This Privacy Policy explains how Guarda ("Guarda," "we," "us," or "our") collects, uses, shares, and protects information when you use the Guarda mobile application (the "App"). Guarda is operated by Emiliano Torres.
We've tried to write this in plain language. Where a section gets technical, look for the In plain terms notes.
If you do not agree with this policy, please do not use the App.
1. A quick summary
What we collect: the email and password you use to create an account; the grocery lists, budgets, favorites, and store choices you create in the App; your subscription status; and, when you use certain features, the search terms, barcodes, and list contents needed to make those features work.
Why: to run the App — sync your data across devices, find prices, generate AI shopping lists, track nutrition, and manage your subscription.
Who we share it with: a small set of service providers that power specific features (Supabase, OpenAI, Kroger, RevenueCat, Apple, and a few nutrition data sources). We list every one of them below.
What we DON'T do: we do not sell your personal information, we do not show ads or use advertising trackers, we do not collect your precise GPS location, and we do not include any third-party analytics or crash-tracking SDKs.
Your control: you can delete your account — and the data tied to it — from inside the App at any time.
The rest of this document is the detailed version.
2. Who is responsible for your data
The party responsible for your personal data (the "data controller" under laws like the GDPR) is:
Emiliano Torres
Contact: guardabudget@gmail.com
If you have any question about this policy or your data, email us at the address above.
3. Information we collect
We collect the following categories of information.
3.1 Information you give us directly
Account information. When you create an account, we collect your email address and a password. Your password is handled by our authentication provider (Supabase) and is stored only as a securely hashed value — we never see or store your plaintext password.
Grocery lists and list contents. The lists you create, the names of items, quantities, custom items you type in (including any custom price you enter), and which items you've checked off.
Budget and store preferences. Your weekly budget amount, your selected store, your ZIP/postal code (used to find nearby stores — see Section 3.4), and whether you shop with a store loyalty card.
Body metrics for calorie goals (optional). If you turn on the App's nutrition/health features, you may enter information such as height, weight, age, and sex so the App can estimate a daily calorie target. This information is stored on your device and, while you are signed in, included in your account's cloud sync data so your calorie target can follow you across devices (see Section 4).
Messages to the AI assistant. The prompts and questions you type into the in-app AI assistant.
3.2 Information created as you use the App
Favorites. Products you star.
Shopping history. A record of completed shopping trips, including amounts spent and dates. It is stored on your device and included in your account's cloud sync data while you are signed in (see Section 4).
Food/nutrition diary (optional). If you use the nutrition features, the foods and portions you log. (Stored on your device — see Section 4.)
Lists shared with you. If another user shares a grocery list with you, we store that list and the sharer's email so it can appear in your "Shared" tab (see Section 8).
Feature-usage counters. Limited counts (for example, how many AI lists you've generated) used to enforce free-tier limits.
3.3 Camera and photos
The App uses your device camera, and can use photos you choose from your photo library, for three separate features. What happens to the image depends on which one you use:
Barcode scanning. The camera frame is processed entirely on your device to read the barcode. The image never leaves your phone. Only the decoded barcode number is sent to a product/nutrition lookup service (see Section 9).
Receipt scanning. If you photograph a receipt, the image is uploaded to our server and forwarded to OpenAI, which reads the line items and prices back so the App can log your trip.
Meal photos and AI assistant attachments. If you photograph a meal to estimate its calories, or attach a photo to a message in the AI assistant, that image is uploaded to our server and forwarded to OpenAI to generate the response.
In plain terms
Barcode scans stay on your phone. Receipt photos, meal photos, and photos you attach to the AI assistant are sent to us and on to OpenAI, because that is the only way those features can work.
For the features that upload an image: we process the photo to produce the result and we do not save the image to our servers or our database — it is held in memory for the length of the request and discarded. We do not use your photos to train any model. OpenAI's handling of the image is described in Section 9.
The App requests camera access only when you open a feature that needs it, and reads a photo from your library only when you pick that specific photo yourself. The App never browses or scans your photo library.
3.4 Approximate location (via ZIP/postal code)
The App does not request or access your device's GPS or precise location. To find nearby stores and local prices, you type in a ZIP/postal code, which we send to our store-data provider (Kroger). This gives an approximate, city-level location only.
3.5 Device and technical information
Session tokens. To keep you signed in, an authentication token is stored securely on your device (in the device keychain/secure storage on iOS).
3.6 Payment and subscription information
Guarda offers an optional paid subscription ("Pro"). Payments are processed by Apple through the App Store — we never receive or store your credit card or payment details.
We work with a subscription-management provider (RevenueCat) to know whether your subscription is active. For this, your in-app account identifier and subscription lifecycle events (purchase, renewal, cancellation, expiration) are processed. We store a record of your entitlement status (whether you have Pro, the product, and the expiry date).
