Pivot to Data

Legal

Pantree Privacy Policy

How Pivot To Data LLC handles information in the Pantree app. Analytics are off until you turn them on, your health answers never leave your device, and we do not advertise, track across apps, or sell your data.

Last updated: September 4, 2026

This Privacy Policy explains how Pivot To Data LLC (“Pivot To Data LLC,” “we,” “us,” or “our”) collects, uses, and shares information in connection with the Pantree mobile application (the “App”). Pantree is a food and beverage label scanner that scores products and suggests alternatives based on preferences you set. By using Pantree, you agree to this Policy.

The short version

  • Analytics are off until you turn them on. During setup we ask once. Declining changes nothing about how Pantreeworks — the scanner, scores, and recommendations are identical either way. You can change your mind at any time in Settings → Privacy & Data.
  • Your health answers never leave your device. Age band, sex, pregnancy or nursing status, and any blood-pressure, blood-sugar, or cholesterol flags are stored locally and are never transmitted. Your scan history and saved products are also device-only.
  • Location is optional, off by default, and never precise. If you turn it on, Pantreerecords an area of roughly 25 km² — a metropolitan area, not a street or address. Exact coordinates are never stored or transmitted.
  • No sign-in, name, or email is required. The App creates an account identified only by a random identifier.
  • No advertising and no cross-app tracking.We do not use the Apple advertising identifier, do not track you across other companies’ apps or websites, and do not sell your personal information.
  • Camera is used only to scan labels. Images are processed on your device. Only a screenshot you explicitly attach to a support report is uploaded.
  • Apple handles payment details. RevenueCat receives the pseudonymous account identifier and subscription transaction information needed to provide and restore Pantree Pro. Your card number and other payment credentials never enter Pantree.

A note on the word “anonymous”

Your account has no name, email, or phone number attached. But the identifier it uses is stable, which means the events recorded under it can be associated with one another. The accurate word for this is pseudonymous, not anonymous, and we use that word throughout this Policy rather than overstating the protection.

Information we collect

Information stored only on your device

The following is stored locally and is never transmitted to us:

  • Your personalization profile: diets, avoided or flagged ingredients, allergen and dealbreaker selections, and goals.
  • Your health-related answers: age band, sex, pregnancy or nursing status, and blood-pressure, blood-sugar, or cholesterol flags.
  • Your scan history, captured product photos, viewed products, and in-app preferences.

Because this information lives on your device, deleting the App removes it. We cannot access, retrieve, or restore it.

Camera and label scanning

The App requests camera access so you can scan product barcodes and labels. Images are processed on your device and are not sent to us. When you use label capture, the product photo may be stored in the App’s local Application Support directory so the captured product remains useful. It is not uploaded.

Your account identifier

An account is created automatically on first launch. No sign-up, email, or password is required. It exists so that your support reports and — if you opt in — your analytics events can be associated with you and deleted at your request. It is a random identifier, and as noted above it is pseudonymous rather than anonymous.

Pantree Pro subscriptions

Subscription purchases are processed by Apple through the App Store. To unlock, maintain, and restore Pantree Pro, our subscription processor RevenueCat receives your pseudonymous App account identifier together with the subscription product, transaction and entitlement status, trial status, renewal or expiration status, and purchase or restore outcome. Apple handles payment credentials; Pantree and RevenueCat do not receive your full card number or Apple Account password.

Analytics — collected only if you opt in

Analytics collection is off until you opt in. We ask once, as a step during setup, where declining is an equally weighted choice and dismissing the request counts as declining. If you decline, no analytics events are transmitted.

If you opt in, we collect through our providers PostHog and Supabase:

  • Products scanned, scores shown, and recommendations displayed, opened, and selected.
  • Products you save or remove, and optional structured feedback about why a product did or did not suit you.
  • A random session identifier, app version, build number, OS version, device class, locale, and scan method.
  • The length of a search term and the number of results it returned — not the text you searched for.
  • Setup steps viewed or completed and time spent on them; optional fixed-choice answers about how you heard about Pantree, why you downloaded it, what interrupted setup, or why you chose the free plan. These questions collect no free-text answer.
  • Subscription product, trial status, and purchase, cancellation, pending, restore, or fixed-category failure outcome. Payment credentials are handled by Apple and do not enter Pantree.

This data does not include your name, email address, your health answers, your personalization profile, your feedback text, scanned images, product photos, or screenshots. Session replay, screen recording, and network telemetry are disabled.

When you tell us why you rejected a product, a dietary reason is recorded as a single general category. It never identifies a specific allergen or medical condition.

You can withdraw consent at any time in Settings → Privacy & Data. On withdrawal, transmission stops immediately, anything still queued on your device is deleted, and the analytics identity is reset.

Approximate location — optional and off by default

Location is off unless you turn it onin Settings → Privacy & Data under “Add Approximate Location to Scans.” All of the following are true and are enforced by the App:

  • Pantree asks only for “While Using the App” permission. It never asks for Always access and has no background location capability.
  • Permission is requested only when you switch the setting on — never at launch, and never from the scanner.
  • The scanner works normally when location is off or denied.
  • Exact coordinates are never stored or transmitted. A position is converted on your device into an approximate area identifier, and the precise reading is discarded immediately.
  • The stored area is roughly 25 km² — a metropolitan area, not a street, building, or address. Our database has no latitude or longitude column, and the area field is length-limited so a more precise value cannot be stored in it.
  • Pantree does not build movement histories, visit histories, or home and work inferences.
  • Location is recorded only as part of an analytics event, so turning analytics off also turns location off.

Alternatively, you may simply pick a store from a list, which records the same kind of approximate area without using location services at all.

Feedback and support

If you submit feedback through the App, we collect through Supabase: any structured selections, optional free text you write, an optional screenshot you choose to attach, the screen or product you were viewing, your app version and build, your iOS version and device model, and your account identifier. Please do not include personal or sensitive information in free-text feedback. Attached screenshots are stored in a private, restricted location readable only by your account.

Missing-label reports

When a scanned product has incomplete label data, Pantree records which fields were missing so the record can be improved. These reports carry no user identifier of any kind — the row describes a barcode and its missing fields, not a person. This limit is enforced by the database schema, not merely by policy.

Crash reports and diagnostics

Crash reports and fixed error codes are collected through PostHog to diagnose defects. Crash reporting operates whether or not you opt in to analytics. We state this plainly because it is an exception to the opt-in described above.

TestFlight

If you access Pantreethrough Apple TestFlight, Apple may separately collect tester-submitted screenshots, comments, and crash feedback, and may share diagnostic information with us, under Apple’s TestFlight terms and privacy policy.

How we use information

  • To operate the App and your account.
  • To provide, maintain, and restore Pantree Pro access.
  • To improve product scores and recommendations. Recommendations are computed from your own scans, saved products, feedback, and stated preferences.
  • To understand aggregate product and category trends.
  • To diagnose crashes and defects.
  • To respond to your feedback and provide support.
  • To comply with legal obligations and enforce our Terms.

We do not use your information for advertising, ad measurement, or audience building. No such purpose exists in the App.

How we share information

We do not sell your personal information, and we do not share it for advertising or cross-app tracking. We share information only with:

  • PostHog, which receives product analytics events and crash reports, as a processor.
  • Supabase, which receives the account, analytics tables, and support reports and screenshots, as a processor.
  • RevenueCat, which receives subscription transaction and entitlement information needed to provide and restore Pantree Pro, as a processor.
  • Apple, for App Store distribution and TestFlight testing when applicable.
  • Legal and safety recipients, if required by law or to protect our rights, users, or the public.
  • A successor entity in connection with a merger, acquisition, or sale of assets, subject to this Policy.

Neither processor is permitted to use the data for its own purposes. Pantree uses no advertising or attribution SDKs.

Data retention

  • User-level analytics: retained for 400 days, then deleted.
  • Account, support reports, and screenshots: kept for the life of your account.
  • Subscription entitlement records:retained by RevenueCat as needed to provide and restore the subscription, under the retention settings for Pantree’s RevenueCat account.
  • Scan history and saved products: stored on your device only, for as long as you keep the App.
  • Aggregate statistics may be kept longer, but only as genuine aggregates.

We do not describe user-level records with the identifier removed as “anonymized.” Stripping an identifier from a sequence of timestamped scans does not make it anonymous, and we will not claim otherwise.

Security

  • All transmission uses HTTPS/TLS.
  • Every analytics table is row-level-secured: you can read and delete only your own rows, and no client role can read across users. Analytics rows are immutable once written.
  • The event queue on your device is written with complete file protection and excluded from backups.
  • Precise coordinates and analytics payloads are never written to our production logs.
  • We restrict staff access to feedback and diagnostics and keep privileged credentials off the device.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

Your choices and rights

Inside the App you can:

  • Delete Analytics Data — removes analytics held on your device and deletes your analytics rows on our servers. Your scan history and saved products are unaffected.
  • Delete Account — permanently deletes your account and everything linked to it, including analytics and support content, together with Pantree’s data on your device. Deleting the account does not cancel an Apple subscription; subscriptions are managed separately in Apple Account settings.
  • Withdraw analytics consentat any time in Settings → Privacy & Data.
  • Turn approximate location off in the same place. The underlying iOS permission is managed in the iOS Settings app.

Depending on where you live, you may also have rights to access, correct, delete, or restrict the processing of personal information we hold, and to object to certain processing. Because we identify data only by a random identifier and do not collect your name or email, we may need additional information to locate it. To make a request, contact us at founder@pivottodata.com. We do not discriminate against you for exercising these rights.

Tracking, sale, and sharing

  • Pantree does not track you across apps or websites owned by other companies.
  • Pantree does not use the Apple advertising identifier (IDFA).
  • Pantree does not sell personal information.
  • Pantree does not share personal information with data brokers or advertising networks.

We do not “sell” or “share” personal information for cross-context behavioral advertising as those terms are defined under U.S. state privacy laws.

Children’s privacy

Pantree is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided us information, contact us and we will delete it.

International users

We operate from the United States, and our service providers may process data in the United States and other countries. If you use the App from outside the United States, you understand your information may be transferred to and processed in the United States.

Changes to this Policy

We may update this Policy from time to time. When we do, we will revise the “Last updated” date above and, where appropriate, provide additional notice in the App.

Contact us

Pivot To Data LLC · founder@pivottodata.com

Get in touch