Skip to main content
Pantry Persona Icon
Pantry Persona

Privacy Policy

Last updated: September 29, 2026

Pantry Persona is a kitchen management service that helps you track your pantry, plan meals, manage recipes, and reduce food waste. In some interfaces, including ChatGPT and other Model Context Protocol (MCP)–compatible clients, Pantry Persona can also help you build shopping lists and send them to grocery and delivery platforms.

This Privacy Policy explains how we collect, use, and share personal information when you use Pantry Persona anywhere in the world, including:

  • Pantry Persona tools available inside ChatGPT or other MCP-compatible hosts
  • Our website at pantrypersona.com
  • Any other Pantry Persona services that link to this Privacy Policy

This policy tells you what we do with your information. It is a notice, and it does not create a contract between us.

1. Information We Collect

We collect information in three main ways: information you provide directly, information collected automatically, and information received from third parties.

1.1 Account Information

When you create or connect an account, we collect:

  • Email address, to identify your account and send important notifications
  • Authentication data, managed by our authentication provider (for example, hashed passwords or tokens)
  • MCP / ChatGPT identity context, such as identifiers provided by a host (for example, a subject or tenant ID) so that host can act on your behalf when using Pantry Persona

We do not store passwords in plain text.

1.2 User Content

You choose what to add to Pantry Persona, such as:

  • Pantry items: food items, quantities, expiration dates, purchase prices
  • Recipes: ingredients, instructions, cooking times, URLs or images (where supported)
  • Meal plans: scheduled meals and associated recipes
  • Shopping lists: items you plan to purchase, including store or retailer selections
  • Household profiles: household members' names or nicknames, tastes, and preferences

This content can be created through our website, our own interfaces, or through tools inside MCP hosts such as ChatGPT.

1.2a Saved Personalisation Preferences

Pantry Persona saves preferences you configure, or that we pick up from your explicit instructions, so the experience stays consistent across conversations and MCP hosts. These influence how we respond to you. For example: the pace and detail you prefer, how recommendations are presented, recipes or topics you have asked us to skip, and any multi-step routines you have set up for planning meals.

Which preferences we save may change over time as we add new ways to tailor the experience. In every case:

  • Preferences come from what you have told Pantry Persona or done inside the service. We do not infer them from outside data.
  • They persist across sessions until you change or clear them.
  • They are used only within Pantry Persona to shape your own experience. They are not shared with third parties and are not used for advertising.
  • You can update or clear any saved preference at any time by asking Pantry Persona inside an MCP host (for example, "forget my pacing preference") or by contacting us.

This section describes the category of personalisation data we save. The specific preferences may change as the service evolves; material changes will be reflected in updates to this Policy.

1.3 Dietary and Health-Related Information (Sensitive Data)

If you choose to provide it, we may process:

  • Dietary preferences (for example, vegetarian, vegan, low-carb)
  • Food exclusions and allergies (for example, nuts, dairy, gluten)
  • Food-related goals (for example, nutrition focus or calorie awareness)

We treat this as sensitive information. We use it only to personalise your Pantry Persona experience, such as:

  • Filtering recipes and suggestions
  • Flagging ingredients you want to avoid
  • Helping you plan meals that better match your preferences

If your account is in the EEA, the UK or Switzerland

We ask for your explicit consent before we store any of this, once, when you first add a dietary, allergy, goal or nutrition-target detail. If you decline, recipes and suggestions are not filtered for you. You can withdraw at any time in Settings, on the "Data controls" page; withdrawing also removes the stored details from every profile on your account, and we keep a record of each consent and withdrawal for as long as your account exists.

Wherever you are, you can remove or change this information at any time under Settings, on the "Data controls" page, or by contacting us.

1.4 Receipt Data

When you add items from receipts, we may process:

  • Receipt text or structured data you input or upload
  • Product mappings we derive from that text, such as normalised product names linked to your pantry items

This allows Pantry Persona to convert receipt information into items in your pantry.

