1. Who we are

HomStock ("the App") is developed and operated by Jorge Mendoza, a sole proprietor based in Illinois, USA, acting as the data controller for the personal data described in this policy.

For privacy-related questions, requests, or complaints, contact: jomen12@icloud.com.

2. The short version

HomStock stores your household data in Google Firebase. It is shared only with members of your household and the limited service providers listed below. We do not sell or rent your data, we don't run ads, and we don't track you across other apps or websites.

3. What data we collect

CategoryWhat it includes
AccountDisplay name and email address from Sign in with Apple; a Firebase user identifier (UID)
HouseholdHousehold name, invite code, member list, your role (owner / member)
ReceiptsPhotos you scan, extracted item names + prices, store name and address, totals, and the date
Shopping listItems you add, quantities, categories, notes, who added each item, who checked it off, and any "for [name]" attribution
Product catalogProduct display names and image URLs created when receipts are scanned
Meal plansWeekly meal plans you create, the meals on each day, ingredients, notes, and cooked/not-cooked status. Shared with members of your household.
Dietary preferences (if you choose to set them)Self-declared dietary toggles (vegetarian, vegan, pescatarian, gluten-free, dairy-free, nut-free, halal, kosher). Used only to personalize meal suggestions. See §4 below for the special-category basis.
Notification preferencesA per-user toggle controlling whether the optional "Weekly meal review" notification is sent on Saturday evenings.
Device registrationA push-notification token per signed-in device, used to deliver shopping-list and meal-review notifications
SubscriptionWhether you have HomStock Pro, the product identifier, transaction ID, purchase date, and expiration date
App preferencesAppearance mode, theme choice, and which sections of the UI are collapsed — stored locally on your device

4. Why we collect it, and our legal basis (GDPR Articles 6 and 9)

PurposeLegal basis
Provide the core features — accounts, households, receipts, shopping lists, meal plans, push notifications, subscription entitlementArticle 6(1)(b) — performance of the contract between you and HomStock
Personalize meal suggestions based on your dietary preferences (only if you choose to set them)Article 9(2)(a) — explicit consent, captured at the moment you save preferences on the Dietary screen. Religious indicators (halal, kosher) and health-related indicators (gluten-free, dairy-free, nut-free) are treated as "special category" data under Article 9 and processed only on this explicit-consent basis.
Send the optional Saturday-evening "Weekly meal review" reminderArticle 6(1)(b) — it is a reminder of your own scheduled data. It is only sent if you explicitly enable it on the in-app disclosure sheet or in Settings → Notifications, and only for weeks where you have at least one planned meal.
Maintain the integrity of the service — clean up stale push tokens, enforce abuse-prevention rate limits on receipt scanning and meal-suggestion / auto-plan AI callsArticle 6(1)(f) — our legitimate interests in keeping the service working
Comply with App Store, tax, and other legal obligationsArticle 6(1)(c) — legal obligation

You can withdraw consent for dietary-preference processing at any time by clearing the toggles on the Dietary screen, or by emailing us. Withdrawing consent has no effect on processing carried out before the withdrawal and does not affect any other features.

We do not currently process any other data on the basis of consent — no analytics, no marketing, no ad tracking. If that ever changes, we will request your explicit, opt-in consent.

5. Service providers ("sub-processors")

The following third parties process limited personal data on our behalf under a written data-processing agreement:

ProviderPurposeLocation
Google Cloud / Firebase (Auth, Firestore, Storage, Cloud Functions, Cloud Messaging, Remote Config, App Check)Backend hosting, authentication, push delivery, scheduled background jobsUSA (us-central1 region)
Google Gemini (via Firebase Cloud Functions)Parsing the text extracted from receipt photos into structured items and prices; generating meal suggestions and weekly meal plans from your pantry and dietary preferencesUSA
PexelsAnonymous stock-image lookup by meal name to illustrate suggestions — no user identifiers sentUSA
Apple Inc.Sign in with Apple, App Store payment processing, APNs push deliveryUSA / EU data centers
RevenueCat, Inc.Subscription entitlement verification and ledger (receives a pseudonymous Firebase UID and Apple transaction metadata only)USA
Open Food FactsAnonymous product-image lookup by product name — no user identifiers sentEU (France)

We do not share your data with advertisers or data brokers.

6. International data transfers

Your data is stored on servers in the United States (Google Cloud, us-central1). Where these transfers fall under the GDPR or UK GDPR, they are covered by the Standard Contractual Clauses (SCCs) incorporated into the Firebase Data Processing and Security Terms and Google's broader Cloud Data Processing Addendum, and supplemented by Google's technical and organizational safeguards described in those documents.

7. How long we keep your data

8. What happens when you delete your account

You can delete your account at any time from Account → Delete Account in the App. When you do:

To revoke Sign in with Apple after deletion, go to iOS Settings → your Apple ID → Sign-In & Security → Sign in with Apple → HomStock → Stop Using Apple ID.

9. Your rights under GDPR and UK GDPR

If you are in the European Economic Area, the UK, or Switzerland, you have the following rights regarding your personal data:

To exercise any of these rights, email jomen12@icloud.com. We will respond within 30 days as required by Article 12.

10. Security

Data is encrypted in transit (TLS) and at rest by Google Cloud. Access is gated by Firebase Authentication and Firestore security rules so only authenticated members of your household can read your data. Dietary preferences and notification preferences are stored under a separate per-user private path that is readable and writable only by you (not by other household members). App Check is enabled to protect Cloud Functions against abuse. We do not have direct access to your receipt photos, shopping lists, meal plans, or dietary preferences; we only see them in aggregate when troubleshooting at your request.

If we ever discover a personal-data breach that is likely to result in risk to you, we will notify the relevant supervisory authority within 72 hours and contact you directly when required.

11. Children

HomStock is not directed to, and we do not knowingly collect personal data from, anyone under 16. If you believe a child has provided us with personal data, contact us and we will delete it.

12. Changes to this policy

We may update this policy from time to time. When we do, we will change the "Last updated" date above. Material changes will also be announced in the App.

13. Contact

Jorge Mendoza (sole proprietor) — jomen12@icloud.com

For requests under the EU Digital Services Act or to identify our published trader contact information, see the HomStock listing on the EU App Store.