Privacy Policy
Cartwheel is a collaborative grocery list app that helps households cook everything they buy. This policy describes what data Cartwheel stores, why we store it, who else sees it, and how you can delete it. It also lays out your formal rights under GDPR (EU/UK) and CCPA (California).
Who we are
Cartwheel is operated by Cartwheel Form LLC, doing business as Cartwheel AI (the "data controller" under GDPR). You can reach us at hello@cartwheelai.app. We don't have a designated EU representative at this time — EU/UK residents can contact us directly at the email above for any data-protection inquiry.
What Cartwheel stores
Account information
When you sign in with Google or Apple, Cartwheel stores your name, email address, profile photo URL (if your provider gives us one), and a unique provider ID — so we can keep your lists synced across devices and let collaborators see who added what to a shared list. If you sign in with Apple and choose Hide My Email, we receive only the relay address Apple generates; we never see your real email.
Your lists, items, and recipes
Lists you create, items you add, recipes you import from URLs, recipes you save to your library, and AI suggestions you accept are stored in Google Firebase Firestore under your account. Members of a shared list can read and write all content on that list — they cannot see anything else in your account.
Dietary preferences, allergies, and household profile
If you set dietary preferences (vegetarian, vegan, halal, kosher, gluten-free, dairy-free, pescatarian, keto), enter ingredients you are allergic to, or enter a household profile (household size, members, allergies per member), Cartwheel stores that information on your user profile or your household's profile in Firestore. Allergy data is health-adjacent and treated as special-category personal data under GDPR Art. 9 — see Legal basis below for how we lawfully process it.
Diagnostic data
Cartwheel uses Firebase Analytics (Google) and Firebase Crashlytics (Google) to understand which features people use, measure performance, and diagnose crashes. The data we collect includes app session length, screen names, button taps that we instrument explicitly, your Firebase user ID, and — for crashes — the stack trace plus the screen you were on. We do not use this for advertising, do not enable Google Ads attribution, and do not link it to your real-world identity beyond the Firebase user ID. You can turn analytics and crash reporting off at any time from Settings → Help improve Cartwheel in the app.
What we don't store
- No payment information — Cartwheel is free during the beta.
- No precise location data.
- No contact list or address-book access.
- No advertising SDKs (no AdMob, no Facebook SDK, no third-party trackers).
- No third-party analytics SDKs other than Firebase Analytics + Crashlytics described above.
- No cross-app tracking. Cartwheel is not enrolled in iOS App Tracking Transparency because we do not track you across apps or websites owned by other companies.
AI features
Cartwheel uses two third-party AI services to power Discover and the Library "+" recipe generator:
Anthropic Claude (recipes)
- Recipe import: when you paste a recipe URL, our server fetches the page text and asks Claude to extract the recipe into structured ingredients and directions.
- Discover suggestions: when you open the Discover tab, our server sends Claude (a) the item names + quantities + categories on your list, (b) attached recipe titles, (c) your applicable dietary preferences and allergies, and (d) your household composition when an "Apply household" toggle is on. We do not send your name, email, list name, or other users' identities.
- Library recipe generator: when you type a free-form prompt in the Library "+" sheet, we send Claude (a) the prompt you typed and (b) the same dietary preferences and allergies as above — so the recipe respects your constraints.
Anthropic processes this data under their commercial Customer Agreement, which prohibits training on customer-submitted data. Anthropic retains API request data for up to 30 days for abuse monitoring and then deletes it. Anthropic operates in the United States.
Google Gemini / Imagen (dish images)
Generated recipe suggestions and library recipes include AI-generated dish photos. We send Google's Imagen API the recipe title and a short list of representative ingredients to generate the image. We do not send your name, email, or any data about your list. Google Imagen is operated by Google in the United States under Google's API terms; Google does not use the input for training when accessed via the API.
Honesty mark
AI-generated recipes are always labeled with a "✦ Generated by Cartwheel" mark in the app, on the public share link page, and anywhere else the recipe surfaces. That label cannot be removed — we believe in being honest about which content came from a model.
