🛒 Grocent

Privacy Policy

Grocent is a shared household grocery list app. This policy explains exactly what information we collect, why we collect it, who it is shared with, and how you can access or delete it.

Effective 29 July 2026 Last updated 20 August 2026 Applies to iOS & Android App ID dev.systemk.grocent

Who we are

Grocent (“Grocent”, “the app”, “we”, “us”, “our”) is a mobile application published by SystemK, operating from the State of Qatar. SystemK is the data controller responsible for the personal information described in this policy.

Grocent helps a household keep one shared grocery list. A Household Owner creates a household and invites Contributors, who can request items, mark items as purchased, and maintain shared lists — depending on the permissions the Owner grants them.

This policy covers the Grocent mobile app on iOS and Android and the backend services that support it. It does not cover third-party services you reach from the app, such as the Apple App Store or Google Play, which have their own privacy policies.

By creating an account and using Grocent, you agree to the handling of information described here. If you do not agree, please do not use the app.

Privacy at a glance

The short version. Every point below is explained in full further down.

No advertising

Grocent contains no ads, no ad networks and no advertising identifiers.

No tracking or analytics

We embed no analytics, attribution or crash-reporting SDKs. We do not profile you.

We never sell data

We do not sell or rent personal information, and we do not share it for cross-context behavioural advertising.

No location or contacts

Grocent does not request location, contacts, microphone or calendar access.

No card details

Subscriptions are billed by Apple and Google. We never see your payment card.

Delete from inside the app

You can permanently delete your account and its data from the app's Profile screen.

The main thing to understand: Grocent is a shared app. Everything you add to a household — item names, notes, photos and your display name — is visible to every other member of that household. See Sharing inside a household.

Information we collect

3.1 Account information

Grocent has no password of its own. You sign in with Google, Facebook or Apple, and we receive a limited profile from the provider you choose:

DataSourceWhy we need it
Email address Google, Facebook or Apple Identifies your account, and is shown as a fallback label to household members if you have no display name.
Display name Google, Facebook or Apple So other household members can see who requested or purchased an item.
Account identifier (UID) Generated by Firebase Authentication The internal key that links you to your household and your content.

We do not receive your password from any provider, nor your friends or contacts list, your posts, or any other profile field. You can review and revoke Grocent's access at any time in your Google account settings, your Facebook app settings, or under Sign in with Apple in your Apple ID settings.

Two things specific to Sign in with Apple. Apple lets you hide your real address and issue Grocent a private relay address ending @privaterelay.appleid.com instead. That is a genuine, working address — we treat it exactly like any other and can still reach you.

Apple also provides your name only the very first time you sign in. We save it at that moment, because Apple will not give it to us again. If you would like to change it later, contact us — we can update it directly.

3.2 Profile and household settings

Stored against your account so the app works the way you left it:

  • Your role (Household Owner or Contributor) and any sub-permissions an Owner grants you, such as Requester, Purchaser, saved-lists access or custom-items access.
  • The household you currently belong to.
  • Your language preference (one of the twenty languages the app offers).
  • Your subscription state — see 3.5.

3.3 Household and list content

This is the content you and your household create. It is the substance of the app:

  • Household name, the list of member accounts, and the date the household was created.
  • Household settings chosen by an Owner, all optional: a country (see Regional disclosures for what it is used for), a currency for prices, the day of the month the household's spending month starts, a monthly budget figure, and whether Contributors may see prices.
  • Grocery items — name, optional description or note, category, quantity, unit, status (pending, approved, purchased), which member requested it, when it was created and, if it was purchased, when. An Owner may also record a price — the amount that line cost, in the household currency. Prices are entered by hand; the app does not look prices up anywhere or fetch them from any shop or website.
  • Custom items and custom categories defined by your household.
  • Saved lists — reusable named lists your household builds.
  • Frequently-bought aggregate — the item name, category, how many times it has been purchased and when it was last purchased. Capped at the 100 most relevant entries per household.
  • Purchase history — a per-day record of what the household bought: for each day, the items marked purchased that day (name, quantity, unit, any price, which member marked it, and when). This is what "spent this month" and the budget figure are calculated from. It is recorded whenever any member marks an item purchased; it can be viewed and deleted only by household Owners, whether or not Contributors are allowed to see individual prices.

