Privacy Policy for the Pantry Pic app and website | Pantry Pic

Review how the Pantry Pic app collects, stores, and protects your data across mobile and web experiences.

PRIVACY POLICY

Effective date: 1 August 2025  ·  Last updated: 18 January 2026

---

1. Who We Are

Apptractive Pty Ltd ("Company," "we," "us," "our") operates the Pantry Pic mobile applications (iOS and Android), website, and related services (collectively, the "Services").

ABN: 37627379800
Address: 3/79 O'Donnell Street, North Bondi NSW 2026, Australia
Email: hello@pantrypic.com

This Privacy Policy explains how we collect, use, share, and protect your personal information when you use our Services.

2. Scope

This Policy applies to:
• The Pantry Pic mobile applications (iOS and Android)
• The pantrypic.com website and web application
• Our customer support channels
• All related services and features

This Policy does not apply to third‑party services that may be linked from or integrated with our Services. Please review those third parties' privacy policies separately.

3. Information We Collect

We collect information in the following categories:

INFORMATION YOU PROVIDE DIRECTLY:

• Account information — name, email address, password (stored in hashed form), country/region, and account preferences
• Profile and preferences — dietary restrictions, food allergies and intolerances, cooking skill level, household members you cook for, cuisine preferences
• User content — photos of your pantry, fridge, or receipts; recipes you create or save; notes and annotations; shopping lists
• Digital pantry data — ingredients and food items you add to your virtual inventory, including quantities and categories
• Communications — messages you send to customer support, feedback, survey responses, and any other communications with us

INFORMATION COLLECTED AUTOMATICALLY:

• Device information — device type and model, operating system and version, unique device identifiers, app version, language and regional settings
• Usage information — features you use, actions you take, time and frequency of use, search queries, pages and screens viewed
• Technical information — IP address, browser type and version, time zone, general location (country/region level, derived from IP address or device settings)
• Performance data — crash reports, error logs, and diagnostic information to help us improve the Services

INFORMATION FROM THIRD PARTIES:

• App store data — if you purchase a subscription, the relevant app store (Apple or Google) may provide us with transaction identifiers, subscription status, and purchase history (but not your full payment card details)
• Analytics data — aggregated usage information from analytics providers to help us understand how the Services are used
• Authentication — if you sign in using a third‑party service, we may receive basic profile information as permitted by that service and your settings

SPECIAL NOTE ABOUT PHOTOS:
Photos you take or upload are processed to detect ingredients and generate recipe suggestions. See Section 4 for details on how we handle your photos.

4. How We Process Photos and User Content

CAPTURE AND STORAGE:
• Photos remain on your device until you choose to upload them to use our ingredient detection features
• When uploaded, photos are transmitted securely (encrypted in transit) to our cloud infrastructure
• Photos and derived data are stored in secure, access‑controlled systems with encryption at rest

PROCESSING AND ANALYSIS:
• Uploaded photos (including pantry photos, fridge photos, and receipts) are processed using automated systems to detect ingredients, read product information, and generate recipe suggestions
• We use third‑party service providers to assist with image analysis and recognition
• We do not use your personal photos to train publicly available machine learning models

DERIVED DATA:
• From your photos, we may generate derived data such as: detected ingredient lists, nutritional estimates, expiration date reminders, and shopping list suggestions
• This derived data is associated with your account to personalise your experience

YOUR CONTROLS:
• You can delete individual photos or all photos through the App settings
• You can revoke camera permissions on your device at any time
• When you delete your account, your photos and derived data are deleted (subject to backup retention periods described in Section 10)

5. Why We Collect and Use Your Information

We use your information for the following purposes:

TO PROVIDE THE SERVICES:
• Create and manage your account
• Detect ingredients from your photos and suggest recipes
• Manage your digital pantry and shopping lists
• Process your dietary preferences and cooking profiles
• Enable you to share recipes and content with others

TO IMPROVE AND PERSONALISE:
• Personalise recipe recommendations based on your preferences, past activity, and household needs
• Analyse usage patterns to improve features and fix issues
• Conduct research and development (using aggregated or anonymised data)
• Run A/B tests to optimise the user experience

