Legal
Privacy Policy
Applies to HomeStock at app.gethomestock.com, this website, and the HomeStock mobile apps. There is a plain-English summary on Your data; this page is the formal version and the one that applies.
The short version
We collect your email, your display name and the data you enter. We do not sell it, we show no advertising, and we run no analytics or tracking SDK. If you join a Household or Business space, the people in that space can see the data in it — that is the most important thing on this page, and it is Section 4. Camera images from barcode scanning are decoded on your device and never uploaded.
1. Who we are
HomeStock ("HomeStock", "we", "us") is an inventory management application operated by BALD EAGLE LABS, LLC, a limited liability company registered in Ohio, United States. This Privacy Policy explains what personal data we collect, why, where it is stored, who can see it, and what rights you have.
It applies to the HomeStock web app, the HomeStock mobile apps, this website, and related services (the "Service"). Questions: support@gethomestock.com.
2. What we collect
2.1 Account information
When you create an account we collect:
- Email address — used to sign in, to send you account emails, and to match invitations addressed to you.
- Display name — shown to other members of any space you share.
- Password — handled by our authentication provider (Supabase) and stored only as a salted hash. We never see or store your plaintext password.
- Avatar initials — automatically derived from your display name. HomeStock does not accept or store uploaded profile photos.
- Display preferences — accent colour, dark mode, and theme.
2.2 Content you enter
HomeStock stores the content you put into it. Depending on which features you use, this includes:
| Category | What it contains |
|---|---|
| Inventory | Item names, brands, quantities, units, categories, storage locations, barcodes, expiry dates, notes, and an optional item image (an image web address you paste, or an emoji — HomeStock does not upload or host image files) |
| Grocery lists | Item names, quantities, stores, assigned person, notes |
| Recipes & templates | Recipe names, ingredients, steps, notes, source, image web address |
| Activity log | A record of check-ins, check-outs and edits, including which member performed the action and when |
| Reminders | Reminder text, schedules, and notification preferences |
| Price history | Prices you record for items over time |
| Spaces | Space names, types, emoji, your storage-location tree and category vocabulary |
| Invitations | The email addresses of people you invite to a space |
| Finance (Personal & Household) | Financial information you choose to enter in the Finance tabs — income, expenses, budgets, bills, debts, and savings goals |
| Business operations | Suppliers (including supplier contact emails and delivery addresses), purchase orders, order forms, stock movements, counts, business revenue and expenses |
| Employee & payroll records | See Section 5 — this is personal data about other people and is treated separately. |
You decide what goes in these fields. Please do not enter sensitive information you do not need to store (for example government identification numbers or bank account numbers — HomeStock has no field that asks for these and no feature that requires them).
2.3 What we do NOT collect
- No analytics or tracking SDK. HomeStock does not integrate Google Analytics, Firebase, Sentry, or any advertising, attribution, or product-analytics SDK. We do not build usage profiles and we do not track you across other apps or websites.
- No advertising identifiers and no advertising of any kind.
- No location data. HomeStock does not request or collect GPS or device location.
- No contacts. We never read your address book. Invitation emails are only ones you type in yourself.
- No biometric data.
- No payment card details. Nothing is being charged today. When paid plans launch, payments will be handled by the Apple App Store, Google Play, or a payment processor for plans bought on this website. We will never receive or store your card number.
Our infrastructure providers (see Section 7) automatically log technical request data such as IP address, timestamp, and browser/user-agent as part of operating and securing their servers. We use these logs only for security, debugging and abuse prevention.
3. Why we use it (and our lawful basis)
| Purpose | Data used | Lawful basis (GDPR) |
|---|---|---|
| Create and secure your account; sign you in | Email, password hash, display name | Performance of a contract |
| Store and sync your content across your devices | Content you enter (Section 2.2) | Performance of a contract |
| Share a space with people you invite | Display name, email, space content | Performance of a contract |
| Send invitations and essential account emails (password reset, security notices) | Email address | Performance of a contract |
| Keep the Service secure; prevent abuse; debug faults | Server logs | Legitimate interests |
| Process employee and payroll records in a Business space | Section 5 data | We act as a processor on the business customer's instructions — see Section 5 |
| Meet legal obligations | As required | Legal obligation |
4. Shared spaces — who can see your data
Read this section carefully. It is the least obvious and most consequential fact about HomeStock.
