Privacy Policy
Last updated: April 27, 2026
1. Who we are
Pantry ("we", "our", "us") is an AI-powered kitchen assistant for iOS that helps you track what's in your fridge, surface recipes, and reduce food waste. This Privacy Policy explains what we collect, why, and the controls you have. We are the data controller for your account data.
2. Information we collect
- Account data: your Apple ID identifier, email (if you choose to share), and display name. We do not store your Apple password.
- Pantry contents: ingredients you add manually, scan, or import — including names, quantities, expiry estimates, and category tags.
- Fridge photos: images you take in-app for ingredient extraction. Photos are uploaded to our processing pipeline, sent to a third-party AI vision provider (Google Gemini), and auto-deleted within 24 hours.
- Cooking history: recipes you save, cook, rate, and the feedback you provide.
- Household data: if you join a household, your pantry data is shared with up to four invited members.
- Subscription state: entitlement status from RevenueCat / Apple. We do not see your card details.
- Diagnostics: anonymous usage events and crash logs (you can opt out in Settings).
3. How we use your data
- Run the app — store your pantry, generate recipe matches, drive expiry alerts.
- Improve ingredient detection accuracy and recipe ranking.
- Send transactional push notifications you've opted into (e.g. expiry alerts).
- Enforce subscription entitlements and prevent abuse.
- Provide customer support when you contact us.
We do not sell your data, share it with advertisers, or train third-party AI models on your photos.
4. Sub-processors
- Google (Gemini API) — fridge photo analysis. Photos are sent at scan time, not stored by Google for training under our enterprise terms.
- Anthropic (Claude API) — fallback ingredient extraction and recipe ranking.
- Spoonacular — recipe database lookups (no user data sent).
- Cloudflare R2 — temporary photo storage (24h TTL).
- RevenueCat — subscription receipt validation.
- Apple (APNs) — push notification delivery.
- Hetzner Cloud (EU) — application servers and database hosting.
5. Where your data is stored
Our primary database is hosted in the European Union (Hetzner, Germany). Photo objects briefly transit Cloudflare's global network before deletion. AI vision processing occurs on Google Cloud servers (region varies). Your data may therefore be transferred outside your country of residence; where required, we rely on Standard Contractual Clauses.
6. How long we keep it
- Account + pantry + cooking history: kept while your account is active.
- Fridge photos: auto-deleted within 24 hours.
- Diagnostic events: 90 days, then aggregated.
- Backups: encrypted database snapshots retained for 30 days.
- Deleted accounts: erased within 30 days, except where law requires us to retain receipts.
7. Your rights (GDPR, UK GDPR, CCPA)
You can exercise the following rights at any time, directly inside the app under Profile → Privacy:
- Access & portability: tap "Export my data" to receive a JSON file of everything we hold about you.
- Erasure ("right to be forgotten"): tap "Delete account" — your data is hard-deleted within 30 days.
- Rectification: edit your profile or pantry entries directly in-app.
- Object / restrict: contact us at the email below.
- Lodge a complaint with your local supervisory authority.
8. Children
Pantry is rated 4+ but the service is not directed at children under 13. We do not knowingly collect data from children under 13. If you believe a child has provided us with information, contact us and we will delete it.
9. Security
Data in transit is encrypted with TLS 1.3. Database backups are encrypted at rest. Refresh tokens are stored as salted hashes. We follow OWASP top-10 mitigations and rotate secrets quarterly.
10. Changes
We may update this policy. Material changes will be announced in-app at least 14 days before they take effect.
11. Contact
Questions or rights requests: support@purifyos.app