OpenPantry
Privacy policy
No account, no ads, no analytics, no trackers. Your recipes live on your device and sync to your private iCloud.
Last updated 12 August 2026
The short version
OpenPantry has no account of its own — no ads, no analytics, no trackers, and nothing to sign up for. Your recipes live on your device and sync to your private iCloud. We send recipe URLs and photos you import to our extraction service so an AI can read them. We do not collect your name, email, or location.
The one sign-in in the app is optional: if you connect a Kroger account to send your shopping list to a cart, that sign-in happens on Kroger's own page and is kept on your device, never on our servers.
What we collect
- Recipes you save, import, or share. Stored on your device, mirrored to your private iCloud database via Apple CloudKit, and — for imports from public URLs and photos — added to a shared, anonymous recipe corpus that powers the in-app Explore tab.
- URLs and images you import. Sent to our extraction service (running on Render) and forwarded to Anthropic's Claude API to extract recipe text. URLs are kept only long enough to fulfil the import; uploaded photos are not stored after extraction.
- Audio from videos you import. If a video share has no caption recipe, our extraction service downloads the video's audio and sends it to Groq's Whisper API for transcription. The audio is discarded afterwards.
- Shared-recipe links. When you tap Share on a recipe, the recipe content is stored on our server under a short random ID so the recipient can view it. Anyone with the link can view the recipe. Links do not expire automatically — contact us to remove one.
- Grocery ordering (optional). If you connect Kroger, we send your ZIP code to look up nearby stores, your shopping-list ingredient names to search that store's catalogue, and the products you choose when you send them to your cart.
- IP addresses are logged briefly by our extraction service for rate-limiting (around 80 requests per minute per IP) and are not used for anything else.
What we don't collect
- No email address, name, password, or OpenPantry account — there is nothing to sign up for. The optional Kroger connection is the only sign-in, it is handled entirely by Kroger, and we never receive your Kroger password.
- No analytics SDKs, tracking pixels, advertising identifiers, or third-party telemetry.
- No location, contacts, calendar, microphone, or device data beyond what you explicitly hand to the app — a photo you pick, a link you paste.
Photos and camera
When you use Import from photo, the chosen image is JPEG-compressed on the device, sent to our extraction service, and forwarded to Anthropic's Claude API. The image is not stored after the recipe is extracted — only the resulting recipe text lands in your library. Photo library access is used solely to read the image you select; no other photos are accessed.
Take a photo launches the iOS camera, captures a single image at your direction, and treats it identically to a gallery import. We never access the camera in the background or without you pressing the shutter.
Connecting a Kroger account
Sending your shopping list to a Kroger cart is optional and off until you turn it on. When you do:
- You sign in on Kroger's own page, not in OpenPantry. We never see your Kroger email or password.
- The resulting access is stored on your device in the iOS Keychain and syncs to your other Apple devices through iCloud Keychain. We do not store it on our servers. It does pass through our service each time it is renewed — renewing it requires a secret that can only be held on a server — but it is used and discarded, never written down.
- We only ask Kroger for permission to add items to your cart. We do not request your Kroger profile, order history, payment methods, or loyalty data.
- We cannot place an order. Items are added to your cart; you review and check out in Kroger yourself.
- Disconnecting in Settings deletes the stored access from your device immediately.
Third parties our service uses
The OpenPantry app talks to these services on your behalf. Each has its own privacy policy:
- Anthropic (Claude API) — extracts recipes from URLs, photos, and video transcripts. anthropic.com/privacy
- Apple iCloud / CloudKit — syncs your library to your private iCloud database. apple.com/privacy
- Supabase — stores the shared anonymous recipe corpus and the short-link share storage. supabase.com/privacy
- Render — hosts our extraction service. render.com/privacy
- Groq — transcribes audio from shared video posts when needed. groq.com/privacy
- Kroger — looks up stores and products, and adds items to your cart, when you connect a Kroger account. kroger.com/privacy-policy
- Spoonacular — provides recipe suggestions in the Explore tab. spoonacular.com/food-api/terms
Your rights and choices
- Delete a recipe any time by swiping left on it in the Recipes tab, or with the red Delete Recipe button on its edit screen.
- Stop iCloud sync by signing out of iCloud or turning off iCloud Drive in iOS Settings. Local recipes remain on the device.
- Remove a shared-recipe link by emailing us the short ID at the end of the link — the part after
/r/. We will delete that link's record from our server. - Disconnect Kroger in Settings ▸ Groceries. That erases the stored sign-in from your device. You can also revoke OpenPantry's access from your Kroger account settings.
- Ask what we have on you by emailing the address below. Because we do not tie data to identifiers, requests of this kind are typically resolved by telling you we have nothing identifiable.
Children
OpenPantry is not directed at children under 13 and we do not knowingly collect any data from them. If you believe a child has provided data to us, contact the email below and we will delete it.
International users
Our services are operated from the United States. By using OpenPantry you understand your data may be processed in the U.S. If you are in the European Economic Area, the United Kingdom, or California, you retain all the rights afforded under applicable law — access, deletion, portability. We have no separate process because we collect nothing identifiable about you.
Changes and contact
We will update this page when the policy changes and bump the date at the top. Material changes will also be noted in the app.
Questions about privacy? Email [email protected]. This page mirrors the policy published at openpantry-proxy.onrender.com/privacy.