Privacy Policy
Last updated: February 12, 2026
Introduction
Welcome to Pantrimo, an AI-powered recipe platform designed to help you create, organize, and share personalized recipes and meal plans. We are committed to protecting your privacy and handling your personal data with care and transparency. This Privacy Policy explains how we collect, use, share, and protect your information when you use our service. By using Pantrimo, you agree to the collection and use of information in accordance with this policy.
Data Collection
We collect the following types of information:
- Account Information: Email address, display name, and password (encrypted) when you create an account
- Content You Create: Recipes, meal plans, shopping lists, pantry items, dietary preferences, and allergen profiles
- Usage Data: How you interact with our service, including features used, recipes viewed, and AI generation requests
- Technical Data: IP address, browser type, device information, and cookies for authentication and service functionality
- Legal Basis: We process your data based on your consent (provided during signup), our legitimate interest in providing and improving our service, and to fulfill our contract with you
How We Use Your Data
We use your information to:
- Provide Our Service: Enable you to create recipes, meal plans, shopping lists, and use AI-powered features
- Personalization: Customize recipe recommendations based on your dietary preferences, allergen profile, and cooking history
- Communication: Send you service-related emails, respond to your inquiries, and provide customer support
- Service Improvement: Analyze usage patterns to improve our AI models, fix bugs, and develop new features
- Safety and Compliance: Detect and prevent fraud, abuse, and security issues, and comply with legal obligations
Data Sharing
We may share your information with the following third parties:
- Service Providers: We use Supabase for database hosting and authentication, which may process your data to provide infrastructure services
- Analytics Provider (PostHog): We use PostHog Cloud for limited product analytics (for example page views, referral/UTM attribution, CTA clicks, and sign-up funnel events). We do not send recipe text, meal plans, shopping lists, pantry contents, or dietary/allergen profile content to PostHog
- AI Providers: Recipe generation and meal planning requests are sent to Google's Gemini AI service. We do not share personally identifiable information with AI providers
- Legal Requirements: We may disclose your information if required by law, court order, or to protect our rights, property, or safety
- Data Protection: All data transfers to third parties are protected using encryption (HTTPS/TLS) and governed by strict data processing agreements
- No Selling: We never sell your personal information to third parties for marketing purposes
Cookies and Tracking
We use cookies and similar technologies to:
- Essential Cookies: Authentication cookies (Supabase session tokens) that are strictly necessary for the service to function. These cannot be disabled
- Functional Cookies: Store your preferences and settings to improve your experience
- Analytics: We use PostHog analytics to measure page views, referral attribution, CTA clicks, and sign-up funnel events. Analytics are configured for manual event capture only (no broad auto-capture). We identify signed-in users in analytics by internal user ID only
- Sensitive Content: Recipe content, meal plans, pantry data, dietary preferences, and allergen profile content remain in Pantrimo systems and are not sent to PostHog analytics
- Analytics Control: You can block or clear browser storage/cookies in your browser settings. This may reduce analytics functionality and attribution accuracy
- Cookie Management: You can control cookies through your browser settings, but disabling essential cookies will prevent you from using the service
Your Rights
You have the following rights regarding your personal data:
- Right to Access: Request a copy of all personal data we hold about you by using the "Export My Data" button in your Profile settings
- Right to Correction: Update or correct your account information, preferences, and content directly through the application
- Right to Deletion: Request deletion of your account and all associated data through the "Delete My Account" option in Profile settings. Account deletion includes a 30-day grace period during which you can recover your account by simply logging in again
- Right to Data Portability: Download your data in JSON format using the data export feature
- Right to Withdraw Consent: You can withdraw consent at any time by deleting your account
- How to Exercise Rights: Most rights can be exercised directly through your Profile settings. For other requests, contact privacy@pantrimo.com
California Privacy Rights (CCPA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):
- Right to Know: You have the right to request that we disclose what personal information we collect, use, disclose, and sell about you
- Right to Delete: You have the right to request deletion of your personal information, subject to certain exceptions
- Right to Opt-Out of Sale: We do not sell your personal information to third parties. If this changes in the future, we will provide a clear "Do Not Sell My Personal Information" link
- Right to Non-Discrimination: We will not discriminate against you for exercising any of your CCPA rights
- Categories of Personal Information: We collect identifiers (email, name), commercial information (recipe usage), internet activity (feature usage), and inferences (dietary preferences)
- Business Purposes: We use your data to provide our service, improve features, ensure security, and comply with legal obligations
