Privacy Policy

Effective date: October 8, 2026

This policy explains what information the Cupboard Chef iOS app ("Cupboard Chef", "we", "us") collects, how we use it, who we share it with, and the choices you have. We've tried to keep it short and in plain English. If you have any questions, email support@getcupboardchef.com.

The short version

Using the app without an account

Cupboard Chef works without signing in. In that case your pantry items, shopping list, saved recipes and settings are stored on your device and are not sent to our servers. A few features still need to contact other services when you use them; these are described below (barcode scanning, store aisle lookup and crash reports). AI meal ideas require an account.

Accounts

Creating an account is optional. You can sign up with an email address and password (we email you one-time codes to verify your address and sign in) or with Sign in with Apple. If you use Sign in with Apple and choose to hide your email, we receive an Apple relay address instead of your real one.

For your account we collect:

Accounts are managed by Supabase, our backend, authentication and database provider. Passwords are handled by Supabase's authentication service and are stored only in hashed form; we never see your password.

Sync, backup and household sharing

When you're signed in, the app backs up and syncs the following to our Supabase database so it's available on your other devices and to household members you invite:

If you invite people to your household (or join someone else's), all members can see and edit the shared pantry, shopping list and staples, and can see each other's display names. Your saved recipes, ratings, cooking history, food log and preferences stay private to you. Only share invite codes with people you trust.

The numbers on the Your Stats page (such as meals cooked, food wasted, streaks and badges) are calculated on your device from the data above.

Please note that diet and allergy preferences may reveal information about your health. We use them only to tailor recipes for you and never for advertising.

AI meal ideas and recipes

When you ask for meal ideas or a recipe, the app sends the following to our server:

Our server uses Anthropic's Claude API to generate the recipes and sends them back to the app. Anthropic processes this information as our service provider under its commercial terms. We do not use your data to train AI models, and under those terms Anthropic does not use it to train its models either. This information is only sent when you request meal ideas or a recipe.

To prevent abuse and keep costs fair, we keep a count of how many AI requests each account makes per day.

AI-generated recipes may contain mistakes. Always check ingredients against your own allergies and dietary needs, and use normal food-safety judgement.

Profile photo (optional)

If you add a profile photo, the app shrinks it on your device and stores it with our backend provider (Supabase). It's shown in the app on your profile, and is available at a hard-to-guess web link so the app can display it. Changing or removing it deletes the old photo, and deleting your account deletes it too. We only use photo library or camera access when you choose to pick or take a photo.

Subscriptions (Cupboard Chef Pro)

If you subscribe to Cupboard Chef Pro, the purchase is made through Apple. We never see your payment details. We use RevenueCat, a subscription service, to confirm purchases with Apple: RevenueCat receives your Cupboard Chef account ID and the details of your App Store purchases (such as the plan, price, and when it renews or ends), and our server stores whether your Pro membership is active. We also keep a count of when you last used the free plan's weekly meal ideas and recipe.

Invite codes. If you redeem a Cupboard Chef invite code (for example, as a beta tester), we record which account used which code and when, so we can give you complimentary Pro. The Cupboard Chef team can see the email address of accounts that redeemed their codes.

Barcode scanning

When you scan a barcode, the camera is used only to read it, and this happens entirely on your device. No photos or video are taken, stored or uploaded while scanning. The barcode number is then looked up in Open Food Facts, a public product database, to fill in the product name and details. Open Food Facts receives the barcode number and standard connection information (such as your IP address) as part of that request.

Store aisle lookup (optional)

If you choose a Kroger-family store for your shopping list:

We don't send your name, email or account information to Kroger. If you don't pick a Kroger-family store, nothing is sent to Kroger.

Crash and error reports

We use Sentry to receive crash and error reports so we can find and fix bugs. These reports include technical information such as your device model, iOS version, app version and stack traces (the part of the code where the problem happened). We don't intentionally include your pantry contents or other personal content in these reports.

Notifications

Expiry reminders and cooking timers are scheduled locally on your device. We don't use these notifications to send marketing messages.

Email

We send transactional emails only, such as sign-in and verification codes. These are delivered through Resend, our email delivery provider. We don't send marketing email.

What we don't do

Who we share data with

We share data only with the service providers described above, and only for the purposes described:

We may also disclose information if required by law, or to protect the rights, safety and security of our users or the service.

Data retention and deletion

We keep your account data for as long as your account exists. You can delete your account at any time in the app under Profile → Delete Account. This permanently deletes your account and the data synced to it. If you're part of a household, the shared household data (pantry, shopping list and staples) stays with the remaining members.

Data stored on your device can be removed by deleting the app. Crash reports are kept by Sentry for a limited period and then deleted automatically.

If you'd like a copy of your data, want something corrected or deleted, or can't access the app, email us at support@getcupboardchef.com and we'll help. Depending on where you live, you may have additional rights under local law, and we'll honor those requests.

Children

Cupboard Chef is not directed to children under 13, and we don't knowingly collect personal information from them. If you believe a child has given us personal information, contact us and we'll delete it.

Security

Data is sent over encrypted connections (HTTPS). Synced data is stored with Supabase, and access is restricted so that only you and your household members can read your data. No system is perfectly secure, but we work to protect your information and limit what we collect.

Changes to this policy

We may update this policy from time to time. When we do, we'll change the effective date at the top of this page, and for significant changes we'll let you know in the app.

Contact

Questions or requests about privacy? Email support@getcupboardchef.com.