pantree
Privacy Policy
Last updated: September 16, 2026 · Pantree iOS app and usepantree.com
This Privacy Policy explains what information Pantree collects, how it is used, which service
providers process it, how long it is retained, and the choices available to you. Pantree is
offered by Turner Hilton, an individual operating in the United States.
Pantree does not use advertising identifiers, advertising networks, or
third-party analytics SDKs. We do not sell personal information or use it for targeted
advertising. You can delete your Pantree account from the app.
1. Scope
This policy applies to the Pantree iOS app and the website at usepantree.com. Pantree is
currently offered in the United States on iOS.
2. Information you provide
- Account information. You may sign in with an email address and password or
with Sign in with Apple. If you use Apple's Hide My Email feature, Pantree
receives the relay address provided by Apple rather than your underlying email address.
Pantree does not receive or store your password. You may optionally provide a first and last
name for display in the app.
- Pantry and shopping information. Pantree stores the items you add, including
names, categories, quantities, units, dates, shopping-list entries, and related inventory
activity. This information is stored on your device and synchronized to Pantree's servers.
- Receipts. If you scan or upload a receipt, the image or PDF is sent to
Pantree's servers and to the AI provider used for receipt extraction. Pantree extracts
candidate line items and presents them for your review before they are added to your pantry.
Receipt scanning is optional.
- Shelf photos. If you photograph a shelf, refrigerator, freezer, or cupboard,
the selected photo is sent to Pantree's servers and to the AI provider used to identify items.
You review the identified items before they are added to your pantry. The source photo is
deleted from Pantree's storage after processing completes, normally within seconds.
- Preferences. You may provide dietary preferences, allergy selections,
household size, meals-per-week preferences, leftover preferences, and shelf-life adjustments.
These settings are optional and are used to filter or rank recipes and meal suggestions.
Allergy selections may reveal health-related information, but Pantree does not access your
medical records or Apple Health data.
- Beta feedback. In TestFlight and internal beta builds, the in-app feedback
tool can include a screenshot, a note you enter, the current screen name, and the app version.
The screenshot is shown before submission and can be removed. This feature is not included in
the public App Store build.
3. Information collected automatically
- Crash and error reports. Pantree records error messages, stack traces,
generalized screen paths, severity, app version, build number, and platform information. When
the app or Pantree's service crashes or reports an error, this information is also sent to
Sentry, which Pantree uses to be alerted to problems. Those reports can include your Pantree
account identifier, device model, operating-system version, and a random identifier for the
app installation. They do not include an advertising identifier, your name, your email
address, pantry contents, receipt contents, or request contents.
- Service logs. Pantree records timestamps, request identifiers, account
identifiers, and the operation a request was performing. Service logs are configured to
exclude receipt contents, pantry contents, request bodies, and database query contents.
- Plan usage counts. Pantree records counts of metered features, such as
receipt scans, shelf-photo scans, and meal generations, to enforce plan limits.
- Subscription information. Pantree uses RevenueCat to manage subscription
entitlements. RevenueCat may process a Pantree account identifier, purchase and subscription
history, entitlement status, and basic device or operating-system information needed to
provide its service. Pantree does not receive your payment-card number.
- Discover activity. If Discover is enabled for your account, Pantree records
which recipe cards were shown and whether you skipped, opened, saved, hid, planned, or marked
them as cooked, together with card position and approximate display time. This information is
stored using recipe identifiers and interaction data rather than free-text pantry contents.
It is used to reduce repetition and improve ranking. If Discover is not enabled for your
account, this activity is not collected.
- Shelf-location selections. If shelf sweeps are enabled and you choose to
answer the optional location question, Pantree stores the location category you select - such
as refrigerator, freezer, pantry, countertop, or other - and the time of the scan. Pantree
does not collect coordinates for this feature. The location selection is used to identify
items that may be missing from an expected storage area.
- Inventory consumption estimates. Pantree may calculate purchase frequency
and estimated consumption rate from inventory events already associated with your account.
These calculations are generated from existing account data and are not stored as a separate
behavioral profile. They may be used to suggest that an item is running low or to ask you to
confirm inventory status.
