Privacy Policy
This Privacy Policy explains how the Fridge Inventory mobile application (“the App”) handles your information. TinyVault (“we”, “us”, “our”) is an independent app studio, the developer of the App, and the data controller for the limited processing described below. It should be read together with our Terms of Use. By using the App you agree to the practices described here.
1. Information stored on your device
Everything you put into the App — your fridge and pantry items, quantities, dates, storage locations, shopping list, custom items, favourites, dietary and allergen preferences, reminder preferences and settings — is stored locally on your device using your device’s standard app storage. We do not operate an account system and we do not keep a copy of this data on our servers. If you uninstall the App, this data is deleted with it. You can export a backup at any time from the App’s settings. Note that dietary and allergen preferences may be considered health-related information in some countries; we hold them only on your device, and they leave it only as described in Section 2 when you ask for recipes.
2. Information sent when you use online features
Online features send data off your device only when you actively use them, and only through our own secure server (which holds the API keys so they never ship inside the App):
- Recipe suggestions. When you request recipes, the App sends the list of ingredient names currently in your fridge and your dietary/allergen preferences, so that matching recipes can be found and adapted. It does not send your name, email, phone number, contact list, location or advertising identifier.
- Recipe chat (“Ask your fridge”). Every install can ask a small number of questions without a Pro plan; Pro raises the allowance. When you send a question, the App sends the words you typed or dictated, the last few messages of that conversation, the names and quantities of the items in the storage place you are cooking from (with the place’s name when you cook from all places, and a flag on items nearing the end of their estimated shelf life), your dietary and allergen preferences, and the App’s language. An AI model uses these to write a reply and recipes. The conversation itself is kept only on your device — our server does not store it — and you can clear it at any time with “New chat”. Please don’t include personal details in your questions; the chat is for cooking, and anything you type is sent as described here.
- Photo scan (only if enabled and only if you choose it). A photo you capture or pick is sent to be analysed into a list of detected grocery items. The image is used to produce that list and is not stored by our server after the request completes. Anything else visible in the frame is sent along with it, so point the camera only at what you intend to scan. The App keeps a count and the times of your recent scans on your device to apply the scan allowance; that count is not sent to us.
- A random app-generated device identifier. Each online request, and each anonymous analytics event (Section 6), carries a random identifier that the App generates on first launch and stores on your device. We use it to count requests against per-device daily limits, which protect the service from abuse and runaway cost, and to group analytics events from one installation so we can tell one person using a feature ten times from ten people using it once. It is not your device’s advertising ID or hardware ID, it is not linked to your name or account, we do not use it for advertising or tracking across apps or websites, and it resets if you reinstall the App.
All of these requests are transmitted over encrypted connections (HTTPS).
Legal bases (EEA/UK). We process this data to perform the service you asked for (Article 6(1)(b) GDPR); where preferences amount to health data, on the basis of your explicit consent, given by choosing to use the recipe feature with those preferences set (Article 9(2)(a)); and we use the request counter on the basis of our legitimate interest in keeping the service available and affordable (Article 6(1)(f)).
3. Voice input and speech recognition
If you use “say what you have”, the App records audio while you hold the button and converts it to text using your device’s own speech-recognition service (provided by Apple or Google as part of your operating system). Depending on your device, OS version and settings, that conversion may happen entirely on the device or may be performed by Apple’s or Google’s servers — that is determined by your platform, not by us, and their handling of it is governed by their own privacy policies.
What we can tell you is what the App does: audio is never sent to TinyVault’s servers, and we never store recordings. The resulting text is interpreted entirely on your device by a local rules-based parser — no AI service and no network call is involved in understanding what you said — and nothing is changed in your inventory until you review and confirm it. The one exception is the recipe chat (Section 2): if you dictate a question there, the transcript is placed in the text box for you to read, and only when you tap send is it sent — as text, exactly like a typed question. Microphone and speech-recognition permissions are requested only when you first use the feature and can be revoked at any time in your device settings.
4. Notifications
Reminders (such as “use soon” prompts and a weekly shopping nudge) are scheduled and delivered locally by your device. Their content is computed on the device from your own inventory and is not sent to us or to any push service. You will be asked for notification permission before any is scheduled, and you can turn reminders off in the App’s settings or in your device settings at any time.
5. Service providers
To provide the online features above, our server passes the necessary data to third-party processors acting on our behalf:
- Anthropic (Claude) — writes the recipe chat’s replies and recipes from your ingredient list, and, where enabled, analyses scan photos. Anthropic does not use this data to train its models.
- Google Firebase (Google Cloud) — hosts the server function that brokers these requests and stores the per-device request counters described in Section 2.