Please avoid putting sensitive personal information — health details, financial details, government identifiers — into item names or notes. These fields are free text shared with your whole household, and they are not designed to hold that kind of data.

3.4 Photos you add to items

You may attach a photo to an item, either by taking one with the camera or choosing one from your photo library. Photos are handled as follows:

  • The image is resized and re-encoded on your device before it is uploaded. Re-encoding also strips the photo's location and camera metadata, so we never receive, read or store it.
  • It is uploaded over an encrypted connection to our image service, hosted by Cloudflare (see Service providers). Each upload is tied to your signed-in account and to your household, and the file is stored under a random identifier together with a record of which account uploaded it and which household it belongs to.
  • The resulting image address is saved with the item so other members of your household can see the photo. Photos are served from a content delivery network. They are not listed or searchable anywhere, and the address is unguessable — but anyone who has the exact address can open it. Please treat an image address like the photo itself and do not share it outside your household.
  • Through the app, any member of your household can replace or delete a photo attached to a shared custom item; people outside your household cannot. Deleting the item or the photo in the app deletes the stored file straight away. A copy may remain in the content network's cache for a short time afterwards before it expires.

Automated safety check. Before a photo is accepted, it is inspected by an automated AI content-safety system to confirm it is safe for work and contains no prohibited content (see the Acceptable use section of our Terms of Service). The analysis runs inside our infrastructure provider, Cloudflare — the image is never sent to any other party for this purpose, is judged before it is stored, and is not used to train any model.

  • If the photo passes, no record of the check is kept beyond ordinary service logs.
  • If the photo is refused, the image is discarded and never stored. You can save the item without a photo or choose a different one. If you believe a refusal was wrong, contact [email protected] — a person will look at it.
  • Review records. Where the system refuses a photo, or accepts one it could not classify with confidence, we keep a moderation record containing a brief machine-generated text description of the image, the category the system assigned, your account identifier, the IP address the upload came from, the time and, for an accepted photo, the image address, so that a person can review the decision and remove the photo if it should not be there. These records are not visible to any user, are used only to review the automated decision and to spot repeated abuse, and are deleted automatically after 180 days. Where the law requires it, a record may be disclosed to the competent authorities.
  • Uploading prohibited content is a breach of our Terms of Service and may lead to your account being restricted or disabled, as described there. Any such decision can be contested and will be reviewed by a person.

Beyond this safety check we do not analyse or run image recognition on your photos.

3.5 Subscription and purchase information

Grocent offers optional paid tiers (Pro and Ultra). Purchases are processed entirely by Apple or Google — we never receive or store your card number, billing address or any payment credential.

Subscriptions are managed for us by RevenueCat, a specialist subscription-management provider. When you subscribe, the store's purchase record is passed to RevenueCat, which verifies it directly with Apple or Google and tells us the result. RevenueCat receives a pseudonymous subscription identifier — derived from your email address, but not the address itself — together with the purchase and transaction details, and standard technical data such as your device type and IP address. It does not receive your email address, your name, your grocery lists, your photos or your household. Because the identifier is derived from your email, a subscription can be recognised again if you delete your account and later sign up with the same address; the identifier alone does not reveal the address.

We then record against your account:

  • subscription status (free, active, expired or cancelled);
  • tier (Pro or Ultra) and billing period (monthly or yearly);
  • the store product identifier and platform (iOS or Android);
  • the expiry date, and when the record was last updated.

Apple and Google notify RevenueCat when a subscription renews, lapses or is cancelled, and that flows through to us, so your entitlement stays correct without you doing anything.

A paid plan is bought by the person who created the household and applies to that household. If they leave, the plan leaves with them and the household returns to the free tier.

3.6 Information stored only on your device

The following never leaves your phone and is removed when you uninstall the app:

  • A bundled catalogue of common grocery products, shipped inside the app and used to power search and suggestions. It is read-only reference data and contains nothing about you. Searches against it happen entirely offline — your search terms are never sent to us.
  • A cache of images already displayed to you, so lists load quickly and use less mobile data.
  • Small local preferences, such as your chosen language and a short queue of purchase-count updates made while you were offline, which are sent once connectivity returns.

