Legal information

Privacy Policy

Effective date: June 23, 2026.

1. Data we process

Pantrio49 may process the following categories of data:

2. Why we use data

3. Third-party providers

The service may use Supabase for authentication and PostgreSQL, Railway for backend hosting, Firebase for analytics, Crashlytics and App Check, OpenAI for AI features, Google Play for subscription billing, Telegram for private developer notifications, and Resend for OTP and service emails. Only the data required for each function is transferred.

Google Play processes subscription payments. Pantrio49 receives and stores the purchase metadata needed to verify, activate, restore, expire, and protect subscription access.

AI requests may contain products and food preferences entered by the user. Receipt images or PDFs and product-package images selected by the user may be sent to the Pantrio49 backend and OpenAI for recognition. Do not upload unrelated personal documents or enter unrelated personal information.

When you use the promotion map, location coordinates or a derived map area may be sent to the Pantrio49 backend and map or store-data providers such as OpenStreetMap/Overpass solely to find nearby stores and promotions.

4. Retention

Active data is kept while the account exists or while it is needed for a selected feature. Location data is used for the current promotion-map request; short-lived caches or technical logs may retain coordinates or a rounded map area only as needed to operate, diagnose, and protect the service. Original receipt and package files are used for recognition and are not retained by Pantrio49 after the request is completed. Recognized product, store, date, and price data may be saved when the user confirms it. Google Play purchase records may be retained as needed to manage subscription access, resolve billing disputes, meet legal obligations, and prevent fraud. Technical logs and abuse-prevention data may be retained longer when required for security. Processed deletion requests and error reports may be anonymized.

5. Shared pantries

After account deletion, membership ends. Actions in a shared activity log may remain in anonymized form so other members do not lose the integrity of the pantry history.

6. Your rights

The app provides data export and account deletion. When you cannot access the app, use the public deletion form. Email is verified first, followed by a separate final confirmation.

7. Security

Application data is accessed through the backend with token, role, and pantry-permission checks. No information system can guarantee absolute security.

8. Contact and updates

Send privacy questions to [email protected]. This policy may be updated when features, providers, or legal requirements change.