AnoSpend
Skip to content
AnoSpend
  • How it works
  • Features
  • Privacy
  • Support
  • Coming soon
AnoSpend
  • How it works
  • Features
  • Privacy
  • Support
Coming soon

AnoSpend Privacy Policy

Last updated 9 October 2026

AnoSpend is a shared shopping-list app for households. This policy explains what personal information the app collects, why, where it is stored, and what you can do about it.

AnoSpend is operated by Anola Technologies Inc., a company incorporated in British Columbia (incorporation number BC1611301) and based in Vancouver, Canada. Two privacy laws apply, and this policy is written to both: British Columbia's Personal Information Protection Act (PIPA), which covers a business operating in the province, and Canada's Personal Information Protection and Electronic Documents Act (PIPEDA), which covers personal information that crosses a provincial or national border, and ours does, because our providers are in the United States.

AnoSpend is in pre-release development. It is not publicly available. Today the only accounts are those of the development household; accounts for testers invited to the TestFlight beta will follow. This policy is published now so it is in place before that happens.

What we collect

InformationWhy
Email address To create your account, sign you in, and send household invitations
First and last name So other household members can see who added or bought an item
Your shopping lists and items The core function of the app: items, quantities, prices, notes and categories
Your purchase history To work out what you buy regularly, so the app can tell you what you are likely running low on
Your budget settings and spending totals To show what a trip cost against the cap you set
Household membership and permissions To control who can see and change a shared list
That you confirmed you are 19 or older, and when AnoSpend is for adults. We keep the fact that you ticked the box, and the time, so we can show it if we are asked.
For a member under 19 only: their date of birth, and who confirmed they are the parent or legal guardian, and when To set the account up, to apply the limits described under “Children and teens” below, and to open the account up on their 19th birthday. The date of birth is deleted then; the record of the guardian's confirmation is kept while the account exists

We never ask your device for its location. We do not collect contacts, advertising identifiers, or analytics about how you use the app, and there is no advertising in AnoSpend. We do not sell personal information to anyone. The only photograph we ever handle is a receipt you choose to scan, described below, and we do not keep it.

One thing a photograph can carry. Phone cameras record hidden details inside a photo file: typically the date and time, the camera model, and, if you have given your camera app permission to use location, the place the picture was taken. The app removes these before a receipt photo leaves your phone: it re-saves the picture as a plain image, which does not carry them. We never read them, extract them, or store them, and nothing in AnoSpend records where you are.

Where it is stored, and who else processes it

AnoSpend relies on five service providers. Each one only receives what it needs to do its job.

ProviderWhat it handlesWhere
Supabase Your account credentials and the app's databaseUnited States
RenderRuns the AnoSpend serverUnited States
Resend Sends account emails, invitation emails, and the copy of your data you can request from Settings, which is delivered as a file attached to an email, so Resend handles everything that copy containsUnited States
Google (Gemini) Turns what you say into list items when you use voice input, and reads a receipt photo when you scan oneUnited States
Google (Firebase Hosting) Serves this page and the Terms of Use, so it receives the address of the device that reads themUnited States

This means your information is stored and processed outside Canada, in the United States, and is subject to the laws of that country, including lawful access by US authorities. We use these providers because they are what the app is built on; if that changes, this policy will be updated and the date above will change with it.

Voice input and automated processing

Voice input is optional. If you never use it, nothing in this section applies to you and nothing is ever sent for processing.

When you do use it, your phone converts your speech to text using its own built-in speech recognition, and AnoSpend sends only that text onward. We never receive or store the audio. Depending on your device and its settings, that speech-to-text step may be performed on the phone itself or by your phone's maker (Apple on an iPhone, Google on an Android device), under their own privacy policies rather than ours.

The text we send goes to Google's Gemini service, which works out which grocery items you meant. Saying "add bread and butter" sends the words "add bread and butter", and nothing else about you: not your name, not your email, not your household, and not the rest of your list.

