Scavenger — Privacy Policy
Last updated: August 8, 2026
Scavenger is built by Northbaseworks, LLC ("Northbaseworks," "we," "us"). This policy explains what information Scavenger collects, how it's used, and what choices you have.
The short version
Scavenger doesn't require an account. Your shopping lists and household sharing are handled through your own iCloud account using Apple's CloudKit framework — Northbaseworks does not operate a separate server that stores your list content by default. Photo-based item recognition and AI categorization (Scout) are processed using Anthropic's API rather than on your device. We don't collect advertising identifiers, track your location on our servers, or sell any data.
Information Scavenger handles
- Shopping list content. Items, quantities, and notes you add to a Hunt are stored in your iCloud account via Apple's CloudKit, and sync across your own devices the same way.
- Shared household data. When you invite others to your Party, list data is shared directly between the invited iCloud accounts using Apple's CKShare mechanism. Northbaseworks does not have a separate copy of this shared data.
- Photos for item recognition (Scout). When you use Scout's photo scanning feature — including the free tier — the photo is sent securely through Northbaseworks' backend to Anthropic's API to identify and extract item text. Photos are transmitted for processing only; Northbaseworks does not retain a copy after the result is returned to your device. Under Anthropic's standard commercial API terms, submitted content is not used to train Anthropic's models and is retained only briefly (currently up to 7 days) for abuse-monitoring purposes before being deleted.
- AI categorization (Scout Pro, subscribers only). If you subscribe to the AI categorization tier, the text of list items you're actively organizing (not photos, and not any account or device identifier) is sent through the same Anthropic API pipeline described above to generate category suggestions, under the same no-training, short-retention terms.
- Location for finding nearby stores. If you use Scavenger's store discovery feature, your device's location is used, via Apple's MapKit, to search for nearby stores and enable the Navigate action. This lookup is handled by Apple's mapping services; Northbaseworks does not receive, log, or store your location.
- Subscription and payment information. Subscriptions are handled entirely by Apple through StoreKit. Northbaseworks never receives or stores your payment details.
- Restoring your subscription to a new household. If you delete and recreate a household, Scavenger uses Apple's own subscription identifier for your purchase (tied to your Apple ID, not to any specific household) to automatically look up and reapply your Scout subscription to the new household — so you don't lose access or have to remember to tap Restore Purchases. This lookup happens entirely through Apple's StoreKit and Northbaseworks' backend; it doesn't involve any additional personal information beyond what Apple already provides for subscription verification, and it extends coverage to everyone in your household, the same as it did before.
What we don't collect
- No account creation, no password, and we never ask for or see your email address — including when you send feedback or report a problem, which now goes directly through the app rather than your email client, so we never learn who you are or how to reach you unless you choose to tell us in the message itself.
- No advertising identifiers or third-party ad tracking
- No location tracking or storage on our servers — location is used in the moment, on Apple's mapping services, only to find nearby stores
- No access to your contacts beyond what iCloud sharing itself requires, which Apple — not Northbaseworks — manages
- No use of your photos or list content to train AI models
Third-party service providers
Scavenger relies on a small number of service providers to function:
- Apple — iCloud/CloudKit for list storage and household sharing, MapKit for store search, and StoreKit for subscription billing.
- Anthropic — processes photos and item text submitted through Scout to power item recognition and categorization, as described above.
- Cloudflare — hosts Northbaseworks' backend infrastructure and this website. We use Cloudflare Web Analytics, a cookieless tool that reports aggregate site performance and traffic trends (such as page views and country-level visit counts) without tracking or storing data about individual visitors.
If you're located outside the United States, using Scout means your photo or item text is transferred to and processed in the United States by Anthropic.
Logs, diagnostics & analytics
Like most online services, Scavenger's backend keeps a small amount of operational data to keep the service running, secure, and reliable:
- Rate-limiting. Your device's IP address is used only briefly (up to 2 hours) to detect abusive request patterns, then discarded. It is never written to persistent storage and is never used to determine or track your location.
- Usage logs. We keep lightweight logs of Scout usage (such as request counts and which model was used) tied to an anonymous household identifier — never your name, email, or iCloud identity. Usage and subscription-related logs are kept for as long as your subscription is active, so we can provide billing support and troubleshoot your account if you contact us.
- Error, auth-failure, and rate-limit events. When a request to our backend fails to authenticate, gets rate-limited, or hits a server-side error, we log the originating IP address and browser/device (User-Agent) string alongside it, for up to 30 days, solely to detect and diagnose things like abuse or a misconfigured client repeatedly failing to authenticate. This is separate from the brief, non-persistent rate-limiting IP use described above, is not linked to any account, name, or iCloud identity, and the IP address and User-Agent are cleared after 30 days even though the underlying event record itself may be kept longer (up to 90 days) for aggregate error-rate trends.
- Crash and performance diagnostics. Using Apple's MetricKit, Scavenger may send sampled, aggregated crash and performance data (app version, OS version, device type) directly to Northbaseworks' own backend — never to a third party — to help us find and fix bugs. This data is kept for 90 days.
- Feedback and problem reports. The in-app "Send Feedback" and "Report a Problem" features send your message directly to us through the app — not through your email client. Report a Problem also includes your app version, OS version, device model, your household's Account ID (a short, non-reversible support code tied to your household, used to look up your account if you contact us — not your name or email), your current subscription plan (Free, Lite, or Pro), and up to the last 30 minutes of on-device technical logs (things like CloudKit sync timing and error events — not personal content). Send Feedback does not include any log data. Neither feature collects or transmits your email address or name — we never see them unless you choose to include them in your message itself.
- How we use this data. We use logs and diagnostics only to operate, secure, and improve Scavenger — for example, fixing crashes, preventing abuse, and understanding which features need work. We do not use this data to build advertising profiles, and we do not sell it.
How long data is kept
Your list data lives in your own iCloud account for as long as you keep the app installed and signed in with iCloud. Deleting the app, removing Scavenger's iCloud data, or leaving a shared Party removes the corresponding data from your device and iCloud. Photos and item text sent to Anthropic for Scout processing are not separately retained by Northbaseworks and are retained by Anthropic only briefly, as described above, before deletion.
Your choices
Scout's photo scanning and AI categorization are optional. You can use Scavenger's core list and sharing features entirely without them by entering items manually. If you have questions about data associated with your use of Scavenger, or would like more information about exercising any privacy rights available to you under applicable law, contact us using the information below.
Children's privacy
Scavenger is not directed at children under 13, and we do not knowingly collect personal information from children under 13.
Changes to this policy
If this policy changes, the "last updated" date above will change and, for material changes, we'll make reasonable efforts to notify users through the app.
Contact
Questions about this policy or Scavenger's data practices: privacy@northbaseworks.com