Last updated · 3 September 2026

Privacy policy

This policy explains how the OurPantry iPhone app and website handle personal information during the closed beta.

Who we are

OurPantry is operated by Tioluwani Kolawole, an independent developer in the United Kingdom, trading as OurPantry. For UK data-protection law, Tioluwani Kolawole is the data controller: the person who decides why and how OurPantry handles personal information.

OurPantry is currently a small, invitation-only beta for adults testing a household grocery app. Contact details are at the end of this policy.

What this policy covers

This policy covers the OurPantry iPhone application and this website (ourpantry.app). It does not cover the separate privacy practices of supermarkets, Apple, Google, or another service you choose to use outside OurPantry.

Information we handle

Account information

You sign in with Apple or Google through our authentication provider, Clerk. We receive your email address and, where your sign-in provider makes them available, your name and profile image. We never receive or store the password for your Apple or Google account.

Household and shopping information

We store the information needed to keep both members of a household in sync, including:

  • your household name, invite code, membership, and which account owns the household;
  • your planning settings, such as shopping cadence, household size, shopping method, market, currency, locale, and time zone;
  • shopping lists and items, including quantity, unit, notes, category, and any estimated price;
  • tracked regular products, their expected rhythm, last recorded purchase, and purchase history;
  • completed shopping trips, including the date, optional store name, optional total, and who shopped or paid; and
  • an optional monthly grocery budget.

Both household members can see and change shared lists, items, tracked products, shopping history, receipts, budget, and notes. Do not add anything you would not want the other household member to read.

Receipt photos

If you photograph a receipt, the image is uploaded to private storage bound to your household. It is not public. The other member of your household can see the household receipt record.

We send the image to Google Cloud Vision for text detection, then use the detected text to suggest a shop total. OurPantry does not currently build a product-level price history from receipt contents. Receipt capture is optional: you can enter a total yourself or skip it.

Notifications

If you enable restock reminders, we handle your reminder preference, delivery time, time zone, and an Expo push token for each signed-in device. You can turn reminders off in Settings or in iOS. Lock-screen text is kept generic and does not name a product, price, shop, or household member.

Optional product analytics

Analytics is off unless you switch it on. It is a separate choice, is not required to use the app, and can be withdrawn at any time in Settings.

If you opt in, we send a limited set of events to PostHog Cloud EU:

  • setup, restock review, shopping, and receipt-capture actions, using coarse buckets instead of exact values where possible; and
  • a user identifier, household identifier, market, platform, and app version.

We do not send product names, notes, prices, totals, receipt contents, email addresses, or names to PostHog. Session replay, automatic capture, and IP-based geolocation are disabled. Withdrawing analytics consent or signing out resets the analytics identity on that device.

Support messages

If you contact us, we receive the contact details and information in your message, plus any screenshots or diagnostics you choose to send. Please do not send passwords, payment-card details, or unrelated personal information.

Operational and security information

Our service providers create limited technical records needed to secure and operate the service. These can include IP address, device or browser type, app version, timestamps, authentication events, request records, and error details. We use them to investigate faults, prevent abuse, and keep the beta working, not for advertising.

This website

This website sets no cookies, runs no analytics, embeds no third-party content, and has no advertising or newsletter scripts. There is therefore no non-essential tracking to accept and no cookie banner.

Our website host and security provider may receive ordinary request data, such as your IP address, browser type, requested page, and request time, in order to deliver and protect the site.

Why we handle it

PurposeInformation usedUK GDPR lawful basis
Creating your account and providing the shared household serviceAccount, household, and shopping informationPerformance of our agreement with you
Reading a total from a receipt you choose to photographReceipt image and detected textPerformance of our agreement with you
Sending the restock reminders you requestReminder settings, time zone, and push tokenPerformance of our agreement with you
Understanding whether the beta is usefulLimited product analyticsYour consent
Answering support requests and improving reliabilitySupport messages and operational recordsOur legitimate interests in supporting and securing the service
Meeting a legal requirement or responding to a lawful requestOnly the information required for that purposeLegal obligation

Where we rely on legitimate interests, we limit the information used and consider the effect on you. You can object as described under “Your rights”. We do not sell personal information, use it for behavioural advertising, or make decisions about you that have legal or similarly significant effects.

