Skip to main content
burr
Home About

Privacy Policy

Effective: August 18, 2026

Version: 4.0

Overview

Adaely Group LLC ("Company", "we", "our", or "us") operates the Burr application and related services. This Privacy Policy (the “policy”) explains how we collect, use, share, retain, and safeguard your information. Burr is designed as a grocery, shopping-list, household task, and coordination application.

Burr does not sell your personal information, does not use your information for advertising, and does not use ordinary shopping, task, location, AI, subscription, or household-sharing features to infer health status, identify health-care seekers, diagnose users, characterize any consumer's physical or mental health status, or create health profiles. Burr's treatment of Washington consumer health data is addressed in the Washington State Consumer Health Data section below.

By using Burr, you agree to the practices described in this policy and our Terms of Service.

Information We Collect

Account Information

When you create an account, we collect your email address. If you sign in with Apple (Sign in with Apple), we receive your name and email address (or an Apple private relay email if you choose to hide your address) as provided by Apple. We track whether your email address can receive our communications based on notifications from Sign in with Apple. We use password-less authentication, so we do not store passwords.

Task and Shopping Data

We store the tasks and shopping items you create, including titles, due dates, categories, and completion history. This data is necessary to provide the core functionality of the app.

Location Data

If you enable location-based features, the app requests "Always" location permission on iOS to monitor geofences in the background. This allows reminders to trigger when you arrive at or depart from saved locations or shared task and store locations, even when the app is not in the foreground.

Geofence monitoring is processed on your device by the operating system. We store the coordinates of stores and key locations you explicitly save, country codes for key locations, and location or store snapshots attached to tasks and shopping items on our servers. Country codes are used to determine whether weather features are available for key locations. We do not continuously track or record your real-time position.

Location-based reminders may include the task or item titles you enter in local notification text, and notification preview visibility is controlled by your device settings. If you join a household, other members may be notified with your display name and the store name when, near the store, you mark shared shopping items as purchased; these alerts do not trigger based on bare proximity alone. Shopping alerts may name a shared item you just marked as purchased; your live device coordinates are never shared. You can disable location features or revoke location permissions at any time through the app or your device settings.

We treat precise saved-location information as sensitive personal information and use it only to provide location-based reminders, geofencing, weather-triggered reminders, household proximity alerts you enable, security, troubleshooting, and related service functions. In Burr's ordinary operations, saved locations are not used to process, share, or sell consumer health data.

We do not use saved locations to identify health-care seekers, infer health status, or create health profiles. If Burr later introduces a feature that would use location information to identify healthcare seeking or health status, Burr will evaluate that feature before launch and provide any legally required notice, consent, or authorization before enabling it.

Weather and Environmental Data

If you create weather-triggered reminders, the app sends weather-trigger key-location coordinates to the National Weather Service (Weather.gov), a free U.S. government API, to retrieve current conditions and forecasts. This data is used to determine when to trigger your reminders. It is not used for advertising.

Display Name

When you create an account via email, we collect a display name you choose. This is visible to other members of your household, if applicable.

Device Information

If you enable push notifications, we collect your device token to deliver them. We do not collect device identifiers for advertising or tracking purposes.

Consent Records

When you accept, decline, or withdraw consent for AI features, household sharing, subscription changes, material-change notices, or other compliance-related choices, we may record the consent interaction timestamp, event type, consent text version, text hash, your IP address, user agent, and an HMAC hash of your email address. These records are maintained solely for legal compliance, consent verification, dispute response, audit, and fraud-prevention purposes. Core consent event metadata is retained as described in the Data Retention section; device-identifying fields such as IP address and user agent are redacted after seven years or upon account deletion, whichever occurs first.

