collect

  • Location data
  • Contacts or address book
  • Camera images (the barcode scanner processes values locally — no images are stored)
  • Any data without your explicit input

03 How We Use Your Information

We use the information we collect to:

  • Authentication — create and manage your GrocaChef account and verify your identity
  • App functionality — sync your lists across devices, enable offline access, and enable list sharing and collaboration
  • AI meal planning — your list contents may be sent to the Anthropic Claude API to generate meal suggestions (Premium feature only)
  • Subscriptions — manage and verify your premium subscription status via RevenueCat
  • Support — respond to your enquiries and support requests
  • Improvement — monitor and analyse anonymised usage patterns to fix bugs and improve features
  • Security — detect, prevent, and address technical issues and security threats
  • Notices — send you important notifications such as changes to our terms or policies

We do not use your data for advertising, profiling, or sale to third parties.

04 How We Share Your Information

We do not sell your personal data. We share it only in the following limited circumstances:

4.1 Service Providers

ServicePurposeData Shared
SupabaseDatabase, authentication & real-time syncAccount info, app data
RevenueCatSubscription managementUser ID, purchase receipts
AnthropicAI meal plan generation (Premium)List contents you submit
Open Food FactsBarcode product name lookupBarcode values only (no personal data)

All third-party service providers are contractually bound to protect your data and may not use it for their own purposes.

4.2 List Sharing

When you choose to share a shopping list with another user, their email address and shared list contents are visible to that user within the App. You control who you share lists with at all times.

4.3 Partner Sharing

If you use the Partner Plan, a household record is created that links your account ID to your Partner's account ID. This record is used solely to grant the Partner premium access. The following is shared between the two accounts:

  • The Owner can see the Partner's display name and email address within the Link Partner screen (and vice versa)
  • No lists, items, categories, or other personal data are shared between accounts unless you separately choose to share a list using the standard list-sharing feature
  • The household link record is deleted when either party removes the link

4.3 Legal Requirements

We may disclose your information if required to do so by law or in response to valid requests by public authorities (e.g. a court or government agency).

4.4 Business Transfers

If GrocaChef is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you before your information is transferred and becomes subject to a different privacy policy.

05 Data Retention

We retain your personal information for as long as your account is active or as needed to provide you with our services.

You may delete your account at any time through the App (see Section 8 below), which will permanently remove your account and all associated data from our systems.

Backup copies may persist for up to 30 days after deletion before being fully purged from our systems.

06 Data Storage & Security

Your data is stored securely on Supabase-managed infrastructure. We implement industry-standard security measures including:

  • All data transmitted over encrypted HTTPS connections (TLS)
  • Authentication handled by Supabase with secure JWT tokens
  • Row-Level Security (RLS) policies — you can only access your own data
  • Your password is hashed and never stored in plain text
  • A local encrypted SQLite database on your device for offline access
  • API keys and sensitive credentials stored server-side only — never included in the App bundle

No system is 100% secure. We encourage you to use a strong, unique password for your account. In the event of a data breach that affects your personal information, we will notify you as required by applicable law.

07 Your Rights & Choices

Depending on your location, you may have the following rights regarding your personal data:

  • Access & Correction — view and update your account information and display name at any time via the Profile screen in the App
  • Erasure — delete all your data via Profile screen → Erase Data, or delete your account entirely via Profile screen → Delete Account (see Section 9)
  • Portability — export your shopping lists to Excel at any time via Menu → Export to Excel
  • Opt-out of AI features — the AI meal planning feature is entirely optional; you may use all core shopping list features without engaging with it
  • Objection — contact us to object to any specific data processing activity

To exercise any right, contact us at admin@grocaaichef.com.

08 Subscription Management & Cancellation

If you hold a Premium subscription, you have full control over it at all times.

Managing your subscription in-app

GrocaChef includes a Manage Subscription button in the app menu (☰). Tapping it takes you directly to:

  • iOS: the App Store subscriptions page, where you can view, change, or cancel your GrocaChef subscription
  • Android: the Google Play subscriptions page, where you can view, change, or cancel your GrocaChef subscription

What happens when you cancel

  • Your subscription will not renew at the next billing date
  • You retain full Premium access until the end of your current paid period
  • After that, your account automatically reverts to the free tier
  • Your data (lists, items, categories) is not deleted when you cancel — only Premium features become inaccessible

Subscription data we hold

We use RevenueCat to manage subscription status. RevenueCat stores your anonymised user ID and purchase receipts to verify entitlements. We do not store your payment card details — all payment processing is handled exclusively by Apple or Google.

For RevenueCat's data practices, see revenuecat.com/privacy.

09 Account Deletion & Data Erasure

Erase data (keep your account)

You can delete all your shopping lists, items, and categories while keeping your account active:

  1. Open the app and tap the menu icon (☰) on the home screen
  2. Tap My Profile
  3. Scroll to Erase Data and confirm

Delete account (full removal)

You may permanently delete your account and all associated data at any time:

  1. Open the app and tap the menu icon (☰) on the home screen
  2. Tap My Profile
  3. Scroll to Delete Account
  4. Type DELETE to confirm and tap the button

This action is irreversible. All your lists, items, categories, and account information are permanently removed from our servers. Backup copies may persist for up to 30 days before being fully purged. This meets the requirements of Apple App Store guideline 5.1.1(v).

Alternatively, you may contact us at admin@grocaaichef.com to request account deletion.

10 Children's Privacy

GrocaChef is not directed at children under the age of 13. We do not knowingly collect personal information from children under 13. If we become aware that we have collected personal information from a child under 13, we will take steps to delete it promptly.

If you are a parent or guardian and believe your child has provided us with personal data, please contact us at admin@grocaaichef.com.

11 International Data Transfers

GrocaChef is operated through cloud service providers whose servers may be located in various regions around the world. If you are located outside the country where our servers are based, your information may be transferred to and processed in a country that may not have the same data protection laws as your country of residence.

By using GrocaChef, you consent to the transfer of your information to these facilities. We ensure that any such transfers are subject to appropriate safeguards consistent with this Privacy Policy.

12 Third-Party Services

The App integrates the following third-party services. We encourage you to review their privacy policies. We are not responsible for their privacy practices.

13 Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date at the top of this page and, where appropriate, notify you via the App or by email.

Your continued use of GrocaChef after changes become effective constitutes your acceptance of the revised Privacy Policy. We encourage you to review this policy periodically.

14 Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

📧
GrocaChef Support admin@grocaaichef.com We aim to respond within 24 hours.