Privacy

Your pantry. Your data.

iGarde is designed to keep your shopping, your receipts, and your meal plan in your hands. This page explains, in plain English, what we collect, why, and the choices you have.

Effective 20 August 2026 UK / GDPR Version 1.8

The short version

1. Who we are

iGarde (“we”, “us”) is a UK-based pantry and meal-planning app for iPhone, published on the App Store, with our website at igarde.app. We are the data controller for any personal data you give us under the UK GDPR and the Data Protection Act 2018.

You can reach us at hello@igarde.app for any privacy question. Plain-text emails are fine; we don't need a form.

2. What we collect, and why

We try to collect the bare minimum to make the app work. The categories below are exhaustive for the consumer product — if we ever add new ones, we'll update this page first.

2.1 Account data required to sign in

You can use iGarde without signing in for the local pantry, manual entry and on-device receipt scan. “Snap your shelf” and the controlled Unified Intake queue require a signed-in account and resolved household so consent, quota, jobs and assets can be bound to the correct people. Visual processing then sends selected photos only as described in 2.4.

2.2 Pantry and preference data your content

This lives in a local database on your device, protected by the operating system's standard at-rest encryption (accessible only after you unlock the device). When you're signed in, the same rows replicate to our Supabase database so they appear on your other devices and to anyone else in your household. Pantry, meals, shopping list, receipts and receipt line items are scoped to the household; recipes and favourites are scoped to you.

Allergy and diet choices are stored only on your device and are used to flag ingredients and filter recipe suggestions. They are not synced to our servers or shared with another user. They remain until you change them, use Delete local data, or uninstall the app.

2.3 Receipts and receipt files sensitive

OCR is on-device. iGarde reads the receipt with Apple's Vision framework on your own device. Reading the receipt does not send the image to Apple or Anthropic. If you stay signed out, the scan, OCR and parsed items stay on your device.

When you are signed in, iGarde can store a captured receipt image privately in Supabase so the receipt and pantry can sync. When the relevant Unified Intake sources are enabled, you can also choose receipt photos or an image/PDF in the app, or continue an eligible image-only Share-menu handoff. Those selected files are normalised on your device and uploaded to the private intake-assets bucket only after you select and submit that route. They are scoped to the exact account, household and job, and access uses short-lived, single-object capabilities. If a Plus AI cleanup is available, the app separately requires a current receipt-text permission before the provider request can begin.

Anthropic receives receipt text only. With current receipt-text AI permission, an eligible Plus cleanup through our parse-receipt Edge Function sends the reconstructed OCR text — item lines, store name, prices and local matches — to Anthropic's Claude API in the United States to clean up and categorise product names. It does not send the receipt image, PDF, imported file, your email address or audio to Anthropic. The result is used for your Kitchen Inbox and household pantry, not advertising, sale or a global learning cache. If you decline, are offline, exceed a limit or the call fails, iGarde keeps the on-device result available.

Suggestions appear for review before they change the pantry during the initial controlled rollout. Receipt camera/photo evidence is deleted from iGarde storage within 30 days. Successful or cancelled imported image/PDF evidence is queued for deletion within 24 hours; a recoverable failed import can remain for up to 7 days so you can retry. Structured receipt rows and reviewed Kitchen Inbox results remain household records as described in sections 2.2 and 6.

2.4 Shelf photos and visual kitchen sweeps cloud processing

Visual intake works differently from receipt OCR. It requires a signed-in account and resolved household. After you grant the current visual-AI permission, the legacy “Snap your shelf” route sends up to three selected photos through our parse-shelf Edge Function to Anthropic's Claude API in the United States so it can identify visible food. When the controlled visual-sweep source is enabled for a signed-in household, you can select kitchen-area photos or a video of up to 60 seconds. Video frame selection happens on your device: iGarde uploads only up to 12 selected still frames, never the original video or its audio.

