Learn what information Pantrip processes and how to manage or delete it.
1. Operator and scope
Pantrip is operated by Seonghun Jeon (전성훈), who is also the privacy contact. Contact jsh097610@gmail.com for privacy questions and rights requests. This notice applies to the app and official support website. The service is intended for people aged 16 and above. If we learn that we collected information from someone under 16, we investigate and delete it.
2. Food inventory and photos
Food names, photos, dates, quantities, notes, barcodes, storage locations, selected models and usage records are stored on your device by default. After Apple or Google sign-in, if you agree to food sync, these records, photos and thumbnails are linked to your account and sent to Supabase database and private file storage to sync with other signed-in devices. This food-sync transfer does not start before your agreement. iCloud sync is not used. Text recognition and background removal run on-device; photos, recognized text and food names are not sent to Amplitude.
Food and photos on your device remain after logout or account deletion. Turning sync off stops transfers but does not delete existing server copies; those are deleted during account erasure. Deleting food with sync on propagates to other syncing devices on the same account. Food belonging to another account is not automatically uploaded to a new account. Data already downloaded by older versions remains, but iCloud-only data is not automatically imported.
3. Account, payment and reward data
Our server processes your guest account ID, authentication tokens, account creation and access information, and linked provider identifiers. Linking Apple or Google may store the email, name and other profile fields supplied by that provider in the authentication system. We do not receive your social-login password.
The server processes point balances, kitchen/product/decoration ownership, transaction and product IDs, times and reward records. The operator does not receive card numbers. For activity rewards, the server receives internal food IDs, registration/completion flags and times, expiry dates, time zones, storage locations, photo-presence flags, barcode hashes and kitchen-name hashes. This rewards API does not receive original food photos or food names. Hashes and activity data linked to an account are treated as personal data.
Information is collected when you enter it or use app features, when linked sign-in, payment or advertising services return information, or when you contact us by email. Device permissions are separate from analytics and advertising choices.
4. Optional features and permissions
Camera access supports photos and barcode scanning; photo access registers selected images; notifications provide expiry reminders. You can change permissions in iOS Settings and still register items manually if you decline.
When you run an online search, Open Food Facts receives the barcode or entered search terms, search language and connection information such as your IP address. Photos are not uploaded for this search. No search request is sent unless you use the feature.
5. Analytics and ads
Amplitude automatically receives events about screens, food-entry methods (manual, camera, photo or barcode), online lookup attempts/results, and kitchen, store, achievement, ad and purchase flows. Data includes an analytics identifier, app version, device/OS details and limited choices, outcomes and durations. There is no separate analytics consent prompt. We do not send photos, food names, typed text, raw barcodes, email or authentication tokens as analytics properties. SDK settings disable automatic location inference from IP addresses. Receiving servers may still process connection information. After social sign-in, the provider-verified email is sent to Amplitude as the user ID. With Apple Hide My Email, this may be a relay address. Anonymous accounts and accounts without a verified email use expirycheck:<account UUID>. Email is not included in event properties but is transmitted to Amplitude as an identity; names are not sent for analytics. Earlier UUID-based records are not guaranteed to merge automatically with email-based records.
Rewarded ads appear when you choose to watch one. We show Google consent messages where required and request iOS tracking permission separately. Denying tracking permission alone does not prevent rewards. The app currently requests non-personalized ads. The ad SDK may process IP addresses, device/app information, ad views/interactions and permitted identifiers. Where applicable, you can change your choices through the app’s ad privacy settings.
6. Purposes, legal grounds and international processing
Account, purchase and reward data support those features. Analytics is automatic by default, with no separate consent popup. In Settings → Privacy choices → Usage analytics, you can stop or resume collection. Stopping removes unsent events; request deletion of already transmitted data by email. Reading this notice is not consent. Regional processing grounds and international-transfer requirements remain under pre-launch review.
Actual processing/storage countries, transfer grounds and detailed provider retention periods are being verified. A provider’s registered country may differ from where data is processed. Confirmed settings and provider statements are distinguished; unresolved details must not be treated as a confirmed country or completed consent. Contact jsh097610@gmail.com.
7. Retention and erasure
Minimum legally required contract, payment and supply records are retained for five years from the original transaction time; complaint/dispute records for three years under the applicable record-specific rule. This does not mean retaining all activity or photos for five years. The server implements retention of deletion status and recovery records for 30 days after completion. The server regularly checks retention periods and deletes the applicable records when those periods have ended. Pending requests are distinguished from completed deletion.
Starting and social-link rewards and their ledger records are managed per Pantrip app account and erased with account deletion. Legally required payment records are retained separately for the periods above. We do not separately retain cross-account identity records to prevent rejoining with the same social account after deletion.
Analytics events are retained while the analytics purpose remains; verified applicable deletion requests are handled through the provider. Automatic 12-month deletion has not been configured, so we do not promise that events disappear after 12 months. Older device-based analytics not linked to an account may not be identifiable from the account ID alone. We explain the available scope and additional steps for such requests.
When the retention purpose ends, we erase data to make recovery difficult. Provider erasure and limited security/backup retention can take time. We distinguish request receipt from external completion. Statutorily retained data is erased when its period ends.
8. Deleting your account
You can request account deletion in My information in settings. After identity and transaction checks, we delete the server account, points, purchased kitchen/decor ownership and synced food and photos. Guest accounts are also covered; local food and photos remain. Account deletion is not a refund. Legally required payment records are retained separately for the necessary period.
External providers erase data separately from account deletion, so completion times may differ. The server processes deletion requests automatically and retries failed tasks. Authentication and token revocation for real Apple accounts, and completed erasure of existing Amplitude events, still require verification. We distinguish receipt of a request, processing, account deletion and completed external erasure. Contact jsh097610@gmail.com to check progress or if you cannot use the app.
The server records analytics email IDs verified from authenticated account data and associates them with the account. Account deletion requests Amplitude deletion for the recorded email IDs and legacy UUID-based IDs.
After account erasure is completed, rejoining creates a new Pantrip account that can receive the applicable starting and linking rewards. Disconnecting and reconnecting within an existing account does not award another bonus.
9. Your rights and regional information
Contact the email above for access, correction, erasure, restriction, withdrawal or objection requests. We verify identity using the minimum necessary information. Do not send passwords, login codes or card numbers. We respond within the applicable legal period and explain any restriction or extension.
Where applicable in the EEA, UK and Switzerland, you also have portability rights, a right to object to legitimate-interest processing, and a right to complain to a supervisory authority. We accept applicable US state-law access, deletion, correction and sale/sharing opt-out requests without discrimination. In Korea, contact the privacy infringement center (118, privacy.kisa.or.kr) or dispute mediation committee (1833-6972, kopico.go.kr). Applicable rights and mandatory local law also prevail in Japan, Thailand, Russia, Mongolia and other countries. Your chosen translation does not determine your country.
For a rights request, describe the action you want and provide your account ID from app settings. If you cannot find your ID, contact us by email first. We may verify authorization for requests made through a representative. If we cannot fulfill a request, we explain the reason and how to challenge the decision.
10. Security and changes
We use encrypted connections, account-level access controls, separated server privileges and restricted secret access. Logs are designed to exclude authentication tokens and original photos. This website has no added analytics or advertising scripts. Its hosting provider may process security logs such as connection IP addresses.
We announce material changes to data, purposes or providers in the app or on this page and update the effective date. Changes requiring new consent are addressed separately.
2026-09-29 update: added a plain light/dark document layout and contents, and clarified collection methods and rights requests. This document update does not introduce new categories of personal data collection. Email us if you need to consult an earlier notice.
2026-09-30 update: added the use of verified social-login email as the Amplitude user ID and how those identifiers are handled during account deletion.
2026-09-30 correction: the first social-link reward is granted once per app account. We corrected the statement that separate duplicate-prevention identity records remain after account deletion. Public webpage hosting changed to OpenAI / ChatGPT Sites.
Providers and data shared
Supabase Pte. Ltd.
Authentication, database, private file storage and server processing: account, points, transaction and reward records, plus food records, photos and thumbnails when you agree to food sync. The database region is Seoul, South Korea; Supabase is based in Singapore. International support/subprocessors may involve the US and other countries. The service and retention rules above apply.
Optional Apple sign-in and App Store payments: provider identifiers, allowed profile fields and transactions. Processed in the US and Apple’s disclosed operating locations for service and security. Apple account retention settings apply. We no longer perform food synchronization through iCloud.
Google sign-in and AdMob rewards: provider identifiers/allowed profiles, ad/device/connection data and reward verification values. Processed in the US and Google’s disclosed operating locations for authentication, ads and security. Ad choices and Google service retention rules apply. Support mail is received through Gmail. Google therefore processes the sender’s email address, message, attachments and any voluntarily supplied account ID to provide email services. We use these to resolve the inquiry; applicable dispute-record duties and provider retention conditions are distinguished.
Payment verification and transaction management: account identifiers, products, transactions, receipts and refunds. Actual processing countries and provider retention periods are being verified. Required payment evidence is retained separately with restricted access.
Usage analytics: permitted events/properties, analytics identifiers and app/device information. This project uses US servers. Collection and retention follow the analytics sections above. Analytics identifiers include the social provider-verified email (including Apple relay addresses) or account UUID.
When you run an online search, Open Food Facts receives the barcode or entered search terms, search language and connection information such as your IP address. Photos are not uploaded for this search. No search request is sent unless you use the feature.
OpenAI / ChatGPT Sites hosts the public webpages. Connection IP addresses, browser and device information, and request metadata may be processed in access logs to serve and secure the pages. App food records, photos and account authentication tokens are not sent to this public site. The hosting provider’s privacy policy applies.