Sources of Information

  • Directly from you: Account information, task and shopping item content, saved locations, display name, and support feedback you submit, including feedback on rejected AI prompts.
  • Automatically from your device: Device tokens for push notifications and precise geolocation if you enable location features, as well as your IP and device information.
  • From third parties: Your name and email address from Apple, Sign in with Apple notifications, and App Store transaction and subscription status records from Apple if you subscribe.
  • Generated by our systems: Buy Again suggestion data, product-level AI-generated categorizations and suggestions, email deliverability and recovery status, subscription entitlement and audit status, material-change consent or refund-offer audit records, and limited AI list generation metadata.

How We Use Your Information

  • Provide and maintain the Burr service.
  • Provide, verify, and support paid subscription features.
  • Verify account email deliverability for authentication, account recovery, privacy responses, billing notices, and security communications.
  • Send push notifications for task reminders and geofence alerts, if enabled.
  • Power optional AI features such as product-level categorization and list suggestions, if enabled.
  • Improve our service based on aggregated, anonymized usage patterns.
  • Respond to support requests.

Purchase Data

When you mark any shopping item as purchased, we automatically record the item name, quantity, unit, category, associated store(s), and timestamp. This recording is part of core app functionality and occurs regardless of whether you use Buy Again features.

This data is used to track purchase count, last purchase date, and your preferred store and quantity for each item, and to provide Buy Again reminders. Buy Again reminders are based on a user-set timer, not algorithmic inference. Burr treats shopping items and purchase records as user-directed product and list-management data. Purchase records are retained for 12 months and Buy Again suggestion data is retained for 14 months after last activity.

App Store Subscription Data

If you buy Burr Pro through the App Store, Apple processes your payment method and payment credentials. Burr does not receive or store your credit card number, CVV, Apple Account credentials, or other payment-card credentials.

Burr receives and stores App Store subscription transaction records needed to provide paid entitlements, support refunds and disputes, prevent fraud, maintain accounting records, and comply with App Store requirements. Burr also records subscription-related compliance events, including annual-renewal reminder delivery, material-change notices, material-change consent or refund-offer actions, and entitlement status changes.

We do not sell your personal information. We do not share your personal information for cross-context behavioral advertising. We do not use your data for advertising or share it with advertising networks.

Communications from Burr

We may send you service-related communications, including verification codes, account-recovery messages, privacy responses, security notices, billing notices, annual renewal reminders, material-change notices, data export messages, account-deletion confirmations, and other transactional or administrative messages. These communications are not advertising. You may not be able to opt out of service-related communications that are necessary to provide the Service, maintain your account, comply with legal obligations, or protect the security of Burr.

Categories Disclosed to Service Providers

  • Task and item content and list generation prompts to Google Gemini for AI-powered features, if enabled. Rejected-prompt feedback submitted to Burr is treated as support feedback and is not disclosed to Google Gemini unless separately processed through enabled AI features.
  • Email address to Brevo for transactional email delivery.
  • Technical diagnostic data to Sentry for service reliability monitoring.
  • Subscription product and transaction metadata to Apple for App Store purchase, subscription, entitlement, refund, and fraud-prevention processing.
  • Account data, app content, saved locations, purchase records, technical logs, and backups to Fly.io and Cloudflare to host, secure, deliver, and back up the Service.

AI Features

Burr offers optional AI-powered features such as item categorization and list generation. When enabled, these features process your content using Google Gemini, a third-party AI service provided by Google. Burr uses AI features to classify products and assist with lists; we do not use AI features to classify users, diagnose users, infer health status, identify health-care seekers, build health profiles, or make advertising decisions. Burr sends only the item, task, category, store type, and prompt content needed to provide the AI feature. Burr does not send your email address, account identifiers, location data, household identifiers, purchase-history identifiers, subscription information, or any other persistent unique identifier that could link the AI request to you.

