← Back to Spud
Privacy Policy
Last updated: 24 July 2026
This policy explains what data the Spud app ("Spud", "we", "us") collects, why, and what
rights you have over it. Spud is a meal-planning app that helps you cook from what's already
in your kitchen.
1. Who is responsible for your data
Spud is operated by Jacob Carlberg. For any privacy
question or request, contact jacobcarlberg97@gmail.com.
2. What we collect
Account & profile
- Email address and password (if you sign up directly), or your name/email as shared by Apple or Google if you use "Sign in with Apple/Google".
- Display name, dietary preferences (vegetarian / vegan / gluten-free), and preferred language.
Kitchen & app data
- Pantry inventory: item names, quantities, units, expiry dates, and scanned barcodes.
- Weekly meal plans and favorited recipes.
- Usage counters for AI features (e.g. how many chat messages or receipt scans you've made in a day), used only to enforce fair-use limits.
Photos, audio, and barcode scans
- If you scan a receipt, the photo is sent to our AI provider to extract item names and is not stored afterward.
- If you use "Speak to add", the audio recording is sent to our AI provider to transcribe it and is not stored afterward.
- Barcode scans are matched against the public Open Food Facts database; no personal data is included in that lookup.
- Camera, photo library, and microphone access are only requested when you actively use these features, and you can decline them and use manual entry instead.
Purchases
- Subscription status and purchase history, handled by our subscription provider (RevenueCat) and the Apple App Store / Google Play Store. We never see or store your payment card details — Apple/Google handle billing directly.
Crash & diagnostic data
- If the app crashes or errors, technical details (device type, OS version, app state, and IP address) are sent to our error-monitoring provider (Sentry) so we can fix the problem. This data is processed in the EU.
3. Why we process it
- To provide the service — matching recipes to your pantry, tracking expiry, building your shopping list. (Necessary to perform our contract with you.)
- To process payments — verifying and managing your subscription. (Necessary to perform our contract with you.)
- To fix bugs and keep the app reliable — crash and diagnostic data. (Our legitimate interest in operating a working product.)
- Optional features you choose to use — camera, photo library, and microphone access. (Your consent, given at the time you use the feature.)
4. Who we share it with
We use a small number of service providers (data processors) to run Spud. We don't sell your data.
- Supabase — hosts our database and handles authentication. Data is stored in the EU (Ireland).
- OpenAI — processes receipt photos, voice recordings, and AI recipe/chat requests. Located in the United States; data sent is limited to what's needed for that specific request, and model training on your data is disabled on our account.
- RevenueCat — manages subscription status across the App Store and Play Store.
- Sentry — receives crash and error diagnostics, processed in the EU.
- Apple / Google — process sign-in (if you use those options) and all in-app purchases.
- Open Food Facts — public barcode database, queried without any personal data attached.
Where a provider is located outside the EU/EEA (such as OpenAI and RevenueCat), transfers are
made under their standard contractual clauses (SCCs), which both providers make available as
part of their standard terms of service.
5. Cookies & website analytics
This section covers hispud.app (this website), separately from the app data described above.
We use Mixpanel to understand how visitors use the site — which pages are
viewed and whether the waitlist form is used. Mixpanel is not loaded and no analytics data is
collected until you accept the cookie banner shown on your first visit; if you decline, none of
this tracking happens. Your choice is remembered in your browser's local storage. We don't use
Mixpanel to track you across other websites, and we don't sell or share this data with third
parties beyond Mixpanel acting as our processor.
6. How long we keep it
- Account and kitchen data is kept for as long as your account is active.
- Receipt photos and voice recordings are processed in real time and are not retained after the request completes.
- If you delete your account, your profile, pantry, meal plan, and favorites data is permanently deleted immediately. Crash reports already sent to Sentry are retained per Sentry's own retention window.
7. Your rights
If you're in the EU/EEA or UK, under GDPR you have the right to:
- Access the personal data we hold about you
- Correct inaccurate data
- Delete your data ("right to be forgotten")
- Export your data in a portable format
- Object to or restrict certain processing
- Withdraw consent at any time (for features that rely on it, like camera/microphone access)
- Lodge a complaint with your local data protection authority — in Sweden, the Integritetsskyddsmyndigheten (IMY)
You can delete your account and all associated data directly from the app under
Profile → Delete account, or by emailing
jacobcarlberg97@gmail.com.
8. Children
Spud is not directed at children under 16 and we do not knowingly collect data from them.
9. Security
Data is encrypted in transit and at rest via our hosting provider. Session credentials are
stored in your device's secure keychain/keystore, not in plain storage. Access to your kitchen
and account data is restricted to your own account by database-level access rules.
10. Changes to this policy
If we make material changes to this policy, we'll update the date at the top of this page and,
where required, notify you in the app.
11. Contact
Questions about this policy or your data: jacobcarlberg97@gmail.com