Reporting AI output
If you see an AI-generated recipe that looks unsafe, contains an allergen you flagged, or is otherwise objectionable, long-press the card and choose Report recipe. We store the report (the recipe ID, the reason category you picked, and any note you add) for review — separate from your normal recipe history. Reports help us improve safety; they are not used for advertising.
Sharing a list
When you share a list with someone via an invite code, they can read and write every item, recipe, and suggestion on that list. They cannot see anything else in your account. Names, profile photos, and avatar colors of list collaborators are visible to other collaborators on that list (via a dedicated peer-readable user record); email addresses are not visible to peers.
How we use your information
We use the information described above only to:
- Authenticate you and keep your data synced across your devices
- Show you and your collaborators a shared, up-to-date view of your list
- Generate recipe suggestions and parse recipe URLs you paste
- Honor your dietary preferences and allergies in AI-generated content
- Diagnose crashes, measure performance, and decide which features to invest in (Firebase Analytics + Crashlytics — opt-outable from Settings)
We do not sell or share your information for cross-context behavioral advertising. We do not share it with advertisers. We do not use it to build a profile of you for any third party.
Legal basis (GDPR Art. 6 and Art. 9)
For users in the EU, UK, or other GDPR-covered regions, we rely on the following legal bases:
- Contract (Art. 6(1)(b)) — to provide the core app: account, sync, sharing, recipe parsing, suggestion generation. Without this, Cartwheel cannot function.
- Consent (Art. 6(1)(a) and Art. 9(2)(a)) — for storing and processing your dietary preferences and allergies, including transmitting them to Anthropic to filter AI output. You provide this consent by entering the data and can withdraw at any time by clearing the fields in Settings.
- Consent (Art. 6(1)(a)) — for Firebase Analytics + Crashlytics diagnostic data. You can withdraw at any time from Settings → Help improve Cartwheel; the default for new installs is "on" and you can turn it off immediately after first launch.
- Legitimate interest (Art. 6(1)(f)) — for content you contribute to lists owned by other users. When you delete your account, the content stays on those lists (anonymized — your name is replaced with "Deleted user") so the list owner is not surprised by silent gaps. We have determined that the list owner's interest in stable shared-list history outweighs the marginal additional privacy impact, given that your name is removed. If you want specific content you contributed to a peer's list removed, email hello@cartwheelai.app.
- Legal obligation (Art. 6(1)(c)) — to respond to lawful requests from competent authorities.
Retention
- Account, lists, items, recipes, library, profile: kept for as long as your account exists. Deleted immediately when you delete your account, except as noted below for shared-list content.
- Shared-list content you contributed: retained on the list owner's list with your name anonymized. The list owner controls when that content is deleted.
- Firebase Analytics events: retained for up to 14 months per the default Firebase Analytics setting. Crash records are retained for up to 90 days.
- Anthropic API request data: retained by Anthropic for up to 30 days for abuse monitoring, then deleted.
- Generated dish image inputs to Google Imagen: retained according to Google's standard API logging window (typically less than 30 days) and not used for training.
- AI output reports: retained indefinitely for safety review; you may request deletion of specific reports by emailing the address above.
- Backups: we may keep operational backups of our database for up to 30 days after the deletion date for disaster recovery; backups are not used for any other purpose and are overwritten on rolling rotation.
Where your data lives — international transfers
Cartwheel stores data in Google Firebase (a Google Cloud product) in US data centers. Anthropic processes AI-related requests in their US infrastructure. Google Imagen / Gemini processes image-generation requests in their US infrastructure. If you are in the EU, UK, Switzerland, or another region that requires safeguards for transfers to the US, we rely on Standard Contractual Clauses (SCCs) and the data-processing addendums Google and Anthropic make available to their API customers. You can request a copy of the relevant SCCs by emailing us.
Deleting your data
You can permanently delete your account directly from the app: Settings → Delete account. The deletion is irreversible and includes:
- Your saved recipe library
- Lists you own that no one else is on (and all items, recipes, AI suggestions, activity, plan slots, and presence records on them)
- Your dietary preferences, allergies, and household-member entries
- Your normalized item history, library hide-blocklist, and per-list view state
- Your Cartwheel account, including its public display record visible to collaborators
- Your membership in any household you belonged to (and the household itself, if you were the only member)
What stays:
- Lists you share with someone else — they keep the list. If you owned a shared list, ownership transfers to whichever member has been on it the longest.
