HomeBasket Privacy Policy
Effective: [EFFECTIVE DATE] · Last reviewed: August 10, 2026
In short
HomeBasket uses account, household, purchase, pantry, preference, and wellness information to provide a shared household food and shopping service.
- We do not sell personal information or share it for cross-context behavioral advertising.
- We do not run third-party advertising or behavioral-analytics trackers.
- We do not request GPS or precise location.
- Receipt images are stored in a private bucket and sent intact to a paid or business AI API so the receipt can be read.
- We do not collect allergy information, symptoms, diagnoses, medication, or any free-text health note, and the app provides nowhere to enter them.
- We do not use any third-party analytics, crash-reporting, or advertising software development kit.
- A household is shared. Other members can see much of the information in it, and shared household records may remain after one member leaves.
This summary does not replace the policy below.
1. Who we are and what this policy covers
[LEGAL ENTITY] ("HomeBasket," "we," "us") operates the HomeBasket mobile and web applications and related services. This policy covers those services and communications with our support team. It does not cover a third-party site or service you choose to open from HomeBasket.
Contact: support@homebasket.io · [POSTAL ADDRESS]
2. Information we collect
| Information | Examples and purpose | Retention criterion |
|---|---|---|
| Account and profile | Email, authentication identifier, name, sign-in provider, legal-policy acceptance | While the account exists, then deleted unless a narrow legal or security need requires retention |
| Household and membership | Household name, invite code, member names, roles, membership | While the household or membership exists |
| Receipt images | Images you select or capture, which may include store, transaction, and partial payment information printed on the receipt | Until the receipt or household is deleted; see Sections 7 and 10 |
| Purchase and commercial records | Retailer, date, products, quantities, prices, totals, barcodes, corrections, and purchase history | While the household exists because these records support the pantry ledger and spending history |
| Pantry and shopping data | Pantry items, inventory events, freshness estimates, lists, budgets, and buy-again patterns | While the household exists or until the relevant item is deleted, subject to ledger integrity |
| Recipe and meal information | Saved or imported recipes, source links, meal plans, and pantry-to-recipe matches | Until deleted or while the household exists |
| Preferences and wellness information | Eating patterns, foods to avoid, preferred cuisines, goals such as heart health or blood sugar, and a calorie target | Until the entry, membership, or household is deleted |
| Derived observations and suggestions | Ingredient warnings; product nutrition scores; observations about recent purchases; suggested foods, recipes, and plans | Recomputed from current household data or retained with the feature that displays it |
| Support communications | Message content, attachments, and our response | As long as needed to resolve the request and maintain reasonable business records |
| Network, device, and diagnostics | IP address and approximate region inferred from it, app/OS or browser information, request identifier, endpoint, timing, status, error, and security events | For the shortest period reasonably needed for reliability, security, fraud prevention, and legal compliance; routine application logs are ordinarily deleted or overwritten within 90 days |
The categories above may include identifiers, customer records, commercial information, internet or electronic-network activity, visual information, inferences, and sensitive personal information under some state laws.
Information a receipt image may contain
A receipt image may display a payment-card fragment, loyalty identifier, transaction number, address, pharmacy item, or other information printed by the retailer. We store the original image so you can review it. Before structured AI output is written to the database, HomeBasket filters detected card/account lines from that output. The original image itself is not redacted before it is stored or sent to the AI processor. Do not upload a receipt if you do not want the full image processed, and cover information you do not want included before you photograph it.
We do not ask for or provide a field to store a full payment-card number, diagnosis, medication, symptom, clinical note, or allergy severity. Do not put those details in free-text fields or support messages.
3. Sensitive information and what we deliberately do not collect
HomeBasket does not collect health information. There is no field in the app for an allergy, a severity, a symptom, a diagnosis, a medication, or a free-text medical note, and we do not ask a person why they avoid a food.
What we do hold about eating is a short, fixed list a person chooses for themselves:
- an eating pattern from a closed list — vegetarian, vegan, pescatarian, non-vegetarian, gluten-free, dairy-free, or lactose-free;
- foods to leave out, written by the person in their own words;
- cuisines they like;
- household wellness goals and an optional daily calorie target.
We treat this information as sensitive and handle it conservatively: it is used to filter and rank food suggestions and to warn about a food a person asked us to leave out. We do not infer a diagnosis from it, we do not use it to build a profile about a person's health, and we do not disclose it for advertising.
An eating pattern is a choice, not a diagnosis. A person may eat gluten-free or dairy-free for reasons that have nothing to do with a medical condition, and we do not record which it is.
If HomeBasket ever collects consumer health data as defined by Washington, Nevada, or Connecticut law, we will publish a separate consumer-health-data privacy policy and obtain separate consent before that collection begins. We do not collect it today.
4. How we collect information
We collect information:
- directly from you, when you create an account, enter or correct data, capture a receipt, scan a barcode, join a household, import a recipe, select a preference or goal, or contact us;
- from another household member, when that person enters shared household data or information relating to you;
- from an authentication provider, such as Apple or Google, when you choose that sign-in method; and
- automatically, from the app, browser, servers, and service providers as needed to authenticate requests, prevent abuse, diagnose errors, and operate the Service.
Product and nutrition sources such as Open Food Facts and USDA FoodData Central return facts about a barcode or product. We do not buy consumer profiles from data brokers or advertising partners.
5. How we use information
We use information to:
- create and secure accounts and shared households;
- read and validate receipts and build an auditable pantry ledger;
- provide pantry, shopping, budgeting, freshness, nutrition, recipe, and meal planning features;
- rank or exclude suggestions according to the preferences and goals users ask us to apply;
- identify products and retrieve product, image, and nutrition information;
- provide support and send transactional or service notices;
- prevent fraud, abuse, unauthorized access, and excessive automated use;
- monitor reliability, troubleshoot, and improve the Service; and
- comply with law, enforce our Terms, and protect rights and safety.
We do not make automated decisions that produce legal or similarly significant effects about a person.
6. Cookies, local storage, analytics, and advertising
HomeBasket does not use advertising SDKs, pixels, session replay, or cross-service behavioral analytics, and we do not use personal information for targeted advertising. A web build or authentication flow may use essential cookies, tokens, or local storage to maintain a secure session, remember a setting, prevent fraud, or complete sign-in. Those mechanisms are not used to track you across unrelated services.
7. When we disclose information
Household members
Household members can access shared receipts, purchases, pantry data, lists, budgets, recipes, meal plans, goals, and other shared data. Foods a person avoids and the person's display name may appear together in an ingredient warning. Only join or invite people you trust.
Processors and service providers
We use processors under contract to perform services for us:
| Provider or category | Information processed | Service |
|---|---|---|
| Supabase | Account, authentication, database records, and receipt images | Authentication, database, and private file storage |
| Render | Information and requests passing through the API; operational logs | Application hosting |
| Google Gemini API | Receipt images and extracted text; product or recipe prompts; limited pantry/recipe context when a requested feature needs it | Receipt reading, product identification, recipe import/generation, and meal planning |
| OpenAI API | The same categories as the configured AI task, if OpenAI is selected | Alternative AI processing; there is no automatic fallback unless configured |
| Apple and Google sign-in | Account and authentication information | Optional sign-in |
| Open Food Facts, USDA FoodData Central, and enabled product-data providers | Barcode or product query; no HomeBasket account or household identifier | Product and nutrition lookup |
Generic catalogue-image providers may receive a generic food prompt but no household or account data. We require contracts appropriate to the data each processor receives and limit processing to our instructions.
