In My Fridge Privacy Policy
Last updated: August 5, 2026
Effective date: July 9, 2026
This Privacy Policy explains how In My Fridge collects, uses, discloses, and protects personal data when you use the In My Fridge iOS application, bundled legal screens, related hosted legal and support pages, and services that support the app (together, the "Service").
The Service is provided by Maksim Yaromau, Individual Entrepreneur, Georgia IP No. 302239897, legal address: 70 M. Tsinamdzgvrishvili street, Georgia ("In My Fridge", "we", "us", or "our").
Contact: Yaromaum@gmail.com
This English version is the official version for users who use In My Fridge in English.
Related documents:
- Terms of Use: https://inmyfridge.app/apps/in-my-fridge/terms
1. Current privacy posture
In My Fridge is designed around local-first kitchen and cooking workflows. Many user-owned items are stored locally on your device. The production app also sends limited data to Apple services, RevenueCat, PostHog, the In My Fridge backend/proxy, OpenAI, Open Food Facts, hosting and logging providers, and email providers when needed to operate a feature you request, maintain purchases, understand app usage, diagnose reliability, or provide support.
In My Fridge does not track you across other companies' apps or websites for advertising. In My Fridge does not use third-party advertising pixels or marketing pixels in the app. In My Fridge does not use an advertising identifier for tracking.
2. Data you provide
Depending on how you use In My Fridge, you may provide:
- Sign in with Apple information, such as Apple user identifier, name, and email address if provided by Apple;
- fridge and kitchen inventory, ingredient entries, equipment entries, quantities, units, categories, and edits;
- dietary preferences, excluded foods, recipe filters, language choices, notification choices, and settings choices;
- meal reminder settings and recipe-filter preferences;
- saved recipes, cooked recipe state, shopping-list items, and recipe interaction state;
- receipt images, product photos, visible text, recognition review edits, confirmed items, and related recognition results;
- optional voice-ingredient transcripts held for the current add flow;
- support emails, feedback, legal requests, privacy requests, and other communications with us.
3. Data generated by the Service
In My Fridge may generate or store:
- recipe match status, available/missing ingredient states, suggested shopping items, and kitchen-equipment match context;
- recognition suggestions, candidate items, confidence values, warnings, and review state;
- local reminder schedule state, app state, cached content, entitlement state, device language, app version, and build information;
- privacy-safe diagnostics and event properties, such as screen name, feature area, action status, package/product identifier, entitlement state, generic error codes, and performance timing.
4. Technical, analytics, diagnostics, and purchase data
In My Fridge may process:
- app user identifiers, anonymous identifiers, session identifiers, and local session state used to operate the app;
- device type, operating system, app version, build number, environment, language, locale, timezone, network status, and basic diagnostics;
- server and reverse-proxy logs containing request timestamps, route, response status, latency, IP address, user agent, and security/error codes where backend or proxy features are used;
- privacy-safe PostHog product analytics events for activation, screen usage, feature usage, paywall views, purchase/restore statuses, entitlement state, recognition flow status, settings usage, notification settings, and app reliability;
- Apple and RevenueCat purchase and entitlement data, such as product identifiers, offering identifiers, entitlement
inmyfridge_plus, renewal or purchase status, restore status, and receipt or transaction metadata handled through Apple and RevenueCat.
We do not receive your full payment card number from Apple.
5. Local storage
Many In My Fridge items live on your device, including fridge and kitchen inventory, equipment, preferences, excluded foods, recipe state, saved/cooked recipes, shopping lists, nutrition setup, reminder settings, recognition review state, app language, and cached runtime content.
Deleting the app or device data may delete local In My Fridge data. We may not be able to recover local data after deletion. Some purchase and entitlement records may remain with Apple, RevenueCat, or backend providers as needed for billing, entitlement, fraud prevention, support, tax, accounting, legal, or security purposes.
6. Recognition, OCR, voice, and AI processing
Receipt and product-photo recognition is optional and should be started by you. You select or capture a receipt or product photo, receive suggested results, review them, and confirm what should be saved.
Recognition first uses on-device Apple technologies where available. In the production app, proxy-assisted recognition is enabled. When the local result is insufficient, the app sends the selected receipt or product JPEG, locale, recognition mode, and a request identifier through an authenticated In My Fridge backend/proxy to OpenAI. Product-barcode lookup sends the barcode, locale, and request identifier to the proxy; the proxy queries Open Food Facts and may send returned product-name/category text to OpenAI for normalization. The iOS client does not receive provider API keys, internal prompts, schemas, or model-routing controls.
