LEGAL // PRIVACY POLICY
Privacy Policy
VERSION privacy-2026-09-02 · EFFECTIVE [LAUNCH DATE], 2026
This Privacy Policy explains what information Expired LLC (“Expired,” “we,” “us”) collects when you use the Expired application and website (the “Service”), how we use it, and the choices you have. It is part of our Terms of Service. The Service is offered to residents of the United States who are at least 18 years old.
00The short version
- We collect the minimum we need to run a kitchen-inventory service — and nothing for advertising.
- We do not sell your personal information. We do not share it for advertising, and we do not let anyone buy, broker, or rent access to it.
- What you track is nobody’s business but your household’s. We do not monetize, profile, or build marketing audiences from your inventory.
- There are no ads, no third-party analytics trackers, and no tracking cookies in the Service.
- Photos you capture are stored privately and are processed by AI providers only to answer the specific request you made (like reading a date off a package).
- You can ask us to delete your account and data at any time (Section 08).
- This summary is here for convenience. The sections that follow are the operative description of what we do.
01Information we collect
Account information. When you sign in with Expired’s passwordless authentication system, we store your email address, account name, and internal account identifiers. If you add a passkey, we store the public credential data needed to recognize it; your biometric data stays with your device or credential manager and is not sent to Expired.
Household information. Household membership and roles (owner, admin, member), and the email addresses used to send invitations.
Inventory content. The items you track — names, dates, quantities, categories, storage locations, notes — plus your shopping lists. This content syncs across your household in real time.
Photos. Item photos, package-date photos, and receipt photos you choose to capture. They are stored in private object storage and served only through expiring, signed links scoped to your household. Receipt photos are deleted from storage shortly after they are read; photos from receipt scans you never finish are deleted automatically within 7 days.
Voice input. If you use speech to add an item, your speech is converted to text so we can create the entry. On our native apps this conversion is performed by your device’s own speech engine, and the audio does not reach us. On the web, speech is converted to text by your browser’s built-in speech service, operated by the browser’s vendor under its own privacy policy; we receive only the resulting text and do not retain audio. Speech input is optional and you can always type instead.
Product contributions. If you submit missing or corrected product information to the shared catalog, we store the submission (including any product photos) along with your account identifier for moderation.
Support messages. If you write to us through the in-app support or feedback form, we keep your message, your email address, and any details you include so we can respond and track the issue.
Billing information. Payments are handled by Polar for purchases made on our website and in our Android app, and by Apple for purchases made inside our iPhone and iPad app; we never see or store full card numbers or other payment details. We store your billing email, your Polar customer and subscription identifiers or the subscription status, identifiers, and receipt information Apple passes to us, and a record that your account and user ID used the one-time free trial (that record is how we enforce one trial per person — we do not use device fingerprinting or IP tracking for this). We also keep a record of the subscription terms you were shown and of your agreement to them, whichever way you subscribed, because the law requires us to be able to prove what you consented to.
Notification data. If you enable reminders: your push endpoint or device token, platform, browser user agent, time zone, and your notification settings (including quiet hours).
Diagnostics. Error reports and technical events so we can fix problems: error details with your internal user ID attached, and recognition diagnostics (timings, outcomes, file sizes — not the photos themselves and not the recognized text). Our infrastructure providers also keep standard server logs, which include IP addresses, as part of serving any web request. We also collect performance telemetry — how long an operation took and which model handled it — which contains no content from your photos or entries. When you sign in or perform a sensitive action, our security provider may evaluate signals from your browser or device to confirm you are not an automated script.
What we deliberately do not collect: your contacts, your location, advertising identifiers, browsing history, or analytics profiles. The Service contains no third-party analytics SDKs.
We also do not use device fingerprinting, and the product catalog is served from our own database, so browsing the catalog does not send a request from your device to any third party.
02How we use information
- To run the Service: store your inventory, sync it live across your household, and send the reminders you asked for.
- To answer recognition requests you make (Section 04).
- To manage subscriptions, process payments through Polar or Apple, and enforce the one-trial-per-person limit.
- To secure the Service, prevent abuse, and debug problems.
- To respond when you contact us for support.
- To meet our legal obligations, including keeping records of subscription consent and of tax and accounting information.
We process this information to provide the Service you asked for, to meet our legal obligations, to keep the Service secure and prevent abuse, and with your consent where we ask for it — for example, push notifications, which you can withdraw at any time. Where a law requires us to identify a legal basis for processing, those are the bases we rely on. Section 11 explains where we offer the Service.
