Privacy Policy

Effective date: August 1, 2026

This Privacy Policy explains how Northform ("we," "us," or "our") collects, uses, and protects information when you use the Have mobile application and the gethave.app website (together, the "Service").

The short version: we collect the minimum needed to run the app — your email, your pantry data, and (if you link it) a connection to your Kroger account. Photos are processed on your device. Your precise location is not stored. We never sell your data.

1. Information we collect

Account information

When you create an account, we collect your email address. We use it to sign you in, sync your data across devices, and contact you about your account. We do not require your name, phone number, or any other identity information.

Pantry and recipe data

The items in your pantry, your quantities, your recipes, and your shopping lists are stored in your account and synced to our cloud database, which is hosted on Supabase. This data is associated with your account so it can follow you across devices, and it is protected by access controls so that only you (and members of your household you explicitly share with, if that feature is available to you) can access it.

Kroger account linking

If you choose to connect a Kroger account, you authorize the connection through Kroger's own sign-in (OAuth). We never see or store your Kroger password. The resulting access tokens are stored encrypted on our servers — never on your device — and are used only to perform the actions you request, such as adding items to your cart and finding product availability. We cache your Kroger profile identifier so we can associate the link with your Have account. You can disconnect your Kroger account at any time in the app's settings, which deletes the stored tokens.

Location

If you grant location permission, we use your approximate location for one purpose: finding Kroger-family stores near you. Your location is sent to look up nearby stores and is not stored beyond caching the resulting store list. We do not track your movements, keep a location history, or share your location with third parties for advertising.

Camera and photos

Have uses your camera to scan barcodes and recognize items on your shelves. Barcode scanning and shelf-photo recognition are performed on your device. Shelf photos are processed locally and are not uploaded to our servers. Only the resulting item information (for example, "canned tomatoes, 2") is synced to your pantry.

Diagnostics

We may collect basic crash reports and anonymized usage diagnostics to keep the app working well. These do not include your pantry contents, photos, or location.

2. How we use information

  • To provide the Service: pantry sync, recipe matching, shopping lists, and cart integration.
  • To operate, maintain, and improve the app.
  • To respond to support requests.
  • To protect the security and integrity of the Service.

3. What we don't do

  • We do not sell your personal information — to anyone, ever.
  • We do not show third-party advertising or share your data with ad networks.
  • We do not store your Kroger credentials or your Kroger tokens on your device.
  • We do not upload your shelf photos or keep a history of your location.

4. Service providers

We use a small number of infrastructure providers to run the Service, including Supabase (database and authentication hosting) and the Kroger API (store lookup, product search, and cart actions you request). These providers process data only as needed to provide their services to us.

5. Data retention and deletion

Your data is retained while your account is active. You can delete your account from within the app (Settings → Account → Delete Account) or by emailing us. Deleting your account permanently removes your pantry data, shopping lists, and stored Kroger tokens from our systems within 30 days, except where a longer retention period is required by law.

6. Security

We use industry-standard measures to protect your data, including encryption in transit (TLS), encrypted storage of Kroger tokens, and database access controls that isolate each account's data. No system is perfectly secure, but we design the Service so that we hold as little sensitive data as possible.

7. Children

The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided us personal information, please contact us and we will delete it.

8. Changes to this policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you through the app or by email before the changes take effect. The effective date at the top of this page always reflects the current version.

9. Contact us

Questions or requests about your data? Email us at support@gethave.app.

Have is not endorsed by, affiliated with, or sponsored by The Kroger Co.