🛒 Grocent

Privacy Policy

Grocent is a shared household grocery list app. This policy explains exactly what information we collect, why we collect it, who it is shared with, and how you can access or delete it.

Effective 29 July 2026 Last updated 29 July 2026 Applies to iOS & Android App ID dev.systemk.grocent

Who we are

Grocent (“Grocent”, “the app”, “we”, “us”, “our”) is a mobile application published by SystemK, operating from the State of Qatar. SystemK is the data controller responsible for the personal information described in this policy.

Grocent helps a household keep one shared grocery list. A Household Owner creates a household and invites Contributors, who can request items, mark items as purchased, and maintain shared lists — depending on the permissions the Owner grants them.

This policy covers the Grocent mobile app on iOS and Android and the backend services that support it. It does not cover third-party services you reach from the app, such as the Apple App Store or Google Play, which have their own privacy policies.

By creating an account and using Grocent, you agree to the handling of information described here. If you do not agree, please do not use the app.

Privacy at a glance

The short version. Every point below is explained in full further down.

No advertising

Grocent contains no ads, no ad networks and no advertising identifiers.

No tracking or analytics

We embed no analytics, attribution or crash-reporting SDKs. We do not profile you.

We never sell data

We do not sell or rent personal information, and we do not share it for cross-context behavioural advertising.

No location or contacts

Grocent does not request location, contacts, microphone or calendar access.

No card details

Subscriptions are billed by Apple and Google. We never see your payment card.

Delete from inside the app

You can permanently delete your account and its data from the app's Profile screen.

The main thing to understand: Grocent is a shared app. Everything you add to a household — item names, notes, photos and your display name — is visible to every other member of that household. See Sharing inside a household.

Information we collect

3.1 Account information

Grocent has no password of its own. You sign in with Google or Facebook, and we receive a limited profile from the provider you choose:

DataSourceWhy we need it
Email address Google or Facebook Identifies your account, and is shown as a fallback label to household members if you have no display name.
Display name Google or Facebook So other household members can see who requested or purchased an item.
Account identifier (UID) Generated by Firebase Authentication The internal key that links you to your household and your content.

We do not receive your Google or Facebook password, your friends or contacts list, your posts, or any other profile field. You can review and revoke Grocent's access at any time in your Google account settings or your Facebook app settings.

3.2 Profile and household settings

Stored against your account so the app works the way you left it:

  • Your role (Household Owner or Contributor) and any sub-permissions an Owner grants you, such as Requester, Purchaser, saved-lists access or custom-items access.
  • The household you currently belong to.
  • Your language preference (English, Arabic, Filipino, Urdu, Indonesian, Sinhala, Tamil or Amharic).
  • Your subscription state — see 3.5.

3.3 Household and list content

This is the content you and your household create. It is the substance of the app:

  • Household name, the list of member accounts, and the date the household was created.
  • Grocery items — name, optional description or note, category, quantity, unit, status (pending, approved, purchased), which member requested it, and when it was created.
  • Custom items and custom categories defined by your household.
  • Saved lists — reusable named lists your household builds.
  • Purchase history — an aggregate of frequently bought items, holding the item name, category, how many times it has been purchased and when it was last purchased. This aggregate is capped at the 100 most relevant entries per household.

Please avoid putting sensitive personal information — health details, financial details, government identifiers — into item names or notes. These fields are free text shared with your whole household, and they are not designed to hold that kind of data.

3.4 Photos you add to items

You may attach a photo to an item, either by taking one with the camera or choosing one from your photo library. Photos are handled as follows:

  • The image is resized and re-compressed on your device before it is uploaded (bounded to roughly 1280 px on the short edge, WebP or JPEG). Uploads are capped at 5 MB.
  • It is uploaded over HTTPS to our image service — a Cloudflare Worker backed by Cloudflare R2 storage, running on a subdomain we operate. Each upload is authenticated with your signed-in session, and the file is stored with a random identifier and a record of which account uploaded it.
  • The resulting image address is saved with the item so other members of your household can see the photo.
  • Deleting the item or the photo in the app deletes the stored image.

We do not scan, analyse or run image recognition on your photos, and we do not use them to train any model. Note that a photo's location and camera metadata are stripped by the re-encoding step described above; we never read or store that metadata.

3.5 Subscription and purchase information

Grocent offers optional paid tiers (Pro and Ultra). Purchases are processed entirely by Apple or Google — we never receive or store your card number, billing address or any payment credential.

