Legal
Privacy policy
Last updated September 12, 2026
Shelfcook sees your kitchen, so it is built to keep as little of it as possible. This policy explains what we collect and why, the legal basis for each use, which companies process it for us and where, how long we keep it, and how to exercise your rights wherever you live.
1. Who is responsible
The data controller for the Shelfcook app and shelfcook.app is Shelfcook, Las Vegas, Nevada, United States. Privacy contact: support@shelfcook.app. Postal address: being set up; until it is published here, write to the email address above and we will answer by email or, on request, by post.
We do not sell personal information, we do not share it for cross-context behavioral advertising, and we do not use advertising identifiers or cross-app tracking. Policy version 2026-09-12.
2. The short version
- Photos of your kitchen are resized and stripped of location data on your phone, sent once to build your pantry, processed, and not stored. Nothing is kept and nothing is used to train anything.
- Your pantry, household profiles, grocery list, saved recipes, and cook log are stored in your account so they follow you between devices and so the app can remind you about expiry. Household data is readable only by members of that household.
- Subscriptions are billed by the App Store or Google Play. We never see a card number.
- News emails are opt-in only, and every one carries an unsubscribe link that works with one click.
- Website analytics are off until you say yes. A Global Privacy Control or Do Not Track signal keeps them off.
3. Camera and photos
When you add to your pantry by photo, the app resizes each shot, strips the EXIF metadata (including location) on your phone, and sends it once to our server function, which passes it to the AI provider to recognize the ingredients. The result is a list of ingredient names with confidence scores; that list is what you confirm and what lands in your pantry. The photo is processed and not stored on our servers or by the AI provider beyond the request, and it is never used to train anything. Photos can contain people, receipts, and addresses; this is why nothing is kept. When community posts arrive in a later release, photos you choose to attach to a post will live in a private bucket with signed links and be covered by an update to this policy.
4. What we collect, why, and on what basis
The legal bases below are the ones the EU and UK GDPR require us to name. Where the basis is consent, you can withdraw it at any time without affecting anything that happened before.
| Data | When | Why | Legal basis |
|---|---|---|---|
| Email address, display name, optional handle, avatar, sign-in identities (email link, Apple, Google) | You create an account | Sign you in, keep your data across devices | Performance of a contract (the terms) |
| Terms and privacy acceptance and age attestation, with the time and policy version | You create an account | Prove that consent and attestation were given | Legal obligation, legitimate interest in keeping records |
| Subscription status, plan, expiry, and the purchase platform's app user id (never your card number) | You subscribe through the App Store or Google Play | Unlock member features on every device and enforce the monthly caps | Performance of a contract |
| Household name, member profiles (name, allergens, diets, dislikes, portion size, kid flag) | You set up your household | Filter and scale every recipe for the people you cook for | Performance of a contract; where a profile describes a child or a dietary restriction, your explicit consent to use it for this purpose |
| Pantry items with quantity, unit, category, expiry, staple flag, and how they were added | You add to the pantry | Suggest dishes, keep the list, remind you about expiry | Performance of a contract |
| Recognized ingredient names and confidence scores from a scan, and a count of tokens used | You scan by photo | Build the confirm step and record usage against the monthly cap | Performance of a contract |
| Generated recipes, the filters you chose, a hash of your pantry, and token counts | You ask for dishes | Show the recipes, cache them for 24 hours so the same request is not paid for twice, record usage | Performance of a contract |
| Saved recipes, cook log entries, ratings, and notes | You save or cook a recipe | Keep what you liked and let the app suggest it again | Performance of a contract |
| Grocery list items and where each came from | You cook or add to the list | The list itself, and restocking checked items into the pantry | Performance of a contract |
| Push token, platform, and app version per device; notification switches and quiet hours | You allow notifications | Send only the pushes you asked for, never during quiet hours | Consent |
| Email, name if given, the page you signed up from, and the time you ticked the news box | You join the waitlist | Tell you when Shelfcook is in the stores and, only if you opted in, send news | Consent |
| Email, subject, and message | You contact support or make a privacy request | Answer you and keep a record of the request and its deadline | Legitimate interest in running support; legal obligation for rights requests |
| Product analytics events without personal data (screen viewed, feature used, plan tier) | You use the app | See which features are used and where people get stuck | Legitimate interest in improving the product; no identifiers beyond a random installation id |
| Crash reports (stack trace, device model, OS version, app version), with emails and tokens scrubbed | The app crashes | Fix the crash | Legitimate interest in keeping the app working |
| Pages viewed, referrer, country, device type on the website, without cookies | You allow analytics on shelfcook.app | Count visits and see which pages help | Consent |
| A keyed hash of your IP address, kept for 24 hours | You submit a public form or sign in | Stop abuse of the forms (rate limiting) | Legitimate interest in security |
5. Companies that process data for us
These providers act on our instructions under a data processing agreement. Where a provider is in the United States and you are in the EU, UK, or Switzerland, the transfer basis is listed. We check each provider's Data Privacy Framework (DPF) status on dataprivacyframework.gov and fall back to standard contractual clauses (SCCs) where a provider is not certified.
