Privacy Policy
What this policy says, in short
- We collect only what's needed to run the app.
- Guest users send us nothing — all data stays on your device.
- For signed-in users, we use Firebase to store your account, lists, and inventory.
- We don't sell your data, show ads, or share it with anyone outside your family home.
- You can delete your account and your data at any time.
Who we are
Kitchen Khata ("the app", "we", "us") is a grocery management application for Android, developed and operated by Onlybizbasics.com from Pimpri-Chinchwad, Maharashtra, India. We act as the data controller for personal information collected through the app.
This Privacy Policy explains what data we collect, why we collect it, how we store it, and what rights you have. It applies to all users of the Kitchen Khata Android app and any related services.
Who this policy applies to
The app supports three categories of users, and the data we collect depends on which category applies to you:
- Guest users — people using the app without signing in. We do not collect any account or personal information from guest users. Your data stays on your device.
- Free users — signed-in users on the free tier. We collect account information (email, name) and household-related data needed for shared lists, inventory, and family features.
- Premium users — signed-in users on a paid subscription. (Premium tier is coming soon. We will update this policy before any Premium-only data collection begins.)
What we collect
3.1 Account information
Collected only when you sign up or sign in:
- Email address (from email/password sign-up or Google Sign-In)
- Display name (from sign-up form or Google account)
- Phone number (optional — only if you choose to add it in your Profile)
- Profile avatar selection (Man / Woman / Boy / Girl) — stored locally on your device
- Firebase User ID (UID) — a unique identifier automatically generated when you sign up. We use it as the key to associate your profile, lists, and inventory with your account. It is not visible to other users and not used for advertising.
3.2 Household and grocery data
Collected only when you use the relevant features:
- Grocery list items, quantities, and categories
- Home inventory items and stock levels
- Recurring item schedules (e.g., daily milk delivery)
- Saved list templates
- Custom items you add to the catalogue
- Purchase and consumption events (when you mark items as purchased or used)
3.3 Family home data (Free users with a shared home)
- Home name and 8-character invite code
- List of members in your home and their roles (admin or member)
- Linkage between your account and your home (homeId)
3.4 Notification preferences
- Which notification types you have enabled (inventory reminders, low-stock alerts)
- Your selected shopping days (e.g., Sunday and Wednesday)
- Last app open timestamp (used to skip reminders if you recently opened the app)
3.5 Device and technical data
- Firebase Cloud Messaging (FCM) token — stored on login to enable future push notifications. The app does not currently send push notifications, but the token is collected so the feature can be activated later without requiring a new sign-in.
- Authentication tokens managed by Firebase Authentication (handled by Google's Firebase SDK)
- App crash and performance data is not currently collected. We do not use Firebase Crashlytics.
3.6 Voice input data
If you use the voice input feature (Free users only), spoken audio is processed by your device's built-in Android Speech Recognizer (provided by Google as a system service). The audio is sent to Google's speech recognition service, not to Kitchen Khata. We only receive the recognized text result, which is then parsed locally on your device. We do not store voice recordings.
When the voice feature cannot match your spoken words to any item in our catalog, we may save the transcribed text (not the audio) to help us improve item recognition for future users. This text contains only the words you spoke, paired with your user ID for audit purposes, and is used solely to add new aliases to our catalog (for example, regional words for vegetables and spices that we haven't yet mapped). You can avoid this entirely by not using the voice feature, or by speaking item names that match our catalog.
3.7 What we do not collect
- Your location
- Your contacts
- Photos or media files
- Browsing history outside the app
- Advertising identifiers
- Payment information (no payments are processed yet — Premium tier is coming soon)
Why we collect it
We collect data only for these purposes:
- To provide app functionality you have requested (saving your grocery list, syncing inventory across family members, sending reminders you have enabled)
- To authenticate you securely via Firebase Authentication
- To enable family collaboration when you create or join a home
- To remember your preferences (notification settings, shopping days, favorite items)
- To send you in-app notifications you have explicitly enabled (inventory reminders, low-stock alerts, shopping day reminders)
- To prepare for future features such as Premium plan billing and family push notifications
We do not use your data for advertising, profiling, or sale to third parties.
How we store it
5.1 Cloud storage (Firebase)
Account information, household data, and shared family data are stored in Google Firebase services:
- Firebase Authentication for sign-in (email/password and Google Sign-In)
- Cloud Firestore for grocery lists, inventory, recurring items, saved lists, family home data, and consumption logs
Firebase is operated by Google LLC. Data is stored on Google's servers, which may be located outside India. We rely on Google's security and compliance practices for the underlying infrastructure. Access is protected by Firestore security rules that prevent users from reading or modifying data belonging to other accounts or other family homes.
All communication between the app and Firebase services is encrypted in transit using HTTPS/TLS. This is enabled by default in the Firebase Android SDK and cannot be disabled.
