Boughtful Privacy Policy
Effective 3 September 2026 · Applies to the Boughtful app (currently in closed beta) for Android, iOS and web, made by Boughtful, an Australian sole-trader project (ABN registration in progress — this line will be updated when issued).
The short version: your data stays on your device unless you switch something on.
Boughtful has no accounts and no server. Your pantry, your receipts, your shopping lists and everything the app learns about your household are stored in a database on your phone. Out of the box the app makes no network calls at all — and every feature that can send anything anywhere is listed below, each behind its own off-by-default switch. We never sell or share your data for advertising. Ever.
What the app stores (on your device)
- Your inventory — products, quantities, locations, expiry dates.
- Your purchase history — receipts you scan or import (including receipt photos, if you scanned them), items, prices, stores, dates.
- Your corrections and preferences — renamed products, adjusted dates, staples, favourite items, settings. This is how the app gets smarter for you; it's stored only on your device.
- Your notification history — what reminders you were shown, so we can keep our promise of at most one per day.
- An AI model file, if you import one — the optional on-device AI engine runs from a model file you supply; it lives in the app's private storage until you remove it.
We don't see any of this. There is no account to create, and nothing is uploaded. Backups are files saved where you choose — we never receive them. API keys you enter for optional AI features are deliberately excluded from backups and never leave the device they were typed on.
A note on sensitivity: we know purchase history is personal — it can hint at things like household size, health or diet. That's exactly why the app is built local-first, and why nothing below sends purchase history anywhere.
What can leave your device — each item has its own switch
This list is complete. Everything below is OFF by default, and the app is fully usable with all of it off.
| Feature (its switch) | What is sent when you turn it on | Where it goes | What is never sent |
|---|---|---|---|
| AI on your phone (Settings → AI → "On this phone") | Nothing. The on-device engine runs a model file you imported; prompts and answers never leave the phone | Nowhere | Everything — no network is involved |
| Cloud AI — receipt reading (Settings → AI; needs a key you supply) | The text of a receipt you scan — read on your phone first, with names, loyalty numbers and card digits removed on your phone | The AI provider you choose: Anthropic (US), Google (Gemini API), or OpenAI (US) — under API terms that do not use your data for training. For Google we state in-app that a paid-tier key is required, because Google's free tier can use prompts to improve its products | The receipt photo never leaves your phone. Your inventory and history are not sent |
| Cloud AI — meal ideas (same switch) | The names and categories of food you have on hand, which items need using soon, and diet preferences if you set them | Same provider you chose | Your purchase history, prices, stores, photos |
| AI model list (Settings → AI → "Choose model" — a button you tap) | A single request asking your chosen provider which models your key can use | Only the provider you configured, using your key | Anything about you or your pantry |
| Online product lookup (Settings → Privacy → "Look up scanned barcodes online") | A product barcode number, when a scanned barcode isn't in the app's built-in catalogue | Open Food Facts, a non-profit open food database | Who you are, or anything else you own |
| Crash reports & basic usage (Settings → Privacy & diagnostics, opt-in) | Nothing automatically. Summaries are collected on your phone only; "sending" means you reading the report and choosing to copy it to us | Only where you paste it (e.g. an email you write) | Your pantry, receipts, or anything you've typed — and nothing at all unless you copy it yourself |
If we add household sharing/sync later, syncing your data between your own household's devices will be its own explicit choice, this table will be updated first, and local-only will remain the default.
What we never do
- We never sell, rent, or trade your personal information. Full stop.
- No advertising SDKs, no trackers, no analytics running quietly in the background.
- No "we miss you" notifications; at most one useful reminder a day.
- We never ask for your supermarket or email passwords, and never log into your accounts.
Keeping your data, deleting your data
- Retention is up to you: items and history stay until you delete them.
- Erase all data (Settings → Data) wipes everything the app has, on the spot. There is no server copy to chase.
- Receipt photos can be deleted separately at any time.
- Imported AI model files can be removed in Settings → AI.
- Export your data (JSON/CSV) or a full backup file whenever you like — it's yours, including if you stop subscribing (paid features pause; access to your own data never does).
- Backups you save, and any OS-level phone backup that includes the app, are under your control — deleting data in-app can't reach into backup files you've kept.
Security
Your data is stored in the app's private storage area, protected by your device's own security (screen lock, device encryption on modern iOS and Android). Because there is no server, there is no server to breach. When an optional feature sends data (table above), it is sent over encrypted connections (HTTPS). API keys are stored on-device only and excluded from backups.
Australian privacy law
We are an Australian sole-trader project. Businesses with turnover under A$3 million are currently exempt from most of the Privacy Act 1988 (Cth) — but we build to the Australian Privacy Principles anyway, voluntarily: plain-language transparency (this policy), collecting only what's needed, no selling of personal information, security and deletion you control, and access/correction that's trivially satisfied because the data sits in your own hands. Where an optional cloud AI feature sends receipt text or food names overseas (see table), we tell you here, in the app, and in the app-store listings, and we choose providers whose API terms do not use your data for training — and we offer the on-device engine for anyone who prefers that nothing leaves the phone at all.
If Australian privacy law changes to cover us fully, our practices are already designed to comply.
Children
Boughtful is a household tool intended for adults doing the shopping. It is not directed at children, has no accounts, no social features, no advertising, and collects no data from anyone — child or adult — beyond what is described above. If Simple Mode is used by younger or older family members on a shared device, everything still stays on that device.
Changes to this policy
If we change what the app does with data, we will update this policy and its effective date before the change ships, summarise the change in the app's release notes, and — for anything that sends new data off your device — ask for your opt-in in the app. We will never flip an existing switch on for you.
Contact us
Questions, access or correction requests, complaints: beta@boughtful.app · boughtful.app
If you're not satisfied with our response, you can complain to the Office of the Australian Information Commissioner (oaic.gov.au).