Skip to content
grocery prices mcp

Privacy

Last updated: 16 September 2026

What is stored

  • Your email address, because that is how you sign in.
  • A SHA-256 hash of each API key — never the key itself — plus its name, creation date and when it was last used.
  • Request counts per key per day, for rate limits and quotas.
  • Salted hashes for rate limiting: your IP address for guest questions, or your account ID for signed-in AI questions. Counters use hourly windows and are removed within two days. The IP address itself is not stored.

What is not stored

We do not save your questions or AI conversation to our database. Conversation context stays in the current browser tab and is sent with follow-up questions. Passwords do not exist here. There is no advertising or analytics profile, and your information is not sold.

Who processes it

Data lives in a Supabase Postgres database hosted in Canada (ca-central-1). The site and API run on Vercel, with functions in Montréal. Sign-in emails are delivered by Resend. Search requests are forwarded to the retailers' own public endpoints, which see the server's address, not yours.

Your questions, recent conversation context and relevant grocery results are sent to Cloudflare Workers AI to generate the assistant's answer. Product photos load from the retailers' or flyer providers' image servers. API keys are never included in AI prompts.

Retention and deletion

Rate-limit rows are deleted within hours; demo-search hashes within two days. Ask for your account to be deleted and everything tied to it — keys and usage rows — goes with it.

Cookies

We use cookies for your sign-in session and a signed, HttpOnly guest cookie to remember that your free AI preview has been used. The guest cookie lasts up to a year; a small local-storage flag mirrors it for the interface. A supplied API key stays in memory in the current tab. No advertising cookies are set.