1.4a Receipts You Email to Us

If you set up receipt forwarding, the grocery receipts you send or forward to our receipts address are read automatically. We take the purchase date, the store, the items and their prices, and add them to your pantry and price history the same way a scanned receipt is handled. We do not keep the email. Once the receipt has been extracted, the message is moved to our mailbox's trash, which Google erases after 30 days. A message we cannot read is trashed within 7 days. We never store the body of the email, its attachments, card numbers, delivery addresses or referral codes. We keep the receipt data and a short record of the message: the sending domain, a fingerprint used to catch duplicates, and whether it was processed.

Mail we cannot match to an account is discarded. We do not send replies from the receipts address.

1.5 Device and Usage Data

We collect limited technical data to operate and improve the service, such as:

  • Browser type and version, basic device and operating system information, and language
  • Information about how you use Pantry Persona (for example, which features you use and how often, error events, and performance metrics)
  • When you first arrive, the campaign link or referring site that brought you and the first page you landed on

This information is generally collected in an aggregated or pseudonymous form through hosting and analytics providers.

For our current web and MCP integrations:

  • We do not collect precise GPS location, contact lists, or your general web browsing history
  • We do not request access to your camera or microphone from the browser

If we release native applications that use additional device features (for example, camera access for barcode scanning), we will request permission through the operating system and explain those uses separately.

1.6 Information from ChatGPT, MCP Hosts, and Other Third Parties

When you use Pantry Persona through ChatGPT or another MCP host:

  • The host sends Pantry Persona tool calls that include your instructions, relevant parameters (for example, which pantry to read or which items to add), and the limited context needed to complete the action
  • We receive only the information needed to fulfil that request, such as a user or session identifier, tool parameters, and any context the host chooses to include

We also receive information from:

  • Payment providers and app stores, such as subscription and transaction information (we do not receive full payment card numbers)
  • Identity providers, such as tokens and profile identifiers used to secure access
  • Grocery and shopping platforms you choose to connect, such as identifiers and tokens needed to create or update carts or lists on your behalf, and limited information about the status of those carts or lists

Each of these third parties handles your information under its own terms and privacy policies.

1.6a Records of Tool Calls

When ChatGPT, Claude or another AI host calls one of our tools for you, we keep a record of the call: which tool ran, which action inside it (for example add or remove), when it ran, whether it worked and how long it took. We do not keep what you typed. On ChatGPT the record includes the anonymised conversation identifier that ChatGPT sends with each call, so we can see which calls belong to the same conversation. We use these records to run, secure and fix our tools. We rely on our legitimate interest in operating the service, and we delete the records after 90 days. They are stored with the hosting providers listed in section 9.1. You can object to this use at any time; see section 8.

1.7 Data Returned in MCP Tool Responses

When you interact with Pantry Persona through an MCP host (such as ChatGPT or Claude), tool responses may include:

  • Internal identifiers used to reference your data in follow-up operations. These are opaque strings with no personal meaning.
  • Activity timestamps and engagement signals tied to the content you have added, such as when items were created, updated, used, completed, or last interacted with. Used for ordering, rotation, expiration tracking, and relevance.
  • Feature adoption indicators showing which parts of the service you have set up or used. Used to provide onboarding and guidance.
  • Derived insights and patterns computed from the content you have already provided to Pantry Persona (see Sections 1.2 and 1.4). These may include aggregated preferences, frequency and timing patterns, and forward-looking suggestions or predictions returned to you within features that depend on them. Derived insights are generated from your own data and are not shared with third parties or used for advertising.
  • Saved preferences and recurring routines that you have configured for yourself or your household, including ratings, recurring constraints, and multi-step routines. Returned alongside the related record so the service applies them consistently across features.
  • Service metadata carried in tool responses to help an MCP host render, route, or classify the result correctly. These auxiliary fields (by convention, prefixed with an underscore) do not contain personal information about you and may change as the service evolves.

These fields are functional. They help an MCP host display your data, call follow-up tools, and provide relevant suggestions. They are not shared with third parties or used for advertising. As the service evolves, the specific fields returned may change; this section describes the categories we return, not an exhaustive list of every field.

2. How We Use Your Information

We use personal information for the purposes described below. For users in the EEA, the UK and Switzerland, the table also names the legal basis we rely on for each purpose under the GDPR, the UK GDPR and Swiss data protection law.

