Privacy Policy
Last updated: September 25, 2026
The short version. Roaminder reminds you about your list when you are near a store that carries it. To do that, your phone needs to know where you are, and our server needs to know what you typed. We use both to answer you, not to profile you. We do not sell your information, we do not share it for advertising, and we do not track you across other apps or websites. An account is optional, and without one we hold no name, no email address and no location history about you. The rest of this document is the long version, and it is meant to be complete.
Contents
- 1. Who we are and what this covers
- 2. Words we use
- 3. What we collect
- 4. How we use it
- 5. How the AI features handle what you give them
- 6. Location, in detail
- 7. Advertising
- 8. Who else handles your data
- 9. When we disclose information
- 10. How long we keep things
- 11. Security
- 12. Your choices and rights
- 13. United States privacy laws
- 14. Children and teens
- 15. Where your data lives
- 16. Changes to this policy
- 17. Contact
1. Who we are and what this covers
Roaminder ("Roaminder", "we", "us") makes:
- the Roaminder app for Android and iOS;
- the Roaminder apps for Wear OS and Apple Watch;
- the Roaminder home-screen widgets;
- the website at roaminder.com, including its pages for shared lists, shared recipes and shared experiences.
This policy covers all of them, which it calls "the Service".
It does not cover websites or apps run by anyone else, even when Roaminder links to them. That includes a store's website, a recipe site you import from, Amazon, Google Maps, Apple Maps and an advertiser's page. Those have their own policies.
Roaminder is offered in the United States only.
2. Words we use
- Device identifier: a random ID the app creates the first time it runs, such as "anon-3f2a…". It is not your phone's serial number, advertising ID or phone number, and nothing about you goes into making it. Clearing the app's data or reinstalling the app creates a new one.
- Account: the optional sign-in described in 3.2. Everything in section 3.1 works without one.
- Personal information: information that identifies you, or could reasonably be linked to you or your device. The device identifier counts.
- Service provider: a company that processes data for us under contract, only to run the Service. Section 8 lists them.
3. What we collect
This section lists everything the Service collects, grouped by what you are doing when it happens. If something is not listed here, we do not collect it.
3.1 Using the app, with or without an account
What you add to your list. When you add an item, the text you typed (for example "2 gallons of milk from Costco") is sent to our server. The server works out what the item is, which kind of store sells it, and whether it needs to be kept cold. The same happens with items you give Roami, the voice assistant, and with several items added at once. The server answers and does not store your list. Two things are kept from these requests:
- A request record (see "Request records" below). For this kind of request it includes the text you typed and the town you typed it in.
- Unrecognised words, with nothing identifying you attached. When our product dictionary has no entry for something, we queue the word itself (for example "birria tortillas") for review, so it can be added to the dictionary. The queue keeps the word, how often it has been seen, and when it was first and last seen. It does not record who typed it or where.
Your location, when you allow it. Section 6 covers this in full. Your phone compares your position with nearby stores itself. It sends your current coordinates to our server in two cases: to fetch a fresh set of nearby stores, and with an item you add, so the server can find a place you named near you. The server uses them for that one request and does not store them.
Request records. Each time the app contacts our server, we record:
- the time;
- the part of the Service it asked for (for example, the nearby-stores lookup);
- whether the request succeeded and how long it took;
- the IP address it came from;
- for some requests, the device identifier.
When a request interprets what you typed, the record also holds that text and the town you typed it in (for example "Chico, California"). It never holds your coordinates. We use these records to find bugs, measure speed and spot abuse, and we delete them after 30 days.
Our web server also keeps an access log of the IP address, time, page requested and browser or app version for each request. It does not record the parts of a web address that carry coordinates or identifiers, and it is deleted after 14 days.
Install records. We record the app version, whether it is Android or iOS, and when each device identifier first and last reached us. This lets us count how many installs are in use. An install record is deleted a year after the device was last seen.
