Skip to main content

Privacy Policy

Last updated: July 2026

Geographic Availability: Visual Inventory is currently available in the United States, Canada, and Mexico.

1. Introduction

Your privacy matters to us — especially since Visual Inventory works with photos of your home. This policy explains what we collect, how we use it, and how we keep it safe. The short version: we don't sell your data, we don't train AI on your photos, and current capture originals aren't copied into our file storage on any plan.

Visual Inventory, LLC ("Visual Inventory," "we," "us," or "our") operates the Visual Inventory application, website, and related services (the "Service"). By using the Service, you agree to the data practices described below.

2. Information We Collect

2.1 Information You Provide

  • Account Information: Email address, name, and password when you create an account
  • Profile Information: Optional information such as household name and preferences
  • Inventory Data: Photos you upload, item details, expiration dates, quantities, and locations
  • Household Information: Household member types and counts (e.g., "2 adults, 1 child") and their roles. See Section 12 for how we handle information about minors
  • Voice Input: If you use voice input, audio is sent to OpenAI for transcription and immediately discarded — we never store your recordings
  • Photos & Receipts: Photographs of your shelves, pantry, receipts, and barcodes that you upload for AI scanning
  • Payment Information: Billing details processed securely through Stripe (we do not store your full payment card details)
  • Communications: Messages you send to our support team

2.2 Information Collected Automatically

  • Device Information: Device type, operating system, browser type, and unique device identifiers
  • Usage Data: Features used, actions taken, time spent, and interaction patterns
  • Log Data: IP address, access times, pages viewed, and referring URLs
  • Location Data: Approximate location based on IP address (we do not collect precise GPS location)

2.3 Cookies, Local Storage, and Tracking Technologies

We use the following client-side storage technologies:

  • Strictly Necessary: Authentication session cookies (Supabase) required for login and security
  • Functional: Local storage for theme preferences, notification settings, and scan drafts
  • Offline Data: IndexedDB for offline inventory cache and pending actions that sync when you reconnect
  • In-session image review: The current scan image remains in browser memory only while you review that scan; it is not copied into durable browser storage
  • Analytics: Vercel Analytics and Vercel Speed Insights for aggregated, anonymous performance monitoring

You can clear local storage and IndexedDB through your browser settings. Note that clearing authentication cookies will require you to log in again.

3. How We Use Your Information

We use your information for the following purposes, along with the legal basis for each:

  • Provide the Service: Process your inventory scans, track items, and deliver features (legal basis: contract performance)
  • AI Processing: Analyze uploaded images and voice to identify and catalog items (legal basis: contract performance)
  • Notifications: Send expiration alerts, shopping suggestions, and service updates (legal basis: contract performance and legitimate interest)
  • Service Improvement: Analyze aggregated, anonymized usage patterns to improve the Service (legal basis: legitimate interest)
  • AI Improvement (opt-in): You can save an explicit preference to contribute anonymized scan correction data in the future. Collection is currently paused while we build privacy-safe storage, so no correction data is being collected for AI improvement today (legal basis, if activated: consent)
  • Support: Respond to your inquiries and provide customer service (legal basis: contract performance)
  • Security: Detect and prevent fraud, abuse, and security incidents (legal basis: legitimate interest)
  • Legal Compliance: Comply with applicable laws and legal processes (legal basis: legal obligation)

4. AI and Image Processing

This is the part most people care about, so here's exactly what happens when you scan:

  • How scanning works: Your photos are sent securely to Anthropic (Claude) for item recognition, then the results come back to you. Voice input goes to OpenAI (Whisper) for transcription only
  • We don't train on your photos: We do not use your photos to train models, and our commercial AI providers do not use API inputs for model training by default. Anthropic may retain API inputs and outputs for up to 30 days for safety and policy enforcement unless a different retention arrangement applies
  • Optional improvement data: You can save an opt-in preference in Settings, but correction contribution is currently paused. No correction data is being collected for AI improvement today
  • How long we keep photos: Current photo and receipt capture originals are processed transiently and are not copied into our file storage on any plan. Expiring cleanup remains in place for legacy files already present in the old scan and receipt buckets
  • Encryption: All data is encrypted in transit (TLS 1.2+)

5. Data Sharing and Disclosure

We do not sell your data. Period. We only share information in these limited circumstances:

  • With Your Consent: When you explicitly authorize sharing
  • Household Members: With other members of your household who you invite
  • Service Providers: With vendors who assist in operating the Service (hosting, payment processing, AI services, analytics), subject to confidentiality obligations
  • Legal Requirements: When required by law, court order, or government request
  • Protection of Rights: To protect our rights, privacy, safety, or property, or that of our users or the public
  • Business Transfers: In connection with a merger, acquisition, or sale of assets, with notice to users

6. Data Security

We implement appropriate technical and organizational measures to protect your information, including:

  • Encryption of data in transit (TLS 1.2+) and at rest
  • Secure cloud infrastructure hosted by industry-leading providers (Supabase, Vercel)
  • Regular security reviews of our codebase and infrastructure
  • Access controls and authentication requirements
  • Principle of least privilege for internal access

No system is 100% bulletproof, but we take security seriously and continuously work to protect your information.

7. Data Retention

We retain your data for as long as your account is active or as needed to provide you services. Specifically:

  • Account Data: Removed from the live service when a successful self-service account deletion completes
  • Inventory and Household Data: Retained until the item or household is deleted. If you delete your account while other household members remain, shared pantry, shopping, meal, and task records stay with the household and your personal attribution is removed
  • Deleted Items: Moved to trash and eligible for permanent cleanup after 30 days; you may also remove them manually
  • Current Capture Originals: Photo and receipt originals are processed transiently and are not copied into our file storage on any plan
  • Legacy Scan and Receipt Files: Account deletion attempts to remove legacy files linked to you. Legacy scan and receipt files also remain subject to their existing automatic expiration periods
  • AI Provider Processing: Anthropic may retain API inputs and outputs for up to 30 days under its default commercial API policy. OpenAI documents no abuse-monitoring or application-state retention for its audio transcription endpoint. Provider exceptions may apply for legal or abuse-prevention requirements
  • Voice Input: Sent to OpenAI for transcription and immediately discarded
  • AI Correction Data: We do not currently collect correction data for AI improvement. If privacy-safe collection is enabled later, we will disclose the retention terms before collection begins
  • Local Device Cache: Offline inventory data and pending actions may use IndexedDB. Scan originals are not copied into durable browser storage by the current capture flow
  • Log Data: Retained for up to 90 days for security and debugging purposes
  • Analytics Data: Aggregated, anonymous performance data via Vercel Analytics (no personal identifiers)
  • Payment Records: When a household owner deletes their account, the current subscription is stopped and its Stripe customer and saved payment methods are removed. Stripe and Visual Inventory may retain transaction, invoice, or billing records for legally required periods
  • Backup Data: Residual copies may remain in backups for up to 30 days after deletion

You can delete your account at any time. A successful self-service deletion removes your live account and user-specific history immediately. Shared household records remain for other members, and backup, legal, security, or billing records may remain for the limited periods described above.

8. Your Rights and Choices

Depending on your location, you may have the following rights:

  • Access: Request a copy of your personal data
  • Correction: Update or correct inaccurate data
  • Deletion: Request deletion of your account and data
  • Portability: Export your data in a machine-readable format (CSV, JSON)
  • Opt-out: Unsubscribe from marketing communications
  • Restrict Processing: Limit how we use your data in certain circumstances

To exercise these rights, contact us at privacy@visualinventory.ai. We will respond within 30 days.

9. California Privacy Rights (CCPA/CPRA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):

  • Right to Know: Request disclosure of the categories and specific pieces of personal information we collect
  • Right to Delete: Request deletion of your personal information
  • Right to Opt-Out of Sale: We do not sell personal information
  • Right to Non-Discrimination: We will not discriminate against you for exercising your rights
  • Right to Correct: Request correction of inaccurate personal information
  • Right to Limit Use: Limit use of sensitive personal information

Categories of Personal Information Collected: Identifiers (name, email), commercial information (purchase history, inventory data), internet/electronic activity (usage data, device info), photos and audio (shelf/product photos, voice input for transcription), approximate geolocation (IP-based), and inferences drawn from the above.

