Stokit
FeaturesSupport

Privacy Policy

Effective date: August 25, 2026 · App: Stokit · Developer: Abdul Adil · Contact: qadeeradil14@gmail.com

Stokit is a household pantry manager and shopping assistant. This policy describes the data used by the current Stokit app, why it is used, who receives it, how long it remains, and how to delete an account.

Stokit does not sell personal information, show third-party advertising, use data for cross-app tracking, or collect contacts, calendar data, microphone audio, health data, behavioural analytics, or developer crash telemetry.

1. Data Stokit uses

1.1 Account and profile

  • Email address — used for account creation, sign-in, email verification, and password reset.
  • Password — submitted directly to Supabase Auth. Stokit does not persist the password on the device. The app stores Supabase session credentials in the device's secure storage so you remain signed in.
  • Account identifier — Supabase assigns a random user ID.
  • Display name — optional and visible to members of each household you share.
  • Profile photo — optional. It is stored in a private, user-scoped Supabase Storage bucket and can be viewed by you and active members of households you share. You can remove it in Settings → Account.

Stokit currently requires an account. It does not offer guest or anonymous use.

1.2 Household, pantry, shopping, and store data

Supabase is the authoritative cloud store for household data. This includes household names and memberships; pantry item names, quantities, units, storage locations, stock states and optional expiry dates; shopping needs and store assignments; store names, addresses, provider place identifiers and coordinates; trips, stops, purchase outcomes and activity derived from those records; receipt totals and line items; and household shopping preferences.

The app keeps limited information on the device, including the signed-in session, a random app-install device ID, pending offline changes, notification preferences, geofence state, appearance settings, and temporary receipt files. Most household views are loaded from Supabase into memory rather than stored as a permanent device copy.

1.3 Receipts

If you photograph or upload a receipt, Stokit temporarily keeps a local copy while uploading it and stores the image in the household's private receipt-assets bucket. A Supabase Edge Function sends the receipt image and an extraction instruction to OpenAI. OpenAI returns extracted merchant, date, subtotal, tax, total, and line-item data. Stokit sends the request with API response storage disabled, but OpenAI may retain API abuse-monitoring information under its own policy. Extracted values are stored in the household and may be corrected in the app.

If you enter a total manually, the amount is saved to Supabase but no receipt image is uploaded or sent to OpenAI.

1.4 Location

  • Store search — when you request nearby results, coordinates are sent to Stokit's authenticated Supabase Edge Function and then to Google Places. Text searches send the query and may include coordinates as a search bias. Stokit stores the selected store's returned name, address, place identifier, and coordinates.
  • Store Arrival Alerts — optional and off until enabled. Stokit requests foreground and background location permission and registers operating-system geofences for the current trip stop. The operating system performs the boundary comparison. Stokit does not store a route or continuous location history.

On a qualifying geofence entry, the device records limited deduplication state, shows a local reminder, and automatically sends an arrival notification to eligible household members through Supabase and Expo. That event sends the household, trip and store identifiers and notification text, but not the device's current coordinates. Geofence exit state remains on the device.

1.5 Notifications

If notifications are enabled, Stokit stores an Expo push token with the account, household, app-install device ID, and platform. Other household members cannot read the token. Notify Family sends a notification only after the shopper explicitly presses that control. Store Arrival Alerts can automatically send an arrival notification after the user enables that feature.

When notifications are disabled or the user signs out, that device's token is marked inactive; it may remain in the database so the same device can safely reactivate it later. Account deletion removes the account's push tokens and notification preferences.

1.6 Store logos

For recognized chains, Stokit requests an icon from Google's favicon service using the chain's public domain. The request does not contain a Stokit account, household, list, or location identifier. Because the request is made from the device, Google can receive ordinary network information such as the device's IP address and request metadata. Unrecognized stores do not make this request.

1.7 Recipes

Recipe suggestions are requested directly from TheMealDB. These requests include ingredient keywords and meal identifiers. Stokit does not add an account or device identifier, but TheMealDB can receive ordinary network information such as the device's IP address and request metadata. Returned recipe details and images are displayed but are not household sync authority.

1.8 Shopping preferences and spending

The household's default unit and optional weekly budget are stored in Supabase. Weekly spending is calculated from finalized receipt totals when displayed; it is not stored as a separate weekly-spend record.

