Privacy Policy
Last updated: May 1, 2026
1. Introduction
FridgeFlow (“we”, “our”, or “us”) is committed to protecting your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website at https://FridgeFlow.app and our associated services (collectively, the “Service”).
Please read this policy carefully. If you disagree with its terms, please do not use our Service. This policy is incorporated into and subject to our Terms of Service.
2. Information We Collect
2.1 Information You Provide Directly
We collect information you provide when you:
- Create an account — your name, email address, and password (stored as a secure hash)
- Set up a household and fridges — household name, member email addresses for invitations, fridge names and specifications
- Add fridge content — inventory items (names, quantities, expiry dates, zones), grocery lists, meal plans, budget and transaction data, and maintenance task preferences
- Upload an avatar — profile photo stored securely in cloud storage
- Share to Community — recipes you choose to publish publicly, including titles, ingredients, and instructions
- Contact support — messages and email correspondence
- Subscribe to a plan — billing information processed by PayMongo (we never store full card details)
- Set preferences — currency symbol, timezone, locale, and notification preferences (in-app, email, and push)
- Enable push notifications — browser push subscription token stored to deliver notifications to your device
- Use AI chat with images — food photos you upload for AI analysis are sent to your configured AI provider (Google Gemini, OpenAI, or Anthropic) for processing
- Provide AI API keys (BYOK) — if you choose to configure your own AI provider key, it is stored encrypted in your household settings
2.2 Information Collected Automatically
When you use the Service, we may automatically collect:
- Usage data — pages visited, features used, timestamps, and actions taken within the app
- Device information — browser type, operating system, device type, and screen resolution
- IP address — used for security, fraud prevention, and approximate geolocation
- Cookies and similar technologies — see Section 8 for details
2.3 Information from Third Parties
If you choose to sign in with Google, we receive your name, email address, and profile picture from Google as permitted by your Google account settings. We do not receive your Google password.
3. How We Use Your Information
We use the information we collect to:
- Provide, operate, and maintain the Service
- Process transactions and send related information (receipts, invoices, subscription updates)
- Send expiry alerts, household invitations, and other transactional emails you have requested
- Power AI-assisted features (recipe generation using Google Gemini, kitchen chat, shelf-life recommendations, and personalised insights) using your inventory context
- Respond to support enquiries and resolve disputes
- Monitor and analyse usage to improve performance and user experience
- Detect and prevent fraud, abuse, and security incidents
- Comply with legal obligations
We do not sell your personal information to third parties, and we do not use your data for advertising purposes.
4. How We Share Your Information
4.1 Household Members
Information you add to a shared household (inventory items, grocery lists, activity events) is visible to all members of that household. Your display name and avatar are visible to household members. Your email address is only visible to household admins.
4.2 Service Providers
We share information with trusted third-party providers who assist us in operating the Service, subject to confidentiality agreements:
- Supabase — database hosting, authentication, and file storage
- PayMongo — payment processing and subscription management
- Nodemailer / Gmail SMTP — transactional and notification email delivery
- Google Gemini, OpenAI, Anthropic — AI-powered features (your inventory context and any uploaded food photos may be sent to generate recipe suggestions, power kitchen chat with multimodal analysis, provide voice responses via TTS, and deliver insights; none of these providers train on API requests by default)
- Vercel — web application hosting and edge functions
- Heroku — backend API hosting
4.3 Legal Requirements
We may disclose your information if required to do so by law or if we believe in good faith that such action is necessary to comply with a legal obligation, protect and defend our rights or property, prevent fraud, or protect the safety of our users or the public.
4.4 Business Transfers
If FridgeFlow is involved in a merger, acquisition, or sale of all or a portion of its assets, your information may be transferred as part of that transaction. We will provide notice before your personal information is transferred and becomes subject to a different privacy policy.
5. AI-Generated Content and Community Recipes
5.1 AI-Generated Recipes
When you use the AI recipe generation feature, your current inventory data (item names and quantities) is sent to Google Gemini to generate personalised recipe suggestions. This data is processed in real time and is not stored by Google. We retain the generated recipe only if you choose to save it to your collection.
5.2 Community Recipes
Recipes you share to Community are publicly visible to all FridgeFlow users. Your display name is shown as the author. You may remove your community recipes at any time, but copies made by other users who saved them to their personal collections are not affected.
5.3 AI Kitchen Chat
Messages you send in the AI Kitchen Chat are processed by an AI provider to generate responses. A snapshot of your current inventory and upcoming expiry dates is included as context. Chat history is stored in your account and can be deleted at any time.
