Overview
PantryManna ("we," "our," or "us") is a private-beta web application that helps households manage their food pantry and generate AI-powered recipe suggestions. This policy explains what data we collect, how we use it, and how we protect it.
This policy governs our use of: Google Sign-In (Firebase Authentication / OAuth 2.0), Google Gemini AI (recipe generation and pantry scanning), Google Firebase Firestore and Cloud Storage (data storage), Firebase Cloud Functions (serverless backend), Mixpanel (product analytics), and Pinterest (future "Save to Pinterest" feature, when enabled).
Our practices conform to the Google API Services User Data Policy, Google OAuth 2.0 Policies, the Pinterest Developer Guidelines, CCPA, and GDPR.
Data We Collect
Account Data (via Google Sign-In)
- Email address and display name
- Google Account UID (used as a unique persistent identifier)
We access Google user data only through the email and profile OAuth scopes. We do not request or access Gmail, Google Drive, Google Calendar, Google Contacts, or any other Google account data.
Pantry Data (User-Entered)
- Item names, quantities, units, categories, and expiration dates
- Barcode images or photos submitted for AI scanning
- Household membership data (if you join or create a shared household)
Recipe Data
- AI-generated recipe suggestions you save
- Saved recipe title, ingredients, and instructions
Usage and Analytics Data
- Page views and feature interactions (via Mixpanel)
- Session identifiers, event timestamps, device/browser type
- IP address (used for geolocation; not stored by us)
How We Use Your Data
- Authentication — verify your identity and maintain a secure session via Google Sign-In.
- Pantry Management — store and retrieve your pantry items and expiration data.
- AI Features — send pantry content and/or scanned images to Google Gemini to generate recipe suggestions and identify scanned items. Data sent to Gemini is used only to generate an immediate response.
- Household Sharing — allow household members to view and edit a shared pantry.
- Product Improvement — use anonymized, aggregated analytics (Mixpanel) to understand feature usage.
- Beta Communications — send important service announcements to beta users via email.
- Pinterest Integration (future) — if you choose "Save to Pinterest," recipe content you explicitly select will be passed to Pinterest on your behalf. No data is sent to Pinterest until you initiate this action.
We do not sell your data, use your data for advertising, use your data to train AI models outside of the session request, or share your data with any third party except as described in the "Data Sharing" section below.
Google API Services — Limited Use Disclosure
PantryManna's use and transfer of information received from Google APIs to any other application will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
- We use Google account data (email address and display name) only to authenticate users and personalize their in-app experience.
- We do not transfer Google user data to any third party except as necessary to provide or improve user-facing features of PantryManna.
- We do not use Google user data to serve advertisements.
- We do not allow humans to read Google user data except where (a) we first obtained affirmative consent, (b) it is necessary for security or fraud investigation, or (c) required by law.
- We do not use Google user data to determine creditworthiness or for lending purposes.
Data Sharing and Disclosure
Service Providers
- Google Firebase (Firestore, Authentication, Cloud Functions, Cloud Storage) — stores user data and runs our serverless backend. Governed by Google's Privacy Policy.
- Google Gemini API — receives pantry content and/or images to generate recipe suggestions. Data is not stored by PantryManna beyond your Firestore account. Governed by Google's Privacy Policy.
- Mixpanel — receives anonymized usage events (page views, feature clicks). No pantry items or recipe content are sent to Mixpanel. Governed by Mixpanel's Privacy Policy.
- Pinterest (future) — if you use "Save to Pinterest," recipe content you select will be shared with Pinterest via their API. This is a user-initiated action. Governed by Pinterest's Privacy Policy.
Legal Requirements
We may disclose your data if required by applicable law, court order, or governmental authority, or to protect the rights, property, or safety of PantryManna, our users, or the public.
No Sale of Data
We do not sell, rent, or trade your personal information to third parties for their own marketing or commercial purposes.
Pinterest API — Developer Guidelines Compliance
When PantryManna's Pinterest integration is live, it will comply with Pinterest Developer Guidelines: we will not use Pinterest API data for purposes beyond those described here; we will link Pins back to their Pinterest source; we will attribute content from Pinterest clearly; we will not circumvent Pinterest's consent mechanisms; we will not incentivize users to save Pins; and we do not permit use by children under 13.
Data Storage and Security
All user data is stored in Google Firebase Firestore (us-central1 region) and protected by Firebase security rules that restrict access to your account only. Security practices include:
- HTTPS/TLS encryption for all data in transit
- Firebase Authentication for secure sign-in — no passwords stored by PantryManna
- Firestore security rules preventing cross-user data access
- Gemini API calls routed through authenticated Cloud Functions — the API key is never exposed to the browser
- Role-based access for Firebase project administration
Data Retention and Deletion
- Pantry and recipe data — retained until you delete it within the app or request account deletion.
- Analytics data — aggregated and anonymized; retained for up to 24 months.
- Authentication data — retained until account deletion is completed.
- Images submitted for scanning — not stored by PantryManna; processed ephemerally by Gemini and discarded.
You can delete individual pantry items and recipes at any time within the app. To request full account deletion, contact us via the feedback form. We will complete deletion within 30 days of a verified request.
Your Privacy Rights
All Users
You have the right to access, correct, delete, or export your personal data. Contact us via the feedback form to exercise these rights.
California Residents (CCPA / CPRA)
You have the right to know what personal information we collect, the right to delete it, and the right to opt out of its sale. We do not sell personal information.
EEA, UK, and Swiss Residents (GDPR)
Our lawful basis for processing is contractual necessity. You also have the right to object to processing, restrict processing, and to lodge a complaint with your local data protection authority.
Cookies and Local Storage
PantryManna uses Firebase Authentication session cookies to maintain your login state and Mixpanel localStorage to persist anonymous analytics identifiers. We do not use advertising cookies, cross-site tracking cookies, or fingerprinting. You may clear local storage at any time through your browser settings.
Children's Privacy
PantryManna is not directed at children under the age of 13 (or 16 in the EU/UK). We do not knowingly collect personal data from children. In compliance with COPPA, we do not use Google Sign-In or any Google API Service for child-directed use. If you believe a child's data has been submitted, please contact us immediately.
International Data Transfers
PantryManna is operated from the United States. Your data is stored in Google Firebase's us-central1 region (Iowa, USA). For EEA/UK users, we rely on Google's Standard Contractual Clauses for the lawful transfer of personal data to the United States, as facilitated by Google Firebase.
Changes to This Policy
If we make material changes — particularly to how we use Google user data or integrate new third-party services — we will notify beta users by email at least 14 days before the changes take effect and prompt users to consent before their data is used in a new way.
Contact
For privacy questions, data access requests, or deletion requests:
- Feedback Form: https://forms.gle/bkkQi6RogzteDz87A
- App Homepage: https://pantrymanna.app
This Privacy Policy was last reviewed for compliance with Google API Services User Data Policy, Google OAuth 2.0 Policies, and Pinterest Developer Guidelines on March 11, 2026.