Kitch privacy policy
Last updated: 5 September 2026 · Effective: on publication
The short version
Kitch looks at photos of your fridge, your pantry and your grocery receipts, and turns them into meal plans. To do that we send those photos to OpenAI, which identifies what's in them. We ask your permission before that happens, and we don't keep the photos.
Most of what Kitch knows about you never leaves your phone. Your pantry, your meal plan and your grocery list are stored on your device, not on our servers. Your dietary restrictions are stored on your device too; they're sent with each scan so we can filter recipes, then discarded.
We don't sell your data. You can delete your account from inside the app.
The rest of this page is the detail behind those sentences.
Who we are
Kitch is operated by Kitch AI, Inc., a Delaware corporation.
Address: 3409 75th St, Jackson Heights, NY 11372
Contact: spencerwalthall@trykitch.ai
Photos
Kitch handles two kinds of photos and treats them differently. This distinction matters, so it comes first.
Scan photos: fridge, pantry and receipts
What we do with one. When you scan, the image is sent over an encrypted connection to our servers and then to OpenAI, which identifies what's visible. OpenAI returns a list. That list becomes your pantry, on your device.
We do not store the image. It is held in memory only for the few seconds the scan takes and is never written to our servers, our database or any file storage. When the scan finishes, the image is gone. There is no photo history on our side and nothing for us to delete later.
What is sent. The image and nothing else. Your name, email address and account identifier are not sent to OpenAI.
What OpenAI does with it. OpenAI processes the image as a service provider. Under OpenAI's API terms your image is not used to train OpenAI's models. OpenAI retains a copy for up to 30 days for abuse monitoring and then deletes it, unless a longer period is required by law.
What we ask of you. Before your first scan, Kitch shows a consent screen naming OpenAI and explaining this. Scanning does not happen until you agree, and you can withdraw consent at any time in Settings.
What to keep out of frame. A fridge photo can capture more than food, including medication, documents on the door, artwork or people in the background. A receipt shows the store, the date and everything you bought. We only extract food items, but the whole image is transmitted. Point the camera at what you want read.
Dish photos: pictures you attach to your own recipes
These are stored, and this is the exception to everything above. When you save your own recipe in Kitch's recipe book you can attach a photo of the finished dish. Unlike a scan photo, that image is uploaded to our file storage and kept, because the recipe would not be much use without it.
Where it goes. Firebase Storage, under a folder tied to your account.
Who can see it. Only you, until you choose to share the recipe. If you share a recipe using its share code, that recipe and its photo become readable by anyone who has the code. Treat a shared dish photo as public.
How to get rid of one. Delete the recipe, and the photo goes with it. Deleting your account removes all of them.
Everything we collect
You give us:
- Account details: name and email address
- Dietary information: allergies, restrictions and preferences
- Photos of your fridge, pantry and receipts, which we process and discard
- Dish photos you attach to your own recipes, which we keep
- Recipes you write and anything you type into them
- Anything you type in, such as manual pantry items
We generate or observe:
- Recipe suggestions and the pantry list built from your scans
- How you use the app: screens viewed, features used, actions taken
- Crash and error reports, which go to PostHog
We do not collect:
- Payment information. Kitch has no payment system. Nothing is charged and no card details exist anywhere in the product.
- Screen or session recordings. Session replay is switched off.
- Console output from the app. Console capture is switched off in our analytics, so nothing typed or scanned leaks into analytics that way.
What stays on your phone
This is worth stating plainly, because it covers most of what Kitch knows about you.
Your pantry, meal plan, grocery list, favourites and cooking history are stored on your device. They are not uploaded to us and we cannot read them. If you delete the app, that data is gone.
The only thing Kitch stores on our servers is your account, the recipes you choose to save to your recipe book, and any dish photos attached to them.
Allergy and dietary data
Allergy and dietary information can reveal health conditions, so we treat it as sensitive.
Where it goes. It is sent to our servers with each scan so we can filter recipes to match. Our recipe service is stateless, which means it uses your preferences to answer that one request and stores nothing.
