TossLess
Privacy Policy
Last updated August 30, 2026
This Privacy Policy explains how Engine Builder LLC (“Engine Builder,” “we,” “us,” or “our”), an Ohio limited liability company with its principal place of business in Ohio, collects, uses, discloses, retains, and deletes information when you use the TossLess mobile app and related support services (collectively, “TossLess”). TossLess is currently offered only in the United States. This policy does not govern the general Engine Builder website, which has a separate Website Privacy Notice.
Information we collect
Account information
We collect the email address you use to create and recover a household account, an internal account identifier, authentication and session information, and basic household-account details. Password authentication is handled by our authentication provider; we do not receive or store your password in readable form.
Kitchen and household content
We store content you choose to add to TossLess, including inventory and Shopping-list items, quantities, categories, barcodes, freshness estimates, optional kitchen storage locations such as “Pantry” or “Freezer,” saved recipes, recipe history, cooking confirmations, and household settings. Settings may include cooking preferences, dietary choices, ingredients to avoid, pantry staples, portions, cuisine, time, taste, cleanup preferences, and custom instructions.
“Storage location” in TossLess means a kitchen location you enter. TossLess does not request or collect your device’s GPS location.
Receipt text, photos, and voice recordings
If you choose an assisted-capture feature, TossLess may process pasted receipt text, receipt or kitchen photos, or a short voice recording to prepare an editable inventory preview. Photos and audio are transmitted to our service and our AI provider for that request. TossLess does not save the original photo, audio recording, or transcript in its application database. Temporary files created on your device for processing are deleted after the request finishes or fails.
AI inputs and outputs
To provide AI Chef and Smart Shopping, TossLess sends the information needed for your request to Google’s Gemini API. Depending on the feature, that information can include selected inventory items, current Shopping-list items, cooking preferences, ingredients to avoid, pantry staples, and custom instructions. Generated recipes and suggestions are returned to TossLess; recipes are stored only when required for recipe history or when you choose to save them.
Subscription and purchase information
If subscriptions are enabled and you view, purchase, or restore a plan, Apple and RevenueCat process information such as a pseudonymous TossLess account identifier, product and entitlement identifiers, subscription status, purchase and renewal dates, expiration, billing state, and store transaction information. Engine Builder does not receive your full payment-card number. Apple processes payment information under Apple’s own terms and privacy policy.
Usage, reliability, and cost information
We collect limited product events such as the feature or capture method used, whether a preview was completed or cancelled, and bounded item counts. This event system cannot store grocery names, recipe text, receipt contents, images, audio, transcripts, preferences, or other free-form content. We also record AI action type, provider, model, request status, token counts, estimated cost, timestamps, and a request identifier for quotas, reliability, and cost control.
Our services may process ordinary network and technical information, such as IP address, request time, app or device information, endpoint, response status, and a randomly generated error identifier. TossLess application logs are designed not to include request bodies, authentication tokens, receipt contents, photos, audio, transcripts, inventory names, or recipe text.
Support communications
If you contact us, we receive your email address and the information you include in your message. Please do not send passwords, authentication tokens, full receipt images, voice recordings, or other sensitive household information in a support email.
Children’s privacy
TossLess is not directed to children under 13. A child under 13 may not create an account, use TossLess, or submit information directly to TossLess. We do not knowingly collect personal information from children under 13.
If you believe that a child under 13 has provided personal information to TossLess contrary to this policy, contact tosslesssupport@enginebuilderllc.com. If we learn that we collected personal information from a child under 13, we will take reasonable steps to delete it.
How we use information
- Provide, personalize, maintain, and secure TossLess and your shared household account.
- Process inventory capture, recipe generation, cooking confirmation, Shopping lists, and subscription access.
- Authenticate users, recover accounts, prevent misuse, enforce usage limits, and investigate reliability or security incidents.
- Understand feature performance using limited, content-free product analytics.
- Measure provider usage and cost and protect the service from unexpected or abusive spending.
- Respond to support requests and comply with legal obligations.
AI processing
Google processes the content sent to Gemini to provide the requested AI feature and for limited service-safety purposes under Google’s applicable terms. Google states that content submitted through paid Gemini API services is not used to improve its products, although prompts and responses may be logged for a limited period to detect prohibited use. TossLess does not use Google Search or Maps grounding for these features.
Do not put information in an AI prompt, photo, receipt, or recording that is not needed for the kitchen task. AI output can be inaccurate and must be reviewed before you rely on it.
When we disclose information
We do not sell personal information, share it for cross-context behavioral advertising, use it for targeted advertising, or use advertising trackers. We disclose information only as needed to operate TossLess, complete a transaction, protect the service, comply with law, or complete a business transfer subject to appropriate safeguards.
Core service providers currently include:
- Supabase for email/password authentication and household application data.
- Google Cloud and the Gemini API for API hosting, security and operational infrastructure, media analysis, recipe generation, and Smart Shopping.
- RevenueCat for subscription status, entitlements, purchase restoration, and subscription-event processing.
- Apple for App Store distribution, in-app purchases, refunds, and subscription management.
- Open Food Facts for product information associated with a barcode you choose to scan.
We require service providers that process personal information for us to protect it consistently with their contractual obligations, this policy, and applicable law. Providers may process information in the United States and other locations where they or their subprocessors operate.
Retention and deletion
- Household content and account data: retained while the account is active or until you delete particular content or the account, unless retention is required for security, legal, or dispute purposes.
- Content-free product analytics: automatically removed after 180 days.
- AI usage and cost records: successful or cost-bearing records are retained for up to 90 days; zero-cost denied, failed, or abandoned reservations are retained for up to 30 days.
- Subscription records: retained while needed to provide subscription access, resolve billing or entitlement issues, prevent fraud, and satisfy accounting or legal obligations.
- Support communications: retained as reasonably necessary to answer the request, maintain business records, and protect the service.
Where isolated backup copies exist, deletion takes effect as those backups are overwritten on the regular backup schedule. We do not use backups to continue ordinary processing of deleted account data. Information already held by Apple, RevenueCat, Google, or another provider may remain for the period required by that provider’s terms or applicable law.
Your choices and rights
You can review, correct, or delete much of your household content directly in TossLess. You can permanently delete the TossLess account from the app after recent password authentication. Account deletion removes the account and household-owned TossLess records, including inventory, settings, recipes, Shopping items, analytics, and TossLess entitlement records.
Deleting a TossLess account does not cancel an Apple subscription. Manage or cancel the subscription in Apple’s subscription settings before deleting the account. Apple, RevenueCat, and other providers may retain transaction or security records as described above.
Depending on where you live, you may have rights to request access, correction, deletion, or a copy of personal information, or to object to or restrict certain processing. Email tosslesssupport@enginebuilderllc.com with the subject “TossLess privacy request.” We may need to verify that you control the relevant account before completing a request.
Security
We use safeguards designed for the sensitivity of the information, including encrypted network connections, access controls, household-level database isolation, server-derived ownership, bounded uploads, private operational records, and restricted service credentials. No method of storage or transmission is completely secure, so we cannot guarantee absolute security.
Changes to this policy
We may update this policy when TossLess, its providers, or legal requirements change. We will change the date above and provide additional notice when required by law. If a change materially expands how previously collected information is used, we will seek consent where required.
Contact
Engine Builder LLC is responsible for TossLess. Privacy questions and requests can be sent to tosslesssupport@enginebuilderllc.com. For ordinary product help, visit TossLess Support.