We use a paid Gemini tier specifically because Google does not use data submitted on it to train its models. We do not use free AI tiers for this reason. Google may hold what we send briefly to detect abuse of its service; we do not control that period, and we do not keep a copy ourselves.

This processing happens in the United States, so using voice input means that text crosses the border, and is subject to the laws of that country.

The result is always shown to you for confirmation before anything is added to your list. Nothing is added automatically, and you can edit or discard any of it. If we cannot work out what you meant, we say so and ask you to try again rather than guessing.

Categories are assigned by a fixed list of words held on our own server, with no AI involved. No automated step described here has any legal or similarly significant effect on you: everything is a suggestion you confirm.

If you would rather not use it, simply don't. Every part of the app works without voice input, and it can be avoided entirely by typing.

Scanning a receipt

Scanning a receipt is optional, offered once after a shopping trip, and easy to decline. If you never use it, nothing in this section applies to you.

If you do, the photo is sent to Google's Gemini service, which reads the items and prices off it, together with the names of the items on your list so it can tell which purchase matches which planned item. We send your list item names and nothing else about you: not your name, not your email, not your household, and no prices you had estimated.

We do not keep the photograph. It is never saved to our database. Our server holds it only for the seconds it takes to pass it to Google (in memory, or in a temporary file for a larger photo), and then it is gone. Google may retain it for a limited period to check for misuse of its service, under its own terms. Only the prices and item names you confirm are kept.

Please be aware of what a receipt contains. As well as your shopping, a till receipt usually shows the shop, the date and time, and often the last four digits of the card used and a loyalty number. All of that is in the photograph you send. We do not read it, extract it, or keep it, but it does leave your phone, and it is processed in the United States. The same goes for the hidden details described above, on the rare occasions a photo still carries them. If you would rather none of it left your phone, photograph only the item lines, or skip the feature: everything else in the app works without it.

As with voice, we use a paid Gemini tier because Google does not use data submitted on it to train its models, and the result is shown to you for confirmation before anything is saved. Prices read from a photo are often slightly wrong, so nothing is recorded until you have looked at it.

Passwords and biometric sign-in

Your password is handled by Supabase's authentication service and is never stored by AnoSpend in a form we can read. If you turn on biometric sign-in (Face ID, Touch ID or a fingerprint), your fingerprint or face data never leaves your device and is never sent to us. The app only asks your phone to confirm it recognised you.

Sharing inside a household

AnoSpend is built for shared lists, so household members can see each other's contributions: the items you add, the notes and prices you set, what you marked as bought, and your name against those actions. Anyone you invite, or who invites you, will see this. The household owner can also see and change what each member is allowed to do.

How long we keep it

We keep your information while your account exists.

Deleting an item does not yet erase it. When you delete something, it stops appearing in the app, and a hidden record stays in the database so that a shared list can recover from a mistake or a device that synced late. We do not yet remove those records on a schedule.

To be plain about what that means: if you erase your account and you were the only member of a household, those records go with it. In a household you share with other people, they stay. We intend to remove them automatically after a set period, and this page will say what that period is once it does.

If you ask us to delete your account, we mark it straight away and erase it after 14 days, so that a mistake can be undone. What is erased is described below.

Two things can hold that up, and we would rather name them. If you still own a household that other people are in, the erasure waits until ownership has moved to someone else. And if our sign-in provider refuses the deletion, we keep trying daily rather than losing track of it, which means the account row survives until it succeeds. Either way, write to us and we will sort it out.

The server also writes operational logs recording actions such as an account deletion against an account identifier, not your name. Those are held by Render, are not used for anything else, and are kept for as long as Render retains application logs, a period we do not currently control or set.

What deleting your account does not remove. We delete your name, email and sign-in, and any household you are the only member of, with everything in it. Items, prices and purchase history you added to a household you share with other people stay with that household. It is their record too, and removing it would delete their shopping history along with yours. Your name is taken off those entries.

