Legal

Privacy policy

Last updated 11 September 2026

This policy explains what CartCraft collects, why, who else sees it, and what you can make us do about it. It covers the CartCraft iPhone app, the web app at web.cartcraft.app, and this website.

The company responsible for your information — the “data controller”, if you are somewhere that uses the term — is Waypoint Digital LLC. CartCraft is a product of Waypoint Digital LLC, not a separate company. You can reach us at privacy@cartcraft.app.

The short version

CartCraft holds the plan you build: who is eating, what they will not eat, the shops you picked, the town you shop in, and what is in your cupboard. It is stored under your account so your phone and your browser agree.

There is no analytics, no advertising, no tracking of any kind, and no cookies. Nothing about you is sold or shared with any company for its own purposes.

What other people can see is your call: nothing about you is visible to anyone unless you make a community profile, publish a recipe, add a friend, or invite someone into your household. Each of those is a choice, each can be undone, and each is spelled out below. None of the detail contradicts this paragraph.

What we collect

Your account

If you create an account we hold your email address and a user id. If you sign in with Apple or Google we receive whatever that service passes us, which is normally an email address and an identifier — with Sign in with Apple you may choose to hide your address, in which case we only ever see Apple’s relay address and that is fine. If you sign in with a password, the password is handled by Google Firebase Authentication and we never see or store it.

You can use the web app without an account. Do that and nothing about your plan leaves your browser, because there is nowhere for it to go.

Your household plan

This is the substance of the service, and it is stored in one document under your account. It contains:

  • How many people you are cooking for, your weekly budget, and how many breakfasts, lunches and dinners you want.
  • Dietary preferences, for the household and for each person you add — vegetarian, gluten free, dairy free, low carb, high protein.
  • Food allergies, for the household and for each person you add, chosen from the nine the United States calls major allergens: peanuts, tree nuts, milk, eggs, fish, shellfish, soy, wheat and sesame. This is health information, and the note further down says what that means.
  • Names of people in your household, if you add them individually. These are whatever you type. They do not have to be real names, and nothing in the app checks or cares.
  • The shops you are willing to visit, which one you prefer, and which day you shop.
  • Where you shop: the town or postal code you typed, and a latitude and longitude for it. The coordinate is what lets the app price your week against your area rather than a national average, and it is the reason your phone and your browser show the same total.
  • What is in your pantry, the meals you have saved or ruled out, and the weeks you have planned.
  • What your kitchen can cook with, if you have been asked: a stovetop, an oven, a microwave, an air fryer, a slow cooker, a blender, a grill. Leaving the question unanswered is not the same as answering “none”, and an unanswered kitchen rules nothing out of your week.
  • Recipes you write yourself. They stay private to your household unless you publish them, which is covered below.
  • A number used to shuffle your meal choices, so the same week does not regenerate identically.

Your community profile, if you make one

The community is optional. Nothing in this section exists until you choose a handle, and if you never do, other users cannot see you at all.

  • A public profile: your handle, a display name, an avatar picked from a fixed set of symbols and colours, the dates you created the profile and last renamed it, and any social links you choose to add. There are no profile photos. Any signed-in CartCraft user can view the profile and can find it by searching for the handle; nothing about it is visible to the open internet.
  • Links to your accounts elsewhere, if you add them: Instagram, X, Facebook, TikTok and Pinterest. We store the username you type, never a link you supply, and build the address ourselves, so the icon can only ever go to the site it names. Anyone who can see your profile can see these and follow them, and following one leaves CartCraft for a site with its own terms and its own privacy policy. Clear the field to remove one.
  • You can change your handle once every 30 days, and a handle you give up becomes available for someone else to take.
  • If you subscribe, the profile carries an approximate end date for the subscription, and whether the seat is a lifetime one; that is what draws the Plus badge, and like the rest of the profile it is readable by any signed-in user. A verified badge exists too, with a short note from us; only we can grant or remove it.

Recipes you publish, and likes

When you publish a recipe you choose its audience: everyone, your friends, or people you pick. It is shown to that audience and nobody wider, under your handle, with your display name, avatar and badges beside it.

  • A published recipe is a frozen copy of the recipe plus your handle at the moment you published. You can change its audience or take it down at any time: access ends immediately, though the community feed can show the old entry for a few minutes more while its cache turns over. A copy somebody already saved into their own household stays theirs, because by then it is part of their plan.
  • Liking a public recipe adds to its like count. Your recent likes of public recipes are also kept in a list that any signed-in user can read, which is what powers the friends boards: it holds the recipe and the date, never more than 500 entries, and entries older than 40 days are dropped as new likes come in. A like on a recipe that was shared privately is never written into it.
  • If you report a recipe, we record that your account reported it. Who reported is visible to nobody, including the recipe’s author, though the count of reports sits on the recipe itself, and reports from enough different accounts hide the recipe automatically.

