Privacy Policy
InStock Kitchen Privacy Policy
Last Updated: September 4, 2026 — applies to InStock Kitchen for iOS and Android, including its optional Apple Watch and Wear OS companion apps
InStock Kitchen ("we", "the app") is designed with privacy as a first principle. This policy explains what the iOS, Android, and optional paired-watch apps handle, where data goes, why it is used, and how long it is retained.
Summary
- No accounts. The app does not require sign-up or login.
- No ads or cross-app tracking. The app has no advertising, attribution, or cross-app tracking SDKs.
- No sale of data. We do not sell data or share it for advertising or behavioral profiling.
- Recipe submission is optional. Beginning with iOS v1.4 and Android v1.1, you can choose to send one custom recipe and its photo to the InStock Kitchen team for manual review. You may submit anonymously or separately opt in to include a name and email address for follow-up.
- AI, your choice. AI Photo Scan and AI recipe cleanup use our private service by default. Privacy Mode prevents photos and recipe text from going to that service.
- Platform-specific storage. iOS can sync through your private iCloud account. Android stores data locally and may use Android Auto Backup in your own Google account. Optional paired-watch companions receive only the content needed for their watch features.
- Limited operational data. Our service keeps device-linked usage and job records for feature limits and reliability. Google ML Kit also sends limited Android SDK diagnostics and usage metrics to Google, but not your images, recognized text, or recognition results.
What the app does not ask for or collect
- Your name or email, unless you separately choose to include both with a recipe submission. The app does not ask for your phone number, contacts, location, age, Apple ID, or Google Account identity.
- Your calendars, microphone recordings, list of installed apps, or files you did not choose for an app feature.
- Your entire photo library. The app receives only images you take in the app or explicitly select.
- Your inventory, shopping and saved lists, scan history, or custom recipe library on our service, except for content involved in an AI or sharing action you choose.
- Advertising profiles or cross-app behavioral-tracking data.
AI features
InStock Kitchen has two AI features: AI Photo Scan, which identifies groceries from photos, and AI recipe cleanup, which turns imported recipe text into clean ingredients and steps.
Our private service (the default)
When Privacy Mode is off, the app sends only the content needed for the AI feature you choose:
- Photo Scan. The app sends an optimized copy of each selected image and the scan mode. A temporary upload copy may be kept in app-private storage for reliability; it is normally removed after upload, and leftover copies are targeted for cleanup within about 24 hours, subject to operating-system scheduling. Source photos are handled temporarily while the request is processed and are not kept as a lasting photo library. Detected item names are retained for up to 14 days so the result can be delivered or recovered, then deleted automatically.
- Recipe cleanup. The app sends the title, ingredients, and steps you chose to import. The source text and cleaned result are deleted when the app fetches the completed result, or after about 1 hour if it is never fetched.
- Installation registration. Requests use a random identifier created for that app installation, plus platform, app version, and timestamps. It is not derived from a hardware identifier or connected to your name, email, payment-card or bank-account credentials, Apple ID, or Google Account identity. On iOS, the service may also retain an APNs token for scan-ready notifications. Android scan-ready notifications are generated locally and do not use Firebase Cloud Messaging.
- Usage and reliability records. Rolling counts enforce feature limits. Technical job records include duration, success or failure, error type, and model version. These records are linked to the installation identifier but contain no source photo or recipe text.
- No human review or training. No person reviews your photos or recipe text as part of normal processing, and we do not use your content to train AI models.
On your device
- iOS. Supported devices can download InStock Kitchen's optional on-device AI model and run Photo Scan and recipe cleanup on the iPhone. Apple on-device frameworks also support label and text reading.
- Android. Barcode detection and label/text reading use Google ML Kit on the device; local rules handle the resulting text. Camera images, recognized text, and recognition results are not sent to Google for these operations. ML Kit may contact Google for fixes, model updates, and compatibility information and sends limited SDK diagnostics and usage metrics as described below.
Privacy Mode
Privacy Mode prevents AI photos and recipe text from being sent to InStock Kitchen's AI service. When Privacy Mode is on, the app asks for one-time permission before sending only that recipe to InStock Kitchen. The permission applies only to that submission, and Privacy Mode remains on for everything else. The app uses available on-device tools instead, so AI results can be less detailed or accurate. Privacy Mode does not disable every network feature or platform service. Barcode lookup, a recipe URL you choose to import, sharing with a friend, platform backup, paired-watch companion sync, and limited ML Kit operational communications may still occur.