PurposeExamplesLegal Basis (EEA, UK, Switzerland)
Provide core featuresTrack your pantry, recipes, meal plans, shopping lists; respond to MCP tool callsPerformance of a contract
PersonalizationTailor recipes and suggestions to your pantry, preferences, allergies, and goalsYour explicit consent, for dietary, allergy, goal and nutrition-target details
AI-powered featuresProvide smart suggestions and automations using your pantry contents, history, and preferencesPerformance of a contract
Grocery and shopping integrationsLet you send a shopping list or selected recipes to a connected grocery or delivery platformPerformance of a contract
Receipt processingTurn receipt text into structured pantry items and product mappingsPerformance of a contract
Billing and account managementProcess subscriptions, handle billing issues, and detect payment-related fraudPerformance of a contract
Service improvement and analyticsUnderstand which features are used, diagnose technical issues, improve performanceYour consent in the EEA, UK and Switzerland. Elsewhere, our legitimate interest in understanding which features are used
Security and abuse preventionProtect accounts and services, detect misuse, and respond to incidentsOur legitimate interest in keeping the service secure
Tool-call recordsRun, secure and fix our tools inside ChatGPT, Claude and other hostsOur legitimate interest in operating the service
Consent recordsKeep a record of when you agreed to store dietary, allergy and goal details, and of any withdrawalLegal obligation to show that consent was given
Legal complianceMeet tax, accounting, and regulatory obligations; enforce our termsLegal obligations

Important: We do not use personal information for cross-context behavioural advertising or for selling personal information.

2.1 Aggregated and De-Identified Information

We may create aggregated, anonymised, or otherwise de-identified information derived from personal information. This type of information does not identify you as an individual and may be used and shared for any lawful purpose, such as:

  • Analysing overall usage patterns and trends
  • Improving and developing our services
  • Generating insights about how people use Pantry Persona

3. MCP and ChatGPT Integration

Pantry Persona is implemented as an MCP server that can be used by compatible hosts such as ChatGPT.

3.1 How MCP Hosts Use Pantry Persona

  • The host (for example, ChatGPT) manages your conversation, identity, and user interface
  • When you ask the host to use Pantry Persona (for example, "add this recipe to my pantry app"), the host sends a tool request to Pantry Persona's MCP server
  • Pantry Persona processes that request, interacts with your Pantry Persona data as needed, and returns structured results to the host

We do not see your entire conversation with the host. We see only the structured tool calls and any context the host includes in those calls.

3.2 What We Receive from MCP Hosts

The host may send:

  • A user or account identifier used to look up your Pantry Persona account
  • Tool parameters, such as item names, recipe identifiers, quantities, and relevant options
  • Limited context needed to perform the action (such as language or region)
  • An anonymised conversation identifier (currently sent by ChatGPT), which we use only to group the tool calls from one conversation

We do not receive your ChatGPT login credentials or independent ChatGPT account data.

The host continues to process your data under its own privacy policy. Pantry Persona processes only the information necessary to provide the features you invoke.

3.3 Security for MCP Integrations

For MCP integrations we:

  • Use scoped tokens and access controls to enforce least-privilege access
  • Validate incoming requests and tokens before performing actions
  • Limit which systems and data MCP tools can access
  • Monitor for misuse and unusual activity

4. Cookies and Similar Technologies

We use cookies and similar technologies for:

  • Session cookies that keep you logged in
  • Basic preference cookies that remember certain settings
  • First-party analytics and attribution cookies that help us understand how visitors use the site, such as which pages are viewed and which link or campaign brought someone here
  • Google Analytics, a third-party service from Google that uses cookies to measure site traffic and usage. You can read how Google uses information from sites that use its services

We do not use advertising cookies or trackers for behavioural advertising.

4.1 Visitors in the EEA, the UK and Switzerland

Nothing non-essential runs or is stored until you accept it through the consent banner. That covers Google Analytics, our own measurement of page views and site performance, Vercel's visitor analytics, and the cookies that record your visit and the link or campaign you arrived from.

If you follow a link from one of our paid ChatGPT ads, we keep the one cookie the signup needs in order to complete. That is the only thing stored before you answer the banner.

