Back
Pantrove

Privacy Policy

Effective date: August 19, 2026

Pantrove ("we", "us", "our") operates the Pantrove application. This policy explains what data we collect, how we use it, and your rights. We keep this short and plain-language on purpose — if anything is unclear, contact us.

1. Data We Collect

Account data: Your email address and a securely hashed version of your password. We never store your plaintext password.

Pantry inventory: Food items you add (name, quantity, unit, location, expiry date, barcode). This is the core data the service needs to function.

Health & nutrition profile: Optional fields you provide during onboarding — height, weight, activity level, dietary restrictions, allergies, and calorie goals. Providing these enables AI-powered meal recommendations.

Meal logs: Meals you log, including any food photos you submit for AI analysis (see Section 3).

Recipe data: Recipes you create or save, including recipes you choose to share publicly with the community.

Receipts & purchases: Receipt photos you scan and order emails you choose to forward to your personal receipts@ address are parsed into line items (item names, prices, store). Raw receipt text is encrypted at rest.

Price reports: Prices captured from your receipts (item, price, store name, and city/state/ZIP you provide) power price comparison. Shared price statistics are aggregated and never identify you.

Household & extras: If you use Family Pantry, your household address is stored only as a salted hash (we cannot read it back). Loyalty card numbers you add and Sous Chef chat messages are encrypted at rest.

Usage data: Standard server logs (IP address, timestamps, request paths) retained for up to 30 days for security purposes only.

2. How We Use Your Data

  • To operate the pantry tracking, meal logging, recipe, and shopping list features.
  • To generate AI-powered refill predictions and meal recommendations personalised to your pantry and nutrition goals.
  • To send you expiry and restock notifications you have opted into.
  • To operate and improve the service. This includes per-user product analytics — a record of actions you take in the app (for example “signed up”, “cooked a recipe”, “added to shopping list”) with a timestamp, tied to your account. It is not anonymous: you can download every one of these rows in your data export, they are deleted with your account, and they are deleted automatically on the schedule in Section 6. We also keep a record of which recipes we showed you, so we do not show you the same thing every day.
  • We do not sell your data, use it for advertising, or share it with third parties except as described in Section 3.

3. Third-Party Services

To make the app work, we share specific data with these providers. We never sell your data, share it with advertisers, or use it to train AI models.

AI processing: Some features process the content you provide (text or images) with AI. Where possible this runs on our own self-hosted models. When cloud processing is used, the providers are OpenAI and Google, on paid API tiers that contractually do not use your data to train their models. We never include your name, email, or account identifier in these requests. See OpenAI's API policy and Google's data governance.

Plaid (optional bank connection, Pro users): If you connect a bank to auto-detect grocery receipts, Plaid retrieves your transactions and sends grocery-related entries to us. Your bank credentials never touch our servers. The access token we receive from Plaid is encrypted at rest. You can disconnect at any time in Settings.

Stripe (billing): If you upgrade to Pro, we share your email and payment metadata. Stripe is PCI-DSS Level 1 compliant. Your full card number is never seen or stored by us.

Expo (push notifications): We share an opaque push token and notification content. Notifications may include the names of items you added (for example, "Milk expires tomorrow").

Instacart (optional, when you send your list to them): If you choose to open your shopping list in Instacart, we send Instacart the item names, quantities and units on that list so they can build the cart for you. We do not send your name, email or account identifier. Instacart is a US company and processes the list in the United States.

Kroger (optional, when you connect a Kroger account): If you connect Kroger, we send the product codes and quantities of the items you choose to add, into your own Kroger cart under the permission you granted them, plus a store or ZIP code to look up prices and availability. We do not send your Pantrove account details. Kroger is a US company and processes this in the United States.

App Store purchases (Apple, Google Play): If you subscribe inside the mobile app, we send the purchase token or transaction identifier the store gave us back to that store to confirm the subscription is genuine and still active. No other data about you is sent.

Nutritionix (nutrition lookup): When you look up the nutrition of a food we send the food text you typed. No account identifier is attached.

Instagram/Facebook (Meta), TikTok, YouTube (recipe import): If you paste a social or web link to import a recipe, we fetch that public page — which means the link you pasted, and our server’s address, reach that platform and any site you link to. Nothing about your account, pantry or health profile is sent.

Providers that never receive your data in production: Groq, Cerebras, OpenRouter, Ollama and DeepSeek are used only for general food-database work that contains nothing about you, and a code-level gate blocks anything you typed, said or photographed from reaching them outside our own development machines. The free tier of Google Gemini is blocked the same way: receipt and food images and their text may only go to Google on a paid tier, under the terms described above. Cloudflare and fal.ai generate illustration images for our shared recipe library from a dish name only.

Resend (email): We share your email address and the message body to send account email (password resets, receipt forwarding) and non-essential email (such as a weekly digest or an occasional reminder if we haven’t seen you in a while). You can unsubscribe from non-essential email at any time using the one-click link in every such message or in Settings, and we honor it immediately. We never sell your email address or send you third-party advertising.

Strava, Fitbit, Whoop, Oura, Garmin, Withings, Polar, Suunto, Wahoo (optional wearable sync): If you connect a wearable, we receive activity, sleep, and energy data. The OAuth tokens and activity payloads are encrypted at rest in our database.

Sentry (error monitoring, production builds only): If the app crashes, we send a stack trace and an opaque user ID. We never send your email, name, message contents, request bodies, or photo data. You can disable crash reporting in Settings.