Do Not Track: We do not currently respond to Do Not Track browser signals.

10. Canadian Privacy Rights (PIPEDA)

If you are a Canadian resident, the Personal Information Protection and Electronic Documents Act (PIPEDA) provides you with rights regarding your personal information:

  • Consent: We collect, use, and disclose your personal information only with your knowledge and consent
  • Access: You have the right to access your personal information held by us
  • Accuracy: You can challenge the accuracy of your information and have it corrected
  • Accountability: We are responsible for personal information under our control

To make a request or file a complaint, contact our Privacy Officer at privacy@visualinventory.ai.

11. Mexican Privacy Rights (LFPDPPP)

If you are a Mexican resident, the Federal Law on Protection of Personal Data Held by Private Parties (LFPDPPP) provides you with rights including:

  • Access (Acceso): Request access to your personal data
  • Rectification (Rectificación): Request correction of inaccurate data
  • Cancellation (Cancelación): Request deletion of your data
  • Opposition (Oposición): Object to the processing of your data

To exercise your ARCO rights, contact us at privacy@visualinventory.ai.

12. Children's Privacy

Visual Inventory is designed for adults (18+). Only adults can create accounts, and we do not knowingly collect personal information from children under 13 (or 16 in certain jurisdictions).

Family Household Features: Our household profile allows adult account holders to indicate the number and types of household members (e.g., "2 adults, 1 child, 1 infant") for the purpose of inventory planning and consumption estimates. This information is entered and managed entirely by the adult account holder. We do not collect names, ages, or any other personal information about minors in the household. Children do not have their own accounts or direct access to the Service.

If you are a parent or guardian and believe we have inadvertently collected personal information from your child, please contact us at privacy@visualinventory.ai, and we will delete such information promptly.

13. International Data Transfers

Your information may be transferred to and processed in the United States, where our primary infrastructure is hosted. Our service providers may also process data in other jurisdictions:

  • Supabase: Database and authentication (United States)
  • Vercel: Hosting and edge network (global edge locations, US primary)
  • Anthropic: Image processing (United States)
  • OpenAI: Voice transcription (United States)
  • Stripe: Payment processing (United States)

For Canadian and Mexican users, your data is transferred to the United States under our data processing agreements with each provider. Data protection laws in the US may differ from those in your jurisdiction.

14. Third-Party Services

We use the following third-party services that may process your information:

  • Supabase: Database, authentication, and file storage — Privacy Policy
  • Stripe: Payment processing (credit card data is handled entirely by Stripe) — Privacy Policy
  • Anthropic: AI image analysis for item recognition (Claude Vision) — Privacy Policy
  • OpenAI: Voice transcription only (Whisper) — Privacy Policy
  • Vercel: Hosting, edge network, and anonymous performance analytics (Vercel Analytics and Speed Insights) — Privacy Policy

These providers process your data under their respective privacy policies and our data processing agreements with them.

15. Data Breach Notification

In the event of a data breach that affects your personal information, we will:

  • Notify affected users via email within 72 hours of confirming the breach
  • Provide details about the nature of the breach, the types of data affected, and the steps we are taking to address it
  • Notify relevant regulatory authorities as required by applicable law (including state attorneys general for US users, the Office of the Privacy Commissioner for Canadian users, and INAI for Mexican users)
  • Provide guidance on steps you can take to protect yourself

16. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by:

  • Posting the new policy on this page
  • Updating the "Last updated" date
  • Sending you an email notification for significant changes

Your continued use of the Service after changes become effective constitutes acceptance of the revised policy.

17. Contact Us

If you have questions about this Privacy Policy or our data practices, please contact us:

Visual Inventory, LLC
Privacy Officer
Email: privacy@visualinventory.ai
General Support: support@visualinventory.ai

By using Visual Inventory, you agree to our Terms of Service and this Privacy Policy.