Privacy Policy
PantryMonkey helps households track groceries: you send receipt photos, and it keeps an inventory, a shopping list and spending insights. This page explains what we collect, why, who processes it, and the choices you have.
What we collect
- Account details: your email address and a hashed password (web sign-up), or your Telegram user ID, username and first name (Telegram bot).
- Household data: household name and size, members, the items in your pantry, shopping list, consumption and waste history, and spending.
- Receipts: the photos you upload and the text we extract from them (store, date, items, prices).
- Technical data: IP address and request logs, kept briefly for security and debugging.
- Waitlist: if you join the waitlist, only your email address and the time you signed up.
How we use it
To run the service: reading receipts, estimating what you have and when it runs out, suggesting what to buy or cook, and sending the alerts you enable. We do not sell your data and we do not use it for advertising.
Who processes it
- Anthropic (Claude): receipt photos and the text of your pantry are sent to Anthropic's API to read receipts and suggest recipes. Under Anthropic's API terms this data is not used to train its models by default.
- Fly.io: hosts the app and stores the database and receipt photos on an encrypted volume.
- Telegram: if you use the bot, messages pass through Telegram under its own privacy policy.
Retention
We keep your data while your account exists. Receipt photos are kept so you can view them in the app; you can erase them at any time with "Reset everything", or delete your whole account. Server backups are kept for up to 30 days and then expire.
Your rights and choices
- Access and portability: Settings → "Export my data" downloads everything we hold about your household as JSON.
- Deletion: Settings → "Delete account" permanently removes your account and, if you are the sole owner, your household's data and receipt photos. If you share a household, contributions you made stay with that household.
- Correction: edit items directly in the app.
- Depending on where you live (for example the EU/UK under GDPR, or California under CCPA/CPRA) you may have further rights, including to object to or restrict processing and to complain to your data protection authority. Contact us to exercise them.
Security
Connections use HTTPS, passwords are hashed, sessions use HttpOnly cookies, and access to household data is limited to household members. No system is perfectly secure; tell us right away if you suspect a problem.
Children
PantryMonkey is not directed to children under 13 and we do not knowingly collect their data.
Changes and contact
If we change this policy in a material way we will update the date above and, where appropriate, tell you in the app or bot. Questions or requests: hello@pantrymonkey.com.