5.4 Multimodal Image Analysis
When you attach a photo to an AI chat message (e.g. a food photo for identification), the image is sent as base64 data to your configured AI provider (Google Gemini, OpenAI, or Anthropic) for visual analysis. Images are not stored by the AI provider beyond the request. A reference to the image is stored in your chat history.
5.5 Voice Mode (Text-to-Speech)
When voice mode is enabled in AI chat, your text and the AI's text response are sent to Google Gemini TTS to generate audio. The generated audio is delivered directly to your browser and is not stored on our servers after the response is complete.
5.6 AI Guardrails
Our AI features are restricted to food management, inventory, recipes, and related household topics. Off-topic queries are rejected. The AI does not provide medical, legal, or financial advice beyond basic food safety guidance. We do not use your data to train AI models.
6. Data Retention
We retain your personal information for as long as your account is active or as needed to provide the Service. Specifically:
- Account data — retained until you delete your account
- Activity logs — retained for 90 days by default, configurable in Settings
- Chat history — retained until you delete individual threads or your account
- Push subscription data — retained until you unsubscribe or delete your account
- Billing records — retained for 7 years as required by financial regulations
- Deleted household data — permanently removed within 30 days of deletion request
You can export all your data or request full account deletion from Settings → Import/Export at any time.
7. Data Security
We implement industry-standard security measures to protect your information:
- All data is transmitted over HTTPS/TLS encryption
- Passwords are hashed using bcrypt; we never store plaintext passwords
- Database access is protected by Row Level Security (RLS) policies
- Sensitive operations require authenticated sessions with JWT tokens
- File uploads are stored in access-controlled cloud storage
While we take reasonable precautions, no method of transmission over the internet is 100% secure. We cannot guarantee absolute security and encourage you to use a strong, unique password and enable any available account security features.
8. Your Rights and Choices
8.1 Access and Correction
You can review and update your personal information at any time from Settings → Profile. If you need assistance accessing or correcting your data, contact us at lewisvillamor26@gmail.com.
8.2 Data Portability
You can export your household data (inventory, grocery lists, activity history) in a structured format from Settings → Import/Export.
8.3 Account Deletion
You can request deletion of your account and all associated personal data from Settings. We will process your request within 30 days. Note that anonymised aggregate data may be retained.
8.4 Email and Push Communications
You can manage email and push notification preferences from Settings → Notifications, including per-type toggles for expiry alerts, maintenance reminders, weekly reports, and more. Push notification subscriptions can be revoked in your browser settings or within the app. Transactional emails related to account security and billing cannot be fully disabled as they are essential to the Service.
8.5 GDPR Rights (EEA Residents)
If you are located in the European Economic Area, you have additional rights under the General Data Protection Regulation (GDPR), including the right to object to processing, restrict processing, and lodge a complaint with your local data protection authority. To exercise these rights, please contact us at the address below.
8.6 California Privacy Rights (CCPA)
California residents have the right to know what personal information we collect and how it is used, to request deletion of personal information, and to opt out of the sale of personal information (we do not sell personal information). To exercise these rights, contact us at lewisvillamor26@gmail.com.
9. Cookies and Tracking Technologies
We use the following types of cookies and similar technologies:
- Essential cookies — required for authentication and to keep you signed in (cannot be disabled)
- Preference cookies — remember your settings such as theme choice and dismissed banners
- Analytics cookies — help us understand how users interact with the Service (may be disabled)
You can control cookies through your browser settings. Disabling essential cookies will prevent you from signing in or using the Service.
10. Children's Privacy
The Service is not directed to children under the age of 13, and we do not knowingly collect personal information from children under 13. If we become aware that we have collected personal information from a child under 13 without verification of parental consent, we will take steps to remove that information from our servers.
If you believe we have inadvertently collected information from a child under 13, please contact us at lewisvillamor26@gmail.com.
11. International Data Transfers
Your information may be transferred to and processed in countries other than your own. Our service providers (including Supabase and Vercel) operate globally. We ensure that appropriate safeguards are in place for international transfers in accordance with applicable data protection laws.
12. Links to Other Websites
Our Service may contain links to third-party websites. We are not responsible for the privacy practices of those sites. We encourage you to review the privacy policies of any third-party sites you visit.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by posting the new policy on this page and updating the “Last updated” date, and where appropriate, by sending you an email notification. Your continued use of the Service after any changes constitutes your acceptance of the new Privacy Policy.
14. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
FridgeFlow Privacy Team
Email: lewisvillamor26@gmail.com
Website: https://FridgeFlow.app
We aim to respond to all privacy enquiries within 30 days.