Legacy shelf photos are not retained in iGarde's database or storage. Unified visual-sweep photos and selected video frames are held privately only for the job: successful or cancelled evidence is queued for deletion within 24 hours, and recoverable failed evidence expires within 7 days. Anthropic's standard commercial API policy is separate from iGarde's storage: Anthropic says API inputs and outputs are normally deleted within 30 days, unless a different agreement applies or longer retention is required for usage-policy enforcement or law. Anthropic does not train its models on commercial API inputs or outputs by default.

Visual results always go to review during the initial rollout. A photo or frame can say that an item was seen; iGarde does not remove food merely because it was absent from an image.

2.5 Share-menu staging on-device first

When the iGarde Share Extension is installed and enabled for your account, you can share up to 12 supported receipt screenshots or other images from another app in one handoff. Use Update Kitchen's in-app file picker for a PDF. It first copies them into iGarde's protected App Group container on that device, bound to the account and household that enabled sharing. The extension itself does not upload the content or contact Anthropic.

Opening iGarde shows the pending handoff and lets you continue into Kitchen Inbox. If the route is eligible for AI cleanup and receipt-text permission is not current, iGarde asks before the provider request. A handoff is removed after import or automatically expires from local staging within 7 days. Signing in as a different account or moving to a different household cannot claim an older handoff.

2.6 Notifications optional

Expiry reminders are scheduled locally by the app on your device — they fire from your device's own clock. We do not register a remote push token and we do not run a push server; nothing about your notifications touches our servers or any push relay. You can revoke notification permission from your device settings at any time.

2.7 Operational logs

Our infrastructure providers keep short-lived request and error metadata so the service stays secure and available. In our current Supabase production plan, application-accessible logs are retained for up to 7 days. We do not deliberately log full request bodies, receipt contents or feedback messages. Provider edge logs can contain ordinary request metadata such as an IP address, path, response status and timestamp.

For abuse prevention, unauthenticated recipe-share attempts use a SHA-256-derived identifier made from the request IP address and the current UTC date. The raw IP is not written to our database by this mechanism, the daily date makes the identifier rotate, and expired rate-limit rows are purged by a six-hourly job after their short window. This is not used for advertising, cross-app tracking or device fingerprinting. Anthropic's separate retention for content sent to its API is described in 2.3 and 2.4.

2.8 What we do not collect

2.9 Product usage & operational diagnostics first-party

Optional product-usage events. This collection is off by default. If you enable it, the iOS app records a small set of feature events such as “app opened”, “receipt scanned” and “paywall viewed”. They use a random install ID rather than your account ID and never include pantry, receipt or recipe contents. They go only to our Supabase project. You can stop these events at any time with Settings › Share anonymous usage data; switching the setting off also drops product-usage events waiting on the device. Server rows are automatically deleted after 90 days. Because the random install ID deliberately has no account link, those rows cannot be selected for an account-specific export or erasure before they expire.

iOS operational diagnostics. Separately, the iOS app records minimal events needed to detect crashes and failed network operations: an event name, status and duration, app version, build number and OS version, plus limited technical details such as a request path/method, error description, exception reason or stack breadcrumb. We do not deliberately attach pantry, receipt or recipe contents. These operational rows are uploaded anonymously so a queued event cannot be attached to a different account after an account switch. They are automatically deleted after 90 days. They go only to our Supabase project under our legitimate interest in maintaining a reliable and secure service. The product-usage toggle does not disable these operational diagnostics.

Feedback and support. If you choose Send feedback, we collect the category, your message, an optional email address, whether you chose to include diagnostics, and the diagnostic fields shown on the form (app/build/iOS/device-model details, pending counts, sign-in state and last-active time). A report sent while signed in can be linked to that account. If delivery fails, the device records which account originated the report and retries it only while that same account is active; it is never attached to a later account. Feedback created while signed out remains anonymous. Linked reports appear in cloud export and are erased with the account. We also export and erase a historical anonymous report when its optional contact exactly matches the account email. All feedback is automatically deleted after 90 days. Delete local data clears reports still queued on that device.

