Privacy Notice
Last updated: 11 August 2026
This notice explains how Pantry Forge ("Pantry Forge", "we", "us") handles your personal data when you use our meal-creation service. Pantry Forge is the data controller for the personal data described here: we decide what data is collected and why, and we are responsible for looking after it.
Personal data we collect
- Account data — name or display name, email address, and login credentials (passwords are stored only as salted hashes; if you sign in with Google we receive your basic profile and email).
- Ingredient photographs — the images you upload for analysis, and the ingredients detected in them.
- Health preferences you choose to enter — flagged conditions (for example high blood pressure or diabetes) and free-text allergy notes. This is sensitive health information; it is entirely optional and you can clear it at any time.
- Recipe and usage data — recipes generated and saved, prompts and notes you add, and basic product analytics such as feature usage and error logs.
- Referral and membership data — your referral code, referrals made, account credit, plan, and subscription status.
- Technical data — IP address, device and browser identifiers, and security logs.
We do not collect or store your card details. Payment data is collected directly by our Merchant of Record, Paddle, under its own privacy notice.
Why we use it, and our legal basis
- Creating and managing your account — to provide the service you asked for (performance of our contract with you).
- Analysing your photos and generating recipes — performance of our contract.
- Tailoring Healthy Hints to your health conditions and allergies — your explicit consent, given when you enter these details. You can withdraw it at any time by clearing them in your health profile.
- Managing memberships, referrals, and credit — performance of our contract and compliance with legal obligations such as tax and accounting.
- Security, fraud and abuse prevention, and service improvement — our legitimate interests in running a safe, reliable product.
- Service and marketing emails — performance of our contract for essential messages, and consent for optional marketing (unsubscribe at any time).
Who we share data with
- Service providers and subprocessors — cloud hosting and database providers, AI model providers that process your ingredient photos and health preferences to generate recipes and hints, email delivery, and analytics or error-monitoring tools. They act on our instructions under contract.
- Merchant of Record — Paddle, for the sale of memberships, subscription management, payments, tax compliance, invoicing, and billing support.
- Professional advisers — legal, accounting, and audit advisers where needed.
- Authorities — where we are required to disclose data by law or to protect our rights or someone's safety.
We do not sell your personal data.
International transfers
Our providers may process data outside your country, including outside the UK and EEA. Where that happens we rely on appropriate safeguards such as adequacy decisions or Standard Contractual Clauses.
How long we keep it
We keep account, membership, and referral data for as long as your account is active and for a limited period afterwards to meet legal, tax, and accounting obligations. Ingredient photographs are kept only as long as needed to generate and display your recipes, then deleted or anonymised. Saved recipes and health preferences remain until you delete them or close your account. Security and billing records are retained for the periods required by law, after which data is deleted or anonymised.
Your rights
Depending on where you live, you have the right to access your data, correct it, delete it, restrict or object to processing, receive a portable copy, and withdraw consent (including for health preferences) at any time. You can also opt out of marketing messages. To exercise any right, contact us through the support link in the app — we respond within one month. If you are in the UK or EEA, you can also complain to your local data protection supervisory authority.
Security
We use appropriate technical and organisational measures to protect your data, including encryption in transit, encryption at rest with our hosting provider, row-level access controls so users can only reach their own records, hashed passwords, and least-privilege access for our systems. No service can be perfectly secure, but we work to keep your data safe and to notify you and the relevant authority if a breach affects you.
Cookies and similar technologies
We use essential cookies and local storage to keep you signed in and to remember basic preferences — these are required for the app to work. We may use limited analytics cookies to understand feature usage, and we do not use advertising cookies. You can clear or block cookies in your browser settings, though signing in will not work without the essential ones.
Changes and contact
We will update this notice as our service changes and will highlight material updates in the app. For any privacy question or request, contact Pantry Forge through the support link in the app.