Privacy Policy
Last updated: July 16, 2026
ScanMyPantry ("we", "our", or "the app") is committed to protecting your privacy. This policy explains what data we collect, how we use it, and your rights.
1. Data We Collect
Data stored on your device:
- Food items, quantities, expiry dates, and categories you add to your pantry
- Recipes generated from your inventory
- Meal plans and preferences
- A compact meal-preference profile inferred from deliberate recipe views, favorites, and meals marked as cooked
- App settings and notification preferences
Data processed temporarily:
- Camera images are processed in real-time for food identification
- Cropped food images or low-FPS live scan frames may be sent to AI providers such as OpenAI or Google Gemini for identification. These requests are used to identify groceries and improve scan accuracy, not to create a user profile
- Aggregate meal-preference signals (for example, preferred cuisines, meal types, or cooking styles) may be sent with a recipe-generation request. The underlying recipe-view history remains on your device
Optional food-recognition research:
- "Improve Food Recognition" is off by default and requires an adult or parent/guardian to opt in from the Profile tab
- After a saved scan, the app may select up to 16 diverse food-item crops. These can include items you save and items you explicitly reject; an explicit rejection is stored as a correction example. The research collector never contributes continuous video or a full camera frame
- Each crop is resized to no more than 512 pixels on its longest edge, re-rendered to remove embedded photo metadata, and adaptively compressed as HEIC or JPEG on your device before upload
- A crop may be accompanied by the predicted label, category, quantity, brand, saved storage section, whether it was saved or explicitly rejected, visibility, normalized crop geometry, image dimensions, model source, model confidence, crop-quality signals, observation/provider counts, app version, app build, a random dataset ID, and timestamps
- The upload service temporarily uses the connection IP address in memory to enforce daily abuse limits. It is not placed in the training record or used to identify or profile you
- We do not include OCR text, the rest of your pantry, location, contacts, advertising identifiers, or account/contact details in a training sample
- Contributed samples are used only to develop, test, and evaluate food-recognition systems. They are not sold or used for advertising
Data we do NOT collect:
- Your name, email, phone number, or any personal contact information
- Location data
- Browsing history
- Contacts or address book
2. iCloud Sync
If you have iCloud enabled, your pantry data syncs across your devices using Apple's CloudKit infrastructure. This data is stored in your personal iCloud account and is governed by Apple's Privacy Policy. We do not have access to your iCloud data.
3. Third-Party Services
We use the following third-party services:
- OpenAI API — For food identification and recipe generation. Cropped images and text prompts are sent via encrypted HTTPS. See OpenAI Privacy Policy.
- Google Gemini API — For stateful live scan assistance and visual food identification. Low-FPS camera frames, OCR hints, barcode hints, and local object track IDs may be sent via encrypted HTTPS/WebSocket connections. See Google Privacy Policy.
- RevenueCat — For subscription management. No pantry data is shared. See RevenueCat Privacy Policy.
- TelemetryDeck — For anonymous, privacy-focused analytics. No personal data or device identifiers are collected. See TelemetryDeck Privacy Policy.
- Open Food Facts — For barcode product lookup. Only barcode numbers are sent. See Open Food Facts Privacy Policy.
- Pexels — For recipe hero photos. No user data is shared. See Pexels Privacy Policy.
- Instacart — If you use the shopping integration, recipe ingredient lists are sent to generate a cart. See Instacart Privacy Policy.
4. Analytics
We use TelemetryDeck for privacy-focused, aggregated product-interaction analytics. We do not use those signals to track people across apps or for advertising.
5. Advertising
We may show ads from Meta (Facebook) Audience Network. If you consent to tracking via Apple's App Tracking Transparency prompt, personalized ads may be shown. You can change this at any time in iOS Settings → Privacy & Security → Tracking.
6. Subscriptions
Pantry Pro subscriptions are processed through Apple's App Store. Payment information is handled entirely by Apple. We do not have access to your payment details.
7. Data Storage & Security
- All pantry data is stored locally on your device using Apple's SwiftData framework
- Optional iCloud sync uses Apple's encrypted CloudKit infrastructure
- API communications use encrypted HTTPS/TLS connections
- Optional research crops are stored under a random dataset identifier with restricted filesystem access; the deletion credential remains on your device and is stored only as a one-way hash on our server
- Research samples may be transferred to an access-controlled offline drive for dataset development. The export process carries deletion markers forward and enforces the same retention period. Offline data is not shared with model vendors or other third parties unless this policy and the consent request are updated first
8. Children's Privacy
ScanMyPantry does not knowingly collect research data directly from children under 13. Food-recognition research is off by default and must be enabled by an adult or a parent or guardian.
9. Your Rights
- Delete all data — Go to Settings → Clear All Food Items in the app
- Stop research contributions — Use Opt Out & Stop Contributions at the bottom of Profile. This also clears samples waiting to upload
- Delete contributed research data — Choose Delete Contributed Scan Data at the bottom of Profile. This uses a device-held deletion credential to remove samples associated with that installation from the online server. A deletion marker removes matching samples from the offline research drive during the next scheduled export/maintenance run, no later than 30 days after a verified request. Marked samples are not used for new training work while deletion is pending
- Disable iCloud sync — Turn off iCloud for ScanMyPantry in iOS Settings
- Opt out of ad tracking — Decline the ATT prompt or change in iOS Settings → Privacy → Tracking
- Cancel subscription — Manage in iOS Settings → Apple ID → Subscriptions
10. Regional Privacy Rights
Depending on where you live, including Canada, the European Economic Area (EEA), the United Kingdom, and California, you may have additional privacy rights:
- Right to access — Request a copy of data we hold about you
- Right to erasure — Request deletion of any data associated with you
- Right to portability — Request your data in a portable format
- Right to object — Object to processing of your data for marketing purposes
- CCPA — California residents have the right to know what personal information is collected, to delete it, and to opt out of its sale. We do not sell personal information.
To exercise any of these rights, email privacy@scanmypantry.app. We will verify and respond to requests within the period required by applicable law.
11. Data Retention
Pantry contents and detailed meal-preference history remain on your device. Aggregated analytics signals (via TelemetryDeck) are retained for up to 12 months. If you opt in to food-recognition research, contributed crops and their limited technical metadata are retained online or on the access-controlled offline research drive for up to 180 days and may be removed earlier to enforce storage limits. Online deletion requests are applied immediately after authentication; deletion markers are applied to the offline drive during the next scheduled export/maintenance run and within 30 days. Deleting the app removes local data but cannot send a server-deletion request, so use "Delete Contributed Scan Data" before uninstalling if you want prior contributions removed.
12. Changes to This Policy
We may update this policy from time to time. Changes will be posted on this page with an updated date. If a change materially broadens optional research collection or use, the app will request fresh consent before making further contributions under the new scope.
13. Contact
Questions about this privacy policy or a deletion request?
privacy@scanmypantry.app