Proposed update β€” not in effect. This proposal adds disclosures about the device-local Siri allowance, local data after sign-out, recipe retention, and account-deletion cleanup. It does not add a new advertising or voice-audio data collection practice. The previously published Privacy Policy remains available unchanged. Publishing this draft does not replace any required in-app or email notice. Any material changes will take effect only after the applicable notice process has been completed. Read the companion proposal.
Summary: FreshTrack stores inventory, saved recipes, and waste history on your device; Pro adds cloud sync through Firebase (Google). Firebase also provides account authentication and secure recipe-import processing. Recipe import may process text through Anthropic when needed. Apple handles Siri speech recognition, and FreshTrack does not receive the audio recording. Google AdMob supports the free tier, Apple and Google process subscriptions, and we do not sell your personal data.

1. Who We Are

FreshTrack is developed and operated by Bilal USLU ("we", "us", "our"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the FreshTrack mobile application (iOS and Android) and this website.

Contact: bilalmanisa@gmail.com

2. Data We Collect

We collect the minimum data necessary to provide the service.

CategoryExamplesSource
Account data Email address, display name, and profile photo URL when provided You provide via Google or Apple Sign-In
Household membership data Household identifier, membership role, join time, and account email address. When you join a household, other active household members may read the email stored with your membership. Your account and household actions
Inventory data Item names, quantities, expiry dates, storage area (fridge / freezer / pantry), notes You enter in the app
Siri & Shortcuts data (iOS) Inventory item names and storage locations made available to Apple's Siri and Shortcuts framework, plus the interpreted command, selected item, and quantity received when a voice action runs. FreshTrack does not receive microphone audio. The resulting inventory change may sync like an edit made in the app when Pro cloud sync is active. A local usage counter keyed by a one-way hash of your account ID tracks the free Siri sampler on this device. Your inventory and Apple's Siri / Shortcuts framework
Shopping list data Item names, quantities, checked state You enter in the app
Recipe data Recipe links; pasted or shared text; text recognized from selected screenshots; titles, ingredients, instructions, servings, source links, general notes, and ingredient-specific notes You provide or import in the app
Waste insights data Item-added, used, and wasted events, item names, categories, quantities, and timestamps Created from your inventory actions
Subscription data Store and product, subscription status and expiration, transaction or purchase identifiers and tokens, store environment, ownership linkage, and a one-way hashed FreshTrack account-binding identifier supplied to Google Play where applicable Apple App Store / Google Play validation and FreshTrack's server-side subscription records
Usage & diagnostics App events (item added, screen viewed), crash reports Firebase Analytics & Crashlytics, using pseudonymous app-instance or installation identifiers and diagnostic metadata
Ad identifiers Advertising ID (IDFA / GAID) used by AdMob for ads where permitted by your consent and device settings (free users only) Google AdMob SDK
Barcode lookups (Pro) When you scan a product, the barcode number is sent to the OpenFoodFacts database to look up its name and category. The camera image is processed on your device and never uploaded. You scan via the in-app camera (camera permission required)
Device info OS version, device model, language/locale Collected automatically by Firebase

We do not collect: payment card details, precise GPS location, contacts, raw barcode-camera images, selected recipe screenshot images, or Siri audio recordings. Selected recipe screenshots are read on your device; only their recognized text may be submitted for recipe extraction.

3. How We Use Your Data

  • Provide the service β€” store inventory, shopping, recipe notes, reminder preferences, and waste history locally; with Pro, sync account inventory, shopping, private recipes and notes across your devices, identify household members, and sync shared inventory, shopping, and waste history within a household.
  • Recipe import β€” retrieve a public recipe webpage or process recipe text you provide. Screenshots are converted to text on your device. When structured recipe data is unavailable, a limited portion of readable webpage text, or the pasted, shared, or screenshot-recognized text you provide, is sent to Anthropic to extract recipe fields.
  • Siri and Shortcuts (iOS) β€” make supported shortcuts discoverable, help Siri select the intended inventory item, receive the command information interpreted by Apple on your device, and apply the requested use or restock action through FreshTrack's normal access and safety checks. We do not send voice-command utterances, item names, or storage locations to FreshTrack analytics.
  • Free Siri allowance β€” keep a per-account usage counter on your device so ordinary sign-out does not restart the 5-command sampler. The account key is one-way hashed. This counter does not contain microphone audio, item names, or raw voice utterances, and is not sent to FreshTrack analytics.
  • Authentication β€” verify your identity via Firebase Authentication and Google or Apple Sign-In.
  • Subscription management β€” validate purchase receipts and grant or revoke Pro access.
  • Advertising β€” show banner and interstitial ads to free-tier users via Google AdMob. Pro subscribers see no ads.
  • Product improvement β€” aggregated or pseudonymous analytics and diagnostics to understand feature usage and fix bugs.
  • Legal compliance β€” retain records as required by applicable law.

We do not sell, rent, or trade your personal data to third parties for their own marketing purposes.

4. Third-Party Services

FreshTrack uses the following third-party services. Each has its own Privacy Policy.

