Also available inside the app under Settings → Privacy & Security. The bundled copy is version 2026-09-27 and works offline.
Privacy Policy
Version 2026-09-27 · Effective September 27, 2026
The short version
- Pantry Tracker is run by one person: Santiago Domenech-Mejia, a sole proprietor in British Columbia, Canada. There is no larger company behind it.
- We collect your account details and the things you track so we can save and sync them across your devices.
- Your pantry, food logs, weight, and workout routes stay private. Nothing is public unless you choose to share it.
- Some features send your photos, voice, or text to outside AI providers to produce a result; we send only what is needed and never use your content to train our own models.
- Our API servers are in Canada, but our database and some providers are in the United States, Singapore, and China, so your data is processed across borders.
- We show ads only on the free tier, we do not sell your personal data, and we use no third-party analytics.
- You can export all of your data at any time, and delete your account from the App or the Website. Deletion removes your personal information right away. Your product-catalog contributions stay in the catalog with no link to you, and content you shared with other people stays available to them (Section 10).
1. Who we are
The App and the Website are run by Santiago Domenech-Mejia, an individual operating as a sole proprietorship registered in British Columbia, Canada under the business name "Pantry Tracker App" (registration number FM1114931). In this Policy, "we", "us", and "our" mean that operator, "you" means the person using the App, "the App" is the Pantry Tracker Android app, and "the Website" is pantrytrackerapp.com. It explains what we collect, how we use and share it, how long we keep it, and your choices. By creating an account or using the App, you accept it; if you do not agree, please do not use the App. The App is offered in Canada first, and later in the United States and Mexico; Section 12 covers rights that may apply where you live.
2. Information we collect
Account details. A username (a permanent handle you choose), your email, a password stored only as a bcrypt hash, and an optional display name (the name other users see; Pro members can change it, and on other plans we change it on request). We also generate a random 6-character public "social ID" so other users can find and add you. If you sign in with GitHub or Discord, we receive and store your provider user ID, display name, and verified email from that provider, but not your GitHub or Discord password. Accounts created this way have no usable password until you set one with "Forgot password".
Content you create. We store what you track so it syncs across your devices: pantry items and quantities, shopping lists, reminders, recipes, meal plans, calorie, nutrition, and weight entries, body details you enter (such as height, age, sex, and goals), exercise routines and set logs, run history (including GPS routes), custom gyms and machines, notes, bug reports, feature suggestions, in-app support threads, and scan history.
Photos and media. Photos you take to scan a barcode, label, or item are stored with your scan history, because our background worker and moderation review read them; they are deleted when you clear your scan history or delete your account, except a product or label photo that has been added to a product in the shared catalog, which stays in the catalog with no link to you (Section 10). Recipe images, exercise animations, and bug-report screenshots are stored as part of your content. We strip embedded metadata such as EXIF (which can contain location) before storing an image. Schedule photos or PDFs you upload to import a routine are processed in a temporary file and never stored.
Voice. When you log by voice, the audio is sent to a transcription provider to turn it into text (Section 5). We do not keep it afterward.
Location and runs. The App accesses your location only while you record a run or other GPS-tracked workout, through a foreground service, to save your route for your own workout history. It does not track your location in the background. You can decline the location permission and keep using the rest of the App.
Device and session details. For each signed-in session, our server stores the IP address, a device label, the Android device identifier (ANDROID_ID), and timestamps, so we can support several devices on one account and keep the service secure. To sync your devices we also register a Firebase Cloud Messaging push token, which carries no personal content.
Subscriptions. If you subscribe, Google Play processes the payment; we store a purchase token, the tier, and its expiry to unlock and verify your plan. We never receive or store your card number.
Advertising identifier. On the free tier, Google AdMob may use your Android advertising ID and related data to show and measure ads, including rewarded ads that earn in-app "ad credits" (Section 8).
3. Information we do not collect
- We do not sell or rent your personal data.
- We do not read your contacts, messages, call history, or any files outside the App.
- We do not track your location in the background. Location is used only while you record a run.
- We do not use your personal content to train our own AI models.