There is no way to remove that content yourself today. If you own the household, you can empty it first from Settings, which erases its lists, items and purchase history for everyone in it. If you do not own it, ask the owner to do that, or write to us at the address below and we will do it by hand. We would rather say this plainly than point you at a button that is not there.

If somebody invited you and you never joined. We hold the email address they gave us, who invited you and when, so the invitation can be delivered and accepted. We keep that record after the invitation expires. If the invitation was for someone under 19, the date of birth the member typed is removed from it when the invitation is accepted, declined or cancelled, or when it expires. You do not need an account to ask us to delete it. Write to the address below and we will.

Your rights

Under PIPA and PIPEDA you can ask us to show you the personal information we hold about you, correct it if it is wrong, or delete it. You can also withdraw your consent, though some of it is needed for the app to work at all: without an email address there is no account.

To make any of these requests, or to raise a concern about how your information is handled, contact us at the address below. We will respond within 30 days. If you are not satisfied with our response, you can complain to a regulator: the Office of the Information and Privacy Commissioner for British Columbia oversees PIPA, and the Office of the Privacy Commissioner of Canada oversees PIPEDA. You do not have to go through us first, and you do not have to live in British Columbia to complain.

Children and teens

Under 13. AnoSpend is not for children under 13 and we do not knowingly collect their personal information. If a household member tries to invite someone whose date of birth makes them under 13, the invitation is refused and the date is not saved. If we find out we hold information about a child under 13 anyway, we delete it.

Adults. Everyone who signs up on their own ticks a box confirming they are 19 or older. We keep that fact and the time it happened.

Members aged 13 to 18. A person under 19 can only join a household when a member of it who is allowed to invite people invites them and confirms that they are the person's parent or legal guardian. We do not check who is a parent or legal guardian. For a member under 19 we hold the same information as for anyone else (name, email address, the shopping list and pantry items they add), plus:

  • the date of birth the inviting member typed, which the person confirms when they join;
  • who confirmed they are the parent or legal guardian, and when.

We use the date of birth only to work out when the account becomes an adult account. On the day after their 19th birthday (calendar days counted in UTC) the account becomes an adult account and we delete the date of birth from it. This happens automatically: a job checks once a day, and it also happens the next time they use the app. Until the invitation is used the date of birth also sits on the invitation, and we remove it from there when the invitation is accepted, declined, cancelled or expires (expired invitations are cleaned up once a day).

The record that a guardian confirmed stays while the account exists, because it is the evidence that the person was allowed in. If the guardian later deletes their own account, we keep the date of the confirmation but it no longer points to them.

Features that send data to Google are switched off for them. Voice input and receipt scanning send what you give them to Google's Gemini service, and are not available to a member under 19. The app turns them off and our servers refuse the request. When a member turns 19 we ask them to decide about those features for themselves; nothing carries over from a guardian's earlier agreement. A member under 19 also cannot change the budget, invite or remove people, or own a household.

Telling the owner. When a member turns 19, the household owner may receive a notification saying so (if they have turned notifications on). Nothing about what the member can do changes until the owner changes it.

Changes to this policy

If we change how we handle personal information (for example by adding a new provider, or a feature that processes something we do not collect today), we will update this page and the date at the top before that change takes effect.

Contact

AnoSpend is operated by Anola Technologies Inc., Vancouver, British Columbia, Canada. Anola Technologies Inc. is accountable for personal information under PIPA and PIPEDA. Its privacy officer, Anthony Adedayo, is the person a request or complaint reaches.

Questions, requests or complaints: [email protected]

Questions about AnoSpend? Email[email protected].

AnoSpend
  • Privacy policy
  • Terms of use
  • Support
  • Anola Technologies

AnoSpend is made by Anola Technologies Inc., Vancouver, British Columbia. © 2026

[email protected]