Privacy Policy
Effective date: March 27, 2026
GrocerySync ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains what personal data we collect, why we collect it, how it is used and stored, and what rights you have regarding that data. It applies to all users of the GrocerySync application worldwide, with additional disclosures for residents of the European Economic Area ("EEA"), United Kingdom, and California.
1. Data Controller
The data controller responsible for your personal data is the operator of GrocerySync. Contact us at: support@grocerysync.online
For EEA/UK residents: if you have questions about how we handle your data under the General Data Protection Regulation (GDPR) or UK GDPR, please contact us at the address above.
2. Data We Collect and Why
GrocerySync is designed to process as little personal data as possible. The categories of data we handle are:
- App content you create: shopping lists, items, categories, recipes, and related content. This data is stored exclusively on your own device and, if you opt in, in your personal Google Drive account. We do not have access to this data. When Drive sync is enabled without passphrase encryption, the sync file is plaintext JSON — Google account holders with access to that file (and anyone it is shared with) can read your lists. Optional passphrase encryption is offered when you first enable Drive sync.
- Google account information (optional): if you sign in with Google to enable sync, we receive your Google account name and email address from Google's OAuth service. This is used solely to identify your sync session and is never stored on our servers.
- Device preferences: theme, notification, and display preferences stored locally on your device via the operating system's standard storage APIs.
We do not operate our own servers or backend infrastructure. We do not collect analytics, crash reports, usage statistics, advertising identifiers, or behavioral tracking data. Optional Google Sign-In / Drive sync is governed by Google's privacy policy (see Section 7).
3. Legal Basis for Processing (EEA/UK Users)
Under the GDPR and UK GDPR, we rely on the following legal bases:
- Performance of a contract (Art. 6(1)(b)): processing necessary to provide the app's core functionality — storing and syncing your grocery lists.
- Legitimate interests (Art. 6(1)(f)): improving app stability and preventing misuse, to the extent any processing occurs for those purposes.
4. How We Use Your Data
Your data is used only to:
- Operate the app — display, edit, and manage your grocery lists and recipes.
- Sync across devices — if you enable Google Drive sync, your app content is uploaded to and downloaded from your personal Google Drive account. Default storage is plaintext JSON in that Drive file unless you choose optional passphrase encryption at first enable (or later in Sync settings).
- Personalise your experience — remember your preferences between sessions.
We do not sell, rent, or trade your personal data to any third party. We do not use your grocery content for advertising or profiling.
5. Data Storage and International Transfers
Your grocery data is stored locally on your device and, optionally, in your own Google Drive account. We do not store your data on our own servers.
Default Drive sync stores a plaintext JSON file in your Drive. Anyone with access to that file through your Google account can read it. Optional end-to-end passphrase encryption protects the file contents at rest; encryption remains opt-in (default-on for all new users is deferred).
When you use Google Sign-In or Google Drive sync, your data is processed by Google LLC, which may store data on servers in the United States and other countries. Google's data transfers are governed by the EU–US Data Privacy Framework, Standard Contractual Clauses, and other approved transfer mechanisms. See Google's Privacy Policy at policies.google.com/privacy.
For EEA/UK users: by enabling Google sync, you acknowledge that your data may be transferred to and processed in the United States under Google's approved transfer safeguards.
6. Data Retention
Your grocery data is retained on your device until you delete it or uninstall the app. Synced data in Google Drive is retained until you delete it from your Google Drive account or revoke the app's access.
Authentication tokens for Google Sign-In are stored locally on your device and are cleared when you sign out.
7. Third-Party Services
GrocerySync integrates the following third-party services. Each has its own privacy policy which governs data collected by that service:
- Google Sign-In / Google Drive: optional account sign-in and cloud sync. Privacy policy: policies.google.com/privacy.
We do not integrate advertising SDKs, social networks, marketing platforms, or analytics SDKs. GrocerySync does not show ads and does not offer in-app purchases.
8. Your Rights
Depending on your location, you may have the following rights:
- Access: view all your data inside the app at any time.
- Rectification: edit any data directly within the app.
- Erasure ("right to be forgotten"): delete individual items, lists, or all data by uninstalling the app. To erase synced data, sign out and delete the GrocerySync file from your Google Drive.
- Data portability: export any list as text or as a .grocerysync JSON file using the Export feature.
- Restriction of processing / objection: because we do not process your grocery content on our own servers, restriction is exercised by simply not using or disabling specific features (e.g., disabling sync).
- Withdraw consent: if you enabled optional Google Sign-In / Drive sync, you may withdraw that consent at any time by signing out and revoking the app's access in your Google account settings.
EEA/UK residents may also lodge a complaint with their local data protection authority if they believe their rights have been violated.
California residents (CCPA/CPRA): you have the right to know what personal information we collect, the right to delete it, the right to opt out of the "sale" or "sharing" of personal information (we do not sell or share your personal information), and the right not to be discriminated against for exercising these rights. To exercise your rights, contact support@grocerysync.online.
9. Children's Privacy
GrocerySync is not directed to children under the age of 13 in the United States (under 16 in the EEA where required). We do not knowingly collect personal information from children. If we become aware that a child has provided personal information, we will take steps to delete it. If you believe a child has submitted personal information, contact us at support@grocerysync.online.
10. Security
We implement the following safeguards:
- On mobile (Android and iOS), list data is stored in the app's sandboxed private storage, which other apps cannot read on a stock device.
- On desktop (Windows, macOS, and Linux), list data is stored as local files under your operating-system user profile (application support). Protect access with a separate OS account per person on shared computers and with full-disk encryption (for example BitLocker, FileVault, or LUKS).
- The on-device list database/files are not encrypted by the app at rest. Optional client-side encryption, when offered, applies to Google Drive sync payloads — not automatically to every local file. See also our desktop/local threat model in the project security docs.
- All communication with Google services uses OAuth 2.0 and TLS/HTTPS encryption, implemented by Google's official client libraries.
- We never store your Google password. Authentication tokens are handled by platform Google Sign-In where available; on desktop, long-lived tokens are stored using the platform secure-storage mechanisms supported by the app build you install (not as your Google password).
No method of electronic transmission or storage is 100% secure. While we use commercially reasonable safeguards, we cannot guarantee absolute security. Rooted or jailbroken devices, malware running as your OS user, and unencrypted disk or profile backups can expose local data.
11. Export Compliance
GrocerySync is subject to United States export control laws and regulations, including the Export Administration Regulations (EAR) administered by the U.S. Department of Commerce Bureau of Industry and Security (BIS). By using the app, you represent that you are not located in, under the control of, or a national or resident of any country to which the United States has embargoed goods or services, and that you are not on the U.S. Treasury Department's list of Specially Designated Nationals or the U.S. Commerce Department's Denied Persons List or Entity List. The app may not be exported, re-exported, or transferred to any sanctioned country or person in violation of applicable U.S. law.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will update the "Effective date" at the top of this policy. For material changes, we will provide notice within the app where reasonably practicable. Your continued use of GrocerySync after the effective date of a revised policy constitutes your acceptance of the changes.
13. Contact Us
For privacy-related questions, requests to exercise your rights, or complaints, please contact:
Email: support@grocerysync.online
We will respond to verifiable requests within 30 days (or within the timeframe required by applicable law).