Privacy Policy
Short version. Your fridge lives on your iPhone and in iCloud. A few features need our server and an AI, and they only run when you ask. Here’s the whole picture, in plain English.
Last updated: October 7, 2026
At a glance
- No FridgEat account, no ads, no tracking. We don’t sell your data, and we don’t share it for advertising.
- Your fridge stays with you, on your iPhone and in iCloud (yours, or that of the person who created your household). We can’t read it.
- AI only when you ask, and with your consent. Photos and texts go through our server (run by Cloudflare) to Anthropic’s AI, Claude. Our server keeps no copy. Anthropic may keep them for up to 30 days, except for legal or security reasons, and under its commercial terms doesn’t use them to train its models.
- Our server keeps very little: a random installation ID with your analysis count and security keys, deleted after 12 months without use, and, if you subscribe, your subscription status for a few hours. Its technical logs, with no photos or texts but with your IP address in Cloudflare’s, are kept for up to 7 days.
- Apple handles payments. We never see your card details.
- No usage analytics in this version of the app, and no analytics or advertising cookies or trackers on this website.
Who’s responsible
FridgEat and this website are published by Bitek — Nicolas Cordeiro, sole proprietor (entrepreneur individuel), based in France (“we,” “us”). Under the GDPR and the UK GDPR, we’re the “controller” of the personal data described here, except where Apple or another company handles data on its own account, as explained below.
Contact: bonjour@fridgeat.app. Postal address: À COMPLÉTER. UK representative: À COMPLÉTER. Full details are in our legal notice. This policy also exists in French; the French version covers a few French-specific rules.
What we use, and why
FridgEat works without an account. It doesn’t ask for your email address, phone number, location, contacts or advertising identifier. Only an optional first name (or, if you share your fridge, your iCloud account name) is shown to your household. Here’s what happens to the data FridgEat does use.
On your iPhone
Everything you put in FridgEat is stored on your iPhone: your items and their dates, shopping list, week plan, activity history, recap, levels and badges, cookbook and notes, your cooking profile (diet, allergies, kitchen equipment, number of people), your settings and your photo consent.
- Photos are never saved, neither in your photo library nor on our server.
- FridgEat keeps a daily backup copy on your iPhone, in case the main file gets damaged.
- Some information appears outside the app, on your iPhone only: notifications, widgets (including on the Lock Screen) and iPhone Search can show item names. You control these in your iPhone’s settings.
- If you back up your iPhone (with iCloud Backup or a computer), that backup includes your FridgEat data.
In your iCloud
When you’re signed in to iCloud, FridgEat automatically syncs part of your data to your private iCloud database (Apple CloudKit), even if you don’t share your fridge: your items, shopping list, planned dinners, activity history (for example “added,” “eaten” or “thrown away”) and the first name your household sees.
- It’s stored in your iCloud account, under Apple’s privacy policy. We have no access to it.
- Your cooking profile, allergies, levels, settings and cookbook aren’t synced this way.
- There’s no switch for this in the app. To stop it, turn off iCloud for FridgEat in your iPhone’s settings.
The shared fridge
If you invite someone (My profile → My household → Invite someone), Apple’s iCloud sharing screen opens. Invitations are private: only the people you invite can join, up to 6 people in all.
- Everyone in the household can see and change the shared items (fridge, pantry, freezer, leftovers), the shopping list, planned dinners and activity history, and sees each member’s first name. The activity history records which member did what, including what they tossed.
- That first name is the one you enter in Your first name (seen by your household) or, if you leave it empty, the name on your iCloud account.
- When you join a household, all your shared content joins it: your items, shopping list, planned dinners and your activity history (including what you tossed). Other members can see it.
- Your profile, allergies, level, settings, badges and cookbook stay yours.
- The shared data is stored in the iCloud account of the person who created the household. The shared fridge is free and needs no FridgEat account. We can’t read it.
- You can leave at any time with Leave the household, and you keep a copy of the fridge. If you created the household, leaving stops the sharing for everyone, and each person keeps their own copy. You can also remove a single person with Remove from household.
