PantryPilot
Privacy Policy
Last updated August 25, 2026.
PantryPilot is a recipe and meal-planning service. This page describes the data this application actually stores today. It is not a claim of certification or a substitute for your own legal review.
What we store
- Account details: name, email, and sign-in provider records needed to authenticate you.
- Kitchen preferences you enter: diet, goals, allergies, servings, weeknight time, AI toggles, and optional cook notes. Allergies and medical needs are never inferred.
- Recipes, meal plans, generation history, ratings, and share records you create. Share links are private by default, tokenized, and artifact-only.
- Cached USDA FoodData Central lookups used to estimate nutrition. Those cache rows are food mappings, not a profile of you.
Cookies
Signed-in sessions use an essential Better Auth cookie. It is HttpOnly, SameSite=Lax, and Secure in non-local environments. PantryPilot does not currently set advertising or analytics cookies. A dismissible notice explains this; it does not block the app behind a consent wall because there are no optional tracking cookies to opt into.
AI and logs
Recipe and meal-plan generation use Workers AI through a configured gateway. Raw prompts, session tokens, OAuth secrets, and USDA keys are not written to application logs. AI text is untrusted and is not rendered as HTML.
Export and delete
Signed-in cooks can export a JSON copy of their account data or permanently delete the account from Profile. Deletion removes the account, saved artifacts, history, and shares.
Open Privacy & data in your profile · Download a data export
Export and delete require a signed-in session. If you are signed out, those links will ask you to sign in first.