Storage, sync, and backups
iOS and iCloud
If you are signed in to iCloud, the iOS app can synchronize your inventory, user-selected inventory and recipe images, learned item names, recipes, shopping lists, and saved lists through Apple's CloudKit private database. The data stays in your private iCloud account under Apple's privacy terms; InStock Kitchen does not receive a server copy. You can turn off iCloud for the app in iOS Settings, and Delete iCloud Data removes the app's synchronized iCloud data.
Android and Auto Backup
Android does not use InStock Kitchen cloud sync between phones. App data is stored in the local database and private files. If Android Auto Backup is enabled, Android may back up the database, custom inventory and recipe images, and preferences to a private area of your Google Drive account for restoration. InStock Kitchen does not receive your Google Account identity or a copy of that backup. The server identifier and token, temporary uploads, caches, and model files are excluded from backup and device transfer. You control backup in Android system settings under Google's privacy policy.
Paired watch companions
If you use the optional Apple Watch or Wear OS companion, the phone shares only the shopping, recipe, and cooking information needed for the watch features through the platform's paired-device services. The watch may keep an app-private local cache and pending changes so those features can work while temporarily disconnected. This content is not sent to InStock Kitchen's AI service. A disconnected watch may retain cached content until it reconnects and synchronizes, the companion app is cleared or uninstalled, or the watch is reset.
Services and providers
Network requests occur only for features you use and platform services:
- InStock Kitchen and Cloudflare. Selected AI content, the random installation identifier, and limited request data are sent over HTTPS to our private AI service when Privacy Mode is off. Cloudflare provides hosting and transport for the website, model downloads, private AI requests, temporary friend-sharing links, and the private storage used when you directly submit a custom recipe for manual review. Cloudflare may process ordinary connection data such as IP address under its privacy policy. InStock Kitchen does not intentionally retain IP addresses as an app-data field.
- Apple. Apple provides private iCloud sync, StoreKit purchases, optional platform diagnostics, and iOS push notifications. Scan-ready push messages contain only a job reference, never a photo, grocery details, item names, or recipe text.
- Google. Google provides Android Auto Backup, Google Play Billing and Developer API purchase verification, refund and void status, and platform diagnostics. ML Kit collects device and app information, per-installation identifiers, performance and configuration metrics, feature events, and error codes for diagnostics and usage analytics. Google says this data is encrypted in transit and not transferred to third parties. ML Kit does not send your images, recognized text, or recognition results to Google. See Google's ML Kit Android data disclosure.
- Hugging Face. It may serve as a fallback host for the optional iOS on-device model. Model-download providers may process IP address and ordinary connection data; the app does not attach its InStock installation identifier.
- Open Food Facts and USDA FoodData Central. Both apps send only the barcode number to Open Food Facts for product details. The iOS app may also query USDA if needed; Android v1.0 does not use USDA. No InStock account or installation identifier is attached.
- Recipe websites. When you import an HTTPS recipe link, the selected website receives a normal request while the app reads its recipe data. The recipe text may then use our AI cleanup service when Privacy Mode is off.
Recipe sharing
- Share with InStock Kitchen. Beginning with iOS v1.4 and Android v1.1, after you confirm that you created the recipe or have permission to share it, tapping Share Recipe securely uploads that single custom recipe, its canonicalized ingredient information, and its hero photo if one exists for manual review. The submission includes no InStock account, device identifier, installation identifier, inventory, scan history, or other recipes. Name and email are absent unless you turn on the separate optional contact switch and enter both fields. Contact information is used only to follow up about that submission. Submissions are never added to the app automatically and are not used to train AI. When Privacy Mode is on, the app asks for one-time permission before sending only that recipe to InStock Kitchen. The permission applies only to that submission, and Privacy Mode remains on for everything else. See the Recipe Submission Terms.
- Share with a friend. To create a short link, the app sends the selected recipe and its optional compact hero image to temporary Cloudflare storage. If a short link cannot be created, the app may instead use a self-contained link that stores nothing on our infrastructure. When Privacy Mode is on, the app asks for one-time permission for that share before sending the recipe to create the short link. The stored content contains no InStock account or installation identifier and is deleted automatically within 10 days. Links created before this 10-day retention update may retain the expiration assigned when they were created, for up to 30 days.
The app never shares a recipe automatically. The team-submission and friend-sharing actions are separate and occur only after you choose them.
Shopping-list sharing
Beginning with version 2.1, you can choose to create a bearer link for one shopping-list snapshot. The snapshot can contain a title, item names, counts, Household hints, and sender-language section labels. Those free-text fields are content you or the sender entered and may be personal or sensitive. The snapshot excludes InStock account, installation and device identifiers, personal user: canonical keys, images, and recipe provenance.
Anyone who has the link can view and copy the snapshot without signing in. InStock Kitchen stores the compressed snapshot in private Cloudflare R2 storage and makes it logically inaccessible exactly 10 days after creation; Cloudflare then schedules the stored copy for physical deletion under the configured lifecycle process. There is no early-revocation control, so share only with people you trust. Importing never replaces the recipient's list: selected rows merge into the recipient's unchecked default list, preserving existing details and avoiding duplicate items.
When Privacy Mode is on, the app asks for one-time permission bound to that exact snapshot before uploading it; Privacy Mode remains on for everything else. Cloudflare temporarily processes the source IP at the edge for abuse-rate controls under its privacy policy. The list-sharing service transforms that address with secret-key HMAC-SHA-256 into a pseudonymous abuse-control value. Neither the raw IP nor that value is included as a field in list storage or application logs. Counter state is used for no more than one hour; physical deletion is scheduled when its rolling window ends and may complete shortly afterward.
Platform services and diagnostics
Siri and Shortcuts (iOS). Apple handles voice requests under its privacy terms. InStock Kitchen carries out the requested action against your local and iCloud data and does not receive your voice request. Relevant vocabulary and list item names may be available to Apple's on-device Siri and Shortcuts system.
InStock Pro. Apple processes the iOS purchase through StoreKit, and Google processes the Android purchase through Google Play Billing. InStock Kitchen receives only the purchase or entitlement status needed to unlock Pro, not your payment-card or bank details. Purchase information is not sent to our AI service.
iOS consumable Credits. Apple processes the payment. InStock Kitchen's first-party service receives limited product, transaction, installation, grant, and refund information needed to verify and deliver Credits, prevent duplicate grants and fraud, reconcile reversals, and provide support. InStock Kitchen does not receive your payment-card or bank details, and this information is not sent to our AI service.
Android consumable Credits. Google Play processes the payment. InStock Kitchen receives limited information about the product, purchase, installation, grant, use, and refund or reversal needed to verify and deliver Credits, recover interrupted purchases, prevent duplicate grants and fraud, provide support, and reconcile refunds or voids. InStock Kitchen does not receive your payment-card or bank details, and this information is not sent to our AI service.
Credit delivery, recovery, and refunds. Android keeps limited encrypted purchase-recovery information in app-private storage so the same installation can finish or verify an interrupted purchase and show support information. This information survives Delete All Data but is excluded from backup and device transfer. Clearing app storage, uninstalling, transferring to another phone, or reinstalling removes or does not restore it, so remaining installation-bound Credits may become inaccessible. Credits may also become inaccessible after 180 days without authenticated app activity. Verified refunds or reversals can remove unspent Credits; amounts already spent may be offset against later grants. Provider updates may take time to appear.
Diagnostics. Apple may provide standard crash reports if you enable diagnostic sharing in iOS Settings. Android contains no third-party crash-reporting SDK, though Android and Google Play may process platform diagnostics. We use platform-provided reports only for reliability, not advertising or profiling. The iOS app also keeps a limited local scan log that can include recognized label text and model output, but not the source photo. It leaves the device only if you deliberately share it. Android recovery records stay in app-private storage.
Permissions
iOS
- Camera: grocery scanning and, when you choose it, taking a custom recipe photo.
- Photos: read-only access to an image you choose to import for a grocery scan or recipe.
- Notifications: optional scan-ready notifications through APNs.
Android
- Camera: Photo Scan and barcode scanning.
- Internet and network state: server AI, recipe cleanup, barcode lookup, recipe URL import, billing, and recovery when connectivity returns.
- Notifications: an optional local scan-complete notification when work finishes in the background.
Android uses the system photo picker and does not request broad storage or media-library permission.
Security
Network traffic described in this policy uses HTTPS, and app data is kept in platform-protected private storage. Android protects the InStock server identifier and token with platform secure storage and excludes them, temporary uploads, caches, and model files from backup. No storage or transmission method is completely immune from risk, but we limit collection and retention to what the features require.
InStock Kitchen's website
The companion website, instockkitchen.com, requires no sign-in and runs no website analytics. Cloudflare hosts the site, model downloads, temporary friend-sharing links, and private pending recipe submissions and may process ordinary connection data such as IP address under its privacy policy.
Data retention and deletion
- Source photos: temporary app-side upload copies are normally removed after upload, with leftover cleanup targeted within about 24 hours. The service handles source photos temporarily and does not keep them as application records after processing.
- Server scan results: detected item names are retained for up to 14 days, then automatically deleted.
- Server recipe cleanup: recipe text and the cleaned result are deleted when fetched, or after about 1 hour if never fetched.
- Server usage records: rolling usage events are deleted shortly after the 24-hour feature-limit window.
- Server job diagnostics: technical job events are deleted after 90 days.
