Privacy Policy — Hungry Shelf
Effective date: 24 August 2026 Last updated: 24 August 2026
Hungry Shelf ("Hungry Shelf", "the app", "we", "us") is operated by Udaya Shree Donthula, an individual developer trading as Hungry Shelf. There is no company behind the app. This policy explains what data the app collects, why, who we send it to, and how you can delete it.
Contact for privacy questions and data requests: hungryshelfinfo@gmail.com
1. Summary
- You can use Hungry Shelf without an account ("guest mode"). In guest mode, your recipes stay on your phone.
- Your recipe library lives on your device first. A cloud copy is created when you sign in and merge your guest library.
- Recipe imports send the link you shared (and, for photo scans, the photo) to our server and to AI providers so a recipe can be extracted.
- Hands-free cook mode streams your microphone audio live to our AI voice provider. Hungry Shelf does not record or store that audio.
- We use no advertising, analytics, or crash-reporting SDKs. We do not collect your location, contacts, or advertising ID, and we do not sell your data.
2. Data we collect
2.1 Account data (only if you create an account)
| Data | When | Why |
|---|---|---|
| Email address | Email sign-up, or supplied by Google / Apple sign-in | Identify your account, sign you in, account recovery |
| Password | Email sign-up only — stored hashed by our auth provider, never in plain text | Authentication |
| Display name | Supplied by Google / Apple, or set by you | Show your name in the app |
| Profile picture URL | Supplied by Google / Apple if available | Show your avatar. We do not copy or host the image |
| Account ID | Automatically | Link your recipes and settings to your account |
If you use Google or Apple sign-in, that provider tells us your email and name. We do not receive your Google or Apple password. Apple's "Hide My Email" is supported — we only ever see the relay address Apple gives us.
2.2 Content you create
- Recipe titles, descriptions, ingredients, quantities, units, steps, timers, notes, tips, servings and cooking times
- Source links and cover-image URLs of recipes you import
- Cookbooks you create and which recipes are in them
This content is stored in a database on your device. If you sign in, a copy of your recipes is stored on our servers so it is not lost with your phone.
2.3 Onboarding answers
The goals and recipe sources you pick during setup (for example "eat healthier", "from social media"). Stored on your device, and on our servers if you are signed in. Used to tailor the app; not used for advertising.
2.4 Import data
When you import a recipe from a link, we store an import job record containing the source URL, processing status, timing, error codes and the extracted recipe draft. This is what lets an import resume, retry, and be debugged when extraction fails.
For imports made without an account, our server temporarily records your IP address in a rate-limit counter to prevent abuse of a costly AI pipeline. It is not linked to a profile and is not used to identify you.
2.5 Photos (recipe photo scan)
If you scan a cookbook page, handwritten card or screenshot, the app resizes the image and sends it to our server, which forwards it to our AI vision provider to read the recipe. The image is not saved to our database or file storage — only the recipe text that comes back, and only if you choose to save the recipe.
The app requests camera and photo-library access only for this feature.
2.6 Microphone and voice (hands-free cook mode)
While cook mode is active, your microphone audio is streamed in real time to our AI voice provider so it can answer questions and follow along. Recipe text (title, ingredients, steps) is sent as part of the conversation so the assistant knows what you are cooking.
Hungry Shelf does not record, transcribe to storage, or retain your audio. The stream exists only for the duration of the session and the microphone is released when you leave cook mode.
2.7 Purchases
Hungry Shelf Plus subscriptions are processed by Google Play or the Apple App Store. We never see or store your payment card. The app stores only a local flag recording that your subscription is active, plus a per-user counter used to enforce fair use limits.
2.8 Device settings
Stored only on your device: measurement units, voice hints on/off, keep-screen-on, language, onboarding completion, and free-tier usage counters.
2.9 What we do not collect
No advertising or analytics SDKs. No crash-reporting SDK. No location. No contacts, calendar or health data. No advertising identifier. No tracking across other apps or websites. No push notifications.
3. Why we use your data (legal bases under GDPR)
| Purpose | Legal basis |
|---|---|
| Provide the app, save your recipes, sync your library | Performance of a contract |
| Import and extract recipes from links and photos you supply | Performance of a contract |
| Run hands-free cook mode | Performance of a contract |
| Prevent abuse and control AI costs (rate limits, quotas) | Legitimate interests |
| Diagnose failed imports | Legitimate interests |
| Process subscriptions | Performance of a contract |
| Comply with law | Legal obligation |
We do not use your data for advertising or profiling, and we do not make automated decisions with legal effect about you.