5.2 On-device storage
Some data is stored only on your device, in Android SharedPreferences. This data does not leave your device unless you explicitly sign in and sync it:
- Favorite items and quantity preferences
- Notification preferences and shopping day selections
- Saved recipes (your bookmarks)
- In-app notification history (the notifications bell on your home screen)
- Avatar selection
- Cached plan tier (so the app works briefly when offline)
Once you sign in, your grocery list, inventory, and consumption logs are stored in Firebase Cloud Firestore — not in on-device SharedPreferences. Every signed-in user automatically has a personal household so this data is available across devices and can be shared with family members. Guest users' data is the exception: it stays only on the device until guest mode ends.
5.3 Guest mode
If you use the app as a guest, all your data is stored only in on-device SharedPreferences. Nothing is sent to our servers. If you later sign up for an account, your guest data is migrated to your new account so you do not lose your work.
How we share data
We do not sell your personal information. We share data only in these specific situations:
- Within your family home: when you join a household, other members of that household can see the shared grocery list, shared inventory, your display name, and your role (admin or member). This is the core function of the family feature.
- With Google Firebase: as our backend infrastructure provider. Google processes data on our behalf under their data processing terms.
- With Google Speech Services: only when you actively use the voice input feature (your device sends audio to Google for transcription, as a standard Android system service).
- If required by law: we may disclose data if compelled by valid legal process from Indian authorities.
We do not currently share data with advertisers, analytics platforms, or any third-party marketing services. Firebase Analytics is not integrated in the current release. If we add analytics in a future version, this policy will be updated before we begin collecting that data.
Permissions the app requests
| Permission | Why we request it | When |
|---|---|---|
| Internet | To sync your data with Firebase when you are signed in. | Always (signed-in users only). |
| Post Notifications (Android 13+) | To send the in-app reminders and alerts you have explicitly enabled in Profile. | Asked once on first run; you can decline. |
| Microphone | To capture voice input when you actively tap the voice button. Audio is processed by Android's system speech recognizer, not by us. | Asked the first time you use voice input. Optional. |
We do not request location, camera, contacts, or storage access in this version. Camera access may be added in a future version for barcode scanning, and we will update this policy before that change.
Data retention
We retain your data for as long as your account is active. Specifically:
- Account data: kept until you delete your account
- Household data: kept until you leave the home or the home is deleted; family members retain access to shared data they were part of, since it belongs to the household, not to a single user
- On-device data (SharedPreferences): kept until you uninstall the app or clear app data from your phone settings
- FCM token: refreshed periodically by the system; updated on each sign-in
We do not have an automatic deletion policy for inactive accounts in this version. If you stop using the app, your data remains accessible to you the next time you sign in.
Your rights and choices
As a user of Kitchen Khata, you have the following rights regarding your data:
- Access — view all your data within the app at any time (your profile, lists, inventory, family home)
- Correction — edit your name, phone number, avatar, and notification preferences from your Profile
- Deletion — request deletion of your account and associated data (see Section 10)
- Withdraw consent — sign out, leave your family home, or use the app as a guest at any time
- Disable notifications — turn off any notification type from Profile or from your Android system settings
- Disable voice input — simply do not use the voice button; permission can be revoked from Android settings
Account deletion
You can delete your Kitchen Khata account and the personal data associated with it through any of the following methods:
- In-app (recommended): open Profile → scroll to "Delete Account" → confirm. Your account and associated personal data are removed immediately, without needing to contact support.
- Web request (without the app): visit our account deletion page and submit a deletion request.
- Email request: write to support@kitchenkhata.com from the email address registered to your account.
When your account is deleted (whether in-app or via request), the following are removed within a reasonable timeframe (typically immediately for in-app deletion, within 30 days for email/web requests):
- Your user profile (name, email, phone, avatar selection, plan tier)
- Your saved lists and any personal data tied to your user ID
- Your authentication record in Firebase
Important note about shared family data: items, inventory entries, and activity log entries you contributed to a family home will remain visible to other members of that home, since this data belongs to the household and removing it would erase shared history for other users. Your name on those entries will be replaced with "Removed user". If you want to remove yourself from a family home before deletion, leave the home first from the Family Home screen.
Contact us
For questions about this Privacy Policy, requests to access or delete your data, or any other privacy concern, contact:
- Data controller: Onlybizbasics.com
- Email: support@kitchenkhata.com
- Location: Pimpri-Chinchwad, Maharashtra, India
We will acknowledge your request within 7 days and respond fully within 30 days.
Children
Kitchen Khata is not directed at children under 13 (or under 18 in jurisdictions where 18 is the relevant age). We do not knowingly collect personal information from children. If you believe a child has provided personal information through the app, contact us at support@kitchenkhata.com and we will delete the data.
Changes to this policy
We may update this Privacy Policy as the app evolves. When we make material changes (for example, when we add Premium subscriptions, push notifications, analytics, or barcode scanning), we will:
- Update the "Effective date" at the top of this document
- Publish the new version on this page
- Notify signed-in users in the app on next launch
Continued use of the app after the effective date of a revised policy means you accept the revised terms. If you do not agree, you may delete your account.
Jurisdiction
This Privacy Policy is governed by the laws of India. The Digital Personal Data Protection Act, 2023 (India) applies to our processing of your personal data. Any disputes shall be resolved in the courts of Pune, Maharashtra, India.
