Privacy Policy
Last updated: May 28, 2026
Effective date: May 28, 2026
This Privacy Policy describes how the FridgeMind mobile application ("FridgeMind", "the App", "we", "our") handles information when you use it. By installing or using the App, you agree to the practices described below.
- App name: FridgeMind
- Platform: iOS
- Developer: Syahrul Ahmad Saputra
- Contact: ccrdevbusiness@gmail.com
1. Summary
FridgeMind is a local-first app. The vast majority of your data — your pantry items, recipes, meal plans, shopping list, notification preferences, name, calorie goal, diet preference, and allergies — is stored only on your device and is never sent to us or to any server.
The App contacts three third-party services in narrowly defined situations:
- Firebase Analytics & Crashlytics (Google) — anonymous usage events and crash diagnostics.
- OpenRouter — when you tap Scan to identify an ingredient from a photo, or when you tap Generate in the Recipes tab. Only the minimum data required to fulfill that request is sent.
- RevenueCat / Apple App Store — when you start, restore, or manage a subscription.
We do not require an account, do not collect names or email addresses, do not track you across apps, and do not sell your data to anyone.
2. Information stored on your device only
The following data is stored in the App's local database, Apple's SwiftData, or in iOS user defaults, on your device only:
- Pantry items, including name, quantity, unit, dates, storage info, and emoji.
- Saved recipes, including title, ingredients, steps, and nutrition notes.
- Meal plan slots, including date, time, recipe reference, and reminder preference.
- Shopping list items, including name, quantity, and unit.
- Profile values you enter, including your name, daily calorie goal, diet preference, and allergies.
- App preferences, including dark mode, units, and notification preferences.
- Counters for free-tier limits, scan count, AI search count, and the date they last reset.
- Recent AI search queries, up to 5 most recent, on-device only.
- Your current premium status flag, true or false.
This data does not leave your device unless you intentionally use the AI scan or AI recipe features described below.
If you uninstall the App, all of this data is deleted with it.
3. Information sent to third-party services
3.1 Firebase Analytics & Crashlytics (Google LLC)
When the App can configure Firebase, the following anonymous events are sent to Google:
- App lifecycle events:
onboarding_started,onboarding_completed,tab_opened,settings_opened. - Feature usage events:
scan_started,scan_completed,pantry_item_added,recipe_search_started,recipe_saved. - Commerce events:
paywall_viewed,purchase_started,purchase_completed,purchase_failed.
Each event may carry up to three generic parameters: tab_name, source, result. Each event is additionally tagged with is_premium, boolean, so we can segment which features paying vs. free users use.
Firebase NEVER receives:
- Your name, calorie goal, diet preference, or allergies.
- Ingredient names, recipe titles, meal slot names, or shopping items.
- Pantry contents, quantities, expiry dates, or storage info.
- Your AI scan images or AI search queries.
- Any text or data returned by our AI provider.
- IDFA / IDFV identifiers for cross-app tracking. The App does not request App Tracking Transparency permission and does not pass any identifier for advertisers to Firebase.
Crashlytics receives the standard iOS crash trace if the App crashes, which may include the function and module names where the crash occurred, the iOS version, and the device model. It does not include the app's content data, such as pantry, recipes, or similar data.
Google's handling of this data is governed by Google's Privacy Policy at https://policies.google.com/privacy and Firebase's privacy and security documentation at https://firebase.google.com/support/privacy.
3.2 OpenRouter (AI inference)
The App contacts OpenRouter, https://openrouter.ai, only in these four situations:
- AI Scan — when you tap the capture button in the Scan tab. We send the photo bytes, base64-encoded over HTTPS, to OpenRouter for analysis. The image is not stored by the App on your device or on our servers. We do not retain it after the request completes.
- AI Recipe Search — when you type a query and tap Generate. We send your query text and a list of your pantry ingredient names, names only — no quantities, no expiry data, no IDs, to OpenRouter so it can suggest relevant recipes.
- From Pantry recipes — same as above with a fixed query.
- Healthy recipes — same as above; we also include your daily calorie goal as numeric context for the prompt.
OpenRouter is not contacted when you launch the App, browse pantry, browse saved recipes, open meal plan, open shopping list, or open settings.
OpenRouter's handling of this data is governed by their Privacy Policy at https://openrouter.ai/privacy and Terms of Service at https://openrouter.ai/terms.