Friends

A friend request is visible to the two accounts it involves and to nobody else. Your friends list is readable only by you: there are no public friend lists, and declining a request is never announced to the person who sent it.

Sharing your household

You can invite a friend’s account into your household, and everyone in it then plans from the same document. Joining a household is a real decision, so here is exactly what it means:

  • Everyone in the household can see and change everything in the plan: the people and the names you gave them, every dietary preference and allergy, the budget, the stores, the town you shop in and its coordinate, the pantry, the weeks planned and past, the household’s recipes, and the shopping list check-offs.
  • Members see each other’s display name or handle, never an email address.
  • Invites only work between friends. Either side can end it at any time: the owner can remove a member, and a member can leave. The household data you had before you joined is kept untouched and comes back when you leave.
  • A subscription is never shared through a household. CartCraft Plus belongs to the account that bought it.

On your device

Your appearance setting and a count of how many swaps and recrafts you have used this week stay in your browser’s local storage. Your signed-in session is kept in your browser’s own storage too, by Firebase. We set no cookies, and there is nothing to consent to.

Payment

If you subscribe on the web, Stripe takes the payment. Stripe receives your account identifier, which plan you chose, and your email address. Your card details go straight to Stripe and never touch our servers — we cannot see them, and we do not store them. If you subscribe on iPhone, Apple takes the payment under its own terms and we are told only that a subscription exists and when it expires.

Asking to be a beta tester

If you ask for a TestFlight invite from our website, we hold what that form collects: your first and last name, the email address your Apple Account uses, your phone number, and the fact that you checked the acknowledgement. We use them to send you an invite and to reach you about the test, and nothing else. The Apple ID goes to Apple, because that is how a TestFlight invite is addressed; the phone number does not. The note that tells us a request arrived is an email delivered through Resend, our email provider, and it carries the details you typed. You can ask us to delete the request at any time, and we delete it ourselves once the beta ends.

Server logs

Our host, Vercel, keeps ordinary request logs, which include IP addresses and browser user agent strings. These exist to keep the service running and to investigate abuse. Our own rate limiting keeps counters too: for signed-in requests they are keyed by your account, and for the beta form by a one-way hash of the IP address, never the address itself.

What we do not collect

Stated plainly, because most policies bury this and most apps cannot say it:

  • No analytics or product telemetry. There is no analytics SDK in any of our apps.
  • No advertising, no ad identifiers, no advertising partners, no retargeting pixels.
  • No cookies, and therefore no cookie banner.
  • No location tracking. We hold the place you typed and its coordinate. We do not follow your device.
  • No contacts, photos, microphone, or health data.
  • We do not sell your personal information, and we do not share it for cross-context behavioural advertising, as those terms are defined under California law. We never have.

A note on allergies, dietary information and names

A food allergy you record is health information outright, not something merely implied by what you eat, and we treat it as that. Dietary preferences imply rather than state: gluten free or dairy free may reflect a medical condition, vegetarian may reflect a belief. In some places both are a protected category of information. We ask for them only to plan meals that work for your table, we use them for nothing else, and you give them to us voluntarily by choosing them in the app.

If you would rather not attach that to a name, use a nickname or an initial. The app never verifies who anybody is, and the plan works exactly the same.

Why we are allowed to hold it

If you are in the UK, EU or somewhere with similar law, these are our legal bases:

  • Performing our contract with you — your account and your household plan. Without them there is no service to provide.
  • Our legitimate interests — keeping the service running, secure and free of abuse, and understanding faults when they are reported to us.
  • Your consent — where you record a food allergy, or volunteer other dietary information that reveals health or belief. You can withdraw it by changing or removing it in the app.
  • Legal obligation — records we are required to keep, such as tax records for a payment.
  • Your consent — the details you give us to ask for a beta invite. You can withdraw it by asking us to delete the request.

Who else sees it

First, other CartCraft users, because that is the sharing that is actually about you: they can see your public profile, whatever you publish, your recent likes of public recipes, and, if you share a household with them, the household plan. All of it is described in the sections above, all of it happens only because you chose it, and all of it can be undone.

Beyond that, we use a small number of companies to run the service. They act on our instructions and may not use your information for their own purposes. This is the complete list of them, what each one does for us, and what it receives. All six are US companies.

