← Plenty

Privacy Notice

Last updated 2026-07-27

This notice explains how Plenty ("we", "us", the "Service") collects and uses your personal data. Plenty is the data controller for information you provide through the Service.

What we collect

  • Account: email, hashed password, optional display name.
  • Kitchen data: pantry items you add, freshness outcomes, recipe interactions, preferences (diet, household size, region, dislikes).
  • Voice input: short audio clips you record are transcribed by our AI provider and then discarded — we do not store audio.
  • Usage & telemetry: counters for AI and voice calls (for plan limits), basic error logs, IP address at request time.
  • Support & feedback: anything you submit via the in-app "Report an issue" button.

Why we use it

  • Provide the core Service (contract).
  • Personalize recipes and freshness advice (contract, legitimate interest).
  • Prevent abuse and enforce plan limits (legitimate interest).
  • Fulfil legal obligations related to payments and tax (legal obligation, via Paddle).

Who we share it with

  • Supabase & Cloudflare — hosting and database.
  • Lovable AI Gateway — LLM, speech-to-text, and text-to-speech providers under a subprocessor arrangement.
  • Paddle.com — Merchant of Record for all payments, subscription management, invoicing, and tax compliance.
  • Professional advisers & authorities — only where legally required.

International transfers

Data may be processed in the US or EU depending on where our processors run their infrastructure. Where required, we rely on Standard Contractual Clauses or adequacy decisions.

Retention

We keep your data for as long as your account exists. You can delete your account any time from Profile → Danger zone. Deletion is immediate and irreversible; some aggregated, non-identifying metrics may be retained.

Your rights

Depending on your jurisdiction you have rights to access, rectify, delete, restrict, object, or port your data, and to withdraw consent. Use the "Export my data" and "Delete my account" controls in Profile, or contact us via the report button. EEA/UK users may also complain to their supervisory authority.

Security

We use encryption in transit (HTTPS) and at rest, row-level authorisation so each account can only read its own data, and hardened service credentials. No system is perfectly secure; if a breach affects you we will notify you as required.

Cookies

We use only essential cookies and localStorage entries needed to sign you in and remember preferences. We do not run advertising trackers.

Contact

Use the in-app report button or reply to any Plenty email.