Historical early-access setup form. Before launch, the former website setup form collected an email address, a free-text pantry description and its parsed pantry items, plus request metadata (user agent and a daily IP-derived hash, not the raw IP), onboarding status/notes and a setup code. The form has been retired. Any remaining submission is deleted after 90 days; an email match also includes it in cloud export and account deletion.

2.10 Permissions and system pickers

Each one is requested only when you first use the related feature, and you can revoke it any time in your device settings:

The system file picker and Share menu expose only the files you select or share; they do not grant broad file access. The app does not request location, microphone, contacts, calendar, reminders, health, motion or cross-app tracking permissions.

3. Legal bases (UK GDPR Art. 6)

You can choose Not now when permission is requested. If you grant it, you can stop future provider requests at any time in Settings › Privacy by withdrawing the receipt-text or visual permission; the server checks current permission again before provider work. You can also delete iGarde-held content from Settings or ask us for help. A provider request that has already started cannot be recalled; withdrawal does not undo processing lawfully completed before it, and remaining copies follow section 6's deletion periods.

4. Third-party processors

We use a small set of vendors to run the service. Each is bound by a Data Processing Agreement and processes data only on our instructions.

We do not use Google Analytics, Meta Pixel, TikTok Pixel, Firebase, Sentry, Mixpanel, Crashlytics, PostHog or any other third-party tracker or crash reporter. Optional product-usage events and iOS operational diagnostics go only to our own Supabase project as described in 2.9.

5. International transfers

Our primary infrastructure (Supabase, Vercel edge) is configured to host data in the European Economic Area. Anthropic processes API requests in the United States under Standard Contractual Clauses (UK Addendum) and equivalent safeguards. Apple's purchase and subscription systems operate on Apple's infrastructure under Apple's privacy terms; Apple Vision receipt OCR, Share-menu staging, video-frame selection and iGarde's local expiry notifications run on your device. Receipt AI transfers text only; selected visual photos and frames are the media sent to Anthropic. We will update this section if any of that changes.

6. How long we keep things

7. Your rights

Under UK GDPR you can:

8. Sharing recipes with other users

When you share a recipe via a share-code, the recipe payload (title, description, ingredients, steps) is stored in a publicly readable table indexed only by that code. Anyone with the code can import it. Don't put anything in a recipe you wouldn't want a stranger to see. Share-codes can be revoked from the recipe screen.

9. Children

iGarde is not directed at children under 13. We do not knowingly collect data from children. If you believe a child has signed up, email us and we'll delete the account.

10. Security

No system is perfect. If you find a vulnerability, please report it to security@igarde.app.

11. Storage and cookies

We do not use cookies for anything. Pantry data lives in the app's local database on your device, and the sign-in session is in Apple's Keychain. Our website sets no cookies and no tracking, advertising or analytics cookies, so no PECR consent banner is required.

If you used the old web app. Until August 2026, igarde.app also offered iGarde in the browser, which saved a local copy of your pantry on the device you used it on. That web app has been retired: igarde.app/web now sends you to the App Store, and nothing reads, syncs or uploads that browser-side copy any more. Its offline cache is deleted automatically the next time you open igarde.app. Anything else it saved stays on your own device, under your control, until you clear site data for igarde.app in your browser — we cannot see or reach it. Data held against your account on our servers is unaffected and is still covered by your rights in section 7.

12. Changes to this policy

We'll update this page when something material changes — a new processor, a new feature, a new region. The “Effective” date at the top always reflects the current version. Where applicable law requires advance notice or renewed consent, we will provide it through an available app, website or account-contact channel before the change applies.

Talk to us

iGarde — hello@igarde.app

For security reports — security@igarde.app

For data-protection requests, mention “GDPR” in the subject so we route it correctly.