← PantryPalz

Privacy Policy

Last updated September 23, 2026 Effective September 23, 2026 Download PDF

In plain English. Your food list, history, shopping lists and recipes stay on your phone and in your own backups. We have no server that holds them. The app sends a barcode number to Open Food Facts, sends recipe search words (or a recipe category for today's recommendations) to TheMealDB, fetches recipe pages you choose to import or open, and uses RevenueCat and Superwall for purchases and the upgrade screen. To learn how the app is used, PantryPalz sends usage analytics to PostHog: which features are used and where people get stuck, never your food names, receipts or recipe links. You can turn this off in Settings. An account is required: you finish setting up with an email address and a password, and Supabase keeps your sign-in (an ID, your email address and a one-way hash of your password) so PantryPalz Pro can follow you to a new phone. You can delete the account in Settings. Receipts, including digital receipts and files you share, are read on your phone. There are no ads, no tracking across other companies' apps, and we never sell your data.

Summary of key points

This summary is here for speed. The detailed sections below are the ones that govern.

  • Do you need an account? Yes. Setting up ends with creating one, using an email address and a password of your choosing. There is no Apple, Google or Facebook login. It is what lets PantryPalz Pro follow you to a new phone. See section 3.9.
  • Where is my food list? On your phone, and in iCloud or computer backups you control. It is not synced to us, and we cannot see it. See section 2.
  • What leaves the phone? A barcode number, recipe search words or a recipe category, recipe pages you import or open, purchase and upgrade-screen data, usage analytics (unless you turn them off), and your email address and password when you sign in. See section 3 and the table in section 4.
  • Do you use analytics? Yes. PostHog records how the app is used, such as which screens are opened and whether food was marked used, under a random ID (or your account ID if you sign in). It never receives your food names, receipt text, recipe links, notes or email. Turn it off any time in Settings > Privacy > Share usage analytics. See section 3.7.
  • Do you process sensitive information? No.
  • Do you sell data, show ads, or track me across apps? No. The app has no advertising SDK, our analytics are not used for advertising or shared with advertisers, and the app never shows the App Tracking Transparency prompt because it does not track you across other companies' apps or websites.
  • What do you receive directly? Emails you send us, the usage analytics described in section 3.7, and your account ID and email address.
  • How do I delete everything? In PantryPalz, Settings > Delete all my data removes everything on the phone. If you signed in, Settings > Account > Delete account deletes your account. See section 14.
  • What are my rights? Depending on where you live, access, correction, deletion, portability and objection. See sections 18 and 19.

1. Who we are

PantryPalz is operated by Kenneth Alvarez, a sole proprietor doing business as PantryPalz, in California, United States ("we", "us"). This policy covers the PantryPalz iPhone app and the website at pantrypalz.com.

For the purposes of the EU and UK General Data Protection Regulation (GDPR), we are the controller of the limited personal data described here. Where a provider processes data on our behalf, such as RevenueCat, Superwall, PostHog and Supabase, it acts as our processor or service provider. Open Food Facts, TheMealDB, DuckDuckGo, recipe websites and Apple act independently under their own policies, as explained below.

Contact for all privacy matters: support@pantrypalz.com.

EU and UK representative. Where the GDPR requires a controller outside the EU or UK to appoint a representative there, the representative's details will be published here. If you are in the EEA or the UK and need to reach a representative, email us and we will provide the current details.

2. What stays on your phone

The following is stored only on your device, in the app's local database, and in any iCloud or computer backups of your device that you choose to make:

  • Your food list: names, brands, categories, where each item is kept, quantities, prices you enter, notes, and every date (printed, estimated, purchased, opened, frozen and thawed).
  • History of what you used, wasted, froze or threw away, and the statistics built from it.
  • Shopping lists and the reason each item is on them.
  • Saved recipes: ingredients, steps, the source link and photo.
  • What PantryPalz remembers about products you buy, including names you gave to barcodes and cached product details from Open Food Facts.
  • Your settings, such as reminder time and reminder timing by category.