3.7 Technical information

Our providers process limited technical data as a normal part of delivering the service — for example, the IP address a request came from, timestamps, and the type of device or app version. This is used for security, abuse prevention, rate limiting and diagnosing faults. We do not use it to build a profile of you and we do not combine it with your list content for any other purpose.

What we do not collect

To be unambiguous, Grocent does not collect, request or process any of the following:

  • Precise or approximate location data.
  • Your contacts, call logs, SMS messages, calendar or files outside images you explicitly pick.
  • Microphone audio or health, fitness or biometric data.
  • Advertising identifiers (IDFA / GAID). The app contains no advertising or attribution SDK. To be precise about one thing: the "Log in with Facebook" option uses Meta's Login SDK, which is built by the same company as Meta's advertising tools and, left at its defaults, would report app-open events and the advertising identifier to Meta. We have switched both of those off in the app's configuration, we do not request the advertising-ID permission on Android, and our release process includes an automated check that fails the build if either setting is ever re-enabled. The Facebook SDK therefore does nothing until you choose to sign in with Facebook, and then only what sign-in requires (see Service providers).
  • Analytics or behavioural telemetry. No Firebase Analytics, no Crashlytics, no third-party analytics or crash-reporting library is present in the app. Nothing records which screens you open, what you search for, or how you use the app. The one exception is narrow and worth naming: our subscription provider necessarily records purchase events — a subscription starting, renewing or ending — because that is how your plan is tracked at all.
  • Payment card or bank details.
  • Any special-category data — racial or ethnic origin, political opinions, religious beliefs, trade-union membership, genetic or biometric data, health, or sexual orientation.

We also do not sell personal information, do not rent or trade it, and do not share it with third parties for their own marketing or for cross-context behavioural advertising.

Device permissions

Grocent asks for the minimum permissions it needs, and only at the moment the matching feature is used. You can decline any of them and keep using the rest of the app.

PermissionUsed forIf you decline
Camera Scanning the QR code that joins a household or adds a member, and taking a photo of an item. You can still join a household by typing the code by hand, and still pick photos from your library.
Photo library Choosing an existing picture to attach to an item. Read-only: the app never saves anything to your library. Items simply have no photo. Everything else works.
Storage (older Android only) On Android 12 and earlier, reading the picture you pick needs the legacy storage-read permission (and, on Android 9 and earlier, storage-write for the camera's temporary file). Newer Android versions use the system photo picker, which needs no permission at all. The app never browses or indexes your files. Items simply have no photo. Everything else works.
Network access Syncing your household's list across members' devices. Required — the app is a shared, synced list.

The camera is used only while a scanning or photo screen is open. Grocent never records video or audio, never accesses the camera in the background, and only ever reads the specific images you select.

How we use information

We use the information described above only to:

  • Run the service — authenticate you, keep your household's list in sync across members' devices, and display who requested or purchased what.
  • Provide the features you use — saved lists, custom items and categories, frequently-bought suggestions, item photos and QR-based joining.
  • Apply your plan — verify subscription receipts and enforce the correct tier limits for your household.
  • Keep the service safe — enforce security rules, rate-limit uploads, and detect abuse or fraudulent purchases.
  • Keep content safe — run the automated AI safety check on uploaded photos described in section 3.4, and act on violations.
  • Support you — respond when you contact us for help or exercise a privacy right.
  • Meet legal obligations — comply with applicable law and respond to lawful requests.

We do not use your information for advertising or to train machine-learning models. The only automated processing of this kind is the image safety check in section 3.4, which may refuse a photo and, for prohibited content, may lead to restrictions on your account; you can always contest such a decision and have it reviewed by a person via [email protected].

Sharing inside a household

Grocent is built for shared use. Please read this section carefully — it is the most important part of this policy for most people.

When you are a member of a household, every other member of that household can see:

  • your display name (or, if you have none, the first part of your email address);
  • every item you add, including its name, notes, quantity and photo;
  • which items you requested and which you marked as purchased;
  • the household's saved lists, custom items, custom categories and purchase history.