TO COMMUNICATE WITH YOU:
• Send transactional messages (account verification, subscription confirmations, security alerts)
• Provide customer support
• Send service updates about changes to features or policies
• With your consent, send marketing communications about new features, offers, and content

TO ENSURE SAFETY AND COMPLIANCE:
• Detect and prevent fraud, abuse, and security threats
• Enforce our Terms & Conditions
• Comply with legal obligations (e.g., tax, accounting, consumer protection)
• Respond to legal requests and protect our rights

6. Legal Bases for Processing (For Users in the EEA/UK)

If you are located in the European Economic Area or United Kingdom, we rely on the following legal bases:

• Contract — processing necessary to provide the Services you requested (e.g., account management, ingredient detection, recipe suggestions)
• Legitimate interests — improving the Services, preventing fraud, analytics, and direct marketing to existing customers (balanced against your rights)
• Consent — marketing communications (where not covered by legitimate interests), push notifications, and processing of health‑related data such as dietary restrictions
• Legal obligation — tax, accounting, and regulatory compliance

You can withdraw consent at any time (see Section 11), but this does not affect the lawfulness of processing before withdrawal.

7. How We Share Your Information

We share your information with the following categories of recipients:

SERVICE PROVIDERS:
We engage third‑party companies to help us operate and improve the Services, including:
• Cloud hosting and infrastructure providers
• Image analysis and AI processing services
• Payment processors and subscription management platforms
• Analytics and performance monitoring services
• Customer support tools
• Email and communication service providers

These providers act as data processors on our behalf and are contractually required to protect your information and use it only as we direct.

APP STORES:
Apple and Google process subscription payments and may act as independent data controllers for payment‑related data under their own privacy policies.

OTHER USERS:
If you use sharing features (e.g., sharing recipes), your shared content may be visible to other users, potentially including users located in other countries with different data protection laws.

LEGAL AND SAFETY:
We may disclose information if required or permitted by law, including:
• In response to valid legal process (subpoenas, court orders, government requests)
• To protect the safety, rights, or property of Apptractive Pty Ltd, our users, or others
• To detect, prevent, or address fraud, security, or technical issues

BUSINESS TRANSFERS:
In connection with a merger, acquisition, reorganisation, bankruptcy, or sale of assets, your information may be transferred to the successor entity, subject to this Policy.

WE DO NOT SELL YOUR PERSONAL INFORMATION for monetary consideration.

8. International Data Transfers

We operate globally, and your information may be transferred to and processed in countries other than your own, including countries that may not have data protection laws equivalent to those in your jurisdiction.

When we transfer personal information internationally, we implement appropriate safeguards, which may include:
• Transfers to countries recognised as providing adequate protection
• Standard contractual clauses approved by relevant authorities
• Other legally recognised transfer mechanisms

By using the Services, you acknowledge that your information may be transferred internationally as described in this Policy.

For users in the EEA/UK: We ensure that any transfers outside the EEA/UK comply with applicable data protection laws. You may request information about the safeguards we use by contacting us.

9. Data Security

We implement technical and organisational measures designed to protect your information, including:
• Encryption of data in transit and at rest
• Access controls and authentication requirements

However, no system is completely secure. While we strive to protect your information, we cannot guarantee absolute security. You are responsible for maintaining the confidentiality of your account credentials.

If you believe your account has been compromised, please contact us immediately at hello@pantrypic.com.

10. Data Retention

We retain your information only as long as necessary for the purposes described in this Policy or as required by law.

RETENTION PERIODS:

• Account data — retained while your account is active, plus a reasonable period afterward for legal and administrative purposes
• Photos and user content — retained until you delete them or delete your account
• Digital pantry data — retained until you delete items or delete your account
• Usage and analytics data — retained in identifiable form for up to 24 months, then aggregated or anonymised
• Transaction records — retained as required by tax and accounting laws
• Support communications — retained for up to 3 years after resolution

AFTER ACCOUNT DELETION:

• Your data is removed from active systems promptly
• Backup copies are purged within 90 days
• Some data may be retained longer if required by law or for legitimate business purposes (e.g., to resolve disputes)

11. Your Rights and Choices

Depending on your location, you may have certain rights regarding your personal information:

• Access — request a copy of your personal information
• Correction — request correction of inaccurate or incomplete information
• Deletion — request deletion of your personal information
• Restriction — request that we limit how we use your information
• Portability — request your data in a portable, machine‑readable format
• Objection — object to certain processing, including direct marketing
• Withdraw consent — withdraw consent where processing is based on consent

HOW TO EXERCISE YOUR RIGHTS:

• In the App — use privacy controls in Settings (where available)
• By email — contact us at hello@pantrypic.com
• Account deletion — available in App Settings or by emailing us

We will verify your identity before processing requests and respond within the timeframes required by applicable law (typically within 30 days, or as specified by local law).

