Introduction
Purchase History is a cloud multi-tenant purchase and visit memory service published by StoicSoft Inc. (stoicsoft.net). Unlike some StoicSoft apps that keep data only on-device, Purchase History stores account and content data on our servers so you can use the app in your browser, household sharing, billing, and the Codex MCP plugin. This Privacy Policy explains what we collect, why we collect it, who processes it, and how you can control it.
Information We Collect
Depending on how you use the service, we may collect and store:
- Google account identity: identifiers and profile details provided via Google OAuth when you sign in (such as Google subject ID, email, and display name).
- Purchase and visit records: items you save (products and dishes), visit place details, ratings, reviews, and notes.
- Photos: images you upload of products or dishes, stored as normalized, metadata-free JPEGs for recognition, review, and lookup.
- Approximate location (transient): device coordinates used only to look up nearby places when you log a restaurant or shop visit. Coordinates are not stored; place details you confirm (name, address, provider place ID, and related visit data) may be saved with the visit.
- Billing identifiers: Stripe customer and subscription identifiers needed to manage Personal and Household plans. We do not store full payment card numbers on StoicSoft servers.
- Account membership: household invites, membership roles, and related account linkage so shared plans work.
- Technical logs: limited operational logs (for example request timing, error diagnostics, and security signals) needed to run and protect the service.
How We Use Information
We use this information to:
- Provide purchase recognition, storage, search, ratings/reviews, and visit logging
- Generate AI descriptions and embeddings that power recognition and “have I bought this before?” lookup
- Bill subscriptions and manage plan limits (analyses, storage, members)
- Support household invites and shared account access
- Authenticate the Codex MCP plugin under your Google account
- Maintain security, prevent abuse, and improve reliability
Processors and Infrastructure
We rely on reputable processors to operate the service. Categories include:
- Google: OAuth sign-in, Places (nearby place lookup), and possibly generative AI (for example Gemini) for description/recognition features
- Stripe: subscription billing and Customer Portal
- Neon / Postgres: primary application database
- Google Cloud Storage (GCS): photo and object storage
- Google Cloud Run: application hosting
Processors act on our instructions to provide the service. We do not sell your personal information.
Data Retention
At a high level, we retain account, purchase, visit, photo, and membership data while your account is active and as needed to provide the service, meet legal obligations, resolve disputes, and enforce agreements. Billing identifiers and related Stripe records may be retained as required for tax, accounting, and fraud prevention. If you delete content or close your account, we remove or anonymize associated application data within a reasonable period, except where retention is required by law or for legitimate security and billing records.
Your Controls
- In-app account and data controls: manage or delete purchase/visit records and photos through the Purchase History application where those controls are available.
- Billing: cancel or change your subscription through the Stripe Customer Portal linked from the app.
- Household: leave a household or revoke invites using account membership controls in the app.
- Contact us: email [email protected] for access, correction, or deletion requests we cannot complete in-app.
Children's Privacy
Purchase History is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If we learn that we have collected such information, we will take steps to delete it.
Security
We use industry-standard safeguards appropriate for a cloud multi-tenant service, including encrypted transport (HTTPS), access controls, and least-privilege credentials for processors. No method of transmission or storage is perfectly secure; please use a strong Google account and report suspected abuse promptly.
Changes to This Policy
We may update this Privacy Policy to reflect product, legal, or operational changes. We will revise the “Last updated” date above when we do. Material changes may also be called out in the app or by email when appropriate. Continued use after an update means you accept the revised policy.
Contact Us
Questions about this Privacy Policy or Purchase History privacy practices: