Privacy Policy — Merlin's Pantry
Effective date: 8/1/2026
Merlin's Pantry ("the app", "we", "us") is operated by Gerald Tilghman. This Privacy Policy explains what information we collect, how we use it, who we share it with, and the choices you have. By creating an account and using the app, you agree to this policy.
1. A quick summary
- You need an account (email + password) to use the app.
- We store the personal recipes you create and a list of the recipes you save. Your pantry ingredient list stays on your device.
- We send your ingredient list to recipe providers to find matching recipes, and your pantry text to an AI provider if you use the "Synthesize a recipe" feature.
- If you use the optional "Snap a recipe" feature, the photo you take or choose is sent to an AI provider to read the recipe, then discarded — we don't store the photo.
- We do not use advertising or analytics trackers and do not sell your data. The app accesses your camera or photo library only when you use "Snap a recipe" (with your permission); it does not access your location or contacts.
- You can delete your account and all associated data from within the app at any time.
2. Information we collect
a. Account information. When you sign up we collect your email address and a password. Authentication is handled by our backend provider (Supabase); your password is stored by that provider in hashed form and is never visible to us.
b. Content you create.
- Personal recipes you add (title, ingredients, instructions, optional category) are stored on your device and synced to your account so they're available across your devices.
- Saved recipes. For recipes from third‑party providers (Spoonacular, TheCocktailDB) and our own recipe catalog, we save only a reference (an ID and source) — not the recipe's content — and re‑fetch the details when you open it. This is both a privacy and a licensing measure.
- A "share with community" preference on each personal recipe. This is off by default; a recipe is never made discoverable to other users unless you explicitly turn it on. (Community discovery is a planned feature and is not active yet.)
c. Your pantry list. The ingredients you enter stay in local storage on your device. We do not upload or store your pantry list on our servers.
d. Information collected automatically. To deliver the app and provide support we (or our infrastructure providers) process standard technical data such as device type/model, operating‑system version, app version, and IP address. If you use the in‑app "Send feedback" button, your email app is opened with your app version, platform, OS version, and device model pre‑filled so you can include them — nothing is sent unless you send the email.
e. Photos you scan (optional). If you use "Snap a recipe," you choose a photo (from your camera or photo library, with your permission) of a recipe. That image is sent to our AI provider (Google Gemini) to read the recipe into text. We do not store the photo — it is used only for that single request and then discarded. Only the extracted text (title, ingredients, steps) is kept, as a personal recipe you review and save. We never access your camera or photo library unless you tap this feature.
f. What we do not collect. We do not integrate advertising SDKs or third‑party analytics/tracking tools. Apart from the optional "Snap a recipe" photo above, the app does not request access to your microphone, location, contacts, or health data.
3. How we use your information
We use the information above to:
- Create and secure your account and sign you in;
- Store and sync your personal recipes and saved‑recipe list across your devices;
- Find recipes that match the ingredients you enter;
- Generate a recipe on request (the "Synthesize" feature);
- Respond to support requests and beta feedback;
- Maintain security, prevent abuse, and comply with legal obligations.
We do not sell your personal information, and we do not use it for advertising or cross‑app tracking.
4. How your information is shared
We share data only with service providers that help us run the app, and only to the extent needed. We do not sell data to anyone.
- Supabase — backend hosting: account authentication, and storage of your personal recipes and saved‑recipe references. Data is stored in the United States.
- Recipe providers — when you search, your ingredient list (and chosen category) is sent to Spoonacular and, for cocktails, TheCocktailDB; our own recipe catalog is sourced from TheMealDB and openly‑licensed content. These requests contain the ingredients you type, not your identity.
- AI providers (Google Gemini / Groq). If you use "Synthesize a recipe," your pantry ingredient text and chosen category are sent to generate a recipe (text only). If you use "Snap a recipe," the photo you provide is sent to Google Gemini to read the recipe into text. These requests run on Google's paid API tier, under which your prompts and images are not used to train Google's models, and we do not store the photo — only the extracted recipe text is kept. Groq is used as a text fallback.
- Expo / EAS — delivers the app and over‑the‑air updates, and processes standard delivery/update and device metadata in the course of doing so.
API keys for these providers are held on our server, so the providers do not receive your account credentials.
We may also disclose information if required by law, to protect our rights or users' safety, or in connection with a business transfer.
5. AI‑generated recipes — important notice
Recipes generated by the app, or read from a photo you scan (via Google Gemini / Groq), are general information, not medical, dietary, or nutritional advice. AI output — including text read from a photo — can be inaccurate or incomplete, so scanned recipes are always shown for you to review and correct before saving. Always verify ingredients and check for allergens yourself before cooking or eating. We are not responsible for the accuracy of AI‑generated content.
6. Data retention
We retain your account and content for as long as your account is active. When you delete your account (see below), your account and the data associated with it are removed from our systems. Your on‑device data (pantry list, local copies) is removed when you delete the app or clear its data. Backups and provider logs may persist for a limited period as part of routine operations.
7. Your rights and choices
- Delete your account and data. You can permanently delete your account and its associated data from within the app (Account → Delete account). This cannot be undone.
- Access and correction. You can view and edit your personal recipes in the app. To request a copy of your data or ask us to correct it, contact us at privacy@tilghman.com.
- Community sharing. The per‑recipe "share with community" setting is off by default and can be changed at any time.
- EEA/UK (GDPR). If you are in the European Economic Area or the UK, you have rights to access, rectify, erase, restrict, and port your data, and to object to certain processing. Our legal basis is performance of our agreement with you (providing the app) and our legitimate interests in operating and securing it.
- California (CCPA/CPRA). If you are a California resident, you have the right to know what personal information we collect, to request deletion, and to correct it. We do not sell or "share" your personal information as those terms are defined under California law.
To exercise any of these rights, contact privacy@tilghman.com.
8. Children's privacy
Merlin's Pantry is not directed to children under 13 (or the equivalent minimum age in your jurisdiction), and we do not knowingly collect personal information from them. If you believe a child has provided us information, contact us and we will delete it.
9. Security
We use industry‑standard measures to protect your data, including encryption in transit (HTTPS) and database access controls that restrict each user's data to that user (row‑level security). Passwords are hashed by our authentication provider. No method of transmission or storage is 100% secure, but we work to protect your information.
10. International users
The app is operated from, and stores data in, the United States. If you use the app from outside the U.S., your information will be transferred to and processed in the U.S. and other countries where our service providers operate.
11. Changes to this policy
We may update this policy from time to time. We will post the updated version with a new effective date and, where appropriate, notify you in the app. Continued use after an update means you accept the revised policy.
12. Contact
Questions about this policy or your data: privacy@tilghman.com, operated by Gerald Tilghman.