Some requests may be limited by applicable law or our legitimate interests. We will explain any limitations when we respond.

For users in the EEA/UK: If you are not satisfied with our response, you have the right to lodge a complaint with your local data protection authority.

12. Cookies and Tracking

ON OUR WEBSITE:
We use cookies and similar technologies for:
• Essential functions — authentication, security, remembering your preferences
• Analytics — understanding how visitors use the Site to improve it
• Performance — monitoring site performance and fixing issues

Where required by law, we obtain your consent before placing non‑essential cookies. You can manage cookie preferences through our cookie banner or your browser settings.

IN OUR MOBILE APPS:
We use mobile analytics and diagnostic tools to understand app usage and improve performance. You can limit certain tracking:
• iOS: Settings → Privacy → Tracking
• Android: Settings → Privacy → Ads

13. Marketing Communications

TYPES OF COMMUNICATIONS:

• Transactional/Service — essential communications about your account, subscription, security, and service changes. These are not marketing and are necessary to provide the Services.
• Marketing — promotional messages about new features, offers, tips, and content. We only send marketing communications with your consent (where required) or under legitimate interests (for existing customers in some jurisdictions).

CHANNELS:

• Email — marketing emails include an unsubscribe link; click to opt out
• Push notifications — require your device permission; manage in App Settings or device settings
• In‑app messages — manage preferences in App Settings

YOUR CHOICES:

• Opt out of marketing emails via the unsubscribe link or App Settings
• Disable push notifications in your device settings
• Adjust in‑app message preferences in App Settings
• Contact us at hello@pantrypic.com to update your preferences

Opting out of marketing does not affect transactional or service communications.

14. Children's Privacy

The Services are not directed to children under 13 (or the applicable age of digital consent in your country, if higher). We do not knowingly collect personal information from children below this age.

If we learn that we have collected personal information from a child without appropriate parental consent, we will delete it promptly. If you believe we have collected information from a child, please contact us at hello@pantrypic.com.

15. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, the Services, or applicable law.

For material changes, we will provide notice by:
• Email (to the address associated with your account)
• In‑app notification
• Posting the updated Policy with a new "Last Updated" date

Your continued use of the Services after the effective date of a revised Policy constitutes acceptance. If you do not agree, please stop using the Services.

16. Contact Us

If you have questions about this Privacy Policy, want to exercise your rights, or have concerns about our data practices, please contact us:

Email: hello@pantrypic.com
Address: 3/79 O'Donnell Street, North Bondi NSW 2026, Australia

For users in the EEA/UK: Our contact details above serve as our point of contact for data protection matters.

---

REGIONAL PRIVACY DISCLOSURES

AUSTRALIA
This Policy is designed to comply with the Privacy Act 1988 (Cth) and the Australian Privacy Principles. You may access your personal information or make a complaint by contacting us.

EUROPEAN ECONOMIC AREA & UNITED KINGDOM
If you are in the EEA or UK, you have additional rights under the GDPR/UK GDPR, as described in Section 11. Our legal bases for processing are set out in Section 6. You have the right to lodge a complaint with your local supervisory authority.

UNITED STATES — CALIFORNIA
If you are a California resident, you may have rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA), including the right to know, delete, correct, and opt out. We do not sell your personal information as defined under these laws.

UNITED STATES — OTHER STATES
Residents of Virginia, Colorado, Connecticut, Utah, and other states with comprehensive privacy laws may have similar rights. Contact us to exercise your rights.

OTHER JURISDICTIONS
We comply with applicable data protection laws. If you have questions about your rights under local law, please contact us.