Basket Vitality
Last updated · 20 July 2026
Basket Vitality reads your receipts and bank statements on your phone, and keeps them there. We don't have a server that stores your data, we don't have accounts, and we can't see your spending, your shopping, or your health information. There is no analytics and no crash reporting.
The only things that ever leave your phone are anonymous lookups to Open Food Facts — the barcode you scan, and a product's photo and details if you open them — plus a periodic update of the product database. Nothing that identifies you goes with any of them.
If that's all you wanted to know, you're done. The rest is detail.
Basket Vitality is built by TheDevSpot, based in the Netherlands. For anything privacy-related, contact privacy@basketvitality.com.
Under the GDPR we are the data controller for the very limited processing described below. For everything stored on your device, you hold the data — we have no copy and no access.
All of it, in practice:
This is stored in an encrypted database on your device, using AES-256. The encryption key is itself protected by the Android Keystore, unlocked by your PIN or biometrics. If someone takes your phone and pulls the app's files off it, they get ciphertext.
We never receive any of this. There is no account to sign into, no sync, and no backup we hold.
Two things, and only two.
When a scanned item isn't in the product database already bundled with the app, we ask Open Food Facts about it. The request contains only the product's barcode — a number identifying the product, not you. It carries no device identifier, no account, no location, and nothing about your basket, your budget or your other items.
Open Food Facts is an independent open database. Their servers will see the request, including the IP address your phone connects from, as any web request would. We do not send them anything else, and we do not receive anything about you from them.
The request identifies the app in its User-Agent header so Open Food Facts can see which application is calling — this is their published etiquette for API users, not a tracking mechanism.
If you open a scanned product's detail, its photo, ingredients and additive list are fetched from Open Food Facts in the same way — again keyed only by the product, never by you, and only for a product you chose to look up. Nothing about your visit is recorded beyond the ordinary web-server log of the request.
The app periodically downloads an updated bundle of product and nutrition data. This is a plain download — a file comes to your phone. Nothing about you is sent in order to fetch it.
There is no analytics SDK, no crash reporting, no advertising, no tracking, and no telemetry of any kind in the app. This isn't a policy promise about how we'd use such data — the code contains none.
| Permission | Why |
|---|---|
| Camera | To photograph receipts and scan barcodes. Images are processed on the device and stored encrypted; they are never uploaded. |
| Internet | Only for the two flows above — product lookups and database updates. |
| Biometrics / Fingerprint | To unlock the app, if you choose to enable it. Your fingerprint or face never leaves the Android system; the app only receives a yes/no. |
The app requests no location, no contacts, no SMS, and no access to your photo library.
Reading the text off a receipt uses Google's ML Kit text recognition, running entirely on your phone with a model bundled in the app. Your receipt image is not sent to Google or to us in order to be read.
If you subscribe to a paid plan, the payment is handled entirely by Google Play Billing. We never see your card details. The app only learns whether your subscription is active. Google's handling of your payment data is covered by Google's privacy policy.
Basket Vitality does not connect to your bank. Statement importing works on a file you export from your bank yourself and choose to open in the app; the parsing happens on your device.
Direct bank connections are planned for a later release. If and when that ships, this policy will be updated before the feature is available, and connecting an account will be something you explicitly opt into.
Because your data lives on your device and we hold no copy, most GDPR rights resolve directly in the app rather than by writing to us:
Uninstalling the app also removes all of it.
You have the right to lodge a complaint with a supervisory authority. In the Netherlands that is the Autoriteit Persoonsgegevens.
Basket Vitality is not directed at children and we do not knowingly process children's data. Since we hold no data at all, there is nothing for us to delete on request — clearing the app's data removes everything.
If the app starts doing something materially different with data — a new outbound connection, optional crash reporting, bank connections — this policy will be updated before that ships, and the change will be called out in the app rather than quietly edited here. The last-updated date above always reflects the current version.