Scavenger for Android — Privacy Policy
Last updated: September 6, 2026
Scavenger is built by Northbaseworks, LLC ("Northbaseworks," "we," "us"). This policy explains what information Scavenger for Android collects, how it's used, and what choices you have.
- The short version
- Account & identity data
- Household & shopping list content
- Invite links & invite codes
- Scout AI (photo & voice input)
- Location
- Device & anti-abuse data
- Diagnostics & logs
- Third-party service providers
- Data retention
- Deletion & your choices
- Your rights
- Children's privacy
- Security
- Changes to this policy
- Contact
The short version
Scavenger for Android doesn't collect more than it needs to keep your household's shopping lists in sync, run Scout (its AI-powered photo and voice input), and help you find nearby stores. Signing in with Google shares your email address and your Google account's display name with us — we use your email to create and manage your account, and your display name to identify you to your household. Photos and voice input you submit to Scout are sent to a third-party AI service to extract and categorize items, and are not stored by Northbaseworks afterward. If you use nearby-store search, your approximate location is sent directly from your device to a third-party mapping service to find real businesses near you. We don't sell your data, use your photos or lists to train AI models, or show ads.
Account & identity data
Scavenger for Android requires signing in with a Google account. Signing in shares two pieces of information with us, which are used for two different purposes:
- Your email address — used to create and manage your account (for example, to sign you back in and to identify your account for support or deletion requests). Your email address is not shown to other members of your household.
- Your Google account's display name — read from your Google sign-in credential and stored against your household record so other members of your household can see who's who in Party Settings, instead of a generic "Member 1"/"Member 2" label. Your display name is visible to every other member of any household you belong to; it is not visible outside your household(s).
We do not store your Google account profile photo. There is currently no way to sign in without a Google account — there is no guest, anonymous, or offline mode.
Household & shopping list content
Scavenger organizes your shopping around a household ("Party"): the store list, hunts (shopping trips), and items on them. This content is stored using Google's cloud infrastructure, scoped to your household and accessible only to members of that household — nothing is visible across households.
If you invite others to your household, they can see and edit the same shopping lists, store list, and hunt history you can, and they can see your display name — household membership is an all-or-nothing, shared view by design.
Invite links & invite codes
You can invite someone to your household two ways: an 8-character invite code, or a share link of the form scavenger.northbaseworks.com/invite/…. Both refer to the same single-use invitation, which expires seven days after it's created.
- What the link contains. The identifier in an invite link is itself the secret that authorizes joining — anyone who has the link can use it once, until it expires or is redeemed. Treat it like a key, and share it only with the person you're inviting.
- What the landing page shows. Opening an invite link loads a page served by Northbaseworks that looks up only that one invitation and displays its status — the household's name and invite code if it's still valid, or a message saying it has expired, has already been used, or isn't a valid invite. That page requires no sign-in and reads only the invitation record; it cannot read the household's lists or any member's information.
- How it's handled. The invite page is served with caching disabled, so a response containing your invite is never cached and served to someone else by a browser or intermediate network. Northbaseworks does not log or retain the invite identifier from the URL. The page is rate-limited by IP address to prevent automated guessing of invite links; if that limit is triggered, the event is logged without the invite identifier, as described under Diagnostics & logs.
- Opening in the app. If you already have Scavenger installed on your Android device, tapping an invite link may open the app directly rather than a browser, through Android App Links. This is handled by Android and your device; whether the link opens the app or the web page, the same single-use invitation is what gets redeemed, and redeeming it always happens from within the signed-in app.
Redeeming an invitation is also rate-limited per IP address, to bound attempts to guess an invite code rather than use a real one. See Device & anti-abuse data for how that data is used.
Scout AI (photo & voice input)
Scout is Scavenger's AI-assisted feature for turning a photo of a list, or a spoken item, into structured shopping-list entries.
- Photos. When you use Scout to scan a photo, the image is sent from your device to Northbaseworks' backend, which forwards it to Anthropic, a third-party AI service we use to read and categorize the photos and text you submit to Scout, to identify and extract item text. The image is used only to generate that result and is not written to Northbaseworks' own storage — it passes through our backend without being saved.
- Voice input. When you add items by speaking, Android's system speech recognizer converts your voice to text on-device — the audio itself is not sent to Northbaseworks or Anthropic. Only the resulting text is sent to Scout for categorization.
- Text categorization. Item names (typed or transcribed) are sent to Anthropic to suggest a category.
Anthropic acts as our AI processing provider for Scout. Anthropic's own retention of what you submit is governed by Anthropic's commercial terms, separate from this policy — Northbaseworks does not currently retain a copy of submitted photos or text after Scout returns a result. If you're located outside the United States, using Scout means your photo or item text is transferred to and processed in the United States.
Location
If you use Scavenger's nearby-store search, your device's location is requested — through the standard Android location permission prompt — only when you open that feature; Scavenger does not access your location at any other time or in the background.
Your approximate location — accurate to roughly city-block level, not your exact position — is sent directly from your device to OpenStreetMap, a third-party mapping service not operated by Northbaseworks, to look up real nearby businesses matching the store category you're searching for. This request goes straight from your device to that service — it is not routed through, logged by, or stored on Northbaseworks' own backend. Northbaseworks does not receive, log, or retain your location.
