Privacy
Last updated 2026-06-09.
What we collect
- Account email and name when you register, so we can sign you in and reach you about your account.
- Pantry, recipe, and grocery data you enter, stored on the servers we operate.
- Waitlist email, if you submit one on this site, plus a hashed (sha256) form of your IP address used purely to detect signup abuse. We do not store the raw IP address.
Who we share it with
- Resend — sends our transactional and confirmation emails. They see your email address and the contents of the message we sent you.
- Cloudflare — hosts this site and the API and provides cookieless web analytics on the marketing site (no GDPR banner; no cross-site tracking).
- PostHog (US region) — our product analytics and error
tracking. On this marketing site we use it in cookieless mode
(no cookies, no session or local storage, no session replay, and no
cross-site identity) to understand which pages visitors read. Once you
are signed in to the product app, we also use it for session replay and
storing the feedback you send us, so we can understand how the app is
used, find bugs, and act on what you tell us. Data is sent through our
own domain (
app.pntrypal.com/ph-relay) and retained for 30 days by default. See the section below for what is and is not recorded.
We do not sell your data. We do not share it with advertisers.
Analytics, error tracking, and feedback in the product app
We use PostHog inside the signed-in product app for four things, from one SDK:
- Product analytics — anonymous-by-design interaction events (page views, clicks, custom events such as “recipe imported” or “grocery list generated”). Events are attributed to your user account and to your household so we can answer questions like “how many households use meal planning?” without singling out individuals.
- Error tracking — uncaught exceptions, failed API requests, and route loader failures. We use these to fix bugs.
- Session replay — a reconstructed view of the page that plays back the interactions during your session. Passwords, email, and numeric/telephone input fields are masked at the browser before anything is sent. The Login, Register, Settings, and Billing pages are not recorded at all. Other personal data the app displays (member emails, household names, invitee emails) is wrapped to be masked in replays. Payment card entry happens inside Stripe's own iframe and is never sent to PostHog.
- In-app feedback — when you use the “Send feedback” option in the app to send us a note, the message you write is stored in PostHog, along with the type you picked (general, bug, or idea) and which screen you sent it from. Unlike the interaction events above, which are counts and IDs rather than anything you type, a feedback note is the text itself — we keep it so we can read it and fix what you flagged. Your note is masked in session replay and retained for 30 days like everything else here. Please don't put anything in a note you wouldn't want us to store; the email opt-out below removes it along with the rest of your PostHog data.
We respect the browser-level Do Not Track signal — if you
have it on, the SDK will not initialize and no events or replays are sent.
We do not currently show an in-app consent banner; if you would prefer to
opt out, email hello@pntrypal.com
from the address on the account and we will exclude you and delete any
existing PostHog data tied to your account.
Cookies
The marketing site uses no cookies — its analytics (Cloudflare and PostHog) both run in cookieless mode. The product app uses one session cookie to keep you signed in.
Deletion
To delete your account, sign in to the app and use the delete-account flow, or email hello@pntrypal.com from the address on the account.
Contact
Questions: hello@pntrypal.com.