Tori Privacy Policy

Last updated 5 September 2026

Tori is a household inventory app. It keeps track of what you have, where you keep it, and what you have used, so you do not buy things twice. This policy describes what Tori collects, why, and how to get rid of it.

What we collect

Local storage, scanning and permissions

Tori keeps a local database on your device or in your browser. Cloud sync, when available on your plan, sends household records to Tori's server. Clearing browser site data, resetting local data or uninstalling the app can remove local-only records; those actions do not delete your server account or cancel a subscription.

Tori does not request access to your contacts, calendar, GPS location or health records. Storage locations such as “Garage” are names you enter, not GPS readings. Text or photos you choose to provide can nevertheless contain personal or sensitive information.

Camera and photo-library access is used for actions you initiate. Supported barcode and receipt scanners process images on your device; choosing a photo for recognition does not by itself send it to Gemini. Receipt text, images and unfinished review data may be retained locally so you can finish a scan. Confirmed item records can sync, and photos you attach through an upload feature are sent to Tori. Recognition and upload features vary by platform and release.

Barcode and product lookup

A product lookup sends a barcode or item-identification details to Tori's server. Tori may consult public product databases such as Open Food Facts and retailer catalogues. Depending on the lookup features enabled, product names, retailer names, retailer item numbers or short receipt item descriptions may also be used in external searches or sent to Google Gemini or OpenAI, according to the configured processing route, to identify a product. Google Search through Gemini grounding is a separate optional lookup feature; it starts disabled in the pilot configuration. Tori does not add your account name or email address to those catalogue requests. Product results and the feedback you submit may be cached to improve later matches.

Tori Assistant

Supported inventory, quantity, package-count and item-location questions are answered from this device without an AI-provider request or an AI credit charge. This includes finding saved items in household storage. Fresh chats search All locations; you can choose Food locations or a specific location. Recipe suggestions filter out locations excluded from food use.

Questions that use the online assistant, including recipes and meal ideas, send your question, a limited recent conversation history, and a bounded selection of inventory and relevant saved recipes to Tori's server and the configured AI provider, Google Gemini or OpenAI. Recognized health or symptom questions receive fixed safety guidance before model processing; this recognition cannot guarantee detection of every sensitive question.

For each item, that list can include the item name, its description, its tags, its barcode, any notes you have written on it, the quantity and unit you have, the full storage path, recorded expiry date and time until expiry, an item identifier, and any package size Tori has worked out. Descriptions, tags and notes can include cached catalogue information. Saved-recipe context can include titles, descriptions, ingredients, instructions and servings.

Tori does not automatically add account email addresses, household membership, authentication tokens, photos or item price fields to the assistant context. However, questions, history, names, descriptions, recipes and notes are free text. Personal information you put there may be sent; the assistant does not reliably redact it.

When the configured route uses Google Gemini, Tori requires paid processing. Google's Gemini API terms state that paid service prompts and responses are not used to improve Google's products. Google still processes data under its applicable terms and retention rules; this is not a promise of zero retention.

When the route uses OpenAI, API inputs and outputs are not used to train its models by default. Tori disables storage of responses for later API retrieval. This does not enable Zero Data Retention: abuse-monitoring logs can include prompts and responses, normally for up to 30 days, with longer retention for legal or safety reasons. Prompt caching and other provider retention rules can also apply. See OpenAI's data controls.

For abuse prevention, Tori also sends OpenAI a stable pseudonymous code derived from the account whose AI allowance funds the request. The code does not contain the raw account or household ID, or an email address, but lets OpenAI link requests funded by the same account. Free text you submit can still contain personal information.

If AI is unavailable, Tori may return a fixed answer or an unavailability message.

Tori's assistant does not save conversation histories on the server. Recent chat messages are held in memory for follow-up questions. AI accounting records are separate: they track usage, credits and estimated provider costs without storing the prompt or response body in that accounting record. Avoid entering sensitive material you do not want processed by a provider; remove a note before using online assistance if you do not want that note included.

The assistant is an inventory and recipe helper; it is not a medical, diagnostic or emergency service, and must not be relied on as one.

Recipe imports, shopping links and exports

Importing a recipe from a URL asks Tori's server to fetch that page; the website operator receives the URL request and normal network information. Opening an external shopping link sends the selected product identifiers to that retailer. For example, Walmart list links contain product identifiers, but do not carry your saved quantities. The retailer's own privacy and shopping terms apply.

Exports create files you choose where to save or share. The inventory export is not a complete export of every account record, photo or saved recipe. Contact support if you need a broader copy of your personal data.

Usage analytics

Tori's supported native builds use Google Analytics for Firebase to understand how the app is used, so we know which features are worth improving and where people get stuck. What is recorded is a fixed, closed list of events: which screens are opened, progress through onboarding, which first inventory route was chosen (receipt or manual), whether a barcode or receipt scan was started and whether it succeeded or failed, how an item was added, whether the assistant was used, and whether sync raised a conflict. Tori also records fixed-label outcomes for scan-to- remove, rough counts of receipt corrections and completion status, whether a receipt location was changed, whether an inventory checkup or use-this-week action was opened, and optional thumbs-up or thumbs-down feedback on an answer. It records which navigation surface opened a destination, and fixed-label actions in the shopping list, recipe book, and locations area, such as adding or completing a list item, importing or saving a recipe, or preparing location labels. Receipt scan outcomes may include a fixed retailer category (such as “Costco” or “other”), never the store name printed on the receipt.

