← Back to homebasket
  Working draft. This document is being finalized ahead of launch and is under legal review; a few details (like the formal business entity) are still being completed. It reflects how HomeBasket actually works today. Questions: support@homebasket.io.

HomeBasket Privacy Policy

Effective: [EFFECTIVE DATE] · Last reviewed: August 10, 2026


In short

HomeBasket uses account, household, purchase, pantry, preference, and wellness information to provide a shared household food and shopping service.

This summary does not replace the policy below.

1. Who we are and what this policy covers

[LEGAL ENTITY] ("HomeBasket," "we," "us") operates the HomeBasket mobile and web applications and related services. This policy covers those services and communications with our support team. It does not cover a third-party site or service you choose to open from HomeBasket.

Contact: support@homebasket.io · [POSTAL ADDRESS]

2. Information we collect

InformationExamples and purposeRetention criterion
Account and profileEmail, authentication identifier, name, sign-in provider, legal-policy acceptanceWhile the account exists, then deleted unless a narrow legal or security need requires retention
Household and membershipHousehold name, invite code, member names, roles, membershipWhile the household or membership exists
Receipt imagesImages you select or capture, which may include store, transaction, and partial payment information printed on the receiptUntil the receipt or household is deleted; see Sections 7 and 10
Purchase and commercial recordsRetailer, date, products, quantities, prices, totals, barcodes, corrections, and purchase historyWhile the household exists because these records support the pantry ledger and spending history
Pantry and shopping dataPantry items, inventory events, freshness estimates, lists, budgets, and buy-again patternsWhile the household exists or until the relevant item is deleted, subject to ledger integrity
Recipe and meal informationSaved or imported recipes, source links, meal plans, and pantry-to-recipe matchesUntil deleted or while the household exists
Preferences and wellness informationEating patterns, foods to avoid, preferred cuisines, goals such as heart health or blood sugar, and a calorie targetUntil the entry, membership, or household is deleted
Derived observations and suggestionsIngredient warnings; product nutrition scores; observations about recent purchases; suggested foods, recipes, and plansRecomputed from current household data or retained with the feature that displays it
Support communicationsMessage content, attachments, and our responseAs long as needed to resolve the request and maintain reasonable business records
Network, device, and diagnosticsIP address and approximate region inferred from it, app/OS or browser information, request identifier, endpoint, timing, status, error, and security eventsFor the shortest period reasonably needed for reliability, security, fraud prevention, and legal compliance; routine application logs are ordinarily deleted or overwritten within 90 days

The categories above may include identifiers, customer records, commercial information, internet or electronic-network activity, visual information, inferences, and sensitive personal information under some state laws.

Information a receipt image may contain

A receipt image may display a payment-card fragment, loyalty identifier, transaction number, address, pharmacy item, or other information printed by the retailer. We store the original image so you can review it. Before structured AI output is written to the database, HomeBasket filters detected card/account lines from that output. The original image itself is not redacted before it is stored or sent to the AI processor. Do not upload a receipt if you do not want the full image processed, and cover information you do not want included before you photograph it.

We do not ask for or provide a field to store a full payment-card number, diagnosis, medication, symptom, clinical note, or allergy severity. Do not put those details in free-text fields or support messages.

3. Sensitive information and what we deliberately do not collect

HomeBasket does not collect health information. There is no field in the app for an allergy, a severity, a symptom, a diagnosis, a medication, or a free-text medical note, and we do not ask a person why they avoid a food.

What we do hold about eating is a short, fixed list a person chooses for themselves:

We treat this information as sensitive and handle it conservatively: it is used to filter and rank food suggestions and to warn about a food a person asked us to leave out. We do not infer a diagnosis from it, we do not use it to build a profile about a person's health, and we do not disclose it for advertising.

An eating pattern is a choice, not a diagnosis. A person may eat gluten-free or dairy-free for reasons that have nothing to do with a medical condition, and we do not record which it is.

If HomeBasket ever collects consumer health data as defined by Washington, Nevada, or Connecticut law, we will publish a separate consumer-health-data privacy policy and obtain separate consent before that collection begins. We do not collect it today.

4. How we collect information

We collect information:

Product and nutrition sources such as Open Food Facts and USDA FoodData Central return facts about a barcode or product. We do not buy consumer profiles from data brokers or advertising partners.

5. How we use information

We use information to:

We do not make automated decisions that produce legal or similarly significant effects about a person.