Additionally, the Household Owner can:

  • change your role and permissions within the household;
  • remove you from the household;
  • delete the household entirely, which deletes its shared list, saved lists and purchase history for everyone.

Joining a household by QR code

Households are joined by scanning a QR code — either an Owner scanning your account code, or you scanning the household's join code (shown only to Owners, who can replace it at any time). Anyone who has your account code can invite you to their household, and anyone with the current join code can join that household until an Owner replaces it. Treat these codes like an invitation link: only share them with people you intend to share your list with.

Leaving a household

You can leave a household at any time. Content you already added remains with the household, because it belongs to the shared list the others continue to use. If you were the last member to leave, the household and all of its content is deleted. If you were the Owner and other members remain, ownership is transferred to a remaining member so the household keeps working.

Outside your household

Your list content is not visible to other Grocent users outside your household. Access is enforced by server-side security rules, not merely hidden in the app.

Service providers

We use a small number of established providers to run Grocent. They process data on our instructions and are not permitted to use it for their own purposes.

ProviderRoleData involved
Google — Firebase
Authentication, Firestore
Account sign-in, and storage and sync of your household's data. Account identifier, email, display name, all household and list content, subscription state.
Google — Sign-In Authenticating you if you choose Google sign-in. Email, display name.
Meta — Facebook Login Authenticating you if you choose Facebook sign-in. Name, email.
Apple
Sign in with Apple
Authenticating you if you choose Apple sign-in. Name (first sign-in only) and email, which may be a private relay address.
RevenueCat
Subscription management
Verifying purchases with Apple and Google, and tracking renewals, cancellations and refunds. A pseudonymous subscription identifier (derived from your email — not the email itself), purchase and transaction data, device and request metadata such as IP address. No email, name, list content, photos or household data.
Cloudflare
Hosting, storage, content delivery, AI inference
Storing and delivering item photos; running the automated photo safety check inside Cloudflare's infrastructure; relaying subscription status updates to our database. The image files you upload, plus the uploading account and household identifiers, subscription status, and request metadata such as IP address (kept in Cloudflare's request logs for a short period for security and diagnostics).
Namecheap
Email hosting (support mailbox)
Hosting our support mailbox, which receives the messages you send us and our internal notifications, including the moderation review records described in section 3.4. Whatever you choose to email us, and the contents of moderation review records — never the image file itself.
Apple
App Store & In-App Purchase
Distributing the iOS app and processing subscription payments. Purchase and receipt data. Apple acts as an independent controller under its own privacy policy.
Google
Google Play & Play Billing
Distributing the Android app and processing subscription payments. Purchase and token data. Google acts as an independent controller under its own privacy policy.

We may also disclose information where we are legally required to, specifically to:

  • comply with a valid legal obligation, court order or lawful request from a public authority;
  • enforce our Terms of Service, or investigate suspected fraud or abuse;
  • protect the rights, safety or property of our users, the public or SystemK.

If SystemK is ever involved in a merger, acquisition or sale of assets, personal information may be transferred as part of that transaction. We will notify you in the app or by email before your information becomes subject to a materially different privacy policy.

International transfers

Grocent is operated from Qatar, and our providers operate globally. Your information may therefore be stored and processed in countries other than your own, including the United States and the European Union, whose data-protection laws may differ from those where you live.

Where personal information is transferred out of the EEA, the UK or another jurisdiction with transfer restrictions, we rely on appropriate safeguards — principally the European Commission's Standard Contractual Clauses and the equivalent UK addendum, which our providers incorporate into their data-processing terms. You may request further detail using the contact address below.