ServicePurposePrivacy Policy
Firebase Authentication User sign-in (Google or Apple identity) firebase.google.com/support/privacy
Cloud Firestore Store & sync account, household, inventory, shopping, recipe, and waste-insight data firebase.google.com/support/privacy
Firebase Cloud Functions Server-side subscription validation, account and household operations, and secure recipe-import processing firebase.google.com/support/privacy
Firebase Analytics Pseudonymous usage analytics firebase.google.com/support/privacy
Firebase Crashlytics Crash reporting firebase.google.com/support/privacy
Google AdMob Advertising for free users policies.google.com/privacy
OpenFoodFacts Product name/category lookup for scanned barcodes (Pro) world.openfoodfacts.org/privacy
Anthropic Extract recipe fields from a limited portion of readable webpage text, or from pasted, shared, or screenshot-recognized text, when automatic structured-data extraction is unavailable anthropic.com/legal/privacy
Apple Siri and Shortcuts Speech recognition, shortcut discovery, command routing, and inventory-item selection for supported voice controls on iOS; FreshTrack receives interpreted command information, not the audio recording apple.com/legal/privacy
Apple App Store (StoreKit) In-app purchase & subscription (iOS) apple.com/legal/privacy
Google Play Billing In-app purchase & subscription (Android) policies.google.com/privacy

Firebase services process data on Google Cloud infrastructure. Google is certified under the EU–US Data Privacy Framework and provides GDPR-compliant Data Processing Agreements.

5. Data Retention

We retain your data for as long as your account is active. If you delete your account:

  • Your Firebase Authentication record and ordinary account-scoped Firestore data are deleted when the in-app deletion request completes, subject to the narrow safeguards below.
  • Saved recipes and their general and ingredient notes, import-usage records, entitlements, and your memberships are also deleted.
  • The free Siri sampler counter for the deleted account is removed locally as part of in-app account deletion. A completed in-app deletion also clears the app's local waste-insights cache on that installation. Ordinary sign-out preserves the counter and any free device-local data retained by the app; it is not an account-deletion request. Free inventory and unowned activity history are installation-scoped, so they may remain visible to someone who opens FreshTrack on the same device after sign-out and may be adopted into a later signed-in account's household if Pro cloud sync is enabled there; account-scoped saved recipes remain hidden. On both Free and Pro, signing out or switching accounts retains saved recipes and notes locally until you sign back into their owning account, including after Pro ends. Completed in-app account deletion removes the deleted account's local recipes and notes.
  • A household that has no other members is deleted. If other members remain, its shared inventory, shopping list, and waste history are retained for those members and ownership is transferred to one of them.
  • A completed account-deletion safety marker containing the deleted Firebase user ID and deletion timestamps is retained for up to 30 days. It prevents delayed sync or subscription processing from recreating deleted account data and allows safe cleanup retries.
  • For Google Play only, a released subscription-ownership record may retain the store type and one-way hashed purchase and FreshTrack account-binding identifiers after account deletion. It does not retain the deleted account's email, name, raw purchase token, or Firebase user ID. We retain it while the associated store purchase may need secure ownership validation or restoration.
  • Pseudonymous analytics and crash-diagnostic records may remain under our configured Firebase and service-provider retention schedules. Because these records use app-instance or installation identifiers rather than the active FreshTrack account record, account deletion may not remove them immediately.

Service-provider backups and security logs may remain for a limited period under the provider's standard retention schedule. You can request deletion at any time via the Delete Account page or by emailing us.

6. Children's Privacy (COPPA)

FreshTrack is not directed to children under 13 years of age. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us with personal information, please contact us at bilalmanisa@gmail.com and we will delete the information promptly.

7. Your Rights β€” GDPR / EEA

If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, you have the following rights under the General Data Protection Regulation (GDPR):

  • Right of access β€” request a copy of your personal data.
  • Right to rectification β€” correct inaccurate data.
  • Right to erasure ("right to be forgotten") β€” delete your account and associated data, subject to the limited security, legal, and service-provider retention described above.
  • Right to restriction β€” limit how we process your data.
  • Right to data portability β€” receive your data in a structured, machine-readable format.
  • Right to object β€” object to processing based on legitimate interest.
  • Right to withdraw consent β€” where processing is based on consent, you may withdraw at any time.

Our legal basis for processing is: contract performance (providing the service you signed up for), legitimate interest (analytics, security), and consent (personalised advertising). To exercise your rights, contact bilalmanisa@gmail.com. We will respond within 30 days.

8. Your Rights β€” CCPA / California

If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA):

  • Right to know β€” what personal information we collect, use, and disclose.
  • Right to delete β€” request deletion of personal information we have collected.
  • Right to opt out of sale or sharing β€” we do not sell personal information for money. Depending on your consent, device settings, and region, AdMob's processing for personalized advertising may be considered β€œsharing” for cross-context behavioral advertising under California law.
  • Right to non-discrimination β€” we will not discriminate against you for exercising your CCPA rights.

Where available, you can revisit ad consent from FreshTrack Settings β†’ Ad privacy options, use your device's privacy controls, or email bilalmanisa@gmail.com from the address associated with your account to submit a verifiable request.

9. Security

We implement the following security measures:

  • All data is transmitted over HTTPS / TLS.
  • Firebase Authentication manages credentials; we never store passwords.
  • Firestore Security Rules restrict account data to its owner and household data to active Pro household members.
  • Subscription entitlements are written server-side only (Firebase Cloud Functions), not by the client.
  • Firebase App Check signals, authentication, input limits, and server-side rate limits help protect backend APIs from abuse.

No transmission or storage method is 100% secure. If you discover a security vulnerability, please report it responsibly to bilalmanisa@gmail.com.

10. Changes to This Policy

We may update this Privacy Policy from time to time. The "Last updated" date at the top will reflect changes. For material changes, we will notify you via in-app notice or email at least 14 days before the new policy takes effect. Continued use of FreshTrack after the effective date constitutes acceptance of the updated policy.

11. Contact Us

For any privacy-related questions, requests, or complaints:

We aim to respond to all privacy inquiries within 5 business days and to complete data subject requests within 30 days.