4. Who we share data with
We do not sell your personal data. We share it only with the service providers below, only to the extent needed to run the app.
| Provider | What it receives | Purpose |
|---|---|---|
| Supabase (hosting, database, auth) | Account details, your recipes, onboarding answers, import records | Backend hosting and authentication |
| OpenAI | Post captions and transcripts, page text, photos you scan, live cook-mode audio, recipe text | AI recipe extraction and the voice assistant |
| Supadata | The social or web URL you import | Fetching post metadata and video transcripts |
| Jina Reader | The web URL you import | Reading article pages |
| Instagram / TikTok / Pinterest (public oEmbed endpoints) | The public post URL | Retrieving public post metadata |
| Google (Sign-In) | Authentication request | Google sign-in |
| Apple (Sign in with Apple) | Authentication request | Apple sign-in |
| Google (STUN server) | Network connection metadata only | Establishing the voice connection |
| Google Play / Apple App Store | Purchase transaction | Subscription billing |
These providers process data under their own privacy policies. Our providers are instructed to process data only on our behalf, and AI providers are used through their API tiers, which do not train models on API data by default.
We may also disclose data if required by law, or to protect the rights, safety or property of users or of Udaya Shree Donthula.
International transfers
Our providers operate servers in the United States and other countries, so your data may be transferred outside your country of residence. Where required, transfers out of the EEA and UK rely on Standard Contractual Clauses.
5. How long we keep data
| Data | Retention |
|---|---|
| Account and recipes | Until you delete the recipe or your account |
| On-device library and settings | Until you delete the app data, or delete your account in the app |
| Import job records (source URL, status, extracted draft) | Detached from your account when you delete your account, then retained up to 90 days for abuse prevention and debugging before deletion |
| Anonymous rate-limit counters (including IP) | 24 hours |
| Photos you scan | Not retained after extraction |
| Cook-mode audio | Not retained |
6. Your rights and how to delete your data
You can request access, correction, deletion, a copy of your data, restriction of processing, or object to processing. Where processing rests on consent (for example microphone or camera access) you may withdraw it at any time in your device settings.
Delete your account in the app: Profile → Settings → Delete account. This permanently deletes your account, your cloud recipes and cookbooks, and your onboarding answers, and clears the recipe library on that device. It cannot be undone.
Delete your account without the app: email hungryshelfinfo@gmail.com from your account email address with the subject "Delete my account". See https://hungryshelf.com/delete-account for the full procedure and timelines. We respond within 30 days.
Deleting your account does not cancel a paid subscription — cancel that in your Google Play or Apple App Store subscription settings.
California residents
We do not sell or share personal information as those terms are defined by the CCPA/CPRA, and we do not use it for cross-context behavioural advertising. You may exercise your rights to know, delete and correct using the contacts above, and we will not discriminate against you for doing so.
Complaints
If you are in the EEA or UK you may complain to your local data protection authority. We would appreciate the chance to resolve the issue first at hungryshelfinfo@gmail.com.
7. Children
Hungry Shelf is not directed to children and is not intended for anyone under 13 (or under 16 in the EEA/UK, where local law requires it). We do not knowingly collect data from children. If you believe a child has given us data, contact hungryshelfinfo@gmail.com and we will delete it.
8. Security
All traffic between the app, our servers and our providers uses HTTPS/TLS. Passwords are hashed by our authentication provider. Database access is restricted per user with row-level security so one account cannot read another's recipes. Server-side rate limits protect the AI pipeline from abuse.
The recipe database on your phone is stored in your app's private storage and relies on your device's own protection — please use a screen lock. No system can be guaranteed perfectly secure.
9. Changes to this policy
If we make material changes we will update the date above and notify you in the app or by email before the change takes effect. Continued use after that constitutes acceptance.
10. Contact
Udaya Shree Donthula Individual developer trading as Hungry Shelf hungryshelfinfo@gmail.com
No separate Data Protection Officer has been appointed. Privacy requests go to the email above. No separate EU or UK representative has been appointed; the same email is the contact for data-protection enquiries from any country.