Where it does not go. It is not sent to OpenAI. It is not sent to Spoonacular, which receives only ingredient names. It is not written to any database of ours.
Analytics. When you change a restriction, our analytics records that a change happened and how many restrictions are now active. It does not record which ones. The specific values, such as a nut allergy, are never sent to our analytics provider.
It is not sold, not used for advertising, and not shared with any third party.
Who we share data with
We do not sell your personal information. We do not share it for cross context behavioural advertising.
| Provider | What it does | What it receives |
|---|---|---|
| OpenAI | Identifies what's in your scan photos | The image only. No account identifiers, no dietary information. |
| Spoonacular | Supplies recipe data | Ingredient names and recipe IDs. No account identifiers, no dietary information. |
| Google Cloud Platform | Hosts our servers, in the United States | Data in transit and during processing |
| Firebase (Google) | Login, recipe database, dish photo storage | Account details, saved recipes, dish photos |
| PostHog | Product analytics and crash reporting | App usage events, error reports, and your account identifier |
We may also disclose information if required by law, to protect the safety of users, or in connection with a merger or acquisition. If ownership of Kitch changes, we'll tell you before your data moves under a different privacy policy.
How long we keep things
| Data | Retention |
|---|---|
| Account details | Until you delete your account |
| Saved recipes and dish photos | Until you delete the recipe, or your account |
| Pantry, meal plans, grocery list, favourites | Stored on your device, not by us |
| Fridge, pantry and receipt photos | Not stored. Discarded when the scan completes. |
| Dietary and allergy information | Not stored by us. Used for the request and discarded. |
| Analytics and error events | 12 months |
| Backups | We keep no restorable backups. When deletion completes, the data is gone. |
When you delete your account we delete your personal data immediately, except where we're required to keep records for legal or accounting reasons.
Your choices and rights
In the app you can:
- Edit or delete individual pantry items, recipes and dietary information
- Withdraw consent for AI photo processing in Settings. Scanning stops, and you can still add pantry items by hand.
- Delete your account from the Profile screen. This deletes your saved recipes, your dish photos, everything Kitch has stored on your device, and your login itself. If you haven't signed in recently, Firebase will ask you to sign in again first, because it requires a recent login before it will delete an account.
Depending on where you live, you may also have the right to:
- Know what personal information we hold and get a copy
- Correct inaccurate information
- Delete your information
- Limit our use of sensitive personal information
- Not be discriminated against for exercising any of these rights
To make a request, email spencerwalthall@trykitch.ai. We'll respond within the time required by law, generally 45 days. We may need to verify your identity first.
California residents: we do not sell or share personal information as those terms are defined under the CCPA, and have not done so in the preceding 12 months.
Children
Kitch is for people aged 13 and over. We don't knowingly collect personal information from anyone under 13.
Parents may enter dietary information about children in their household, such as a child's allergy, so meal plans work for the whole family. That information is used to filter recipes and is not stored on our servers. Please enter only what's needed for meal planning.
If you believe a child under 13 has created an account, contact spencerwalthall@trykitch.ai and we'll remove it.
Security
Data is encrypted in transit using TLS and at rest by our infrastructure providers. Access to production data is limited to people who need it. Scan photos are never written to storage, so there is no archive of your fridge to breach.
No system is perfectly secure and we can't guarantee absolute security, but we'll notify you and any required authority if a breach affects your personal information.
Where your data is processed
Kitch runs in the United States, in Google Cloud's us-central1 region, and your data is processed there. OpenAI also processes in the United States. If you use Kitch from outside the US, you're sending your information to a country whose data protection laws may differ from your own.
Changes to this policy
If we change how we handle your data in a way that matters, we'll tell you in the app before it takes effect and update the date at the top. Material changes to AI processing will require fresh consent.
Contact
spencerwalthall@trykitch.aiKitch AI, Inc.
3409 75th St, Jackson Heights, NY 11372