When you subscribe, the app sends the store's purchase receipt or purchase token to our verification service, which checks it directly with Apple or Google. We then record against your account:

  • subscription status (free, active, expired or cancelled);
  • tier (Pro or Ultra) and billing period (monthly or yearly);
  • the store product identifier and platform (iOS or Android);
  • the expiry date, and when the record was last updated.

Apple and Google also notify our service when a subscription renews, lapses or is cancelled, so your entitlement stays correct without you doing anything.

3.6 Information stored only on your device

The following never leaves your phone and is removed when you uninstall the app:

  • A bundled catalogue of common grocery products, shipped inside the app and used to power search and suggestions. It is read-only reference data and contains nothing about you. Searches against it happen entirely offline — your search terms are never sent to us.
  • A cache of images already displayed to you, so lists load quickly and use less mobile data.
  • Small local preferences, such as your chosen language and a short queue of purchase-count updates made while you were offline, which are sent once connectivity returns.

3.7 Technical information

Our providers process limited technical data as a normal part of delivering the service — for example, the IP address a request came from, timestamps, and the type of device or app version. This is used for security, abuse prevention, rate limiting and diagnosing faults. We do not use it to build a profile of you and we do not combine it with your list content for any other purpose.

What we do not collect

To be unambiguous, Grocent does not collect, request or process any of the following:

  • Precise or approximate location data.
  • Your contacts, call logs, SMS messages, calendar or files outside images you explicitly pick.
  • Microphone audio or health, fitness or biometric data.
  • Advertising identifiers (IDFA / GAID) — the app contains no advertising or attribution SDK.
  • Analytics or behavioural telemetry. No Firebase Analytics, no Crashlytics, no third-party analytics or crash-reporting library is present in the app.
  • Payment card or bank details.
  • Any special-category data — racial or ethnic origin, political opinions, religious beliefs, trade-union membership, genetic or biometric data, health, or sexual orientation.

We also do not sell personal information, do not rent or trade it, and do not share it with third parties for their own marketing or for cross-context behavioural advertising.

Device permissions

Grocent asks for the minimum permissions it needs, and only at the moment the matching feature is used. You can decline any of them and keep using the rest of the app.

PermissionUsed forIf you decline
Camera Scanning the QR code that joins a household or adds a member, and taking a photo of an item. You can still join a household by typing the code by hand, and still pick photos from your library.
Photo library Choosing an existing picture to attach to an item. Items simply have no photo. Everything else works.
Network access Syncing your household's list across members' devices. Required — the app is a shared, synced list.

The camera is used only while a scanning or photo screen is open. Grocent never records video or audio, never accesses the camera in the background, and only ever reads the specific images you select.

How we use information

We use the information described above only to:

  • Run the service — authenticate you, keep your household's list in sync across members' devices, and display who requested or purchased what.
  • Provide the features you use — saved lists, custom items and categories, frequently-bought suggestions, item photos and QR-based joining.
  • Apply your plan — verify subscription receipts and enforce the correct tier limits for your household.
  • Keep the service safe — enforce security rules, rate-limit uploads, and detect abuse or fraudulent purchases.
  • Support you — respond when you contact us for help or exercise a privacy right.
  • Meet legal obligations — comply with applicable law and respond to lawful requests.

We do not use your information for advertising, for automated decision-making that produces legal or similarly significant effects, or to train machine-learning models.

Sharing inside a household

Grocent is built for shared use. Please read this section carefully — it is the most important part of this policy for most people.

When you are a member of a household, every other member of that household can see:

  • your display name (or, if you have none, the first part of your email address);
  • every item you add, including its name, notes, quantity and photo;
  • which items you requested and which you marked as purchased;
  • the household's saved lists, custom items, custom categories and purchase history.

Additionally, the Household Owner can:

  • change your role and permissions within the household;
  • remove you from the household;
  • delete the household entirely, which deletes its shared list, saved lists and purchase history for everyone.

Joining a household by QR code

Households are joined by scanning a QR code — either an Owner scanning your account code, or you scanning the household's code. Anyone who obtains your account code can look up your basic profile in order to invite you, and anyone with a household code can request to join that household. Treat these codes like an invitation link: only share them with people you intend to share your list with.

Leaving a household

You can leave a household at any time. Content you already added remains with the household, because it belongs to the shared list the others continue to use. If you were the last member to leave, the household and all of its content is deleted. If you were the Owner and other members remain, ownership is transferred to a remaining member so the household keeps working.

