Privacy Policy

Last updated: October 7, 2026 · Effective: October 7, 2026

At a glance

  • We collect the data we need to run FridgeSpy — your account, your inventory, and (briefly) the photos you scan.
  • We do not sell or "share" your personal information for cross-context behavioral advertising.
  • We do not use your data to train general-purpose AI models.
  • You can delete your account and all associated data at any time from the Account screen.

This Privacy Policy explains how Dream Holdings LLC, an Indiana limited liability company located at 5474 US Hwy 6, Portage, IN 46368, United States ("FridgeSpy", "we", "us", or "our") collects, uses, discloses, retains, and protects personal information when you use the FridgeSpy mobile and web applications, fridgespy.com, our APIs, and related services (collectively, the "Service"). It also describes the rights and choices available to individuals located in the United States, the European Economic Area, the United Kingdom, Switzerland, and other jurisdictions.

For purposes of the EU General Data Protection Regulation ("GDPR"), the UK GDPR, and the Swiss Federal Act on Data Protection, FridgeSpy is the controller of the personal data described below. For purposes of the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA/CPRA"), FridgeSpy is a business.

1. Information we collect

1.1 Information you provide to us.

  • Account information: email address, password (stored as a salted hash, never in plaintext), display name, optional profile photo, time zone, household name and members you invite.
  • Cooking profile: dietary preferences, allergens, household size, skill level, equipment, and similar preferences you supply to personalize recipes.
  • Inventory data: the items, quantities, units, locations (fridge/freezer/pantry), purchase dates, expiry dates, prices, barcodes, photos, and notes you add.
  • Photos you submit: receipt photos, fridge / freezer / pantry photos, and product label photos you choose to capture or upload.
  • Communications: messages, support requests, survey responses, and feedback you send us.
  • Payment information: processed entirely by Paddle (our Merchant of Record). We receive only metadata such as plan, subscription status, country, currency, last four digits of the card or a payment-method token, and renewal date. We never receive or store your full card number or CVV.

1.2 Information collected automatically.

  • Device and usage data: device model and OS, browser type, language, app version, screen size, IP address, approximate location derived from IP (city/region only), timestamps, screens viewed, features used, error and crash logs, scan counts, recipe generations, and similar diagnostic information.
  • Cookies and similar technologies: we use a small number of strictly necessary cookies and similar storage (such as localStorage) for authentication, session management, security (CSRF), preference storage, and to remember whether you've dismissed banners. We do not use advertising or cross-site tracking cookies. Where required by law, we ask for consent before setting any non-essential cookies.
  • Activity log: an append-only audit trail of certain actions you take in the Service (for example, scans, purchases, and security events) for fraud prevention and abuse detection.

1.3 Information from third parties.

  • Authentication providers (e.g. Google sign-in) share with us the identifiers, email, and basic profile you authorize.
  • Paddle shares billing metadata as described above.
  • Open Food Facts returns public product information based on the barcodes you scan.
  • If you reach us through referrals or campaigns, our analytics may show the referring source.

1.4 Sensitive information. We do not request government IDs, financial-account numbers, precise geolocation, biometric identifiers, or other sensitive categories. Dietary preferences and allergens you choose to enter may, in some jurisdictions, be considered sensitive — we process them only to personalize recipes and warnings, never for profiling or third-party use.

1.5 Children. The Service is not directed to children under 13 (or the equivalent minimum age in your jurisdiction) and we do not knowingly collect personal information from them. If you believe a child has provided us with personal information, contact us at matt@fridgespy.com and we will promptly delete it.

2. How we use information

We use personal information for the following purposes:

  • Provide the Service: create and authenticate your account, sync your inventory across devices, send expiry reminders and other notifications you enable, share lists with your household, and generate recipes and meal-prep plans based on what you own.
  • AI processing: when you scan a receipt, fridge photo, or product label, the image (and limited context, such as your cooking preferences) is sent to AI providers to extract items, dates, totals, and to generate recipes. See Section 4.
  • Process payments: manage your subscription, billing cycles, refunds, and tax compliance (via Paddle).
  • Security and fraud prevention: detect, investigate, and prevent abuse, unauthorized access, security incidents, and breaches of our Terms.
  • Support and communications: respond to your requests, send service announcements, security alerts, and (with consent where required) marketing emails — you can unsubscribe at any time.
  • Improve the Service: diagnose bugs, monitor performance, and analyze aggregate, de-identified usage patterns to plan new features.
  • Legal and compliance: meet legal, regulatory, accounting, and tax obligations; enforce our Terms; and protect our rights, property, safety, and that of our users and the public.

3. Legal bases (EEA / UK / Switzerland)

If GDPR or the UK GDPR applies to you, we rely on the following legal bases:

  • Performance of a contract (Art. 6(1)(b)) — to provide the Service you sign up for, including AI scanning and recipe generation features you actively use.
  • Legitimate interests (Art. 6(1)(f)) — to keep the Service secure, prevent fraud and abuse, debug issues, conduct aggregate analytics, and communicate with you about features you use.
  • Legal obligation (Art. 6(1)(c)) — to comply with tax, accounting, and other applicable laws.
  • Consent (Art. 6(1)(a)) — for push or email marketing, non-essential cookies, and any processing where consent is specifically required. You may withdraw consent at any time without affecting the lawfulness of prior processing.

4. AI processing

FridgeSpy uses AI services provided through the Lovable AI Gateway and underlying models such as Google's Gemini family. When you scan or upload an image, the image and a brief instruction are transmitted to the AI provider for processing. The provider returns structured data (items, dates, totals) and/or generated text (recipes, meal-prep ideas), which we store with your account so that you can use the result.

By contract and configuration, our AI providers process inputs and outputs only to deliver the response and do not use them to train their general models. We retain transient AI inputs only as long as needed to deliver the result. Generated outputs and the parsed item data remain associated with your account until you delete them or your account.

AI Output may be inaccurate, incomplete, or biased. See Section 5 ("AI features and food-safety disclaimer") of the Terms of Service for important limitations.

5. How we share information

We share personal information only as described below.

  • Service providers / processors: companies that perform services on our behalf under written contracts that restrict their use of the data to providing the service, including:
    • Paddle.com Market Ltd — Merchant of Record, payments, billing, tax, invoicing, fraud prevention (privacy notice).
    • Supabase — hosting, database, authentication, and storage infrastructure.
    • Lovable AI Gateway and underlying providers (Google) — AI scanning and generation.
    • Open Food Facts — public barcode lookup (we transmit only the barcode you scan).
    • Email and push-notification providers — to deliver transactional and (where applicable) marketing communications.
    • Crash reporting and analytics — to diagnose errors and understand aggregate use.
  • Household members: if you join or create a household, other members can see the inventory, lists, and recipes shared within that household.
  • Third-party AI assistants you connect (MCP): FridgeSpy can connect to AI assistants such as ChatGPT or Claude through our MCP (Model Context Protocol) integration. When you connect an assistant, you authorize it to read and manage your kitchen data — including inventory items, expiry dates, shopping lists, household kitchens, and cooking preferences — and that data is transmitted to the assistant's provider (for example, OpenAI or Anthropic) each time you use it. Their use of that data is governed by their own privacy policies, not ours. You can disconnect the integration at any time from the assistant's settings; disconnecting stops future sharing but does not delete data the provider has already received.
  • Legal and safety: we may disclose information when we believe in good faith that it is necessary to comply with a law, regulation, legal process, or governmental request; to enforce our Terms; or to protect the rights, property, safety, or security of FridgeSpy, our users, or the public.
  • Business transfers: if we are involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, your information may be transferred as part of that transaction, subject to standard confidentiality protections.
  • With your consent: any other sharing you direct or authorize.

We do not sell or "share" your personal information for cross-context behavioral advertising, as those terms are defined under the CCPA/CPRA and similar U.S. state privacy laws. We have not done so in the past 12 months.

6. International data transfers

We are based in the United States and our service providers may process personal data in the United States and other countries that may have different data-protection laws than your home country. Where we transfer personal data out of the EEA, the United Kingdom, or Switzerland, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum, as applicable) with our processors, and we conduct transfer-impact assessments where required. You may request a copy of the relevant safeguards by emailing us.

7. Data retention

We retain personal information only for as long as needed for the purposes described in this Policy, unless a longer retention period is required or permitted by law. In general:

  • Account, inventory, and cooking-profile data: for as long as your account is active, and up to 30 days after deletion to complete erasure across backups and downstream systems.
  • Shared household kitchens: inventory and shopping-list items belong to the household. If you leave or delete your account while others remain in the household, those items stay available to the remaining members and are no longer linked to you. A household with no remaining members is deleted along with its items.
  • AI scan inputs (photos): we discard the source image after processing; only the extracted structured data is retained with your inventory.
  • Activity log: retained for up to 24 months for security, fraud, and abuse-prevention purposes, then pruned by our service role.
  • Billing records: retained by us and Paddle for the period required by applicable tax and accounting laws (typically 7 years in the U.S.).
  • Support correspondence: retained for up to 24 months after the issue is resolved.
  • Backups: retained on a rolling basis (typically 30 days) and then overwritten in the ordinary course.

