Privacy

FIFO · Privacy Policy

Privacy Policy

FIFO: Pantry & Recipes

Provider: CNTRL Design (“we”, “us”)
Last updated: 20 July 2026
Contact: support@cntrldesign.com

FIFO helps you track the food you already have, reduce waste, and plan groceries. We built FIFO to need as little of your data as possible. This policy explains what the app handles and where it goes.

The short version: Your pantry, grocery list, recipes, and history live on your device. If you choose to sign in with Apple, we also keep one private cloud backup of that data so you can restore it. Off-device processing is limited to the features and operations described below: AI scans and text requests, product and recipe lookups, account sync and referral records, subscription and install-attribution data, feedback, and limited diagnostics. No ads, no tracking, no analytics.
01

Information stored on your device

Everything you enter or generate in normal use is saved locally on your device. Unless you sign in and it is part of your cloud backup (section 02c), it is not transmitted to us:

If you delete the app, or use Reset app in Settings, this information is erased from your device. We keep no copy — unless you have signed in and it is part of your cloud backup (section 02c).

02

Information that leaves your device

a) AI photo scanning

When you choose to scan a receipt or a photo of your food — or take a photo of a plated meal to get an estimate of its calories and nutrition — the image is resized and sent — over an encrypted connection — to our processing service (Supabase Edge Functions) and our AI provider (Anthropic, the Claude API) to identify the items or estimate the meal. The same applies to text-only AI features (recipe ideas, grocery suggestions, waste tips, describing a meal you ate out), which send the relevant item names or text. Any nutrition figures returned are advisory estimates, not medical or health records.

We do not store these images or the AI results on our servers; they are processed to generate your result and then discarded. The image carries no name, email, or account details. Anthropic processes the request under its own terms, does not use it to train its models, and typically deletes API inputs and outputs from its systems within about 30 days.

b) Barcode and food-name lookups

If you scan a product barcode, the barcode number is sent to Open Food Facts (an open product database) to fetch the product name. No personal information is included.

If you tap Find nutrition facts on a fresh item — one without a barcode or nutrition label — the item’s name (for example, “chicken thighs”) is sent to USDA FoodData Central, a public U.S. government food database, to fetch typical nutrition facts for that food. This happens only when you tap the button, never automatically, and the request carries no account details. Like any web request, it includes your device’s IP address; we don’t retain the lookup, and the result is always marked estimated so you can adjust it.

c) Optional account and cloud backup (Sign in with Apple)

FIFO works fully without an account. If you choose to Sign in with Apple, we receive your email address — or Apple’s private relay address if you pick Hide My Email — and, the first time only, your name (shown on your account screen). Both are stored with your account until you delete it.

Signing in also keeps one cloud backup of your pantry data — items, lists, recipes, history, and settings; never your photos — stored with your account (via Supabase) and replaced on each sync, so you can restore it on a new device. Access is locked to your account, and it is never shared with anyone else. If you stay signed out, nothing changes: your data stays on your device.

d) Fair-use rate limiting

So that AI features stay affordable and available to everyone, the app creates a random, anonymous identifier (via Supabase anonymous sign-in) and stores only a daily count of AI requests against it, to enforce per-user and overall limits. If you sign in, requests count against your account instead. Reinstalling the app while signed out generates a new identifier.

e) Product images

Your item thumbnails are built into the app — matching a pantry item to its food photo happens entirely on your device, with no network request. Only recipe photos load from TheMealDB, a free food-image database, as you browse the recipe library or view a recipe (including a cooked meal that uses its recipe’s photo). Like any web image, that request carries your device’s IP address and identifies which recipe’s photo was fetched — never your account details or the contents of your pantry.

f) Subscriptions

Premium subscriptions are processed by Apple through the App Store. We use RevenueCat to manage and verify subscription status. RevenueCat receives your purchase/subscription details and basic device information under a random purchase identifier — or, when you sign in, under your account id, so Premium follows your account. We never see your payment card details — Apple handles payment.

If you installed FIFO after tapping an Apple Search Ads ad, iOS provides a privacy-preserving attribution token (Apple’s own AdServices — no advertising identifier, no cross-app tracking) that we pass to RevenueCat to measure which ads bring people to FIFO. It tells us a campaign led to the install; it does not identify you.

g) Diagnostics

Our servers keep limited technical error logs (for example, “the AI request failed”) to keep the service running. These do not contain your pantry contents or photos.

h) Feedback you send

If you use Account → Send feedback, the category and the message you type are sent to our backend (Supabase) so we can read it and improve FIFO. It’s free text — include only what you’re comfortable sharing. You can also reach us anytime at support@cntrldesign.com.

i) Referral rewards

If you choose to use referrals, FIFO stores your personal referral code, reward totals, and a record when another signed-in user applies your code. That record links the two account ids with its status and timestamps. Our server asks RevenueCat whether the invited user made their first paid Premium purchase after applying the code, then grants the referrer a promotional month when eligible. Neither person sees the other person’s name, email, per-person purchase details, or pantry data. Aggregate referral totals can show that one or more invited users converted.

03

What we do NOT collect

We do not collect your phone number, contacts, precise location, or advertising identifiers. Your name and email reach us only through Sign in with Apple — and only if you choose to sign in. FIFO contains no in-app advertising, no third-party analytics/tracking SDKs, and we never sell your data. (We do promote FIFO through Apple Search Ads and receive Apple’s privacy-preserving install-attribution token described in section 02f, which does not track you across apps.)

04

Third-party services

The services that may process data on our behalf, each under its own privacy policy:

05

Data retention

06

Your choices and deletion

07

Children’s privacy

FIFO is not directed to children under 13, and we do not knowingly collect information from them.

08

Security

Data sent off the device travels over encrypted (HTTPS/TLS) connections. No method of transmission or storage is 100% secure, but we limit what is sent and what is kept.

09

Changes to this policy

We may update this policy as the app evolves. We will revise the “Last updated” date above and, for significant changes, note them in the app or its release notes.

10

Contact

Questions? Contact CNTRL Design at support@cntrldesign.com.