🍎 🥑 🥕 🍋 🫐 🍇 🥦 🧀 🥖 🍓
Pastro
Imprint Privacy Terms of Use
Back to homepage Deutsch

Privacy Policy for the Pastro App

This privacy policy applies to the progressive web app “Pastro”, available at pantry.pastro.app. A separate privacy policy applies to the website at pastro.app.

Last updated: 26 September 2026

On this page

  1. Controller
  2. Overview of processing
  3. Relevant legal bases
  4. Security measures
  5. Processors, service providers and other recipients
  6. International data transfers
  7. Retention period and deletion of data
  8. Rights of data subjects
  9. Provision of the app, hosting and local storage
  10. Registration, sign-in and user account
  11. Shared households
  12. Core features: pantry, shopping list, recipes and statistics
  13. AI-assisted features
  14. Audience measurement with Umami
  15. Voluntary support via Buy Me a Coffee
  16. Contact
  17. Changes to this privacy policy

At a glance

  • Pastro is free and ad-free. We do not sell data, do not evaluate individual people and do not run advertising tracking.
  • Your data is stored with our backend provider Appwrite in the EU (Frankfurt am Main region). Free-text content is additionally encrypted there.
  • The AI features (receipt, voice input, recipes) are optional, run through Mistral AI (France) and require your consent. We do not store images or recordings.
  • In a shared household, the members see the same content and each other's display name and email address.
  • Audience measurement with Umami works without cookies, is pseudonymous and can be switched off in the settings.
  • You can delete your account and your data yourself at any time in the settings.

1. Controller

The controller within the meaning of the General Data Protection Regulation (GDPR) and other national data protection laws is:

Jonas Sieder
Zum Freibad 78
14943 Luckenwalde
Germany
Email: contact@pastro.app

Further provider details can be found in the legal notice (imprint).

This privacy policy applies to the progressive web app “Pastro” (hereinafter “app” or “Pastro”), available at pantry.pastro.app. A separate privacy policy applies to the website at pastro.app.

Data protection officer: No data protection officer has been appointed, because there is no obligation to appoint one: fewer than 20 people are permanently engaged in the automated processing of personal data (Section 38 (1) BDSG, German Federal Data Protection Act), and none of the cases in Art. 37 (1) GDPR apply. Please send data protection enquiries to the contact address given above.

2. Overview of processing

Types of data processed:

  • Account and contact data: email address; display name (when you sign in with Google, we take the name from your Google account; you can change it at any time); a user ID assigned by us; time of registration and of your last access; whether your email address has been verified; when signing in with Google, the link to your Google account (section 10).
  • Session data: for each sign-in, the IP address, the country derived from it, browser, operating system and device type, for as long as the session exists (section 10).
  • Content data: groceries recorded in the app (name, category, amount, price, purchase date, estimated expiry date, icon), purchase history, shopping lists, saved product adjustments (name, shelf life, category, icon), recipes (AI suggestions and your own) and your recipe requests (free text).
  • Image, document and audio data: photos, image files or PDF files of receipts as well as voice recordings – only if you use the AI features, and held by us only for the duration of processing (for retention by the AI provider see section 13).
  • Preferences for recipes (optional): free text about taste and cooking habits, e.g. “spicy, no mushrooms, 30 minutes max” (section 13.3).
  • Household data: assignment to your household, your role (owner or member), invitations sent by you or addressed to you with email address, time and status (section 11).
  • Usage and settings data: colour theme, app language, hidden navigation areas, desired number of recipes per request, order of your shopping lists, the version of the Terms of Use you accepted, the times of your AI consent and its withdrawal, weekly counters of AI requests (per household and per person), supporter flag (for this we match the email address reported by Buy Me a Coffee against your account, section 15).
  • Proof of consent: time and wording of your AI consent or its withdrawal; after an account deletion additionally your user ID, a hash value of your email address and the time of deletion (sections 7 and 13).
  • Meta and communication data: technically necessary access data (IP address, time, requested resource, status code, browser identifier) when the app and the servers are accessed (section 9); pseudonymous usage and event data of the cookie-free audience measurement (section 14).

Categories of data subjects: users of the app, including members of a shared household; people who are invited into a household; people who support Pastro via Buy Me a Coffee; people who send us a message; people whose details are contained in an uploaded receipt or a voice recording.