6. Cookies, local storage, analytics, and advertising

HomeBasket does not use advertising SDKs, pixels, session replay, or cross-service behavioral analytics, and we do not use personal information for targeted advertising. A web build or authentication flow may use essential cookies, tokens, or local storage to maintain a secure session, remember a setting, prevent fraud, or complete sign-in. Those mechanisms are not used to track you across unrelated services.

7. When we disclose information

Household members

Household members can access shared receipts, purchases, pantry data, lists, budgets, recipes, meal plans, goals, and other shared data. Foods a person avoids and the person's display name may appear together in an ingredient warning. Only join or invite people you trust.

Processors and service providers

We use processors under contract to perform services for us:

Provider or categoryInformation processedService
SupabaseAccount, authentication, database records, and receipt imagesAuthentication, database, and private file storage
RenderInformation and requests passing through the API; operational logsApplication hosting
Google Gemini APIReceipt images and extracted text; product or recipe prompts; limited pantry/recipe context when a requested feature needs itReceipt reading, product identification, recipe import/generation, and meal planning
OpenAI APIThe same categories as the configured AI task, if OpenAI is selectedAlternative AI processing; there is no automatic fallback unless configured
Apple and Google sign-inAccount and authentication informationOptional sign-in
Open Food Facts, USDA FoodData Central, and enabled product-data providersBarcode or product query; no HomeBasket account or household identifierProduct and nutrition lookup

Generic catalogue-image providers may receive a generic food prompt but no household or account data. We require contracts appropriate to the data each processor receives and limit processing to our instructions.

We may also disclose information when reasonably necessary to comply with law or valid legal process; protect rights, security, or safety; investigate fraud or abuse; establish or defend legal claims; or complete a merger, financing, reorganization, bankruptcy, or sale of assets. A successor must honor this policy for data acquired in the transaction or give legally required notice and choice before using it differently.

8. AI processing

A receipt image is sent intact to the configured AI processor. We instruct the processor not to return structured payment data and filter detected card/account lines from the structured result before it is stored. That does not amount to pre-model image redaction.

We use only paid or business API configurations under which submitted inputs and outputs are not used to train general-purpose provider models, and we do not opt in to provider training. Providers may retain prompts and responses for a limited period for abuse monitoring, security, or legal compliance under their business terms. We do not use household content to train a HomeBasket general-purpose model.

Automated output is validated before persistence where the feature requires structured data. Receipt extraction remains unconfirmed until a user reviews and confirms it. Automated systems can still be wrong.

9. Security

We use administrative, technical, and physical safeguards designed for the nature of the information, including encryption in transit, provider-managed encryption at rest, private receipt storage, expiring image links, secure device storage for sessions, household-scoped authorization, database row-level controls, and payment-line filtering from structured receipt data.

No system is completely secure. Contact support@homebasket.io promptly if you believe an account or household has been accessed without permission.

10. Retention and deletion

We retain each category for the period or according to the criterion in Section 2, then delete or deidentify it unless retention is reasonably necessary for security, fraud prevention, legal compliance, dispute resolution, or enforcement.

Deleting an account immediately removes the person's access and membership and starts deletion of the authentication account and member-specific records. A household with no remaining member is deleted with its receipts, pantry, lists, and other content. A household with another member remains, along with its shared receipts, purchase history, pantry, lists, recipes, plans, budgets, and goals. The in-app deletion preview identifies which result applies. Before leaving, a member may delete content that the Service allows that member to delete. A privacy request may require additional review where information relates to more than one household member.

How long deletion takes. You can delete an account from inside the app. Access ends immediately. We complete deletion from active systems within 30 days of the request and, where a processor holds a copy, instruct that processor within the same period. If we cannot complete a request in 30 days we will tell you why and give a date.

Deletion from active systems may not immediately remove isolated backup copies. Backups are access-restricted, not used in the ordinary course, and overwritten under provider backup cycles. If a backup is restored, deletion requests are reapplied.

11. Your rights and choices

Wherever you live in the United States, you may ask us to:

You may also edit or delete many entries in the app, leave a household, and initiate account deletion in the app.

Submit a request from the email associated with your account to [PRIVACY EMAIL]. We will verify the request using information already associated with the account and will not ask for unnecessary sensitive information. An authorized agent may submit a request with proof of authority. We ordinarily respond within 45 days and may extend once where permitted, with notice. We do not discriminate against anyone for exercising a privacy right.