When you use AI features
Some features need an AI to read your photos or texts. They only run when you use them, and only with your consent. The content goes from your iPhone to our server, run by Cloudflare, which passes it to Anthropic’s AI (Claude) and sends the result back to you.
| Feature | What’s sent | When |
|---|---|---|
| Grocery photos | 1 to 4 photos, shrunk to about 1.2 megapixels, with all metadata removed (no location, device or date) | When you photograph your groceries |
| Receipts and PDFs | The text read on your iPhone (12,000 characters at most; for a PDF, from its first 10 pages). For a receipt with almost no readable text, the receipt photos instead | Only if reading on your iPhone found nothing, or if you tap Reread with AI |
| Custom recipes (FridgEat+) | Items in your fridge (name, quantity, days left; not the freezer, pantry or expired items), your diet, allergies, kitchen equipment, whether you’re a beginner, number of people and your request | Each time you ask, after you tap Agree and send |
| Recipe import | The text and link you pasted (6,000 characters at most). The video itself is never copied | Only if reading on your iPhone isn’t enough, after you agree |
Your consent. FridgEat asks before the first analysis. On first launch, the note under Snap my groceries explains it, and tapping that button counts as your consent. Otherwise, a screen called One small thing before your first photo asks you. This consent covers grocery photos and AI rereading of receipts and PDFs. Once given, it isn’t asked again: if your iPhone can’t read anything in a receipt or a PDF, its text goes to the AI without another question, including your name and delivery address if they’re in it. You can withdraw it at any time in My profile → Privacy → Photo analysis → Withdraw consent, and FridgEat will ask again before the next photo. Custom recipes and recipe imports ask for your agreement every single time.
What travels with it. With each AI request, the app also sends our server some technical information: a random installation ID, the app’s language, Apple security data (App Attest, see below) and, if you have FridgEat+, your subscription’s original transaction ID. Anthropic receives none of these, only the photos or text and our instructions.
What happens to it. Our server handles the content in memory during the request and doesn’t store any image, text or product name. Anthropic processes it on our behalf to produce the result. Anthropic may keep it for up to 30 days, except for legal or security reasons, and under its commercial terms doesn’t use it to train its models. No automated decision with legal or similarly significant effects is made about you: the AI suggests a list or recipes, which you check and correct.
Be careful what you send. A receipt or a delivery order can include everything printed on it, such as the store’s address, a loyalty card number or, for an online order, your name and delivery address. FridgEat doesn’t filter this text. Try not to photograph people or personal documents. If you’d rather not send something, add your items by hand or with the barcode scanner: neither uses AI.
Without consent, FridgEat still works: adding items by hand, barcodes, reading receipts and PDFs on your iPhone, guided recipes, reminders, the shopping list, the shared fridge and your recap. Only grocery photos always need the AI.
Our server: counters and security
To give everyone a fair number of free analyses and keep the service from being abused, our server (on Cloudflare) keeps a strict minimum:
- A random installation ID, created by the app and stored in your iPhone’s Keychain. It stays if you reinstall FridgEat on the same iPhone, but doesn’t follow you to another iPhone. We don’t link it to your name or your Apple Account.
- Your analysis count for the month, attached to that ID, so the free and FridgEat+ limits work.
- App Attest data. Once per installation, Apple’s App Attest service lets the app prove to our server that requests come from the genuine FridgEat app. The server keeps the resulting public key and a counter, attached to the installation ID.
- Short-lived security data: a one-time code used to set up App Attest (5 minutes at most), and the time of your last request (60 seconds), used to limit each iPhone to one AI request every 10 seconds.
- Your subscription status. If you have FridgEat+, our server asks Apple whether your subscription is active, using its original transaction ID. It stores that transaction ID with “active” or “not active,” for 6 hours (1 hour if not active). Our code never stores your installation ID and your transaction ID together; only Cloudflare’s logs, described next, may contain both, because they may keep the request headers.
- Technical logs. Our code only writes one line per request to its logs: the feature called, the response status, the duration, the number of items found and, if something failed, an error code. Never an image, a text or a product name. Our code doesn’t read your IP address. But Cloudflare’s logging service, which is turned on for our server, also records technical metadata about each request and response. It may include your IP address, the date and time, and the request headers, so your installation ID and, if you have FridgEat+, your subscription’s original transaction ID. According to Cloudflare’s documentation, these logs are kept for up to 7 days. As for this website, Cloudflare may also process security data about these requests, under its own policy.
Barcodes (Open Food Facts)
Each time you scan a barcode (except for items you named yourself), your iPhone asks Open Food Facts (world.openfoodfacts.org), an open food products database, for the product’s name, quantity and category. The request contains the barcode number and identifies the app (not you), and Open Food Facts receives your IP address, as any website you visit would. No photo and no personal details are sent. Open Food Facts handles this under its own privacy policy. The date is estimated by FridgEat, not by Open Food Facts. Products you name yourself are remembered on your iPhone and aren’t looked up again. FridgEat doesn’t save Open Food Facts’ answers with your data, though iOS may briefly keep them in its cache.
