Binz
Food Storage Management
Privacy Policy
Effective Date: April 15, 2026 · Last Updated: June 1, 2026
This Privacy Policy explains how PureTech Software ("we," "us," or "our") collects, uses, and protects
information about you when you use the Binz mobile and web application
(the "App") and related services. By using Binz, you agree to the practices described in this policy.
1. Who We Are
Binz is developed and operated by PureTech Software, a Delaware C-Corporation.
For all privacy-related inquiries, please contact us at
lily@puretech.software.
2. Age Requirement
Binz is intended for users who are 13 years of age or older. We do not knowingly
collect personal information from children under 13. If you are a parent or guardian and believe
your child under 13 has created an account, please contact us at
lily@puretech.software and we will promptly delete the account
and associated data.
Users between 13 and 17 should review this policy with a parent or guardian before using the App.
3. Information We Collect
3.1 Information You Provide Directly
| Information | Required? | Purpose |
| Email address | Yes | Account creation, login, notifications, support |
| Username | Yes | Identifying your account within the App |
| Password | Yes (unless Google Sign-In) | Account security (stored as a one-way bcrypt hash — we never store your plaintext password) |
| Display name | No | Shown to other users in shared rooms |
| Phone number | No | SMS notifications only — never shared or used for marketing |
| Storage content | Yes (to use the App) | Bins, items, food details, images, room names — your personal storage data |
| Contact form submissions | No | Customer support |
| Feedback submissions | No | Product improvement |
3.2 Information Collected Automatically
- Device identifier: A randomly generated ID stored on your device, used solely to coordinate real-time sync across your devices. This is not linked to any advertising profile.
- Device type: Whether you are on web, iOS, or Android — used to deliver appropriate experiences (e.g., push notification format).
- Login timestamps: When you last signed in, for account security purposes.
- Activity logs: Actions taken within shared rooms (e.g., item added, bin edited) — visible to other room members and retained for audit purposes.
- IP address and User-Agent: Collected in server logs for security and fraud prevention. Stored for a maximum of 30 days.
3.3 Barcode / Product Lookup Data
When you scan a barcode in the App, we query the Open Food Facts public database
(world.openfoodfacts.org)
to retrieve product information. We send only the barcode number — no personal information is
transmitted to Open Food Facts.
3.4 Google Sign-In
If you choose to sign in with Google, we receive from Google your name, email address, and
profile photo URL. We do not receive your Google password or payment information. Your use of
Google Sign-In is also governed by Google's Privacy Policy.
4. How We Use Your Information
We use the information we collect to:
- Create and manage your account
- Provide the core storage management features of the App
- Send expiration alerts, preservation reminders, and room invitations via push, email, or SMS (based on your preferences)
- Respond to your support and feedback submissions
- Detect and prevent fraud, abuse, and security incidents
- Comply with legal obligations
- Improve the App based on aggregated, non-identifiable usage patterns
We do not use your data for targeted advertising. We do not sell
your personal information to any third party, ever.
5. Third-Party Services
We use the following third-party services to operate Binz. Each is contractually obligated to
protect your data and may only use it to provide services on our behalf:
| Service | Purpose | Data Shared |
| Railway |
Cloud hosting and database (PostgreSQL) |
All app data is stored on Railway-hosted servers |
| Google / Firebase |
Google OAuth sign-in; Firebase Cloud Messaging (FCM) for Android push notifications |
Email, name (for OAuth); push notification tokens (for FCM) |
| Expo |
Cross-platform push notification delivery service (routes through FCM for Android, APNs for iOS) |
Push notification tokens and notification payload |
| Resend |
Transactional email delivery |
Your email address and the content of emails we send you |
| Twilio |
SMS notification delivery (only if you add a phone number) |
Your phone number and SMS message content |
| Open Food Facts |
Barcode product lookup |
Barcode number only — no personal information |
We do not integrate any advertising networks, analytics SDKs, or data brokers.
6. How We Share Your Information
We share your information only in these circumstances:
- With other users you invite: When you share a room, your username and display name are visible to room members. Your full email is never shown; only a masked version (e.g.,
li***@gmail.com) is displayed in user search results.
- With third-party service providers: As described in Section 5, solely to operate the App.
- For legal compliance: If required by applicable law, court order, or to protect our rights or the safety of our users.
- In a business transfer: If PureTech Software is acquired or merged, your data may be transferred as part of that transaction. We will notify you via email or in-app notice before your data is transferred and becomes subject to a different privacy policy.
We never sell your personal information.
7. Data Storage and Security
Your data is stored:
- On our servers: A PostgreSQL database hosted by Railway (production environment).
- On your device: Authentication tokens are stored in iOS/Android secure storage (Expo SecureStore) or encrypted browser storage (web). We never store your plaintext password anywhere.
We implement industry-standard security measures including:
- Passwords hashed with bcrypt (12 rounds)
- JWT authentication with token revocation on logout
- HTTPS for all data in transit
- Rate limiting on authentication endpoints
- Input validation and parameterized database queries to prevent injection attacks
While we take security seriously, no system is 100% secure. We encourage you to use a strong,
unique password and to notify us immediately at lily@puretech.software
if you suspect unauthorized access to your account.
