1. 适用范围
本政策适用于 PantryPlan AI Android 应用、公开产品网站以及用于 AI 增强和匿名额度管理的 PantryPlan AI 服务端。应用无需注册账号,也不要求姓名、手机号、电子邮箱或精确位置。
我们不接入广告 SDK、第三方行为分析 SDK、社交登录或跨应用追踪。公开网站不使用 Cookie、追踪像素或外链字体。
2. 保存在设备上的数据
家庭人数与餐次设置、库存、日期、偏好与排除条件、菜单、购物清单、收藏、烹饪历史、自建食谱和应用设置默认只保存在你的设备上。这些数据用于本地搜索、确定性菜单生成、库存计算、备份和恢复。
匿名安装令牌由 Android Keystore 保护,不写入普通数据库、导出文件或日志。你导出的备份由你自行选择保存和分享的位置,我们无法访问该文件。
3. 服务端处理的数据
Cloudflare Worker 只保存匿名安装令牌的不可逆哈希、令牌状态、UTC 日维度的 AI 使用次数、最少的反馈类别与诊断元数据,以及目录或公开配置版本。服务端不持久化家庭档案、库存明细、完整菜单、完整 Prompt 或 AI 原始输出。
运行日志只允许包含请求 ID、耗时、HTTP 状态、模型标识和匿名错误类别。我们不故意记录令牌、家庭信息、库存、排除食材或请求正文。Cloudflare 作为基础设施提供方可能按其服务条款处理连接与安全元数据。
4. AI 增强如何处理数据
AI 增强默认可关闭。只有你主动生成 AI 菜单、替换菜品或修复计划时,应用才会把完成该请求所需的数据发送给 PantryPlan AI Worker,其中可能包括人数与餐次、时间与厨具、预算范围、饮食偏好、排除条件、库存条目、临期状态和候选食谱标识。
Worker 会严格校验请求,然后把必要内容临时转发给运营方配置的 OpenAI-compatible AI 中转服务,当前模型为 glm-5.2。中转服务及其上游模型提供方可能为生成结果处理这些数据。请求只在完成本次响应所需的内存生命周期内使用,PantryPlan AI 不把请求正文写入 D1、KV 或应用日志。
AI 输出必须再次经过结构校验与硬约束验证。失败、超时、额度耗尽或关闭 AI 时,应用会回退到本地或服务端的确定性规划。请不要在偏好、自建食谱或反馈中填写姓名、联系方式、病历等不必要的个人信息。
5. 数据保留期限
- 匿名日额度明细:最多 35 天,之后删除或聚合为不可关联统计。
- 不含请求正文的运行日志:最多 14 天。
- 最少化反馈记录:最多 180 天,执行全部删除时提前清除可关联记录。
- 匿名安装记录:主动删除时立即撤销并删除;连续 180 天无活动时清理。
- 设备本地数据:保留到你在应用内删除、清除应用数据或卸载应用。
6. 删除、导出与恢复
你可以在“设置 > 数据与隐私”中导出本地备份、恢复备份,或选择“删除全部数据”。全部删除会立即清理本地业务数据,并向服务端请求撤销匿名安装记录和可关联反馈。
如果删除时离线,本地删除仍会执行;应用会暂时保留由 Keystore 保护的删除凭证和“待远程删除”状态,用于联网后重试,成功后立即清除凭证。恢复备份前会先检查版本、结构和完整性,失败时不会覆盖现有数据。卸载应用会删除其本地沙箱,但不会自动送达服务端删除请求,建议先在应用内执行全部删除。
7. 安全措施
应用与 PantryPlan API 之间使用 HTTPS。当前经授权配置的 AI 中转站只提供 HTTP,因此开启在线 AI 时,最少化的规划约束与候选信息在 PantryPlan API 到该中转站这一段不具备传输加密;在中转站提供有效 TLS 前,我们不会把它表述为端到端加密。你可以关闭 AI 或启用离线模式来避免该传输。
匿名令牌由 Android Keystore 保护;服务端执行请求体上限、严格 Schema 校验、安装维度额度、速率限制与最少日志。Provider 密钥只作为 Worker Secret 注入,不进入 Android 安装包、网站或版本库。任何系统都无法承诺绝对安全。若发现可能影响用户的安全事件,我们会按适用法律和发布渠道要求处理并提供通知。
8. 健康与内容边界
PantryPlan AI 只提供一般家庭膳食规划,不是医生、营养师或紧急服务。结果不用于诊断或治疗疾病,不承诺严重过敏安全,也不能替代核对商品标签。孕期、儿童营养、慢性病、进食障碍或严重过敏等情况,请咨询具备资质的专业人士。
9. 儿童隐私
应用面向负责家庭膳食安排的成年人,不以儿童为目标用户,也不要求儿童建立资料。家庭中的儿童份量只作为设备上的菜单计算设置。如果监护人认为儿童向反馈入口提交了个人信息,请通过应用内反馈联系我们处理。
10. 你的选择
你可以不启用 AI、随时切换离线模式、取消通知权限、查看和修改本地资料、导出备份以及删除全部数据。由于没有账号体系,我们通常无法凭姓名或邮箱定位匿名安装记录,应用内删除令牌是最可靠的关联方式。
11. 政策变更与联系
功能、数据流或保留规则发生实质变化时,我们会更新本页、生效日期和 Google Play Data safety 信息,并在必要时通过应用内明显位置提示。
关于隐私、数据删除或安全问题,请使用应用内“设置 > 反馈”。在 Google Play 上线后,也可使用商店详情页公布的开发者联系渠道。
1. Scope
This policy applies to the PantryPlan AI Android app, its public website, and the PantryPlan AI service used for optional AI assistance and anonymous quota management. No account is required, and we do not ask for your name, phone number, email address, or precise location.
We include no advertising SDK, third-party behavioral analytics SDK, social login, or cross-app tracking. The public website uses no cookies, tracking pixels, or remote fonts.
2. Data stored on your device
Household size and meal settings, pantry items and dates, preferences and exclusions, plans, shopping lists, favorites, cook history, personal recipes, and app settings stay on your device by default. They support local search, deterministic planning, pantry calculations, backup, and restore.
The anonymous installation token is protected with Android Keystore and is excluded from the ordinary database, exports, and logs. You choose where exported backups are stored or shared. We cannot access those files.
3. Data processed by the service
The Cloudflare Worker stores only an irreversible hash of the anonymous installation token, token status, daily UTC AI usage counts, minimal feedback categories and diagnostic metadata, and catalog or public configuration versions. It does not persist household profiles, pantry details, full plans, complete prompts, or raw AI output.
Operational logs may contain only a request ID, duration, HTTP status, model identifier, and anonymous error category. We do not intentionally log tokens, household information, pantry items, exclusions, or request bodies. Cloudflare may process connection and security metadata under its own service terms as our infrastructure provider.
4. How AI assistance processes data
AI assistance can be disabled. Only when you ask for an AI plan, meal swap, or repair does the app send data needed for that request to the PantryPlan AI Worker. This may include servings and meals, time and appliances, budget range, dietary preferences, exclusions, pantry entries, expiry state, and candidate recipe identifiers.
The Worker validates the request and temporarily relays necessary content to the operator-configured OpenAI-compatible AI relay, currently using the glm-5.2 model. The relay and its upstream model provider may process this content to generate a result. PantryPlan AI uses request content only in memory for the response and does not write it to D1, KV, or application logs.
AI output is parsed and validated against hard constraints. When AI is disabled, unavailable, over quota, or invalid, the app falls back to deterministic planning. Do not place names, contact details, medical records, or other unnecessary personal information in preferences, personal recipes, or feedback.
5. Retention
- Anonymous daily quota records: up to 35 days, then deleted or aggregated into non-linkable statistics.
- Operational logs without request bodies: up to 14 days.
- Minimal feedback records: up to 180 days, or earlier when linked records are deleted.
- Anonymous installation records: revoked and deleted on request, or cleaned after 180 days without activity.
- On-device data: until you delete it in the app, clear app storage, or uninstall.
6. Delete, export, and restore
Under Settings > Data and privacy, you can export or restore a local backup or choose Delete all data. Deletion immediately clears local business data and asks the service to revoke the anonymous installation and linked feedback.
If the device is offline, local deletion still runs. The app temporarily retains only a Keystore-protected deletion credential and a pending-remote-deletion state so it can retry when online, then clears the credential immediately after success. Restore checks version, structure, and integrity before replacing data, and a failed check leaves existing data unchanged. Uninstalling removes the app sandbox but cannot send a service deletion request, so use Delete all data first when possible.
7. Security
The app-to-PantryPlan API connection uses HTTPS. The currently authorized AI relay exposes only HTTP, so when online AI is enabled, minimized planning constraints and candidate information are not transport-encrypted on the PantryPlan API-to-relay segment. We do not describe this as end-to-end encrypted unless that relay gains valid TLS. You can disable AI or enable offline mode to avoid that transfer.
Anonymous tokens are protected with Android Keystore, and the service applies request size limits, strict schema validation, per-installation quota, rate limiting, and minimal logs. Provider keys are injected only as Worker Secrets and are excluded from the Android package, website, and source repository. No system can guarantee absolute security. We will handle and communicate a qualifying incident as required by applicable law and distribution channels.
8. Health and content boundary
PantryPlan AI provides general household meal planning only. It is not a doctor, dietitian, or emergency service. Results do not diagnose or treat disease, cannot guarantee severe allergy safety, and do not replace checking product labels. Seek a qualified professional for pregnancy, child nutrition, chronic conditions, eating disorders, or severe allergies.
9. Children
The app is intended for adults who organize household meals and is not directed to children. It does not ask children to create profiles. Child serving size is only an on-device planning setting. A guardian who believes a child submitted personal information through feedback can contact us through the in-app channel.
10. Your choices
You can leave AI disabled, switch to offline mode, deny notifications, inspect and change local data, export a backup, and delete all data. Because there is no account system, we generally cannot locate an anonymous installation by name or email. The token held by the app is the reliable link for deletion.
11. Changes and contact
If features, data flows, or retention rules materially change, we will update this page, its effective date, and the Google Play Data safety disclosure. We will use a clear in-app notice when appropriate.
For privacy, deletion, or security questions, use Settings > Feedback in the app. After Google Play release, you may also use the developer contact channel published on the store listing.