← Grocy

Privacy Policy

Last updated: July 2026

Grocy is a voice-to-grocery-list Android app. This policy explains what data the app touches and where it goes. Grocy's developer never sees your grocery list, your voice, or your transcript — the one small piece of backend Grocy operates never receives any of that (see "Free plan setup" below), and everything else happens either entirely on your device or directly between your device and OpenRouter.

Voice input

When you speak a list, Grocy uses your Android device's built-in speech recognition (the same system service other apps use) to turn your voice into text, entirely on your phone. Grocy does not record, store, or transmit raw audio anywhere.

What gets sent to OpenRouter

To turn a spoken transcript into a structured list — and, if you choose to, to categorize items and estimate prices — Grocy sends the transcript text and list items to OpenRouter, an AI model routing service. This goes directly from your device to OpenRouter using an API key stored on your device — Grocy's developer has no access to this traffic. That key is either one you connected yourself (your own OpenRouter account, from the app's Settings screen) or one issued automatically by Grocy's provisioning endpoint, described next.

OpenRouter's own handling of this data is governed by OpenRouter's privacy policy, not this one.

Free plan setup

So the app works immediately without requiring you to create an OpenRouter account first, the first time it needs a key, your device makes one request to a small Grocy-operated endpoint that issues a free, spending-capped OpenRouter key. This request contains no grocery list content, no voice data, and no personal information — it is a single "issue me a key" call. Grocy's developer does not log or retain anything from it beyond standard, aggregate infrastructure metrics (like request counts) that Cloudflare, the hosting provider, provides for any web request. Once issued, the key is stored on your device and used directly with OpenRouter for everything else — this endpoint isn't involved again unless a new key is needed (e.g. after reinstalling).

What's stored, and where

None of this is uploaded to, or visible to, Grocy's developer, because there is nothing on the other end to receive it.

What Grocy does not do

Children's privacy

Grocy is not directed at children and does not knowingly collect data from children.

Changes to this policy

If this policy changes, the updated version will be posted at this same address with a revised date above.

Contact

Questions about this policy: contact@grocy.store