We may also disclose information when reasonably necessary to comply with law or valid legal process; protect rights, security, or safety; investigate fraud or abuse; establish or defend legal claims; or complete a merger, financing, reorganization, bankruptcy, or sale of assets. A successor must honor this policy for data acquired in the transaction or give legally required notice and choice before using it differently.
8. AI processing
A receipt image is sent intact to the configured AI processor. We instruct the processor not to return structured payment data and filter detected card/account lines from the structured result before it is stored. That does not amount to pre-model image redaction.
We use only paid or business API configurations under which submitted inputs and outputs are not used to train general-purpose provider models, and we do not opt in to provider training. Providers may retain prompts and responses for a limited period for abuse monitoring, security, or legal compliance under their business terms. We do not use household content to train a HomeBasket general-purpose model.
Automated output is validated before persistence where the feature requires structured data. Receipt extraction remains unconfirmed until a user reviews and confirms it. Automated systems can still be wrong.
9. Security
We use administrative, technical, and physical safeguards designed for the nature of the information, including encryption in transit, provider-managed encryption at rest, private receipt storage, expiring image links, secure device storage for sessions, household-scoped authorization, database row-level controls, and payment-line filtering from structured receipt data.
No system is completely secure. Contact support@homebasket.io promptly if you believe an account or household has been accessed without permission.
10. Retention and deletion
We retain each category for the period or according to the criterion in Section 2, then delete or deidentify it unless retention is reasonably necessary for security, fraud prevention, legal compliance, dispute resolution, or enforcement.
Deleting an account immediately removes the person's access and membership and starts deletion of the authentication account and member-specific records. A household with no remaining member is deleted with its receipts, pantry, lists, and other content. A household with another member remains, along with its shared receipts, purchase history, pantry, lists, recipes, plans, budgets, and goals. The in-app deletion preview identifies which result applies. Before leaving, a member may delete content that the Service allows that member to delete. A privacy request may require additional review where information relates to more than one household member.
How long deletion takes. You can delete an account from inside the app. Access ends immediately. We complete deletion from active systems within 30 days of the request and, where a processor holds a copy, instruct that processor within the same period. If we cannot complete a request in 30 days we will tell you why and give a date.
Deletion from active systems may not immediately remove isolated backup copies. Backups are access-restricted, not used in the ordinary course, and overwritten under provider backup cycles. If a backup is restored, deletion requests are reapplied.
11. Your rights and choices
Wherever you live in the United States, you may ask us to:
- confirm whether we process information about you and provide access;
- provide a portable copy;
- correct inaccurate information;
- delete information, subject to lawful exceptions and the rights of other household members;
- withdraw consent for future consumer-health-data processing;
- identify categories of recipients and, where required, specific third parties;
- opt out of sale, targeted advertising, or qualifying profiling (we do none); and
- appeal a denial.
You may also edit or delete many entries in the app, leave a household, and initiate account deletion in the app.
Submit a request from the email associated with your account to [PRIVACY EMAIL]. We will verify the request using information already associated with the account and will not ask for unnecessary sensitive information. An authorized agent may submit a request with proof of authority. We ordinarily respond within 45 days and may extend once where permitted, with notice. We do not discriminate against anyone for exercising a privacy right.
If we deny a request, reply with “Privacy Appeal.” We will review the appeal and provide a written decision within the period required by applicable law, including information about contacting the appropriate regulator when required.
12. Device permissions
HomeBasket asks for a permission only at the moment a feature needs it, never on first launch, and the app remains usable if you decline.
| Permission | What it is for | If you decline |
|---|---|---|
| Camera | Photographing a grocery receipt and scanning a product barcode | You can still add items by hand or pick an existing photo |
| Photo library | Choosing a receipt photo you already took | You can still use the camera or add items by hand |
| Notifications | Reminders you turn on, such as food about to expire | The app works; you receive no reminders |
| Alarms and start-at-boot (Android) | Delivering a scheduled reminder at the right time, and restoring your schedule after a restart | Reminders may arrive late or stop after a restart |
We choose a single photo you select or capture. We do not read your photo library, and we do not ask for GPS or precise location, the microphone, contacts, or the calendar.
