Privacy Policy
Effective date: September 30, 2026
Virtual Pantry ("the app", "we", "us") is made by Jeremy Potter. This policy explains what information the app collects, why, and what you can do about it.
If you have any question about this policy or your data, email us at jeremypotter.business@gmail.com.
The short version
- You need an account to use Virtual Pantry. We store your pantry, lists, recipes and meal plans on our server so they are backed up, sync to your other phones, and can be shared with your household.
- When you ask the app to read a receipt, estimate how long a food lasts, plan meals, or import a recipe, the relevant text, photos or video are sent to Google's Gemini AI to do that job.
- We do not sell your information, show ads, or use tracking or advertising SDKs.
- You can delete your account, and everything in it, from inside the app at any time.
What we collect
Account information. Your email address and the name you give us. If you sign in with Apple or Google, we receive the email address and name that service shares with us (with Sign in with Apple you can choose to hide your email; we then receive a private relay address). If you create an account with an email and password, we store your password only as a secure one-way hash.
Your pantry and kitchen data. Everything you put into the app: food items and their dates, quantities, storage locations and notes; shopping lists; the history of foods you used or threw away; receipts you save; recipes you save or write; your weekly meal plans; and the answers you gave during setup (diet, allergies, cuisines, kitchen equipment, budget, how many people you cook for).
Allergy and diet information. If you tell us about food allergies or dietary needs, we store them so meal plans leave those foods out. You choose whether to give us this information. It is shared with the other members of your household so their meal plans stay safe for you.
Photos and videos you choose to send. Receipt photos, photos of recipes or cookbook pages, and videos you share to import a recipe. Receipt photos and your own food photos stay on your phone; the app sends a copy to our server only for the moment needed to read it (see "AI features" below). Uploaded recipe videos are deleted from our server within one hour; large videos are passed to Google through its file service, which deletes them automatically within 48 hours.
Links you share. When you share a TikTok, Instagram, YouTube or website link to import a recipe, we store the link, the creator's public name and handle, and the recipe we extracted, so we can show where the recipe came from.
Purchase information. If you subscribe, Apple processes the payment. We receive (through our payments provider, RevenueCat) which plan you bought, whether it is active, and when it renews or ends. We never see your card or Apple account details.
Technical information. Our server records basic request logs (time, the address the request came from, and whether it succeeded) to keep the service running and to stop abuse. These logs are kept for 30 days.
AI features and Google Gemini
Several features use Google's Gemini AI, run through our server:
- Reading a receipt: the receipt photo is sent to Gemini to list what you bought.
- Shelf-life estimates: the name of a food is sent to Gemini to estimate how long it keeps.
- Meal planning: your household's food preferences, allergies, equipment and the foods in your pantry are sent to Gemini to write the week's recipes.
- Importing a recipe: the post's caption or description, the web page's recipe, the photo, or the video you shared is sent to Gemini to turn it into a recipe.
We send only what the feature needs, and we do not send your name or email address. Google processes this data under its Gemini API terms. We use Google's free Gemini service, under which Google may use this data, including through human review, to improve its products. Please don't send photos containing information you don't want reviewed.
How we use your information
- To run the app: store and sync your data, share it with your household, send you reminders, and provide the features you ask for.
- To keep your household's meal plans safe for everyone's allergies and diets.
- To manage your subscription.
- To prevent abuse, such as limiting how many AI requests an account can make each day.
- To answer you when you contact us.
We do not use your information for advertising, and we do not sell or rent it.
Who we share it with
- Your household. If you join or create a household, its members can see the shared pantry, lists, recipes and meal plan, your display name, and your allergies and diet choices.
- Service providers that run parts of the app for us, only for that purpose:
- Railway (hosting our server and database, United States)
- Google (Gemini AI; also Google Sign-In if you use it)
- Apple (Sign in with Apple, payments)
- RevenueCat (subscription status)
- Open Food Facts and the USDA FoodData Central database (when you scan a barcode, the barcode number is looked up there)
- TikTok, YouTube and the recipe website you share (we ask them for the public caption, description or recipe of the link you shared)
- The law. If we are required to by law, or to protect someone's safety.
How long we keep it
We keep your data for as long as your account exists. YouTube video descriptions used for an import are deleted after 30 days. If you delete your account, we delete your account and your personal data from our database right away; backups are overwritten within 30 days. If you were in a household with other members, the shared household data you added stays with that household.
Your choices and rights
- See and change your data: everything you store is visible and editable in the app.
- Delete your account: Settings ▸ Account ▸ Delete account. This removes your account and personal data.
- Allergies and diet: you can remove them at any time in Settings ▸ Home Menu.
- Notifications: you can turn reminders off in the app or in iOS Settings.
- Depending on where you live (for example the EU, UK or California), you may have further rights, such as asking for a copy of your data or objecting to how we use it. Email us at the address above and we will respond within 30 days.
Children
Virtual Pantry is not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child has given us information, contact us and we will delete it.
Security
Data travels to our server over encrypted connections, passwords are stored only as hashes, and access to the database is limited. No system is perfectly secure, but we work to protect your information.
Changes to this policy
If we make important changes, we will tell you in the app before they take effect. The effective date at the top shows when this policy last changed.
Contact
Jeremy Potter
Email: jeremypotter.business@gmail.com