🔒 Privacy

Privacy Policy

We take your privacy seriously. Here's a plain-English explanation of exactly what data we collect and why.

Last Updated: July 2026
✓ Apple App Store (Nov 2025) ✓ Google Play (Apr 2026) ✓ GDPR ✓ CCPA ✓ COPPA

1. Who We Are

StillFresh ("we," "us," or "our") is the operator of the StillFresh mobile app (bundle ID: com.vivek-0217.stillfresh), available on the Apple App Store and Google Play Store.

If you have any questions about this policy, email us at [email protected].

2. What We Collect

2a. Information You Give Us

2b. Information Processed Automatically

2c. Photos & Camera

When you use the "Scan Receipt / Photo" feature, your image is uploaded over an encrypted TLS connection to a private, secure Supabase Storage bucket (grocery-scans). Our server-side Supabase Edge Function analyzes the photo for grocery items and immediately deletes the image from storage upon processing completion. Photos are not permanently stored on our servers unless you explicitly save an item photo, in which case its URL reference is stored in your private pantry item record accessible only to your account.

2d. What We Do NOT Collect

3. How We Use Your Data

We use your data only for these purposes:

🔑 API keys for AI providers (Gemini and OpenAI) are stored strictly as server-side secrets and are never bundled into the app binary. Your data is sent to AI providers only through secure Supabase edge functions.

4. Third-Party Services

StillFresh uses the following third-party services to operate:

Supabase

We use Supabase for backend database storage, authentication, encrypted file storage, and edge functions. Your pantry data is protected by Row Level Security (RLS). See: supabase.com/privacy

RevenueCat

We use RevenueCat to manage in-app subscriptions and entitlements. RevenueCat receives a pseudonymous user ID (your Supabase UUID), platform type, device locale, SDK version, and transaction history. It does not receive your payment card details or email address. See: revenuecat.com/privacy

AI Providers (Google Gemini & OpenAI)

Grocery photo scans and recipe prompts are processed by Google Gemini or OpenAI via our secure edge functions. Data sent to AI providers contains image content or grocery item names only; no user names, email addresses, or personal identifiers are included.

Pexels

We may query the Pexels API to display stock culinary images for recipes. Search queries consist solely of food dish titles and contain no user identity or personal information. See: pexels.com/privacy-policy

Apple & Google (Authentication & Payments)

Sign-In and subscription transactions are processed directly by Apple (iOS) or Google (Android) under their respective privacy policies. We do not receive payment card numbers or your raw password.

Expo Infrastructure

Expo routes push notifications to your device when enabled. See: expo.dev/privacy

⚠️ We do not use Firebase, Google Analytics, Meta/Facebook SDK, or any third-party ad-tracking SDKs.

5. In-App Purchases & Subscriptions

StillFresh offers a StillFresh Pro subscription (monthly or yearly). Purchases are processed entirely by Apple (on iOS) or Google (on Android) — we never handle your payment information directly.

Auto-Renewal Disclosure

Subscriptions automatically renew at the end of each billing period unless cancelled at least 24 hours before the renewal date. Your Apple ID or Google account will be charged within 24 hours prior to the end of the current period.

RevenueCat's Role

RevenueCat acts as a data processor for entitlement verification using your pseudonymous account ID.

How to Cancel

6. Data Retention

We keep your account data and pantry items for as long as your account is active. If you delete your account (via the in-app profile screen or by contacting support), all personal data, pantry items, recipes, and stored tokens are permanently deleted from our primary servers within 30 days.

To request account deletion by email, contact [email protected] with the subject "Delete My Account."

7. Children's Privacy (COPPA)

StillFresh is not directed to children under the age of 13 (or 16 in the EU/UK). We do not knowingly collect personal information from children. If you believe a minor has created an account, contact us at [email protected] for prompt deletion.

8. Your Rights (GDPR — EU / UK Residents)

If you reside in the EEA or UK, you have the following data rights:

Email [email protected] to exercise your rights. Requests are fulfilled within 30 days.

9. California Residents (CCPA / CPRA)

California residents have the right to Know, Delete, Correct, and Opt-Out of the sale/sharing of personal information. We do not sell or share personal information for cross-context behavioral advertising. Submit CCPA requests to [email protected].

10. Security

We implement robust technical protections including TLS encryption in transit, Row Level Security (RLS) policies in Supabase, server-side secret management for API keys, and JWT authentication tokens.

11. Changes to This Policy

We may update this Privacy Policy periodically. Material changes will be communicated via in-app notification or email.

12. Contact Us

Questions or requests? Contact:
📧 [email protected]