Privacy policy
We do not sell your data, and we do not use what is in your pantry — or which allergens a household profile records — for advertising or profiling. Without an account, nothing leaves your phone except the anonymous barcode lookups and the advertising and diagnostic traffic described above. We hold no readable copy of your pantry unless you deliberately switch on live sync.
Who we are
This policy covers the Pantry Pals Android app, package
com.luckytools.fridge_split, as published on Google Play by Cloudy NI (sole
trader), together with the cloudyni.com pages that support it: this policy, the terms of use and the data deletion
page.
It describes the build that is on Google Play now. Where a feature is optional this policy says so, and where the app keeps nothing on our servers it says that too. We do not sell personal data.
What stays on your device
The following is written into the app's own private storage on your phone and is never sent to us:
- Your pantry items, zones, quantities and use-by dates.
- Consumption history and your shopping list.
- Household member profiles and any allergen or dietary notes you entered.
- Item photos, held in the app's own storage.
- Reminder and notification preferences, theme and language settings.
- The locally cached Premium entitlement for this install.
Clearing the app's storage or uninstalling the app deletes all of it at once, without contacting us. The data deletion page lists the steps.
What the app can access
The app asks Android for as little as it can. This is the complete list for the published build:
- Camera, only while you are scanning a barcode — you can type the number in instead
- Microphone, only while you use voice entry for an item
- Notifications, for expiry, shopping and household alerts you turn on
- Run at start-up, so reminders you set still fire after a restart
- Network access, for advertising, purchases, barcode lookups, optional sync and push messaging
- Vibration, for alerts
- Your chosen photos, read only when you attach one to an item
An item above is used only while the feature that needs it is running, and nothing beyond this list is accessed by the app.
Information the app handles
This is the full picture for the published build: everything the app records, processes or transmits, and where it goes.
- Pantry content. Item names, quantities, units, storage zones, use-by dates, sharing flags, consumption history and shopping-list entries, all stored locally and synced only if you enable live sync.
- Item photos. Pictures you attach with Android's own photo picker. They stay on the device in local-only use; with sync on they are uploaded so the rest of the household can see them.
- Display name and household profiles. The name shown next to what you add, plus any allergen or dietary notes a household profile carries. Those notes can be sensitive, so enter only what you need for the household's warnings.
- Barcode lookups. The number you scan or type, sent to OpenFoodFacts to fetch product details. No account, name or household identifier is sent with it.
- An optional account email, only if you create an account for live sync.
- Notification token. A device push token, stored only when you allow notifications, so household alerts can reach the right phone.
- Diagnostics and analytics described in the analytics section below.
- Advertising data processed by Google AdMob on the free tier.
- Correspondence you send to support.
Optional live sync and sharing
Pantry Pals works fully offline and unsigned-in: items, history, profiles and preferences live in a local database on your phone. An account and live sync are optional and off until you switch them on. If you do, the pantry content you see in the app is also stored by our processor Supabase, in the United Kingdom (London, eu-west-2), so every phone in your household can show the same fridge.
Sign-in is by email and password, or with Google if you prefer. You join a household with an invite code or link rather than by browsing, and access on the server is restricted per household, so a member of one household cannot read another's pantry. Synced rows are not end-to-end encrypted — the service can read them, because that is what makes sharing work, and the same data appears on every member's phone. Treat a shared pantry as shared information: do not put anything in it you would not show the other members, and keep medical details out of the notes.
If you choose to use that optional feature, these rules apply:
- Live sync is a shared-household feature, not private storage. Anything you add to a synced pantry is visible to the other members of that household and is stored on a server we can read.
- You need a working email address to create an account, and you must keep your password (or your Google account) secure. Everything done under your account in a shared pantry is attributed to your display name.
- Photos you attach to a synced item are uploaded to our storage bucket and served to household members through short-lived signed links. Removing the item, leaving the household or deleting the account removes the app's copy; signed links already issued expire shortly afterwards.
- We may suspend or delete an account that is used to abuse the service or to store unlawful content, and we may stop offering live sync altogether.
- Keep your own copy of anything you cannot afford to lose — the app can export your data, and sync is a convenience, not a backup guarantee.
- You may delete the account and its cloud copy at any time. See the data deletion page.
Deleting the account removes the hosted copy and signs out every device that was sharing it. The data deletion page explains what that erases and what stays on each device.
Sensitive information
Allergen and dietary notes, and anything you write about a person's health, are the most sensitive information this app can hold. They are used only to raise a warning where the app thinks a product may conflict with a profile you set up, and you choose what to enter. You can edit or delete them at any time, and you can leave a profile blank.
Because a synced pantry is shared with the other members of that household, those notes are visible to them — that is the point of the feature. If you would rather keep a condition private, keep it out of the shared profile and rely on your own judgement instead.
Where that is special category data under UK GDPR — health information, for example — the basis for using it is your explicit consent, given when you choose to record it, and withdrawn by deleting the entry. If the text above says the record stays on your device, your device is the only place it is processed.
Children and families
Pantry Pals is a household shopping tool aimed at a general audience and is not directed at children. We do not knowingly collect personal information from a child. If a child has used the app on a shared device, clearing the app's storage or uninstalling it removes everything held locally, and a parent or guardian can contact support@cloudyni.com about an account or a support email.