- IP address. Pantree may process an IP address temporarily for security and
rate-limiting, including protection of sign-in attempts and payment webhooks. Pantree does not
store the IP address in its application database for these purposes.
4. Device permissions and information Pantree does not collect
- Location. Pantree does not request device location permission or collect
GPS coordinates.
- Advertising identifiers. Pantree does not use IDFA, advertising SDKs, or
App Tracking Transparency for cross-app tracking.
- Third-party analytics SDKs. Pantree does not include Google Analytics,
Firebase Analytics, Amplitude, Mixpanel, Segment, Meta SDK, or an attribution SDK.
- Push-notification tokens. Pantree reminders are scheduled locally on your
device. Pantree does not send a push-notification token to its servers for those reminders.
- Contacts, microphone, medical records, Apple Health, or biometric data.
Pantree does not request access to these sources.
- Photo library. Pantree does not scan or index your photo library. If you
select an existing receipt or shelf photo, Pantree receives only the item you selected.
- Photos you add to your own recipes. If you add a photo to a recipe you
wrote yourself, that photo stays on your device. It is not uploaded to Pantree, is not sent
to any third party, and is removed when you delete the recipe, sign out, or delete your
account.
- Payment card details. Subscription purchases are processed by Apple.
Pantree does not receive your payment card number.
5. How Pantree uses information
Pantree uses information described in this policy to:
- create and maintain your account;
- synchronize pantry, shopping-list, and preference data;
- process receipts and shelf photos that you choose to submit;
- provide product lookups, recipe filtering, meal suggestions, and inventory features;
- personalize Discover when that feature is enabled;
- manage subscriptions and enforce plan limits;
- prevent abuse, secure accounts, diagnose errors, and operate the service; and
- respond to support requests and beta feedback.
Pantree does not sell personal information and does not use personal information for
cross-context behavioral advertising or third-party advertising profiles.
6. AI processing
Certain Pantree features use third-party AI services.
Anthropic. Receipt extraction, shelf-photo reading, and generated meal ideas
are processed using the Anthropic API. Depending on the feature, Pantree may send a receipt image,
a shelf photo, or a limited snapshot of pantry and dietary information needed to produce the
requested result. Under Anthropic's current commercial-service practices, API inputs and outputs
are not used for model training by default. Standard API inputs and outputs are generally deleted
from Anthropic's backend within 30 days, subject to Anthropic's stated exceptions for legal,
safety, abuse-prevention, feedback, or separately agreed retention requirements.
Microsoft Azure AI Foundry. Shelf classification sends generic item names,
such as "whole milk," to Microsoft Azure AI Foundry to classify where an item is normally stored.
Pantree does not send receipt images to Microsoft for this feature. Microsoft states that customer
prompts and completions are not used to train generative foundation models without permission.
Under Microsoft's default abuse-monitoring process, content flagged for potential abuse may be
subject to automated review and, in some cases, review by authorized Microsoft personnel.
Pantree does not train its own AI model on your personal information.
7. Service providers
| Provider | Purpose |
| Supabase | Database services and account authentication |
| Railway | Application hosting and service logs |
| Cloudflare | Website hosting, temporary receipt and shelf-photo storage, and encrypted database backups kept for up to 7 days |
| RevenueCat | Subscription and entitlement management; may process account identifier, purchase history, subscription status, and basic device or operating-system information |
| Anthropic | Receipt extraction, shelf-photo reading, and generated meal ideas |
| Microsoft Azure AI Foundry | Classification of generic item names |
| Apple | Sign in with Apple and App Store subscription billing |
| Resend | Account-confirmation and password-reset email; receives the destination email address |
| Sentry | Crash and error reporting; may process account identifier, error details, app version, device model, operating-system version, and a random installation identifier |
| Expo | Delivery of app updates; when the app checks for an update, receives the device operating system, a random installation identifier, and IP address |
These providers process information on Pantree's behalf or provide services necessary to
operate the app. Their handling of information is also governed by their applicable contracts,
privacy terms, and legal obligations.