List generation prompts and AI-generated list text are processed in real time and are not stored by Burr after delivery. Burr retains limited AI list generation metadata for 90 days, including the generation identifier, internal user identifier used for quota enforcement and save retry, whether the request counted toward the free monthly quota, timestamps, quota status, and save retry or idempotency identifiers. This metadata does not include your prompt or the generated list text, is not transmitted to Google Gemini, and is used only for operational purposes unrelated to health-status determination. If you submit feedback on a rejected AI prompt, Burr stores the rejected prompt as user feedback so we can evaluate and improve the feature and respond to support or safety concerns; retention of this feedback is described in the Data Retention section.

You may disable AI features at any time through the app's Settings. When disabled, no data is sent to third-party AI services.

Automated Decision-Making

Burr does not use automated decision-making or profiling to make decisions that produce legal or similarly significant effects about users. Optional AI features are used to assist with product-level categorization and list generation, not to evaluate users, determine eligibility, infer health status, or make advertising decisions.

Data Sharing

Burr's ordinary service-provider disclosures are made only to provide, secure, maintain, support, or operate the Service. These disclosures are not sales of personal information. Burr does not use service-provider disclosures to infer health status, identify health-care seekers, or create health profiles. If Burr later introduces a materially different data use or disclosure, Burr will evaluate that activity before launch and provide legally required notices, consents, or authorizations.

  • Household sharing: With other household members for items you explicitly share with the group.
  • AI processing: Task and item content and list generation prompts with Google Gemini, if AI features are enabled. Rejected-prompt feedback submitted to Burr is treated as support feedback and is not disclosed to Google Gemini unless separately processed through enabled AI features.
  • Weather services: Weather-trigger key-location coordinates with the National Weather Service, if you create weather-triggered reminders.
  • Hosting, security, and backups: Account data, app content, saved locations, task and store location snapshots, purchase records, technical logs, and backup data with Fly.io and Cloudflare.
  • Legal compliance: To comply with legal obligations.
  • Email delivery: Email address with Brevo for transactional notices.
  • Safety: To protect our rights or the safety of users.

Household Sharing

If you join a household group, other members can see shopping items and tasks you explicitly share with the group. Items and tasks are private by default unless you affirmatively share them.

Household sharing is user-directed. Items and tasks are private by default. You choose whether to share an item or task with your household. Shared content may reveal information about your dietary preferences, habits, location, schedule, or items that may be sensitive to you, including health-related products. If you share an item that may be sensitive or health-related, Burr facilitates that disclosure at your direction. If you do not want other household members to see a particular item, do not share it. All household members must be at least 13 years of age.

If you share an item or task related to health, medication, personal care, dietary needs, or other sensitive topics, other household members will be able to see it. Burr does not filter or hide health-related items you choose to share. You control what is visible to your household.

  • The household creator manages membership and can remove members.
  • Burr household sharing is separate from Apple's Family Sharing.
  • If you leave a household, items you shared are removed from the household.
  • If you delete your account, items you shared with a household remain visible to other members but are no longer associated with your identity or account.
  • You may stop sharing an item or leave a household through the app. We will remove your shared items from the household going forward, but information already viewed by other household members may remain known to them or may remain in device caches outside Burr's control.
  • Shopping alerts may name a shared item you just marked as purchased near the store; these alerts do not trigger based on bare proximity alone, and your live device coordinates are never shared.

Data Retention

We retain personal information for as long as reasonably necessary to provide the Service, maintain account and subscription functionality, comply with legal obligations, resolve disputes, enforce our agreements, protect the security and integrity of the Service, and maintain the audit records described below.

