KitchenKeepr, LLC (“KitchenKeepr”, “we”, “our”, or “us”) is committed to protecting your privacy. This Privacy Policy explains what information we collect when you use the KitchenKeepr mobile application and website (collectively, the “Service”), how we use it, who we share it with, how long we keep it, and the choices you have.
We collect two categories of health-related data that are stored differently:
Stored on our servers (Supabase):
Stored on your device only (not transmitted to our servers):
Transmitted to OpenAI for AI meal plan generation:
When you generate a meal plan, your household dietary preferences, pantry contents, macro targets, and health profile context (activity level, calorie goal) are automatically included in the generation request sent to OpenAI. You do not need to take any additional action for this to occur — it happens as part of the normal meal plan generation feature. See Section 4 (Consumer Health Data) for additional disclosures.
The following data is stored on our servers, not locally on your device:
When you use the “Order Groceries” feature, your shopping list items are passed to your selected grocery partner (Instacart or Walmart) to pre-populate your order. We do not store your payment information — all payment transactions are handled directly by the grocery partner.
We do not use your data for advertising or sell it to advertisers.
California and other state laws require us to disclose, for each category of personal information we collect, the purpose for which we collect it, who receives it, and how long we keep it.
| Category | Purposes | Recipients | Retention Period |
|---|---|---|---|
| Account & contact information (name, email, login credentials, support communications) | Create and maintain your account; authenticate you; send transactional emails; provide customer support | Supabase (authentication and storage); Resend (transactional email) | Active account life plus 3 years after account deletion, except where a longer period is required by law |
| Profile, nutrition, and preference information (dietary preferences, allergies, pantry items, meal plans, shopping lists, recipes) | Personalize meal plans, shopping suggestions, and app features; generate AI content | Supabase (storage); OpenAI (AI generation, transmitted at time of each request) | Until you delete the data, until account deletion, or until no longer reasonably necessary for the disclosed purpose |
| Health & wellness data (height, weight, age, activity level, calorie and macro goals — see also Section 4) | Personalize macro calculations and AI meal planning | Supabase (storage); OpenAI (AI generation, transmitted at time of each request) | Same as profile and preference data above |
| Device, log, and diagnostic data (device type, operating system, app version, crash data, error stack traces) | Operate, secure, troubleshoot, and improve the Service | Sentry (error monitoring and crash reporting) | 12 months from collection |
| Usage and analytics data (screen views, feature interactions, session events — pseudonymous) | Understand how the Service is used; improve features and user experience | Mixpanel (product analytics); first-party database | 12 to 24 months from collection |
| Location data (approximate device location when store-finder feature is used) | Find nearby grocery stores via Google Places | Google Places API (queried at time of each request, not retained by us) | Not stored — used only at the time of the request |
| Transaction and subscription data (subscription status, order identifiers, billing metadata received from app stores or RevenueCat) | Manage subscriptions; verify entitlements; prevent fraud; maintain financial records | RevenueCat (subscription management); Apple App Store and Google Play (billing platform) | 7 years from transaction date for tax, accounting, and audit obligations |
| Community aisle contributions (aisle location data for products — anonymized at submission) | Improve aisle location suggestions for all users | Our database; not shared externally | Retained indefinitely in anonymized form; not linked to your account |
We do not collect personal information for materially different purposes or disclose it to additional categories of recipients without providing you with additional notice as required by applicable law.
Some information you provide through KitchenKeepr may be considered “consumer health data” under certain state laws, including the Washington My Health My Data Act. This includes personal information linked or reasonably linkable to you that identifies your past, present, or future physical or mental health status. In KitchenKeepr, this includes:
We collect consumer health data only (a) with your consent for the specific disclosed purpose (meal planning and nutrition personalization), or (b) as necessary to provide a product or service you requested.
We transmit health-adjacent data to OpenAI solely to generate the meal plans and recipes you request. We do not share consumer health data for advertising, marketing, analytics, or any purpose beyond providing the Service. OpenAI processes this data as a service provider under API terms that restrict its use.
