1. Who We Are
StillFresh ("we," "us," or "our") is the operator of the StillFresh mobile app (bundle ID:
com.vivek-0217.stillfresh), available on the Apple App Store and Google Play Store.
If you have any questions about this policy, email us at [email protected].
2. What We Collect
2a. Information You Give Us
- Account information — your email address, optional display name, and profile picture URL (if provided directly or via Apple/Google Sign-In).
- Authentication & Re-authentication tokens — if you sign in with Apple or Google, we receive identity tokens. Encrypted refresh tokens are stored securely to re-authenticate your identity if you request account deletion. We never receive or store your Apple ID password or Google password.
- Pantry items & AI Metadata — food item names, quantities, purchase dates, best-before dates, storage notes, item category classifications, estimated retail costs, and attached photo URLs.
- Recipes & Favorites — saved AI-generated recipes, ingredient lists, and custom recipe prompts.
2b. Information Processed Automatically
- Device & Regional data — device type, operating system, device language preference, and region code (used to route Apple/Google payments and calculate localized grocery cost estimates).
- Push notification metadata — Expo push notification tokens and scheduled reminder triggers so we can alert you before food expires.
- Usage data & Security counters — feature usage counters (tracked atomically server-side in our database to manage tier limits) and server-side security logs (such as temporary failed scan counters to protect against AI abuse).
2c. Photos & Camera
When you use the "Scan Receipt / Photo" feature, your image is uploaded over an encrypted TLS connection to a
private, secure Supabase Storage bucket (grocery-scans). Our server-side Supabase Edge Function
analyzes the photo for grocery items and immediately deletes the image from storage upon
processing completion. Photos are not permanently stored on our servers unless you explicitly save an item
photo, in which case its URL reference is stored in your private pantry item record accessible only to your
account.
2d. What We Do NOT Collect
- We do not collect your full real legal name unless you set it as your display name.
- We do not collect your precise GPS location.
- We do not collect financial or payment card information (this is handled entirely by Apple or Google).
- We do not use third-party advertising SDKs or sell your personal data to data brokers.
3. How We Use Your Data
We use your data only for these purposes:
- To create, authenticate, and maintain your account.
- To store and sync your pantry items and saved recipes across your devices.
- To run AI image analysis and generate recipe suggestions on your behalf via server-side edge functions.
- To send push notifications reminding you of upcoming expiry dates (only if notification permissions are granted).
- To verify your subscription status through RevenueCat.
- To calculate waste reduction statistics and localized estimated grocery savings.
- To prevent system abuse and safeguard our API infrastructure.
🔑 API keys for AI providers (Gemini and OpenAI) are stored strictly as server-side secrets and are never bundled into the app binary. Your data is sent to AI providers only through secure Supabase edge functions.
4. Third-Party Services
StillFresh uses the following third-party services to operate:
Supabase
We use Supabase for backend database storage, authentication, encrypted file storage, and edge functions. Your pantry data is protected by Row Level Security (RLS). See: supabase.com/privacy
RevenueCat
We use RevenueCat to manage in-app subscriptions and entitlements. RevenueCat receives a pseudonymous user ID (your Supabase UUID), platform type, device locale, SDK version, and transaction history. It does not receive your payment card details or email address. See: revenuecat.com/privacy
AI Providers (Google Gemini & OpenAI)
Grocery photo scans and recipe prompts are processed by Google Gemini or OpenAI via our secure edge functions. Data sent to AI providers contains image content or grocery item names only; no user names, email addresses, or personal identifiers are included.
Pexels
We may query the Pexels API to display stock culinary images for recipes. Search queries consist solely of food dish titles and contain no user identity or personal information. See: pexels.com/privacy-policy
Apple & Google (Authentication & Payments)
Sign-In and subscription transactions are processed directly by Apple (iOS) or Google (Android) under their respective privacy policies. We do not receive payment card numbers or your raw password.
Expo Infrastructure
Expo routes push notifications to your device when enabled. See: expo.dev/privacy
⚠️ We do not use Firebase, Google Analytics, Meta/Facebook SDK, or any third-party ad-tracking SDKs.
5. In-App Purchases & Subscriptions
StillFresh offers a StillFresh Pro subscription (monthly or yearly). Purchases are processed entirely by Apple (on iOS) or Google (on Android) — we never handle your payment information directly.
Auto-Renewal Disclosure
Subscriptions automatically renew at the end of each billing period unless cancelled at least 24 hours before the renewal date. Your Apple ID or Google account will be charged within 24 hours prior to the end of the current period.
RevenueCat's Role
RevenueCat acts as a data processor for entitlement verification using your pseudonymous account ID.
How to Cancel
- iOS: Settings → [your name] → Subscriptions → StillFresh → Cancel Subscription.
- Android: Google Play Store → Profile icon → Payments & subscriptions → Subscriptions → StillFresh → Cancel.
6. Data Retention
We keep your account data and pantry items for as long as your account is active. If you delete your account (via the in-app profile screen or by contacting support), all personal data, pantry items, recipes, and stored tokens are permanently deleted from our primary servers within 30 days.
To request account deletion by email, contact [email protected] with the subject "Delete My Account."
7. Children's Privacy (COPPA)
StillFresh is not directed to children under the age of 13 (or 16 in the EU/UK). We do not knowingly collect personal information from children. If you believe a minor has created an account, contact us at [email protected] for prompt deletion.
8. Your Rights (GDPR — EU / UK Residents)
If you reside in the EEA or UK, you have the following data rights:
- Access & Portability — request a machine-readable copy of your personal data by emailing support.
- Correction — request updates to inaccurate data.
- Erasure — delete your account and associated data ("right to be forgotten").
- Restriction & Objection — restrict or object to certain processing activities.
- Withdraw Consent — revoke push notification consent anytime via device settings.
Email [email protected] to exercise your rights. Requests are fulfilled within 30 days.
9. California Residents (CCPA / CPRA)
California residents have the right to Know, Delete, Correct, and Opt-Out of the sale/sharing of personal information. We do not sell or share personal information for cross-context behavioral advertising. Submit CCPA requests to [email protected].
10. Security
We implement robust technical protections including TLS encryption in transit, Row Level Security (RLS) policies in Supabase, server-side secret management for API keys, and JWT authentication tokens.
11. Changes to This Policy
We may update this Privacy Policy periodically. Material changes will be communicated via in-app notification or email.
12. Contact Us
Questions or requests? Contact:
📧 [email protected]