Privacy Policy
Last updated: August 14, 2026
Privacy, in plain language
Your grocery data is for your household. We do not sell your receipts, pantry, shopping list, or Assistant conversations, and we do not send that grocery data to advertisers. This policy explains the information ShopIQ needs to run, the services that help us run it, and the choices you have.
Data we store
- Receipt contents and photos you scan: stores, items, prices, discounts, and dates.
- Your pantry inventory and shopping list activity derived from them.
- Account details: your name, email address, and a hashed password.
- An approximate location — country and city — derived from your IP address when you register or sign in, used to set your default currency and time zone. We never ask for device location and there is no permission prompt; both stay editable in Settings.
- If you subscribe to a paid plan: your plan, its status, and renewal dates. Card details are handled by our billing provider and never reach ShopIQ.
- Assistant messages, chat history, and the extraction details needed to review or fix a scan.
- Technical logs and product-usage data used to keep ShopIQ reliable and improve it.
- If you turn on notifications, the push subscription your browser issues (a delivery address and its encryption keys). It is used only to send you ShopIQ notifications and is discarded when your browser revokes it or you turn notifications off.
Who processes it
We use carefully selected service providers to operate ShopIQ: Supabase for the database and private receipt storage, Vercel for hosting, Google Gemini for the built-in Assistant, PostHog for product analytics, Resend for service email, and Lemon Squeezy for paid-plan billing. They process information only as needed to provide their part of the service.
Your household and your grocery data
Household members you invite can see the household's shared inventory, shopping list, receipts, and spending data. ShopIQ is designed to keep grocery data scoped to that household. Receipt photos live in private storage; we do not sell your grocery data or share it with advertisers or data brokers.
AI processing
The built-in Assistant sends the messages and images you choose to share to Google Gemini so it can answer you and read receipts. If you use ShopIQ through an external AI client (for example, ChatGPT or Claude), that client's handling of your conversation and receipt is also governed by its own terms and privacy policy.
Analysing a receipt in ChatGPT
You can have a receipt analysed in ChatGPT without a ShopIQ account. That analysis is arithmetic on the lines the AI client sends us. We store nothing. No account is created, no household exists, and we do not record who you are.
If — and only if — you press “Keep this receipt”, we store one copy of that receipt so you can save it to an account:
- What: the receipt lines (item names, quantities, prices), the store name, the purchase date and the printed total. Nothing else.
- Not stored: no name, no email, no account, no ChatGPT conversation, and nothing that identifies you. The copy is not linked to a person.
- How: encrypted (AES-256-GCM). It is unreadable without a key held separately from the database.
- How long: 72 hours. After that it can no longer be opened, and a daily job deletes it from our database.
- What happens if you do save it: the receipt moves into your household like any other receipt, and the temporary copy is closed to further use.
- Recipients: nobody. It is not shared, sold, or used to train anything, and it is not sent to any third party.
- Control: do nothing and it expires by itself. To have it removed sooner, email us and say roughly when and where you scanned it.
Notifications
If you allow them, ShopIQ sends notifications about your own household — items running low, food expiring soon. They are grouped into a single digest rather than sent one by one, they never contain marketing, and you can turn them off at any time in your browser or device settings.
Analytics and advertising measurement
We use PostHog (hosted in the European Union) to understand how the app is used: pages visited, features used, and session recordings of how the interface is navigated. All text you type into form fields — including passwords — is masked before a recording leaves your browser. Events are linked to your member id so we can tell one person's journey from another's; they are never linked to your receipts or pantry contents, and no grocery data is sold or shared with advertisers or data brokers. We also use Meta and Google advertising measurement on public pages to understand whether an ad led to a visit, lead, or registration. Those services may receive standard browser, device, and conversion-event information; they do not receive your receipts, pantry, shopping list, or Assistant conversations.
Cookies and local storage
ShopIQ uses essential cookies to keep you signed in and remember choices such as language and theme. Analytics and advertising providers may also use their own cookies or similar technologies. You can manage or clear non-essential browser data in your browser settings; clearing essential data may sign you out or reset preferences.
Your control
- You can delete any receipt at any time; its inventory effects are removed with it.
- The household owner can export the household's data (Settings → Account).
- The household owner can delete the entire household — every receipt, item and member — from Settings → Account. You are offered an export first, and the deletion is permanent.
- A household owner can remove any other member, which deletes that member's access and personal sign-in details.
- How to delete your account — every route, including by email if you cannot sign in.
Retention and requests
We keep household data while the household exists, unless it is deleted sooner. Some limited information may need to remain for security, fraud prevention, billing, or legal obligations. For access, correction, export, deletion, or another privacy request, contact us using the details below.
Contact
Questions, privacy requests, or support: support@goshopiq.com. You can also use the in-app Feedback page, or contact the household owner who invited you.