- Server installation registrations: inactive records are deleted after 180 days without authenticated activity, provided no retained job still references the record.
- iOS local and iCloud data: uninstalling removes the local app copy. Delete iCloud Data removes the app's synchronized iCloud copy.
- Paired-watch data: the watch keeps an app-private local cache. A disconnected watch may retain that cache until it reconnects and synchronizes, the companion app is cleared or uninstalled, or the watch is reset.
- Android local data: Settings > Delete All Data removes the local database, user-created content and images, pending scan and recipe records, temporary uploads, service caches, and side-loaded model files. It keeps Privacy Mode, language, the local Pro-entitlement cache, and limited installation-bound information needed for feature-limit continuity and purchase recovery. Uninstalling the app or clearing Android storage removes the purchase-recovery information because it is excluded from backup and device transfer.
- Android backup: backup retention and deletion are controlled by Android and the user's Google account settings under Google's policies.
- iOS Credits commerce records: pseudonymous purchase, grant, use, refund, and security records may be kept for as long as needed to preserve paid value, prevent duplicate grants and fraud, reconcile reversals, provide support, protect the service, and meet legal or accounting obligations.
- Android Credits commerce records: Pseudonymous purchase, grant, use, refund, reversal, and security records may be kept for as long as needed to preserve paid value, prevent duplicate grants and fraud, reconcile refunds or voids, provide support, protect the service, and meet legal or accounting obligations.
- Friend-sharing links: Recipe content stored for a short sharing link on iOS or Android is deleted within 10 days. Links created before this update may retain the expiration assigned when they were created, for up to 30 days.
- Shopping-list sharing links: the snapshot becomes inaccessible exactly 10 days after creation. Cloudflare's storage lifecycle then schedules the encrypted stored object for physical deletion. The link cannot be revoked early.
- Pending team submissions: the submitted recipe, its optional hero photo, and optional contact information are stored privately for no more than 90 days unless the recipe is accepted into the InStock Kitchen catalog. Rejected or unselected pending submissions expire automatically.
There is no InStock Kitchen account to delete. You can stop future server AI processing by enabling Privacy Mode, revoke camera, photo, or notification access in device settings, and control iCloud or Android backup in platform settings. Third-party providers apply their own retention terms.
Clearing Android app storage or uninstalling removes local purchase-recovery information but does not automatically delete server commerce records. Contact us before clearing or uninstalling if you need help locating eligible records. Deleting eligible commerce records may permanently forfeit remaining Credits. We may retain limited pseudonymous purchase and refund records when needed to preserve paid value, prevent duplicate grants or fraud, process refunds or voids, provide support, protect the service, or meet legal and accounting obligations.
To request deletion help or ask us to determine whether a server-held record can be associated with your installation, email support@instockkitchen.com. For a pending recipe submission that included contact information, write from the included email address and identify the recipe. We will make reasonable efforts to remove an accepted recipe from future releases when requested, but cannot recall recipe data already delivered in an older installed app version.
Anonymous recipe submissions contain no account, device, installation, name, or email identifier, and the app does not preserve or display a submission reference. We therefore cannot reliably locate an individual anonymous submission for early deletion; it remains subject to the automatic 90-day pending-submission limit. Other service records may require an installation identifier to locate and may be impossible to associate without it.
Children
InStock Kitchen is a general-audience app and is not directed to children under 13. We do not knowingly collect personal information from children under 13. Children should not provide contact information or submit a recipe to the InStock Kitchen team without permission from a parent or guardian. If you believe a child provided personal information, contact us so we can review and, where required, delete it.
Your privacy rights
Depending on where you live, you may have rights to request access to, correction of, deletion of, portability of, or information about personal data associated with you, and to object to or restrict certain processing or withdraw consent. You may also have the right to contact your local privacy regulator. Email us to make a request. We may need information to verify the request, and some records may be retained where necessary for security, fraud prevention, support, transactions, or legal and accounting obligations.
AI accuracy and food safety
Photo scanning, recipe cleanup, and ingredient matching can be inaccurate or incomplete. Do not rely on them for allergen, dietary, medical, nutritional, or food-safety decisions. Always read product packaging and verify ingredients yourself, especially for allergies or dietary restrictions. InStock Kitchen is not a substitute for professional medical or nutritional advice.
Changes
If this policy changes materially, the relevant app update will include a note in its release information. The most recent policy is always available at instockkitchen.com/privacy.
Spanish and Brazilian Portuguese translations are provided for convenience. If a translation conflicts with this English version, this English version controls to the extent permitted by applicable law.
Contact
Privacy contact for InStock Kitchen: Otilia Labs, LLC. Questions, privacy requests, or deletion help: support@instockkitchen.com