The same list also covers what happens around plans and limits: viewing the upgrade screen and which part of the app led there, tapping to upgrade, starting and completing a purchase, starting a trial and whether it converted or lapsed, and being stopped by a plan limit (and which one — items, locations, members, photo storage or AI credits). It records the first time an item is added and the first time a receipt is completed, so we can see how far people get.

Tori also records the rough size of an account — how many items, storage locations, household members and households it has, each as a range rather than a number — and whether the app is set to the Business profile or a business-oriented group of item fields was opened. These tell us whether Tori is being used to run a business, which is a product decision we would rather make from evidence than from guesswork.

These events carry counts and fixed labels only. They never include item names, quantities, prices, locations, notes, photos, receipt contents, your email address, or anything you typed. Where a count could itself be revealing it is recorded as a range rather than a number. Analytics also records the standard device and app information Firebase collects, such as device model, operating system version, country, and an app-instance identifier.

Alongside the events, four slow-moving labels are attached to your app instance so the figures can be grouped: the week the app was first opened, the campaign label from the Play Store install referrer if the install came from an advertisement we ran, the app profile, and the current plan. The install referrer is read once when the app first runs; only the campaign's short source label is kept, never the rest of the link.

See Google's Firebase privacy information. The static marketing pages do not load analytics or advertising scripts. The current browser app does not send these custom Firebase events; sign-in, hosting and payment services still process their own operational information.

Crash reporting

Supported native builds use Firebase Crashlytics to report crashes. A crash report contains the stack trace, device model, operating system version, and an installation identifier generated by Crashlytics and diagnostic error information. Tori does not intentionally attach inventory records, chat bodies or account details to crash reports. See Google's Firebase privacy information.

Advertising

Free accounts may see a banner ad supplied by Google AdMob. Where required by law, Tori asks for your advertising consent choices before any personalised ad is requested, and you can change that choice later from Settings.

When ads are enabled, Google may process advertising identifiers, device and app information, IP-derived approximate location, ad interactions and diagnostics to serve, measure and protect ads. This is separate from access to your device's GPS location. See Google's Privacy Policy and AdMob data disclosure.

Subscriptions and payments

RevenueCat helps connect subscription purchases to your Tori account and determine which features and credits are available. It receives an account identifier, subscription and transaction information, and device or SDK information needed to operate billing. App-store purchases are processed by Apple or Google. Where web checkout is offered, RevenueCat Web Billing and Stripe process checkout and payment details. Tori receives purchase status and transaction references rather than your full card number. See RevenueCat's Privacy Policy and Stripe's Privacy Policy.

Who else sees your data

Where it is kept and for how long

Tori's database and image storage are operated by Tori in the United States. Your active household records are kept to provide the service until they are deleted or the account or household is removed, subject to the shared-household exceptions on the account-deletion page. Providers may process information in other countries under their own service terms.

Account deletion revokes account access and removes or de-identifies the active records described on that page. Physical media cleanup can be retried after an initial failure. Routine backups use a 14-day rotation setting, but rotation is not instant erasure: failed cleanup and separate recovery copies can retain data longer. We do not promise that every copy is erased within 14 days.

Some records remain for payment reconciliation, credit accounting, fraud prevention, security or handling support requests. These can include transaction references, account or household identifiers, lookup feedback and operational logs. Replacing an account's profile with a deletion record does not make every related identifier or free-text record anonymous. Payment providers may also retain records under their own obligations. Contact support to request deletion of remaining personal data or information about a particular record; we will explain any applicable retention reason.

Security

Traffic between the app and Tori's server is encrypted with HTTPS; the app refuses unencrypted connections. Passwords are stored only as bcrypt hashes. Sign-in tokens are short-lived and can be revoked.

Your choices and rights

You can view and edit your inventory in the app at any time, export a copy of it, and delete your account from Settings → Account and device data → Delete account. Changing the name or email on the account itself is not yet possible in the app; email support@usetori.com and we will do it for you. Depending on where you live, you may also have the right to request a copy of your data, correct it, restrict how it is used, or complain to a data protection authority. Email support@usetori.com and we will respond.

Children

Tori is not directed to children under 13, and we do not knowingly collect their personal information. If you believe a child has created an account, email support@usetori.com and we will delete it.

Deleting your account

See Account deletion for exactly what is removed and what remains for other members of a shared household.

Changes

We publish revisions on this page and update the date above. Where a change requires additional notice or consent, we will provide it through an appropriate channel. The app does not currently require you to accept every policy revision.

Contact

Questions, requests, or privacy concerns: support@usetori.com.