Pantrove ("we", "us", "our") operates the Pantrove application. This policy explains what data we collect, how we use it, and your rights. We keep this short and plain-language on purpose — if anything is unclear, contact us.
Account data: Your email address and a securely hashed version of your password. We never store your plaintext password.
Pantry inventory: Food items you add (name, quantity, unit, location, expiry date, barcode). This is the core data the service needs to function.
Health & nutrition profile: Optional fields you provide during onboarding — height, weight, activity level, dietary restrictions, allergies, and calorie goals. Providing these enables AI-powered meal recommendations.
Meal logs: Meals you log, including any food photos you submit for AI analysis (see Section 3).
Recipe data: Recipes you create or save, including recipes you choose to share publicly with the community.
Receipts & purchases: Receipt photos you scan and order emails you choose to forward to your personal receipts@ address are parsed into line items (item names, prices, store). Raw receipt text is encrypted at rest.
Price reports: Prices captured from your receipts (item, price, store name, and city/state/ZIP you provide) power price comparison. Shared price statistics are aggregated and never identify you.
Household & extras: If you use Family Pantry, your household address is stored only as a salted hash (we cannot read it back). Loyalty card numbers you add and Sous Chef chat messages are encrypted at rest.
Usage data: Standard server logs (IP address, timestamps, request paths) retained for up to 30 days for security purposes only.
To make the app work, we share specific data with these providers. We never sell your data, share it with advertisers, or use it to train AI models.
AI processing: Some features process the content you provide (text or images) with AI. Where possible this runs on our own self-hosted models. When cloud processing is used, the providers are OpenAI and Google, on paid API tiers that contractually do not use your data to train their models. We never include your name, email, or account identifier in these requests. See OpenAI's API policy and Google's data governance.
Plaid (optional bank connection, Pro users): If you connect a bank to auto-detect grocery receipts, Plaid retrieves your transactions and sends grocery-related entries to us. Your bank credentials never touch our servers. The access token we receive from Plaid is encrypted at rest. You can disconnect at any time in Settings.
Stripe (billing): If you upgrade to Pro, we share your email and payment metadata. Stripe is PCI-DSS Level 1 compliant. Your full card number is never seen or stored by us.
Expo (push notifications): We share an opaque push token and notification content. Notifications may include the names of items you added (for example, "Milk expires tomorrow").
Instacart (optional, when you send your list to them): If you choose to open your shopping list in Instacart, we send Instacart the item names, quantities and units on that list so they can build the cart for you. We do not send your name, email or account identifier. Instacart is a US company and processes the list in the United States.
Kroger (optional, when you connect a Kroger account): If you connect Kroger, we send the product codes and quantities of the items you choose to add, into your own Kroger cart under the permission you granted them, plus a store or ZIP code to look up prices and availability. We do not send your Pantrove account details. Kroger is a US company and processes this in the United States.
App Store purchases (Apple, Google Play): If you subscribe inside the mobile app, we send the purchase token or transaction identifier the store gave us back to that store to confirm the subscription is genuine and still active. No other data about you is sent.
Nutritionix (nutrition lookup): When you look up the nutrition of a food we send the food text you typed. No account identifier is attached.
Instagram/Facebook (Meta), TikTok, YouTube (recipe import): If you paste a social or web link to import a recipe, we fetch that public page — which means the link you pasted, and our server’s address, reach that platform and any site you link to. Nothing about your account, pantry or health profile is sent.
Providers that never receive your data in production: Groq, Cerebras, OpenRouter, Ollama and DeepSeek are used only for general food-database work that contains nothing about you, and a code-level gate blocks anything you typed, said or photographed from reaching them outside our own development machines. The free tier of Google Gemini is blocked the same way: receipt and food images and their text may only go to Google on a paid tier, under the terms described above. Cloudflare and fal.ai generate illustration images for our shared recipe library from a dish name only.
Resend (email): We share your email address and the message body to send account email (password resets, receipt forwarding) and non-essential email (such as a weekly digest or an occasional reminder if we haven’t seen you in a while). You can unsubscribe from non-essential email at any time using the one-click link in every such message or in Settings, and we honor it immediately. We never sell your email address or send you third-party advertising.
Strava, Fitbit, Whoop, Oura, Garmin, Withings, Polar, Suunto, Wahoo (optional wearable sync): If you connect a wearable, we receive activity, sleep, and energy data. The OAuth tokens and activity payloads are encrypted at rest in our database.
Sentry (error monitoring, production builds only): If the app crashes, we send a stack trace and an opaque user ID. We never send your email, name, message contents, request bodies, or photo data. You can disable crash reporting in Settings.
Open Food Facts, USDA, Wikidata (free public food databases): Barcode scans and ingredient lookups query these public APIs. No personally identifiable information is sent.
We do not use Google Analytics, Facebook Pixel, or any advertising trackers.
Your data is stored in an encrypted database hosted in the United States. Passwords are hashed with bcrypt at cost factor 12. Sensitive fields — wearable OAuth tokens, activity payloads, daily check-in notes, receipt raw text, weight-log notes, and Plaid access tokens — are additionally encrypted at rest using AES-256-GCM with authenticated encryption.
On the mobile app, your authentication token is stored in the device's hardware-backed secure store (iOS Keychain / Android Keystore). On the web app, tokens live in browser storage. All network traffic uses HTTPS with current TLS.
We rate-limit login, registration, and password-reset endpoints to deter automated attacks.
No system is 100% secure. We encourage strong, unique passwords. If you suspect unauthorized access, contact us immediately.
Regardless of where you are located, you have the right to:
EU/UK users: you have additional rights under GDPR/UK GDPR including the right to lodge a complaint with your local supervisory authority.
California residents: we do not sell or share your personal information as those terms are defined by the CCPA/CPRA, and we have not done so in the preceding 12 months. You may exercise your access, deletion, and correction rights via the in-app tools above or by email, without discrimination.
Your pantry, recipes, receipts and profile are kept for as long as your account is active, and are deleted when you delete your account. Some records are deleted automatically sooner than that, by a nightly job — you do not have to ask:
| Record | Deleted after |
|---|---|
| Notifications you have already read | 90 days |
| Your in-app activity history (what you did and when) | 180 days |
| Your record of consenting to a subscription renewal | 1095 days |
| Security and account-action audit records | 365 days |
| The one-way record that your account deletion happened | 1095 days |
| Scan records for photos you did not allow us to keep | 90 days |
| Internal job/processing logs | 60 days |
| The log of changes to your pantry (who changed what) | 90 days |
| Which recipes we showed you | 30 days |
| Household invitations that expired or were accepted | 30 days |
| Anti-abuse signup fingerprints (see below) | 395 days |
| An account you asked us to delete (the grace period) | 30 days |
One consequence worth stating plainly: if you export your data in month seven, your activity history will start 180 days ago, because the older rows have already been deleted. Server logs (IP address, timestamps, request paths) are held by our hosting provider and deleted after 30 days.
Scan & meal photos: full-resolution images are processed in real time and are not kept by default. A small thumbnail (64 pixels) is saved with your scan history so you can review past scans; it is deleted with the scan entry and permanently with your account. If full-image storage is ever enabled for quality debugging, it applies only prospectively and is disclosed here first.
Photos you contribute to recipes and products: if — and only if — you turn on “help improve Pantrove for everyone”, the photos you take of dishes you cook and of product packaging are kept as part of our shared food library, and they stay there if you later delete your account. When that happens the photo is separated from you: your account link is removed and the date it was contributed is reduced to the month, so the image can no longer be traced back to you. We remove location, device and timestamp information from every photo when it is uploaded, before it is stored. Photos are only kept this way when you are 18 or older, when you have given that permission, and when an automated check found no people in the picture; every other photo you take is yours alone and is deleted with your account. You can change the permission at any time in Settings, and you can delete any individual photo yourself.
Anti-abuse signup fingerprints: when an account starts a free trial we store one-way hashes of the email address, device identifier and truncated IP prefix so the same person cannot claim repeated free trials. These are hashes, not your details, and they are the one record that intentionally survives account deletion — erasing them would defeat the fraud control they exist for. They are deleted automatically 13 months after they are created.
Pantrove is not directed at children. You must be at least 16 years old to create an account, except in the United States and the United Kingdom, where the minimum age is 13. We ask for your year of birth at sign-up and refuse the account if it does not meet the minimum for your country; we do not store the year.
The 16 comes from Article 8 of the GDPR, which sets the age at which a person can consent to an online service for themselves; some EU countries have set a lower age, and we do not rely on those lower ages. The 13 is the United States COPPA threshold and the age stated in the UK GDPR. If you believe a child under these ages has provided us data, contact us and we will delete it promptly.
We will notify registered users by email of material changes to this policy at least 14 days before they take effect. Continued use after that date constitutes acceptance.
Questions or requests: privacy@pantrove.app