HomeStock spaces come in three types: Personal, Household and Business. Household and Business spaces are shared. Anything you enter into a shared space is visible to the other members of that space, subject to the permissions described below. It is not private to you.
Specifically, when you are a member of a shared space, the other members of that space can see:
- All inventory items, grocery lists, recipes, reminders, price history, and the storage-location and category structure in that space.
- The activity log — which member added, edited, checked in or checked out an item, and when. Your actions in a shared space are attributable to you.
- All finance entries recorded in that space's Finance tabs (Household spaces), where the space owner has granted them finance access.
- Business operations data in that space — suppliers, purchase orders, stock movements, counts, revenue and expenses — according to the capabilities they have been granted.
- Your profile: your display name, your avatar initials, your role in the space, and your email address.
Access within a space is granted per person by the space owner, and it is enforced by the server through PostgreSQL row-level security — not merely hidden in the interface. A member who has not been granted access to a category of data is not sent that data at all. Employee contact details and pay are held in a separate, separately-restricted store; see Section 5.
That said, permissions protect against the ordinary case, not against a determined member you have given wide access to. Only invite people you are willing to trust with what you have granted them, and review those grants when someone's involvement changes.
Your Personal spaces are not shared and cannot be invited into. Data in one space is isolated from every other space at the database level, so members of one space cannot read another space's data.
If you remove a member from a space, they lose access immediately, and any invitation of theirs that had not yet been accepted is cancelled at the same time so it cannot be reused. Content they entered remains in the space, and content you entered that they already saw or exported cannot be un-seen. If you leave a space, the data in that space stays with the space — it is not deleted with your account.
5. Employee and payroll records in Business spaces
Business spaces let a customer record information about their employees — people who are not HomeStock users, did not install the app, and did not agree to this policy.
Where a Business space is used, HomeStock may store the following about each employee, as entered by the business:
- Identity and contact: name, email address, phone number
- Employment details: role/job title, department, assigned zones, employment type, start date, active/inactive status
- Compensation: hourly wage, default deductions
- Time and attendance: clock-in and clock-out times, hours worked, overtime
- Payroll: pay periods, gross pay, itemised deductions, and net pay per employee
Contact details and pay are stored separately from the rest of the employee record and are readable only by the space owner and by members the owner has specifically granted access. This is enforced at the database level, including at the level of individual columns.
5.1 Our role: processor, not controller
For this employee and payroll data, the business customer that operates the Business space is the data controller. HomeStock acts as a data processor, storing and processing that data on the customer's instructions. We do not use employee or payroll data for any purpose of our own.
5.2 The customer's obligations
If you create or administer a Business space, you are responsible under applicable law for the employee data you enter. By entering it, you confirm that you have a lawful basis to do so and that you have given your employees whatever privacy notice the law requires. See the Employee Data clause in our Terms of Use.
5.3 If you are an employee of a HomeStock customer
If your employer records your details in HomeStock and you want to access, correct, or delete that data, please contact your employer — they control it and can amend or remove it directly. You may also contact us at support@gethomestock.com and we will refer your request to them and assist them in responding.
6. Where your data is stored
6.1 Our database
Your data is stored in a hosted PostgreSQL database provided by Supabase, which is the authoritative copy. Access is restricted by row-level security policies so that a signed-in user can only reach data belonging to spaces they are a member of. Data is encrypted in transit (HTTPS/TLS) and encrypted at rest by our hosting provider.
Our database region is us-west-2 (Oregon, United States). If you are located outside that region, your data will be transferred to and processed there.
6.2 On your own device — please read
HomeStock is offline-first. To load instantly and to work without a connection, the app writes a copy of your space's data into your browser's local storage on the device you are using. That copy is unencrypted plain text.
