PRIVACY
Data Protection Policy
Food name, quantity, category, storage location, best-before date, opened state, notes, and the update time are stored in a Cloudflare D1 database managed by the operator. Nothing is stored in your browser (only the language preference remains in this device's Local Storage).
On first access, the server automatically issues an anonymous account and links it to your browser with an httpOnly cookie (name pantry_session, SameSite=Lax, 400-day expiry). This cookie is required for PANTRY to function and is not used for advertising or analytics. If you delete the cookie or switch to a different browser or device, you can no longer reach the food data tied to it.
Registering an email address and password promotes your existing anonymous account in place, so you keep your data while being able to use it from multiple devices. Passwords are stored as a salted PBKDF2-SHA256 hash; the password itself is never stored. Data is transmitted over HTTPS.
An anonymous account that has not registered an email address is automatically deleted 400 days after its last access. Accounts with a registered email address are not subject to this automatic deletion.
Exported JSON files contain your records as plain text. Do not place them in a shared folder; save them somewhere under your control.
“Delete all” erases the entire list on the server. Logging out switches you to a new anonymous account, and the previous list becomes unreachable (until you log back in, if you still hold the credentials). Contact the WorksHub operator if you need the account itself deleted.