Subscriptions and other Apple services
- Purchases. FridgEat+ is bought, renewed and refunded through Apple. We never see your payment details or your Apple Account details, only the subscription’s transaction ID described above.
- App Attest, described above.
- Sync notifications. To keep iCloud sync up to date, the app registers for Apple’s silent notifications, which display nothing and need no permission. Your reminders are scheduled by your iPhone itself: we don’t send them.
- Siri and Shortcuts. FridgEat answers with the data on your iPhone. Your voice request is handled by Apple, under its own rules.
- Crash reports. If you agreed, in your iPhone’s settings, to share analytics with app developers, Apple may send us crash reports and aggregate statistics.
Apple handles this data under its own privacy policy: https://www.apple.com/legal/privacy/.
Emails you send us
If you email us, or use Give feedback in the app, we receive your email address and your message. Give feedback also adds the app version and build, the iOS version, the device type (“iPhone”) and the recipes version, plus a screenshot if you choose to attach one. You see all of it in your email app before sending. We use it only to answer you and improve FridgEat.
Things you choose to share
When you share something from FridgEat (a challenge link, a recap card or video, a backup file), it goes wherever you send it, through your iPhone’s share sheet. It doesn’t go through our server.
- Challenge links contain only the first name you chose, your score for the week (items saved and a percentage) and an expiry date, 7 days later. Anyone with the link can see them. When the link is opened in a browser, the part after “#” is never sent to our website: only the page itself reads it.
- Backup files (My profile → Backup → Back up my fridge) contain all your FridgEat data, including your profile and allergies. Keep them somewhere safe.
Usage analytics: off
This version of FridgEat sends no usage analytics, to us or to anyone else. You may see Help improve FridgEat and See what gets sent in My profile → Privacy: in this version, the events listed there (the last 30) are only kept in your iPhone’s memory, disappear when the app is closed, and are never sent. While the switch is on (the default), the app still creates a random ID, stored on your iPhone with your data (so it’s in your backups); it’s never sent anywhere, and turning the switch off erases it. If we ever turn on analytics, we’ll update this policy first.
This website
fridgeat.app sets no analytics, advertising or tracking cookies, uses no analytics or trackers, and loads nothing from other websites. Only Cloudflare, our host, might set a technical security cookie (such as “__cf_bm”) if it needs to filter out bots: it’s strictly necessary and isn’t used to track you. Like any web host, Cloudflare processes your IP address and basic technical information (such as your browser type) to deliver the pages and protect the site. Our website code doesn’t record anything about your visit, and no visit logs are turned on for this website.
Allergies and diet
Allergies are health data, and some diets (such as halal) can reveal religious beliefs. The law treats this information as sensitive, and so do we.
- It’s optional. You decide whether to fill in your diet and allergies in My cooking profile. FridgEat uses them on your iPhone to pick guided recipes that suit you.
- It stays on your iPhone, in your iPhone backup and in any backup file you create. It isn’t synced to your iCloud database or shared with your household.
- It leaves your iPhone only for custom recipes (FridgEat+), and only if you tap Agree and send in the “Send my preferences to Claude?” message, which appears every time. Our server doesn’t keep it. Anthropic may keep it for up to 30 days, as explained above.
- Legal basis: your explicit consent (GDPR and UK GDPR, Article 9(2)(a)), given each time. You can simply say no, or remove your allergies from your profile at any time.
- Always check the ingredients. FridgEat double-checks every custom recipe against your allergies and diet, but it can’t guarantee there’s no mistake, and it isn’t a medical tool.
Consumer Health Data Privacy Policy
This section is our consumer health data privacy policy under Washington’s My Health My Data Act, Nevada law (SB 370) and similar US state laws.
- Health data we collect: the allergies you choose to add to your cooking profile (and, if it reveals health information, your diet).
- Why: only to write the custom recipes you ask for, and to pick guided recipes that suit you on your iPhone.
- Where it comes from: you, in the app. It leaves your iPhone only for a custom recipe, after you tap Agree and send, every time.
- Who receives it: no third party. Only our processors, Cloudflare (our server’s host) and Anthropic (the AI that writes the recipe), handle it on our behalf. Our server doesn’t keep it; Anthropic may keep it for up to 30 days, except for legal or security reasons.
- We never sell it, and we don’t share it for advertising.
- Your rights: you can withdraw your consent at any time (just tap Cancel, or remove your allergies from your profile), and ask us to confirm, access or delete any health data we have, by emailing bonjour@fridgeat.app. If we deny a request, you can appeal by replying to our answer.
