Last updated · 3 September 2026
Privacy policy
This policy explains how the OurPantry iPhone app and website handle personal information during the closed beta.
Who we are
OurPantry is operated by Tioluwani Kolawole, an independent developer in the United Kingdom, trading as OurPantry. For UK data-protection law, Tioluwani Kolawole is the data controller: the person who decides why and how OurPantry handles personal information.
OurPantry is currently a small, invitation-only beta for adults testing a household grocery app. Contact details are at the end of this policy.
What this policy covers
This policy covers the OurPantry iPhone application and this website (ourpantry.app). It does not cover the separate privacy practices of supermarkets, Apple, Google, or another service you choose to use outside OurPantry.
Information we handle
Account information
You sign in with Apple or Google through our authentication provider, Clerk. We receive your email address and, where your sign-in provider makes them available, your name and profile image. We never receive or store the password for your Apple or Google account.
Household and shopping information
We store the information needed to keep both members of a household in sync, including:
- your household name, invite code, membership, and which account owns the household;
- your planning settings, such as shopping cadence, household size, shopping method, market, currency, locale, and time zone;
- shopping lists and items, including quantity, unit, notes, category, and any estimated price;
- tracked regular products, their expected rhythm, last recorded purchase, and purchase history;
- completed shopping trips, including the date, optional store name, optional total, and who shopped or paid; and
- an optional monthly grocery budget.
Both household members can see and change shared lists, items, tracked products, shopping history, receipts, budget, and notes. Do not add anything you would not want the other household member to read.
Receipt photos
If you photograph a receipt, the image is uploaded to private storage bound to your household. It is not public. The other member of your household can see the household receipt record.
We send the image to Google Cloud Vision for text detection, then use the detected text to suggest a shop total. OurPantry does not currently build a product-level price history from receipt contents. Receipt capture is optional: you can enter a total yourself or skip it.
Notifications
If you enable restock reminders, we handle your reminder preference, delivery time, time zone, and an Expo push token for each signed-in device. You can turn reminders off in Settings or in iOS. Lock-screen text is kept generic and does not name a product, price, shop, or household member.
Optional product analytics
Analytics is off unless you switch it on. It is a separate choice, is not required to use the app, and can be withdrawn at any time in Settings.
If you opt in, we send a limited set of events to PostHog Cloud EU:
- setup, restock review, shopping, and receipt-capture actions, using coarse buckets instead of exact values where possible; and
- a user identifier, household identifier, market, platform, and app version.
We do not send product names, notes, prices, totals, receipt contents, email addresses, or names to PostHog. Session replay, automatic capture, and IP-based geolocation are disabled. Withdrawing analytics consent or signing out resets the analytics identity on that device.
Support messages
If you contact us, we receive the contact details and information in your message, plus any screenshots or diagnostics you choose to send. Please do not send passwords, payment-card details, or unrelated personal information.
Operational and security information
Our service providers create limited technical records needed to secure and operate the service. These can include IP address, device or browser type, app version, timestamps, authentication events, request records, and error details. We use them to investigate faults, prevent abuse, and keep the beta working, not for advertising.
This website
This website sets no cookies, runs no analytics, embeds no third-party content, and has no advertising or newsletter scripts. There is therefore no non-essential tracking to accept and no cookie banner.
Our website host and security provider may receive ordinary request data, such as your IP address, browser type, requested page, and request time, in order to deliver and protect the site.
Why we handle it
| Purpose | Information used | UK GDPR lawful basis |
|---|---|---|
| Creating your account and providing the shared household service | Account, household, and shopping information | Performance of our agreement with you |
| Reading a total from a receipt you choose to photograph | Receipt image and detected text | Performance of our agreement with you |
| Sending the restock reminders you request | Reminder settings, time zone, and push token | Performance of our agreement with you |
| Understanding whether the beta is useful | Limited product analytics | Your consent |
| Answering support requests and improving reliability | Support messages and operational records | Our legitimate interests in supporting and securing the service |
| Meeting a legal requirement or responding to a lawful request | Only the information required for that purpose | Legal obligation |
Where we rely on legitimate interests, we limit the information used and consider the effect on you. You can object as described under “Your rights”. We do not sell personal information, use it for behavioural advertising, or make decisions about you that have legal or similarly significant effects.