Setup counts. The app counts how many phones reach each setup step (for example "allowed notifications"). Each phone reports each step at most once, with only the step name, the day, and whether it is Android or iOS. These counts carry no device identifier, account, location or list content, so they cannot be tied to you.
Photos you ask Roaminder to read. You can add an item from a photo, or photograph a list, a recipe or a product. The photo is sent to our server for the AI features to read (section 5), and then discarded; we do not keep it. Photos you choose to attach to an item or a shared list are different: they are kept, as described in 3.2 and 3.3.
Barcodes. When you scan a barcode, the number is sent to our server and looked up in a product database we keep on our own hardware. If you correct a product's name or category, we keep the barcode number and the name and category you gave, with nothing identifying you, to improve the database for everyone.
Store reports. You can report that a store has closed, or that it does not carry an item. We store the report with the store, the item, the store's location, the time and your device identifier. The identifier is there so one phone can report the same thing only once.
Feedback. If you use Send Feedback, we store the message you write with your app version, phone model, platform and device identifier. That lets us match a report to a build and notice repeated reports. Please do not include personal details. We keep feedback until we have dealt with it and deleted it.
Voice. When you talk to Roami, the speech recognition built into Android or iOS turns what you say into text on your phone or watch (see section 8). Roaminder receives only the text, never the recording. Roami's spoken replies are generated on our own hardware from the text of the reply, and neither the text nor the audio is stored. In Cook Mode, the hands-free "Hey Roami" listener uses on-device recognition while it waits, so nothing leaves the phone until you speak to her.
The 8-Ball (experiences). To suggest something to do, the app sends our server what you asked for and your answers to its questions. We send the suggestion back and do not store it unless you save or share it (3.2).
Recipes. When you import a recipe from a website, your phone fetches the page itself, straight from that website. The website sees that request as it would if you opened the page in a browser. Your phone then sends the page's recipe text to our server, which turns it into ingredients and steps. When Roami invents a recipe from what you have, the app sends the ingredients you listed.
3.2 If you create an account
An account is optional. It exists to back up your setup, move it to a new phone, and use shared and family lists.
- Account details: your email address, first name and last initial. There is no password. Each time you sign in, we email you a six-digit code that works once and expires after 15 minutes.
- Signed-in devices: for each phone you sign in on, a sign-in token, a label such as "Pixel 8", and when the token was last used. We store the token only as a one-way hash, so it cannot be read back.
- Notification tokens: Google or Apple issues the app a push token on each of your devices. We store it so we can notify you about lists you share, along with whether you have list notifications turned on.
- Settings backup: your custom lists, settings, store preferences, hidden and reported stores, exclusion zones, saved experiences and automatic reminder schedules. They are stored as the app wrote them, so they can be restored.
- Your lists: your saved personal lists and their items, with quantities, notes, categories and when each was completed. They appear on every phone you sign in on.
- Item notes, prices, barcodes and photos: anything you add to an item is stored with it under your account. Photos are stored as image files on our server.
- Recipes: recipes you save, with their ingredients, steps, notes, nutrition and the web address they came from.
- Shared recipes and experiences: if you share one by link, anyone with the link can open it on roaminder.com without an account. If you send one to another Roaminder user, we store who sent it to whom, your first name, any note you wrote, and whether they accepted.
3.3 Shared lists and family
- Shared lists: the list's name, its items and notes, and photos attached to items. Who added, claimed or completed each item, and when. Any reminders set on the list. For an event list, the description, place, date and time you entered, and the place's coordinates.
- People on a list appear as a first name and last initial ("Dana R."), never more. Each person has a private member token that lets their app or browser act on the list.
- Opening a shared list in a web browser: the page asks for a name to show beside what you add. Your browser keeps a cookie with your member token so the page remembers you, and the cookie is used for nothing else. The shared-list pages set no other cookies and run no analytics or advertising.
- Invitations: when you invite someone by email address, we check whether that address has a Roaminder account. If it does, we store the invitation until it is accepted or declined. You can choose the address from your contacts: that opens your phone's own contact picker, and the app receives only the address you pick. It never reads your address book.