Advertising
The free version shows advertising served by Google AdMob, with consent collected through Google's User Messaging Platform where the law requires it. Google and its partners may process your advertising ID, IP address and device information to serve and measure ads. Advertising never receives your pantry content, your household profiles or your photos, and we do not use what is in your fridge to target ads. Buying an ad-free or Kitchen Premium subscription removes advertising.
Where the law requires it, the app asks for your advertising consent through Google's User Messaging Platform before it requests an advertisement, and you can change or withdraw that choice from the app's privacy options at any time.
Advertising is served and measured by Google and its partners under Google Privacy Policy and AdMob & privacy. You can reset or delete your advertising ID, and turn personalised advertising off, in Android Settings → Privacy → Ads.
Buying a paid product removes advertising for as long as that product is active; the next section explains what we learn from Google Play.
Analytics, diagnostics and crash reports
The app reports anonymous usage, performance and crash information through the Google services we configure:
- Google Analytics for Firebase (anonymous usage analytics)
- Firebase Crashlytics (crash and error diagnostics)
- Firebase Performance Monitoring
- Firebase Remote Config
- Firebase Cloud Messaging (push notifications)
Those reports carry an app-instance identifier rather than your name, and Google handles them for us under Firebase privacy and security. They are diagnostic: we use them to find crashes and to see which features are used, not to identify you.
We use Google Analytics for Firebase for anonymous usage analytics, Crashlytics for crash and error reports, Firebase Performance Monitoring for startup and responsiveness, Remote Config to change feature switches without an app update, and Firebase Cloud Messaging to deliver household push notifications when you allow them. Analytics events describe app behaviour (for example “item added”) and never include item names, notes, photos, household profiles or anything else you typed. You can turn notifications off in Android settings at any time.
Other services that receive data
Beyond Google Play and the services already named, these processors can receive data from the app:
- OpenFoodFacts a community-maintained public product database. When you scan or type a barcode the number is sent to it, and the product name, ingredients, allergens and nutrition figures come back. No personal data, account or household identifier is included in the request. Its data is contributed by the public and may be incomplete or wrong — check the packet if a warning matters.
- Google ML Kit used for on-device receipt text recognition. The receipt image is processed on your phone and is not uploaded to us or to Google by this feature.
- Android speech recognition used when you dictate an item name. Audio is handled by the speech service on your device under its own terms, and it is never sent to us.
Each is bound by its own privacy policy and by the terms we agree with it. A service acting only as our processor may use the data only to provide that service to us.
Purchases and subscriptions
Anything you buy in Pantry Pals is sold through Google Play Billing. Google is the merchant of record, so your payment method, billing address and the amount you paid are held by Google and never shared with us.
To unlock a paid feature the app asks Google Play whether the product is active. The product identifiers are on the terms of page, and the price is always the amount shown on the Google Play purchase sheet when you confirm it. See Google Play Terms of Service and Google Privacy Policy.
A subscription is cancelled in Google Play, not by deleting anything here, and deleting your data does not cancel it.
How long we keep things
Local pantry data stays on your phone until you clear the app's storage or uninstall it. Synced data stays on our processor's storage while the account exists and while you are a member of a household: deleting the account removes the rows and photos it owns, and leaving a household removes your membership and your profile from it. Household changes are recorded in an audit log so members can see who changed what, and those entries are deleted with the household. Support correspondence is kept only as long as needed to answer the query, and deleted on request within 90 days. Firebase and AdMob data is retained by Google under our configuration and Google's own rules, and Google keeps purchase records as merchant of record.
A cloud copy is kept only for as long as the account exists; deleting the account, or asking us to delete it, erases it.
Google keeps purchase records and advertising data under its own policies, as the store and as an advertising provider rather than on our behalf.
Your rights
Under UK GDPR you can ask us for a copy of your information, ask us to correct or erase it, restrict or object to how we use it, ask for it in a portable format, and withdraw consent where consent is what we rely on.
Most of what this app holds is on your device, so you are the fastest route to erasure: delete the entries, clear the app's storage, or uninstall the app. Where an account exists, deleting it erases the copy we hold: see the data deletion page.
Email support@cloudyni.com for any of these. We answer within one month and we do not charge for a first request. You can also raise a complaint with the ICO if you are unhappy with how we have handled your information.
How we protect your data
Data kept by the app sits in its private app storage, inside Android's application sandbox, protected by your device lock and by Android's file-based encryption. Anything the app sends or receives travels over HTTPS.
Cloud data is stored on EU infrastructure by our processor, transferred over TLS, and reachable only with the credentials that belong to the account.
No system is perfect. If we learn of a breach that puts your information at risk we will tell you and the ICO as UK GDPR requires; where we hold nothing about you, there is nothing for a breach to expose.
Changes to this policy
This page was last updated on 30 September 2026, and it describes the build that was on Google Play on that date. If a change affects what the app collects or where it goes, we update this page and the date above before the change ships. If the change is significant we will say so on the app's Google Play listing.
Contact us
Cloudy NI (sole trader) is a sole trader based in Northern Ireland, registered with the ICO for data protection under reference ZC222090.
Email support@cloudyni.com for privacy questions, a purchase problem or a deletion request. We answer data-protection requests within one month and deletion requests within 30 days.
The exact steps for deleting data, and what to send us if you cannot use them, are on the data deletion page.