If we deny a request, reply with “Privacy Appeal.” We will review the appeal and provide a written decision within the period required by applicable law, including information about contacting the appropriate regulator when required.

12. Device permissions

HomeBasket asks for a permission only at the moment a feature needs it, never on first launch, and the app remains usable if you decline.

PermissionWhat it is forIf you decline
CameraPhotographing a grocery receipt and scanning a product barcodeYou can still add items by hand or pick an existing photo
Photo libraryChoosing a receipt photo you already tookYou can still use the camera or add items by hand
NotificationsReminders you turn on, such as food about to expireThe app works; you receive no reminders
Alarms and start-at-boot (Android)Delivering a scheduled reminder at the right time, and restoring your schedule after a restartReminders may arrive late or stop after a restart

We choose a single photo you select or capture. We do not read your photo library, and we do not ask for GPS or precise location, the microphone, contacts, or the calendar.

Reminders are produced on your device. HomeBasket schedules them locally. There is no push-notification token, and no reminder or its content is sent to us or to a third party.

13. App store disclosures

App stores require a summary of the data an app collects. This section states ours so the store listing and this policy say the same thing. "Linked" means the data is associated with your account. "Tracking" has the meaning the app stores give it: following you across other companies' apps or websites.

CategoryExamplesPurposeLinkedTracking
Contact informationName, email addressAccount and household membershipYesNo
User contentReceipt images, pantry items, shopping lists, saved and imported recipes, meal plans, notes you writeCore featuresYesNo
PurchasesRetailer, date, items, prices and totals read from your receipts; budgets you setPantry, spending and budget featuresYesNo
Sensitive informationEating pattern, foods to leave out, wellness goals, calorie target — see Section 3Filtering and ranking food suggestionsYesNo
IdentifiersAccount identifier, household identifierSign-in and keeping a household's data separateYesNo
Diagnostics and usageIP address and the approximate region inferred from it, app or browser version, request identifier, endpoint, timing, status, and error — kept as server logs, described in Section 2Reliability, security, and abuse preventionYesNo

We use no third-party crash-reporting or performance software development kit; the diagnostics above are our own server logs.

We do not collect precise location, contacts, browsing history, biometrics, health or fitness data, payment card numbers, or advertising identifiers.

We do not track you. HomeBasket does not follow you across other companies' apps or websites, does not use an advertising identifier, and takes part in no advertising network or data-broker arrangement. Because we do not track, the app presents no tracking-permission prompt.

We use no third-party analytics, crash-reporting, or advertising software development kit. We keep operational server logs to run and secure the service, described in Section 2.

14. Children

The Service is for adults age 18 and older. We do not knowingly allow a person under 18 to create an account or use the Service. An adult may enter limited household information relating to a minor only if the adult has legal authority and provides any notice and consent required by law. Do not enter a minor's diagnosis, medication, symptom, clinical note, or allergy severity. Contact support@homebasket.io if you believe a minor has provided information directly.

15. California notice

During the preceding 12 months, we collected the categories described in Section 2 from the sources in Section 4, used them for the purposes in Section 5, and disclosed them to the categories in Section 7. We did not sell personal information or share it for cross-context behavioral advertising, including personal information we know relates to anyone under 16.

We use sensitive personal information only to provide requested features, secure the Service, and for other purposes permitted without a right to limit under California law. We do not use it to infer characteristics for advertising.

California residents may exercise the rights in Section 11. Under California's “Shine the Light” law, you may ask about disclosure for third parties' own direct marketing; we make no such disclosures. A registered California user under 18 may request removal of content posted while under 18, although the Service does not permit under-18 accounts.

16. Nevada notice

Nevada residents may direct an operator not to make a covered sale of certain information. We do not make covered sales. Submit a request to support@homebasket.io with “Nevada Privacy Request” in the subject. We do not collect Nevada consumer health data; see Section 3.

17. Changes to this policy

We will post an updated policy with a new effective date. If a change materially expands collection, use, or disclosure, we will provide notice before the change takes effect and obtain consent where required. We will not apply a materially different use retroactively without a lawful basis and required consent.

18. Accessibility

If you use assistive technology and need this policy in another format, contact support@homebasket.io.

19. Where we operate

HomeBasket is offered only in the United States. Data is processed in the United States and may be processed in another country where an identified processor operates, subject to its contract with us. The Service is not offered to people in the European Economic Area, United Kingdom, or Switzerland.

20. Contact

[LEGAL ENTITY]<br> [POSTAL ADDRESS]<br> support@homebasket.io