- Items and recipes you added to a shared list — they stay so the list is not gutted, but your name on them is replaced with "Deleted user". This is the legitimate-interest tradeoff described above; email us if you want specific content removed.
- Operational backups (up to 30 days; see Retention).
If you would prefer not to use the in-app deletion flow, email hello@cartwheelai.app and we will process the deletion within 30 days.
Your rights — GDPR / UK GDPR
If you are in the EU, UK, Switzerland, or another GDPR-covered region, you have the right to:
- Access the personal data we hold about you (Art. 15)
- Rectify inaccurate data (Art. 16)
- Erase ("right to be forgotten") your data (Art. 17) — covered by the in-app delete flow
- Restrict processing (Art. 18)
- Data portability — export your data in a machine-readable format (Art. 20)
- Object to processing based on legitimate interest (Art. 21)
- Withdraw consent at any time without affecting prior processing (Art. 7(3))
- Lodge a complaint with your local data-protection authority. For UK residents, the ICO at ico.org.uk. For EU residents, the supervisory authority in your country of residence — a directory is at edpb.europa.eu/about-edpb/about-edpb/members.
To exercise any right except erasure (which is in-app), email hello@cartwheelai.app. We will respond within 30 days.
California Residents — CCPA / CPRA Notice
This section describes how Cartwheel handles personal information of California residents under the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA).
Categories of personal information we collect
- Identifiers — name, email address, your Google or Apple provider ID, your Firebase user ID
- Internet or other electronic network activity — Firebase Analytics events (screen names, button taps), crash reports
- Inferences — none drawn for advertising; allergen + dietary preferences inferred only as you entered them yourself
- Sensitive personal information (CPRA §1798.140(ae)) — allergy information you choose to enter (health-adjacent). We use this only to filter AI output and never share it for any other purpose; you can clear it at any time in Settings.
Purposes
See How we use your information above. We use personal information only for the purposes described and do not use it for any incompatible purpose.
Sources
All personal information comes from you directly (sign-in providers, in-app entries) or from your device (analytics + crash reports). We do not buy or rent personal information from data brokers.
Recipients
The service providers in Where your data lives above (Google Firebase, Anthropic, Google Imagen). All are bound by contract to process your data only for the services we describe.
Do Not Sell or Share My Personal Information
Cartwheel does not sell personal information for monetary or other valuable consideration, and does not share personal information for cross-context behavioral advertising as defined by CPRA §1798.140(ah). Because we do not sell or share, we do not offer or need to offer a "Do Not Sell or Share" link — but you can email us to confirm in writing.
Your California rights
- Right to know what personal information we collect and how it is used (§1798.110)
- Right to know what categories of personal information we have collected, sold, or shared in the past 12 months (§1798.115)
- Right to delete personal information (§1798.105) — covered by the in-app delete flow
- Right to correct inaccurate personal information (§1798.106)
- Right to opt out of sale or sharing (§1798.120) — Cartwheel does not sell or share, so there is nothing to opt out of
- Right to limit use of sensitive personal information (§1798.121) — your allergy information is used only for AI filtering, never for any other purpose
- Right to non-discrimination for exercising any of the above (§1798.125)
To exercise any of these rights, email hello@cartwheelai.app with "California" in the subject line. We will respond within 45 days.
Children's privacy
Cartwheel is not directed to children under 13, and we do not knowingly collect personal information from children under 13. By creating an account, you confirm that you are at least 13 years old. If you believe we have collected personal information from a child under 13, contact us at hello@cartwheelai.app and we will delete the information promptly.
Changes to this policy
If we make material changes to this policy, we will update the "Effective" date at the top and surface a notice in the app on next launch. Continuing to use Cartwheel after a change means you accept the updated policy.
Contact
Questions about this policy or how Cartwheel handles your data? Email hello@cartwheelai.app.