← Back to PantryBook

Privacy Policy

Last updated: October 5, 2026

1. Information We Collect

Account data: Email address and authentication credentials (managed by Supabase Auth). If you sign in with Apple or Google, we receive your name and email address from that provider; Apple may give us a private relay address instead of your real email.

Recipe data: Recipes, images, meal plans, grocery lists, and food journal entries you create.

Usage data: Feature usage counts (e.g., AI extractions per month) for enforcing plan limits.

Payment data: Web purchases are processed by Stripe. iPhone purchases are processed by Apple and managed through RevenueCat. We store only customer and subscription IDs, never your card number.

Reminders: Cook timer and baking reminders are scheduled on your device. Reminder content is not sent to us.

2. How We Use Your Data

  • To provide and improve the Service
  • To run the AI features you use: recipe import, recipe generation, receipt and pantry scanning, journal estimates, and recipe photos
  • To manage your subscription and billing
  • To enable family sharing features you opt into

3. AI Processing

When you use an AI feature (importing a recipe, generating one, scanning a receipt or pantry, or estimating a journal entry), the content you provide is sent to Anthropic's Claude API for processing. This data is used solely to provide that feature and is not retained by Anthropic for training. See Anthropic's privacy policy for details.

When you ask PantryBook to create a recipe photo, the recipe's title, cuisine, description and ingredients (or a description you type) are sent to Google's Gemini API, under Google's API terms.

4. Data Storage

Your data is stored in Supabase (hosted on AWS). Recipe images are stored in Supabase Storage. All data is encrypted in transit (TLS) and at rest.

5. Data Sharing

We do not sell your data. We share data only with:

  • Supabase: Database and authentication hosting
  • Anthropic: AI processing for the features described above
  • Google: Recipe photo generation (Gemini) and, if you choose it, Google sign-in
  • Apple: Sign in with Apple, if you choose it, and iPhone purchases
  • Stripe: Web payment processing
  • RevenueCat: iPhone subscription management
  • Vercel: Application hosting and privacy-friendly usage analytics

6. Family Sharing

When you share recipes with family members, they can view (read-only) your recipe collection. You control who has access and can revoke it at any time. Only your email is visible to people you share with.

If you create a share link for a recipe, anyone with that link can view that recipe (without your notes or account details). You can turn a link off at any time.

7. Cookies & Local Storage

We use essential cookies for authentication (Supabase session). We use localStorage for user preferences (sort order, unit system, aisle preferences). We use Vercel Analytics to count page views and feature use; it sets no cookies and is not used for advertising. We do not use tracking cookies or ad networks.

8. Your Rights

You have the right to:

  • Access your data (viewable in-app)
  • Correct your data (editable in-app)
  • Delete your data (delete individual items or request full account deletion)
  • Export your data (contact us for a full data export)

9. Data Retention

Your data is retained as long as your account is active. If you delete your account, all associated data is permanently removed within 30 days.

10. Children

The Service is not intended for children under 13. We do not knowingly collect data from children under 13.

11. Changes

We may update this policy from time to time. We will notify you of significant changes via email or in-app notice.

12. Contact

Privacy questions? Contact us at support@mdglabs.dev.