- We do not use any third-party analytics or crash-reporting service.
4. How we use your information
- Run the App: save, sync, and show your pantry, recipes, nutrition, workouts, and other data across your devices.
- Social features: let you find and add other users, share content with the audience you pick, join a household and pool a pantry, and rate shared content.
- AI features: process photos, voice, and text through the providers in Section 5 to identify products, read labels, look up nutrition, transcribe voice, and suggest recipes and coaching.
- Communicate: send verification codes, security and account notices, replies to your support messages and bug reports, and moderation results.
- Keep it safe: review content submitted for public sharing, enforce our Terms, and prevent abuse and fraud.
- Billing and ads: verify purchases, apply the right tier, and show ads on the free tier.
- Legal: meet legal obligations and enforce our agreements.
5. AI features and who processes your content
Some features send your content to outside AI providers so they can return a result. We send only what is needed, and we do not use your content to train our own models. Each provider processes what we send under its own terms and privacy policy:
- OpenAI (United States): understands photos of products and labels, and transcribes voice logging. OpenAI Privacy Policy.
- Alibaba Cloud Model Studio (Singapore): Qwen models for image understanding, text extraction from images (OCR), and text processing such as item enrichment, ingredient matching, and catalog checks. Alibaba Cloud Privacy Policy.
- DeepSeek (People's Republic of China): text processing for voice-based food, pantry, and cooking logging, and recipe import. DeepSeek Privacy Policy.
- Google Cloud Vision (United States): a fallback for text extraction from images (OCR). Google Privacy Policy.
We log AI requests: which feature was used, when, and how often, so we can apply your plan's limits and keep the features working. We also keep a limited sample of AI inputs and outputs so we can look into suspected abuse and check the quality of results, and a person may review that sample. We do not use it to train our own AI models, and we delete it within 90 days. If you delete your account, that sample goes with it. Section 16 of our Terms of Service explains what counts as misuse of these features and what happens then.
In-app support threads may be triaged or first answered by an automated assistant that uses the text providers above; a person can always review them. AI results are estimates and can be wrong; see the Terms of Service for the related disclaimers.
6. Where your data is stored
We use these infrastructure providers. Because they are in different countries, your data is transferred and processed across borders, including outside Canada; by using the App you consent to these transfers.
- OVH (Canada, in Beauharnois, Quebec): our API servers. OVH data protection.
- Neon (United States, on AWS in Oregon): our main database, where your account and content are stored. Neon Privacy Policy.
- Cloudflare (global edge network): media storage, content delivery, and security. Cloudflare Privacy Policy.
- Resend (United States): transactional email, such as verification codes and data-export files. Resend Privacy Policy.
- Google Play Billing, AdMob, and Firebase Cloud Messaging: subscriptions, free-tier ads, and sync notifications. Google Privacy Policy.
- GitHub and Discord: optional sign-in. GitHub Privacy Statement, Discord Privacy Policy.
- OpenStreetMap: map tiles for run and territory maps, so its tile servers receive your device IP address and the map area you view. OpenStreetMap Privacy Policy.
Our database is in the United States, not in Canada. If you use the App from Canada, Mexico, or elsewhere, your data is processed in these countries, which may have different data-protection laws than your own.
7. What other users can see
Nothing you track is public by default. These optional features disclose specific information to others:
- Profile. Your username, display name, and public social ID are visible so others can find and add you. Follower and following counts may be visible; the list of who you follow is visible only to you.
- Public sharing. A recipe, exercise, or routine you share publicly can be viewed and imported by others. Shared routines carry the structure only; your logged reps and weights are removed first. Public exercises and routines are reviewed by our moderators before others see them; shared recipes may appear without prior review. If you delete your account, what you shared stays available, shown as coming from a deleted user (Section 10).
- Private sharing. You can instead share with specific users you name; only you and they can see it, and it does not enter the public catalog. If you delete your account, it stays available to them.
- Ratings and comments. A rating counts toward a public average, and a short comment may be visible to others. Do not put personal information in comments.