- How to Exercise Rights: Submit requests via privacy@pantrimo.com or use the data export and account deletion features in your Profile settings. We will verify your identity and respond within 45 days
- Authorized Agent: You may designate an authorized agent to make requests on your behalf by providing written authorization
Social Media Recipe Import
When you use our Share to Pantrimo feature to import recipes from social media platforms (TikTok, Instagram, Facebook, YouTube, Pinterest), we handle your data as follows:
- What We Process: We process the shared URL, caption text, and thumbnail image to extract recipe information. We do not download or store video or audio content
- What We Store: Only the extracted recipe data (ingredients, instructions, title) and basic attribution (creator name, platform, original URL) are stored in your account. The original caption text is not retained after processing
- Attribution: We display creator attribution to respect original content creators. You can remove attribution from any imported recipe at any time through the recipe detail page, which deletes the original URL and creator information while keeping your recipe content
- Analytics: We collect anonymized, aggregated analytics about import success rates and processing performance. These analytics are automatically anonymized (user identifiers removed) after 90 days. No URLs or caption content are stored in analytics
- AI Processing: Caption text and thumbnail images may be sent to AI providers (Claude, K2.5 Vision) for recipe extraction. No personally identifiable information is included in these requests
- Copyright: You are responsible for ensuring your use of imported recipes complies with applicable copyright laws. Pantrimo stores imported recipes for personal use only
- Data Deletion: When you delete your account, all imported recipes, attribution data, and import analytics are permanently removed
⚠️ Important Food Safety and Allergen Information
CRITICAL SAFETY NOTICE: Pantrimo's AI-powered features, including recipe generation and allergen detection, are NOT 100% reliable and should NOT be your sole method of identifying allergens or ensuring food safety.
- Always Verify Ingredients: If you have food allergies or sensitivities, you MUST independently verify all ingredients in every recipe before cooking or consuming
- AI Limitations: Our allergen detection uses AI analysis which may miss allergens, misidentify ingredients, or fail to account for cross-contamination
- No Medical Advice: Pantrimo is not a substitute for professional medical or nutritional advice. Consult qualified healthcare professionals for dietary decisions
- User Responsibility: You assume all risks associated with following any recipe or dietary information provided by our service
- Report Issues: If you encounter allergen detection errors, please report them immediately to safety@pantrimo.com
Data Security
We implement industry-standard security measures to protect your data, including: encryption of data in transit (HTTPS/TLS) and at rest, secure password hashing (bcrypt), Row-Level Security (RLS) policies in our database to prevent unauthorized access, regular security updates and monitoring, and restricted CORS policies to prevent cross-site attacks. In the event of a data breach affecting your personal information, we will notify affected users and relevant authorities within 72 hours (as required by GDPR) or without unreasonable delay (as required by CCPA). While we strive to protect your data, no method of transmission over the internet is 100% secure, and we cannot guarantee absolute security.
Data Retention
We retain your personal data only for as long as necessary to provide our services and comply with legal obligations. Active account data is retained indefinitely while your account remains active. When you request account deletion, your data enters a 30-day grace period during which you can recover your account by logging in. After the grace period expires, all your personal data (recipes, meal plans, shopping lists, preferences, and account information) is permanently deleted from our systems. We may retain anonymized, aggregated data for analytics purposes. Backup copies may persist for up to 90 days in our disaster recovery systems but are not accessible for normal operations. We may retain certain data longer if required by law, such as for tax record keeping, regulatory investigations, legal disputes, or other legitimate legal purposes.
Children's Privacy
Pantrimo is intended for users who are at least 13 years of age. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child under 13 has provided us with personal information, please contact us at privacy@pantrimo.com, and we will promptly delete such information from our systems. Users between 13 and 18 should have parental or guardian permission before using our service.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will notify you by email (sent to the address specified in your account) and/or by prominently posting a notice in the application at least 30 days before the changes take effect. We encourage you to review this Privacy Policy periodically. The "Last updated" date at the top of this page indicates when the policy was last revised. Your continued use of Pantrimo after changes become effective constitutes your acceptance of the revised Privacy Policy.
Contact Information
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:
- Email: privacy@pantrimo.com
- Mailing Address: 971 US Highway 202N Suite N, Branchburg, NJ 08876, USA
- Response Time: We aim to respond to all privacy inquiries within 30 days
- GDPR/CCPA Requests: For data subject requests under GDPR or CCPA, please use the data export and account deletion features in your Profile settings, or contact us at the email address above