03What we never do
- We do not sell personal information — yours or your household’s — for money or anything else.
- We do not share personal information for cross-context behavioral or targeted advertising.
- We do not show ads, place marketing pixels, or allow ad-tech trackers in the Service.
- We do not use your inventory, photos, or habits for market research, trend reports, partnerships, or any purpose other than running the Service for you.
- We do not use your content to train our own AI models, and we use our AI providers on commercial terms under which the content we send is not used to train their models. As of the effective date of this policy, OpenAI states that data sent to its API is not used to train or improve its models unless the customer opts in, and Anthropic states that content from its commercial products, including its API, is not used for model training. Each provider keeps a short-lived copy for abuse monitoring — currently up to 30 days — and then deletes it. There are narrow exceptions we want you to know about: either provider may keep material longer where the law requires it or where it is needed to investigate a violation of that provider’s usage policy, and images sent to OpenAI are automatically screened for child sexual abuse material, with any image the screen flags retained for human review. We verified these positions against each provider’s published terms on the effective date of this policy, and if a provider changes its position we will change providers or update this policy before continuing.
04AI recognition features
Some features send data to third-party AI providers — only when you actively use the feature, and only to produce the result you asked for:
- Photo recognition (naming an item from a photo): the photo is processed by OpenAI or Anthropic.
- Expiration-date reading: the photo (and any text extracted from it, optionally via Google Cloud Vision OCR) is processed by Anthropic or OpenAI.
- Receipt scanning: receipt photos are processed by Anthropic.
- Product contribution review: submitted product photos may be scored by Anthropic to assist our moderators.
- Speech to text on the web: if you add an item by voice in a web browser, the audio is converted to text by your browser’s built-in speech service, operated by the browser’s vendor under its own privacy policy; we receive only the resulting text and do not retain audio.
Providers access photos through short-lived signed links. We keep the suggestion that comes back (so you can correct it) and technical diagnostics — we do not send your photos anywhere except to fulfill your request. AI output is an estimate and can be wrong; the Terms of Service explain why you should verify it. Each of the AI providers named above acts as our processor under a data processing agreement and may use what we send only to return the result you asked for. Your browser’s speech service is different. It is a feature of the browser you are already using: the audio travels from your browser to the browser’s vendor without passing through us, we have no agreement with that vendor, and the vendor’s own privacy policy governs what it does. Recognition features are optional; you can add every item by hand and never send a photo to a provider.
05Service providers
We share personal information only with the service providers that make the Service work, and only so they can provide their service to us:
- Convex — application database and backend.
- Better Auth — the authentication framework that runs inside our own stack and holds identity and passkey records.
- Cloudflare — hosting, networking, bot and security checks (Turnstile), and private object storage (R2) for photos.
- Resend — delivery of one-time sign-in codes and other transactional email.
- Polar — subscription and scan pack billing for purchases made on our website and in our Android app. Polar is the merchant and seller of record for those purchases, which means Polar decides how to handle the transaction data it collects and is an independent controller of that data, not merely our processor. Polar’s own privacy policy governs the payment transaction and the customer portal you use to manage your subscription.
- Anthropic, OpenAI, Google Cloud Vision — AI recognition (Section 04).
- Sentry — error monitoring. We disable session replay and automatic collection of personal details; error reports may include your internal user ID.
- Honeycomb — performance telemetry. It receives timing and technical metadata about operations, not the content of your photos or entries.
- Apple — in-app purchase billing for subscriptions and scan packs bought inside our iPhone and iPad app, and notification delivery through APNs. For purchases, Apple is the seller of record and an independent controller of the transaction data it collects; we receive only the subscription status, identifiers, and receipt information Apple passes to us, never your payment details. Apple’s privacy policy governs the payment transaction.
- Google (FCM) and your browser’s push service — delivery of the notifications you enable.
Beyond providers, we disclose personal information only: within your household (that’s the point of a shared inventory); if the law genuinely requires it; as part of a merger or acquisition (in which case these commitments continue to apply to your data); or at your direction. Approved product contributions become part of the shared product catalog as product facts (barcode, name, brand) — without public attribution to you.
Each provider we share personal information with is bound by an agreement with us that requires it to protect your personal information to the same or an equivalent standard as this policy, and to use what we send only to provide its service to us. Two things described in this policy work differently: your browser’s built-in speech service and your browser’s or device’s push service. Both are features of software you already use, we have no agreement with their vendors, and each vendor’s own privacy policy applies. Speech audio travels from your browser to the browser’s vendor without passing through us. For push notifications, your browser or device gives us a vendor-operated delivery address, and we send each notification there in encrypted form that the vendor cannot read. We keep a current list of our providers here and will update this section before adding a provider that receives personal information.
