Legal — Document 01
Privacy Policy
Last updated — September 10, 2026
1. Who we are
Pantryify ("we", "us") provides a pantry management, receipt scanning and AI meal planning service (the "Service"). For the purposes of the EU/UK General Data Protection Regulation (GDPR) we act as the data controller for the personal data described here. For the purposes of the California Consumer Privacy Act as amended by the CPRA, we are a business. Contact details are in section 13.
2. What we collect
- Account data: name, email address, hashed authentication credentials, email verification state, and — if you enable reminders — your phone number.
- Pantry and food data: the items you add, quantities, expiry dates, dietary preferences, allergen exclusions, saved recipes and grocery lists.
- Receipt images (OCR): photos you choose to scan are transmitted as base64 to our AI processor for structured item extraction.
- Barcode data: the barcode digits you scan, looked up against the public Open Food Facts database.
- Messaging data: your WhatsApp/SMS number, opt-in state, and delivery status of reminders we send you.
- Billing data: subscription plan, status and payment references. Card details are handled by our payment processor and never touch our servers.
- Technical and security data: coarse country/region derived from IP for currency and local ingredients, device/browser metadata, audit log entries, and a salted, truncated hash of your IP address used solely for abuse and rate-limit enforcement.
We do not collect precise GPS location, and we do not use advertising trackers or sell behavioural profiles.
3. Why we process it, and our legal basis (GDPR Art. 6)
| Purpose | Legal basis |
|---|---|
| Creating and running your account; pantry, meal plan and grocery features | Contract (Art. 6(1)(b)) |
| AI meal generation and receipt OCR on data you submit | Contract (Art. 6(1)(b)) |
| WhatsApp / SMS meal reminders and check-ins | Consent (Art. 6(1)(a)) — withdrawable at any time |
| Dietary and allergen preferences (health-adjacent data) | Explicit consent (Art. 9(2)(a)) |
| Billing, invoicing, fraud prevention | Contract and legal obligation (Art. 6(1)(b),(c)) |
| Security, WAF, rate limiting, audit logging | Legitimate interests (Art. 6(1)(f)) — protecting the Service and its users |
| Product emails and newsletters | Consent, withdrawable via unsubscribe |
4. AI processing and receipt OCR
Meal plans, ingredient suggestions and receipt extraction are produced by large language models operated by Google (Gemini) and, as a fallback, Groq. We send only what the feature needs: your pantry items, dietary preferences and — for OCR — the receipt image you chose to scan. We do not send your name, email, phone number or payment details to any AI provider.
Receipt images are processed transiently to extract food items and are not retained by us after extraction; only the resulting item list is saved to your pantry. AI output is generated content and may be inaccurate — see the health and allergen disclaimer in our Terms of Service. There is no automated decision-making producing legal or similarly significant effects on you within the meaning of GDPR Art. 22.
5. WhatsApp and email communications
Reminders are opt-in. When you provide a phone number and enable notifications, we share that number and the message content with our messaging provider (Twilio and/or the Meta WhatsApp Cloud API) purely to deliver the message. You can stop messages at any time by replying STOP, or by turning reminders off in Notification settings — both actions revoke consent immediately for future sends. Transactional account and security emails (verification, password reset, billing receipts) are not marketing and continue while your account exists.
6. Processors and third parties
- Supabase — database, authentication, edge compute (hosting and storage of your account and pantry data).
- Google (Gemini API) — AI meal generation and receipt OCR.
- Groq — fallback AI inference.
- Open Food Facts — public product lookup by barcode (we send only the barcode).
- TheMealDB — public recipe reference data.
- Twilio and/or Meta Platforms — WhatsApp and SMS delivery.
- Resend — transactional email delivery.
- Paystack and Paddle — payment processing (PCI-DSS scope sits with them; we store only plan and reference metadata). Paystack handles Nigerian payments; Paddle is our Merchant of Record for other regions and handles their own tax/compliance obligations for those transactions.
- Vercel / Cloudflare — application hosting, CDN and edge protection.
Each is engaged under its own data processing terms and processes data only on our instructions. We do not sell personal information, and we do not "share" it for cross-context behavioural advertising as those terms are defined by the CPRA.
7. International transfers
Our processors operate in the United States and other jurisdictions outside the EEA/UK. Transfers rely on the European Commission's Standard Contractual Clauses (and the UK Addendum where applicable), together with the processor's own technical safeguards.
8. Retention
- Account, pantry, recipes, meal plans: for as long as your account is active.
- Receipt images: not stored after extraction.
- AI meal cache: pruned automatically on a rolling basis.
- Security and abuse telemetry (hashed IP counters): up to 30 days.
- Audit logs of sensitive operations: up to 24 months, as a security and integrity record.
- Billing records: up to 7 years where tax or accounting law requires it.
- After account deletion: personal data is erased or irreversibly anonymised within 30 days, except records we must legally keep.
9. Your rights
If you are in the EEA or UK (GDPR Arts. 15–21): you have the right of access, rectification, erasure ("right to be forgotten"), restriction, data portability, objection to processing based on legitimate interests, and withdrawal of consent at any time without affecting prior lawful processing.
If you are a California resident (CCPA/CPRA): you have the right to know what we collect and why, to delete, to correct, to opt out of sale/sharing (we do neither), to limit use of sensitive personal information, and not to be discriminated against for exercising any of these rights.
How to exercise them:
- Access / portability: Account Settings → export your data. We return your profile, pantry, saved recipes, meal plans and grocery lists in machine-readable JSON.
- Correction: edit directly in the app, or contact us.
- Erasure: Account Settings → delete account. This cascades across your pantry, recipes, meal plans, notification settings and subscription records, and revokes your sessions. Anonymised security and legally required billing records may persist for the periods in section 8.
- Messaging opt-out: reply STOP on WhatsApp/SMS, or toggle reminders off in Notifications.
- Anything else: contact us (section 13). We respond within 30 days (GDPR) or 45 days (CCPA), and will tell you if we need an extension. Authorised agents may submit CCPA requests with proof of authorisation.
You may also complain to your local supervisory authority (for example the UK ICO or your EU Member State DPA). We would appreciate the chance to resolve it first.
10. Security
Data is encrypted in transit (TLS). Every database table enforces row-level security so that your records are readable only by your authenticated session. Sensitive operations — role changes, deletions, billing events, security patches — are written to an append-only audit log. Our public API endpoints run an input-filtering layer against injection and cross-site-scripting payloads plus adaptive per-network rate limiting. Payment card data never reaches our infrastructure. No system is perfectly secure; if a breach affects your personal data and poses a risk to you, we will notify the relevant supervisory authority within 72 hours of becoming aware and inform you without undue delay where required.
11. Cookies and local storage
We use strictly necessary storage only: your authentication session, and a small amount of local state (language, region, referral code). We do not run advertising or cross-site analytics cookies.
12. Children
Pantryify is not directed to children under 13 (or under 16 in jurisdictions where that is the digital-consent age), and we do not knowingly collect their personal data. If you believe a child has given us data, contact us and we will delete it.
13. Contact and changes
Privacy requests and questions: use in-app Support, or the contact details published on pantryify.com. We will post material changes to this policy on this page and update the date above; where the change is significant we will also notify you in-app or by email.