Categories of recipients:

  • our backend provider including its sub-processors (cloud infrastructure, content delivery and web security, email delivery, error monitoring, support),
  • the AI provider for receipt capture, voice input and recipe suggestions – as our processor; for the abuse monitoring of its interface at the same time under its own responsibility (section 13),
  • the provider of the audience measurement including its sub-processors,
  • Google as sign-in service (only when signing in with Google) and as provider of our contact mailbox,
  • Buy Me a Coffee (only if you support Pastro there),
  • in shared households: the other members of your household.

Details on the recipients and on transfers to third countries can be found in sections 5 and 6.

Purposes of processing:

  • Provision of the app, its features and content.
  • Registration, sign-in and management of the user account.
  • Management of pantry, shopping lists, recipes and statistics.
  • AI-assisted recognition of groceries from receipts (photo/PDF) and voice recordings.
  • AI-assisted recipe suggestions from your pantry.
  • Shared use in households including invitations.
  • Proof of consents given and defence against legal claims.
  • Security, prevention of abuse (limit on AI requests) and technical operation.
  • Audience measurement and improvement of the app.
  • Flagging of voluntary support.
  • Responding to your enquiries.

3. Relevant legal bases

We process personal data on the following legal bases of the GDPR; in addition, the national data protection provisions in Germany apply (in particular the BDSG, the German Federal Data Protection Act, and the TDDDG, the German Telecommunications Digital Services Data Protection Act). Each section of this policy states which basis applies to the respective processing.

  • Performance of a contract (Art. 6 (1) (b) GDPR): processing that is necessary to provide the features you request – user account and sign-in, storage and synchronisation of your pantry, shopping lists, product adjustments, recipes and statistics, storage of your preferences for recipes, the household feature including the shared use of the household data by all members, and responding to your enquiries about the app.
  • Consent (Art. 6 (1) (a) GDPR): the three AI-assisted features – receipt capture, voice input and recipe suggestions –, that is, the transfer of your receipt, your recording or your recipe request together with pantry and preferences to the AI provider and the processing there (section 13). If a member of your household uses the AI features, shared household data that you entered (pantry, product adjustments) goes along as well. Towards you, this is based on the household feature you chose (Art. 6 (1) (b) GDPR, section 11).
  • Legitimate interests (Art. 6 (1) (f) GDPR): technical operation, security and troubleshooting (server logs, session data), prevention of abuse (limit on AI requests), delivery of invitations to invited people, deletion of never-used accounts and expired invitations, privacy-friendly audience measurement without cookies (section 14), flagging of voluntary supporters (section 15), responding to enquiries that do not concern the use of the app (section 16), and the retention of the proof of consent after an account deletion for the defence against legal claims (section 7). We name our interest in each case in the relevant section. You can object to these processing operations (section 8).
  • Legal obligation (Art. 6 (1) (c) GDPR): the obligation to demonstrate consent under Art. 7 (1) GDPR (for as long as your account exists) and statutory retention obligations for business correspondence (section 16).

Special categories of personal data (Art. 9 GDPR): Pastro is not designed to process health data, religious beliefs or other special categories of personal data. We do not ask for such data and do not evaluate it. The preferences for recipe suggestions are meant for taste and cooking habits; the app explicitly asks you not to enter allergies, intolerances, illnesses or religious reasons there. Nevertheless, it cannot be completely ruled out that details you provide yourself – in the preferences, in recipe requests, in voice recordings or on receipts (for example pharmacy or drugstore products) – indirectly allow conclusions about health or beliefs. We process such content only if you upload or enter it yourself, only for the respective purpose and on the basis of the explicit consent that you give before first using the AI features and that expressly names this case (Art. 9 (2) (a) GDPR). You can delete such details yourself at any time and withdraw your consent (section 8). Voice recordings are exclusively converted into text; there is no recognition of people by their voice, and no biometric data is created.