These providers process the data only to return a result for your request, under their own privacy and security commitments and under contractual terms with us. We do not authorise them to use your data for their own purposes.
Where you buy a Pro plan, the purchase is processed by Apple or Google under their own privacy policies. We never see or receive your payment card, billing address or store account details.
6. Analytics
The App collects anonymous product analytics: which features are used, how far you get through a flow such as first-time setup or the shopping list, how long a screen took to load, and whether a request to our recipe service succeeded. Each event carries your app version, platform, language, a session identifier, how many days ago the App was installed, and whether you have a Pro subscription. We use this to find where the App is confusing or broken and to decide what to build next.
Events are tied only to the same random app-generated identifier described in Section 2 — never to your name, email, account, advertising identifier, or contact list. We do not collect the contents of your fridge as text: an event may record that an item in a built-in category was added, but never the names of items you typed yourself, your notes, your shopping list, or your photos.
Analytics data is processed on our behalf by Mixpanel, Inc., on servers in the European Union, and by Google (Google Analytics 4), which we use only to keep a long-term archive of the same anonymous events. Events are queued on your device and sent in batches, so the App works offline.
This is audience measurement: it is limited to understanding how the App itself is used. It is not used to build a profile of you, is not combined with data from other sources, is not shared with anyone else, and does not follow you across other apps or websites. There is no advertising identifier involved.
If you would rather we did not collect it, email us at the address in Section 14 and we will exclude your installation and delete the events already associated with it. Because the identifier is random and not linked to you, please send the request from the App’s “Contact support” link in Settings, which includes it automatically.
7. What we do not do
- We do not require an account or collect your name, email, or phone number.
- We do not sell or rent your data to anyone, and we do not “share” it for cross-context behavioural advertising as those terms are defined under US state privacy laws.
- We do not show ads or use advertising identifiers or trackers.
- We do not collect your location.
- We do not access your photo library beyond the specific photo you choose to scan.
- We do not send your audio recordings to our servers, or store them anywhere.
- We do not use your data to train AI models.
- We do not record your screen, and we do not use session-replay or heatmap tools.
8. Data retention
Data you enter stays on your device until you delete it or uninstall the App. Recipe, recipe chat and scan request contents are processed in real time and are not retained by our server after a response is returned. The per-device request counters described in Section 2 are keyed by day (or, for the recipe chat’s monthly allowance, by month) and are retained for a short period (currently no longer than 30 days after the day or month they count) purely to enforce those limits, then deleted. Our hosting provider keeps standard operational logs (such as timestamps, error traces and truncated network addresses) for a limited period for security and debugging. Anonymous analytics events (Section 6) are retained for up to 12 months and then deleted.
9. Security
Data on your device is protected by your device’s own security, including its passcode and storage encryption. Data in transit to our server and its providers is encrypted with HTTPS, and our API keys are held server-side so they never ship inside the App. No method of transmission or storage is 100% secure, but we keep the amount of data that ever leaves your device to the minimum needed to provide a feature.
10. Children’s privacy
The App is intended for a general audience and is not directed at children under 13 (or the minimum age of digital consent in your country, where higher). We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us and we will delete it.
11. Your rights
Because your data lives on your device, you are in direct control of it: you can view, edit and export it at any time from within the App, remove any item or list there, and delete all of it permanently by uninstalling. You can also withdraw camera, photo, microphone, speech-recognition and notification permissions at any time in your device settings.
If you are in the EEA, the UK, Switzerland, or a US state with a comprehensive privacy law (such as California), you have rights to access, correct, delete, port, and restrict or object to the processing of personal data we hold, and to lodge a complaint with your supervisory authority. In practice we hold almost nothing about you — there is no account to look up — so the main thing we can act on is the random app-generated identifier described in Section 2. It stays the same for as long as the App is installed and is replaced by a new, unrelated one if you reinstall. Contact us and we will delete what is associated with it, and help you exercise any of these rights, without charge. We do not discriminate against anyone for exercising these rights, and we do not sell personal information, so no “Do Not Sell or Share” action is necessary.
12. International transfers
When you use the online features, your request may be processed on servers located in other countries, including the United States, by the providers listed in Section 5. Where personal data is transferred out of the EEA or the UK, it is protected by the European Commission’s Standard Contractual Clauses (and the UK Addendum) or another lawful transfer mechanism offered by the provider concerned.
13. Changes to this policy
We may update this policy as the App evolves — for example, if we add a new feature. When we do, we will revise the “Last updated” date above and post the new version on this page. Material changes will be reflected here, and in the store listing’s data-safety disclosure, before the feature they describe ships; where the law requires it, we will ask for your consent.
14. Contact
Questions about this policy or your data? Email tinyvault.apps@gmail.com and a person will reply. We aim to respond within 30 days.