This local copy includes the same categories listed in Section 2.2. Your signed-in session token is also held in local storage.
Employee and payroll records are deliberately excluded. The data described in Section 5 — names, contact details, hourly wages, hours worked and pay — is held in memory only for as long as the screen showing it is open, and is re-read from our servers each time. It is never written to your device's local storage, and any copy written by an older version of the app is deleted automatically when the app starts.
What this means for you in practice:
- Anyone with access to your unlocked device, browser profile, or operating-system user account may be able to read that cached data without knowing your HomeStock password.
- Use HomeStock on devices you control, protect them with a device passcode, and sign out on shared or public computers.
- Signing out and clearing your browser's site data removes the local copy from that device. It does not delete your data from our database.
7. Third parties we share data with
We do not sell, rent, or trade your personal data, and we do not share it for anyone's marketing or advertising. We use a small number of service providers to run HomeStock:
Receipt scanning. If you photograph a receipt, the image is read on your device. The photograph is never uploaded to us or to anyone else, and it is discarded once it has been read — only the lines you choose to keep are saved. A receipt can show the shop, the time, what you bought and the last four digits of a payment card, so we explain it here even though the reading never leaves your device.
How the reading is done depends on where you are using HomeStock:
- In the Android app, we use Google ML Kit, which runs entirely on your phone. The photograph and the text read from it are never sent to Google. ML Kit does send Google anonymous diagnostics about how the feature is performing — your device model and operating system, the app version, an installation identifier, timings, the size of what was processed, and any error codes. It does not send the photograph, the text, or anything you have stored in HomeStock. Google's own terms require us to tell you this, and there is currently no way for us to switch that reporting off.
- In a web browser, your browser downloads a text-recognition engine from jsDelivr, a public code distribution network. jsDelivr receives your IP address as part of that download and receives no receipt data.
| Provider | What it does | What it can access |
|---|---|---|
| Supabase | Database, authentication, account emails | Your account data and all content you store in HomeStock |
| Vercel | Hosts and serves the web app and this website | Technical request logs (IP address, user-agent, timestamps). Vercel does not hold your database content. |
| jsDelivr | Delivers the barcode and receipt-reading code to your browser | Your IP address as part of the download. No HomeStock content. |
| Google ML Kit (Android app only) | Reads receipt text on your device — see the note above | Anonymous performance diagnostics: device model and OS, app version, an installation identifier, timings, processed size, error codes. Never the photograph, the text read from it, or your HomeStock content. |
| Open Food Facts | Optional product lookup when you scan a barcode — see Section 8 | The barcode number only |
| Porkbun | Domain registration and forwarding of email sent to our support address | Email you send to our support address |
| Apple App Store / Google Play (planned) | App distribution and, for paid plans, payment processing | Purchase and subscription status. They do not receive your HomeStock content; we do not receive your payment card details. |
We may also disclose data if we are legally required to (for example, a valid court order), and we will tell you where we are lawfully permitted to. If HomeStock is ever merged, acquired, or its assets sold, your data may transfer as part of that transaction; we will notify you beforehand.
8. Barcode scanning and the camera
Camera images never leave your device.
When you use the barcode scanner, HomeStock asks your device for camera permission and reads frames from the camera only while the scanner is open. Those frames are decoded into a barcode number entirely on your device. No image, photo, or video is transmitted to us or to anyone else, and none is stored. When you close the scanner, the camera is released immediately.
Once a barcode has been decoded, HomeStock sends the barcode number by itself to Open Food Facts (world.openfoodfacts.org), a public product database, to try to look up the product's name and brand so you do not have to type them. Only the number is sent — not your account, your identity, or any other data. If you would rather not use this lookup, enter items manually instead of scanning. Open Food Facts' privacy policy is at world.openfoodfacts.org/privacy.
9. How long we keep your data
- While your account is open: we keep your account data and content for as long as your account exists, so the Service works.