4. Security measures

In accordance with Art. 32 GDPR, we take appropriate technical and organisational measures to ensure a level of protection appropriate to the risk. These include in particular:

  • Transport encryption: All data is transmitted encrypted via HTTPS/TLS.
  • Encrypted storage of content: Your free-text content is additionally stored encrypted in the database: the names of your groceries, shopping list entries, lists and product adjustments; title, ingredients, instructions and tips of your recipes; the text of your recipe requests and your preferences for recipes. Structured values such as categories, prices, amounts, dates and status fields are not separately encrypted. The encryption is performed server-side by our provider's database with a key belonging to our project. It protects the stored data against unauthorised access but is not end-to-end encryption: the app and we can read the content during operation.
  • Storage in the EU: Data is held with our backend provider in the Frankfurt am Main region chosen by us (for access from third countries see section 6). The provider describes its security measures in security documentation that forms part of our data processing agreement.
  • Access separation: Content data is isolated at household level through permissions; within the app, only the members of the respective household have access. Your preferences for recipes are readable by you alone. The proof of consent is kept in an area that no app user can access. As the operator, we ourselves access stored data only where this is necessary for troubleshooting, for responding to your enquiry or for fulfilling a legal obligation.
  • Server-side checks: The AI features check your sign-in, your household membership, your consent and the weekly limit server-side before any data goes to the AI provider. The consent is read from the separately stored proof, not from your settings.
  • Passwordless authentication: You sign in with a one-time code sent by email or with your Google account; we do not store passwords. Sessions end when you sign out and at the latest after one year.
  • No content in logs: Our server functions do not write receipt texts, transcripts, recipe content, email addresses or names to logs; error messages contain technical details only.
  • Backups: Automated backups of the database, once a day, kept for 7 days, then deleted automatically; stored with the same provider (section 6).
  • Data minimisation: We collect only the data necessary for the respective purpose and delete data that is no longer needed automatically (section 7).

5. Processors, service providers and other recipients

We pass your data on only to the following parties. “Processor” means: the provider processes data exclusively on our instructions, and a data processing agreement under Art. 28 GDPR is in place with it.

Processors:

  • Appwrite (backend, authentication, database, real-time synchronisation, server functions, hosting, delivery of the sign-in and invitation emails): The contracting parties are Appwrite Code LTD (Israel) and Appwrite Code, Inc. (USA). Storage and processing take place in the Frankfurt am Main region (EU) chosen by us, on infrastructure of the provider DigitalOcean. Appwrite uses sub-processors, including DigitalOcean, Fastly and Cloudflare (cloud infrastructure, content delivery, web security), Mailgun, Resend and SendGrid (delivery of emails such as one-time codes and household invitations), Sentry (error monitoring) and Help Scout (support). The provider and some of these sub-processors can access the data from the USA and Israel (section 6). The complete list forms part of the data processing agreement and can be requested from us.
  • Mistral AI (AI models for text recognition, speech transcription and text generation): Mistral AI, 15 rue des Halles, 75001 Paris, France. Used only when the AI features are used and only with your consent (section 13). According to its own statements, Mistral processes on infrastructure in the EU by default; where Mistral exceptionally uses sub-processors outside the EU, it states that it secures the transfer through standard contractual clauses (section 6).
  • Umami (audience measurement without cookies): Umami Software, Inc., 28 Geary St, Suite 650 #243, San Francisco, USA. The audience data is stored in the EU region of the service (infrastructure at Hetzner Online GmbH, EU; analytics database at ClickHouse, Inc., USA/EU); for script delivery, hosting, network security and logging, the provider uses sub-processors based in the USA (including Cloudflare, Vercel, Amazon Web Services, Axiom). See sections 6 and 14.
  • Google Workspace (contact mailbox): Google Cloud EMEA Limited, 70 Sir John Rogerson's Quay, Dublin 2, Ireland, as provider of the mailbox contact@pastro.app (section 16).

Independent controllers – process data under their own responsibility according to their own privacy policies:

  • Google (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland) for the optional sign-in with your Google account (section 10).
  • Mistral AI for the automated abuse monitoring of its interface, to which the transmitted data is subject for up to 30 days (section 13; Mistral AI's privacy policy at legal.mistral.ai).
  • Buy Me a Coffee (Publisherr Inc., San Francisco, USA), if you voluntarily support Pastro there (section 15).

Other recipients: the other members of your household, if you share a household (section 11).