Changing your answer below takes effect immediately, and declining does not change how the site works.

Analytics cookies: not set

5. International Data Transfers

Pantry Persona is operated from the United States. The database that holds your account and your content is hosted in Canada, a country the European Commission has recognised as providing an adequate level of protection for personal data handled by commercial organisations. Our application servers and most of our other providers are in the United States, so information also travels there.

For the providers we use in the United States, we rely on the Standard Contractual Clauses approved by the European Commission, together with the UK Addendum and the Swiss amendments where those apply. Where a provider is certified under the EU-US Data Privacy Framework, including its UK and Swiss extensions, we also rely on that certification.

Email us if you would like the current list of the providers we use and the transfer mechanism that applies to each.

6. Data Security

We use a range of technical and organisational measures to help protect personal information, including:

  • Encryption in transit using HTTPS/TLS
  • Encryption at rest provided by our database and storage providers
  • Access controls and role-based permissions for staff with a need to know
  • Scoped tokens and OAuth-style access controls for integrations and tools
  • Security headers and other hardening measures
  • Monitoring and logging to detect unusual or abusive activity

No security method is completely free of risk, but we work to maintain the security and integrity of your data. You can help by using a strong, unique password for your account and keeping access to your devices and host accounts (such as ChatGPT) secure.

7. Data Retention

We keep personal information only for as long as necessary for the purposes described in this Privacy Policy, or as required by law. The specific retention periods for each category of data are described below and apply equally to all users regardless of subscription tier.

Data CategoryRetention Period
Account informationLife of account + 30-day deletion grace period
Recipes, pantry, and shopping listsLife of account
Meal plans and food eventsLife of account (events older than 6 months may be aggregated into monthly summaries for performance)
Household profiles and dietary preferencesLife of account
Receipts and price historyLife of account
Emailed receipts (the message itself)Extracted receipt data: life of account. The email is trashed as soon as it is extracted, or within 7 days if we cannot read it; Google erases trashed mail after 30 days.
Brand preferences and staplesLife of account
Security and access logs90 days
Records of tool calls90 days
Consent recordsLife of account
Payment recordsAs required by tax and financial regulations
Aggregated and de-identified dataMay be retained indefinitely, as it does not identify you

7.1 Account Deletion

If you delete your account:

  • You have a 30-day recovery window during which you can cancel the deletion and restore your account
  • After the recovery window, personal data in active systems is permanently deleted (typically within 7 days)
  • Data in backups and archives will be removed according to regular backup rotation schedules
  • We may retain limited information as required for legal, accounting, or security purposes

Once an account is deleted and any applicable retention periods have passed, the deletion is permanent and the account cannot be restored.

8. Your Rights

Your privacy rights depend on where you live, but we aim to provide all users with meaningful control over their personal information.

8.1 Rights Available to All Users

Regardless of your location, you can:

  • Access: request information about the personal data we hold about you
  • Correct: ask us to correct inaccurate or incomplete data
  • Delete: request deletion of your account and associated personal data, subject to legal and operational exceptions
  • Export: download a copy of your personal data in a structured, commonly used, machine-readable format
  • Withdraw consent: withdraw consent for specific processing (for example, dietary/health preferences) where consent is the legal basis

Your export is a ZIP you download from Settings, on the "Data controls" page, after confirming your password. It holds the content you added and the records built from it, as CSV and JSON files with a short guide to each. A complete copy of everything we hold about you, including access logs and consent records, is available on request at the address in Section 12; we answer within one month.

Some of these rights can be exercised directly through your account settings. You can also contact us using the details at the end of this Policy.

8.2 Additional Rights for Residents of the EEA, the UK and Switzerland

If you are in the EEA, the UK or Switzerland, you have additional rights under the GDPR, the UK GDPR and Swiss data protection law, including:

  • Right to be informed about how your data is used
  • Right of access to your personal data
  • Right to rectification of inaccurate personal data
  • Right to erasure ("right to be forgotten") in certain circumstances
  • Right to restrict processing in specific situations
  • Right to data portability for certain data you have provided to us
  • Right to object to processing based on legitimate interests, including profiling
  • Rights in relation to automated decision-making; we do not make decisions with legal or similarly significant effects solely based on automated processing

We answer requests within one month. If a request is complex, or if you have made several at once, we may need up to two further months, and we will tell you within the first month when that happens and why.