None of this is synced to our servers. We have no server that holds your food, receipts or recipes, and signing in does not change that. We cannot read it, and we could not hand it to anyone if asked. iCloud backups are handled by Apple under Apple's privacy policy and your iCloud settings.

Images you scan are not kept. Receipt photos and the camera view used for barcodes and printed dates are processed on your phone. The receipt image is not saved and not uploaded. Only the food lines you confirm are stored.

Digital receipts and shared files are read on your phone. When you choose a photo or screenshot, paste receipt text, or choose or share a PDF, email, web page or text file, PantryPalz reads it on your phone. It is not uploaded. A shared file is deleted once it has been read. Only the food lines you confirm are stored.

Reminders are local. They are scheduled on your phone by iOS and are not sent through any server.

Your onboarding answers (what you want help with, household size, how often food goes off, and diet) are kept on your phone to shape your estimate and recipe recommendations. They are also recorded as usage analytics unless you have turned analytics off (section 3.7). The waste estimate is worked out on your phone.

3. What the app sends, and why

These are the only network requests the PantryPalz app makes.

3.1 Barcode lookups: Open Food Facts

When you scan a barcode that is not already saved on your phone, the app sends the barcode number to Open Food Facts (world.openfoodfacts.org) to get the product name and details. As with any web request, Open Food Facts also receives your IP address and a user-agent that identifies the PantryPalz app. Product images are loaded from Open Food Facts' image server. The result is cached on your phone so the same product does not need another lookup. Nothing else about you or your food is sent. Open Food Facts is an independent non-profit and handles these requests under its own privacy policy. Product data from Open Food Facts (openfoodfacts.org), ODbL.

3.2 Recipe imports: the website you choose

When you import a recipe link, by sharing it from Safari or another app, or by pasting it, your phone fetches that page and its photo directly from the website. The request does not pass through us. The website receives what any web request carries, such as your IP address and a user-agent, and its own privacy policy applies. PantryPalz sends the website nothing else about you. Recipe photos for saved recipes are loaded from the recipe's website.

3.3 Recipe recommendations and search: TheMealDB

The recipes on the Recipes tab come from TheMealDB (www.themealdb.com), a recipe database. The app contacts it in four cases: once a day, with a recipe category (such as "Pasta" or "Vegetarian", chosen to suit the diet you picked) to fill the Recommended row, which is then kept on your phone for the day; when you search, with the words you typed; when you tap "Use up your" a food, with that single food name; and when you open or save a recipe, with that recipe's number. TheMealDB receives your IP address, as any website does. Nothing else about your kitchen is sent. PantryPalz never sends your food list, and it does not look up recipes for your food unless you tap to see them. Recipe photos for these results are loaded from TheMealDB. TheMealDB acts independently under its own terms.

3.4 Web search: DuckDuckGo in Safari

If you tap Search in Safari, PantryPalz opens a DuckDuckGo search for the words you typed in Safari, Apple's browser, and the app has no part in what you browse after that. Safari's own settings and the sites' privacy policies apply. See DuckDuckGo's privacy policy.

3.5 Purchases and subscription status: Apple and RevenueCat

Apple processes all payments. We never see your name, Apple Account details or card details from a purchase.

RevenueCat manages purchases and tells the app whether PantryPalz Pro is active. It receives an app user ID, device and app information (such as device model, operating system version, app version, locale and IP address), and your purchase and subscription history for PantryPalz, which it obtains from Apple. If you are not signed in, the app user ID is a random ID. If you sign in, it is your PantryPalz account ID, so PantryPalz Pro can follow you to a new phone. The same ID is shared with Superwall so purchase and upgrade-screen numbers line up. RevenueCat never receives your name or email from us. RevenueCat also sends subscription events (such as a trial starting, a renewal or a cancellation) to PostHog under the ID the app uses for analytics (section 3.7). RevenueCat acts as our service provider. See RevenueCat's privacy policy.

