The details
Privacy
What stays on your device, what may leave it, and the choices you have during this early release.
Price Pantry is an alpha release. This page describes the current app and service; it will be updated as the service develops. Last updated 25 September 2026.
Your shopping information
Shopping lists, pantry items, receipt reviews, purchase history and retailer account information are kept on your device for app features. Price Pantry does not make these items public through its community catalogue. A receipt must be reviewed before it changes your pantry or purchase history.
Removing the app's local data through Android settings removes information held only on that device. Android backup or a connected retailer may retain separate copies under their own settings and policies.
Location and retailer requests
With your permission, the app can use precise device location to find nearby stores. You can instead choose an area or store where the app offers that option. Your selected search radius is 1–65 km. Retailer sites may receive a postcode, store or regional context needed to request relevant prices and availability. Those sites process requests under their own privacy practices.
Prices and optional community sharing
The app may request catalogue data from the Price Pantry service and retailers. If you explicitly enable community sharing, the app can send a limited set of catalogue observations: product and price information, retailer branch or region, and observation times. Sharing is off by default. It is intended for public catalogue information, not your shopping list, search terms, precise GPS coordinates, receipts, loyalty details, retailer login cookies or purchase history.
Shared observations may become visible to other users as partial community data. The service checks incoming records, but cannot guarantee every price or product detail is correct. The public view uses observations from the last 24 hours and shows at most 50 community items for a selected store or area. Submitted observations expire after 90 days and are removed by daily cleanup.
Turning sharing off stops future uploads and asks the service to revoke this installation's sharing token and delete observations linked to it. If your device is offline, that request is sent when it next connects. The service removes those retained observations when it receives the request. Copies that other devices already downloaded cannot be recalled.
Service and account data
Requests to the service can expose technical information such as an IP address, request time and device or app details to the service and its hosting provider. This information may be personal information. It is used to deliver requests, maintain security and limit abuse. The community service stores a hash of an anonymous installation token for up to 30 days. It uses short-lived keyed hashes of IP addresses and tokens to enforce rate limits; it does not store raw IP addresses in its community database. Those rate-limit records expire within a day and are purged by daily cleanup. This does not rule out network logs held by the hosting provider.
Optional sign-in or payment features, if configured and used, can involve account identifiers, Google tokens and subscription records. The availability of those features in the alpha may be limited.
We do not describe catalogue observations as anonymous in every circumstance: branch, time and network information can sometimes be linked to a person. Price Pantry does not use the website to ask you for a shopping profile or payment card number.
Sharing, storage and security
The Price Pantry service uses Cloudflare to host the site and API. Information sent to the service may be processed by Cloudflare and its infrastructure outside Australia. Retailers may also receive your network IP address, selected area or postcode when the app requests their data. Retailers, Google and payment providers process information when you use their respective services. We limit shared catalogue submissions and validate them, but no internet service can promise absolute security.
Retention periods for hosting-provider logs and optional account or subscription records, and the countries in which service data is processed, are being confirmed for this alpha. The community data periods above are separate from those records. Please contact the person who provided your build if you need details before choosing to share observations.
Your choices and requests
- Use Android permissions to grant or withdraw precise location access. Precise GPS coordinates are not part of community contributions.
- Turn community catalogue sharing off in the app to stop future contributions and request deletion of observations linked to this installation's token when the app connects.
- Review receipts before confirming purchases; remove local app data through Android settings when you no longer want it on your device.
For access, correction, removal or a privacy complaint relating to information held by the service, contact the person who provided your alpha build and identify the request. They can pass it to the operator for review. Do not send passwords, retailer cookies or full receipts with an initial request. If you are in Australia and are dissatisfied with a response to a privacy complaint, you may be able to contact the Office of the Australian Information Commissioner.