Who helps us run OurPantry

We share information only where it is needed to provide or protect the service, where you ask us to, or where the law requires it. The main services involved are:

ServiceWhat it doesWhat it handles
ClerkAuthentication and account managementEmail, name, profile image, account identifiers, sign-in records
ConvexApplication database, backend logic, and private receipt storageAccount identifiers, household and shopping data, receipt images
Google Cloud VisionDetects text on a receipt you photographThe receipt image submitted for detection
ExpoDelivers push notificationsPush token and generic notification content
PostHog Cloud EUOptional product analyticsThe limited, consent-gated events described above
CloudflareWebsite hosting, DNS, security, and, once enabled, email forwardingWebsite request records and email routing information
Apple and GoogleSign-in method chosen by youSign-in request and the profile information you allow them to share

Providers that process information for us are engaged under their service and data-protection terms. Apple and Google may also handle information for their own purposes under the privacy notice for the sign-in service you choose.

International transfers

PostHog analytics is configured for its European Union cloud region. Other providers may process information in the UK, the European Economic Area, the United States, or another country where they operate.

When personal information is transferred outside the UK, we rely on a safeguard recognised by UK law, such as UK adequacy regulations or approved contractual protections. You can ask us for more information about the safeguard relevant to your information.

How long we keep it

We use the following retention rules:

  • account, household, and shopping information is kept while the account or shared household remains active;
  • if one member deletes their account, shared household history remains for the other member and the deleted member is shown as “Former household member”;
  • if the last member deletes their account, the household and its active data, including receipt records and images, are deleted;
  • device push tokens are removed when they are no longer needed, including when you sign out or delete your account;
  • support messages are normally deleted within 12 months after the issue is closed, unless they are needed for security or a legal requirement; and
  • consented analytics and operational records are kept only while useful for the limited beta purpose, then deleted or anonymised. We review that need at least once a year.

Copies may remain temporarily in routine provider backups after active data is deleted. Backups are access-restricted, are not used for ordinary product activity, and are overwritten through each provider's backup cycle. We may keep information longer where the law requires it or where it is needed to establish, exercise, or defend a legal claim.

Your rights

Depending on where you live, data-protection law may give you the right to ask for a copy of your personal information; correct it; delete it; restrict or object to its use; receive information you supplied in a portable form; and withdraw consent. Withdrawing consent does not affect processing that happened before you withdrew it. We will honour these controls for all users where reasonably possible, even where local law does not require a particular right.

You can update shopping information, turn reminders or analytics off, and delete your account from inside the app. For another rights request, email us from the address connected to your OurPantry account where possible. We may ask for limited information to confirm the account is yours. We will respond without undue delay and normally within one month.

If you are unhappy with how we handle your information, please contact us first so we can investigate. You can also complain to the Information Commissioner's Office, the UK regulator, at ico.org.uk/make-a-complaint.

Deleting your account

Account deletion is available inside the app and is permanent. What is removed depends on whether another person remains in the shared household. The account deletion page explains both cases and the route to use if you cannot access the app.

Children

OurPantry is for adults running a household. You must be at least 18 to create an account or take part in the beta. We do not knowingly collect personal information from anyone under 18. If you believe a child has used OurPantry, please contact us so we can investigate and delete the account where appropriate.

Security

We use access controls, encrypted connections, private storage rules, and established service providers to protect personal information. No online service can guarantee absolute security. If we discover a breach that creates a risk to you, we will investigate it and notify affected people and the ICO where the law requires us to.

Changes to this policy

We will update this policy as the beta changes. The date at the top shows the latest revision. If a change materially affects how we use personal information, we will tell testers in the app or by email before it takes effect where practical.

Contact

Privacy questions and rights requests can be sent to support@ourpantry.app.