You also have the right to lodge a complaint with your local data protection authority. You can contact us first so we can try to resolve any concern.

For users in the EEA, the UK and Switzerland, the controller of your personal information is Zen Design & Solutions, LLC.

8.3 Additional Rights for Residents of California and Some Other US States

If you are a resident of California or certain other US states with comprehensive privacy laws, you may have additional rights, including:

  • Right to know the categories and specific pieces of personal information we collect, use, and disclose
  • Right to request deletion of personal information, subject to certain exceptions
  • Right to correct inaccurate personal information
  • Right to opt out of the "sale" or "sharing" of personal information, as those terms may be defined by law
  • Right to limit the use and disclosure of sensitive personal information, where applicable
  • Right not to be treated differently for exercising your privacy rights

Note: Pantry Persona does not sell personal information or share personal information for cross-context behavioural advertising. If this changes in the future, we will update this Policy and provide any required notices and choices.

8.4 How to Exercise Your Rights

To exercise any of the rights described above, you can:

  • Open Settings and go to the "Data controls" page, where you can download a copy of your data and remove your dietary and allergy details. Account deletion is on the "Danger zone" page of the same Settings area
  • Email us at hello@pantrypersona.com with the subject line "Privacy Request"

We may need to verify your identity before responding to a request, for example by asking you to confirm control of your account or email address. Where your local law permits you to use an authorised agent, we may request proof of that authorisation.

If your local law gives you the right to appeal our response to a request (for example, in certain US states), you can do so by replying to our response and stating that you want to appeal. If you are not satisfied with the outcome, you may also have the right to contact your local regulator.

9. Third-Party Service Providers and Other Sharing

We share personal information with third parties in limited situations, as described in this section.

9.1 Categories of Service Providers

We use third-party service providers that process personal information on our behalf and under our instructions. These providers help us operate, secure, and improve Pantry Persona.

CategoryPurposeTypes of Data Shared
Payment processorsProcess subscription payments, handle billing, and support fraud detectionContact details (such as email), transaction details, limited billing information
Cloud hosting and database providersHost our services, store data, maintain backups, and provide infrastructureAccount data, pantry data, recipes, meal plans, shopping lists, logs and technical data
Authentication and identity providersManage login, tokens, and secure access to your accountEmail address or user identifier, authentication and token data
Analytics and logging providersUnderstand usage trends, diagnose issues, and improve performancePseudonymous usage data, device and technical information, error and performance logs
Email and notification providersSend transactional emails and service-related communicationsEmail address and notification content or metadata necessary for delivery
AI and machine learning service providersPower certain features, such as recommendations and smart pantry suggestionsOnly the information necessary to provide the requested AI feature
Recipe content extraction servicesFetch and parse public recipe content from URLs you submit (web pages, social-media captions, video transcripts, sampled frames)Only the URL you submit; for short-form video URLs, the public caption, transcript, thumbnail, and a small number of sampled frames as published by the platform

When we use external AI or machine learning service providers, they process personal information only to provide services to us and are not permitted to use that information for their own independent purposes (such as training or improving general-purpose models) without an appropriate legal basis and our instructions.

We may change service providers over time. When we do, they will perform similar functions to those described above, and we will require them to protect personal information appropriately.

9.2 Grocery and Shopping Integrations You Choose to Use

Pantry Persona can integrate with certain grocery and delivery platforms so you can send items from your shopping list or recipes directly into a cart or shoppable list on those platforms.

When you use these integrations:

  • We send only the information needed to create or update the cart or list (for example, item names, quantities, product identifiers where available, and sometimes store or location selections)
  • We may receive limited information in return, such as a cart or list identifier, a link, or basic status information indicating whether the action succeeded
  • We do not see your full grocery platform account history, full order history, or full payment details through these integrations

The grocery or delivery platform is an independent company. Its use of your information is governed by its own terms and privacy policy, not this one.