| Provider | What it does for us | Data it sees | Location and transfer basis |
|---|---|---|---|
| Supabase | Database, authentication, file storage, server functions | Account, household, pantry, recipes, lists, devices, contacts, support tickets, consent records, usage counters | Hosting region set at project creation (published here once confirmed); SCCs through the Supabase DPA |
| Vercel | Hosts shelfcook.app, the account pages, the admin screens, and the scheduled jobs | Request logs (IP, page, browser) for a short period | United States; DPA with SCCs |
| RevenueCat | Subscription status across devices | App user id, store receipt identifiers, subscription status | United States; DPF where certified, otherwise SCCs |
| Apple App Store, Google Play | Billing for subscriptions | Handled under Apple's and Google's own policies | Your store account's region |
| Resend | Sends account emails, support replies, and the news emails you opted into | Your email address and the message; for news, the opt-in time | United States; DPF |
| PostHog | Product analytics in the app and, after consent, on the website | Events without personal data: screen or page, feature used, plan tier, a random installation id | United States (US cloud); DPA with SCCs |
| Sentry | Crash reporting for the app | Stack traces, device model, OS and app version; emails and tokens are scrubbed before sending | United States; DPF |
| Our AI provider | Recognizes ingredients in a scan photo and writes the recipes for your pantry | The photo for one request only, then the pantry item names, your household's allergens and diets, and your filters; never your name or email | United States; DPA with SCCs; no retention beyond the request and no training on your data |
We do not use data brokers, and no processor may use your data for its own purposes.
6. How long we keep it
| Data | Kept for |
|---|---|
| Scan photos | Not stored. Processed and discarded within the request |
| Scan records (item count, tokens, cost), without any image | While the account exists |
| Generated recipe cache | 24 hours; a recipe you save or cook stays with your account |
| Account, household, pantry, recipes, lists, cook log | While the account exists. On deletion, everything is purged within 30 days |
| Terms acceptance and consent records | The life of the account or contact plus 3 years, as evidence that consent was given |
| Product analytics | 12 months |
| Crash reports | 90 days |
| Waitlist and news list | Until you unsubscribe or ask us to delete you. An unsubscribe is recorded and you come off the news list; only a new opt-in from you puts you back on it. Addresses that bounce or complain are blocked from news email |
| Support tickets and privacy requests | 3 years from closing, then deleted or anonymized |
| Rate-limit hashes | 24 hours |
| Admin audit log | 24 months |
| Deleted accounts | Purged within 30 days of the request, then confirmed by email |
7. Your rights, by where you live
Everyone can ask us to access, correct, export, or delete their personal information, and can object to or restrict a use of it, by the methods in section 8. We never discriminate against anyone for exercising a right. Regional details:
European Economic Area, United Kingdom, and Switzerland
You have the rights of access, rectification, erasure, restriction, portability, and objection, and the right to withdraw consent at any time. We answer within one month; if a request is complex we may extend by two further months and will tell you why. You can complain to your national supervisory authority (in the UK, the Information Commissioner's Office). Where we rely on legitimate interest we have balanced it against your rights; ask us for the assessment. We are assessing whether Article 27 of the GDPR requires us to appoint a representative in the EU and the UK; until one is named here, contact us directly at the address above.
California
As of the date of this policy, Shelfcook is below the thresholds that make the California Consumer Privacy Act apply. We still give California residents the same rights: to know what we collect, to delete it, to correct it, and to opt out of any sale or sharing, which we do not do. We answer within 45 days. Under the California Online Privacy Protection Act we disclose that we honor the Global Privacy Control signal and treat a Do Not Track signal the same way, as a decline of analytics.
Nevada
Under Nevada Revised Statutes Chapter 603A: we do not sell covered information as defined there. Nevada consumers may submit a verified request not to sell their covered information to support@shelfcook.app, our designated request address, and we respond within 60 days.
Canada
Under PIPEDA and provincial laws you can access and correct your personal information and withdraw consent. We respond within 30 days. You may complain to the Office of the Privacy Commissioner of Canada.
Brazil
Under the LGPD you have the rights of confirmation, access, correction, anonymization, portability, deletion, information about sharing, and revocation of consent. Requests go to the contact above, which also serves as our data protection contact for LGPD purposes.
Australia
You can request access to and correction of your personal information, and complain to the Office of the Australian Information Commissioner if you are unhappy with our answer.
Elsewhere
We apply the same rights and the 30-day response time unless your local law gives you more.
8. How to exercise a right
- In the app: Settings, then Data, then Export my data gives you a JSON file of everything in your account. Delete account, on the same screen, removes the account; the request is processed within 30 days and confirmed by email.
- On the site: sign in to your account for the same export and deletion, or use the contact form and choose Privacy request, or email support@shelfcook.app.
- By email: unsubscribe links in every news email work with one click, no sign-in needed.
We verify that a request comes from the address on the account or list before acting, usually by replying to it. An authorized agent may act for you with written permission. There is no charge unless requests are manifestly unfounded or excessive, in which case we may charge a reasonable fee or decline and explain why.
9. Cookies, analytics, and privacy signals
shelfcook.app sets no advertising cookies. Website analytics are not turned on. Your theme choice and your analytics answer are kept in your browser's local storage. If your browser sends a Global Privacy Control signal or Do Not Track, we treat that as a decline. Change your answer any time with Privacy choices in the footer. Signed-in account and admin sessions use an authentication cookie. The app contains no advertising SDKs; its product analytics and crash reporting carry no personal data.
10. Children
Shelfcook is not directed to children. You must be at least 13 to create an account, and in the European Economic Area and the United Kingdom at least 16, or the age your country has set for consenting to online services if it is lower. We do not knowingly collect personal information from anyone under those ages; if we learn that we have, we delete it. A parent can add a child as a member profile inside their own household; that profile holds a first name and dietary needs only, never an account.
11. Security
Data in transit is encrypted with TLS. Server data is stored with providers that encrypt at rest, and every table is protected by row-level access rules so that only you, your household members, or a signed-in administrator on an allow list with a verified authenticator can read your records. Administrator actions are logged. There are no passwords to leak: sign-in is by email link, Apple, or Google. Public forms are rate limited. Report a security concern to support@shelfcook.app; details are on the security page and in security.txt.
12. International transfers
Shelfcook operates from the United States, so if you are outside it your data is transferred here and to the processors in section 5. For transfers out of the EEA, UK, and Switzerland we rely on the EU-US Data Privacy Framework (with its UK and Swiss extensions) where the provider is certified, and on standard contractual clauses otherwise. Ask us for a copy of the clauses.
13. Changes
When this policy changes we update the date and version at the top. For material changes we also show a notice in the app and email everyone on the news list before the change takes effect. Earlier versions are available on request.
14. Contact
Shelfcook, Las Vegas, Nevada, United States. Email support@shelfcook.app.