Privacy Policy
Last updated: February 2026. MyClipbox™ is privacy-first by design. Here's exactly what that means.
We believe privacy is a right, not a feature. Your family's data stays with your family. This policy explains in plain language what we collect, what we refuse to collect, and how you stay in control.
1. What We Collect
- Email address — for account access and beta communications only.
- ZIP code — stored only on your device and used to determine your timezone. Never sent to our servers.
- Family name — an optional display label (defaults to "My Family"). Visible only to your family.
- Receipts and coupons you upload — stored securely, used only to build your shopping lists and match savings.
- Messages received in your personal inbox — organized on your device for coupons, events, and categories.
2. What We Do Not Collect
- Your personal phone number — we never ask for it.
- GPS, Wi-Fi, or any form of location data — we never request location permissions.
- Your contacts, address book, or call history.
- Camera, microphone, or photo library access.
- Calendar, reminders, or Bluetooth data.
- Device identifiers (IDFA / GAID), advertising IDs, or device fingerprints.
- Browsing history, cross-app behavior, or usage patterns for profiling.
- Your device timezone — we derive it from the ZIP code you provide at signup.
3. What We Do Not Do — Data Sharing
- We do not sell your personal data — to anyone, for any reason.
- We do not share your information with third-party advertisers or ad networks.
- We do not trade or rent your data to data brokers, affiliates, or marketing partners.
- We do not build advertising profiles about you or your family.
- We do not license your personal information to other companies.
- You may opt out of all communications at any time.
4. How We Process Your Data
- Message organization, coupon detection, and calendar event extraction all happen on your device — none of that content is sent to AI or cloud services.
- Receipts and coupons are processed to extract items, prices, and merchant information only when you initiate a scan.
- Cloud AI scanning is optional. You can restrict all processing to on-device only in Settings → AI & Privacy.
- MyClipbox does not request any phone permissions — no access to your contacts, camera, microphone, photos, or location.
- Your data is encrypted at rest and in transit, and never shared outside your family account.
- You can delete any or all data at any time.
5. Zero Phone Permissions
- MyClipbox requests zero phone permissions. We built the app to work without accessing any sensitive device features.
- No contacts, no camera, no microphone, no photo library.
- No location, no Bluetooth, no motion sensors, no calendar.
- No advertising identifiers, no tracking cookies, no web beacons.
- If it isn't necessary to organize your receipts and coupons, we don't request it — period.
6. Encryption & Security
- All network traffic is encrypted in transit via TLS.
- Sensitive on-device data (calendar events, message tracking) is cryptographically signed and encoded using per-install encryption keys that never leave your device.
- Phone numbers assigned to your account are encrypted with AES-256 — decryption keys are stored only on your device.
- Cloud data is protected by Row Level Security — each family can only access their own records.
- Access to personal data is strictly limited to authorized personnel on a need-to-know basis.
- We will notify you promptly in the unlikely event of a data breach.
7. Your Personal Inbox
- MyClipbox assigns you a dedicated inbox number to receive messages from businesses you subscribe to (e.g. text clubs, deal alerts).
- This is not your personal phone number — it is a separate number managed by MyClipbox.
- Messages received in your inbox are organized on your device — categories, coupons, and events are detected locally.
- You can unsubscribe from any business with a single tap, and we handle the opt-out automatically.
- If you delete your account, your inbox number is released and all associated messages are permanently deleted.
8. Data Retention and Deletion
- We retain your data only while your account is active.
- You may request deletion of all your data at any time.
- Upon deletion, we permanently remove all cloud and device data — messages, receipts, coupons, memberships, and your inbox number.
- Active text club subscriptions are automatically opted-out on your behalf during deletion.
- You can delete individual receipts, shopping lists, and coupons at any time from within the app.
- You have the right to erasure under applicable privacy laws (GDPR, CCPA).
9. Third-Party Services
- Supabase — secure cloud database and authentication (data encrypted, access scoped to your family).
- Anthropic (Claude) — AI vision for receipt and coupon scanning (used only when you initiate a scan; images are not retained or used for AI training).
- Stripe — payment processing (handled by Stripe under PCI compliance — we never see your card details).
- Telecommunications provider — inbox number provisioning and message routing (encrypted, access-controlled).
- No advertising SDKs, analytics trackers, or data brokers are integrated into the app.
10. Your Rights
- Access — request a copy of all data we hold about you.
- Deletion — request complete deletion of your account and all associated data.
- Portability — export your data in a standard, machine-readable format.
- Correction — request correction of any inaccurate personal data.
- Opt-out — unsubscribe from any communications at any time.
- Transparency — view exactly what our AI has processed about you in the "What AI Knows" screen inside the app.
Don't take our word for it
Use our Privacy Scanner to compare this policy against any other app's terms.
Questions about our privacy practices? Contact us at privacy@myclipbox.com