3.6 The upgrade screen: Superwall

Superwall shows the PantryPalz Pro upgrade screen and decides when to show it. It receives:

  • the same app user ID RevenueCat uses (see section 3.5): a random ID, or your account ID if you are signed in;
  • device details: model, operating system version, locale, language, time zone, app version and install date;
  • events: Superwall's standard app events, such as app opens and sessions, when the upgrade screen is shown or closed, and purchase events from it;
  • subscription status; and
  • approximate location (such as country or region), which Superwall derives from your IP address.

Superwall uses its standard event tracking so it can decide when to show the upgrade screen and measure it. The app also passes Superwall's upgrade-screen and purchase events on to our usage analytics (section 3.7), with only a short list of details such as which screen was shown and which product was chosen. Superwall acts as our processor. See Superwall's privacy policy.

3.7 Usage analytics: PostHog

PantryPalz uses PostHog (PostHog, Inc.) to understand how the app is used, so we can see which features help, where people get stuck, and whether changes make things better. From the first time you open the app, and unless you turn it off, the app sends PostHog:

  • a random ID created by the app on your phone. If you sign in, the app tells PostHog your account ID, and your earlier usage on that phone is joined to it. If you sign out or delete your account, the app starts a new random ID;
  • events: screens you open and actions you take, such as finishing a setup step, adding, using, wasting, freezing or opening food, scanning a barcode or receipt, shopping list actions, viewing, searching for or saving a recipe, upgrade-screen and purchase events, account actions, changing a setting, and opening a notification;
  • details of those events, limited to food categories, counts, how many days were left before a date, whether a receipt was digital, the length of a recipe search (not the words), recipe numbers from TheMealDB, where something came from (for example "barcode" or "receipt"), product IDs, and outcomes;
  • facts about your use: whether you have PantryPalz Pro, whether you are signed in, how many foods and recipes you have, whether reminders are on, and your onboarding answers (goals, household size, how often food goes off, diet);
  • app and device information that the PostHog SDK includes, such as app version, build, language and region setting, device model and operating system version, and your IP address, from which PostHog may derive an approximate location.

PostHog never receives your food names, receipt text or images, recipe links or search words, notes, or email address from the app. The app does not record your screen (no session replay), does not show surveys, and does not capture your taps automatically. Events are stored on your phone and sent in batches, so they are sent later if you are offline.

Your choice. Go to Settings > Privacy > Share usage analytics and turn it off. The app stops sending usage analytics straight away, and your choice is remembered on the phone. You can turn it back on at any time.

Where and how long. We use PostHog's US cloud (us.i.posthog.com), so this data is stored in the United States. We keep it as long as needed to understand use of the app, then it is deleted or aggregated. PostHog acts as our processor. See PostHog's privacy policy.

3.8 Feedback you send us

When you write to us from Settings > Feedback & Support, or answer the How was your experience? prompt, we store what you wrote with Supabase, together with the details shown on the screen before you send: your app version and build, your phone model, your iOS version, the screen you were on, the time, and your account ID so we can reply. Your food list, receipts and recipes are never attached. We keep feedback for as long as it is useful for fixing and improving PantryPalz, and delete it when it is not. Ask us at support@pantrypalz.com to delete yours at any time.

3.9 Your account: email address and password, run by Supabase

Setting PantryPalz up ends with creating an account: you choose an email address and a password. PantryPalz offers no third-party login, so no Apple, Google or Facebook account is involved and none of those companies learns that you use PantryPalz. Here is what that account holds:

  • Your email address is the name on the account and where a password-reset code is sent. We do not send you marketing email.
  • Your password is never stored as you typed it. Supabase stores a one-way hash of it (bcrypt), which cannot be turned back into the password. Nobody at PantryPalz can see or recover it, which is why a forgotten password is replaced rather than looked up.
  • A forgotten password is reset with a six-digit code emailed to your address. Typing that code and a new password signs you in and replaces the old password. Codes expire after a few minutes.
  • Supabase (Supabase, Inc.) runs our sign-in service. It stores your account ID, your email address, a one-way hash of your password, and the technical details a sign-in service keeps, such as when the account was created and last signed in, and the IP address of sign-in requests. It also sends the password-reset code when you ask for one. The data is stored in the United States. Supabase acts as our processor. See Supabase's privacy policy.
  • Your food, receipts and recipes are not sent to Supabase and stay on your phone.
  • What the account is for: while you are signed in, RevenueCat, Superwall and PostHog use your account ID instead of a random ID, so PantryPalz Pro can follow you to a new phone and your usage is counted as one person.
  • Signing out (Settings > Account > Sign out) removes the sign-in from your phone. Deleting your account (Settings > Account > Delete account) deletes your account, your email address, your password hash and the records linked to them from Supabase. Your food on the phone stays. Neither cancels a subscription, which Apple manages.

3.10 Crash reports and statistics from Apple

If you have chosen in your iPhone settings to share analytics with app developers, Apple may provide us with crash reports and aggregated usage statistics through App Store Connect. These do not identify you to us. You control this in Settings > Privacy & Security > Analytics & Improvements.

3.11 What the app does not do

The app contains no advertising SDK. It does not collect your name, phone number, contacts, precise location, health data or advertising identifier, and it collects an email address only if you sign in. It does not track you across other companies' apps or websites, and it does not sell your data.

4. Third parties at a glance

WhoWhat they receiveWhyTheir policy
Open Food Facts The barcode number you scan, plus IP address and app user-agent. Product images are loaded from its image server. To look up a product name and details. Independent organization. world.openfoodfacts.org/privacy
Recipe websites you import from A request for the page and photo you chose, with IP address and user-agent. To import the recipe you asked for. Independent of us. The policy of that website
TheMealDB A recipe category once a day, the words of a recipe search, the one food name you tap, or the number of a recipe you open, plus IP address. Never your food list. To show recommended recipes and find recipes when you search. Independent of us. themealdb.com
DuckDuckGo, in Safari Your search words, with IP address, like any Safari search. Only when you tap Search in Safari. Independent of us. duckduckgo.com/privacy
RevenueCat An app user ID (random, or your account ID if you sign in; also used by Superwall), device and app information, purchase and subscription history from Apple. Sends subscription events to PostHog under the app's analytics ID. To manage purchases and turn on PantryPalz Pro. Our service provider. revenuecat.com/privacy
Superwall The same app user ID RevenueCat uses, so purchase and upgrade-screen numbers line up; device model, OS version, locale, language, time zone, app version and install date; Superwall's standard app events, upgrade screen views and purchase events; subscription status; approximate location from IP. To show the upgrade screen and decide when to show it. Our processor. superwall.com/legal/privacy-policy
PostHog (usage analytics) A random ID (or your account ID if you sign in); screens opened and actions taken, with categories, counts and outcomes only; whether you have PantryPalz Pro, counts of foods and recipes, reminder setting and onboarding answers; app and device information and IP address. Never food names, receipt text, recipe links or email. Stored in the United States. To understand how the app is used and improve it. Off in Settings > Privacy. Our processor. posthog.com/privacy
Supabase (your account) Your account ID, your email address, a one-way hash of your password, sign-in times and IP address, and the password-reset codes it emails you. Stored in the United States. Never your food, receipts or recipes. To run your account so PantryPalz Pro can follow you to a new phone. Deleted when you delete your account. Our processor. supabase.com/privacy
Apple Your purchases, through your Apple Account. Optional crash reports and statistics if you share them. iCloud backups if you use them. Apple is not involved in your PantryPalz sign-in. App distribution, payments, refunds, backups. Independent of us. apple.com/legal/privacy
GoatCounter (website only) Page address, referrer, browser, screen size, country, and clicks on marked buttons. No cookies. To count visits to pantrypalz.com. Our processor. goatcounter.com/help/privacy
Netlify (website only) IP address and request details of each visit. To host and deliver this website. Our processor. netlify.com/privacy

There are no advertising networks, social media pixels or data brokers.

5. Permissions the app asks for

  • Camera, only when you choose to scan a barcode, a receipt, a printed date or package text. Everything the camera sees is processed on your phone and not recorded.
  • Photos: no permission is needed. You pick receipt photos or screenshots with the system picker, and PantryPalz sees only the ones you pick. PantryPalz does not browse or upload your photo library.
  • Files: only a PDF, image, email, web page or text file you choose or share.
  • Notifications, asked on the reminders step of setup, after you add your first foods (or the first time you add food, if you left setup early), so PantryPalz can remind you before food needs using. Never at launch.
  • Your account is not a permission. It is how you finish setting PantryPalz up: you type an email address and choose a password, and nothing else is asked for.
  • Siri and Shortcuts, only if you use the "What needs using" shortcut. The answer is built on your phone.

PantryPalz does not ask for location, contacts, microphone, health data, Bluetooth, or permission to track you. Web pages opened inside PantryPalz can't use your camera or microphone. You can change any permission at any time in iPhone Settings.

6. What we receive directly

By email: your email address, your name if you include it, and the content of your message, such as your iOS version or a screenshot. We use it only to answer you and to fix the problem you reported.

Your account: your account ID, your email address and a one-way hash of your password, held by Supabase for us (section 3.9). We use them only to run your account and to send a reset code when you ask for one. We do not send you marketing email.

In our provider dashboards: the usage analytics in PostHog (section 3.7) and the purchase and upgrade-screen records in RevenueCat and Superwall (sections 3.5 and 3.6). We use them to understand how the app is used, to improve it, and to answer billing questions. If you are not signed in, these records are tied to a random ID, not to your name or email.

7. This website

  • Visit counting. pantrypalz.com uses GoatCounter to count page views and clicks on a few buttons, such as the App Store link. GoatCounter does not use cookies, does not track you across sites, and does not store your full IP address. It records the page, the referring site, your browser and screen size, and your country.
  • Hosting. The site is hosted by Netlify, which processes your IP address and request details to deliver pages and protect the service.
  • Fonts. The site's typeface is served from pantrypalz.com itself, so no font service receives your visit.
  • No forms and no cookies. The site has no sign-up, contact form or cookie banner, because it sets no cookies. Clicking an email link opens your own email app.

To stop visit counting, you can block gc.zgo.at and goatcounter.com with a content blocker. The site works normally without them.

8. Cookies, ads and tracking

The app uses no cookies, no advertising identifier and no advertising SDK. Our usage analytics (section 3.7) stay with us and our processor: they are not combined with data from other companies' apps or websites, not used for targeted advertising, and not shared with data brokers. Because PantryPalz does not track you across other companies' apps or websites, it never shows the App Tracking Transparency prompt, and its App Store privacy label reads "Data Not Used to Track You". You can turn usage analytics off in Settings > Privacy.

The website sets no cookies and stores nothing in your browser.

9. Categories of personal information, in the legal format

US state privacy laws ask for this list in the categories defined by the California Consumer Privacy Act. "Collected" here includes data received by our service providers on our behalf.

  • A. Identifiers. Yes. Random IDs used by PostHog, RevenueCat and Superwall; your account ID once you sign in, which then replaces those random IDs; IP addresses received by our providers; your account email address; your email address if you write to us.
  • B. Personal information in Cal. Civ. Code 1798.80. Limited. Your email address and a one-way hash of your password, and your name if you include it in an email.
  • C. Protected classification characteristics. No.
  • D. Commercial information. Yes. PantryPalz Pro purchase and subscription history. Not payment card details, which only Apple holds.
  • E. Biometric information. No.
  • F. Internet or network activity. Yes. How you use the app: screens opened and actions taken, with categories, counts and outcomes (PostHog, unless you turn it off); Superwall's app events, upgrade screen views and purchase events; and website visits (GoatCounter). Recipe search words go to TheMealDB, and web searches to DuckDuckGo, only when you search; we do not receive them.
  • G. Geolocation data. Approximate only. Country or region derived from IP address. No precise location.
  • H. Audio, electronic, visual or similar information. No. Camera and receipt images, digital receipts and shared files are processed on your phone and not kept.
  • I. Professional or employment information. No.
  • J. Education information. No.
  • K. Inferences. No. Your onboarding answers and usage counts are used to shape the app for you and, in aggregate, to improve it. We do not draw inferences to profile you for advertising or for decisions about you.
  • L. Sensitive personal information. No.