Legal bases
If you’re in the European Economic Area or the UK, here’s what allows us to use your data under the GDPR and the UK GDPR:
| What | Legal basis |
|---|---|
| Making the features you use work: iCloud sync, shared fridge, barcode lookup, subscription check | Performance of our contract with you (Art. 6(1)(b)) |
| AI analysis of photos, receipts, PDFs and imported recipes | Your consent (Art. 6(1)(a)), which you can withdraw at any time |
| Custom recipes using your allergies and diet | Your explicit consent (Art. 6(1)(a) and 9(2)(a)), asked every time |
| Giving you the number of analyses your plan includes, free or FridgEat+ (installation ID, monthly count) | Performance of our contract with you (Art. 6(1)(b)) |
| Preventing abuse and keeping our server secure (rate limits, App Attest) | Our legitimate interest in preventing abuse and keeping the service secure (Art. 6(1)(f)) |
| Spotting server problems (technical logs, ours and Cloudflare’s) | Our legitimate interest in keeping the service running (Art. 6(1)(f)) |
| Delivering and protecting this website | Our legitimate interest in running a secure website (Art. 6(1)(f)) |
| Answering your emails | Our legitimate interest in replying to you (Art. 6(1)(f)) |
Who else handles your data
We don’t sell or rent your data. Only these companies are involved, for the purposes described above:
| Who | What for | What they receive |
|---|---|---|
| Cloudflare, Inc. (United States, worldwide network) | Hosts our server and this website, passes AI requests to Anthropic, stores the counters | Requests to our server and website, including your IP address, and the server data listed above |
| Anthropic (United States) | Runs the AI (Claude) that reads photos and texts and writes custom recipes | The content you send for analysis, with no technical identifier (no installation ID or subscription ID) |
| Apple | App Store, subscriptions, App Attest, iCloud sync and sharing, notifications | What Apple’s services need, under Apple’s own privacy policy |
| Open Food Facts | Product names for barcodes | The barcode number and your IP address, under its own privacy policy |
| Our email provider | Receives the emails you send us | Your messages and email address |
Cloudflare, Anthropic and our email provider process data on our behalf. They’re contractually bound to give your data the same or equal protection as described in this policy. Apple and Open Food Facts act independently, under their own policies, and receive most of this data directly from your iPhone. We may also disclose data if the law requires it, for example to comply with a court order.
International transfers
We’re based in France, but Cloudflare and Anthropic are US companies, and Cloudflare’s network runs in data centers around the world. Your data may therefore be processed in the United States and in other countries outside the European Economic Area and the UK. When that happens, it’s protected by the safeguards the GDPR and the UK GDPR require, such as the European Commission’s standard contractual clauses (with the UK addendum) in our providers’ data processing terms, or the EU-U.S. Data Privacy Framework where a provider is certified. Email us at bonjour@fridgeat.app for more details or a copy of these safeguards.
If you live outside Europe, your data may be processed in France, where we are, and in the United States.
How long we keep data
| Data | How long |
|---|---|
| Your data on your iPhone | Until you erase it (Erase all my data) or delete the app |
| Your data in iCloud | Until you erase it in the app or delete it from iCloud |
| Photos and texts sent to the AI | Not stored by our server. Anthropic: up to 30 days, except for legal or security reasons |
| Installation ID and analysis count | Deleted 12 months after your last analysis |
| App Attest key | Deleted 12 months after your last AI request |
| One-time security code | 5 minutes at most, deleted once used |
| Time of your last request | 60 seconds |
| Subscription status (active or not) | 6 hours if active, 1 hour otherwise |
| Server technical logs (ours: no image or text; Cloudflare’s: request metadata such as IP address and headers) | Up to 7 days, according to Cloudflare’s documentation; Cloudflare’s security data under its own policy |
| Website visits | No visit logs on our side; Cloudflare’s security data under its own policy |
| Your emails | As long as needed to answer you and follow up, and no more than 3 years after our last exchange |
Your rights and choices
In the app
Open My profile by tapping FridgEat’s head, at the top right of the Home screen. From there:
- Withdraw your AI consent: Privacy → Photo analysis → Withdraw consent.
- Get a copy of your data: Backup → Back up my fridge creates a file with all your FridgEat data.
- Leave a shared fridge: My household → Leave the household.
- Erase your data: Privacy → Erase all my data → Erase → Erase everything.
- Stop iCloud sync: turn off iCloud for FridgEat in your iPhone’s settings.