  • Active accounts: Account data is retained while your account is active.
  • Purchase history: Retained for 12 months after the purchase date.
  • Task completion history: Retained for 24 months.
  • Buy Again suggestion data: Retained for 14 months after last activity.
  • Limited AI list generation metadata: Retained for 90 days.
  • Nudge notification log: Retained for 90 days.
  • Security event logs: Logs of authentication and other security-relevant events, including IP address and user agent, are retained for 12 months for security, fraud-prevention, and audit purposes.
  • Saved location data: Retained while your account is active and deleted upon account deletion.
  • The core event metadata, including event type, consent text version, text hash, HMAC email hash, and timestamp, is retained indefinitely for legal compliance. IP address and user agent are redacted after seven years or upon account deletion, whichever occurs first.
  • Transactional email audit records: HMAC-hashed delivery records for annual renewal reminders, material-change notices, account-deletion confirmations, and data exports may be retained for up to four years after the send date for legal compliance and dispute response. Authentication-code emails are not retained in this audit log. These audit records may not be deleted to the extent retention is reasonably necessary to comply with legal obligations, including under California Civil Code § 1798.105(d)(8).
  • App Store subscription records: Active subscription state is retained while needed to provide Burr Pro features. Raw Apple signed payloads are redacted when your account is deleted. Limited redacted subscription transaction, entitlement-transition, and material-change audit records, such as original transaction ID, notification type or UUID, timestamp, transition reason, material-change action, and consent text version, may be retained for up to seven years for refund, dispute, accounting, fraud-prevention, statutory auto-renewal, and legal compliance purposes.
  • Sign in with Apple notification metadata: Minimized event metadata is retained for four years for account-deliverability, account-recovery, audit, and deletion-compliance purposes. Verified notification payloads that cannot be written to the database may be temporarily encrypted for replay and retained for up to seven days.
  • Support feedback, including feedback submitted on rejected AI prompts and the rejected prompt text included with that feedback: Retained while your account is active and deleted with your account, unless we need to retain limited records for legal compliance, service integrity, safety review, or dispute resolution.
  • Undeliverable accounts: If we cannot reach a private-relay account email after Sign in with Apple reports forwarding disabled or revoked, we prompt for email recovery in the app. If the account is not recovered within 120 days, it is deleted under the Terms unless a current Burr Pro entitlement or an open privacy-request deletion hold defers automated deletion.
  • Deleted accounts: Data is permanently deleted within 30 days, except limited records retained for legal compliance, refund, dispute, accounting, fraud-prevention, security, and audit purposes.

Household-sharing logs, if retained, are used only for service functionality, security, legal compliance, user-rights requests, troubleshooting, and dispute response.

Upon account deletion or a verified deletion request, Brevo ceases all email delivery. Brevo processes transactional emails on our behalf and retains delivery logs under its applicable data processing terms. Google processes AI requests under its applicable paid API data processing terms and may temporarily log prompts for safety monitoring under its API terms. Burr does not permit Google to use AI prompts for advertising, to build user profiles, or to link requests to identifiable Burr users for unrelated purposes. Sentry processes diagnostic reports under its applicable data processing terms.

Data Security

We implement commercially reasonable technical and organizational measures to protect your data, including encryption in transit, encryption at rest for stored data, secure storage practices, access controls, logging, and backup protections. Backup copies of the database are encrypted at rest and retained for a limited period as part of our disaster recovery procedures. If we restore from a backup, any account deletions that occurred after the backup date are re-applied. However, no method of electronic storage or transmission is 100% secure, and we cannot guarantee absolute security.

In the event of a data breach affecting your personal information, we will evaluate the nature of the incident, the categories of information involved, whether the information was secured, and whether notice is required. We will notify affected users and regulators as required by applicable law, including within 30 days when required by Washington law.

Your Rights

  • Access: Request a copy of your data by contacting [email protected].
  • Delete: Delete your account and all associated data from Settings in the app.
  • Correct: Update your information through the app.
  • Portability: Request an export of your data in a portable format.

Withdraw Consent

You may withdraw consent for AI features or household sharing at any time through the app's Settings or applicable feature controls. You may also delete your account entirely, which removes your data subject to the limited legal-compliance retention described in this policy. Depending on where you reside, you may have additional rights under applicable state laws. We will not discriminate against you for exercising your privacy rights.