  • Google (Firebase): authentication and the database your household plan is stored in. Receives your sign-in credential, email address and everything in the household document.
  • Apple: Sign in with Apple; App Store subscriptions if you subscribe on iPhone; and the Apple Maps Server API when you search for shops or a town. That search is made by our server, so Apple receives the words you typed and, if you asked for shops near a point, that point. Apple does not receive your IP address or your identity from us.
  • Google: Sign in with Google, if you use it. Receives only the sign-in itself.
  • Stripe: payments on the web. Receives your account identifier, plan and email address, and takes your card details directly.
  • Resend: delivers the email that tells us a beta invite was requested. Receives the details on that form.
  • Vercel: hosting, and the request logs described above. Receives your IP address and browser user agent on every request, as any host must.

Nothing else is loaded from anyone else. The fonts on this website, the artwork on its pages and the screen recordings on its front page are served from our own host, so no third party learns that you visited.

We will also disclose information if the law genuinely requires it, and if CartCraft is ever sold or merged your information may transfer with it — in which case this policy continues to apply until you are told otherwise.

Where it is held, and for how long

Our providers are US companies and your information is processed in the United States. If you are in the UK or EU, that is a transfer outside your region; it is covered by the standard contractual clauses our providers offer, or by the EU–US Data Privacy Framework where they participate in it.

We keep your household plan for as long as your account exists. Delete your account and it goes with it. A recipe you published stays published until you take it down or ask us to, and the record that an account reported a recipe is kept even after the recipe comes down, because it is the evidence for the takedown. Records tied to a payment are kept as long as tax and accounting rules require, which is typically seven years. A request for a beta invite is kept until the beta ends, or until you ask us to delete it. Server logs are kept on our host’s ordinary schedule, a matter of weeks.

Your rights

Wherever you are, you may ask us for a copy of what we hold about you, ask us to correct it, or ask us to delete it. Write to privacy@cartcraft.app and we will answer within 30 days.

If you are in the UK or EU you also have the right to restrict or object to processing, the right to receive your information in a portable form, the right to withdraw consent, and the right to complain to your data protection authority — in the UK, the Information Commissioner’s Office.

A copy of your information, or a portable one, is the same thing from us: a JSON file containing your household document, your community profile and the recipes you published, sent to the email address on your account. Ask at privacy@cartcraft.app from that address and it arrives within 30 days, usually much sooner.

If you are in California you have the right to know what we collect and why, the right to delete it, the right to correct it, and the right to opt out of sale or sharing. There is nothing to opt out of: we do not sell or share personal information. We will not treat you differently for exercising any of these rights.

Deleting your account

You can do this yourself, on either platform, and it takes effect immediately.

  • On the web — open Household and choose Delete account and cloud data at the bottom of the screen.
  • On iPhone — open Account and choose Delete account and cloud data.

Either one removes the stored household document and then the account itself: the household, your stores, your pantry, your recipes and every week you have planned. It cannot be undone. Two things can stand in its way: if other accounts are still linked to your household you will be asked to remove them first, so a shared plan is never pulled out from under the people using it, and if you signed in a long time ago you may be asked to sign in again before the deletion is accepted.

What the button does not yet remove is the community side: your profile and handle, recipes you published, your likes, and your friendships. You can take a published recipe down yourself at any time from Recipes; for the rest, email privacy@cartcraft.app from the address on your account and we will remove all of it within 30 days. We would rather tell you that plainly than let the button imply more than it does. The same address also works if you want us to do the whole deletion for you.

Deleting your account does not cancel a subscription. Cancel one bought on iPhone in your App Store settings, and one bought on the web from the billing portal, before you delete.

Security

Your household document is readable only by your own account and by the household members you have invited, enforced by database rules rather than by our good intentions. What you publish is readable by the audience you chose, and nothing in the community is visible without a signed-in account. Connections are encrypted in transit. Passwords are handled by Firebase Authentication and never reach us. No system is perfectly secure, and we do not claim otherwise. If a breach ever puts your information at risk we will tell you by email without undue delay, and notify the relevant authority within 72 hours of learning of it where the law requires that.

Children

CartCraft is not intended for children under 13, and we do not knowingly collect their information. If you add a child to your household as a person to cook for, please use a first name or a nickname — nothing more is needed. If you believe a child has created an account, write to privacy@cartcraft.app and we will remove it.

Changes

If this policy changes we will update the date at the top, and for anything significant we will tell you in the app or by email before it takes effect.

Contact

Waypoint Digital LLC, the company behind CartCraft — privacy@cartcraft.app.