3.3 RevenueCat & Apple App Store (subscriptions)
When you purchase, restore, or manage a subscription, the App uses the RevenueCat SDK to facilitate the transaction with Apple's App Store servers. RevenueCat receives the Apple transaction identifier and an anonymous device identifier so it can determine whether your subscription is active. RevenueCat does not receive your name, email, or contents of the App.
Apple's role in processing the purchase is governed by Apple's standard policies at https://www.apple.com/legal/privacy/. RevenueCat's handling is at https://www.revenuecat.com/privacy.
4. Photos and camera
The App requests camera permission so you can take a photo of an ingredient inside the Scan feature. Photos:
- Are held in memory only for the duration of the network call to OpenRouter.
- Are never written to your device's photo library, the App's local storage, or any iCloud backup of the App.
- Are never sent to Firebase, RevenueCat, Apple, or any of our own servers.
We do not request access to your existing photo library unless you tap the Gallery button inside Scan. Even then, the selected photo follows the same rules as a captured photo — used once for the AI request, then released.
You can revoke camera or photo library permission at any time in iOS Settings → Privacy & Security.
5. Notifications
Local notifications, including expiry alerts, meal reminders, and weekly summary, are scheduled by the App locally on your device. The notification content, such as "Apple expires in 2 days", is generated on your device and shown to you by iOS. Notification content never leaves your device.
You can disable any or all notification types in Settings → Notifications inside the App, or globally in iOS Settings.
6. AI output disclaimer
AI-generated values shown in the App — including estimated calories, shelf life, storage advice, nutrition notes, and any recipe content — are estimates only. They are not medical, nutritional, dietary, or professional advice. Always consult a qualified professional for dietary, allergy, or medical decisions.
7. Children's privacy
The App is rated 4+ on the App Store. It does not knowingly collect personal information from anyone, including children under 13. The App does not require an account, does not collect names or email addresses, and the only "personal" fields, such as name, calorie goal, diet, and allergies, are optional and stored only on your device.
If you are a parent or guardian and you have questions about this App, please contact us at the email above.
8. Your choices and rights
Because the App stores your content only on your device and does not maintain user accounts on our servers:
- Access — your data is fully visible inside the App at all times.
- Correction — you can edit any value, such as pantry, recipes, or profile, inside the App.
- Deletion — deleting an item in the App removes it from local storage. Uninstalling the App removes all of your data from your device permanently.
- Withdrawal of consent — uninstalling the App stops all data processing by the App.
You can also revoke individual iOS permissions, such as camera, photos, and notifications, in iOS Settings → Privacy & Security at any time.
If you live in a jurisdiction with applicable data protection laws, such as GDPR, CCPA, UK GDPR, or PDP Indonesia, you may have additional rights including the right to lodge a complaint with your local data protection authority. Because we do not maintain user accounts or hold your content on any server, requests for access or deletion of "data held by us" generally do not apply — uninstalling the App is the equivalent action.
For questions about your rights, contact us at the email above.
9. Data retention
- On-device data: retained until you delete the item or uninstall the App.
- Firebase Analytics: Google's default retention applies, currently 14 months for event data, unless we shorten it. We do not extend it.
- Firebase Crashlytics: crash reports are retained for 90 days per Firebase defaults.
- OpenRouter requests: governed by OpenRouter's privacy policy. We do not request retention beyond what is needed to fulfill the request.
- RevenueCat / Apple: retained per their policies for subscription verification.
10. International data transfers
The third-party services we use may process data outside your country of residence, including Google in the United States and other regions, OpenRouter in the United States, Apple in the United States, and RevenueCat in the United States. By using the App you understand that anonymous analytics, crash diagnostics, and the AI/subscription requests described above may be transferred to and processed in these jurisdictions.
11. Security
We use HTTPS for all network requests. API keys are stored in the App binary and are protected by Apple's code signing. No personal account credentials are collected by the App.
No transmission over the internet is 100% secure. While we use industry-standard protections, we cannot guarantee absolute security.
12. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. The "Last updated" date at the top of this document reflects the most recent revision. Material changes will be communicated through the App or via the App Store update notes. Continued use of the App after a change indicates acceptance of the revised policy.
13. Contact
For privacy questions or requests, contact:
Syahrul Ahmad Saputra
Email: ccrdevbusiness@gmail.com