How to Exercise Your Rights

You may request access to, correction of, or deletion of your personal information by contacting [email protected] or by using the deletion feature in the app's Settings. We will respond within 45 days of receiving a verifiable request and will cover the period required by applicable law. You may also request data portability in a machine-readable format. You may adjust your Buy Again reminder interval for each item through the app. To correct or delete individual purchase records, contact [email protected].

Authorized Agents and Appeals

You may designate an authorized agent to submit privacy requests on your behalf by providing a signed written authorization to [email protected]. If we deny a privacy request, you may appeal by contacting [email protected] with the subject line "Privacy Appeal."

Limit the Use of My Sensitive Personal Information

Under the California Privacy Rights Act, precise geolocation is a category of sensitive personal information. Burr collects precise coordinates for saved stores and key locations, key-location country codes, and task or store location snapshots to provide location-based reminders and geofencing features. To limit our use of precise geolocation, disable location features in the app's Settings or revoke location permissions on your device.

This treatment of precise geolocation as sensitive personal information under California privacy law does not mean Burr treats precise geolocation as consumer health data in its current ordinary operations.

Washington State Consumer Health Data

Burr's current v1 ordinary grocery, shopping-list, task, location, AI, subscription, service-provider, and household-sharing operations do not collect, process, share, or sell consumer health data as defined by Washington's My Health My Data Act. Burr treats shopping items, task titles, and AI prompts as user-directed product labels and list-building inputs, not as health-status data.

Burr does not perform algorithmic inference on purchase data. Buy Again suggestions are based on a user-controlled timer, not derived from purchase patterns. AI categorization classifies products, not consumers. Burr does not use, analyze, or process shopping items, purchase history, saved locations, household activity, AI categorization, subscription records, service-provider disclosures, or household-sharing logs to determine, characterize, or infer any consumer's physical or mental health status, identify health-care seekers, diagnose users, or create consumer health profiles. If Burr introduces a future feature or changes an existing feature in a way that would collect, process, share, sell, or disclose consumer health data, Burr will evaluate that activity before launch and provide any consumer health data privacy policy, notice, consent, or authorization required by applicable law. Nothing in this policy is intended to characterize Burr's current ordinary operations as consumer health data processing.

California Privacy Rights

If you are a California resident, the California Consumer Privacy Act and California Privacy Rights Act provide you with specific rights regarding your personal information. This section supplements the rest of this Privacy Policy.

For California residents, this Privacy Policy is intended to serve as a notice at collection describing the categories of personal information we collect, the purposes for which we use it, whether we sell or share it, and how long we retain it.

  • Identifiers: Name, email address, device token.
  • Geolocation data: Precise coordinates of saved stores and key locations, country codes for key locations, and task or store location snapshots.
  • Commercial information: Shopping items, purchase history, purchase count.
  • Commercial activity: Buy Again suggestion data.
  • Internet activity: Aggregated app usage patterns.
  • Consent records: Consent interaction timestamps, event types, consent text versions, IP address, user agent, and email HMAC hash.

We do not sell or share your personal information for cross-context behavioral advertising. We do not use or disclose sensitive personal information for purposes other than providing the Service.

State Privacy Rights

Depending on where you reside, you may have additional privacy rights under applicable state privacy laws, including rights to access, correct, delete, or obtain a copy of personal information, and to appeal a decision regarding a privacy request. Burr does not sell personal information, does not share personal information for cross-context behavioral advertising, and does not use personal information for targeted advertising. To exercise applicable state privacy rights, contact [email protected].

International Users

Burr is operated from the United States. If you access or use the Service from outside the United States, your information may be processed and stored in the United States or other locations where Burr or its service providers operate. Privacy laws in those locations may differ from the laws where you reside. By using the Service, you understand that your information may be processed in the United States and other applicable service-provider locations as described in this Privacy Policy.

Children's Privacy

Burr is not intended for children under 13. We do not knowingly collect personal information from children under 13. Children aged 13–17 may use the Service with parental consent. A parent or guardian who adds a minor to a household represents that they are authorized to consent on that child's behalf.

