Privacy Policy
Last updated July 6, 2026
Pantry Deals ("we", "us") helps you track grocery spending and find savings by reading your receipts. This policy explains what we collect, why, who we share it with, and how to delete it. We designed the product to keep only what it needs: stores, products, and prices — not personal or identifying details beyond what's required to run your account.
Information we collect
- Account & sign-in. When you sign in (including with Facebook or other providers via our authentication provider, Clerk), we receive your email address and basic public profile so we can create and identify your account. We do not receive your Facebook password or friends list.
- Receipts you upload or forward. Receipt images/PDFs, and the data we extract from them: store name and address, ZIP code, purchase date, product names, quantities, prices, and item barcodes (GTIN).
- Preferences. Your ZIP code and the stores you choose to track, shopping lists and staples you create, recipes and meal plans you save, and any feedback you send us.
How we use it
To parse your receipts into a spending history, compare prices across stores, surface relevant deals near you, power shopping lists and meal plans, and (if enabled) send you a weekly summary email. We are not an advertising or rewards business, and we never sell personal or identifying information about you. We do license de-identified price data — facts about products and stores that are not linked to you — as described under De-identified price data we license below.
Service providers we share data with
We share the minimum necessary with vetted processors that operate on our behalf:
- Clerk — authentication (your email and sign-in identity).
- Google (Gemini API) — reads your uploaded receipt images/text to extract line items; processes recipe text and meal-plan inputs.
- Resend — sends our outbound email and powers the forward-your-receipt inbound address.
- Amazon Web Services — stores your receipt files.
- Kroger — looks up product details from barcodes (no account data sent).
- Flipp — retrieves local deals using your ZIP code.
Sensitive details on receipts
When your receipt contains sensitive details — such as payment-card numbers, loyalty or membership numbers, the receipt's barcode, or personal contact information — we automatically black them out in the copy we store and delete the unredacted original from our storage. We read your receipt to extract its line items first, so the store, product, and price data we use is unaffected.
This redaction is automated and best-effort: it may not catch every instance, especially on hard-to-read or unusually formatted receipts. To read your receipt in the first place, the original image or PDF is processed by our parsing provider (Google Gemini); afterward, only the redacted copy is kept in our systems.
Separately, we strip embedded metadata — such as EXIF and GPS location tags — from every receipt photo when you upload it, before it is stored. This happens whether or not anything on the photo is later blacked out, so a stored photo can't reveal where it was taken.
Data retention
We keep your data while your account is active. You can delete individual receipts, staples, and recipes at any time inside the app, or delete your entire account and all associated data (see Data Deletion). After a full deletion, residual copies in encrypted backups are purged within 30 days.
We also retain de-identified price and product information that cannot reasonably be tied back to you. Because it is not personal information, it is not removed when you delete your account — see De-identified price data we license for exactly what it contains and how we use it.
De-identified price data we license
Grocery prices are facts about a store, not about you. From your receipts we build a de-identified dataset of price observations. Each observation is limited to a product, its size and category, the store and ZIP code, the price, and the date — with no name, email, account ID, or receipt grouping, and nothing that identifies you or ties observations back to a single shopper or shopping trip.
We may license this de-identified data — both individual price observations and aggregate statistics built from them (for example, the median price of a product at a chain in a ZIP code over time) — to third parties such as retailers, researchers, and market analysts. We do not attempt to re-identify this data, and we contractually require anyone we share it with not to attempt to re-identify it either. We never license your name, contact information, account, receipt images, or the grouping of purchases that make up a shopping trip.
Deleting your account stops us from collecting new data about you. Because the de-identified observations already in this dataset carry no link to you, they are not personal information and are not deleted.
Your choices & rights
You can access, correct, or delete your data. Account holders manage most of this directly in the app; for anything else — including requests from people who can no longer sign in — use the request form. Depending on where you live, you may have additional rights under laws such as the GDPR or CCPA.
Security
Data is encrypted in transit, access is restricted to what each service needs, and receipt files are stored in access-controlled object storage. No system is perfectly secure, but we work to protect your information.
Children
Pantry Deals is not directed to children under 13 (or the minimum age of digital consent in your country), and we do not knowingly collect their data.
Changes
We may update this policy; we'll revise the "Last updated" date above and, for material changes, notify you in the app or by email.
Contact
Questions or privacy requests? Use our request form and we'll respond.