Reminders are produced on your device. HomeBasket schedules them locally. There is no push-notification token, and no reminder or its content is sent to us or to a third party.
13. App store disclosures
App stores require a summary of the data an app collects. This section states ours so the store listing and this policy say the same thing. "Linked" means the data is associated with your account. "Tracking" has the meaning the app stores give it: following you across other companies' apps or websites.
| Category | Examples | Purpose | Linked | Tracking |
|---|---|---|---|---|
| Contact information | Name, email address | Account and household membership | Yes | No |
| User content | Receipt images, pantry items, shopping lists, saved and imported recipes, meal plans, notes you write | Core features | Yes | No |
| Purchases | Retailer, date, items, prices and totals read from your receipts; budgets you set | Pantry, spending and budget features | Yes | No |
| Sensitive information | Eating pattern, foods to leave out, wellness goals, calorie target — see Section 3 | Filtering and ranking food suggestions | Yes | No |
| Identifiers | Account identifier, household identifier | Sign-in and keeping a household's data separate | Yes | No |
| Diagnostics and usage | IP address and the approximate region inferred from it, app or browser version, request identifier, endpoint, timing, status, and error — kept as server logs, described in Section 2 | Reliability, security, and abuse prevention | Yes | No |
We use no third-party crash-reporting or performance software development kit; the diagnostics above are our own server logs.
We do not collect precise location, contacts, browsing history, biometrics, health or fitness data, payment card numbers, or advertising identifiers.
We do not track you. HomeBasket does not follow you across other companies' apps or websites, does not use an advertising identifier, and takes part in no advertising network or data-broker arrangement. Because we do not track, the app presents no tracking-permission prompt.
We use no third-party analytics, crash-reporting, or advertising software development kit. We keep operational server logs to run and secure the service, described in Section 2.
14. Children
The Service is for adults age 18 and older. We do not knowingly allow a person under 18 to create an account or use the Service. An adult may enter limited household information relating to a minor only if the adult has legal authority and provides any notice and consent required by law. Do not enter a minor's diagnosis, medication, symptom, clinical note, or allergy severity. Contact support@homebasket.io if you believe a minor has provided information directly.
15. California notice
During the preceding 12 months, we collected the categories described in Section 2 from the sources in Section 4, used them for the purposes in Section 5, and disclosed them to the categories in Section 7. We did not sell personal information or share it for cross-context behavioral advertising, including personal information we know relates to anyone under 16.
We use sensitive personal information only to provide requested features, secure the Service, and for other purposes permitted without a right to limit under California law. We do not use it to infer characteristics for advertising.
California residents may exercise the rights in Section 11. Under California's “Shine the Light” law, you may ask about disclosure for third parties' own direct marketing; we make no such disclosures. A registered California user under 18 may request removal of content posted while under 18, although the Service does not permit under-18 accounts.
16. Nevada notice
Nevada residents may direct an operator not to make a covered sale of certain information. We do not make covered sales. Submit a request to support@homebasket.io with “Nevada Privacy Request” in the subject. We do not collect Nevada consumer health data; see Section 3.
17. Changes to this policy
We will post an updated policy with a new effective date. If a change materially expands collection, use, or disclosure, we will provide notice before the change takes effect and obtain consent where required. We will not apply a materially different use retroactively without a lawful basis and required consent.
18. Accessibility
If you use assistive technology and need this policy in another format, contact support@homebasket.io.
19. Where we operate
HomeBasket is offered only in the United States. Data is processed in the United States and may be processed in another country where an identified processor operates, subject to its contract with us. The Service is not offered to people in the European Economic Area, United Kingdom, or Switzerland.
20. Contact
[LEGAL ENTITY]<br> [POSTAL ADDRESS]<br> support@homebasket.io