Device & anti-abuse data
To keep Scout AI usage fair and prevent abuse (for example, one device repeatedly creating new households to get around usage limits), our backend uses your IP address briefly, at the time of a request, to apply rate limits and detect abusive traffic patterns — see Data retention for how long this is kept. Android does not currently use a device-attestation mechanism beyond this.
Diagnostics & logs
Like most online services, Scavenger's backend keeps a limited amount of operational data to keep the service running, secure, and reliable:
- Crash and performance diagnostics. Crash, hang, and performance data (app version, OS version, device type, and similar metrics) may be sent to Northbaseworks' backend, tied to a randomly generated household identifier — never your Google account, name, or email.
- Error and rate-limit logs. When a request to our backend fails, gets rate-limited, or errors, we log details like the route and error type, along with your IP address and basic information about your device and app version, to detect abuse and diagnose problems.
- Support requests. If you contact us through the in-app support flow or the contact form on this website, we receive whatever you choose to include (for example, your name, email, and message) so we can respond.
- We use this data only to operate, secure, and improve Scavenger. We do not use it to build advertising profiles, and we do not sell it.
Third-party service providers
Scavenger for Android relies on a small number of service providers to function:
- Google — handles Google Sign-In, and stores your household and shopping-list data.
- Google Play Billing — handles Scout subscription purchases. Payments are made to Google, and Northbaseworks never receives or stores your payment details; our backend records only a purchase token against your household, used to check whether that household's subscription is active.
- OpenStreetMap — a third-party mapping service used directly from your device for nearby-store search, as described above.
- Anthropic — processes photos and item text submitted through Scout, as described above.
- Our hosting provider (Cloudflare) — hosts Northbaseworks' backend infrastructure (Scout processing, diagnostics, anti-abuse checks) and this website.
Data retention
We keep data only as long as it's useful for the purpose it was collected for:
- Archived shopping trips (hunts). Deleted automatically 90 days after being archived.
- Abandoned households. A household with no activity for 12 months, along with all of its lists, stores, and hunt history, is deleted automatically.
- Crash/performance diagnostics. Kept for 90 days, then deleted.
- Error and rate-limit logs. The IP address and device information on these logs are cleared after 30 days; the underlying event record (without that identifying detail) may be kept longer, up to 90 days, for aggregate trend analysis.
- Scout usage and subscription records. Kept for as long as needed to support billing history and account troubleshooting.
- Photos and voice-derived text sent to Scout. Not retained by Northbaseworks after a result is returned to your device.
- Location data. Not retained by Northbaseworks at all — it is sent directly from your device to OpenStreetMap and never reaches our backend.
Deletion & your choices
Deleting a household. The member who created a household is its owner, and only the owner can delete it. Deleting a household permanently removes that household's lists, stores, hunts, and item history, along with the member display names stored against it, for every member.
Leaving a household, or being removed from one. Any member other than the owner can leave a household at any time, and the owner can remove another member. In both cases the effect on your data is the same and is deliberately narrow: your account identifier is removed from that household's member list, so the household's content is no longer accessible to you and you no longer appear as a current member. The household's shared content — its lists, stores, and hunt history — is not deleted, because that content is household-scoped rather than attributed to individual members; it stays available to the remaining members. Your display name may remain stored as an inactive entry on that household record after you leave; it is no longer shown as a current member anywhere in the app. Leaving or being removed also has no effect on any subscription attached to that household, which is recorded at the household level and is not attributed to whichever member purchased it. The owner cannot leave a household without deleting it, because Scavenger does not currently support transferring ownership.
Leaving a household is not the same as deleting your account. There is still no in-app "delete my account" action — Settings offers Sign out, Leave Party, and Delete Party only — but you can request deletion of your account (your account identifier, email address, and display name) at northbaseworks.com/scavenger/delete-account, which does not require the app to be installed. Requests are processed manually and confirmed by email; if you own a household with other members, deleting your account deletes that household for everyone, the same as using Delete Party, since Scavenger does not currently support transferring ownership.
Scout's photo scanning and voice input are optional — you can use Scavenger's core list and sharing features entirely by entering items manually. Nearby-store search is also optional and only accesses your location if you open it and grant the permission prompt.
Your rights
Depending on where you live, you may have rights to access, correct, or delete personal information we hold about you. Contact us at the address below to make a request.
Children's privacy
Scavenger is intended for users 16 and older. The app does not currently ask for or verify a user's age at sign-up.
Security
Household and shopping-list data is protected by access-control rules that restrict it to members of that household. We rely on the security practices of our infrastructure providers (Google, Cloudflare) in addition to our own access controls. No method of storage or transmission is completely secure, and we can't guarantee absolute security.
Changes to this policy
If this policy changes, the "last updated" date above will change and, for material changes, we'll make reasonable efforts to notify users through the app.
Contact
Questions about this policy or Scavenger's data practices: use the contact form on our Support page. To actually request deletion of your data, use the dedicated form at northbaseworks.com/scavenger/delete-account instead — the Support page's contact form is for questions, not for submitting a deletion request.