3.7 What we do NOT collect
For clarity, Guarda does not:
collect your precise GPS location;
access your contacts, microphone, or calendar;
browse, scan, or read your photo library — the App receives only the individual photos you deliberately pick or take (see Section 3.3);
use advertising identifiers or serve you ads;
embed third-party analytics or crash-reporting SDKs (we currently include none);
track you across other apps or websites.
4. Where your data lives: your device vs. our cloud
Guarda keeps some data only on your device and syncs other data to our cloud so it follows your account across devices. In plain terms:
Synced to our cloud (Supabase), tied to your account:
your grocery lists and their contents,
your budget, selected store, and loyalty-card preference,
your favorites,
your subscription/entitlement status,
lists that have been shared with you,
limited free-tier usage counters,
your completed shopping-trip history, and
your optional body metrics/calorie profile.
Stored only on your device (not uploaded to our servers):
your nutrition/food diary.
Sent to a third party only when you use the specific feature (covered in Section 9):
AI assistant → OpenAI,
price/search/cart → Kroger,
nutrition lookups → USDA FoodData Central and Open Food Facts,
When you sign out, the App clears its local cache of your synced data from the device.
5. How we use your information
We use the information described above to:
Provide the core App: create and sync your lists, budgets, favorites, preferences, shopping history, and optional calorie profile across your devices.
Find prices and stores: look up stores by ZIP code and retrieve product prices and availability.
Power the AI assistant: generate shopping lists and answer questions. To make its suggestions relevant, the assistant's context may include figures such as your budget, your total spent, the number of lists you have, and a small number of your most recent shopping trips with their amounts and dates. (See Section 9 regarding OpenAI.)
Provide nutrition features: look up nutrition facts for foods and barcodes and let you keep a food diary.
Enable list sharing: deliver a list you send to another user, and show you lists others have shared with you (Section 8).
Manage subscriptions: determine whether you have an active Pro subscription and apply the right features and limits.
Send notifications you've enabled: price-drop alerts for products you're watching.
Maintain, secure, and improve the App: enforce fair-use limits, prevent abuse, debug problems, and keep the service running.
Comply with the law and enforce our terms.
6. Legal bases for processing (for users in the EEA/UK)
If you are in the European Economic Area or the United Kingdom, we rely on the following legal bases under the GDPR/UK GDPR:
Performance of a contract — to provide the App and the features you ask for (e.g., syncing your lists, running an AI request you submit, processing your subscription).
Consent — where required, such as enabling the device camera, choosing a photo to upload, or using optional health/nutrition features. You can withdraw consent at any time (e.g., by disabling the permission or feature).
Legitimate interests — to keep the service secure, prevent abuse, enforce free-tier limits, and operate and improve the App, balanced against your rights.
Legal obligation — where we must process data to comply with applicable law.
7. We do not sell or "share" your personal information
Guarda does not sell your personal information, and does not "share" it for cross-context behavioral advertising, as those terms are defined under the California Consumer Privacy Act (CCPA/CPRA) and similar U.S. state laws. We have not done so in the past 12 months. We also do not use your information for targeted advertising.
8. Sharing lists with other Guarda users
The App lets you send one of your grocery lists to another Guarda user. This is something you choose to do, on a list-by-list basis. When you use it:
You enter the email address of the person you want to send the list to. We use that email only to locate the recipient's Guarda account on our server; we do not reveal anything about whether other email addresses are registered beyond confirming we could or could not deliver to the one you entered.
The contents of the list you send (item names, quantities, and prices) and your account email become visible to that recipient, so they know who shared it.
A copy is stored so it can appear in the recipient's "Shared" tab.
Either of you can delete a shared list at any time from within the App. Deleting it removes that shared copy.
Only send lists to people you trust with the information they contain.
9. Service providers we share information with
We rely on a small number of trusted third-party providers ("sub-processors") to operate specific features. We share only the information each needs for its function. Each provider has its own privacy policy governing how it handles data.
Provider
What it does for Guarda
Information it processes
Supabase
Account authentication and cloud database/hosting
Your email, hashed password, and the account data we sync (lists, budget, favorites, store, entitlement status, shared lists)
OpenAI
Powers the in-app AI assistant, receipt scanning, and meal-photo calorie estimates
The prompts you submit, plus contextual figures such as your budget, total spent, list counts, and recent shopping trips (amounts and dates) needed to answer your request; and any photo you take or attach for receipt scanning, meal estimation, or an assistant message (see Section 3.3)
Kroger
Store lookup, product search, prices, and (if you choose) adding items to a Kroger cart
Your ZIP/postal code, search terms, product barcodes/UPCs, and — only if you start a Kroger cart checkout — the items and quantities in that list
RevenueCat
Subscription management
Your in-app account identifier and subscription lifecycle events
Apple (App Store)
Processes subscription payments
Your payment details are handled directly by Apple under Apple's privacy policy; we do not receive them
USDA FoodData Central
Nutrition facts lookups
Food names you look up (no personal account information)
Open Food Facts
Barcode and ingredient lookups
Product barcodes/codes (no personal account information)
Backend hosting provider
Runs the Guarda server that brokers the above requests
Acts as the secure intermediary for the data flows described above
We may also disclose information:
to comply with the law, a court order, or a valid legal request;
to protect rights and safety — to enforce our terms, prevent fraud or abuse, or protect the security of our users and the public;
in a business transfer — if Guarda is involved in a merger, acquisition, or sale of assets, in which case we will notify you of any change in how your data is handled.
