Privacy policy
Last updated 2 August 2026
Pantrini keeps track of the food in your kitchen. This explains exactly what it stores, who else sees it, and how to get rid of it.
The short version
- We store your email address and the contents of your pantry. That is essentially all of it.
- We do not sell anything to anyone, and there is no advertising or tracking in the app.
- Card numbers never reach our servers. Stripe handles payments.
- Deleting your account deletes your data. Not archived, not anonymised, deleted.
- Barcodes you scan are looked up against Open Food Facts, which does not receive anything identifying you.
Who is responsible
Raúl da Costa Gomes is the data controller for the information described here. The registered address is Rua Dr. Teixeira Dias 29, 3090-495 Paião.
For anything in this policy, including exercising the rights below, write to [email protected].
What we collect
Your account
- Email address. It is how you sign in and how we send verification codes, password resets and pantry invitations.
- Display name. Whatever you choose. It is shown to people who share a pantry with you.
- Password. Stored only as a salted hash. We cannot read it, and neither can anyone who obtains the database.
- Preferences. Metric or imperial, and your language, so that emails arrive in the language you use.
If you sign in with Google, we receive your email address, your name and Google's confirmation that the address is verified. We do not receive your Google password, your contacts, your calendar or anything else, and Pantrini cannot act on your Google account.
Your pantry
- The pantries you create and their names.
- The items in them: product, quantity, unit, expiry date, category and any alert thresholds you set.
- Your shopping list, including anything you type by hand.
- Barcodes you scan, stored against the item so the next scan resolves faster.
- Who you invite to a shared pantry, and whether they can edit or only look.
Your subscription
We store a Stripe customer reference, the status of your subscription and the dates it runs between. We never see or store your card number, expiry date or security code. Those go directly to Stripe on a page hosted by Stripe, which is the reason payment happens in a browser rather than inside the app.
Technical records
Our servers keep short lived request logs containing IP addresses, for security and for diagnosing faults. They are not used to build any profile of you.
What we do not collect
- No advertising identifiers, and no advertising.
- No analytics or tracking software of any kind. The app contains no third party SDK that reports your behaviour.
- No location data.
- No contacts, photos or files. The camera is used only to read a barcode, the reading happens on your phone, and no image ever leaves the device.
Why we are allowed to hold it
| Information | Basis |
|---|---|
| Account and pantry data | Performing the contract with you. Without it there is no app. |
| Subscription records | Performing the contract, and legal obligations around tax and accounting. |
| Request logs | Our legitimate interest in keeping the service secure and working. |
Who else sees it
We do not sell data and we do not share it for anyone else's marketing. These companies process it on our behalf so the service can function:
| Who | What for | Where |
|---|---|---|
| Hetzner | Servers and database hosting | European Union |
| Cloudflare | Domain routing and protection against attacks | Global, EU entry points |
| Stripe | Payments and subscription management | Ireland and United States |
| Resend | Sending verification, reset and invitation emails | Ireland (eu-west-1) |
| Sign in with Google, only if you use it | United States |
Transfers outside the European Economic Area rely on the European Commission's standard contractual clauses.
We may also disclose information where the law requires it, which in practice means a valid order from a court or a competent authority.
Product lookups
When you scan a barcode or search for a product, that barcode or search term is sent to Open Food Facts, an open food database. The request carries no account identifier, no email address and nothing else about you, so Open Food Facts cannot connect a lookup to a person. Product information we receive back is cached on our servers so that repeated scans do not need another lookup.
How long we keep it
| What | Kept |
|---|---|
| Account and pantry data | Until you delete your account |
| Email verification codes | 24 hours, or until used |
| Alerts and notifications | Cleared automatically once resolved, and in any case after 30 days |
| Request logs | A short rolling window |
| Payment and invoice records | Held by Stripe for as long as tax and accounting law requires, typically several years |
Deleting your account deletes your data. Settings, then Delete account. Your pantries, items, shopping lists and alerts are removed from the database immediately. Backups roll over within 30 days. The one exception is the payment record Stripe is legally required to retain.
If you owned a pantry that other people were sharing, deleting your account removes that pantry for them too. It is worth telling them first.
Your rights
Under the GDPR you may:
- ask for a copy of what we hold about you;
- have anything inaccurate corrected, most of which you can do yourself in the app;
- have your data deleted, which the app does directly;
- ask for your data in a portable format;
- object to processing based on legitimate interests;
- withdraw consent where consent was the basis, without affecting anything done beforehand.
Write to [email protected] and we will respond within one month.
If you are not satisfied you can complain to your national data protection authority. In Portugal that is the Comissao Nacional de Proteccao de Dados (CNPD).
Security
- Everything travels over HTTPS.
- Passwords are stored as salted hashes, never in a readable form.
- Sign in tokens are short lived, and the app keeps the long lived one in the phone's secure storage rather than ordinary app storage, so a device backup does not contain a credential.
- Access to the production database is restricted to the operator.
No system is perfectly secure. If you believe you have found a vulnerability, please write to [email protected] before disclosing it publicly.
Children
Pantrini is not intended for children under 16. We do not knowingly create accounts for them. If you believe a child has an account, tell us and we will remove it.
Changes
When this policy changes the date at the top changes with it. If a change materially affects how your information is used we will tell you by email before it takes effect.