If you believe a child under 13 has provided us with personal information, please contact us at [email protected].

If we discover that we have collected an email address or email HMAC hash from a child under 13 without verifiable parental consent, we will delete or erase that information from active systems, subject only to limited retention required for security, legal compliance, or deletion-confirmation purposes.

Third-Party Services

  • Authentication: Apple Sign in with Apple.
  • AI processing: Google Gemini.
  • Weather data: National Weather Service / Weather.gov.
  • Maps: Apple Maps.
  • Payments and subscriptions: Apple StoreKit and the App Store.
  • Notifications: Apple Push Notification service.
  • Hosting, security, and backups: Fly.io and Cloudflare.
  • Email delivery: Brevo.
  • Error and diagnostics monitoring: Sentry.
  • Consent and compliance-email integrity: DigiCert and FreeTSA timestamp authority services. Only SHA-256 hash values are transmitted; plaintext email bodies, HTML, attachments, recipient addresses, IP addresses, and user agents are not sent to these timestamp authorities.

Email Delivery

We use Brevo to send transactional emails, including verification codes, annual renewal reminders, material-change notices, account-deletion confirmations, and data export files. Brevo processes your email address and email content to deliver these messages. For certain compliance-class emails, Burr may retain HMAC-hashed delivery records, template identifiers or versions, send dates, delivery status, provider correlation data, and hash-only proof of the rendered subject, body, or attachment set. We do not store the plaintext email body, HTML, attachment bytes, or plaintext recipient address in this audit log.

Error Monitoring

We use Sentry to monitor backend errors, app crashes, and service reliability. Diagnostic reports may include technical data such as stack traces, app version, build information, device or environment details, and reliability data. We configure diagnostic monitoring to avoid sending shopping item titles, list content, location data, or other user-entered content where feasible.

App Store Purchases and Subscriptions

We use Apple StoreKit and the App Store for Burr Pro purchases and subscriptions. Apple processes payment credentials and manages the purchase sheet, cancellation, and refund request flow. Burr receives and stores subscription transaction records from Apple so we can provide Pro features, validate entitlement status, handle subscription lifecycle events, support refunds or disputes, and maintain accounting and legal records.

Hosting, Security, and Backups

We use Fly.io to host the Burr backend and database, and Cloudflare for DNS, CDN/TLS, static web hosting, security, and R2 backup/log storage. Backup copies may include the account, app, location, purchase, household, and operational data described in this Privacy Policy, and are retained for a limited period as part of disaster recovery. We use these providers to host, secure, deliver, and back up Burr and do not permit them to use Burr personal information for advertising or unrelated purposes.

Each third-party service operates under its own privacy policy. We encourage you to review the privacy practices of these services.

No Advertising Cookies or Tracking Technologies

Burr does not use advertising cookies, tracking pixels, advertising software development kits, or similar tracking technologies to serve ads, measure advertising, or track users across apps or websites for advertising purposes.

Do Not Track

Some browsers offer “Do Not Track” signals. Because Burr does not use advertising cookies or cross-site advertising tracking technologies, the Service does not currently respond to “Do Not Track” browser signals.

Changes to This Policy

We may update this policy from time to time. If we make material changes, we will provide at least 30 days' notice through the app or via email before the changes take effect, except where changes are required by law or court order.

Contact Us

If you have questions about this Privacy Policy or wish to exercise your privacy rights, please contact us:

  • Privacy inquiries: [email protected]
  • Legal inquiries: [email protected]
  • Mail:
    Adaely Group LLC
    Attn: Privacy
    522 W Riverside Ave, Ste N
    Spokane, WA 99201
burr

never miss what matters

Privacy Terms AI Policy Disclaimer About Home © 2026 Adaely Group LLC

Built in the Pacific Northwest by an independent maker who wanted better reminders for ordinary household tasks.