Nobody has asked me this yet. That is exactly why I want to write it down now, while it is still a choice I'm making and not an answer I'm giving because somebody got upset.
Here's the thing about a pantry list. It looks like the most boring data on earth. Beans, rice, a yogurt on its last day. But line the whole thing up and it says more than you'd think. How many people live in your house. Whether you cook or reheat. What you can't eat. What you couldn't afford this month. Whether there's a baby in the picture, a diet, a holiday coming. You never sat down to write a personal document. You just added milk.
So if I'm going to ask you to type your kitchen into my app, you should know where it lands.
What actually gets stored
Your email, so you have an account to come back to. Your items: names, quantities, expiration dates, and whatever you type in the notes. If you're in a shared household, the people in that household see the shared pantry, which is the entire point of a shared pantry.
That lives in Supabase, the database service running behind the app. It isn't on my laptop. I can't sit at my kitchen table and go browsing through your fridge.
What the AI sees, and only if you say yes
The first time you tap anything AI-powered, a screen comes up before a single thing gets sent anywhere. It says Google Gemini by name, and it lists exactly what goes over:
- Pantry items and quantities
- Dietary preferences and restrictions
- Meal history and saved recipes
- Household headcount and equipment
That's the list. It's that list because AI Chef can't hand you dinner for four people with a gas stove, a peanut allergy, and half a bag of rice unless it knows those four things.
Two things worth saying about that screen. First, you can say no. Tap "Not Now" and your pantry, your shopping list, and manual meal planning all keep working exactly the same. The AI parts just stay quiet. Second, it isn't a one-time trap. There's an AI & Privacy section in Settings with a switch, and you can shut it back off any day you want.
Those requests also don't go from your phone straight to Google. They pass through a server I run. That's mostly a boring engineering detail, but it does mean there's one door instead of one on every phone. What Google does with what it receives is covered by their policy, not mine, and I'm not going to stand here and pretend that part is mine to promise.
What never touches the app at all
Your card. I have never seen a card number, and the app has no way to show me one. Subscriptions run through Apple and Google, with RevenueCat keeping track of whether yours is active. When somebody subscribes, the thing I find out is that somebody subscribed.
The part that makes me look bad
Before launch, I put a session recording tool in the app. It's a completely normal thing to use. It replays how people move through the screens, and honestly it's how you discover that a button nobody ever presses is sitting in the wrong place.
Then I sat with it for a day and turned it off.
Not because it's evil. Because recording somebody's session is exactly the sort of thing you have to say out loud first, in the privacy policy and on the store listing, and I hadn't done that yet. Shipping it quietly and disclosing it later would have been backwards. The code is still in there, commented out, with a note to myself about what has to happen before it ever comes back.
And while I'm being thorough: the website you're reading this on does run analytics and a Facebook pixel. That's how I find out whether anything I post reaches a single human being. It's a different thing from your pantry, but I'd rather tell you than have you go find it yourself.
What I don't do
I don't sell it, trade it, or rent it out. Ask me and your account and everything in it gets deleted. support@pantrypulse.app, and it's me reading it.
There's no scandal behind this post. No angry review, no lawyer, nobody demanding answers. Just an app that quietly knows there are three cans of black beans in your cabinet, and the guy who built it figuring you're owed a straight account of where that goes.
If any of it ever changes, it gets its own post. Not a line buried in an update note.
D