You may withdraw consent for future collection or sharing of consumer health data at any time by:
KitchenKeepr uses the following third-party services, each subject to their own privacy policies. Where required by applicable law, we maintain service-provider or data-processing agreements with these vendors restricting their use of personal information to the purposes for which it is disclosed.
We do not sell your personal information to any third party.
The KitchenKeepr mobile application does not use browser cookies. The app includes the following third-party software development kits (SDKs) that collect information automatically:
Our website may use analytics tools (such as server-side access logs or page analytics) to understand site traffic and improve the site experience. We do not use third-party advertising cookies or sell web browsing data to advertisers.
Server-side storage (Supabase, hosted in the United States):
Your account information, household and member profiles, health profile inputs (height, weight, age, activity level, macro targets), grocery inventory items (including barcodes), meal plans, shopping lists, recipes, and cooking schedules are stored in Supabase’s managed PostgreSQL database.
Device-only storage:
Daily body weight entries, sleep logs, and workout logs are stored locally on your device using encrypted on-device storage and are not uploaded to our servers.
Transmitted to third parties for service delivery:
Your household dietary preferences, pantry contents, macro targets, and health profile context are transmitted to OpenAI when you use AI meal plan generation. Crash and error data are transmitted to Sentry. Feature usage data is transmitted to Mixpanel. Subscription and purchase data is transmitted to RevenueCat.
Security measures:
No security measure is perfect or impenetrable. In the event of a security incident that requires notification under applicable law, we will follow applicable breach notification requirements.
The specific retention periods for each category of data are set out in Section 2. In summary:
KitchenKeepr is not directed to children under the age of 13 and we do not knowingly collect personal information from children under 13. Where our signup flow includes an age confirmation step, that step occurs before we collect personal information other than what is minimally necessary to perform the age-screening function.
If we learn that we have collected personal information from a child under 13 without the consent required by applicable law, we will delete that information promptly. If you believe a child has provided us with personal information, please contact us at support@kitchenkeepr.com and we will investigate and delete it promptly.
Users between 13 and 18 years of age must have a parent or legal guardian’s permission to use the Service.
Depending on where you live, you may have the right to request access to the personal information we maintain about you, request correction of inaccurate information, request deletion, receive a copy of certain information in a portable format, and opt out of certain processing or disclosures. We will not discriminate against you for exercising your privacy rights.
You may: (a) email us at support@kitchenkeepr.com with “Privacy Request” in the subject line, or (b) submit a data rights request using our online form.
We will verify your identity using methods appropriate to the nature and sensitivity of the request. We will not require you to create a new account to exercise your rights.
We will respond within 45 days of receiving a verifiable request. If we need additional time (up to 90 days total where permitted by law), we will notify you of the extension within the initial 45-day period and explain the reason.
If we deny your request in whole or in part, we will explain why. Where applicable law provides an appeal right, we will inform you how to submit an appeal.
California residents additionally have: the right to know what personal information we collect, use, disclose, and share; the right to opt out of the sale or sharing of personal information (we do not sell or share personal information for cross-context behavioral advertising); the right to limit use and disclosure of sensitive personal information; and the right to non-discrimination for exercising privacy rights.
Washington residents have additional rights under the Washington My Health My Data Act with respect to consumer health data as described in Section 4, including the right to withdraw consent for future collection or sharing.
Under the Texas Data Privacy and Security Act, Texas residents may also have rights to access, correction, deletion, and portability of personal information we process, subject to applicable exemptions.
We are based in the United States and process and store personal information in the United States and in other countries where our service providers operate. By using the Service, you acknowledge that your personal information may be transferred to, processed in, and stored in the United States, where privacy and data protection laws may differ from the laws in your country.
The Service is currently offered only to users in the United States. If we later offer the Service to individuals in the European Economic Area, the United Kingdom, or Switzerland, we will provide additional jurisdiction-specific disclosures regarding legal bases for processing, cross-border transfer mechanisms (such as standard contractual clauses), your rights under applicable law, and any required local representative information before doing so.
We may update this Privacy Policy from time to time. When we do, we will update the “Effective Date” above. If the changes are material, we will notify you via the app or by email at least 14 days before the changes take effect.
If you have questions or concerns about this Privacy Policy or our data practices, please contact us: