Privacy Policy for Guarda

Last updated: August 28, 2026

This Privacy Policy explains how Guarda ("Guarda," "we," "us," or "our") collects, uses, shares, and protects information when you use the Guarda mobile application (the "App"). Guarda is operated by Emiliano Torres.

We've tried to write this in plain language. Where a section gets technical, look for the In plain terms notes.

If you do not agree with this policy, please do not use the App.

1. A quick summary

The rest of this document is the detailed version.

2. Who is responsible for your data

The party responsible for your personal data (the "data controller" under laws like the GDPR) is:

Emiliano Torres
Contact: guardabudget@gmail.com

If you have any question about this policy or your data, email us at the address above.

3. Information we collect

We collect the following categories of information.

3.1 Information you give us directly

3.2 Information created as you use the App

3.3 Camera and photos

The App uses your device camera, and can use photos you choose from your photo library, for three separate features. What happens to the image depends on which one you use:

In plain terms Barcode scans stay on your phone. Receipt photos, meal photos, and photos you attach to the AI assistant are sent to us and on to OpenAI, because that is the only way those features can work.

For the features that upload an image: we process the photo to produce the result and we do not save the image to our servers or our database — it is held in memory for the length of the request and discarded. We do not use your photos to train any model. OpenAI's handling of the image is described in Section 9.

The App requests camera access only when you open a feature that needs it, and reads a photo from your library only when you pick that specific photo yourself. The App never browses or scans your photo library.

3.4 Approximate location (via ZIP/postal code)

The App does not request or access your device's GPS or precise location. To find nearby stores and local prices, you type in a ZIP/postal code, which we send to our store-data provider (Kroger). This gives an approximate, city-level location only.

3.5 Device and technical information

3.6 Payment and subscription information

Guarda offers an optional paid subscription ("Pro"). Payments are processed by Apple through the App Store — we never receive or store your credit card or payment details.

We work with a subscription-management provider (RevenueCat) to know whether your subscription is active. For this, your in-app account identifier and subscription lifecycle events (purchase, renewal, cancellation, expiration) are processed. We store a record of your entitlement status (whether you have Pro, the product, and the expiry date).

3.7 What we do NOT collect

For clarity, Guarda does not:

4. Where your data lives: your device vs. our cloud

Guarda keeps some data only on your device and syncs other data to our cloud so it follows your account across devices. In plain terms:

Synced to our cloud (Supabase), tied to your account:

Stored only on your device (not uploaded to our servers):

Sent to a third party only when you use the specific feature (covered in Section 9):

When you sign out, the App clears its local cache of your synced data from the device.

5. How we use your information

We use the information described above to:

6. Legal bases for processing (for users in the EEA/UK)

If you are in the European Economic Area or the United Kingdom, we rely on the following legal bases under the GDPR/UK GDPR:

7. We do not sell or "share" your personal information

Guarda does not sell your personal information, and does not "share" it for cross-context behavioral advertising, as those terms are defined under the California Consumer Privacy Act (CCPA/CPRA) and similar U.S. state laws. We have not done so in the past 12 months. We also do not use your information for targeted advertising.

8. Sharing lists with other Guarda users

The App lets you send one of your grocery lists to another Guarda user. This is something you choose to do, on a list-by-list basis. When you use it:

Only send lists to people you trust with the information they contain.

9. Service providers we share information with

We rely on a small number of trusted third-party providers ("sub-processors") to operate specific features. We share only the information each needs for its function. Each provider has its own privacy policy governing how it handles data.

ProviderWhat it does for GuardaInformation it processes
SupabaseAccount authentication and cloud database/hostingYour email, hashed password, and the account data we sync (lists, budget, favorites, store, entitlement status, shared lists)
OpenAIPowers the in-app AI assistant, receipt scanning, and meal-photo calorie estimatesThe prompts you submit, plus contextual figures such as your budget, total spent, list counts, and recent shopping trips (amounts and dates) needed to answer your request; and any photo you take or attach for receipt scanning, meal estimation, or an assistant message (see Section 3.3)
KrogerStore lookup, product search, prices, and (if you choose) adding items to a Kroger cartYour ZIP/postal code, search terms, product barcodes/UPCs, and — only if you start a Kroger cart checkout — the items and quantities in that list
RevenueCatSubscription managementYour in-app account identifier and subscription lifecycle events
Apple (App Store)Processes subscription paymentsYour payment details are handled directly by Apple under Apple's privacy policy; we do not receive them
USDA FoodData CentralNutrition facts lookupsFood names you look up (no personal account information)
Open Food FactsBarcode and ingredient lookupsProduct barcodes/codes (no personal account information)
Backend hosting providerRuns the Guarda server that brokers the above requestsActs as the secure intermediary for the data flows described above

We may also disclose information:

10. Data retention

11. How we protect your information

We take reasonable technical and organizational measures to protect your data, including:

No method of transmission or storage is 100% secure, and we cannot guarantee absolute security. If we become aware of a data breach affecting your personal information, we will notify you and the relevant authorities as required by law.

12. Your privacy rights

Depending on where you live, you may have some or all of the following rights regarding your personal information:

How to exercise them:

California residents (CCPA/CPRA): you have the rights described above, including the right to know the categories and specific pieces of personal information we collect, the right to delete, the right to correct, and the right to opt out of the sale or sharing of personal information. As stated in Section 7, we do not sell or share your personal information. You may also designate an authorized agent to make a request on your behalf.

EEA/UK residents: you have the right to lodge a complaint with your local data protection authority if you believe we have not handled your data lawfully.

13. International data transfers

We and our service providers may store and process your information in countries other than your own, including the United States. These countries may have data-protection laws that differ from those in your country. Where we transfer personal data out of the EEA or UK, we rely on appropriate safeguards (such as the European Commission's Standard Contractual Clauses) where required, or another lawful transfer mechanism. By using the App, you understand that your information may be transferred to and processed in these countries.

14. Children's privacy

Guarda is not directed to children. We do not knowingly collect personal information from children under 13 (or under 16 in jurisdictions where that is the relevant age, such as parts of the EEA). If you believe a child has provided us with personal information, contact us at guardabudget@gmail.com and we will delete it.

15. Third-party services and links

The App relies on the third-party services listed in Section 9, and may reference store or product information from them. Their handling of data is governed by their own privacy policies, not this one. We encourage you to review the privacy policies of:

We are not responsible for the privacy practices of third parties.

16. Changes to this policy

We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date at the top. If we make material changes, we will provide a more prominent notice (such as an in-app message). Your continued use of the App after an update means you accept the revised policy.

17. Governing law

This Privacy Policy is governed by the laws of the United States, without regard to its conflict-of-laws principles, except where applicable data-protection law provides otherwise for your benefit.

18. Contact us

If you have questions, requests, or concerns about this Privacy Policy or your personal information, contact:

Emiliano Torres
Email: guardabudget@gmail.com