1.9 Diagnostics

Stokit maintains a small in-memory diagnostic buffer containing technical event categories, timestamps, mutation identifiers and entity identifiers. It is not sent to a developer analytics or crash service and disappears when the app process ends.

2. Household sharing

Active household members can see that household's pantry, shopping needs, stores, trips, receipts, spending totals, and activity, plus other members' display names and profile photos. They cannot read another member's email address, password, secure session credentials, or push token through the app.

An invite code allows a signed-in person to join the household. Resetting the code revokes the previous code without removing existing members.

3. Service providers

ServicePurposeData involvedPolicy
SupabaseAuthentication, database, sync, private file storage, Edge FunctionsEmail, account ID, household data, device ID, receipt and profile images, push tokensSupabase Privacy
OpenAI APIReceipt extractionReceipt image, extraction instruction, extracted resultOpenAI Privacy
Google PlacesStore searchSearch query or coordinates; returned place dataGoogle Privacy
Google favicon serviceRecognized chain iconsPublic chain domain and ordinary network informationGoogle Privacy
TheMealDBRecipe suggestionsIngredient keywords, meal identifiers, ordinary network informationTheMealDB
ExpoPush-notification relay and Expo application infrastructurePush token, platform, notification text and trip/store identifiersExpo Privacy
Apple Push Notification service / Firebase Cloud MessagingPlatform notification deliveryPlatform token, notification text and routing dataApple Privacy / Google Privacy

4. Storage, retention, and security

Active household records are retained while the household exists. Completed trips, receipts, prices, mutation records, and deletion tombstones can remain for the household's lifetime because they support history, synchronization, conflict prevention, and household spending. Deleted items and stores may remain as hidden database tombstones rather than being immediately hard-deleted. There is currently no general time-based purge of household history.

Receipt and profile images remain until removed by an available in-app action, account deletion, or deletion of a household with no remaining members. Temporary local receipt files are removed after processing or by cleanup. Signing out removes the local authentication session and disables notifications, but device preferences and pending local state can remain. Account deletion clears Stokit's local application state and known secure account/device keys.

Supabase database-backup retention depends on our Supabase plan and configuration. Storage objects are managed separately from database backups. Provider backup or security copies may remain for the period stated in the provider's applicable terms.

Network requests use HTTPS. Supabase row-level security and constrained database functions restrict household records to active members of the relevant household. Private images use access-controlled Storage buckets. No security system can be guaranteed infallible; contact us if you believe data has been accessed improperly.

5. Deletion

Items and stores can be removed in the app. Shopping needs can be cancelled or removed. Non-finalized receipts can be deleted; finalized receipts remain part of household history but their totals and line items can be corrected. Stokit does not currently offer a separate command to erase a completed trip while retaining the household.

To permanently delete your account, open Settings → Account → Delete Account and type DELETE. You may also contact qadeeradil14@gmail.com for assistance.

Account deletion removes the Supabase Auth user, profile, active and historical memberships, push tokens, notification preferences, user-specific mutation records, and Stokit's local app state. Profile photos and receipt images uploaded by your account are deleted. If another active member remains in a household, household-owned structured records stay available to that household and authored-by fields are anonymized. If the deleting user is the only owner, the oldest remaining active member becomes owner. If no active member remains, the household and its database records are purged. Removing your receipt image from a shared household does not automatically remove the structured receipt values already shared with that household.

6. Choices and requests

You can decline camera, photo-library, location, or notification permission and continue using features that do not require it. Permissions can be changed in system Settings. Arrival alerts and push notifications can also be disabled in Stokit.

You may request access, correction, or deletion of personal information by emailing qadeeradil14@gmail.com. We will respond within 30 days, subject to applicable law and identity verification. Depending on your location, you may also have a right to complain to a data-protection regulator.

7. Children

Stokit is not directed to children under 13 in the United States or under 16 in the European Economic Area. We do not knowingly collect their personal information. Contact us if you believe a child created an account.

8. Changes

We will update the effective date when this policy changes. If a change materially affects how Stokit uses data, we will provide an appropriate in-app or service notice.

9. Contact

Privacy, support, access, and deletion requests: qadeeradil14@gmail.com.

Stokit

Pantry and shopping, finally in sync.

FeaturesSupportPrivacyTermsAccount Deletion

© 2026 Stokit