Early Public draft
Privacy & data use
This is a plain-language Early Public draft, not a substitute for formal legal review. It describes the product as it works today.
What Cost of Life uses
Cost of Life uses your sign-in email, receipt images, the information read from those receipts, shopping-list text, and the account settings you choose. A receipt can contain store, purchase, payment, and item details, including the last four card digits when printed.
If you enable notifications, Cost of Life also uses a push-notification token for your device to deliver them.
Location is optional and off by default. If you turn it on, Cost of Life can record it when you photograph a receipt so a price can be matched to the right store. Cost of Life does not collect location in the background.
Where it goes
Cost of Life uses service providers to run sign-in, storage, receipt processing, notifications, and the application database. Receipt images are sent to a third-party AI service to read them; item names may also be sent as text to help resolve a receipt line.
What stays private
Early Public keeps your receipts, receipt images, payment evidence, and personal purchase history private to your account. Cost of Life does not publish receipt-derived observations or make them available as community data in Early Public.
When you delete an account, you can explicitly choose to retain de-linked price observations without account, receipt, or personal-catalog identity. That optional retention remains internal; it does not enable publication or community price data. Any later public contribution would need its own deliberate, purpose-specific consent and release gate.
Your controls
You can request an export of your account data from Settings. You can also delete your account from Settings and choose whether associated price observations are removed or retained without your account identity.
Cost of Life deletes receipt and capture files it can identify during account deletion. A receipt or capture upload that finishes after the final cleanup sweep can leave an unreferenced storage object with no automatic expiry. Cost of Life cannot currently promise when that rare residual object is purged. For files Cost of Life successfully deletes, AWS may keep noncurrent storage versions for up to 30 days.
Questions
Email support with questions about your account or data.