Pixel Fridge ("the app", "we") helps you track the food in your fridge, provides best-by estimates and reminders, and suggests recipes. This policy explains what data the app and its public website handle, why, and what control you have over it. The short version: we collect the minimum needed to run and protect the service, we don't run ads, we don't sell data, and you can delete your account data yourself, in the app, at any time.
| Data | Purpose | Where it lives |
|---|---|---|
| Email address and password | Creating and signing in to your account. Supabase stores the password only as a secure hash. When you delete an account, the password you re-enter is processed transiently by our Supabase-hosted deletion function and Supabase Auth to authorize that deletion; it is never logged or stored in plaintext. | Supabase (our backend) |
| Your fridge contents | Item names, categories, expiry dates, and whether you ate or discarded each item — this is the core function of the app and powers your reminders and monthly stats. | Supabase, linked to your account and readable only by you |
| Grocery photos you scan | Identifying the food in the photo. The photo is sent over an encrypted connection to our server function, forwarded to our AI provider (SiliconFlow) for one-time processing, and is not stored by Pixel Fridge. Only the resulting food list is kept (as fridge items, if you save them). | Processed transiently; never stored by us |
| Usage counters | A count of your AI scans and recipe requests per reset window (currently weekly for scans, daily for recipe requests), used solely to enforce fair-use limits. | Supabase, linked to your account |
| Subscription status | Whether your account is on the free or Premium plan, so the app can apply the right usage limits. Payment itself is handled entirely by Apple or Google — we never see or store your card details. | Supabase (plan only) and RevenueCat (subscription state) |
| Crash reports | If the app crashes or hits an error, a technical report (the error, stack trace, device model, and OS version) is sent so we can fix it. The app disables default PII, removes attached user records, redacts authorization, cookie, token, password, email, IP, and request-body fields, and does not use screen recording. | Sentry (crash reporting service) |
| Bot-protection technical and interaction data | When an authentication or account-deletion challenge runs, hCaptcha automatically processes technical and security signals such as IP address, browser/platform, device and operating-system details, timestamps, challenge results, and interaction behavior. Pixel Fridge receives the resulting one-time proof, not hCaptcha's underlying risk profile. | hCaptcha; Pixel Fridge uses the proof transiently and does not store it |
| Website request metadata | When you visit our public website, privacy/terms pages, or an authentication redirect page, our host receives ordinary delivery and security metadata such as IP address, browser/user-agent and device information, requested URL (including any query component sent by the browser), referrer, and request timestamp. | Netlify service/access logs; Pixel Fridge has not added advertising analytics to the site |
We do not request precise GPS location or access your contacts, and Pixel Fridge does not build advertising profiles, use data for cross-app advertising, or sell personal data to data brokers. hCaptcha and Netlify do receive the IP-derived and technical security/request data described above; we use those services for bot prevention, security, and website delivery, not advertising. Expiry reminders are scheduled locally on your device and never leave it.
We use a small number of processors to run and protect the service: Supabase (database, authentication, and server functions), SiliconFlow (AI models that identify foods in your photos and generate recipe suggestions), hCaptcha (bot and abuse prevention using the technical and interaction signals described in section 1; see the hCaptcha privacy policy), RevenueCat (managing Premium subscription status across the App Store and Google Play; see the RevenueCat privacy policy), Sentry (redacted technical crash/error reports only; see the Sentry privacy policy), and Netlify (hosting and securing the public website and its redirect pages; see the Netlify privacy statement). Each receives only the data needed for its stated function.
Your account data is kept for as long as your account exists. You can delete your account at any time from the app's Settings tab ("Delete account"). Deletion is permanent: your account, fridge history, stats, and usage counters are removed from our live systems right away. Residual copies may persist briefly in our database provider's encrypted backups, which are purged automatically within 30 days. Processor records follow the processors' published or contracted retention schedules: subscription records at RevenueCat and redacted crash reports at Sentry age out under their retention settings; hCaptcha states that certain automatically collected technical data may be retained for up to one year and then deleted or de-identified, subject to security or legal exceptions; Netlify processes website service/access data under its hosting terms and data-processing agreement. You can also request deletion by email. Note that deleting your account does not cancel an active subscription — manage that in your App Store or Google Play settings.
All traffic is encrypted in transit (TLS). Server-side, your data is isolated by row-level security so that your account can only ever read or change its own rows. Account deletion requires the current password and a one-time CAPTCHA proof to be verified by Supabase Auth inside the deletion function; possession of a signed-in session alone is not enough. AI keys and administrative credentials never ship inside the app.
Pixel Fridge is not directed at children under 13 (or the equivalent minimum age in your region), and we do not knowingly collect data from them.
Depending on where you live (e.g., GDPR in the EU/UK, CCPA in California), you may have rights to access, correct, export, or erase your personal data, and to lodge a complaint with a supervisory authority. The in-app deletion erases your live data right away (see section 4 for backup timing); for anything else, contact us and we'll respond within 30 days.
If we make material changes (for example, adding analytics or a new category of collected data), we will update this page and the effective date, and note the change in the app's release notes.
Questions or requests: support@aifridge.net