06Cookies and local storage
- Session cookie (essential): keeps you signed in. HTTP-only and protected with secure cookie settings.
- App markers and preferences: a cookie identifying our native app shell, and local storage for things like theme and filter preferences. These stay on your device.
- Security check: our bot-protection provider may set a short-lived token to record that a challenge was passed.
We use no advertising or cross-site tracking cookies, and no third-party cookies.
07Data retention
- Authentication records: active sign-in sessions and passkeys remain until they expire or you remove them. After account deletion, we may retain a revoked, pseudonymous authentication identifier where necessary to prevent unauthorized relinking, investigate abuse, and maintain an audit trail; one-time migration claims are deleted with your account.
- Inventory and account data: kept while your account is active.
- Deleted items: recoverable for 7 days, then permanently purged along with their photos.
- Live-sync events: purged after about 7 days.
- Notification delivery events: retained for 90 days; expired records are swept daily.
- Billing records: kept as required for tax, accounting, and audit purposes, and the free-trial record is kept to enforce the one-trial limit. Records of the subscription terms you agreed to are kept for three years, or one year after your subscription ends, whichever is longer, because the law requires it.
- Diagnostics: 90 days for error reports and recognition diagnostics, after which they are automatically purged.
- Account deletion: when you ask us to delete your account (Section 08), we delete your personal data except the minimal records we must keep for the purposes above, and residual copies leave backups on their normal cycle within 7 days.
08Your rights and choices
These apply to everyone, not just where the law requires them. Export and deletion are self-serve in the app under Settings → Your data; for anything else, email privacy@expired.app and we will act on your request within 30 days:
- Access / export — download a copy of the personal data and inventory content we hold about you anytime from Settings → Your data.
- Correction — fix inaccurate account data (most content you can already edit in-app).
- Deletion — delete your account and associated data yourself from Settings → Your data (see Section 07 for what is retained).
- Notifications — disable push anytime in the app or your device settings.
- AI features — entirely optional; you can always enter items manually.
- Authorized agents — you may use an agent to make a request for you; we will ask for proof that you authorized them.
- Appeals — if we decline a request, we will tell you why, and you may appeal by replying to that message or writing to privacy@expired.app. We will respond to an appeal within 45 days and, if we still decline, will tell you how to complain to your state attorney general.
- Verification — we confirm requests through the email address on your account. We may ask for more information if we cannot confirm who you are, and we will not create an account or collect new data just to verify a request.
Because we do not sell or share personal information for advertising, there is nothing to opt out of under laws like the CCPA/CPRA, and opt-out preference signals such as Global Privacy Control require no action from us to honor — but we treat them as valid requests where they apply. We will never discriminate against you for exercising privacy rights. We also do not process sensitive personal information for the purpose of inferring characteristics about you. Residents of Texas, California, and other states with comprehensive privacy laws have the rights described above regardless of whether those laws apply to us by their own terms; we have chosen to offer them to everyone.
09Security
Data is encrypted in transit; photos are reachable only through expiring signed links; household data is scoped by role-based access; and production access is restricted. No service can promise perfect security — if we learn of a breach affecting your personal data, we will notify you as required by law at the email on your account. Keep your email account secure, since access to it is how someone signs in as you.
10Children
The Service is intended only for adults. It is not directed to children, we do not knowingly collect personal information from anyone under 18, and we do not knowingly allow anyone under 18 to create an account. If you believe someone under 18 has an account, contact us at privacy@expired.app and we will close it and delete the data.
11International users
We operate from the United States, we offer the Service only in the United States, and your information is processed in the United States. We do not target or market the Service to people in the European Economic Area or the United Kingdom, our pricing and content are directed to United States consumers, and we have not appointed a representative under Article 27 of the GDPR because we do not offer the Service to people in those regions. If you access the Service from outside the United States, you do so on your own initiative and you understand your data is transferred to and processed in the United States. If we begin offering the Service in the EEA or the UK, we will update this policy first.
12Changes to this policy
Each version of this policy is dated and identified at the top of this page. If we make a material change — especially any change to Section 03 — we will notify you and, where required, ask for your agreement before it applies to you. We will never weaken the commitments in Section 03 retroactively.
13Contact
Expired LLC
5900 Balcones Drive, Suite 100, Austin, TX 78731
privacy@expired.app