10. Data retention
Account data (your email and the synced data tied to your account) is retained for as long as your account exists. When you delete your account (Section 12), this data is deleted from our authentication and database systems, and related rows are removed automatically.
Shared lists are retained until you or the recipient deletes them.
Photos you upload for receipt scanning, meal estimation, or AI assistant attachments are not retained — they are processed for the length of the request and discarded.
On-device data (your food/nutrition diary) remains on your device until you delete it in the App, sign out, or uninstall the App. Your shopping history and optional calorie profile are also part of your account's synced data while you are signed in, and are deleted from our active systems when you delete your account.
Backups. Our database provider may retain encrypted backups for a limited period (typically a short rolling window) for disaster recovery, after which they are overwritten.
Some limited records may be retained longer where necessary to comply with legal obligations, resolve disputes, or enforce our agreements.
11. How we protect your information
We take reasonable technical and organizational measures to protect your data, including:
Encryption in transit — connections between the App, our server, and our providers use TLS/HTTPS.
Hashed passwords — handled by our authentication provider; we never store plaintext passwords.
Row-Level Security — our database enforces access rules so that one user cannot read or write another user's data.
Secure on-device storage — your sign-in token is stored in the device's secure keychain.
Least-privilege server access — administrative keys that can bypass access controls are kept server-side and never shipped in the App.
No method of transmission or storage is 100% secure, and we cannot guarantee absolute security. If we become aware of a data breach affecting your personal information, we will notify you and the relevant authorities as required by law.
12. Your privacy rights
Depending on where you live, you may have some or all of the following rights regarding your personal information:
Access — request a copy of the personal information we hold about you.
Correction — ask us to correct inaccurate information.
Deletion — ask us to delete your personal information.
Portability — request your information in a portable format.
Restriction / objection — ask us to limit or stop certain processing.
Withdraw consent — where processing is based on consent (e.g., camera, notifications, health features).
Non-discrimination — we will not deny you service or charge you differently for exercising your rights.
How to exercise them:
Delete your account and data yourself, anytime: open the App's settings and choose Delete Account. This permanently deletes your account from our authentication system and removes the associated data.
For any other request, email us at guardabudget@gmail.com. We will respond within the timeframe required by applicable law (generally within 30–45 days). We may need to verify your identity before acting on a request.
California residents (CCPA/CPRA): you have the rights described above, including the right to know the categories and specific pieces of personal information we collect, the right to delete, the right to correct, and the right to opt out of the sale or sharing of personal information. As stated in Section 7, we do not sell or share your personal information. You may also designate an authorized agent to make a request on your behalf.
EEA/UK residents: you have the right to lodge a complaint with your local data protection authority if you believe we have not handled your data lawfully.
13. International data transfers
We and our service providers may store and process your information in countries other than your own, including the United States. These countries may have data-protection laws that differ from those in your country. Where we transfer personal data out of the EEA or UK, we rely on appropriate safeguards (such as the European Commission's Standard Contractual Clauses) where required, or another lawful transfer mechanism. By using the App, you understand that your information may be transferred to and processed in these countries.
14. Children's privacy
Guarda is not directed to children. We do not knowingly collect personal information from children under 13 (or under 16 in jurisdictions where that is the relevant age, such as parts of the EEA). If you believe a child has provided us with personal information, contact us at guardabudget@gmail.com and we will delete it.
15. Third-party services and links
The App relies on the third-party services listed in Section 9, and may reference store or product information from them. Their handling of data is governed by their own privacy policies, not this one. We encourage you to review the privacy policies of:
Supabase, OpenAI, Kroger, RevenueCat, Apple, USDA FoodData Central, and Open Food Facts.
We are not responsible for the privacy practices of third parties.
16. Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date at the top. If we make material changes, we will provide a more prominent notice (such as an in-app message). Your continued use of the App after an update means you accept the revised policy.
17. Governing law
This Privacy Policy is governed by the laws of the United States, without regard to its conflict-of-laws principles, except where applicable data-protection law provides otherwise for your benefit.
18. Contact us
If you have questions, requests, or concerns about this Privacy Policy or your personal information, contact: