Provision

Privacy

Last updated 23 September 2026

Provision is a trading name of Bathbloops Ltd, a company registered in England and Wales, number 17401627, registered office 8 Cleveland Road, Hale, Altrincham, WA15 8AY. Bathbloops Ltd is the controller for the purposes of UK GDPR and operates provisionapp.co.uk, contactable at provision.app.support@gmail.com or on +44 7904 000842.

The short version: the app holds the list of supplies you type in, the ages and sexes of the people in your household, and your email address. If you fill them in, it also holds two pieces of health information: a medicine somebody takes daily with the number of doses, and whether somebody is pregnant or breastfeeding. Both are optional, both exist only to work out how long your supplies last, and both are covered in full under health information below. All of it is stored on one server in London. It is not sold, not shared with advertisers, and nothing about you is tracked — see counting, but not tracking below.

What is stored, and why

DataWhy it existsLawful basis
Email addressIdentifies your account so you can sign back in.Performance of a contract
PasswordStored only as a PBKDF2-HMAC-SHA256 hash at 600,000 iterations. The password itself is never written down and cannot be recovered from what is stored — not even by me.Performance of a contract
Household membersAge, sex and activity level. These set the calorie and water figures — a 14-year-old and a 70-year-old do not need the same amount. Names are free text; a nickname works as well as a real one.Performance of a contract
Pregnant or breastfeedingOptional, and health information. Adds 200 or 500 kcal a day to that person's figure and nothing else. See health information below.Explicit consent
Daily medicineOptional, and health information. A number of doses per day, so the first aid list can say how long the supply lasts, and — separately optional again — a label of your choosing for what it is. Only the dose count is used for anything. See health information below.Explicit consent
Nutrition figuresProtein, fat, carbs and salt you copy off a packet. About the food, not about you.Performance of a contract
Your suppliesWhat you have, how much, where it is kept, and its date.Performance of a contract
Session cookieOne strictly necessary cookie so you stay signed in. It holds a random token, not your details, and only its hash is stored on the server. No advertising or analytics cookies are set, which is why there is no cookie banner.Strictly necessary
Calendar feed tokenA random string in your private calendar address.Performance of a contract

Health information

Yes, health-related data is collected, and it is worth being blunt about that. Two of the fields on the household screen are information about health, held against a person you have named, which UK GDPR treats as special category data and holds to a higher standard:

  • A medicine taken daily, and how many doses of it, which is what lets the first aid list say how long your supply lasts.
  • Whether somebody is pregnant or breastfeeding, which changes the calorie figure materially. Leaving it out would make the answer wrong, which is the only reason it is asked.

Both are optional, both are off by default, and the app works without either of them. They are processed only with your explicit consent, given by filling them in, and used for nothing whatever except the two sums above: how long the medicine lasts, and how many calories the household needs a day. Nothing is inferred from them, no profile is built, and nothing on the buying screens changes because of them.

They are never sold, never shared, and never sent to any third party. Not to Amazon, not to Google or Apple, not to an advertiser, not to an analytics service, and not into training anything. They go into the same database as the rest of your store, on one server in London, and stay there.

Deleting is immediate and it is in your hands. Clearing either field and saving removes it. Deleting the person removes their whole row, medicine, doses, pregnancy status and all, from the database at once, with no archived copy kept.

The medicine name is optional even when the dose count is not. The run-down is worked out from the number of doses a day and nothing else, so leaving the name blank changes no figure at all. It is a label printed back to you, so the list can read "their ramipril" rather than "their medicine".

If you do fill it in, it is free text and it is up to you what goes in it. "Blue inhaler" works exactly as well as the drug name.

Provision is not a medical device. It counts what you typed in. It does not know what the medicine is, whether the dose is right, or what happens if you run out.

The calendar feed

Your expiry dates are published as a private iCalendar feed at an address containing a long random token. Anyone who has that address can read your store's dates. They cannot change anything, and they cannot sign in as you.

Treat it as a password. If you have shared it or think it has leaked, rotate it from the Calendar tab — the old address stops working immediately.

Once you subscribe, a copy of those dates sits with whoever runs your calendar — Google, Apple, or Microsoft — under their privacy policy, not this one.

Signing in with Google

If you choose Google, Provision receives your email address, whether Google has verified it, and a stable account identifier. It does not receive your password and does not ask for access to your Gmail, contacts, files, or your Google Calendar. The calendar feed is a subscription address you add yourself; the app never writes to your calendar.

You do not have to use Google. Email and password works the same, and accounts created that way are never linked to Google.

The camera and barcodes

Scanning a barcode uses the camera on your device, with your permission, and decodes the stripes on the device itself while you hold it there. No photograph is taken, nothing is uploaded, and no image ever reaches the server. The only thing that leaves is the number underneath the barcode.

The server then looks that number up in Open Food Facts, an open community database of groceries, and sends back a name, a pack size and a nutrition table. The lookup goes out from the server rather than from your device, so Open Food Facts learns a barcode and nothing about you — not your address, not your account, and nothing else in your store.

The to buy and build up screens link to Amazon, and those links carry an affiliate tag. If you buy something, Amazon may pay a commission at no extra cost to you. Following one tells Amazon you arrived from Provision; what you do there is covered by Amazon's privacy notice. As an Amazon Associate, Provision earns from qualifying purchases.

The commission does not influence the advice. What the app suggests is calculated from your own store and target — it buys whatever you are short of, and nothing on the list is paid placement.

Where it is stored, and who else can see it

Everything above lives in a single SQLite database file on one machine hosted by Fly.io in their London region. One machine and one file, on purpose: a second copy of the database is a second thing to lose track of. Nothing is replicated abroad, and there is no separate analytics store, no data warehouse and no third-party backup service holding a copy.

Traffic between the app and that server is encrypted in transit over HTTPS, which is enforced rather than merely offered.

  • Fly.io hosts the server and stores the database, in their London region. Everything above passes through them, and they are the only processor that touches your store or your household.
  • An email provider delivers the handful of messages the app sends, which today is password resets and nothing else. They see the address the message goes to and what it says. They never see your store.
  • Stripe takes the payment if you subscribe on the web, and holds the card details, which never reach this server. On Android and iOS the payment goes through Google Play or Apple instead, under their terms. None of them receive your store or your household.
  • Nobody else. The data is not sold, rented, shared with advertisers, or used to train anything. That includes the health information: it has never left this database and there is no code in the app that would send it anywhere. There are no tracking pixels and no third-party scripts on the page.

Counting, but not tracking

Provision keeps a daily tally of a few things — how many people reached the front page, how many finished the calculator, how many made an account. It is how anyone can tell whether the app is being used at all.

The tally cannot be traced to you. It is a count and a date, and nothing else: there is no column in it for who did the thing, no cookie, no identifier, and no third party involved. Nobody can look up what you did, including us, because it was never written down.

One thing is counted per account, and it is worth naming rather than hiding: the number of barcode lookups you make in a day, so a daily limit can be enforced on a service somebody else pays for. It is a date, a number, and which account, and it goes when the account goes. Nothing you looked up is recorded.

How long it is kept, and deleting it

Until you delete it. Sign-in sessions expire after 60 days.

Three things you can delete yourself, from inside the app, and they take effect on the spot:

  • A person. Deleting them from the household screen removes their whole row — name, age, sex, medicine, doses and pregnancy status — from the database immediately.
  • A field. Clearing the medicine name, setting doses to zero, or setting additional needs back to none, and then saving, overwrites what was there.
  • An item, or the whole store at once by resetting it.

To close the account itself, Settings → delete my account. You type your email address to confirm, and it happens straight away: every row belonging to the account goes — supplies, household, kit answers, settings and sessions — permanently, with no backup copy kept for a rainy day. There is no charge, no waiting period, and no reason has to be given.

If you would rather somebody did it for you, email provision.app.support@gmail.com from the address the account uses and it will be done by hand.

Your rights

Under UK GDPR you can ask for a copy of your data, correct it, delete it, restrict or object to its use, or ask for it in a portable format.

You do not have to ask for the copy. Settings → your data downloads everything this account holds — household, settings and every field of every item — as a JSON file, plus the inventory as a spreadsheet. It is on every plan, because it is your data rather than something we sell. For anything else, email provision.app.support@gmail.com and you will get a reply within 30 days.

If you are unhappy with the response you can complain to the Information Commissioner's Office at ico.org.uk.

Children

Provision is not aimed at children and accounts are for adults. Children can of course be listed as members of a household — that is the point of asking for ages — and those entries are ordinary account data belonging to the adult who created them.

Changes

If this policy changes in a way that affects you, the date at the top changes and you will be told in the app before it takes effect.