You can disconnect a grocery integration at any time in your Pantry Persona settings (when available). Disconnecting stops new data being shared from that point on, but does not delete information already held by that platform.

9.3 Affiliate Referral Relationships

Some grocery integrations include affiliate referral links. When you send your shopping list to a supported platform (such as Instacart) and place an order, we may receive a referral fee or commission from that platform or its attribution partner (currently Impact.com). This does not change the price you pay. These referral relationships help support Pantry Persona.

9.4 Corporate Affiliates

We may share personal information with our current and future "affiliates," meaning entities that control, are controlled by, or are under common control with us, as reasonably necessary to operate, improve, and secure our services. Where we share personal information with affiliates, they will be required to handle it in a manner consistent with this Privacy Policy.

9.5 Business Transfers

If we are involved in a merger, acquisition, financing, reorganisation, bankruptcy, or sale of all or part of our business, personal information may be transferred to another company as part of that transaction.

That company may use personal information as described in this Privacy Policy or in a successor policy that provides materially similar protection. If any future use of personal information is materially different from the uses described here, we will provide additional notice and obtain consent where required by law.

9.6 Legal Disclosures

We may disclose personal information if we believe in good faith that doing so is reasonably necessary to:

  • Comply with applicable laws, regulations, legal processes, or governmental requests
  • Enforce our terms and agreements
  • Protect the rights, property, or safety of Pantry Persona, our users, or the public

9.7 No Sale or Advertising Use

We do not:

  • Sell personal information for money
  • Share personal information for cross-context behavioural advertising
  • Allow third parties to use personal information for their own independent marketing without your consent

If this ever changes in the future, we will update this Privacy Policy and provide any required notices and choices.

9.8 Third-Party Data Sources

To provide accurate product and nutrition information, we use data from third-party sources:

  • USDA FoodData Central (fdc.nal.usda.gov): The U.S. Department of Agriculture’s open food composition database. Public domain (U.S. Government work). We use this data to compute per-serving nutrition for recipes, including calories, macronutrients, and portion conversions. When you save a recipe from a web page that publishes its own nutrition facts, we keep the page’s numbers and label them as coming from the recipe site. We compute nutrition from USDA data when the page has no facts or they fail our consistency checks.
  • FoodOn (foodon.org): A harmonized food ontology developed by an international academic consortium. Made available under the Creative Commons Attribution 4.0 International (CC-BY-4.0) license. We use FoodOn to map ingredient names to canonical food categories that improve matching accuracy.
  • Open Food Facts (openfoodfacts.org): An open, collaborative database of food products from around the world. Made available under the Open Database License (ODbL). We use this data to match receipt items to product information, including allergens and product categories.

These data sources are open and may not always be complete or accurate, especially for less-common products. We use them to assist with product identification and nutrition computation but encourage users to verify important information such as allergens and dietary values. A consolidated record of dataset licenses is maintained in THIRD_PARTY_LICENSES.md in our open-source repository.

10. Children's Privacy

You need to be at least 16 to use Pantry Persona, or the age of digital consent in your country if that age is lower. In the United States the minimum age is 13.

  • We do not knowingly collect personal information from children below the age that applies where they live
  • If we learn that we have collected personal information from a child below that age without appropriate consent, we will take steps to delete that information as required by applicable law

If you believe a child has provided personal information to Pantry Persona, please contact us using the details below.

11. Changes to This Policy

We may update this Privacy Policy from time to time.

When we make changes:

  • We will update the "Last updated" date at the top of this page
  • For material changes, we may provide additional notice, such as a prominent notice in the product, an email, or a message within an MCP host that uses Pantry Persona

Your continued use of Pantry Persona after an updated Privacy Policy becomes effective means that you accept the updated Policy.

12. Contact and Controller Information

If you have questions about this Privacy Policy or how we handle personal information, or if you want to exercise your privacy rights, you can contact us at:

Email: hello@pantrypersona.com

Post: Zen Design & Solutions, LLC, 733 Struck St, PO Box 44593, Madison, WI 53744, United States

Pantry Persona is operated by Zen Design & Solutions, LLC, which is the controller of personal information processed under this Privacy Policy unless stated otherwise in a specific context.