Product lookups
When you scan a barcode or search for a product by name, the barcode or search term may be
sent to USDA FoodData Central. Those requests do not include your Pantree account
information. Pantree also searches a local copy of the Open Food Facts database;
searches of that copy are processed on Pantree's systems and are not sent to Open Food Facts.
8. Retention and deletion
| Data | Retention |
| Account, pantry, preferences, and shopping list | Until you delete the account or the data |
| Receipt images | Up to 30 days, then automatically deleted |
| Shelf photos | Deleted after processing completes, normally within seconds |
| Receipt line items and price history | Until you delete the account or the applicable record |
| Beta feedback and submitted screenshots | Until you delete the account |
| Individual Discover activity | 30 days, then automatically deleted |
| Discover aggregate totals by recipe | Until you delete the account |
| Background job records | 7 days after successful completion; 30 days after failure |
| Service logs | Retained according to the hosting provider plan and configured log-retention period |
| Crash and error reports held by Sentry | Up to 30 days, then automatically deleted |
| Database backups | Deleted data may remain in encrypted daily backups for up to 7 days |
| Account-deletion tombstone | Retained as needed to prevent a recently deleted account from being recreated by a previously issued sign-in token |
Deleting your account
In Pantree, open Settings and choose Delete account. Account
deletion permanently removes your active account record, pantry, shopping list, receipts,
receipt images still within their retention period, shelf photos still being processed,
preferences, feedback, subscription records maintained by Pantree, and sign-in credentials.
The action cannot be undone.
Pantree retains a limited deletion record containing the former account identifier and deletion
status so that a sign-in token issued shortly before deletion cannot recreate the account. The
record does not contain your email address, name, pantry contents, receipt contents, or other
user-submitted content.
Deleting your Pantree account does not cancel an App Store
subscription. Apple manages subscription billing separately. Cancel the subscription in
your Apple subscription settings if you do not want it to renew.
Deletion is subject to limited operational retention. Deleted records may remain in encrypted
backups for up to 7 days. Service logs and crash reports may continue to contain a Pantree account
identifier after account deletion until their retention period ends; they are configured not to
contain your name, email address, pantry contents, or receipt contents.
9. Security
Pantree uses administrative and technical safeguards designed to protect information. Network
traffic between the app and Pantree's servers is encrypted in transit using TLS. Database access
uses row-level security tied to the authenticated account, and receipt images are stored in
access-controlled object storage. Service logs are configured to exclude pantry and receipt
contents.
No system can guarantee absolute security. If Pantree becomes aware of a security incident
requiring notice under applicable law, affected users will be notified as required.
10. Your choices and privacy requests
- Add pantry items manually instead of scanning a receipt or shelf.
- Leave optional name, dietary, allergy, and household-preference fields blank.
- Turn local reminders off in the app.
- Delete individual records or delete your entire account.
- Request access to or a copy of your Pantree data by emailing
support@usepantree.com.
- Request correction or deletion of personal information by contacting the same address.
Depending on where you live, applicable law may provide additional privacy rights. Pantree
will respond to qualifying requests as required by applicable law and may need to verify the
request before acting on it.
11. Children
Pantree is intended for users age 13 and older and is not directed to children under 13.
Pantree does not knowingly collect personal information from children under 13. If you believe
a child under 13 has provided personal information to Pantree, contact
support@usepantree.com.
12. Dietary, allergy, and freshness information
Dietary and allergy filters are convenience features and are not medical safeguards. Recipe
and product information may be incomplete, inaccurate, or outdated. Always review the actual
ingredient label and applicable allergen or cross-contact information. Freshness and best-by
dates shown by Pantree are estimates and are not food-safety guarantees.
13. Third-party links
Pantree may link to Apple subscription settings, external recipe sources, and other third-party
services. This Privacy Policy does not govern those third parties.
14. Changes to this policy
Pantree may update this Privacy Policy as the app or its data practices change. The current
version will be posted on this page with a revised last-updated date. If a change materially
affects how personal information is handled, Pantree will provide additional notice when required
by applicable law.
15. Contact
Questions or privacy requests may be sent to
support@usepantree.com.