Sources: you (onboarding answers, the account you create), your device, and Apple (purchase history). Your food list is not in any of these categories for us, because we never receive it.

10. Purposes and legal bases

We use the limited information above only for these purposes. If you are in the EEA, the UK or Switzerland, the legal basis under Article 6 of the GDPR is shown for each.

  • Looking up products, searching for recipes and importing recipes you ask for: performance of our contract with you.
  • Selling and turning on PantryPalz Pro, and restoring purchases: performance of a contract.
  • Showing the upgrade screen and deciding when to show it: our legitimate interest in offering PantryPalz Pro in a way that does not interrupt people unnecessarily. We have balanced this against your rights, and the data is pseudonymous and minimal. You may object at any time.
  • Usage analytics (PostHog): our legitimate interest in understanding how PantryPalz is used so we can fix problems and improve it. We have balanced this against your rights: the data excludes your food, receipts and recipes, is not used for advertising, and can be switched off at any time in Settings > Privacy. Where the law requires your consent for this kind of measurement, for example under the ePrivacy rules in the EEA and the UK, we rely on consent, and you can withdraw it with the same switch.
  • Your account, and linking PantryPalz Pro and usage to it: performance of our contract with you, so we can give you the app and carry your purchase between devices.
  • Deleting your account when you ask: performance of a contract, and our legal obligation to honor deletion requests.
  • Answering support email: performance of a contract, or our legitimate interest in helping you.
  • Counting website visits: our legitimate interest in knowing whether the site is used, using a cookie-free, minimal tool.
  • Notifications and camera use: your choice, through iPhone permissions, which you can withdraw at any time.
  • Keeping tax records and responding to lawful requests: legal obligation.

We do not use any information for advertising, and we do not sell it.

11. Sale, sharing and disclosure

We do not sell personal information, and we do not share it for cross-context behavioral advertising or targeted advertising, as those terms are defined by US state laws. We have not done so in the past 12 months. We do not knowingly sell or share the personal information of anyone under 16.

Usage analytics are used only by us and our processor PostHog. They are not shared with advertisers or data brokers.

Beyond the providers in section 4, we disclose information only where we reasonably believe it is required by law, a court order or a lawful government request, or where it is necessary to investigate fraud or a security incident, enforce our terms, or protect the rights or safety of any person. Where we are allowed to tell you about such a request, we will. Given how little we hold, there is usually nothing to disclose.

Business transfers. If PantryPalz is merged, acquired, reorganized, converted into a company, or its assets sold, the limited information we hold may transfer as part of that transaction. The recipient would remain bound by this policy for information collected before the transfer.

12. International transfers

We are based in the United States, our usage analytics (PostHog) and account (Supabase) data are stored in the United States, and RevenueCat, Superwall, PostHog, Supabase, GoatCounter and Netlify may process information in the United States and other countries. Open Food Facts is based in France. If you are outside the country where a provider is located, your information will be processed in a country whose data protection laws may differ from yours.

Where personal data is transferred out of the EEA, the UK or Switzerland to a processor acting for us, we rely on an appropriate safeguard, such as the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or the provider's certification under the EU-US Data Privacy Framework, as offered in that provider's terms. You can ask us which safeguard applies.