Open Food Facts, USDA, Wikidata (free public food databases): Barcode scans and ingredient lookups query these public APIs. No personally identifiable information is sent.

We do not use Google Analytics, Facebook Pixel, or any advertising trackers.

4. Data Storage & Security

Your data is stored in an encrypted database hosted in the United States. Passwords are hashed with bcrypt at cost factor 12. Sensitive fields — wearable OAuth tokens, activity payloads, daily check-in notes, receipt raw text, weight-log notes, and Plaid access tokens — are additionally encrypted at rest using AES-256-GCM with authenticated encryption.

On the mobile app, your authentication token is stored in the device's hardware-backed secure store (iOS Keychain / Android Keystore). On the web app, tokens live in browser storage. All network traffic uses HTTPS with current TLS.

We rate-limit login, registration, and password-reset endpoints to deter automated attacks.

No system is 100% secure. We encourage strong, unique passwords. If you suspect unauthorized access, contact us immediately.

5. Your Rights

Regardless of where you are located, you have the right to:

  • Access the personal data we hold about you.
  • Correct inaccurate data via the Settings page.
  • Delete your account and all associated data yourself in Settings → Privacy & data → Delete account (30-day grace period; to change your mind, tap Cancel deletion in Settings → Privacy & data before it elapses — simply signing in again does not cancel it), or by emailing us. Deletion removes your data from our live systems, including stored scan images; any residual copies in our encrypted, access-controlled backups are overwritten on our standard backup-rotation cycle. Three things are deliberately kept: a one-way hash recording that the deletion happened (our proof to regulators that we honoured it); the anti-abuse signup fingerprints described under Data Retention below — both are one-way hashes, neither can be read back as your details, and the fingerprints are deleted automatically once their retention window ends; and, only if you gave that specific permission, the food photos you contributed, which are separated from your account as described under Data Retention.
  • Export your data yourself in Settings → Privacy & data → Download my data — a complete machine-readable JSON file, free, no request needed.
  • Withdraw consent at any time by deleting your account.

EU/UK users: you have additional rights under GDPR/UK GDPR including the right to lodge a complaint with your local supervisory authority.

California residents: we do not sell or share your personal information as those terms are defined by the CCPA/CPRA, and we have not done so in the preceding 12 months. You may exercise your access, deletion, and correction rights via the in-app tools above or by email, without discrimination.

6. Data Retention

Your pantry, recipes, receipts and profile are kept for as long as your account is active, and are deleted when you delete your account. Some records are deleted automatically sooner than that, by a nightly job — you do not have to ask:

RecordDeleted after
Notifications you have already read90 days
Your in-app activity history (what you did and when)180 days
Your record of consenting to a subscription renewal1095 days
Security and account-action audit records365 days
The one-way record that your account deletion happened1095 days
Scan records for photos you did not allow us to keep90 days
Internal job/processing logs60 days
The log of changes to your pantry (who changed what)90 days
Which recipes we showed you30 days
Household invitations that expired or were accepted30 days
Anti-abuse signup fingerprints (see below)395 days
An account you asked us to delete (the grace period)30 days

One consequence worth stating plainly: if you export your data in month seven, your activity history will start 180 days ago, because the older rows have already been deleted. Server logs (IP address, timestamps, request paths) are held by our hosting provider and deleted after 30 days.

Scan & meal photos: full-resolution images are processed in real time and are not kept by default. A small thumbnail (64 pixels) is saved with your scan history so you can review past scans; it is deleted with the scan entry and permanently with your account. If full-image storage is ever enabled for quality debugging, it applies only prospectively and is disclosed here first.

Photos you contribute to recipes and products: if — and only if — you turn on “help improve Pantrove for everyone”, the photos you take of dishes you cook and of product packaging are kept as part of our shared food library, and they stay there if you later delete your account. When that happens the photo is separated from you: your account link is removed and the date it was contributed is reduced to the month, so the image can no longer be traced back to you. We remove location, device and timestamp information from every photo when it is uploaded, before it is stored. Photos are only kept this way when you are 18 or older, when you have given that permission, and when an automated check found no people in the picture; every other photo you take is yours alone and is deleted with your account. You can change the permission at any time in Settings, and you can delete any individual photo yourself.

Anti-abuse signup fingerprints: when an account starts a free trial we store one-way hashes of the email address, device identifier and truncated IP prefix so the same person cannot claim repeated free trials. These are hashes, not your details, and they are the one record that intentionally survives account deletion — erasing them would defeat the fraud control they exist for. They are deleted automatically 13 months after they are created.

7. Minimum Age

Pantrove is not directed at children. You must be at least 16 years old to create an account, except in the United States and the United Kingdom, where the minimum age is 13. We ask for your year of birth at sign-up and refuse the account if it does not meet the minimum for your country; we do not store the year.

The 16 comes from Article 8 of the GDPR, which sets the age at which a person can consent to an online service for themselves; some EU countries have set a lower age, and we do not rely on those lower ages. The 13 is the United States COPPA threshold and the age stated in the UK GDPR. If you believe a child under these ages has provided us data, contact us and we will delete it promptly.

8. Changes to This Policy

We will notify registered users by email of material changes to this policy at least 14 days before they take effect. Continued use after that date constitutes acceptance.

9. Contact

Questions or requests: privacy@pantrove.app

Terms of Service · Back to Pantrove