Privacy Policy for the Pantry Pic app and website | Pantry Pic

Review how the Pantry Pic app collects, stores, and protects your data across mobile and web experiences.

PRIVACY POLICY

Effective date: 1 August 2025  ·  Last updated: 15 June 2026

---

1. Who We Are

Apptractive Pty Ltd ("Company," "we," "us," "our") operates the Pantry Pic mobile applications (iOS and Android), website, and related services (collectively, the "Services").

ABN: 37627379800
Address: 3/79 O'Donnell Street, North Bondi NSW 2026, Australia
Email: hello@pantrypic.com

This Privacy Policy explains how we collect, use, share, and protect your personal information when you use our Services.

2. Scope

This Policy applies to:
• The Pantry Pic mobile applications (iOS and Android)
• The pantrypic.com website and web application
• Our customer support channels
• All related services and features

This Policy does not apply to third‑party services that may be linked from or integrated with our Services. Please review those third parties' privacy policies separately.

3. Information We Collect

We collect information in the following categories:

INFORMATION YOU PROVIDE DIRECTLY:

• Account information — name, email address, password (stored in hashed form), country/region, and account preferences
• Profile and preferences — dietary restrictions, food allergies and intolerances, cooking skill level, household members you cook for, cuisine preferences
• User content — photos of your pantry, fridge, or receipts; recipes you create or save; notes and annotations; shopping lists
• Digital pantry data — ingredients and food items you add to your virtual inventory, including quantities and categories
• Communications — messages you send to customer support, feedback, survey responses, and any other communications with us
• Forwarded receipts — if you use Email a Receipt to Your Pantry, the emails you forward to your personal receipts address, including the sender address, subject line, message body, and any PDF or image attachments (see Section 5)

INFORMATION COLLECTED AUTOMATICALLY:

• Device information — device type and model, operating system and version, unique device identifiers, app version, language and regional settings
• Usage information — features you use, actions you take, time and frequency of use, search queries, pages and screens viewed
• Technical information — IP address, browser type and version, time zone, general location (country/region level, derived from IP address or device settings)
• Performance data — crash reports, error logs, and diagnostic information to help us improve the Services

INFORMATION FROM THIRD PARTIES:

• App store data — if you purchase a subscription, the relevant app store (Apple or Google) may provide us with transaction identifiers, subscription status, and purchase history (but not your full payment card details)
• Analytics data — aggregated usage information from analytics providers to help us understand how the Services are used
• Authentication — if you sign in using a third‑party service, we may receive basic profile information as permitted by that service and your settings

SPECIAL NOTE ABOUT PHOTOS:
Photos you take or upload are processed to detect ingredients and generate recipe suggestions. See Section 4 for details on how we handle your photos.

4. How We Process Photos and User Content

CAPTURE AND STORAGE:
• Photos remain on your device until you choose to upload them to use our ingredient detection features
• When uploaded, photos are transmitted securely (encrypted in transit) to our cloud infrastructure
• Photos and derived data are stored in secure, access‑controlled systems with encryption at rest

PROCESSING AND ANALYSIS:
• Uploaded photos (including pantry photos, fridge photos, and receipts) are processed using automated systems to detect ingredients, read product information, and generate recipe suggestions
• We use third‑party service providers to assist with image analysis and recognition
• We do not use your personal photos to train publicly available machine learning models

DERIVED DATA:
• From your photos, we may generate derived data such as: detected ingredient lists, nutritional estimates, expiration date reminders, and shopping list suggestions
• This derived data is associated with your account to personalise your experience

YOUR CONTROLS:
• You can delete individual photos or all photos through the App settings
• You can revoke camera permissions on your device at any time
• When you delete your account, your photos and derived data are deleted (subject to backup retention periods described in Section 11)

5. Email a Receipt to Your Pantry

Email a Receipt to Your Pantry is available to Pantry Pic subscribers. It lets you forward grocery receipts to a personal Pantry Pic email address so we can read the items and add them to your Digital Pantry after you review and confirm them.

