FIFO · Privacy Policy
Privacy Policy
FIFO: Pantry & Recipes
FIFO helps you track the food you already have, reduce waste, and plan groceries. We built FIFO to need as little of your data as possible. This policy explains what the app handles and where it goes.
Information stored on your device
Everything you enter or generate in normal use is saved locally on your device. Unless you sign in and it is part of your cloud backup (section 02c), it is not transmitted to us:
- Pantry items, quantities, locations, and expiry dates
- Grocery / shopping lists
- Saved and AI-generated recipes, and your taste preferences
- Used / thrown-away history and money-saved figures
- App settings (theme, text size)
If you delete the app, or use Reset app in Settings, this information is erased from your device. We keep no copy — unless you have signed in and it is part of your cloud backup (section 02c).
Information that leaves your device
a) AI photo scanning
When you choose to scan a receipt or a photo of your food — or take a photo of a plated meal to get an estimate of its calories and nutrition — the image is resized and sent — over an encrypted connection — to our processing service (Supabase Edge Functions) and our AI provider (Anthropic, the Claude API) to identify the items or estimate the meal. The same applies to text-only AI features (recipe ideas, grocery suggestions, waste tips, describing a meal you ate out), which send the relevant item names or text. Any nutrition figures returned are advisory estimates, not medical or health records.
We do not store these images or the AI results on our servers; they are processed to generate your result and then discarded. The image carries no name, email, or account details. Anthropic processes the request under its own terms, does not use it to train its models, and typically deletes API inputs and outputs from its systems within about 30 days.
b) Barcode and food-name lookups
If you scan a product barcode, the barcode number is sent to Open Food Facts (an open product database) to fetch the product name. No personal information is included.
If you tap Find nutrition facts on a fresh item — one without a barcode or nutrition label — the item’s name (for example, “chicken thighs”) is sent to USDA FoodData Central, a public U.S. government food database, to fetch typical nutrition facts for that food. This happens only when you tap the button, never automatically, and the request carries no account details. Like any web request, it includes your device’s IP address; we don’t retain the lookup, and the result is always marked estimated so you can adjust it.
c) Optional account and cloud backup (Sign in with Apple)
FIFO works fully without an account. If you choose to Sign in with Apple, we receive your email address — or Apple’s private relay address if you pick Hide My Email — and, the first time only, your name (shown on your account screen). Both are stored with your account until you delete it.
Signing in also keeps one cloud backup of your pantry data — items, lists, recipes, history, and settings; never your photos — stored with your account (via Supabase) and replaced on each sync, so you can restore it on a new device. Access is locked to your account, and it is never shared with anyone else. If you stay signed out, nothing changes: your data stays on your device.
d) Fair-use rate limiting
So that AI features stay affordable and available to everyone, the app creates a random, anonymous identifier (via Supabase anonymous sign-in) and stores only a daily count of AI requests against it, to enforce per-user and overall limits. If you sign in, requests count against your account instead. Reinstalling the app while signed out generates a new identifier.
e) Product images
Your item thumbnails are built into the app — matching a pantry item to its food photo happens entirely on your device, with no network request. Only recipe photos load from TheMealDB, a free food-image database, as you browse the recipe library or view a recipe (including a cooked meal that uses its recipe’s photo). Like any web image, that request carries your device’s IP address and identifies which recipe’s photo was fetched — never your account details or the contents of your pantry.
f) Subscriptions
Premium subscriptions are processed by Apple through the App Store. We use RevenueCat to manage and verify subscription status. RevenueCat receives your purchase/subscription details and basic device information under a random purchase identifier — or, when you sign in, under your account id, so Premium follows your account. We never see your payment card details — Apple handles payment.
If you installed FIFO after tapping an Apple Search Ads ad, iOS provides a privacy-preserving attribution token (Apple’s own AdServices — no advertising identifier, no cross-app tracking) that we pass to RevenueCat to measure which ads bring people to FIFO. It tells us a campaign led to the install; it does not identify you.
g) Diagnostics
Our servers keep limited technical error logs (for example, “the AI request failed”) to keep the service running. These do not contain your pantry contents or photos.
h) Feedback you send
If you use Account → Send feedback, the category and the message you type are sent to our backend (Supabase) so we can read it and improve FIFO. It’s free text — include only what you’re comfortable sharing. You can also reach us anytime at support@cntrldesign.com.
i) Referral rewards
If you choose to use referrals, FIFO stores your personal referral code, reward totals, and a record when another signed-in user applies your code. That record links the two account ids with its status and timestamps. Our server asks RevenueCat whether the invited user made their first paid Premium purchase after applying the code, then grants the referrer a promotional month when eligible. Neither person sees the other person’s name, email, per-person purchase details, or pantry data. Aggregate referral totals can show that one or more invited users converted.
What we do NOT collect
We do not collect your phone number, contacts, precise location, or advertising identifiers. Your name and email reach us only through Sign in with Apple — and only if you choose to sign in. FIFO contains no in-app advertising, no third-party analytics/tracking SDKs, and we never sell your data. (We do promote FIFO through Apple Search Ads and receive Apple’s privacy-preserving install-attribution token described in section 02f, which does not track you across apps.)
Third-party services
The services that may process data on our behalf, each under its own privacy policy:
- Apple — in-app purchases / subscriptions, Sign in with Apple
- RevenueCat — subscription management
- Supabase — backend, authentication, cloud backup, rate limiting
- Anthropic (Claude API) — AI image and text processing
- Open Food Facts — barcode product lookup
- USDA FoodData Central — fresh-food nutrition lookup
- TheMealDB — recipe photos
Data retention
- On-device data: kept until you delete it (Reset app) or uninstall the app.
- Cloud backup, email, and name (signed-in only): kept while your account exists; deleted permanently with your account.
- Scanned images / AI text: not retained by us after processing.
- Anonymous rate-limit counts: automatically roll over daily.
- Feedback you send: kept while we work through it; deleted with your account if you’re signed in. Feedback sent without an account can’t be traced back to you, so we can’t delete it individually.
- Referral records: your personal code and reward history are kept while your account exists. A code-use record stays with the invited user’s account to enforce the one-code-ever rule. Deleting the invited user’s account removes that record; deleting the referrer’s account removes the referral link, personal code, and reward history.
Your choices and deletion
- Delete your data: use Reset app in the app’s Settings, or uninstall the app, to remove all information stored on your device.
- Delete your account: in the app, go to Account → Delete account. This permanently deletes your account, your email and name, your cloud backup, and your referral code/reward history, removes your account from referral links, and revokes the Sign in with Apple connection at Apple. Signing out alone stops syncing but keeps your backup until you delete the account.
- Reset your anonymous identifier: reinstalling the app while signed out issues a new anonymous identifier.
- Subscriptions: manage or cancel anytime in your Apple ID → Subscriptions settings.
- For any privacy question or request, contact us at the email above.
Children’s privacy
FIFO is not directed to children under 13, and we do not knowingly collect information from them.
Security
Data sent off the device travels over encrypted (HTTPS/TLS) connections. No method of transmission or storage is 100% secure, but we limit what is sent and what is kept.
Changes to this policy
We may update this policy as the app evolves. We will revise the “Last updated” date above and, for significant changes, note them in the app or its release notes.
Contact
Questions? Contact CNTRL Design at support@cntrldesign.com.