Recognition results may be wrong, incomplete, duplicated, or uncertain. You must review and confirm suggestions before saving them.
Voice ingredient entry is optional. Microphone audio is processed for live speech recognition, is not saved by In My Fridge, and is not sent to the In My Fridge proxy. The transcript is kept in memory for the current flow. When local parsing is ambiguous, the transcript may be sent once through the proxy to OpenAI. The proxy sets store: false and does not write image bytes, recognition text, transcripts, prompts, or model results to its database or application log. OpenAI's current API documentation states that Responses API data is retained for at least 30 days by default and that abuse-monitoring logs may be retained for up to 30 days or longer where required for legal or safety reasons. The project's eligibility or enablement for OpenAI Zero Data Retention is not currently verified, so this Policy does not claim zero provider retention.
We minimize recognition payloads. The proxy does not send account email, Apple user identifier, push token, PostHog identifier, full fridge state, dietary restrictions, calorie goals, or unrelated preferences to OpenAI or Open Food Facts.
7. Device permissions
The App may request:
- camera access to scan receipts and product labels;
- photo library access to pick receipt or product photos;
- microphone and speech-recognition access for optional voice ingredient entry;
- notification access for optional local meal reminders.
You can manage permissions in iOS settings. Some features may not work if a permission is denied or revoked.
8. Notifications
If you enable notifications, In My Fridge may use iOS notification permissions and local notification scheduling to provide meal, cooking, or kitchen reminders.
Recipe calories and macronutrients may be displayed as informational values. In My Fridge does not use them to maintain a personal daily calorie target or daily intake history.
Notification content is designed to avoid raw receipt text, private support messages, payment details, and sensitive free text. You can disable notifications in In My Fridge settings or iOS settings.
9. How we use data
We use data to:
- provide, personalize, and maintain the Service;
- authenticate users and maintain app sessions where sign-in is used;
- show and manage fridge, kitchen, recipe, reminder, and shopping-list data;
- match recipes to available ingredients and kitchen equipment;
- process optional receipt and product-photo recognition requests;
- process optional voice ingredient recognition requests;
- show recognition suggestions for user review before saving;
- schedule optional local reminders;
- manage In My Fridge Plus access, purchase status, entitlement state, restore status, and billing-related support;
- operate privacy-safe analytics, reliability monitoring, security, fraud prevention, debugging, and abuse prevention;
- respond to support, legal, privacy, and safety requests;
- comply with law, platform rules, tax, accounting, and legal obligations;
- enforce our Terms and protect the rights, safety, and integrity of In My Fridge, users, and others.
10. Legal bases for EEA/UK processing
Where EEA or UK data protection law applies, we rely on one or more of the following legal bases:
- contract necessity, where processing is needed to provide the Service or paid features you request;
- consent, where required for camera access, photo library access, notifications, optional permissions, or certain optional processing;
- legitimate interests, such as app security, product analytics, debugging, fraud prevention, service improvement, support, and enforcing terms, balanced against your rights;
- legal obligations, such as tax, accounting, consumer protection, platform, and lawful request obligations.
11. Analytics and diagnostics limits
PostHog analytics is configured for product analytics and is intended to use privacy-safe events. In My Fridge analytics should not include raw email, name, comments, support text, raw free text, voice transcripts, audio, search query text, raw OCR text, receipt text, URLs, payment information, API keys, secret tokens, or full recognition payloads.
Sensitive onboarding and nutrition values should use buckets rather than raw values. Ingredient labels should be sanitized catalog-backed labels when tracked, not arbitrary user-entered text.
12. When we disclose data
We may disclose data to:
- Apple services, including App Store, StoreKit, Sign in with Apple, subscription management, refund request tools, iOS notification systems, camera/photo permission systems, speech recognition, and on-device recognition;
- RevenueCat, to manage purchase and entitlement state;
- PostHog, for privacy-safe product analytics;
- OpenAI, for production proxy-assisted recognition and normalization when local processing is insufficient;
- Open Food Facts, for user-requested product-barcode lookup;
- backend/cloud hosting, database, logging, security, and infrastructure providers used to operate In My Fridge backend or proxy services;
- your configured email provider and our recipient email provider when you choose to send a support, legal, or privacy email. The app and website open an email draft; they do not submit a website form through FormSubmit;
- professional advisers, authorities, courts, regulators, or other parties where needed to comply with law, protect rights, prevent fraud or abuse, or handle legal claims;
- a successor or relevant party in connection with a merger, acquisition, reorganization, asset sale, or similar transaction, subject to appropriate protections.
