Pantry · Privacy
Pantry Privacy Policy
Last updated September 22, 2026. This policy describes the Pantry system currently in development and will be updated if the product’s data practices change before launch.
New Tab Web Solutions, LLC (“New Tab,” “we,” “us,” or “our”) is developing Pantry, a grocery inventory and household planning product for iOS and Android. This Privacy Policy explains how the current Pantry application and backend handle information. Pantry is not currently available for public download, and features described as planned are not treated as current data practices.
1. Information you provide
Depending on the Pantry workflow you use, the current system may process:
- account information such as first name and email address, plus an optional phone number supported by the current account system;
- password information in the form of a server-side password hash rather than a readable password;
- household information such as a household name, membership, role, and active membership status;
- inventory information such as product names, barcodes, categories, preferred stores and brands, package and unit details, quantities, storage locations, notes, descriptions, manufacturers, ingredients, tracking settings, and replenishment settings;
- inventory activity such as consume, restock, audit, scanned-code, quantity, note, user, and timestamp information;
- shopping, price-comparison, recipe, recipe-ingredient, and meal-plan information when those backend workflows are used; and
- product or inventory images that you upload during item setup.
2. Camera and product lookup information
Pantry’s scanner can use your device camera to read product barcodes. The current mobile app requests camera access for that purpose. Camera frames are used by the scanner workflow; the audited Pantry source does not save camera video or photos from the scanner itself.
When an unknown barcode is looked up during product setup, the backend may send the barcode and lookup request to configured food-data providers. The current code supports USDA FoodData Central, Open Food Facts, and a limited UPCitemdb fallback. Provider fields may include product identity, brand, category, quantity, stores, ingredients, and image URLs. Pantry may download a selected provider image to its own item storage. Existing locally saved UPCs use the local Pantry record instead of calling a provider.
3. Information stored on your device
The current Flutter client stores its access token using the platform secure-storage plugin. It also caches account and household identity, inventory items, inventory events, and queued offline consume actions in local application preferences so the app can show cached information and synchronize later. The contents of local device storage are controlled in part by your device and operating-system settings.
4. How we use information
We use current Pantry information to create and authenticate accounts, establish household access, display and synchronize inventory, process inventory actions, maintain activity history, build shopping and planning records, support barcode and product lookup workflows, store selected item images, and operate and troubleshoot the service.
5. Household information
Pantry is designed around household data. Active household members may be able to access information associated with the household through the access rules implemented by the Pantry backend. Do not add information to a shared household that you do not want other authorized household members to see. Household invitation, removal, and deletion behavior is still being expanded and should not be understood as a completed privacy-control workflow.
6. Authentication and security
The current backend uses password hashing for account passwords. Mobile API access uses bearer tokens that expire and can be revoked; the backend stores token hashes rather than the raw bearer token. Pantry also uses household membership checks for current API data access.
These are safeguards in the current implementation, not a guarantee that any system is completely secure. The production deployment, hosting controls, transport configuration, backups, and operational security procedures must be reviewed before Pantry is publicly launched.
7. Service providers and sharing
The audited Pantry source does not contain advertising, behavioral tracking, analytics, crash-reporting, push-notification, Apple/Google billing, Stripe, or RevenueCat integrations. Those areas are not currently implemented in the audited application and backend.
Pantry may use the food-data providers described in Section 2 when a barcode lookup is requested. The current repository does not establish the production hosting provider, processing regions, backup provider, or server-log configuration. Those details must be confirmed and this policy updated if they introduce additional processing or sharing before launch.
8. Subscriptions and payments
The current Pantry application and backend do not implement subscriptions, in-app purchases, payment processing, or server-side receipt validation. Any future subscription or payment practices will be described in an updated policy before those features are made available.
9. Retention and deletion
The current code does not define public retention periods for accounts, household records, inventory, images, activity logs, backups, or server logs. The current Pantry system also does not provide an account-deletion route or an automated account-deletion workflow. Deleting an inventory item is not the same as deleting an account.
If you have a privacy or account-deletion question, contact us using the Pantry support page. This website cannot delete a Pantry account, and a request may require confirmation and review against the actual Pantry backend records and available deletion capabilities.
10. Analytics, notifications, and tracking
No analytics, advertising, cross-context tracking, crash-reporting, or push-notification integration was found in the audited Pantry source. The product may receive additional integrations before launch; this policy will be updated before any such functionality is made available.
11. Children
Pantry is a household grocery application and is not directed to children. We do not knowingly design Pantry to solicit personal information from children. If you believe a child has provided information to Pantry, contact us so we can review the situation.
12. Your questions and privacy requests
You may contact us with questions about information associated with your Pantry use, or to ask about access, correction, or deletion options that are available in the current system. Depending on where you live, applicable law may provide additional privacy rights. We will review requests in light of the current implementation and applicable requirements; this policy does not promise a particular response time or outcome.
13. Changes to this policy
We may update this Privacy Policy as Pantry, its backend, its providers, or its legal requirements change. The “Last updated” date identifies the current version. We will publish the updated policy at this URL before material new data practices are made available through Pantry.
14. Contact
Pantry is operated by New Tab Web Solutions, LLC. For privacy questions, use the Pantry support page or contact contact@newtabwebsites.com.