Ambry — Privacy Policy

Effective 3 September 2026. (Previous version 23 August 2026. What changed: Instagram (Meta) is now named as a service that reads a link you import a recipe from; RevenueCat, a subscription-management SDK that is bundled but switched off and sends nothing, is now disclosed; and Recipe ideas is described accurately — it sends how soon each food expires as well as its name.)

Ambry is made by one person, Everett Yan. This policy says what the app stores, what leaves your phone, and what you can delete. It is written to be read, not to be survived — if something here is unclear, email me and I will fix the wording.

Contact: everettyan@gmail.com


The short version


What Ambry stores

Your account

Since 23 August 2026 the sign-in system runs on Ambry’s own server rather than a third-party sign-in service, and its records live in the same database as everything else described here. No identity vendor holds your account.

What you put in the app

Everything you enter or capture into your kitchen: food items and where they are stored, the storage locations and zones you create, expiry dates, stock status, grocery list entries, notes, household names and invite codes, and your recipes — titles, ingredients, steps, tags, and any recipe photo you add.

Two things about this data are worth being explicit about:

Settings and housekeeping

What Ambry does not store


AI processing

Some Ambry features work by sending your input to an AI model. In every case:

The features that do this:


Other services Ambry relies on

Service What it does What it gets
Neon Hosts the database, including the sign-in records Your account and everything you save
Cloudflare Runs the API and the sign-in service itself, stores recipe photos, syncs households live Requests you make; your sign-ins; recipe photos
Anthropic The AI model behind the features above Only the content described above
Open Food Facts Looks up products you scan by barcode Only the barcode digits — no user, household, or device information
Expo Delivers the daily reminder to your phone, on to Apple’s push service Only while server reminders are on: this device’s push token and the text of the notification, which names the food that is going off
Apple Distributes the app, handles any subscription, and — only if you tap Sign in with Apple — confirms it is you Whatever Apple’s own terms describe; I see no payment details. For sign-in: Apple learns you use Ambry, and returns an email address (or a Hide My Email relay) plus, on the first sign-in only, your name
Google Confirms it is you — only if you tap Sign in with Google That you signed in to Ambry; it returns your email address and profile name, and nothing about your kitchen goes the other way
RevenueCat Would manage subscriptions — switched off today, because nothing is for sale in this build Nothing at all today. When subscriptions go live it receives your Ambry user id and the App Store purchase receipt — never your card number, and nothing about your kitchen. This row changes before that build ships
YouTube (Google) Reads the description of a YouTube link you import a recipe from Only the video’s id, sent from our server — never your account, household, or device information
TikTok Reads the public caption of a TikTok link you import a recipe from Only the link you pasted, sent from our server — never your account, household, or device information
Instagram (Meta) Reads the public caption of an Instagram link you import a recipe from Only the link you pasted, sent from our server — never your account, household, or device information. You are never signed in to Instagram on our behalf

Ambry also uses public food data from Open Food Facts (product names, photos and nutrition, under ODbL/CC-BY-SA — credited in the app wherever it is shown) and from the USDA (FoodData Central and FoodKeeper, public domain). None of that involves your data going anywhere.


Deleting your account and your data

Open Profile → Delete account in the app. It asks you to type DELETE, and then it is immediate and permanent — there is no undo and no grace period.

What goes: your profile and sign-in, all of your recipes including any you published, your recipe photos, and any household where you are the only member, with everything in it.

What stays: households you share with other people — they keep the pantry, the list, and the locations, and you are simply removed. Recipes other people wrote are theirs and are untouched.

Two things worth knowing:

If you would rather not do it in the app, email everettyan@gmail.com from the address on the account and I will delete it by hand.


Security

Every table in the database denies access by default and opens only to the rows you are entitled to — your household’s data, your own recipes, plus public recipes. All traffic is HTTPS. AI provider keys live only as server secrets and are never in the app you download.

No system is perfect, and I am one person. If you find something wrong, email me before telling the internet and I will fix it quickly.

Children

Ambry is not directed at children under 13 and does not knowingly collect their data. If you believe a child has created an account, email me and I will delete it.

Changes

If this policy changes materially, the effective date at the top changes and the new version is published here before the change takes effect. Its full history is in the repository’s git log, which is public.

Contact

everettyan@gmail.com — questions, deletion requests, or corrections to this page.