Privacy Policy
DRAFT — This document has not been reviewed by legal counsel. Do not rely on this as a binding privacy policy until it has been reviewed and approved by a qualified attorney.
1. What We Collect
Pantry (“we”, “us”, “our”) collects the following information when you use our mobile application and related services:
- Account information: Email address, display name, authentication provider (Apple, Google, Facebook, or email/password). Passwords are stored as bcrypt hashes — we never store or see your password in plaintext.
- Receipt images: Photos you scan or email to us. Stored in AWS S3 with private access controls. Never indexed, never used for advertising.
- Receipt data: Store name, date, line items, prices, and quantities extracted from your receipts by our AI parsing pipeline.
- Product data: Item classifications (category, subcategory, attributes) and corrections you make to improve accuracy.
- Device information: Device type, operating system version, and locale (used for currency and language settings).
- Subscription information: Payment provider (Apple, Google, or Stripe), subscription tier, and billing period. We do not store credit card numbers — payments are processed entirely by Apple, Google, or Stripe.
2. How We Use Your Data
- Core service: Extracting, classifying, and organizing your grocery purchase history.
- Spending insights: Generating personalized spending summaries, price trends, and category breakdowns for your household.
- Global product database: Your corrections to product classifications contribute to a shared product database that improves accuracy for all users. See Section 5 for what is and is not shared.
- Notifications: Sending scan completion alerts, weekly digests, and price alerts (configurable in settings).
3. What We Never Do
- We never sell your receipt data, purchase history, or household information to advertisers, CPG companies, data brokers, or any third party.
- We never use receipt images for advertising or share them with third parties.
- We never expose which household bought which product. The global product database contains only aggregate product information (product names, categories, average prices) — never individual purchase records.
4. Health-Sensitive Data
Items in the following categories are treated with additional privacy protections and are never included in any cross-user analytics, benchmarking, or price comparison features:
- Pain relief / OTC medication
- Vitamins and supplements
- Feminine care products
- Baby care products (diapers, formula, baby food)
- Skincare products
These items appear only in your private household ledger and spending summaries. They are excluded from global aggregation at the data layer — not just the UI — so they cannot be exposed even via API queries.
5. What We Share (and What We Don’t)
Shared globally (anonymous, aggregate only):
- Product names, categories, and attributes (from the global product database)
- Aggregate price statistics (average price of a product at a store chain, computed from 10+ observations across 3+ households)
- Product match counts (how many times a product has been scanned, without household attribution)
Never shared:
- Your receipt images
- Your individual purchase records
- Your household identity or membership
- Your spending totals or patterns
- Health-sensitive product purchases (see Section 4)
6. Data Storage and Security
- All data is stored in AWS infrastructure (US region, us-east-1).
- Receipt images are stored in S3 with private access controls and accessed only via short-lived presigned URLs.
- Database connections use TLS encryption.
- Authentication tokens are stored as cryptographic hashes, never in plaintext.
- All API communication uses HTTPS.
7. Data Retention and Deletion
Your data is retained for as long as your account is active. When you delete your account:
- Phase 1 (within 24 hours): All directly identifying information is permanently deleted — email address, display name, receipt images, authentication tokens, and social login connections.
- Phase 2 (within 30 days): Remaining data is anonymized — household references in global tables (taxonomy votes, price observations) are replaced with anonymous identifiers. Receipt line items have their raw OCR text replaced with a deletion marker.
This two-phase approach preserves the integrity of the global product database while ensuring complete removal of personally identifiable information within the GDPR-mandated 30-day window.
8. Your Rights
You have the right to:
- Access your data (your full purchase history is available in the app at all times)
- Export your data (CSV export available for paid subscribers; contact us for a full data export)
- Correct your data (inline correction on every receipt and item)
- Delete your account and all associated data (Settings > Account > Delete Account)
- Opt out of notifications (Settings > Notifications)
9. Children’s Privacy
Pantry is not directed at children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, please contact us and we will delete it.
10. Changes to This Policy
We will notify you of material changes to this policy via in-app notification and/or email at least 30 days before the changes take effect.
11. Contact
For privacy-related inquiries: privacy@pantry.fyi