Privacy Policy
Last updated: 10 July 2026
CartUnmask helps you tell whether a shopping “deal” is real. We are privacy-minimal by design: we collect only what we need to check prices and send you the alerts you ask for.
What we collect
- Waitlist email — if you join the waitlist, we store your email address to tell you when CartUnmask is ready. This is handled by our email provider, Resend.
- A device identifier — the app generates a random ID for your install so we can sync your watched products and send push notifications. It is not tied to your name.
- Google account details — if you sign in, Firebase provides an account ID and may provide your email, name, and profile photo. Signing in is optional.
- Products you track — the links and items you add, so we can check their prices over time.
- Screenshots you choose to save — if you use “verify from a screenshot,” the reading is used to compare the in-app price against the price we track. The image itself is stored only when you opt to save it as your own proof, and it is shown back only to you.
- Problem reports — the report type, store, price and note you submit, plus an optional screenshot. Reports are reviewed by CartUnmask and never automatically change a Truth Card verdict.
- First-party usage events — limited actions such as opening the app or add flow, viewing a card, watching an item, sharing a receipt, or opening a notification. We store no IP address or raw product URL in usage analytics and use no third-party analytics SDK.
How we use it
- To check prices and build the Truth Card for a product.
- To send the price and “fake sale” alerts you turn on.
- To improve accuracy and fix problems.
- To measure beta reliability and whether core app flows work.
We do not sell your personal data, and we do not run third-party advertising trackers.
Who processes data for us
- Resend — waitlist email delivery and forwarding a web account-deletion request to our support inbox.
- Google Firebase Cloud Messaging — delivering push notifications to your device. Firebase Authentication verifies optional Google sign-in and handles account deletion.
- Cloudflare — serving our API securely and storing private proof/report images in a non-public R2 bucket.
- Error monitoring (Sentry) — diagnosing crashes and failures. We configure it to avoid collecting personal data.
Retention and security
First-party usage events are deleted after 90 days. Terminal notification records are normally deleted after 90 days. Routine evidence checks may be aged out, while meaningful market evidence is retained to support price history and honesty claims. User-owned reports, analytics, account links, and private images are deleted when you delete your account or install data. Private images are available only through owner-checked app or admin routes.
Your choices
- Unsubscribe from waitlist email at any time using the link in any message.
- Turn any notification on or off in the app.
- Delete a signed-in account in the app under Account → Delete account, or delete guest data under Account → Delete data on this device.
- If you cannot access the app, use our account deletion request or email support@cartunmask.com.
Contact
Questions about privacy? Email support@cartunmask.com.