$This Price Is Right

Privacy Policy

Effective September 5, 2026 · What changed: First version.

This Price Is Right is a grocery price-history and price-alert site. This page says in plain English what the site collects, why, who can see it, and how to have it deleted. It describes what the site actually does today, not what it might do someday.

Your account

When you sign up we store:

  • Your email address (it is your sign-in name).
  • A scrambled version of your password (a scrypt hash with a random salt). We never store the password itself and cannot see it.
  • Your ZIP code, if you give one, so deals and prices are pulled for your area.
  • Your default alert margin (a percent) and, if you set one, a separate alert email.
  • Whether the account is the site admin, and when the account was created.
  • If you ask for a password reset, a one-hour reset token, stored only as a SHA-256 hash (the link itself exists only in the email), and when it was used.

Watches and alerts

A watch is a product search you track (for example “shrimp”), with any include or exclude words, a category, a target price, and a margin. Each time a watch is checked, the current prices it finds are saved as price records so the history builds up. When a price hits your trigger, we save the alert (item, store, price, threshold, when it fired) and, if email is set up, the address it was sent to.

Where prices come from

Price records come from three places:

  • Public store flyers. We look up flyers through Flipp’s flyer service. To do that, the ZIP code and search term of a watch (or of a Deal Search you run) are sent to that service. The code also contains retailer product feeds (Kroger, Walmart) that only run when the site owner has credentials for them; when one is on, the same ZIP and search term go to that retailer to look up prices.
  • The browser extension. The Price Collector Chrome extension records product names, prices, item codes and the store for products on pages of supported retailers (Walmart, Target, The Home Depot, Stine Home + Yard, Albertsons) that you open yourself. It does nothing in the background, never sends a request to a retailer, and reads a retailer’s own store cookies only to work out which store the page is priced for. It never collects your name, retailer accounts, carts, orders, or browsing history. Each price it records is tagged with your account so your own counts show in the extension.
  • Scans and receipts. When you scan a barcode in the app and type a price, we save the barcode, price, unit, the store name you picked, and your ZIP. Receipts are described in the next section.

Prices you contribute become part of the shared price history for your market (the first three digits of the store’s ZIP). Other shoppers there see the product, store, price and date — never your name, email, or that you were the one who recorded it.

Receipt photos

When you upload a receipt photo, the photo itself is never stored. It is held in memory only long enough to send it, over an encrypted connection, to Anthropic’s Claude API, which reads the printed lines into a list of items. Then the photo is discarded. We do not use receipt photos to train anything, and we send them nowhere but Anthropic. Anthropic processes the image under its API terms; we can only speak for what we do with it.

What we keep from a receipt:

  • The reader’s transcription: store name and address, purchase date, subtotal and total, a confidence score, the name of the model that read it, and each printed line as text. That includes non-item lines such as tax and payment lines, so if the receipt shows the last digits of a card, that text is in the transcription. Cover or crop payment details before uploading if you would rather they not be.
  • The item lines you reviewed, edited, and confirmed.
  • The price records made from the confirmed lines (store, ZIP, item, price, purchase date), which join the shared price history described above.

You can delete a receipt from the Receipts page. Price records already made from it stay.

Email

Alert emails, test emails, password-reset emails, and the site admin's own operational notices are sent through Resend, an email delivery service (or through an SMTP server, if the site owner configures one instead). To deliver a message, the recipient address, subject and message text pass through that service. A password-reset email goes only to the account's sign-in address and names the IP address the request came from, so you can tell whether it was you. When no email service is set up, alerts show only inside the app. We do not send marketing email.

Cookies and what stays on your device

  • One cookie, tpir_session. It is a signed token (HMAC-SHA256) holding your user id, a session version, and an expiry 30 days out. It is HTTP-only and, on the live site, sent only over HTTPS. Signing out or resetting your password bumps the session version, which signs you out everywhere at once.
  • No third-party cookies, no analytics, no ad or tracking scripts. The site loads no tracking pixels and no advertising or analytics software.
  • The Scan page keeps your recent scans and the last store you picked in your browser’s local storage, on your device only; they are not sent to us.
  • If you install the app, its service worker caches a few pages and icons on your device so they open offline. Signing out clears the cached pages. Nothing from the API is ever cached.
  • The browser extension keeps your collector token and settings in Chrome’s extension storage, and a short-lived queue of prices waiting to be sent.

Connection data and rate limits

Like any website, our servers see your IP address and browser details when you connect. We use the IP address to rate-limit sign-in, sign-up and password-reset attempts; that count lives in the server’s memory and is not written to the database. The one place an IP address is written down is the password-reset email described above, which tells the account holder where the request came from. Uploads, scans and extension batches are rate-limited per account the same way.

Site keys

The API keys the site admin pastes into the Admin page (for receipt reading and for email) are stored encrypted (AES-256-GCM). Only the last four characters are ever shown back. Extension collector tokens are stored as a SHA-256 hash; the token itself is shown once, when you create it, and you can revoke it in Settings at any time.

Who can see what

  • You see your own account, settings, watches, alerts, receipts and collector tokens. You also see shared market prices: flyer deals, prices from system watches, and prices other shoppers contributed — without who contributed them. You never see another user’s private watches.
  • The site admin (the person who runs the site) can see everything in the database: every account’s email, ZIP, settings, watches, alerts and receipts, and the sweep and source health pages. The admin cannot see your password (only its hash) or a saved API key.
  • Nobody else. We do not sell, rent, or share your account data. The only services that receive any of it are the ones named on this page, and only for the purpose named.

How long we keep it, and deleting your account

Your account data is kept for as long as your account exists. There is no self-serve delete button yet, so to delete your account, contact the site owner and ask. Deleting an account removes the account, its watches, alerts, receipts, receipt lines and collector tokens. Price records you contributed to the shared history are kept but de-identified: the link to your account is removed, and what remains is the store, item, price and date — the same thing other shoppers already saw.

Children

The site is not directed at children under 13, and we do not knowingly collect information from them. If you believe a child has created an account, contact the site owner and it will be removed.

Changes to this policy

When how the site works changes, this page changes with it: the effective date at the top moves and the “what changed” line says what is different. Keep using the site after a change and the new version applies to you.

Questions? Contact the site owner. See also the Terms of Use.