13. How long information is kept

  • Your food list, history, shopping lists and recipes: on your phone until you delete them, use Delete all my data, or uninstall the app. Copies in backups last as long as you keep those backups.
  • Cached product details: on your phone, until you delete the app or its data.
  • Receipt and camera images, digital receipts and shared files: not kept. Shared files are deleted once read, and after 24 hours at most.
  • Support emails: only as long as needed to answer you and resolve the issue, then deleted, unless we must keep a message to meet a legal obligation or handle a legal claim.
  • RevenueCat purchase records: kept by RevenueCat for as long as needed to provide subscription status for PantryPalz and to meet accounting and tax obligations, under its policy and our agreement with it.
  • Superwall records: kept by Superwall under its retention policy and our agreement with it.
  • Usage analytics (PostHog): kept as long as needed to understand use of the app, then deleted or aggregated. If you turn analytics off, nothing new is sent.
  • Your account (Supabase): kept while you have an account. When you delete it in Settings > Account, the account, your email address, the password hash and the records linked to the account are deleted from Supabase. Backups kept by Supabase for its service roll off on its schedule.
  • Your analytics switch and onboarding answers: on your phone until you change them, use Delete all my data, or uninstall the app.
  • Website visit counts: kept by GoatCounter as aggregate statistics.
  • Data held by Open Food Facts, TheMealDB, DuckDuckGo, recipe websites and Apple: under their own policies.

14. Deleting your data

  • Everything on your phone: in PantryPalz, go to Settings > Delete all my data. Your food, history, shopping lists, recipes and settings are removed from the phone. This does not cancel a subscription, which Apple manages.
  • Your account: in PantryPalz, go to Settings > Account > Delete account. This deletes your account, your email address, your password hash and the records linked to it. Your food on the phone stays. Delete all my data does not delete your account, and uninstalling the app does not either, so delete the account first if you want both gone.
  • Usage analytics: turn them off in Settings > Privacy to stop new data. To delete what was already sent, email us; if you are not signed in, we may need your help to find the records, because they are tied to a random ID. Deleting your account also stops your usage being linked to it.
  • Uninstalling PantryPalz also removes its data from the phone. Copies in iCloud or computer backups remain until you delete those backups, which you control.
  • Support emails: ask us and we will delete the thread.
  • RevenueCat and Superwall records: if you were signed in, we can find them by your account ID. Otherwise they are tied to a random ID, not your name or email, so we may need your help to find them. Email us with the approximate date of any purchase and we will ask the provider to delete the records we can match.
  • Purchase history held by Apple: managed by Apple through your Apple Account.

15. Security

The strongest protection is architectural: your food data never leaves your device, so there is no central store of it to breach. In addition:

  • The app's data is stored in its private area on your device, which iOS isolates from other apps and encrypts when your iPhone has a passcode.
  • All network requests the app makes use HTTPS.
  • Recipe imports use HTTPS only, refuse local and private network addresses at every redirect, and stop reading a page after 4 MB.
  • Receipt images, digital receipts and shared files are read on the device and are never uploaded by PantryPalz. Shared files are checked by their content, not their name.
  • PantryPalz has no web browser of its own. Web search opens in Safari, so nothing you browse passes through the app.
  • Payments are handled entirely by Apple. We never receive card details.
  • Your password is sent over TLS and stored by Supabase only as a bcrypt hash, never in a form anyone can read back. PantryPalz asks for at least eight characters. Your signed-in session is kept in the iPhone Keychain, not in ordinary app storage, and our server code checks who is calling before it acts. Use a password you do not use anywhere else, and a password manager if you have one.
  • The app accepts only public client keys for its providers and refuses secret keys, so no secret key ships inside the app.
  • Usage analytics are built from a fixed list of events with no free text, and the app's tests check that no food names or other content are included.
  • This website is served over HTTPS only, with HTTP Strict Transport Security, a strict Content Security Policy, no cookies, and no forms.
  • We use multi-factor authentication on the accounts we use to run PantryPalz, and give access to provider dashboards only to the people who need it.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. Protecting your device with a passcode and keeping iOS up to date protects your food data as well. To report a security issue, see our security contact.

