Privacy · limited beta
How we handle what you send us.
Plain-language summary of what ChoiceWorth collects when you upload a gas bill, search for fuel, or scan a grocery receipt, what we retain, and who processes the data on our behalf. Last reviewed 2026-09-09.
What ChoiceWorth is
A Georgia-focused household-decision helper. You give it a bill, a ZIP code, a receipt, or a vehicle profile. It reads the fine print, cross-checks public information (Georgia Public Service Commission filings, Google Maps fuel data, and — when enabled — Kroger product data and USDA FoodData Central nutrition), and returns a summary you can act on. It is not a broker, a marketplace, a savings guarantee, or a personalized offer feed.
What we collect, and when
Only what you provide, and only for the flow you use:
- Gas bill uploads. The image or PDF you submit, and the structured extraction the AI returns (marketer, rate per therm, plan type, expiration date, monthly charges, billing period). The extraction prompt explicitly forbids account numbers, meter numbers, names, addresses, and email addresses; stored extraction JSON is passed through an additional redaction helper.
- Gasoline search. The ZIP code, fuel grade and radius you submit. Nothing is written back to Google's Places or Routes APIs about you individually.
- Grocery receipt uploads. The photo you submit, plus the line items and prices the AI extracts. Loyalty numbers, phone numbers, and addresses on the receipt are excluded by prompt and stripped again server-side.
- Vehicle profile (optional). Make, model, year, EPA combined MPG, tank size. Stored against a random per-browser identifier (not your identity) in a `httpOnly` cookie.
- Watch requests. If you ask for a renewal reminder on your gas bill or a price-drop alert on fuel, the email address you enter is stored so we can send that specific reminder.
- Aggregate visit counts. Only when explicitly enabled. Uses a rotating daily network hash — no cookies, no personal identifiers, honors Do-Not-Track and Global Privacy Control. Counts estimate networks, not identified people.
What we do not collect
- No user account, no password, no name.
- No marketing email opt-in. The only emails we ever send are the specific reminders you request.
- No third-party analytics (no Google Analytics, no Meta Pixel, no Segment).
- No cross-site tracking cookies.
- No sale or sharing of anything to advertisers or data brokers, ever.
PII redaction is best-effort, not a guarantee. If the AI or the redactor misses a personal identifier printed on your bill, some copy of it may briefly exist in our processing. Crop or blur account numbers, addresses, and names before uploading.
Who processes your data
These third parties see the specific data noted below, only for the immediate request. None have a standing feed of ChoiceWorth's stored data.
- OpenAI (via our OmniRoute gateway) or Google AI — receives the image content of a bill or receipt when you upload one, so it can extract structured fields. We do not use these providers for anything except extraction on the specific document you sent. Their data-use terms apply to that interaction.
- Google Maps Platform (Places, Routes) — receives the ZIP code and, for detour math, approximate coordinates. It does not receive any personal identifier.
- Kroger Public API (only when the grocery-store feature is enabled and approved) — receives the store number and product identifiers for the exact-basket lookups you request.
- USDA FoodData Central (only when nutrition lookup is enabled) — receives food and nutrient queries or a specific UPC/GTIN you look up. Public dataset; queries are not linked to you.
- Google Cloud (Compute Engine, Secret Manager, Persistent Disk snapshots) — hosts the database, application, and encrypted backup snapshots. Data is stored in the United States (`us-east1`).
- Email provider — planned, not currently sending. When configured, sees only the specific reminder email address and message content you triggered.
How long we keep things
- Bill and receipt records: access ends 30 days after upload, or immediately when you delete them from the app (either action requires the private cookie set in your original browser).
- Physical expiry: a scheduled maintenance job purges expired records from the database on a rolling basis.
- Encrypted backup snapshots: retained 14 days in Google Cloud, then expired automatically. Backups do not support instant deletion of a single record — a deleted record may persist in a snapshot until that snapshot ages out.
- Vehicle profile: stored against your browser cookie. Removing the vehicle in the app (or clearing your browser cookies) removes it.
- Watch requests: retained until the reminder is sent or you ask us to delete it.
- Uploaded document originals: not retained after processing; only the extraction result and its metadata are stored.
Your controls
- Delete a bill or receipt — open the result page in the browser you uploaded from and use the delete button. This removes the bill/receipt, its extracted items, its cached recommendations, and any associated funnel events. Deletion requires the private cookie from the original upload.
- Remove your vehicle profile — use "Remove" on the vehicle picker on the fuel page.
- Cancel a reminder — email admin@choiceworth.com with the address you signed up with and a description of the reminder. There is no self-service unsubscribe link because there is no marketing list to unsubscribe from.
- Ask for everything about you to be removed — email us. Because we don't operate a user identity, we may need extra information (approximate upload date, marketer name on your bill, ZIP code you searched) to locate the records.
Security
- TLS in transit (Let's Encrypt), automatic renewal.
- Application secrets managed in Google Secret Manager; not stored in the container image or in version control.
- Uploads are optionally scanned with ClamAV before processing.
- Persistent disk encrypted at rest by Google Cloud default; automated daily snapshots retained 14 days.
- Content Security Policy, HSTS, and standard OWASP response headers enforced.
No system is unbreachable. If you become aware of a security issue in ChoiceWorth, please email us at the address below rather than posting publicly.
Children
ChoiceWorth is intended for adult household decision-makers. It is not designed for and does not knowingly collect data from anyone under 13.
Changes to this policy
When we materially change what we collect, who processes it, or how long we keep it, we'll update the "Last reviewed" date at the top and note the change in the site's changelog. Continued use after the change constitutes acknowledgment; if a change would reduce your existing protections we will note it prominently before it takes effect.
Contact
Questions, deletion requests, or security reports: admin@choiceworth.com.
For anything that isn't urgent, the fastest way to get a straight answer is a short email describing what you did on the site, what happened, and what you'd like changed.