We do not sell personal data for money.
13. Retention
We retain personal data only as long as reasonably needed for the purposes described in this Privacy Policy, including providing the Service, maintaining local app functionality, managing purchases and entitlements, supporting users, security, debugging, fraud prevention, tax, accounting, legal compliance, dispute resolution, and enforcing terms.
Local app data may remain on your device until deleted by you, the app, or the operating system. The proxy holds recognition request bodies and results in memory while servicing the request and does not persist them. It does persist account-linked recognition-job metadata (request identifier, recognition type, status, timestamps, and outcome/error code) for quota and abuse controls; no automatic deletion schedule is currently implemented for that metadata. Production had no user or recognition-job rows on August 5, 2026.
OpenAI retention is described in Section 6. Caddy access logs retain IP and request metadata and use Caddy's file-output rotation because no custom rotation values are configured. The Node service log contains route, status, duration, and safe error codes, is append-only, and currently has no separate automatic deletion rule. Database backups have no automated retention schedule. Support email remains in the sender's and recipient's email systems until deleted under their settings and our operational or legal needs. Purchase and entitlement records may be retained as needed for billing, accounting, fraud prevention, support, and legal obligations.
14. Your choices and controls
You can:
- choose what food, equipment, preferences, recognition images, and nutrition information you provide;
- edit or delete supported app content in the app;
- disable notifications in In My Fridge settings or iOS settings;
- deny or revoke camera, photo library, microphone, speech recognition, and notification permissions in iOS settings;
- use Restore Purchases to refresh Apple and RevenueCat entitlement state;
- delete local app data by using available app controls or deleting the app from your device;
- contact us at Yaromaum@gmail.com for support, legal, or privacy requests.
Some data exists only on your device and may not be accessible to us. We cannot export, correct, or delete local-only data that we do not possess, except through app controls available to you.
15. EEA/UK privacy rights
If EEA or UK data protection law applies, you may have the right to request access, correction, deletion, restriction, portability, objection to processing, and withdrawal of consent where processing is based on consent.
You may submit requests to Yaromaum@gmail.com. We may need to verify your identity before fulfilling a request. You also may have the right to complain to a data protection authority.
16. U.S. resident privacy rights
Depending on your U.S. state of residence, you may have rights to request access, deletion, correction, portability, and information about certain disclosures.
In My Fridge does not use data for cross-context behavioral advertising in the current app. In My Fridge does not sell personal data for money. If we later use processing that qualifies as sale, sharing, targeted advertising, or profiling under applicable U.S. state privacy laws, we will update this Privacy Policy and provide required controls.
You may submit requests to Yaromaum@gmail.com. We will not discriminate against you for exercising privacy rights.
17. International processing
We and our providers may process data in countries other than your country of residence. Those countries may have data protection laws different from yours. Where required, we use appropriate safeguards for international transfers.
18. Security
We use reasonable technical, organizational, and administrative safeguards designed to protect personal data. These may include access controls, encryption in transit where appropriate, iOS data-protection mechanisms, Keychain session storage, backend security controls, secret separation, logging redaction, provider controls, and privacy-safe diagnostics rules.
No method of transmission or storage is completely secure. We cannot guarantee absolute security.
19. Children
The Service is intended for users who are at least 13 years old or the minimum age required by law in their country to use online services without parental consent. We do not knowingly collect personal data from anyone below that age. If you believe a child provided personal data to In My Fridge without proper consent, contact us at Yaromaum@gmail.com.
20. Third-party links and services
The Service may link to third-party websites, services, platforms, or policies. We do not control those third parties and are not responsible for their privacy practices. Review their policies before using them.
21. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. If changes are material, we will provide notice through the Service, hosted pages, email, or another reasonable method where required by law.
The updated Privacy Policy becomes effective when posted or on the date stated in the notice. Your continued use of the Service after the effective date means you acknowledge the updated Privacy Policy.
22. Contact
For support, legal notices, privacy requests, or questions about this Privacy Policy, contact:
Maksim Yaromau, Individual Entrepreneur
Georgia IP No. 302239897
70 M. Tsinamdzgvrishvili street, Georgia
Yaromaum@gmail.com