Understand why your grocery bill changed.
Last updated: 30 August 2026
GroceryLens reads your grocery receipts so it can tell you why your bill changed. To do that it needs the receipts. It does not need to know who you are beyond an email address, and it does not ask.
GroceryLens is operated by Nikhil AI Labs, in Ontario, Canada.
For anything in this policy — a question, a request, or a complaint — write to hello@nikhilailabs.com.
| What | Why |
|---|---|
| Email address | To sign you in. We send a one-time link; there is no password |
| Photographs of your receipts | To read the items and prices off them |
| Country, currency, language | To show money correctly. Asked as a question, never read from your device |
| Monthly grocery budget | Optional. To show progress against it |
| Household size | Optional. Nothing is shown per-person unless you set it |
| Corrections you type | When you fix what a receipt said an item was |
| What | Why |
|---|---|
| Line items: what you bought, and what it cost | The whole product. Every figure comes from your own receipts |
| Which shop a receipt came from | So a price can be compared between shops you have used |
| Your own price history | To tell you when something you buy has changed price |
| A record that a receipt was read | To count usage against a fair limit, and to spot outages |
A receipt usually prints the shop's address. We reduce it before storing it and
keep only the country, region, town and postal district — L5R, never
L5R 3S9. No coordinates are stored anywhere, at all.
That is about a shop, not about you. We never infer where you live, where you work, or your routine, and the only home region we use is the one you choose in Settings. The stored address is deleted on the retention period you set.
Your name. Your address. Your phone number. Your income. Your payment or card details — no part of a card number is stored, and any fragment printed on a receipt is not extracted. Your precise location. Your contacts. Your browsing or search history. Health data. Advertising identifiers.
We use a small number of processors. They are listed here because you should know, not because they may do anything they like with your data.
| Who | What reaches them | Why |
|---|---|---|
| Supabase | Everything: the database, sign-in, and your receipt photographs in a private bucket | This is where GroceryLens runs |
| Amazon Textract | The receipt photograph itself | To read the text off it |
| Anthropic | One uncertain item label at a time, plus your language, country, currency and the type of shop | To suggest what an unclear line means |
Two of those deserve to be spelled out rather than buried.
Amazon Textract receives your receipt photograph. Everywhere else this app goes to real lengths to send the least it can; reading a receipt is the deliberate exception, because it cannot be done without the receipt. Textract is used as a processor and the image is sent for that single purpose.
Anthropic never receives a receipt, an image, or anything identifying you.
Not your email, not any identifier, not a total, not a price, not an address,
not the rest of the receipt. One printed label such as ABC GROC 400G, so it
can suggest that it means paneer. There is a check in the code that refuses to
send a payload containing an identifier, and it runs before every call.
Beyond those, we share nothing. No advertisers, no data brokers, no analytics companies. We will disclose data if the law requires it, and we will tell you unless we are forbidden to.
The database, sign-in and receipt images are hosted in Canada. Receipt images are sent to Amazon Textract in the Canada (Central) region to be read. Item labels sent for suggestion are processed by Anthropic in the United States.
| What | Kept for |
|---|---|
| Receipt photographs | The period you choose in Settings. Default 30 days after being read |
| Shop addresses from receipts | The period you choose in Settings |
| Receipts and their items | Until you delete the receipt, or your account |
| Your email and settings | Until you delete your account |
Deletion means the file and the row are gone, not hidden behind a flag.
Settings → Leaving → Delete account, inside the app. You type your email address to confirm, and then:
It happens immediately. There is no grace period, no archived copy, and we cannot restore it afterwards. If that matters to you, be sure before you type your address.
You can also delete a single receipt at any time, which deletes its photograph with it, and clear all saved shop addresses without touching anything else.
Depending on where you live you may have rights to access, correct, delete or export your data, and to object to or restrict processing.
To exercise any of these, or to complain, write to hello@nikhilailabs.com. In Canada you may also complain to the Office of the Privacy Commissioner; in the EEA or UK, to your local supervisory authority.
GroceryLens is not directed at children and we do not knowingly collect data from anyone under 13. If you believe a child has created an account, write to hello@nikhilailabs.com and we will delete it.
Sign-in uses a one-time link rather than a password. Receipt images live in a private bucket that is not publicly readable, reachable only through short-lived signed links. Every table enforces row-level security keyed to your account, so one person's data is not merely hidden from another — it does not exist as far as their session is concerned. The app itself holds no provider keys of any kind.
No system is perfectly secure, and we do not claim otherwise.
If we change this policy we will update the date at the top, and we will tell you in the app before any change that affects what we collect or who we share it with.