Privacy Policy

Last updated: July 2026

Who we are

UrCartBuddy is operated by Binary Components Limited, a company registered in England and Wales (company number 05837146), registered office 79 Goldhawk Road, London, W12 8EG (privacy@urcartbuddy.com). Binary Components Limited is the data controller for personal data processed through this service.

What data we collect and why

Account data

When you sign in with Google or Facebook we receive your name, email address, and profile picture. If you register with an email address and password instead, we store your email address and a securely hashed password — your password is never stored in plain text. We store these to identify your account and personalise your experience. Your account creation date, current subscription tier, and interface preferences such as whether help tips are shown, which help tips you have dismissed, and whether you wish to receive WhatsApp or Telegram notifications when collaborators check off items you added, are also stored. We also record the date and time you last used the app on the web or messaged our WhatsApp or Telegram bot, so we can maintain the service and understand overall usage.

Shopping lists and items

We store the lists, items, tags, and categories you create. Each item records who added it, who checked it off, and when — so collaborators can see activity on shared lists. Items may also store an optional description — free-text notes, substitution preferences, or sizes — that you enter manually. Items created from image imports may also store package weight and QR/barcode metadata when detected, so richer item viewing and editing can be supported later. Lists may also store an optional source URL and title, such as the original recipe page used to create a recipe shopping list, and per-list field display preferences (which optional item fields such as Brand and Weight are visible on that list).

Item attachments

You can attach files (photos, PDFs, receipts, or any other format) to items from the web app, or by sending a document or photo to our WhatsApp or Telegram bot. Attached files are stored on Cloudflare R2 object storage and are viewable by every member of the list the item belongs to. Files are subject to a per-user storage quota and a per-file size limit. When an item is archived, its attachments are scheduled for permanent deletion after a short grace period; deleting an attachment from an item removes it immediately.

When the "AI attachment titles" feature is enabled for a list (enabled by default), the contents of newly uploaded attachments up to 15 MB are sent to Google Vertex AI (Gemini) solely to generate a short descriptive title. File contents are not retained by us beyond the AI request. You can disable this at any time per list under List Settings → AI → AI attachment titles.

Collaboration data

When you share a list, we store the membership relationship (your user ID, the list, your role, and when you joined) so that collaborators can access the shared list.

First-party product analytics

To understand whether the service is useful, we record the UTC days on which an authenticated account meaningfully uses the web app, WhatsApp bot, or Telegram bot, and a small fixed set of home-screen install prompt outcomes. These records contain an internal user ID, date/time, channel, and fixed event name only. They do not contain shopping-list or item content, messages, contact details, IP addresses, location, referrers, or browser user-agent strings. We use no third-party analytics or advertising identifiers. Administrators see aggregate adoption and retention results, not individual behavioural timelines.

When you invite someone, we store the invited email address or phone number, the inviting account and list, delivery method and status, attempt timestamps, expiry, and a masked form for display to the list owner. Invitation links are single-use and expire after seven days. We store a cryptographic hash for lookup and a protected copy solely so the background delivery service can include the link in the invitation message; raw invitation tokens are not logged. Email invitations may be sent to people who do not yet have an account.

When you share a list to a phone number that doesn't yet belong to a UrCartBuddy account, we create a placeholder record for that number so the list can be accessed via WhatsApp. If the owner of that number later signs in with Google and adds the same phone in their Profile, the number is treated as unverified — and stored with a verification timestamp of "none" — until they send an inbound message to our WhatsApp bot from that number. That inbound message proves ownership, at which point we link the placeholder's list memberships and history to their signed-in account and remove the placeholder. We record the date and time of phone verification on the account.