8. Data Retention
We retain your personal data for as long as your account is active. When you delete your account:
- Your account and all associated data (bins, items, rooms, settings, notifications) will be
permanently deleted within 30 days of your deletion request.
- Server access logs (IP address, User-Agent) are deleted within 30 days on a rolling basis.
- We may retain anonymized, aggregate data (e.g., total number of items stored) that cannot be
linked back to you, indefinitely, for product analytics.
- We may retain records of your account deletion for legal compliance purposes.
You can export all your data at any time before deleting your account via Account Settings →
Data Export.
9. Your Rights and Choices
You have the following rights regarding your personal data:
- Access: View your account information in Account Settings at any time.
- Correct: Update your name, username, email, or phone number in Account Settings.
- Export: Download a complete copy of your data (JSON, CSV, Excel, PDF, ZIP) via Account Settings → Data Export.
- Delete: Delete your account and all associated data via Account Settings → Delete Account. Deletion is processed within 30 days.
- Opt out of notifications: Manage push, email, and SMS notification preferences in Notification Settings at any time.
- Withdraw Google access: Revoke Google's connection to Binz via your Google Account settings at any time.
To exercise any right or for assistance, contact us at lily@puretech.software.
10. Push Notifications
If you grant permission, we send push notifications to remind you about expiring items,
preservation ready dates, and room invitations. On Android, push notifications are delivered
via Google's Firebase Cloud Messaging (FCM). On iOS, they are delivered via Apple Push Notification
service (APNs). On web, they use the Web Push standard.
You can disable push notifications at any time in your device settings or within the App's
Notification Settings screen.
11. Room Sharing and Other Users
Binz allows you to create shared rooms and invite other users. When you participate in a shared room:
- Your username and display name are visible to other room members.
- Actions you take (adding items, editing bins) are logged in the room's activity history, visible to all members.
- Content you add to shared rooms (item names, descriptions, images) is visible to all members of that room.
You are responsible for the content you post in shared rooms. Do not share sensitive personal
information (financial details, medical information, etc.) through room content fields.
If another user in a shared room violates our Terms of Service (e.g., posts inappropriate content),
room owners can remove that member, and you can report the issue to us at
lily@puretech.software.
When a user invites someone to share a room, we send that person a one-time invitation email.
We use the email address only to deliver that invitation and delete the record when it expires or
is accepted. We do not use it for marketing or share it with third parties.
11.1 Room Chat Messages
Public shared rooms include a real-time chat feature that allows members to exchange text messages
and images. Here is how that data is handled:
- What we store: Message text, attached images, the sender's user ID and timestamp,
and any @mention references embedded in a message. We also retain the full edit history (original
content, edit timestamps) and soft-delete records (who deleted a message and when) indefinitely
so that room owners can review the complete chat history for moderation purposes.
- Who can see your messages: All current members of the room can see non-deleted
messages. Room owners additionally have access to a full audit log that shows edited and deleted
messages, including their original content. Deleted messages are hidden from regular members but
the tombstone (who deleted, when) remains visible to owners.
- @Mention notifications: When you @mention another user in a chat message, we
send that user a push notification and/or email notification (subject to their notification
preferences) containing your username, the room name, and a snippet of the message. By tagging
someone you acknowledge their name and a portion of your message may be delivered to their
notification inbox and email.
- Images: Images sent in chat are uploaded to the same secure storage used for
other App images and are accessible to all room members via a private URL. Removing yourself from
a room does not automatically delete images you uploaded; contact us at
lily@puretech.software to request removal.
- Retention: Chat messages are retained for as long as the room exists.
When a room is deleted, all associated messages, images, and audit records are permanently deleted.
You may also request deletion of your chat history at any time by contacting us.
- Do not post sensitive data: Room chat is not encrypted end-to-end. Do not
share passwords, financial details, government ID numbers, or other sensitive personal information
in chat messages.
12. European Users (GDPR)
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, the
following applies:
Our legal basis for processing your personal data is:
- Contract: Processing necessary to provide the App services you have requested (account creation, storage management, notifications).
- Legitimate interests: Security monitoring, fraud prevention, and product improvement.
- Consent: For optional features such as SMS notifications and push notifications.
You have the right to access, rectify, erase, restrict, or object to the processing of your
personal data, and the right to data portability. You may also lodge a complaint with your
local supervisory authority. To exercise these rights, contact us at
lily@puretech.software.
As a US-based company, we transfer data to the United States. We rely on Standard Contractual
Clauses where applicable to lawfully transfer data from the EEA to the US.
13. California Users (CCPA / CPRA)
If you are a California resident, you have the following rights under the California Consumer
Privacy Act (CCPA) and California Privacy Rights Act (CPRA):
- Know: The categories and specific pieces of personal information we collect.
- Delete: Request deletion of your personal information.
- Correct: Request correction of inaccurate personal information.
- Opt out of sale: We do not sell your personal information.
- Non-discrimination: We will not discriminate against you for exercising your rights.
To submit a CCPA request, contact us at lily@puretech.software
or use the in-app data export and account deletion features.
14. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify
you by email (to the address on your account) and/or by a prominent notice in the App at least
30 days before the changes take effect. The "Last Updated" date at the top of this page reflects
the most recent revision.
Your continued use of Binz after the effective date of any changes constitutes your acceptance of the
updated policy.
We aim to respond to all privacy-related requests within 30 days.