Overview
grocertap is a paid-upfront iOS grocery-list app. It has no advertising, analytics SDK, tracking, developer account system, Supabase service, or separate developer server. The app uses Apple’s iCloud and CloudKit services to sync and share a household list.
This policy explains the data the app handles, where it goes, why it is needed, and the choices available to you. Apple’s own privacy terms also apply to your use of iCloud and Apple’s system services.
Data and purpose
grocertap handles the content needed to provide the list:
- household name and member display names;
- item names, quantities, pack sizes, prices, categories, emoji, recipe context, and favourites;
- who added or bought an item and relevant timestamps;
- purchase history, aisle corrections, aisle order, and recent list activity;
- stable record identifiers, deletion markers, and synchronisation metadata used to merge changes safely; and
- your iCloud account identity as supplied by CloudKit, used to bind the local cache to the correct account and household.
This information is used only to display, organise, remember, synchronise, and share your household grocery list. grocertap does not use it for advertising, analytics, profiling, or sale.
iCloud, CloudKit, and household sharing
A household uses one custom CloudKit zone. A private household is stored in the owner’s private iCloud database. When the owner invites named participants through Apple’s sharing sheet, shared records become available through the participants’ shared iCloud databases with read-and-write access. Public access is disabled.
Household and member names, item and preference payloads, and any saved activity snapshot are written using CloudKit encrypted fields. Stable record identifiers, event kind, actor identifiers, occurrence and merge timestamps, deletion markers, and other merge metadata remain queryable so devices can identify, order, and reconcile changes. Do not share a household with anyone who should not be able to see or change its contents.
If you accept an invitation while you already have a private list, the app asks whether to merge that local content into the shared household or keep it private. It does not upload that existing list without that choice.
Speech recognition and microphone
Voice input is optional. grocertap asks for speech-recognition and microphone permission when you use it. You can deny either permission and continue adding items by text, or change the permissions later in iOS Settings.
The app uses Apple’s Speech framework and requests on-device recognition where the selected language and device support it. In other configurations, Apple’s speech service may process audio to provide the transcription. grocertap does not save raw microphone recordings. It keeps only the text items you review and confirm, then handles that text like any item you type.
Widget, share extension, and App Group
The main app, widget, and share extension use an Apple App Group container for one local list document and a small command queue. The widget reads that local document and checks that the current iCloud account matches before it displays household data. It can queue an item as bought.
The share extension receives only text you explicitly select and send to grocertap through the iOS share sheet. It does not read the clipboard. It queues the selected item text for the main app to apply and synchronise.
Data retention, deletion, and your choices
The active list and remembered preferences remain locally and in CloudKit while you keep using them. Live item deletions synchronise through CloudKit deletion records. Recent removed or bought activity can remain in the app’s recoverable history; activity is limited to 200 records, and remembered purchase dates are limited to the 12 most recent dates per item. Bought items leave the live list immediately and are archived from the Bought view according to your selected cleanup timing.
You can delete individual live items in the app and manage or stop household sharing through Apple’s sharing controls. A participant can leave a shared household; an owner can remove participants or stop sharing. These actions may affect other household members’ access.
Deleting the app removes its local container from that device, but does not by itself guarantee deletion of records already stored in iCloud or shared with other participants. grocertap does not operate a separate account database from which the developer can erase your iCloud content. For help understanding the available app and iCloud controls, contact support before sending any sensitive list content.
You can withdraw microphone or speech-recognition permission at any time in iOS Settings. You can also stop using voice input without affecting typed list entry.
Security
grocertap relies on Apple’s iCloud account authentication, CloudKit access controls, and Apple’s security for data in transit and on its servers. The app also uses CloudKit encrypted fields for user-entered values and atomic local writes for its App Group document. No method of storage or transmission is completely risk-free.
When an iCloud account changes, grocertap hides the previous account’s cached household data and blocks its pending uploads. The cached bytes are preserved locally so returning to the original account can resume safely.
Children
grocertap is a general household utility and is not directed to children. It does not ask for a date of birth or create a separate profile with the developer. A parent or guardian should manage the device, iCloud account, and household invitation used by a child.
International availability
App Store and iCloud availability varies by country or region and by the settings of the Apple account. The app interface is in English; grocery-item input supports English and Portuguese. No claim of worldwide availability is made.
Changes to this policy
This policy may change when the app’s behaviour or applicable requirements change. The updated policy will be posted here with a new effective date. Material changes will not be applied retroactively in a way that misrepresents earlier data handling.
Contact
Developer: Marco Brito
Email: marconmbrito@gmail.com
For support, include the iOS version and a short description of the issue. Do not email grocery-list content you consider sensitive.