Data retention

We keep information only as long as it serves a purpose:

InformationRetention
Account profile (email, display name, role, language)Until you delete your account, after which it is removed.
Grocery items, saved lists, custom items and categoriesUntil deleted by a household member, or until the household itself is deleted.
Frequently-bought aggregateAutomatically limited to the 100 most relevant entries per household; deleted with the household.
Purchase history (per-day record of what was bought, with prices)Until the household Owner deletes a day's record, or the household is deleted. Any household member's purchase is recorded; only Owners can view or delete the record.
Household settings (name, country, currency, spending month, budget)Until changed by an Owner, or the household is deleted.
Item photosDeleted from storage when the photo is replaced or removed, or when the household is deleted. A cached copy on the content network may persist briefly afterwards until it expires. Photos attached to shared custom items belong to the household, so a photo one member uploaded remains while the item exists even after that member leaves.
Household recordDeleted when its last member leaves or when the Owner deletes it.
Photo moderation review recordsDeleted automatically 180 days after they are created. Copies held in our support mailbox are deleted on the same schedule.
Subscription record (pseudonymous)Retained for as long as needed to honour your entitlement and to meet tax, accounting and audit obligations. It contains no email or name — only the pseudonymous identifier, tier, status and dates — and is not removed by account deletion (see section 14). Apple and Google retain their own transaction records under their policies.
Security and operational logsShort retention periods set by our providers, typically measured in days to a small number of months.
On-device cache and preferencesUntil you clear the app's storage or uninstall the app.

Backups are cycled out on a rolling basis, so residual copies may persist for a short period after deletion before being overwritten.

Your rights and choices

Subject to your local law, you have the right to:

  • Access the personal information we hold about you, and receive a copy.
  • Correct information that is inaccurate or incomplete. Your name and email come from your sign-in provider — updating them there updates them in Grocent on your next sign-in.
  • Delete your account and personal information — see the next section, which you can do yourself in seconds.
  • Port your data by receiving it in a structured, commonly used, machine-readable format.
  • Object to or restrict processing based on our legitimate interests.
  • Withdraw consent for camera or photo access at any time in your device's system settings.
  • Complain to your local supervisory authority. We would appreciate the chance to resolve the matter first.

To exercise any of these, email [email protected] from the email address associated with your account. We respond within 30 days, and will tell you if we need longer because a request is complex. We do not charge a fee, and we will never discriminate against you for exercising a privacy right.

One practical limit worth stating plainly: content you contributed to a shared household — an item you added to a list others are still using — forms part of that household's shared record. We can remove your account and disassociate you from it, but we cannot unilaterally erase a shared list that other members still rely on. If you need household content removed, ask the Household Owner, or contact us and we will help.

Deleting your account

You can delete your Grocent account and its data from inside the app, without contacting us. The steps are below; our data deletion guide shows the same thing with pictures of each screen.

  1. Open Grocent and go to the Profile screen.
  2. Choose Delete account.
  3. Confirm your identity by signing in again with the same provider you originally used — a security step required before an account can be destroyed.
  4. Confirm the deletion.

What deletion removes

  • Your account profile — email, display name, role and language preference.
  • Your sign-in credentials with Grocent.
  • If you signed in with Apple, Grocent's Sign in with Apple token is revoked, so the app no longer appears under Sign in with Apple in your Apple ID settings.
  • Your membership of any household.
  • If you were the household's last remaining member: the household itself, its grocery list, its saved lists, its purchase history, its settings and its item photos.

What deletion does not remove

  • Shared household content, where other members remain — the list continues to exist for them, including any photos you attached to shared custom items and any purchases of yours in the household's purchase history. If you were the Owner, ownership passes to a remaining member.
  • The pseudonymous subscription record. Your subscription is tracked under a pseudonymous identifier derived from your email, not under your account, and that record is deliberately kept: it is what lets a paid plan survive a reinstall or an accidental deletion and be recognised again if you sign up with the same address, and it is needed for tax and accounting. It contains no email, name or list content — only that identifier, tier, status and dates. If you want it removed as well, email us and we will erase it once any legal retention period has passed.
  • Photo moderation review records, if any exist for your account, until they expire automatically after 180 days.
  • Records Apple or Google hold about your purchases, which are governed by their policies.
  • Information we must retain by law, such as transaction records kept for tax and accounting purposes.

Deleting your account does not cancel a paid subscription. Subscriptions are billed by Apple or Google and must be cancelled separately, in your App Store or Google Play account settings, or you will continue to be charged. Please cancel before deleting your account.

If you cannot access the app — for example you have lost access to the Google, Facebook or Apple account you signed in with — email [email protected] and we will delete your account after verifying your identity.