- Household and shared pantry. Other members see your username, display name, social ID, and the items and quantities you pool. Using a pooled item updates the shared quantity for everyone; items you do not pool stay private. You can leave at any time and keep your own pantry data. If you delete your account, you leave the household as if you had left it yourself: the items you pooled leave with you, while the household's shared quantity history stays with the other members, shown as coming from a deleted user. If you own the household, it continues and ownership passes to the remaining member on the highest plan (Pro, then Basic, then Free), the one who joined earliest among equals; it closes only when no other member is left, and every member keeps their own pantry data.
- Territory (optional, off by default, Pro tier). If you turn it on and claim an area by running, a simplified outline of that area, its size, and a short display name you choose (reviewed by our moderators) can appear on a shared map and leaderboard. Your detailed GPS routes are never shown to others.
- Catalog contributions. A product you add by hand (name, brand, barcode, size, nutrition, and photo) may be reviewed and, if approved, added to a shared product catalog. This covers product facts only, never your quantities or personal data. The catalog builds on Open Food Facts and is offered for download under the Open Database License (ODbL). If you delete your account, your contributions stay, de-identified (Section 10), including a submission still waiting for review together with its photo, which may still be approved; a submission we rejected is deleted with your account, together with its photo. Photograph only the product and its label, and do not include people, faces, or other personal information in product photos.
8. Subscriptions and advertising
The App has a free tier with ads, plus Basic and Pro subscriptions sold through Google Play. Subscriptions renew automatically until you cancel in Google Play, and refunds follow Google's policy. On the free tier, Google AdMob shows ads and may use your Android advertising ID and related data to serve and measure them, including rewarded ads that earn in-app "ad credits". You can reset or limit this ID in Android under Settings, Google, Ads. Paid subscribers do not see ads. We do not sell your personal data to advertisers or share your private content with them.
We may also give an account a complimentary or lifetime Basic or Pro plan at our discretion. We record which plan was given, when, by whom on our side, and why, and we can revoke it if our Terms of Service are broken. That record is deleted with your account.
9. Security
- All traffic is encrypted with HTTPS (TLS).
- Passwords are stored only as bcrypt hashes, never in plain text.
- Session tokens are stored as SHA-256 hashes.
- The database keeps each user's rows isolated at the row level.
- Cloudflare provides a web application firewall and edge authentication.
- Credentials saved on your device use encrypted storage.
- No system is perfectly secure, but we work to protect your data and to notify you of a significant breach as the law requires.
10. Keeping and deleting your data
We keep your data while your account is active. You can delete your account at any time in the App at Settings, Privacy & Security, Delete account (enter your password and type DELETE), or on the Website at pantrytrackerapp.com/delete-account (enter your username and password). Deletion is immediate and cannot be undone: your data is taken out of the live service right away, and the copies in our backups are gone for good within 30 days (see Backups below). Export your data first if you want a copy (Section 11).
What we delete. When you delete your account, we delete all of your personal information, including: your account, email, and username; your body data (weight, height, age, sex, and goals); your calorie, macro, and food logs; your exercise data, including workouts, routines, set logs, runs, and GPS routes; your own pantry list, quantities, and purchase and consumption history; your shopping lists, reminders, meal plans, and settings; recipes you did not share; voice recordings; photos and videos you did not share and that are not part of the shared catalog; catalog submissions we rejected, with their photos; any complimentary plan we gave you; and your other uploads. Notes our staff wrote about your account are deleted, or reduced to a de-identified record of what was done and when. We also end your sessions and remove your GitHub or Discord sign-in links.
What we keep, de-identified: product catalog contributions. Product records you added, product and label photos attached to a catalog product, nutrition corrections, and catalog submissions that were approved or are still waiting for review (with their photos) are part of the shared product catalog. When you delete your account, we keep them but remove your username from them, so they are de-identified and no longer linked to you or your account; a submission still waiting for review may still be approved. A submission we rejected is not kept: it is deleted with your account, together with its photo. Because these photos stay in the catalog, do not include people, faces, or other personal information in product photos.