- Family: we store the family's name, its members (first name and last initial), who organizes it, its lists, and a shared pantry (what the household keeps and how fast it goes). We also keep a purchase history. When a member completes an item on a family list, the history records the item, the amount, the price if one was entered, the store, the time and the member's first name. Everyone in the family can see this history.
People you share a list with, and the other members of your family, can see what you put on those lists. That is the point of sharing, but it also means they can copy or screenshot it, and we cannot undo that.
3.4 Permissions on your phone
Roaminder asks for a permission only when a feature needs it. Every feature that uses one still has a way to work without it.
| Permission | What it is used for | What happens if you say no |
|---|---|---|
| Location (while using) | Finding stores near you | The list still works; no store alerts |
| Location (all the time) | Alerting you near a store when the app is closed | Alerts only while the app is open |
| Notifications | Store alerts, reminders, shared-list activity | No alerts are shown |
| Camera | Scanning barcodes; photographing items, lists and recipes | Type instead |
| Photos | Choosing a picture to attach or to have read | Use the camera or type instead |
| Microphone and speech recognition | Talking to Roami | Type instead |
| Contacts (picker only) | Choosing an email address to invite | Type the address instead |
| Battery optimization exemption (Android) | Keeping store alerts reliable in the background | Alerts may arrive late or not at all |
3.5 Watches and widgets
The Wear OS and Apple Watch apps talk only to the Roaminder app on your paired phone, over the connection your phone and watch already use. They send nothing to our server themselves. When you talk to Roami on your watch, your speech becomes text on the watch or phone, and your phone handles it exactly as in 3.1. Home-screen widgets only show data already on your phone.
3.6 What we do not collect
- A history of where you have been, or any record of your movements
- Your coordinates, in any stored form (section 6 covers the one kind of location we keep)
- Your phone's advertising ID, for our own use (section 7 covers what the ad network does)
- Your contacts, call log, messages, calendar, browsing history or other apps
- Payment or financial information. Roaminder has nothing to buy.
- Passwords. There are none.
- Biometric data, health data or government identifiers
- Recordings of your voice
4. How we use it
We use the information above only to:
- Run the features you use. That covers working out what an item is and which stores sell it, finding nearby stores, alerting you, and keeping your devices in sync. It also covers running shared and family lists, sending sign-in codes and notifications, and generating recipes, experiences and Roami's replies.
- Keep the Service working and fair. We find and fix bugs, measure speed, count active installs, and enforce our Terms of Service. We also detect and stop abuse, such as automated requests or attempts to overload the server.
- Improve the Service. We add unrecognised products to the dictionary, correct store and barcode data from reports, and see which setup steps people get stuck on. We do this from the anonymous queues and counts in 3.1, not by studying individual users.
- Contact you, only if you have an account or have written to us: sign-in codes, replies to your messages, and notices about changes to this policy or to your account.
- Meet legal obligations, as described in section 9.
We do not use your information to build a profile of you, to target ads at you, or for any purpose not listed here. We do not make automated decisions about you that have legal or similarly significant effects. If we ever want to use your information in a new way, we will update this policy first and, where the law requires, ask you.
5. How the AI features handle what you give them
Roaminder uses AI models to read what you type, say and photograph. They also power Roami's answers, recipe import and invention, and the 8-Ball's suggestions.
- The models run on hardware we own and operate, not on a third-party AI service. What you send is processed there to produce the answer, then discarded. The AI hardware keeps no copy of your text or photos.
- Backup provider. If our own AI hardware is unavailable, we may temporarily send AI requests to Anthropic, a service provider (section 8). Anthropic processes them under its commercial terms, which do not allow it to train its models on what we send.
- We do not train AI on your content. We do not use your lists, messages, photos or recipes to train AI models. The dictionary improves only from the anonymous word queue in 3.1, and nothing reaches the published dictionary until a person approves it.
