This Price Is Right is a grocery price-history and price-alert site. This page says in plain English what the site collects, why, who can see it, and how to have it deleted. It describes what the site actually does today, not what it might do someday.
Your account
When you sign up we store:
- Your email address (it is your sign-in name).
- A scrambled version of your password (a scrypt hash with a random salt). We never store the password itself and cannot see it.
- Your ZIP code, if you give one, so deals and prices are pulled for your area.
- Your default alert margin (a percent) and, if you set one, a separate alert email.
- Whether the account is the site admin, and when the account was created.
- If you ask for a password reset, a one-hour reset token, stored only as a SHA-256 hash (the link itself exists only in the email), and when it was used.
Watches and alerts
A watch is a product search you track (for example “shrimp”), with any include or exclude words, a category, a target price, and a margin. Each time a watch is checked, the current prices it finds are saved as price records so the history builds up. When a price hits your trigger, we save the alert (item, store, price, threshold, when it fired) and, if email is set up, the address it was sent to.
Where prices come from
Price records come from three places:
- Public store flyers. We look up flyers through Flipp’s flyer service. To do that, the ZIP code and search term of a watch (or of a Deal Search you run) are sent to that service. The code also contains retailer product feeds (Kroger, Walmart) that only run when the site owner has credentials for them; when one is on, the same ZIP and search term go to that retailer to look up prices.
- The browser extension. The Price Collector Chrome extension records product names, prices, item codes and the store for products on pages of supported retailers (Walmart, Target, The Home Depot, Stine Home + Yard, Albertsons) that you open yourself. It does nothing in the background, never sends a request to a retailer, and reads a retailer’s own store cookies only to work out which store the page is priced for. It never collects your name, retailer accounts, carts, orders, or browsing history. Each price it records is tagged with your account so your own counts show in the extension.
- Scans and receipts. When you scan a barcode in the app and type a price, we save the barcode, price, unit, the store name you picked, and your ZIP. Receipts are described in the next section.
Prices you contribute become part of the shared price history for your market (the first three digits of the store’s ZIP). Other shoppers there see the product, store, price and date — never your name, email, or that you were the one who recorded it.
Receipt photos
When you upload a receipt photo, the photo itself is never stored. It is held in memory only long enough to send it, over an encrypted connection, to Anthropic’s Claude API, which reads the printed lines into a list of items. Then the photo is discarded. We do not use receipt photos to train anything, and we send them nowhere but Anthropic. Anthropic processes the image under its API terms; we can only speak for what we do with it.
What we keep from a receipt:
- The reader’s transcription: store name and address, purchase date, subtotal and total, a confidence score, the name of the model that read it, and each printed line as text. That includes non-item lines such as tax and payment lines, so if the receipt shows the last digits of a card, that text is in the transcription. Cover or crop payment details before uploading if you would rather they not be.
- The item lines you reviewed, edited, and confirmed.
- The price records made from the confirmed lines (store, ZIP, item, price, purchase date), which join the shared price history described above.
You can delete a receipt from the Receipts page. Price records already made from it stay.
Alert emails, test emails, password-reset emails, and the site admin's own operational notices are sent through Resend, an email delivery service (or through an SMTP server, if the site owner configures one instead). To deliver a message, the recipient address, subject and message text pass through that service. A password-reset email goes only to the account's sign-in address and names the IP address the request came from, so you can tell whether it was you. When no email service is set up, alerts show only inside the app. We do not send marketing email.
Connection data and rate limits
Like any website, our servers see your IP address and browser details when you connect. We use the IP address to rate-limit sign-in, sign-up and password-reset attempts; that count lives in the server’s memory and is not written to the database. The one place an IP address is written down is the password-reset email described above, which tells the account holder where the request came from. Uploads, scans and extension batches are rate-limited per account the same way.
Site keys
The API keys the site admin pastes into the Admin page (for receipt reading and for email) are stored encrypted (AES-256-GCM). Only the last four characters are ever shown back. Extension collector tokens are stored as a SHA-256 hash; the token itself is shown once, when you create it, and you can revoke it in Settings at any time.
Who can see what
- You see your own account, settings, watches, alerts, receipts and collector tokens. You also see shared market prices: flyer deals, prices from system watches, and prices other shoppers contributed — without who contributed them. You never see another user’s private watches.
- The site admin (the person who runs the site) can see everything in the database: every account’s email, ZIP, settings, watches, alerts and receipts, and the sweep and source health pages. The admin cannot see your password (only its hash) or a saved API key.
- Nobody else. We do not sell, rent, or share your account data. The only services that receive any of it are the ones named on this page, and only for the purpose named.
How long we keep it, and deleting your account
Your account data is kept for as long as your account exists. There is no self-serve delete button yet, so to delete your account, contact the site owner and ask. Deleting an account removes the account, its watches, alerts, receipts, receipt lines and collector tokens. Price records you contributed to the shared history are kept but de-identified: the link to your account is removed, and what remains is the store, item, price and date — the same thing other shoppers already saw.
Children
The site is not directed at children under 13, and we do not knowingly collect information from them. If you believe a child has created an account, contact the site owner and it will be removed.
Changes to this policy
When how the site works changes, this page changes with it: the effective date at the top moves and the “what changed” line says what is different. Keep using the site after a change and the new version applies to you.
Questions? Contact the site owner. See also the Terms of Use.