If the access that placeholder record was created for is withdrawn instead — the owner removes it from the list, revokes the invitation, or the invitation expires unused — we remove the phone number and everything else in that record that identifies or can reach the person. A record that was never used for anything is deleted outright. If items or attachments it added are still on someone else's list (including items already archived into that list's purchase history), we cannot delete the record without deleting that person's list content along with it, so we reduce it to an unnamed marker instead: the phone number, the phone-derived name and any linked WhatsApp or Telegram identity are removed, those items show "Former member" as who added them, and the record can no longer be signed into, messaged, matched to a phone number, or reused if that number is invited again. Our records of what an AI request cost remain, with the phone number stripped out of them. The invitation's own audit record is retained with the list as described above and is unlinked from the anonymous marker. A daily background check applies the same treatment to any record the immediate cleanup did not reach.

WhatsApp and Telegram integrations (optional)

If you choose to link your WhatsApp number, we store it to route incoming messages to your account. If you connect Telegram, we store your Telegram user ID, chat ID, optional username, and display name so private bot messages can be routed to your account. List invite and Telegram connection QR links use short-lived tokens, and Telegram list invite links may create a minimal account for the invited Telegram user. Message content is processed to manage your lists and is not stored beyond what is needed to fulfil your request. For larger WhatsApp or Telegram imports, we may temporarily store a draft import session containing the proposed item names, quantities, detected package weight or code metadata, target list, and tags so you can review them through a secure magic link before saving. Treat this review link as sensitive: anyone who opens it can edit and save the draft into your own lists. Do not forward it. We also temporarily store the latest pending chat confirmation for your phone number or Telegram user ID so replies such as "yes", "no", or "tag with freezer" apply to the correct recent import. After a WhatsApp or Telegram item action or import is confirmed, we keep a short list of the item names just added for around two hours so follow-up replies such as "tag with freezer" or "delete it" apply to the correct items. If you have a phone number or Telegram account linked, you may also receive an automated WhatsApp or Telegram message when a collaborator on a shared list checks off and archives items you originally added. This is controlled by a per-account preference in your Profile and is on by default.

Recipe import (optional)

If you ask UrCartBuddy to find a recipe and import its ingredients, your recipe request is used to search the web, fetch a recipe page, and extract ingredients. We store the resulting shopping items, any recipe tag applied to them, and the source recipe URL/title when attached to an import or list, but we do not store a separate copy of the full recipe page.

Voice commands (optional)

When you choose to record a voice command, UrCartBuddy temporarily holds the audio in the app's private storage and uploads it to our service so an AI provider can transcribe the words and carry out your list request. Recording begins only after you tap the microphone action and grant microphone permission. The temporary on-device recording is deleted after it is sent, cancelled, or discarded. We do not retain a separate audio recording on our servers after the request. The transcript is used to process the command and may remain briefly in the in-memory conversation context used for follow-up requests; that context expires automatically. Transcripts are not normally written to server logs, but transcript logging can be enabled temporarily by an operator when diagnosing a voice incident.

Push notifications (optional)

If you enable browser push notifications, we store your browser's push subscription endpoint and associated encryption keys in order to send you real-time list updates.

If you use the Android app and allow notifications, we store the notification token that Google's Firebase Cloud Messaging service issues for that installation of the app, along with the platform name and when it was last seen. That token is an address for the device, not a means of identifying you personally, and it is used only to deliver updates about lists you are a member of. Notification content is limited to a short title and message plus the list's address; item details are not included. The token is removed when you turn notifications off, sign out on that device, delete your account, or when Firebase reports the installation no longer exists. Notification delivery is governed by Firebase's Privacy and Security information.

Archived items and service improvement

When items are archived, some may be flagged internally as candidates for improving our automatic item-sorting feature. No personal identifiers are used in this process — only the item name text.

AI usage metadata

When an AI feature is used, we store usage metadata linked to your account so we can measure service cost, monitor reliability, and prevent abuse. This includes the source feature, AI provider and model, specific AI interaction type, token counts, timing, success or error status, and related channel or list IDs where relevant. We do not store the prompt text, AI response text, recipe page text, images, or shopping item content in these usage records.