8. Security

We implement technical and organizational measures designed to protect personal information, including encryption in transit (TLS), encryption at rest, salted and hashed passwords, row-level security on our database (so users access only their own rows), server-managed fields enforced by triggers for privileged attributes, audit logging, principle-of-least-privilege access controls for staff, regular dependency and vulnerability scanning, and incident-response procedures. No system is perfectly secure; please report suspected vulnerabilities to matt@fridgespy.com.

9. Your privacy rights

9.1 Everyone. Regardless of where you live, you can:

  • access and update your account details and cooking profile in the Account screen;
  • edit or delete inventory items, photos, and household memberships at any time;
  • delete your account and all associated personal data from Account → Delete account;
  • unsubscribe from marketing emails using the link in any such email;
  • turn off push notifications at the OS level.

9.2 EEA, UK, and Switzerland. Subject to applicable law, you have rights to: (a) access the personal data we hold about you and receive a copy in a portable format; (b) rectify inaccurate or incomplete data; (c) erase your data ("right to be forgotten"); (d) restrict or object to processing, including processing based on legitimate interests; (e) withdraw consent at any time where processing is based on consent; (f) not be subject to a decision based solely on automated processing that produces legal or similarly significant effects (we do not engage in such processing); and (g) lodge a complaint with your local supervisory authority. To exercise these rights, email matt@fridgespy.com.

9.3 California (CCPA/CPRA) and other U.S. state laws. If you are a California resident — or a resident of another state with a comprehensive privacy law (such as Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, or others as they come into effect) — you have the right to:

  • Know / access the categories and specific pieces of personal information we collect, use, and disclose, and the categories of sources and recipients;
  • Delete personal information we have collected from you, subject to legal exceptions;
  • Correct inaccurate personal information;
  • Port a copy of your personal information in a portable, machine-readable format;
  • Opt out of the sale or sharing of personal information for cross-context behavioral advertising — we do not engage in either, so no opt-out is necessary;
  • Limit the use of sensitive personal information — we do not use sensitive personal information for purposes that require an opt-out under California law;
  • Be free from retaliation for exercising any of these rights.

To exercise these rights, email matt@fridgespy.com from the email address on your account, or use the in-app deletion tools. We will verify your request using your account credentials (and, where necessary, additional information). You may use an authorized agent acting on your behalf, provided that you have given them written permission and we can verify their authority. We will respond within the time required by applicable law (generally 45 days, extendable once where reasonably necessary).

Notice of financial incentive. We do not offer financial incentives in exchange for personal information.

10. Cookies and tracking choices

We use strictly necessary cookies and similar storage to provide and secure the Service. We do not currently use third-party advertising trackers. Where required by law (for example, in the EEA and UK), we display a consent banner for any non-essential cookies and respect your choices. Most browsers allow you to refuse or delete cookies via their settings; doing so may prevent you from signing in or using certain features.

We honor Global Privacy Control (GPC) signals where required by applicable law as a valid opt-out of sale or sharing of personal information (although, as noted, we do not sell or share personal information).

11. Automated decision-making

We do not use personal information for automated decision-making that produces legal or similarly significant effects about you, such as creditworthiness or insurability. Our AI features generate recipe suggestions and parse images, which are convenience features and do not, by themselves, produce legal effects.

12. Third-party links and integrations

The Service may contain links to third-party websites and may integrate with third-party services (for example, when you tap a recipe source). Their privacy practices are governed by their own policies; we are not responsible for them. Review their notices before providing personal information.

Retailer links. When you tap a Walmart or Amazon link, you pass through a FridgeSpy redirect that records the store and the item searched (not who you are) so we can count clicks, then you're sent to the retailer. Some links are affiliate links; the retailer may set its own cookies to credit the referral. As an Amazon Associate we earn from qualifying purchases.

13. Changes to this Policy

We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top. For material changes, we will provide additional notice (such as an email to your account email or a prominent in-app notice) at least seven (7) days before the change takes effect. Your continued use of the Service after the effective date constitutes acceptance of the updated Policy.

14. EU/UK representative

If you are located in the EEA or the UK and wish to contact us about this Policy, you may do so by emailing matt@fridgespy.com or by writing to the address below. If we are required by law to appoint an EU/UK representative or Data Protection Officer, we will update this Policy with their details.

15. Contact us

To make a privacy request, ask a question, or report a concern about your data, contact:

Dream Holdings LLC
Attn: Privacy
5474 US Hwy 6
Portage, IN 46368
United States
Email: matt@fridgespy.com

See also our Terms of Service.