16. If there is a breach

If a security incident affects personal information we are responsible for, we will notify you and the relevant authorities where the law requires it, within the time the law sets, which under the GDPR is 72 hours to the supervisory authority where feasible. We will say what happened, what was affected, and what you can do.

17. Children

PantryPalz is not directed to children under 13, and we do not knowingly collect personal information from children under 13. The account holds only an email address and a password hash, and the app has no public profiles or posting. If you believe a child under 13 has sent us personal information, for example by email, contact support@pantrypalz.com and we will delete it.

18. Your rights: EU, UK and elsewhere

If you are in the EEA, the UK or Switzerland, you have the right to access your personal data, correct it, delete it, restrict or object to its processing, receive it in a portable format, and withdraw consent where processing is based on consent. You also have the right to complain to your data protection authority. In the UK that is the Information Commissioner's Office. We would welcome the chance to help first.

An honest note: we hold little about you. Your food data is on your own device, where you can already see, change, export through your backups, and delete it. What we hold is described in section 6: email you have sent us, usage analytics, and, if you signed in, your account. You can delete your account yourself in Settings > Account > Delete account, and turn usage analytics off in Settings > Privacy (this is also how to object to analytics). If you are not signed in, records held by PostHog, RevenueCat and Superwall are tied to a random ID, so to act on them we may need details that help us find them, such as the date of a purchase.

We apply these rights to everyone, wherever you live, including in Australia, Canada and other countries with privacy laws. You may also complain to your local regulator, such as the Office of the Australian Information Commissioner or the Office of the Privacy Commissioner of Canada.

How to exercise them: email support@pantrypalz.com. We reply within two working days and complete requests within the time the law allows, normally one month. We will ask only for what we need to verify the request.

19. Your rights: US states

If you live in California or another US state with a comprehensive privacy law, such as Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah or Virginia, you may have the right to:

  • Know and access the personal information we have collected about you, and obtain a portable copy.
  • Correct inaccurate information.
  • Delete your personal information. You can delete your account yourself in Settings > Account.
  • Opt out of the sale or sharing of personal information, targeted advertising and profiling. We do none of these, so there is nothing to opt out of.
  • Limit the use of sensitive personal information. We do not collect any.
  • Not be discriminated against for exercising these rights. We will never charge you differently or give you a worse service for doing so.
  • Appeal a decision we make about your request by replying to it. We will respond with our reasoning within the time the law allows, and tell you how to contact your state Attorney General if you disagree.

To make a request, email support@pantrypalz.com. An authorized agent may act for you with proof of authority. We respond within 45 days, or the period your state sets.

California. The categories we collect, their sources, purposes and retention are in sections 3, 9, 10 and 13. We have disclosed personal information for a business purpose only to the service providers in section 4. We offer no financial incentives tied to personal information. Under California Civil Code section 1798.83 ("Shine the Light"), we do not disclose personal information to third parties for their direct marketing purposes.

20. Do Not Track and Global Privacy Control

We do not track you across sites or apps, so a Do Not Track signal has nothing to change. We honor the Global Privacy Control signal as an opt-out of sale and sharing where the law requires it. Because we do not sell or share personal information, there is nothing further for it to switch off.

21. Automated decisions

Superwall uses rules we set, for example when a monthly free limit is reached, to decide when to show the PantryPalz Pro upgrade screen. This does not affect your price, your rights, or your access to the free features. We do not make any decision about you by automated means that has legal or similarly significant effects, and we do not use your usage analytics to profile you for advertising.

22. Changes to this policy

We may update this policy. The date at the top always shows the current version. If a change is material, for example if the app starts sending new information anywhere, we will update this page and say so in the app before the change takes effect. Where the law requires your consent, we will ask for it.

23. Contact us

Email support@pantrypalz.com about anything in this policy. Postal address available on request.

Kenneth Alvarez, doing business as PantryPalz, California, United States.

Also available as a PDF: PantryPalz Privacy Policy (PDF). See also the Terms of Use and the Help Center.