Skip to content
Pantrly

Security

Your pantry data, and what we do with it

Written plainly and without padding, because this is the page that decides whether you trust a product you found last week with what is in your kitchen.
01

What happens to your pantry data

When you type an ingredient list or describe what is in your fridge, that text is sent to a model provider to produce your meal suggestions, and the resulting suggestions are stored in our database against your account so you can come back to them. That is the whole journey for text.

The text is transmitted over TLS 1.2 or better and stored encrypted at rest by our database provider (Neon Postgres). It is never posted anywhere public, never shared with another user, and never sent to any third party other than the model provider that produces your suggestions.

02

Photos

If you snap a photo of your fridge or pantry, the image is sent to a vision model to identify ingredients. The image is discarded immediately after that recognition step. We do not store photos, and no image is passed to any party beyond the single recognition call. The ingredient list that comes out of that call is what we store, not the image.

03

Model providers, and training

Pantrly routes across providers. We use these providers under their business API terms, which prohibit training on API traffic. We do not fine-tune any model on your pantry data, we do not use your ingredient lists to improve prompts without asking, and we do not sell or license customer text to anyone for any purpose.

04

Who at Pantrly can read your data

Access to the production database is limited to the engineers who operate it, and it is used to fix things, not to browse. We do not read customer pantry data for product research.

If you open a support ticket about a specific saved cook and send us the link, we may look at that one record to answer your question. If you would rather we did not, say so in the ticket and we will work from your description instead.

05

How long we keep it

  • Saved cooks and the pantry text stored with them: until you delete them, or until 30 days after you delete your account, whichever is sooner.
  • Account records: for as long as the account is open, then 30 days.
  • Form submissions from the contact and help forms: 24 months.
  • Server logs, which record request paths and timings but not pantry or ingredient text: 30 days.
  • Backups: rolling 7 days, after which deleted data is gone from backups too.
06

Deleting your data

Delete any saved cook from your account, which removes the suggestion and the pantry snapshot used to produce it. Delete your whole account from Settings, which removes every saved cook, your pantry, and the account record.

Both are immediate and neither needs a support ticket. If you want written confirmation for your own records, email us and we will send it.

07

Accounts and access

  • Passwords are hashed with scrypt and a per-user salt. We never store or log a password, and nobody at Pantrly can see one.
  • Sessions are httpOnly, sameSite cookies signed with a server-side secret, and they expire after 30 days.
  • Google sign in is supported so you do not have to keep another password at all.
  • Every request for a saved cook checks that the cook belongs to the account asking for it, in the database query itself rather than in the page.
08

Our own posture

  • Two-factor authentication is required on every service Pantrly uses, with no exceptions and no shared logins.
  • Production access is limited to the operations team and reviewed quarterly.
  • Dependencies are updated on a weekly cadence and security advisories are actioned within 72 hours for anything reachable from production.
  • We do not yet hold a SOC 2 report. We are a pre-seed company and would rather tell you that than imply otherwise.
09

Reporting something

Email security@getpantrly.com. We acknowledge within two business days, we will not threaten you for reporting in good faith, and we will tell you when it is fixed. If you want to be credited, say so and we will.

This page describes what Pantrly does today. The privacy policy is the legal version of the same thing, and the terms cover the rest. Last reviewed July 2026.