- AI makes mistakes. It can misread an item, pick the wrong kind of store, or suggest a place that has closed. You can correct any item. The Terms of Service explain what Roaminder does and does not promise.
6. Location, in detail
Location is the most sensitive thing Roaminder uses, so here is exactly what happens to it.
On your phone. Your phone keeps a list of nearby stores and compares your position against it. On Android this uses Google Play services location and geofencing; on iOS it uses Apple's Core Location. If you allow location "all the time", these checks also run when the app is closed. They happen entirely on your phone and send nothing to us.
Fetching nearby stores. When the app needs a fresh set of nearby stores (for example, after you have travelled some distance), it sends your current coordinates and device identifier to our server. The server uses them to pick the stores within range and send them back. It does not store the coordinates, link them to your device identifier or account, or keep any record that you were there. The web server's access log records that a store lookup was made, but not the coordinates in it.
Adding an item. When you add an item, the app sends your coordinates with it, so the server can find a place you named near you: which WinCo you mean, or the pharmacy in "pick up prescription at Walgreens". The coordinates are used for that request and not stored. The server also works out your town from them, and the request record keeps the town, never the coordinates, for 30 days (3.1).
Location you enter yourself is not tracking, and we keep it like any other content. Examples are an exclusion zone you draw, a store you pin an item to, and the place of an event on a shared list.
Turning it off. You can change location access at any time in your phone's settings. With location off, Roaminder still works as a shopping list; it just cannot tell you when you are near a store.
7. Advertising
Roaminder is free, and a small number of ads pay for it:
- a banner under the top bar;
- a banner on the Home screen;
- one full-screen ad while an 8-Ball experience is being written, at most once every ten minutes and three times a day.
There are no ads in Cook Mode, in alerts, or on your watch.
Ads are served by Google AdMob. We request non-personalized ads only, so Google does not use your past activity to choose them. We do not give Google your location, your list, your account, your device identifier or anything you type. The iOS app does not ask to track you, and does not track you as Apple defines tracking.
To show an ad at all, the AdMob software in the app still sends Google some information directly. Google uses it to limit how often the same ad appears, measure whether ads were shown, and prevent fraud. It can include your IP address, device and operating system type, app version and, on Android, your phone's advertising ID. Google describes how it handles this at https://policies.google.com/technologies/partner-sites. On Android you can reset or delete your advertising ID in your phone's settings. On iOS, Roaminder cannot read the advertising ID, because it never asks for tracking permission.
You can turn off the banner ads by asking Roami ("turn off banner ads"). The full-screen ad never runs while you are being shown how the app works.
8. Who else handles your data
We use the service providers below to run the Service. Each receives only what it needs for its job, and may use it only to do that job for us. The exceptions are marked "independent party": those also use data under their own policies.
| Provider | What it does for us | What it receives |
|---|---|---|
| OVHcloud (United States) | Hosts our server and database | Everything the server stores |
| Cloudflare | Serves roaminder.com and forwards email sent to our addresses | Website visits, including IP address; messages you send us |
| Resend | Sends sign-in codes and service emails | Your email address and the message |
| Google Firebase Cloud Messaging, and Apple Push Notification service | Deliver notifications to your phone | Your device's push token and the notification's text |
| Expo (EAS Update) | Delivers app updates between store releases | Your app and phone version, and an update identifier, when the app checks for an update |
| Anthropic | Backup AI processing, only while our own AI hardware is down (section 5) | The text or photo in that request |
| Google AdMob | Ads (section 7); independent party for its own ad-safety and measurement uses | As described in section 7 |
| Google (Android) and Apple (iOS) | Speech recognition, maps, location and geofencing built into your phone; independent parties | Whatever your phone's system services send, under your Google or Apple settings |
Links to other sites. Some buttons open another company's website or app: directions in Google Maps or Apple Maps, "Find on Amazon", or a recipe's original page. Roaminder sends that company nothing except the web address you open. Amazon links carry our affiliate tag, so Amazon may pay Roaminder a small commission if you buy something. Amazon learns nothing about you from Roaminder, only what it learns from your visit.
Our own hardware. Our AI models, Roami's voice and our copy of the barcode database run on a computer we own and operate, reached over an encrypted connection. Encrypted backups of our database are also kept there (section 10).
9. When we disclose information
We do not sell personal information, and we never have. We do not "share" it in the sense California law uses, meaning passing it to others for cross-context behavioral advertising. We do not rent, trade or license it to anyone.
We disclose information only in these cases:
- To the people you choose, when you share a list, a recipe or an experience, or join a family.
- To service providers, as described in section 8.
- When the law requires it, to comply with a valid subpoena, court order or other legal process. Where we are allowed to, we will tell you first so you have a chance to object. We will disclose only what the request actually requires.
- To protect people, when we believe in good faith that it is needed to prevent death, serious injury or a crime. The same applies to protecting the rights, property or safety of Roaminder, our users or the public.
- If Roaminder changes hands. If Roaminder is sold, merged or reorganized, the information may pass to the new owner, who must honor this policy for anything collected under it. We will tell you in the app before that happens.
- With your permission, for anything else.
10. How long we keep things
| Information | How long |
|---|---|
| Your list text, coordinates, photos you ask us to read, voice text, 8-Ball questions and answers | Not stored; discarded once the request is answered |
| Request records (IP address, device identifier, typed text, town) | 30 days |
| Web server access log (IP address, page, time) | 14 days |
| Install records | One year after the device was last seen |
| Setup counts, unrecognised-word queue, barcode corrections | Kept; they identify no one |
| Store reports | Until we have acted on them and no longer need them |
| Feedback | Until we have dealt with it and deleted it |
| Sign-in codes | Work once; expire after 15 minutes |
| Your account, backup, lists, recipes, and item notes, prices and photos | Until you delete them or your account |
| Shared lists | Until deleted. A list with no activity for 30 days becomes read-only, and is deleted 30 days after that. Any activity resets the clock. |
| A family and its lists, pantry and purchase history | Until the family is disbanded or its last member leaves. Family lists never expire while the family exists. |
| Shared recipe links | Until you delete the recipe or your account |
| Shared experience links | Until you delete your account |
| Encrypted database backups | Up to 35 days, then overwritten |
Deleted information can stay in the encrypted backups until they are overwritten, up to 35 days. Backups are used only to recover from a failure. We never search them, or restore from them to bring back something a person deleted.
11. Security
- Everything between the app and our servers is encrypted in transit (HTTPS/TLS), including the connection to our own AI hardware.
- There are no passwords to steal. Sign-in codes work once and expire quickly, and sign-in tokens are stored only as one-way hashes.
- Logging in to the server itself requires cryptographic keys, not passwords.
- Database backups are encrypted before they leave the server.
- Only the people who run Roaminder can access the systems that hold your data.
No system is perfectly secure, and we cannot promise your information will never be exposed. If a breach affects your personal information, we will tell you, and the authorities where the law requires, as quickly as we can.
12. Your choices and rights
Without an account, almost everything Roaminder knows about you is on your phone. Clear the app's data in your phone's settings, or uninstall the app, and it is gone. The request records and install record for your device identifier then expire on their own, on the schedule in section 10. Those records are tied only to a random ID that we cannot connect to you, so we usually cannot find them from an email request. That is also why they are of little use to anyone.
With an account, you can:
- Correct your name or email address in Settings › Account.
- Delete your account in Settings › Account › Delete my account. You do not need to contact us, and we do not ask why. Deletion is immediate and permanent. It removes your account and backup, your lists and recipes, your item notes, prices and photos, your signed-in devices and notification tokens, your shared experience links, and any shared lists you own with their photos. It does not touch anything on your phone.
- Sign out instead, to disconnect a phone and leave the account intact.
Deleting your account does not delete a family you belong to, because the family belongs to its other members too. Instead, you leave it. If you organized it, another member takes over, and if you were the last member, the family is disbanded. Some of what you added stays with other people, under your first name, because it is part of their records:
- items you added to other people's shared lists;
- entries in a family's purchase history;
- recipes and experiences you sent to other people.
Other choices:
- turn location, notifications, camera and microphone access on or off at any time in your phone's settings;
- turn off shared-list notifications in the app;
- turn off banner ads through Roami;
- reset your advertising ID in your Android settings.
Requests. Email info@roaminder.com to ask us to:
- tell you what personal information we hold about you;
- give you a copy of it in a portable format;
- correct it;
- delete it.
We may ask you to confirm that a request really comes from you; for an account, we send a code to its email address. We will not ask for more than we need. We answer within 45 days, and will tell you if we need longer. There is no charge, and we will not treat you differently for making a request.
An authorized agent can also make a request for you. We may ask the agent for proof that you gave permission, and ask you to confirm your identity directly.
If we decline a request, we will tell you why, and you can appeal by replying to that message. If you are unhappy with the result of your appeal, you can contact your state attorney general.
13. United States privacy laws
Many states give their residents privacy rights, among them California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah and Virginia. Roaminder gives the rights in section 12 to every user, wherever they live in the United States. This section adds the specific disclosures those laws require.
Categories collected in the last 12 months (California's categories):
| Category | Examples from this policy | Source | Purpose | Disclosed to |
|---|---|---|---|---|
| Identifiers | Device identifier, IP address, email address, push tokens | You and your device | Sections 4 and 11 | Service providers (section 8) |
| Personal records | First name and last initial | You | Accounts, shared lists | Service providers; people you share with |
| Commercial information | Lists, purchase history, prices, recipes | You | Running the features you use | Service providers; people you share with |
| Internet or network activity | Request records, access logs | Your device | Fixing bugs, stopping abuse, counting installs | Service providers |
| Geolocation | Coordinates, used and not stored; town, stored 30 days | Your device | Finding nearby stores, interpreting what you type | Service providers |
| Audio, electronic or visual information | Photos you attach or ask us to read | You | The features you use | Service providers |
| Inferences | None. We do not create profiles. | — | — | — |
Sensitive personal information. California law treats your precise location as sensitive personal information. We use it only to provide the service you asked for, which the law allows without a right to limit it, and we do not use it to infer anything about you.
Sale and sharing. We do not sell personal information or share it for cross-context behavioral advertising, and have not done so in the last 12 months. We have no actual knowledge of selling or sharing personal information of anyone under 16.
Global Privacy Control and Do Not Track. We do not sell or share personal information, or track you across other websites, so there is nothing for these signals to switch off. Our websites behave the same whether or not your browser sends them.
California "Shine the Light". We do not disclose personal information to third parties for their direct marketing.
Nevada. We do not sell covered information as Nevada law defines it.
14. Children and teens
Roaminder is not directed to children under 13, and you must be at least 13 to use it. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has given us personal information, email info@roaminder.com and we will delete it.
Roaminder is not designed for teenagers in particular. If a teen aged 13 to 17 uses it, their information is handled exactly as this policy describes. That already means no sale, no sharing for advertising, and non-personalized ads only.
15. Where your data lives
Roaminder's server, database, AI hardware and backups are all in the United States, and the Service is offered only in the United States. Some of our service providers may process data in other countries, under their own safeguards.
16. Changes to this policy
We will update this policy when the Service changes, and the date at the top shows when it was last revised. The current version is always in the app under Settings, and at roaminder.com/privacy.
If a change materially affects how we handle information we already hold, we will tell you in the app before it takes effect and, if the law requires it, ask for your consent. We will not apply a materially less protective policy to information collected under an earlier one without your permission.
17. Contact
Questions, requests or complaints about privacy: info@roaminder.com
Please put "Privacy" in the subject line. We read every message.
This is the same text shown inside the app under Settings › Legal. Questions? Get in touch.