- After you delete your account: deletion begins when the 14-day cancellation period described in Section 10.3 ends. We then delete your profile, and your personal spaces and their contents, from our production database within 30 days.
- Backups: residual copies may persist in encrypted infrastructure backups for up to 90 days after deletion, after which they are overwritten.
- Shared spaces you did not own: content you contributed to a Household or Business space belongs to that space and is not removed when you delete your account, because it is also other members' records. Your profile is disassociated from it.
- Business/employee data: retained for as long as the business customer keeps the Business space, and deleted on that customer's instruction. The customer decides the retention period.
- Legal holds: we may retain data longer where the law requires it.
10. Your rights
You have the right to access the personal data we hold about you, to correct it, to export a copy of it in a portable format, to delete it, to restrict or object to processing, and to withdraw consent where processing is based on consent. You will never be discriminated against for exercising these rights.
10.1 Correction
You can change your display name and preferences at any time in the app under Settings → Profile, and you can edit or delete any content you have entered directly in the app.
10.2 Access and export
To receive a copy of all personal data we hold about you, email support@gethomestock.com with the subject "Data export request" from the email address on your account. We will respond within 30 days.
10.3 Deleting your account
In the app: open Settings → About → Delete Account. Before you confirm anything, HomeStock shows you what will happen to each of your spaces — which are handed over and to whom, and which are deleted along with your account.
Confirming starts a 14-day countdown. Nothing is deleted during it, and you can cancel at any point. Every screen in the app shows how many days remain and carries a Keep my account button; signing in and using it stops the deletion. When the countdown ends, your account and the data described in Section 9 are deleted on the timescales set out there.
By email (always available): email support@gethomestock.com from the address on your account with the subject "Delete my account". We will verify the request and delete the account within 30 days.
A shared space is not deleted with you. If you own a Household or Business space that other people are members of, that space is transferred to another member rather than deleted, because it holds their records too. You choose who takes it over before you confirm; if you do not choose, it passes to the longest-standing member. Only a space with no other members is deleted along with your account, because that one is genuinely your own data. As explained in Section 9, content you contributed to a space owned by somebody else stays with that space.
10.4 If you are in the EEA or UK (GDPR)
Our lawful bases are set out in Section 3. You may lodge a complaint with your national data protection authority. Where we transfer data out of the EEA/UK, we rely on our providers' Standard Contractual Clauses.
10.5 If you are in California (CCPA/CPRA)
You have the right to know what personal information we collect and why, to request deletion, to request correction, and to opt out of the "sale" or "sharing" of personal information. HomeStock does not sell or share personal information as those terms are defined by the CCPA, and has not in the preceding 12 months. Use the routes in Sections 10.2 and 10.3 to exercise your rights.
11. Security
- All traffic between the app and our servers uses HTTPS/TLS.
- Passwords are stored only as salted hashes, by our authentication provider.
- Every database table is protected by row-level security, so the server — not just the app — enforces that you can only read data from spaces you belong to, and only the parts of it you have been granted.
- Sessions use expiring tokens that refresh automatically.
No system is perfectly secure. Please also read Section 6.2 about the unencrypted local copy on your own device. If you believe you have found a security vulnerability, please report it to support@gethomestock.com and give us a reasonable opportunity to fix it before disclosing it publicly.
12. Children
HomeStock is not directed at children under 13, and we do not knowingly collect personal data from them. If you believe a child under 13 has given us personal data, contact support@gethomestock.com and we will delete it. If you are between 13 and 18, please review this policy with a parent or guardian.
13. Changes to this policy
If we change this policy we will update the "Last updated" date above. If the change is material we will also notify you by email and in the app before it takes effect. Continuing to use HomeStock after a change takes effect means you accept the updated policy.
14. Contact
BALD EAGLE LABS, LLC
Ohio, United States
Email: support@gethomestock.com
Web: www.gethomestock.com
Privacy and data-deletion requests go to the same address.
We respond to rights requests within 30 days. If a request is complex we may extend this and will tell you why.