Outside your household

Your list content is not visible to other Grocent users outside your household. Access is enforced by server-side security rules, not merely hidden in the app.

Service providers

We use a small number of established providers to run Grocent. They process data on our instructions and are not permitted to use it for their own purposes.

ProviderRoleData involved
Google — Firebase
Authentication, Firestore, Cloud Functions
Account sign-in, storage and sync of your household's data, and subscription receipt verification. Account identifier, email, display name, all household and list content, subscription state.
Google — Sign-In Authenticating you if you choose Google sign-in. Email, display name.
Meta — Facebook Login Authenticating you if you choose Facebook sign-in. Name, email.
Cloudflare
Workers, R2 storage, CDN
Storing and delivering item photos. The image files you upload, plus the uploading account identifier and request metadata such as IP address.
Apple
App Store & In-App Purchase
Distributing the iOS app and processing subscription payments. Purchase and receipt data. Apple acts as an independent controller under its own privacy policy.
Google
Google Play & Play Billing
Distributing the Android app and processing subscription payments. Purchase and token data. Google acts as an independent controller under its own privacy policy.

We may also disclose information where we are legally required to, specifically to:

  • comply with a valid legal obligation, court order or lawful request from a public authority;
  • enforce our Terms of Service, or investigate suspected fraud or abuse;
  • protect the rights, safety or property of our users, the public or SystemK.

If SystemK is ever involved in a merger, acquisition or sale of assets, personal information may be transferred as part of that transaction. We will notify you in the app or by email before your information becomes subject to a materially different privacy policy.

International transfers

Grocent is operated from Qatar, and our providers operate globally. Your information may therefore be stored and processed in countries other than your own, including the United States and the European Union, whose data-protection laws may differ from those where you live.

Where personal information is transferred out of the EEA, the UK or another jurisdiction with transfer restrictions, we rely on appropriate safeguards — principally the European Commission's Standard Contractual Clauses and the equivalent UK addendum, which our providers incorporate into their data-processing terms. You may request further detail using the contact address below.

Data retention

We keep information only as long as it serves a purpose:

InformationRetention
Account profile (email, display name, role, language, subscription state)Until you delete your account, after which it is removed.
Grocery items, saved lists, custom items and categoriesUntil deleted by a household member, or until the household itself is deleted.
Purchase history aggregateAutomatically limited to the 100 most relevant entries per household; deleted with the household.
Item photosDeleted from storage when the item or photo is removed, or when the household is deleted.
Household recordDeleted when its last member leaves or when the Owner deletes it.
Subscription and purchase recordsRetained for as long as needed to honour your entitlement and to meet tax, accounting and audit obligations. Apple and Google retain their own transaction records under their policies.
Security and operational logsShort retention periods set by our providers, typically measured in days to a small number of months.
On-device cache and preferencesUntil you clear the app's storage or uninstall the app.

Backups are cycled out on a rolling basis, so residual copies may persist for a short period after deletion before being overwritten.

Your rights and choices

Subject to your local law, you have the right to:

  • Access the personal information we hold about you, and receive a copy.
  • Correct information that is inaccurate or incomplete. Your name and email come from Google or Facebook — updating them there updates them in Grocent on your next sign-in.
  • Delete your account and personal information — see the next section, which you can do yourself in seconds.
  • Port your data by receiving it in a structured, commonly used, machine-readable format.
  • Object to or restrict processing based on our legitimate interests.
  • Withdraw consent for camera or photo access at any time in your device's system settings.
  • Complain to your local supervisory authority. We would appreciate the chance to resolve the matter first.

To exercise any of these, email support@systemk.dev from the email address associated with your account. We respond within 30 days, and will tell you if we need longer because a request is complex. We do not charge a fee, and we will never discriminate against you for exercising a privacy right.

One practical limit worth stating plainly: content you contributed to a shared household — an item you added to a list others are still using — forms part of that household's shared record. We can remove your account and disassociate you from it, but we cannot unilaterally erase a shared list that other members still rely on. If you need household content removed, ask the Household Owner, or contact us and we will help.

Deleting your account

You can delete your Grocent account and its data from inside the app, without contacting us:

  1. Open Grocent and go to the Profile screen.
  2. Choose Delete account.
  3. Confirm your identity by signing in again — a security step required before an account can be destroyed.
  4. Confirm the deletion.