Security

Measures we take to protect your information include:

  • Encryption in transit. All communication between the app and our services is encrypted (HTTPS/TLS).
  • Encryption at rest for stored data, provided by our infrastructure providers.
  • Server-side access rules. Access to your data is enforced on our servers, not just in the app: a household's content is available only to its members, settings and purchase history only to its Owners, and a paid plan is applied only once the store has confirmed the purchase.
  • Photo storage. Uploads and deletions require a signed-in account and are subject to rate limits and quotas. Photos are stored under unguessable addresses and are not listed or searchable anywhere; as section 3.4 explains, anyone who holds a photo's exact address can open it, so treat an address like the photo itself.
  • No password to lose. Because sign-in is delegated to Google, Facebook or Apple, Grocent never stores a password of yours.
  • Data minimisation. We collect only what the app's features require.

No system is perfectly secure, and we cannot guarantee absolute security. If we become aware of a breach affecting your personal information, we will notify you and the relevant authorities as required by applicable law and without undue delay. You can help by keeping the account you sign in with secure, and by sharing household QR codes only with people you trust.

If you believe you have found a security vulnerability in Grocent, please report it to [email protected] rather than disclosing it publicly. We welcome good-faith reports and will work with you on a fix.

Children's privacy

Grocent is a general-audience household utility. It is not directed to children, and we do not knowingly collect personal information from children under 13 — or under 16 where you are in the European Economic Area, the United Kingdom or another jurisdiction that sets a higher age.

Sign-in requires a Google, Facebook or Apple account, which carries its own minimum-age requirements.

If you believe a child has provided us with personal information, contact [email protected] and we will delete the account and its data promptly. Parents and guardians should note that a child added to a household will be visible to the other members of that household, as described in Sharing inside a household.

Regional disclosures

About the household "country" setting. A household Owner may, optionally, record the household's country in the app's settings. We use it for exactly two things: to suggest the matching currency for prices, and to help us apply the right regional rules below. It is a self-declared setting that we do not verify, we never derive it from your location or IP address (the app has no location access), and it does not change what data we collect or where it is stored. It can be left blank or cleared at any time. The disclosures below apply based on where you actually live, whatever the setting says.

Qatar

We process personal data in accordance with Law No. 13 of 2016 concerning Personal Data Privacy Protection and its implementing guidance. You have the right to be informed about the processing of your personal data, to object to processing, and to request access, correction, erasure or blocking. You may exercise these rights, or raise a concern with the competent authority, and we will assist you in doing so.

European Economic Area and United Kingdom

SystemK is the controller of your personal data. Our legal bases are set out in Legal bases, and the rights available to you in Your rights and choices. You may lodge a complaint with your national data protection authority — in the UK, the Information Commissioner's Office. We have not appointed an EU or UK representative on the basis that our processing is occasional, limited in scope and low risk; if that changes, this section will be updated.

California

In the past 12 months we have collected the categories of personal information described in Information we collect — principally identifiers (email, account identifier), your own user-generated content, and commercial information about your subscription.

We have not sold personal information, and have not shared it for cross-context behavioural advertising, in the past 12 months — and we do not do so now. We do not knowingly sell or share the personal information of consumers under 16. California residents may request to know, delete or correct their personal information, and may not be discriminated against for doing so. Requests go to [email protected].

Other jurisdictions

Wherever you are, we will honour any additional rights your local data-protection law grants you. Please write to us and we will apply them.

Changes to this policy

We may update this policy as the app develops or the law changes. The Last updated date at the top of this page always reflects the current version.

If we make a material change — for example, collecting a new category of information or using it for a genuinely new purpose — we will give you prominent notice in the app before it takes effect, and where the law requires it, we will ask for your consent. Continuing to use Grocent after a change takes effect means you accept the updated policy.

Contact us

For any question about this policy, to exercise a privacy right, or to report a concern, write to us — we read every message.

SystemK — publisher of Grocent
Email: [email protected]
Location: State of Qatar

Please include the email address associated with your Grocent account so we can locate it, and tell us what you would like us to do. We reply within 30 days.

See also the Grocent Terms of Service and our step-by-step guide to deleting your data.