Skip to content

LEGAL

Privacy Policy

Last Updated: August 16, 2026

This Privacy Policy explains how Expired Solutions, LLC ("we," "our," or "us") collects, uses, discloses, and retains information when you use the Xpired mobile application ("App"), this website, or the website assistant.

This policy is a notice of our practices, not a request for blanket consent. Where consent is legally required for a particular use, we will request it separately. If you do not want information processed as described here, do not use the relevant feature and contact us with questions.

1. Information We Collect

1.1 Personal Information You Provide

  • Account Information: Email address, username, and authentication data handled by the authentication service configured for the active App environment
  • Profile Information: Optional display name and dietary preferences
  • User Content: Fridge or pantry photos you submit for item identification, produce photos submitted through an enabled feature, saved inventory items, and notes you create

1.2 Automatically Collected Information

  • Device and Request Information: Device type, operating-system and app version, IP address, request time, and similar technical data made available by the App, browser, or hosting provider
  • Usage Data: History created by enabled features, feature usage, session duration, and app interactions
  • Camera Data: A fridge or pantry photo you submit is forwarded to an identified third-party vision provider so it can propose item names, as described in Sections 3 and 6. Xpired does not evaluate freshness, ripeness, or food safety from it. Scanner availability is not verified for the active build.
  • Location Data: Approximate location only when an enabled feature requests it and you grant device permission

1.3 Website and Assistant Information

  • Website Requests: Hosting, security, analytics, and performance providers may process technical request and device information when their features are enabled
  • Assistant Messages: Messages you submit, an ephemeral session identifier, and limited recent conversation context are sent to our chat endpoint and may be processed by the configured AI provider to generate a response
  • Assistant Feedback Analytics: If you select thumbs up or thumbs down, the feedback type and ephemeral assistant session identifier may be sent to Vercel Web Analytics as a chatbot_feedback event. Message content is not included in that event.
  • Browser Storage: The current assistant keeps message history in page memory only and does not persist its messages or user identifier in localStorage

1.4 Contact, Demo, Newsletter, and Waitlist Information

  • Contact and demo requests: Name, email address, optional company, and the message you submit
  • Interest and newsletter requests: Name, email address, optional company, submission source, and any topic indicated by the form
  • Shopper waitlist: First and last name, email address, shopping frequency, produce-eating frequency, and submission source
  • Submission metadata: Server timestamp and browser user-agent string associated with these requests
  • Storage and notification flow: The active website endpoints store these submissions in a configured Firestore database. Contact-form and shopper-waitlist content is also sent through the configured email-delivery provider to an internal inbox when the notification succeeds.

1.5 Marketplace Reservation Information

Xpired is currently free during beta and does not process marketplace card payments in the App.

  • Reservation Data: Listing, quantity, pickup-window, store, and reservation-status details needed to manage a pickup reservation
  • Amount Due: If a participating listing is actually available, the App can show an amount due at pickup; the store processes payment in person using a method it accepts
  • Payment Card Data: Xpired does not currently collect or process card, Apple Pay, or Google Pay details for marketplace reservations

2. How We Use Your Information

We use the information we collect to:

  • Provide, maintain, and improve the App's functionality
  • Process a produce image for a supplemental estimate only when that feature is enabled in the active build
  • Send enabled inventory reminders or user-configured date notifications when the current build supports them
  • Create and manage a marketplace pickup reservation when a participating listing is actually available, and show the amount due at pickup
  • Personalize enabled features when you choose to provide relevant preferences
  • Respond to contact and demo requests, administer requested newsletters or waitlists, and send operational notifications about those submissions
  • Monitor and analyze usage patterns to improve the service; scan photos are used for model training only under the opt-in process in Section 3
  • Detect, prevent, and address technical issues and fraudulent activity
  • Comply with legal obligations and enforce our Terms of Service

3. AI and Machine Learning

Fridge-photo item identification is the only image path currently offered; scanner availability and the exact model stack are not verified for the active build. We handle image data as follows:

  • Images sent by an enabled path to a deployed service are transmitted using encrypted connections (HTTPS/TLS)
  • Third-party vision provider: a fridge or pantry photo you submit for item identification is forwarded to OpenAI via its API, which returns proposed item names for you to confirm. Under that provider’s current API terms, inputs are not used to train its models but may be retained up to 30 days for abuse monitoring. See Section 6 for provider details.
  • Submitted images (your own history): our servers hold a submitted fridge photo in memory for the identification request and do not write it to disk, a database, or object storage; any longer retention applies only when the active build exposes the applicable history feature, and Section 5 says for how long.
  • Training images are opt-in only: we do not use your scan photos to train or improve our AI models unless you explicitly enable the applicable consent control in a build where it is available. If the control is unavailable, or if you want to withdraw consent or request removal of contributed images, email privacy@expiredsolutions.com. Opted-in images may still contain information visible in the submitted photo, so avoid including people or other identifying content.
  • Image analysis is intended for produce, not people. Do not submit images containing faces, documents, addresses, or other identifying information.

4. Data Storage and Security

Security measures depend on the active App build, hosting configuration, and providers. Current disclosures do not promise a particular certification, audit cadence, storage location, or access-control implementation.