Before you erase
Erase all my data erases your fridge, shopping list, week plan, cooking profile (allergies included), cookbook, recap, levels and settings from this iPhone. It also removes your items, shopping list, planned dinners and activity history from iCloud: on all your devices and, if you’re in a household, from the shared fridge of every member. You stay a member of your household afterward. To erase only your own copy, leave the household first.
Some things aren’t erased this way:
- the installation ID and the App Attest key in your iPhone’s Keychain, and a few technical files and preferences (such as barcodes you named and your remaining free analyses);
- your household membership, and your first name in the household’s iCloud data;
- the counters on our server, which expire on their own 12 months after your last use (so erasing doesn’t reset your free analyses);
- your subscription, which Apple manages;
- what Anthropic may still keep (up to 30 days), and backups of your iPhone made earlier.
Deleting the app removes its data from your iPhone, but not the Keychain items or your iCloud data. You can manage the data stored in your iCloud from your iPhone’s settings.
Your rights under the GDPR and UK GDPR
If you’re in the European Economic Area or the UK, you have the right to access your data, correct it, erase it, restrict or object to its use, receive it in a portable format, and withdraw your consent at any time (this doesn’t affect what was done before). If you’re in France, you can also give instructions about what happens to your data after your death. Email us at bonjour@fridgeat.app, and we’ll reply within one month.
On our server, our counters and keys are only tied to the random installation ID, and the subscription status only to Apple’s transaction ID. Cloudflare’s logs, kept for up to 7 days, may also contain your IP address. Because there’s no account, we usually can’t tell which data is yours, and we’ll explain this if it’s the case. If you give us details that help us find it, we’ll look for it. Most of your data is on your iPhone and in your iCloud, where you control it directly with the options above.
You can also complain to a data protection authority: in France, the CNIL (https://www.cnil.fr); in the UK, the Information Commissioner’s Office (https://ico.org.uk); or the authority where you live or work.
US state privacy rights
Several US states, such as California, Colorado, Connecticut and Virginia, give their residents rights over their personal information. Here’s where we stand, whatever state you live in:
- We don’t sell your personal information, and we don’t share it for targeted (cross-context behavioral) advertising. There are no ads in FridgEat.
- No tracking. We don’t track you across other companies’ apps or websites, and we don’t use your data for profiling that has legal or similarly significant effects.
- Do Not Track and Global Privacy Control. Because neither the app nor this website tracks you over time or across other sites, they work the same way whether or not your browser sends a Do Not Track or Global Privacy Control signal.
- Sensitive information (your allergies and diet) is only used to write the custom recipes you ask for. See our Consumer Health Data Privacy Policy.
- You can ask what personal information we have about you, and ask us to correct or delete it. To delete your data, use Erase all my data in the app (see above), and email us at bonjour@fridgeat.app for anything else. We may need to verify your request, and you can use an authorized agent.
- No discrimination. Using these rights won’t change the service or the price you get.
- If we can’t fully grant a request, we’ll explain why, and you can appeal by replying to our answer.
The categories of information we handle, where they come from, why we use them and who receives them are described in the sections above.
Children
FridgEat is made for a general audience. It isn’t directed to children under 13, and we don’t knowingly collect personal information from them. The app has no account and doesn’t ask for a name, email address, age or contact details.
If you’re a parent and believe your child under 13 has sent us personal information (for example by email), contact us and we’ll delete it. In the EU and the UK, young people below the age of digital consent in their country (13 to 16, depending on the country) should ask a parent or guardian before using the AI features.
Security
- Connections between the app, our server and our providers are encrypted (HTTPS).
- Our server checks, with Apple’s App Attest, that requests come from the genuine FridgEat app.
- Photos lose their metadata before they leave your iPhone, and our server never stores content.
- The installation ID and the security key are kept in your iPhone’s Keychain (the key itself in the Secure Enclave), on that iPhone only.
- We keep as little data as possible, for as short a time as possible.
No system is perfectly secure. If a security incident affected your data, we’d take the steps the law requires, including informing you and the authorities where needed.
Changes to this policy
We’ll update this policy when FridgEat changes or the law requires it, and change the date at the top. If a change significantly affects how your data is used, we’ll tell you clearly beforehand (for example in an app update or on this site) and ask for your consent again if needed.
Contact
Questions about your data or this policy? Email us at bonjour@fridgeat.app. We’re Bitek — Nicolas Cordeiro, sole proprietor (entrepreneur individuel), and our postal address is in the legal notice.







