Privacy Policy
Last updated
Pantry is a recipe and meal-planning app for families. This page says, in plain words, what Pantry keeps about you and your family, who can see it, what goes to other services, and how to delete it. Pantry never sells your information, shows no ads, and uses no tracking or analytics.
What Pantry keeps
- Your login: your name, your email, and your password, kept scrambled so no one can read it; your sign-ins, each lasting up to 30 days; your alert settings and the alerts you were sent; the address or location you gave to find stores near you; and which version of the Terms you agreed to, and when.
- Your family's people: each person's card — their name, allergies and diets, children's included — your saved guests, and the cards other families send you.
- Your kitchen: your pantry and staples; your Meal Plan and who's eating each meal; your grocery list and what's checked off; what you cooked, when, and your notes on it; leftovers; and your ratings, reviews and notes on recipes.
- Your shopping: the stores you shop at, and prices — the ones you type in and the ones read from your receipts. When you scan a receipt, Pantry keeps what it added to your pantry, not the receipt photo.
- Photos: the photos you add to recipes, your after-meal photos, and the photos on your posts. Before keeping or showing a photo, Pantry removes the hidden details phones save inside it — where and when it was taken, and the camera that took it.
- Recipes: the recipes your family adds — from a link, a photo, a file or by typing — private ones included, the photo or file you added a recipe from, and the recipes you save.
- Sharing: your posts; the families and chefs you follow, and who follows you; the cards you send, and the email you sent a card to; the invites you make; and the recipe websites you suggest.
- Who did what: who added a pantry item or a recipe, who planned a meal, and who cooked it.
- Records that keep Pantry working and safe: Pantry's server records each visit's internet address and the page asked for — which can include a place you searched for stores near — your email when a sign-in fails, and what the AI service read from each scan. When someone types a join code, Pantry keeps the internet address it came from.
Who sees what
- Your family. Everyone with a login in your family sees and can change what your family keeps: its people, pantry, plans, recipes and sharing.
- Families are findable unless private. Anyone signed in to Pantry can find your family's name in Find families and open its page, which shows your family's name, the recipes you've shared and saved, and your posts — never your people. A parent can make your family private in Household settings: then it isn't listed, and only the families it lets follow it can open its page.
- Kids' names and cards never leave the family. Children have no logins, and no one outside your family sees a child's name or card unless a parent sends that card to another family or shares its private link.
- A family's allergies show only if a parent shares them. Then others see the common allergies and diets on your family's cards — never who has them, an allergy you typed in yourself, or your saved guests.
- Posts can be for everyone or followers. You choose when you post, and you can change it or delete the post. A private family's posts reach only its followers.
- Private recipes stay in the family. A recipe your family adds goes into Pantry's shared cookbook: anyone signed in to Pantry can find it, open it, cook it and plan it, with its photos and your family's name (no name while your family is private). Switch on Keep private and no one outside your family can open it; a family that planned or cooked it before sees only its name.
- Your kitchen stays home. Your pantry, Meal Plan, grocery list, receipts, star ratings and what you cooked are your family's alone; so are your after-meal photos unless you post one, and your reviews and notes unless you're a public chef (below). Prices are kept with the store, though, so other families who shop at the same store see them too, with no name on them.
- Public chefs. A parent can make a cook with a login a public chef. Then everyone sees that cook's full name on the recipes they add, their reviews, notes and gallery photos, and their chef page. A card without a login, like a child's, can never be a public chef.
- A card sent to another family is shared only while the parent allows. A card you send to another family, or share by its private link, shows its first name, allergies and diets, and the reason and dates you gave — nothing else of your family — until the end of the last day you chose, or until a parent stops it.
- The people who run Pantry can reach what it stores, to fix problems and keep Pantry safe.
What goes to other services
Pantry never sells your information. A few things go to other services so Pantry can work:
- An AI service reads receipt and photo images. When you scan a receipt or a photo of your fridge or pantry, or add a recipe from a photo, screenshot or PDF, Pantry sends the picture, without its hidden details, to Anthropic, the company that makes the Claude AI, to read it. Anthropic handles it under its own terms. Pantry also sends Anthropic the steps of recipes it adapts from the web, to put them in Pantry's own words.
- Online recipe search (when on) sends search words. When What's for Dinner looks for recipes online, it sends a web search service (Tavily) the names of the newest few items in your pantry and the word "recipe" — never a person's name, allergies or diets. Pantry's server then opens the recipe pages found; those websites see Pantry, not you.
- Recipe links. When you add a recipe from a link, Pantry's server opens that page. The recipe's photo may then load straight from that website, so the website can see your browser load it.
- Barcode checks send only the barcode number, to Open Food Facts, a free product database. Your family's cards never leave Pantry.
- Finding stores near you sends the address you type — or your location, if you choose Use my location — and the store names you search for, to OpenStreetMap's free map services.
- Alerts. If you turn alerts on, they reach your phone or computer through your browser's own push service, sealed so only your device can read them.
- Recipes Pantry adapts credit their sources. A recipe Pantry adapts from a website, or from the Wikibooks cookbook, says where it came from, and its license when it has one. Bringing in Wikibooks recipes sends nothing about you.
Allergies
Pantry checks a recipe's ingredients, not the products you buy, and you must read every label. The Terms say more.
Children
Pantry logins are for adults, 18 or older. Children's cards are kept by their parents, inside the family, and children never sign in. If you think a child has a login, write to ehrhard1982@gmail.com and Pantry will delete it.
Cookies
Pantry uses two cookies: one keeps you signed in, for up to 30 days, and one remembers whether you like the Meal Plan by week or by month. No ad or tracking cookies.
Deleting your information
- Delete my account, at the foot of Household settings, deletes your login: your email and password, your sign-ins, your alert settings and alerts, your saved address and your agreement to the Terms. Your card, and everything you added, planned or cooked, stay with your family under your name. If you're your family's only login, Pantry offers Delete our family instead.
- Delete our family, also at the foot of Household settings, deletes your family and everything it holds: its people and their cards, pantry, Meal Plan, grocery list, receipts, store choices, photos and uploaded files, posts, private recipes, saves, follows, the cards it sent, invites, and every login that isn't in another family too. Photos and files are removed from storage, not just hidden. Prices stay with stores other families still use. The recipes you shared stay with families who saved, planned or cooked them, with no family name and none of your photos, unless you tick "Also remove the recipes we shared".
- You can delete a post, or a photo you added to a recipe, at any time.
- Deleting doesn't reach Pantry's server records (above).
- Can't sign in? Write to ehrhard1982@gmail.com.
Changes
When this policy changes, the date at the top changes.
Contact
Write to ehrhard1982@gmail.com.