6. International data transfers

Where your data is located. Your account and content data is stored and processed in the EU (Frankfurt am Main region, section 5). According to Mistral AI, AI processing takes place in the EU by default, and the audience data is located in Umami's EU region. Transfers to countries outside the EU or the EEA occur in the following cases:

  • Appwrite – Israel and USA. Our backend provider operates and maintains the service through companies in Israel and the USA; some of its sub-processors are based in the USA. In the course of operation, maintenance and support, they can access the data stored in Frankfurt; such access counts as a transfer. Israel: adequacy decision of the European Commission under Art. 45 GDPR (Decision 2011/61/EU, reviewed and confirmed by the Commission in its report of 15 January 2024). USA: the European Commission's standard contractual clauses (module “controller to processor”) as appropriate safeguards under Art. 46 (2) (c) GDPR, part of our data processing agreement.
  • Umami – USA. The provider is based in the USA and uses sub-processors there for script delivery, hosting, network security and logging. These temporarily process your IP address when your browser loads the script and sends events; according to its own statements, Umami itself does not store the IP address (section 14). Safeguard: standard contractual clauses (module “controller to processor”) under Art. 46 (2) (c) GDPR, part of the data processing agreement.
  • Mistral AI – exceptional cases. According to its own statements, Mistral secures transfers to sub-processors outside the EU through standard contractual clauses (Art. 46 (2) (c) GDPR); Mistral maintains the list of its sub-processors in its Trust Center (trust.mistral.ai).
  • Google Workspace – USA. With the contact mailbox, a transfer to Google LLC in the USA may occur. Google LLC is certified under the EU-US Data Privacy Framework; the transfer is covered by the adequacy decision of the European Commission of 10 July 2023 (Art. 45 GDPR). Our contract with Google additionally contains standard contractual clauses that apply should this decision cease to exist.
  • Google sign-in and Buy Me a Coffee. If you sign in with Google or support Pastro via Buy Me a Coffee, these providers process your data under their own responsibility, including in the USA. We receive from them only the details named in sections 10 and 15 respectively.

Please note that in the USA, despite the agreed safeguards, access by government agencies under local law cannot be completely ruled out.

Copy of the safeguards. You can request a copy of the standard contractual clauses or further information on the safeguards from us; an informal message to the contact address is sufficient. The contractual terms of Umami (umami.is/dpa) and Mistral AI (legal.mistral.ai) are publicly available.

7. Retention period and deletion of data

We store personal data only for as long as is necessary for the respective purposes. In detail:

  • Account data, settings and content data: for as long as your user account exists.
  • Sessions: The session data stored for a sign-in (section 10) exists until you sign out, for one year at most. The link to your Google account exists until your account is deleted.
  • Deletion of the account: You can delete your account yourself at any time in the settings. This immediately deletes your user account including sessions and Google link, your settings, your preferences for recipes, your personal AI counter and the data assigned to you. The only exception is the proof of consent (below).
  • Shared households: If you are a member of a shared household, the shared household data remains (pantry, purchase history, shopping lists, product adjustments, recipes, recipe requests, statistics) for the other members when you delete your account or leave the household. When the last member leaves the household, all household data is deleted.
  • Purchase history: The entries of your purchase history (category, price, amount, purchase date – without item name and without assignment to a person) remain stored for as long as your household exists, even when the grocery has long been used up, because the household's statistics are built on them (the last 12 months are displayed). You can delete the history completely at any time by leaving the household or deleting your account, or have it deleted with an informal message to us.
  • Receipt images, PDF files and voice recordings: are transmitted to the AI provider only for the duration of processing and are not stored in Pastro – neither in the database nor in file storage or logs. Only the grocery entries created from them are stored. At the AI provider, they are subject to abuse monitoring for up to 30 days according to its privacy policy (section 13).
  • Recipe requests and AI recipe suggestions: In the recipe chat, at most 50 AI suggestions that are not favourites are kept; beyond that, the oldest suggestions together with their request are deleted automatically the next time the recipe chat is opened. Favourites and your own recipes remain until you delete them. You can clear the chat history yourself at any time.
  • Preferences for recipes: until you change or delete them, until you withdraw your AI consent (they are deleted in the process) or until your account is deleted.
  • Counters of AI requests: For each week in which AI features were used, we keep a counter per household and per person. Counters of past weeks are deleted automatically once they are older than 8 days, so that no usage profile is created.
  • Invitations and never-used accounts: An invitation into a household is valid for 10 days (from the last time it was sent) and is deleted automatically afterwards. Accounts that were created through an invitation or by requesting a one-time code but were never verified and never used are deleted automatically 10 days after they were created.
  • Proof of consent: When you consent to AI processing or withdraw this consent, we record this separately from your other data: the time and the wording of the consent text as it was shown to you, in each case the current state. We are obliged to do so under Art. 7 (1) GDPR. This proof exists for as long as your account exists. If you delete your account, the proof is supplemented with the time of deletion and a pseudonymous hash value of your email address (not the address itself) and is kept together with your user ID until the end of the regular limitation period of three years from the end of the year of the account deletion (Sections 195, 199 BGB, German Civil Code) – exclusively for the defence against legal claims (Art. 6 (1) (f), Art. 17 (3) (e) GDPR). After that, it is deleted automatically. If you never consented, no proof exists.
  • Server and function logs: Access logs (section 9) are deleted automatically by our backend provider after 7 days.
  • Backups: created daily, kept for 7 days, then deleted automatically. If you delete data, it is removed from the live system immediately; it may still be contained in the backups for up to 7 days. Backups are accessed exclusively in the event of a restore.
  • Audience data: pseudonymous (section 14); deleted automatically by the provider after 6 months.
  • Data on your device: until you sign out, delete your account or switch household (offline mirror and session), or until you clear the website data in your browser (section 9).
  • Enquiries by email: until they have been dealt with conclusively, at the latest twelve months afterwards; where a message is subject to statutory retention obligations (business correspondence), up to ten years (section 16).