  • Encrypted Connections: Deployed services use HTTPS/TLS to protect data in transit
  • Infrastructure: Application hosting, object storage, and database providers process data under their applicable service terms and security controls
  • Authentication: Authentication behavior and credential storage depend on the active build and platform configuration
  • Access: Service-data access depends on the configured provider and application controls
  • Review: Controls may change as the product and infrastructure evolve

Despite our efforts, no security system is impenetrable. We cannot guarantee the absolute security of your data.

5. Data Retention

We retain your personal information for as long as necessary to fulfill the purposes outlined in this Privacy Policy:

  • Account Data: Retained while your account is active
  • Scan Images (your own history): May be retained for up to 12 months to support enabled history features, unless deleted earlier or retained longer for a documented legal, security, fraud-prevention, or dispute reason
  • Training Images (opt-in only): Only exist if you explicitly opted in (see Section 3). Retained only as long as needed for the stated purpose. Use the applicable in-app control when available or email privacy@expiredsolutions.com to withdraw consent or request removal, subject to lawful exceptions and backup lifecycles.
  • Inventory Data: Generally retained while the item or account is active, subject to the exceptions below
  • Marketplace Reservation Records: Retained as needed to operate the service, resolve disputes, and meet applicable legal obligations
  • Contact, Demo, Newsletter, Interest, and Waitlist Submissions: Retained in the configured database while reasonably needed to respond, administer the requested relationship, maintain operational records, or address legal, security, fraud, or dispute needs. We do not promise a fixed retention period for these records. You may request deletion or withdrawal from requested updates by emailing privacy@expiredsolutions.com, subject to the same lawful exceptions.
  • Deleted Accounts: A verified deletion request initiates deletion or de-identification of account-linked data from active systems. Limited records may be retained when reasonably necessary for legal obligations, security, fraud prevention, disputes, or enforcement. Backup copies may remain isolated until the applicable backup lifecycle expires. We will respond within the period required by applicable law; this policy does not promise that every copy is purged within 30 days.

6. Third-Party Services

We use the following third-party service providers:

OpenAI

Fridge and pantry photos you submit for item identification are sent to OpenAI's API, as described in Section 3; the response is a list of proposed item names for you to confirm. Under that provider's current API terms, inputs are not used to train its models but may be retained up to 30 days for abuse monitoring. Data is handled under the provider's API terms and the service's configured data controls; consult OpenAI's current data-usage policy for details.

Infrastructure Service Providers

Application hosting, object storage for photos, and database hosting. Current website form endpoints persist contact, interest, and waitlist records in a configured Firestore database. Providers can change as the service evolves; they process data under their applicable privacy terms.

Email Delivery Provider

Contact-form and shopper-waitlist notifications, including the submitted fields described in Section 1.4, are transmitted through the configured email-delivery provider to an internal inbox when delivery succeeds. Requested updates may also use an email-delivery provider. Provider configuration can change.

Apple Inc.

App distribution and device-platform services. Xpired does not currently offer a paid in-app subscription or process marketplace card payments through Apple.

Authentication and Diagnostics Providers

The active App environment may use service providers for authentication, error reporting, and diagnostics. Provider configuration can change; we do not claim on this page that Firebase is enabled for every current path.

Website Analytics and Cookies

The site includes Vercel Web Analytics and Speed Insights scripts, which send data only when enabled in the hosting project. Assistant thumbs-up/down feedback can send the feedback type and ephemeral session identifier as a chatbot_feedback analytics event; it does not include the assistant message text. We do not currently set custom first-party advertising cookies or persist chatbot history in browser storage. Hosting or security providers may use strictly necessary technologies under their own terms. If our cookie or analytics use changes materially, we will update this notice and provide any legally required choice.

We do not sell, rent, or trade your personal information to third parties for marketing purposes.

7. Your Privacy Rights

Depending on your location, you may have the following rights:

7.1 GDPR Rights (EU/EEA Users)

  • Right to Access: Request a copy of your personal data
  • Right to Rectification: Correct inaccurate or incomplete data
  • Right to Erasure: Request deletion of your personal data
  • Right to Restrict Processing: Limit how we use your data
  • Right to Data Portability: Export your data in a usable format
  • Right to Object: Object to processing based on legitimate interests
  • Right to Withdraw Consent: Withdraw consent at any time

7.2 CCPA Rights (California Residents)

  • Right to Know: Information about data collection and use
  • Right to Delete: Request deletion of personal information
  • Right to Opt-Out: Opt out of sale of personal information (we do not sell data)
  • Right to Non-Discrimination: Equal service regardless of privacy choices

7.3 How to Exercise Your Rights

  • In-App: Use Settings → Export My Data or Delete Account when those controls are available in your current build
  • Email: Contact us at privacy@expiredsolutions.com
  • Response Time: We will respond within the period required by applicable law

8. Children's Privacy

The App is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has provided us with personal information, please contact us at privacy@expiredsolutions.com and we will delete such information.

9. International Data Transfers

Your information may be transferred to and processed in countries other than your country of residence, including the United States. These countries may have different data-protection laws. Where applicable law requires a transfer mechanism or other safeguard, we will assess and use the measures required for the relevant processing; this policy does not claim that a specific transfer mechanism applies to every current provider or user.

10. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last Updated" date. For significant changes, we will provide notice through the App or by email.

11. Contact Us

If you have any questions about this Privacy Policy or our data practices, please contact us:

Expired Solutions, LLC

Email: privacy@expiredsolutions.com

Support: expiredsolutions.com/support