YOUR PERSONAL RECEIPTS ADDRESS:
• When you turn the feature on, we generate a unique, randomly assigned inbound email address for your account (for example, u-xxxxx@receipts.pantrypic.app)
• Anyone who has this address can send mail to it, so keep it private and only use it to forward your own receipts
• You can turn the feature off at any time in Settings, which deactivates the address

WHAT WE RECEIVE:
• When you forward a receipt, we receive the email — the sender address, the subject line, the message body, and any PDF or image attachments
• Forwarded receipts can contain other people's personal information, such as a name, delivery address, or email address printed on an invoice
• You are responsible for the content you choose to forward, and you should only forward receipts you have the right to share — see our Terms & Conditions

HOW WE READ YOUR RECEIPTS:
• We use automated processing — our Pantry Pic Smart features — to read the email text, the text inside PDF attachments, and any photos of receipts, and to identify the grocery items
• To do this, we send the relevant receipt text and receipt images to trusted third‑party service providers we engage to carry out the processing on our behalf. These providers may process this data in other countries, including the United States — see Section 9
• We require these providers by contract to keep your information secure, to use it only to provide the processing service to us, and not to use it for their own purposes

WHAT WE STORE AND FOR HOW LONG:
• The original forwarded email and its attachments are kept in encrypted, access‑controlled storage and are automatically deleted within 30 days of being received
• The details we extract from a receipt — such as product names, categories, quantities, a retailer estimate, the sender address, and the subject line — are held as a temporary import and are automatically deleted within 30 days
• Items added to your Digital Pantry are kept as part of your pantry, under the normal pantry retention described in this Policy

YOUR CONTROLS:
• Review your imports and remove any items you do not want, or discard an import entirely
• Turn the feature off and deactivate your receipts address at any time in Settings
• When you delete your account, we delete your receipt imports and deactivate your receipts address, and any original emails still in temporary storage are removed within the 30‑day window above

6. Why We Collect and Use Your Information

We use your information for the following purposes:

TO PROVIDE THE SERVICES:
• Create and manage your account
• Detect ingredients from your photos and suggest recipes
• Manage your digital pantry and shopping lists
• Process your dietary preferences and cooking profiles
• Enable you to share recipes and content with others

TO IMPROVE AND PERSONALISE:
• Personalise recipe recommendations based on your preferences, past activity, and household needs
• Analyse usage patterns to improve features and fix issues
• Conduct research and development (using aggregated or anonymised data)
• Run A/B tests to optimise the user experience

TO COMMUNICATE WITH YOU:
• Send transactional messages (account verification, subscription confirmations, security alerts)
• Provide customer support
• Send service updates about changes to features or policies
• With your consent, send marketing communications about new features, offers, and content

TO ENSURE SAFETY AND COMPLIANCE:
• Detect and prevent fraud, abuse, and security threats
• Enforce our Terms & Conditions
• Comply with legal obligations (e.g., tax, accounting, consumer protection)
• Respond to legal requests and protect our rights

7. Legal Bases for Processing (For Users in the EEA/UK)

If you are located in the European Economic Area or United Kingdom, we rely on the following legal bases:

• Contract — processing necessary to provide the Services you requested (e.g., account management, ingredient detection, recipe suggestions)
• Legitimate interests — improving the Services, preventing fraud, analytics, and direct marketing to existing customers (balanced against your rights)
• Consent — marketing communications (where not covered by legitimate interests), push notifications, and processing of health‑related data such as dietary restrictions
• Legal obligation — tax, accounting, and regulatory compliance

You can withdraw consent at any time (see Section 12), but this does not affect the lawfulness of processing before withdrawal.

8. How We Share Your Information

We share your information with the following categories of recipients:

SERVICE PROVIDERS:
We engage third‑party companies to help us operate and improve the Services, including:
• Cloud hosting and infrastructure providers
• Image analysis and AI processing services
• Payment processors and subscription management platforms
• Analytics and performance monitoring services
• Customer support tools
• Email and communication service providers
• Trusted third‑party providers that carry out automated text and image processing for features such as Email a Receipt to Your Pantry and photo ingredient detection (which may process data in other countries, including the United States)

These providers act as data processors on our behalf and are contractually required to protect your information and use it only as we direct.

APP STORES:
Apple and Google process subscription payments and may act as independent data controllers for payment‑related data under their own privacy policies.

OTHER USERS:
If you use sharing features (e.g., sharing recipes), your shared content may be visible to other users, potentially including users located in other countries with different data protection laws.

LEGAL AND SAFETY:
We may disclose information if required or permitted by law, including:
• In response to valid legal process (subpoenas, court orders, government requests)
• To protect the safety, rights, or property of Apptractive Pty Ltd, our users, or others
• To detect, prevent, or address fraud, security, or technical issues

BUSINESS TRANSFERS:
In connection with a merger, acquisition, reorganisation, bankruptcy, or sale of assets, your information may be transferred to the successor entity, subject to this Policy.

WE DO NOT SELL YOUR PERSONAL INFORMATION for monetary consideration.

9. International Data Transfers

We operate globally, and your information may be transferred to and processed in countries other than your own, including countries that may not have data protection laws equivalent to those in your jurisdiction.

When we transfer personal information internationally, we implement appropriate safeguards, which may include:
• Transfers to countries recognised as providing adequate protection
• Standard contractual clauses approved by relevant authorities
• Other legally recognised transfer mechanisms

By using the Services, you acknowledge that your information may be transferred internationally as described in this Policy.

Some features rely on service providers located in other countries. For example, when you use Email a Receipt to Your Pantry or our photo ingredient detection, receipt and image content is processed on our behalf by trusted providers that may be located in other countries, including the United States. We remain accountable for how our service providers handle your information and require them by contract to protect it and to use it only to provide the service to us.

For users in the EEA/UK: We ensure that any transfers outside the EEA/UK comply with applicable data protection laws. You may request information about the safeguards we use by contacting us.

10. Data Security

We implement technical and organisational measures designed to protect your information, including:
• Encryption of data in transit and at rest
• Access controls and authentication requirements

However, no system is completely secure. While we strive to protect your information, we cannot guarantee absolute security. You are responsible for maintaining the confidentiality of your account credentials.

If you believe your account has been compromised, please contact us immediately at hello@pantrypic.com.

11. Data Retention

We retain your information only as long as necessary for the purposes described in this Policy or as required by law.

RETENTION PERIODS:

• Account data — retained while your account is active, plus a reasonable period afterward for legal and administrative purposes
• Photos and user content — retained until you delete them or delete your account
• Digital pantry data — retained until you delete items or delete your account
• Forwarded receipt emails — the original email and attachments are automatically deleted within 30 days of being received
• Receipt imports — the details extracted from a forwarded receipt are automatically deleted within 30 days; items you add to your Digital Pantry are kept under the pantry retention above
• Usage and analytics data — retained in identifiable form for up to 24 months, then aggregated or anonymised
• Transaction records — retained as required by tax and accounting laws
• Support communications — retained for up to 3 years after resolution

AFTER ACCOUNT DELETION:

• Your data is removed from active systems promptly
• Backup copies are purged within 90 days
• Some data may be retained longer if required by law or for legitimate business purposes (e.g., to resolve disputes)

12. Your Rights and Choices

Depending on your location, you may have certain rights regarding your personal information:

• Access — request a copy of your personal information
• Correction — request correction of inaccurate or incomplete information
• Deletion — request deletion of your personal information
• Restriction — request that we limit how we use your information
• Portability — request your data in a portable, machine‑readable format
• Objection — object to certain processing, including direct marketing
• Withdraw consent — withdraw consent where processing is based on consent

HOW TO EXERCISE YOUR RIGHTS:

• In the App — use privacy controls in Settings (where available)
• By email — contact us at hello@pantrypic.com
• Account deletion — available in App Settings or by emailing us

We will verify your identity before processing requests and respond within the timeframes required by applicable law (typically within 30 days, or as specified by local law).

Some requests may be limited by applicable law or our legitimate interests. We will explain any limitations when we respond.

For users in the EEA/UK: If you are not satisfied with our response, you have the right to lodge a complaint with your local data protection authority.

13. Cookies and Tracking

ON OUR WEBSITE:
We use cookies and similar technologies for:
• Essential functions — authentication, security, remembering your preferences
• Analytics — understanding how visitors use the Site to improve it
• Performance — monitoring site performance and fixing issues

Where required by law, we obtain your consent before placing non‑essential cookies. You can manage cookie preferences through our cookie banner or your browser settings.

IN OUR MOBILE APPS:
We use mobile analytics and diagnostic tools to understand app usage and improve performance. You can limit certain tracking:
• iOS: Settings → Privacy → Tracking
• Android: Settings → Privacy → Ads

14. Marketing Communications

TYPES OF COMMUNICATIONS:

• Transactional/Service — essential communications about your account, subscription, security, and service changes. These are not marketing and are necessary to provide the Services.
• Marketing — promotional messages about new features, offers, tips, and content. We only send marketing communications with your consent (where required) or under legitimate interests (for existing customers in some jurisdictions).

CHANNELS:

• Email — marketing emails include an unsubscribe link; click to opt out
• Push notifications — require your device permission; manage in App Settings or device settings
• In‑app messages — manage preferences in App Settings

YOUR CHOICES:

• Opt out of marketing emails via the unsubscribe link or App Settings
• Disable push notifications in your device settings
• Adjust in‑app message preferences in App Settings
• Contact us at hello@pantrypic.com to update your preferences

Opting out of marketing does not affect transactional or service communications.

15. Children's Privacy

The Services are not directed to children under 13 (or the applicable age of digital consent in your country, if higher). We do not knowingly collect personal information from children below this age.

If we learn that we have collected personal information from a child without appropriate parental consent, we will delete it promptly. If you believe we have collected information from a child, please contact us at hello@pantrypic.com.

16. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, the Services, or applicable law.

For material changes, we will provide notice by:
• Email (to the address associated with your account)
• In‑app notification
• Posting the updated Policy with a new "Last Updated" date

Your continued use of the Services after the effective date of a revised Policy constitutes acceptance. If you do not agree, please stop using the Services.

17. Contact Us

If you have questions about this Privacy Policy, want to exercise your rights, or have concerns about our data practices, please contact us:

Email: hello@pantrypic.com
Address: 3/79 O'Donnell Street, North Bondi NSW 2026, Australia

For users in the EEA/UK: Our contact details above serve as our point of contact for data protection matters.

---

REGIONAL PRIVACY DISCLOSURES

AUSTRALIA
This Policy is designed to comply with the Privacy Act 1988 (Cth) and the Australian Privacy Principles. You may access your personal information or make a complaint by contacting us.

EUROPEAN ECONOMIC AREA & UNITED KINGDOM
If you are in the EEA or UK, you have additional rights under the GDPR/UK GDPR, as described in Section 12. Our legal bases for processing are set out in Section 7. You have the right to lodge a complaint with your local supervisory authority.

UNITED STATES — CALIFORNIA
If you are a California resident, you may have rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA), including the right to know, delete, correct, and opt out. We do not sell your personal information as defined under these laws.

UNITED STATES — OTHER STATES
Residents of Virginia, Colorado, Connecticut, Utah, and other states with comprehensive privacy laws may have similar rights. Contact us to exercise your rights.

OTHER JURISDICTIONS
We comply with applicable data protection laws. If you have questions about your rights under local law, please contact us.
Privacy Policy for the Pantry Pic app and website | Pantry Pic | Pantry Pic