What we keep: content you shared with others. Routines, exercises (including your own photos and videos in them), recipes, and cookbook listings that you shared publicly or with other people stay available to the public or to the people you shared them with, shown as coming from a deleted user. Messages you sent to a coach or client stay in that person's conversation, shown as coming from a deleted user. Copies other users already imported stay with them. In a household, the items you pooled leave with you, while the shared quantity history stays with the other members, shown as coming from a deleted user; a household you own continues under the remaining member on the highest plan, the one who joined earliest among equals. Section 8 of the Terms of Service describes the license that allows this. If you do not want something to stay available, stop sharing it or delete it before you delete your account.
Taking down shared content. Whether or not you still have an account, if content someone shared shows you, for example your face in a video, or you want a specific item you shared taken down, email support@pantrytrackerapp.com and tell us which item it is. We can trace every copy of shared content back to the person who uploaded it, including copies other users imported, and we will review the request and act on it.
Backups. We make nightly backups of our database and keep them for up to 30 days on infrastructure we operate; after that they are overwritten. This means data you delete, including a deleted account, can remain in a backup for up to 30 days before it is gone for good. We use backups only to recover from errors or outages, never to restore a deleted account.
If you cannot sign in, for example because you use GitHub or Discord and never set a password, either use "Forgot password" if an email is on file, or email support@pantrytrackerapp.com from the account's email address with the subject "Delete my account". We verify and process it within 30 days.
11. Exporting your data
You can request a full copy of your data at any time, on any tier, at no cost. In the App, go to Settings, Privacy & Security, Export my data, and we email a JSON file to the address on your account (rate-limited to prevent abuse). You can also ask by emailing support@pantrytrackerapp.com. For your protection, the export goes only to the email on the account, not to any address given in the request.
12. Your rights by region
Depending on where you live, you may have rights to access, correct, delete, or receive a copy of your personal information, and to withdraw consent. In the App you can already view and edit your data, export it (Section 11), and delete it (Section 10). For any other request, email support@pantrytrackerapp.com; we verify it against your account and reply within the time the law allows. We do not sell personal information, so there is no sale opt-out; to limit ad personalization, use your device ad settings (Section 8).
Canada. We handle personal information under Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and, in British Columbia, the Personal Information Protection Act (PIPA). You may access and correct your information and withdraw consent, within legal limits. If a concern is unresolved, you may contact the Office of the Privacy Commissioner of Canada or of British Columbia.
United States. Some states, including California, Virginia, Colorado, Connecticut, and Utah, give you rights to know, access, delete, correct, and receive a copy of your personal information, and to opt out of its sale or of targeted advertising. We do not sell your personal information or share your private content with advertisers. Contact us to use these rights, or to appeal a decision by replying to our response; we will not discriminate against you for doing so.
Mexico. We process personal data under the Federal Law on the Protection of Personal Data Held by Private Parties (LFPDPPP). You have the ARCO rights (Access, Rectification, Cancellation, and Opposition), and may revoke consent and limit the use or disclosure of your data. Contact us to exercise them; if you are not satisfied, you may contact Mexico's data protection authority (INAI).
Europe and the United Kingdom. The App is not aimed at users in the European Economic Area or the United Kingdom. If you use it from there, our legal bases are our contract with you, your consent, our legitimate interest in keeping the service secure, and legal obligations. You have rights of access, correction, erasure, restriction, portability, and objection, and may complain to your local authority.
13. Children
The App is not for children under 13 (or the higher age of digital consent where you live). We do not knowingly collect data from children under that age. If you are under the age of majority where you live, use the App only with a parent's or guardian's permission. If you believe a child gave us data, contact us and we will delete it.
14. Changes to this Policy
We may update this Policy. When a change is material, we will show an in-app notice, and email you where we have your address, before it takes effect, and we will update the version and date at the top. The version you accepted at signup is recorded with a timestamp. Continued use after a change takes effect means you accept the updated Policy.
15. Contact
For any privacy question or request, email support@pantrytrackerapp.com. The operator is Pantry Tracker App (Santiago Domenech-Mejia, sole proprietor), British Columbia, Canada. See also our Terms of Service and Cookie Policy.