Who helps us run OurPantry
We share information only where it is needed to provide or protect the service, where you ask us to, or where the law requires it. The main services involved are:
| Service | What it does | What it handles |
|---|---|---|
| Clerk | Authentication and account management | Email, name, profile image, account identifiers, sign-in records |
| Convex | Application database, backend logic, and private receipt storage | Account identifiers, household and shopping data, receipt images |
| Google Cloud Vision | Detects text on a receipt you photograph | The receipt image submitted for detection |
| Expo | Delivers push notifications | Push token and generic notification content |
| PostHog Cloud EU | Optional product analytics | The limited, consent-gated events described above |
| Cloudflare | Website hosting, DNS, security, and, once enabled, email forwarding | Website request records and email routing information |
| Apple and Google | Sign-in method chosen by you | Sign-in request and the profile information you allow them to share |
Providers that process information for us are engaged under their service and data-protection terms. Apple and Google may also handle information for their own purposes under the privacy notice for the sign-in service you choose.
International transfers
PostHog analytics is configured for its European Union cloud region. Other providers may process information in the UK, the European Economic Area, the United States, or another country where they operate.
When personal information is transferred outside the UK, we rely on a safeguard recognised by UK law, such as UK adequacy regulations or approved contractual protections. You can ask us for more information about the safeguard relevant to your information.
How long we keep it
We use the following retention rules:
- account, household, and shopping information is kept while the account or shared household remains active;
- if one member deletes their account, shared household history remains for the other member and the deleted member is shown as “Former household member”;
- if the last member deletes their account, the household and its active data, including receipt records and images, are deleted;
- device push tokens are removed when they are no longer needed, including when you sign out or delete your account;
- support messages are normally deleted within 12 months after the issue is closed, unless they are needed for security or a legal requirement; and
- consented analytics and operational records are kept only while useful for the limited beta purpose, then deleted or anonymised. We review that need at least once a year.
Copies may remain temporarily in routine provider backups after active data is deleted. Backups are access-restricted, are not used for ordinary product activity, and are overwritten through each provider's backup cycle. We may keep information longer where the law requires it or where it is needed to establish, exercise, or defend a legal claim.
Your rights
Depending on where you live, data-protection law may give you the right to ask for a copy of your personal information; correct it; delete it; restrict or object to its use; receive information you supplied in a portable form; and withdraw consent. Withdrawing consent does not affect processing that happened before you withdrew it. We will honour these controls for all users where reasonably possible, even where local law does not require a particular right.
You can update shopping information, turn reminders or analytics off, and delete your account from inside the app. For another rights request, email us from the address connected to your OurPantry account where possible. We may ask for limited information to confirm the account is yours. We will respond without undue delay and normally within one month.
If you are unhappy with how we handle your information, please contact us first so we can investigate. You can also complain to the Information Commissioner's Office, the UK regulator, at ico.org.uk/make-a-complaint.
Deleting your account
Account deletion is available inside the app and is permanent. What is removed depends on whether another person remains in the shared household. The account deletion page explains both cases and the route to use if you cannot access the app.
Children
OurPantry is for adults running a household. You must be at least 18 to create an account or take part in the beta. We do not knowingly collect personal information from anyone under 18. If you believe a child has used OurPantry, please contact us so we can investigate and delete the account where appropriate.
Security
We use access controls, encrypted connections, private storage rules, and established service providers to protect personal information. No online service can guarantee absolute security. If we discover a breach that creates a risk to you, we will investigate it and notify affected people and the ICO where the law requires us to.
Changes to this policy
We will update this policy as the beta changes. The date at the top shows the latest revision. If a change materially affects how we use personal information, we will tell testers in the app or by email before it takes effect where practical.
Contact
Privacy questions and rights requests can be sent to support@ourpantry.app.