What deletion removes

  • Your account profile — email, display name, role, language preference and subscription record.
  • Your sign-in credentials with Grocent.
  • Your membership of any household.
  • If you were the household's last remaining member: the household itself, its grocery list, its saved lists, its purchase history and its item photos.

What deletion does not remove

  • Shared household content, where other members remain — the list continues to exist for them. If you were the Owner, ownership passes to a remaining member.
  • Records Apple or Google hold about your purchases, which are governed by their policies.
  • Information we must retain by law, such as transaction records kept for tax and accounting purposes.

Deleting your account does not cancel a paid subscription. Subscriptions are billed by Apple or Google and must be cancelled separately, in your App Store or Google Play account settings, or you will continue to be charged. Please cancel before deleting your account.

If you cannot access the app — for example you have lost access to your Google or Facebook account — email support@systemk.dev and we will delete your account after verifying your identity.

Security

Measures we take to protect your information include:

  • Encryption in transit. All communication between the app and our services uses HTTPS/TLS. Release builds refuse to send data over an unencrypted connection.
  • Encryption at rest for stored data, provided by our infrastructure providers.
  • Server-side access rules. Access to household data is enforced on the server, not just in the app. A modified client cannot read another household's list, and no client can grant itself a paid subscription — subscription state is written only by our verification service after Apple or Google confirm the receipt.
  • Authenticated uploads. Every image upload and deletion is verified against your signed-in session before it is accepted, with per-user rate limits and quotas to prevent abuse.
  • No password to lose. Because sign-in is delegated to Google and Facebook, Grocent never stores a password of yours.
  • Data minimisation. We collect only what the app's features require.

No system is perfectly secure, and we cannot guarantee absolute security. If we become aware of a breach affecting your personal information, we will notify you and the relevant authorities as required by applicable law and without undue delay. You can help by keeping your Google or Facebook account secure, and by sharing household QR codes only with people you trust.

If you believe you have found a security vulnerability in Grocent, please report it to support@systemk.dev rather than disclosing it publicly. We welcome good-faith reports and will work with you on a fix.

Children's privacy

Grocent is a general-audience household utility. It is not directed to children, and we do not knowingly collect personal information from children under 13 — or under 16 where you are in the European Economic Area, the United Kingdom or another jurisdiction that sets a higher age.

Sign-in requires a Google or Facebook account, which carries its own minimum-age requirements.

If you believe a child has provided us with personal information, contact support@systemk.dev and we will delete the account and its data promptly. Parents and guardians should note that a child added to a household will be visible to the other members of that household, as described in Sharing inside a household.

Regional disclosures

Qatar

We process personal data in accordance with Law No. 13 of 2016 concerning Personal Data Privacy Protection and its implementing guidance. You have the right to be informed about the processing of your personal data, to object to processing, and to request access, correction, erasure or blocking. You may exercise these rights, or raise a concern with the competent authority, and we will assist you in doing so.

European Economic Area and United Kingdom

SystemK is the controller of your personal data. Our legal bases are set out in Legal bases, and the rights available to you in Your rights and choices. You may lodge a complaint with your national data protection authority — in the UK, the Information Commissioner's Office. We have not appointed an EU or UK representative on the basis that our processing is occasional, limited in scope and low risk; if that changes, this section will be updated.

California

In the past 12 months we have collected the categories of personal information described in Information we collect — principally identifiers (email, account identifier), your own user-generated content, and commercial information about your subscription.

We have not sold personal information, and have not shared it for cross-context behavioural advertising, in the past 12 months — and we do not do so now. We do not knowingly sell or share the personal information of consumers under 16. California residents may request to know, delete or correct their personal information, and may not be discriminated against for doing so. Requests go to support@systemk.dev.

Other jurisdictions

Wherever you are, we will honour any additional rights your local data-protection law grants you. Please write to us and we will apply them.

Changes to this policy

We may update this policy as the app develops or the law changes. The Last updated date at the top of this page always reflects the current version.

If we make a material change — for example, collecting a new category of information or using it for a genuinely new purpose — we will give you prominent notice in the app before it takes effect, and where the law requires it, we will ask for your consent. Continuing to use Grocent after a change takes effect means you accept the updated policy.

Contact us

For any question about this policy, to exercise a privacy right, or to report a concern, write to us — we read every message.

SystemK — publisher of Grocent
Email: support@systemk.dev
Location: State of Qatar

Please include the email address associated with your Grocent account so we can locate it, and tell us what you would like us to do. We reply within 30 days.

See also the Grocent Terms of Service.