We also store a per-account monthly AI spend cap (an optional override and timestamps for when 90% and 98% warnings were shown each month) so we can enforce a per-user monthly limit and pause AI features when exceeded. See AI usage limits for details.

Subscription and billing

UrCartBuddy offers a free trial followed by a paid subscription. Current pricing is shown before you subscribe on the Billing page. Which company processes your payment depends on where you subscribe: purchases made on the website are processed by Stripe, and purchases made inside the Android app are processed by Google Play, as Google requires for purchases made in apps distributed through the Play Store. Whichever you use, the subscription applies to your whole account on every device.

We store a customer identifier and a subscription identifier from whichever processor you used, together with your subscription status and period dates, so we can tell whether your subscription is active. We do not store your card number or full payment details; those are held exclusively by the payment processor. For Google Play purchases, the identifier we send to Google is a one-way hash of your internal account ID rather than the ID itself, and we receive no payment details back. If you were referred by a partner, we store the referral attribution so the partner can be credited appropriately. Subscription status and period dates are retained until you delete your account.

Contact form

If you use the contact form, your name, email address, and message are sent to us by email. This information is not stored in our database.

Server logs

Our servers produce standard application logs (errors, warnings, key events such as sign-ins and account deletions). Logs are retained for up to 30 days and are used solely for diagnosing technical issues.

Legal basis for processing (UK GDPR)

  • Contract performance — processing your account data, lists, items, and integrations is necessary to provide the service you signed up for.
  • Consent — optional features such as WhatsApp, Telegram, and browser push notifications are only activated when you explicitly choose to enable them.
  • Legitimate interests — server logging and security monitoring are necessary to maintain a safe and reliable service.

Who we share data with

We do not sell your data or share it for advertising purposes. Data is shared only with:

  • Stripe — for payment processing when you subscribe on the website. We share your name, email address, and a unique customer identifier. Governed by Stripe's Privacy Policy.
  • Google Play — for payment processing when you subscribe inside the Android app, where Google is the seller of record. We send a one-way hash of your internal account ID so the purchase can be matched to your account; we do not send your name or email address. We receive back the subscription's status, expiry date, order identifier, and the country the purchase was made in. We receive no payment details. Governed by Google's Privacy Policy.
  • Google — for sign-in authentication only. Governed by Google's Privacy Policy.
  • Meta (Facebook) — for sign-in authentication and WhatsApp messaging (if enabled). Governed by Meta's Privacy Policy.
  • Telegram — for Telegram bot messaging and Telegram list invite links (if enabled). Governed by Telegram's Privacy Policy.
  • Google Firebase Cloud Messaging — delivers push notifications to the Android app, if you allow them. Only the device's notification token and the notification's short title, message, and target list address are sent. Governed by Firebase's Privacy and Security information.
  • Oracle Cloud Infrastructure — our hosting provider, where your data is stored on servers located in the United Kingdom or European Economic Area.
  • Cloudflare R2 — object storage for any files you attach to items. We do not scan or process the contents of these files; only the file itself, your user ID (in the storage key), and metadata such as filename, size, and content type are stored. Governed by Cloudflare's Privacy Policy.
  • Groq — for AI-assisted parsing of shopping items, recipe ingredient extraction, item sorting helpers, and voice transcription when configured. Only the text, image, or audio content needed to fulfil the request is sent; no account identifiers are intentionally included. Governed by Groq's Privacy Policy.
  • Google Gemini (via Vertex AI or Google AI Studio) — used for the chat agent loop, AI-assisted item parsing, attachment title generation (when enabled per list), and voice transcription when configured. Only the text, image, file, or audio content needed to fulfil the request is sent; no account identifiers are intentionally included. Governed by Google's Privacy Policy.
  • Open Food Facts — when a product barcode is detected in an AI, WhatsApp, or Telegram image import, the barcode may be sent to Open Food Facts to look up a product name and package quantity. Governed by Open Food Facts' Privacy Policy.
  • SearXNG and third-party recipe websites — if you use recipe import, your recipe query is sent through our self-hosted SearXNG instance and the selected recipe page is fetched from the relevant website so ingredients can be extracted.
  • Collaborators you invite — users you share a list with can see the list contents and the names of other members.

Data retention

  • Your account and all your data are retained until you delete your account.
  • Items on shared lists are retained until the list owner deletes them.
  • Attachments are retained for the lifetime of the item they belong to. When an item is archived, its attachments are scheduled for permanent deletion after a short grace period. Deleting an attachment from an item removes it immediately.
  • Draft import review sessions expire automatically and are no longer usable after they are saved, cancelled, or expired.
  • Pending WhatsApp and Telegram confirmations are short-lived and are completed, cancelled, superseded, or expired automatically.
  • Recent WhatsApp and Telegram item context used for follow-up tagging or removal is only used for short-lived chat context and is cleaned up automatically.
  • Voice recordings are processed for the requested command and are not retained as separate server files after that request. Temporary recordings in the app's private storage are deleted after sending, cancelling, or discarding.
  • Photos you send to the assistant from the Android app are copied into the app's private storage only for the length of that request and deleted afterwards. If the app is interrupted mid-capture, the copy is deleted the next time the app starts.
  • The Android app's on-device copies — the offline cache of your lists, any data export you have generated but not yet shared, an invitation link waiting to be opened, and a note of which list you last had open so the app can reopen it — are removed when you sign out on that device or delete your account.
  • Android notification tokens are retained until you turn notifications off, sign out on that device, delete your account, or Firebase reports the installation is gone.
  • AI usage metadata is retained with your account until account deletion unless we introduce a shorter operational retention period.
  • Fixed-name product events are retained for no more than 13 months and daily meaningful-activity records for no more than 25 months. Both are removed on account deletion.
  • Telegram connection tokens expire after a short time; Telegram list invite tokens expire automatically and are single-use.
  • Email and phone list-invitation links expire after seven days and are single-use. Invitation audit/status records remain with the list until it or the inviting account is deleted.
  • A placeholder record created by sharing a list to a phone number loses its phone number when that access is withdrawn — removed from the list, revoked, or expired unused. The record is deleted outright unless items or attachments it added are still on someone else's list, in which case it is reduced to an unnamed "Former member" marker that keeps the attribution on those items without naming or identifying anyone. A daily check covers any the immediate cleanup did not reach.
  • Push notification subscriptions are removed when you disable notifications or delete your account.
  • Server logs are retained for up to 30 days.

Your rights

Under UK GDPR you have the right to:

  • Access — request a copy of the data we hold about you.
  • Portability — download all your data in machine-readable format from your profile page.
  • Rectification — ask us to correct inaccurate data.
  • Erasure — delete your account and all associated data at any time from your profile page, or by emailing us.
  • Restriction — ask us to restrict processing of your data in certain circumstances.
  • Object — object to processing based on legitimate interests.

To exercise any of these rights, email privacy@urcartbuddy.com. We will respond within 30 days.

Complaints

If you are unhappy with how we handle your data, you have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk. We would appreciate the chance to address your concern first — please contact us at privacy@urcartbuddy.com.

Cookies

UrCartBuddy does not use tracking or advertising cookies. We use browser localStorage solely to keep you signed in between sessions. No third-party cookies are set.

Children's privacy

UrCartBuddy is not intended for use by children under the age of 13. We do not knowingly collect personal data from children. If you believe we have inadvertently collected such data, please contact us at privacy@urcartbuddy.com and we will delete it promptly.

Changes to this policy

We may update this policy from time to time. Material changes will be notified via the app or by email. The date at the top of this page shows when it was last revised.

Contact

Data controller: Binary Components Limited (company number 05837146), 79 Goldhawk Road, London, W12 8EG, United Kingdom.
Email: privacy@urcartbuddy.com

version e55357a
An unhandled error has occurred. Reload 🗙