8. Rights of data subjects

As a data subject, you have in particular the following rights under the GDPR:

  • Access (Art. 15): information on whether and which personal data we process about you.
  • Rectification (Art. 16): rectification of inaccurate or completion of incomplete data. You can change display name, pantry, lists, recipes, product adjustments and preferences directly in the app.
  • Erasure (Art. 17): deletion of your data where the legal requirements are met. You can delete your account yourself in the settings (section 7). Shared data of a shared household remains available to the other members (section 11).
  • Restriction of processing (Art. 18) under the legal requirements.
  • Data portability (Art. 20): the data you provided in a structured, commonly used, machine-readable format. The app has no export feature; on request, we provide you with your account and household data as a JSON file.
  • Withdrawal of consent (Art. 7 (3)): at any time with effect for the future; the lawfulness of the processing carried out until then remains unaffected. You withdraw your consent to the AI features in the settings in the “Account” section (“Withdraw consent and delete details”); this deletes your preferences for recipes; entries, recipes and product adjustments already created remain until you delete them (section 13).
  • Complaint to a supervisory authority (Art. 77): without prejudice to other remedies, in particular in the member state of your habitual residence, your place of work or the place of the alleged infringement.

Right to object (Art. 21 GDPR)

You have the right to object at any time, on grounds relating to your particular situation, to the processing of your personal data that is based on Art. 6 (1) (f) GDPR (legitimate interests, section 3). We will then no longer process the data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims. You can object to the audience measurement (section 14) without giving reasons: in the settings under “Usage statistics” or by message to us. We do not engage in direct marketing.

The supervisory authority responsible for us is the State Commissioner for Data Protection and for the Right of Access to Information of Brandenburg (Landesbeauftragte für den Datenschutz und für das Recht auf Akteneinsicht Brandenburg, LDA Brandenburg), Stahnsdorfer Damm 77, 14532 Kleinmachnow, Germany, phone +49 33203 356-0, email Poststelle@LDA.Brandenburg.de.

To exercise your rights, an informal message to the contact address given in section 1 is sufficient, preferably from the email address of your Pastro account. If we have reasonable doubts about your identity, we may request additional information (Art. 12 (6) GDPR). We respond within one month; in complex cases, this period may be extended by up to two months, of which we will inform you within the first month (Art. 12 (3) GDPR).

9. Provision of the app, hosting and local storage

Hosting and access data. Pastro is delivered on the infrastructure of our backend provider Appwrite (Frankfurt am Main region; for access from third countries see section 6). When the app is accessed and during every communication with the servers – including over the real-time connection and every call of a server function, for example for AI processing – technically necessary data is processed and logged: IP address, date and time, requested resource or function, status code, browser and operating system identifier and, for account actions, the approximate location derived from the IP address. These logs serve the delivery of the app, stability, security and the detection of abuse. They are deleted automatically after 7 days. The content of your requests (images, recordings, texts) is not logged. Of its own accord, the app connects only to the servers of Appwrite and – for the audience measurement (section 14) – of Umami; fonts, images, emoji data and scripts are delivered from our own server, no content delivery network and no Google font is loaded.

Legal basis: Art. 6 (1) (f) GDPR (our legitimate interest in secure and trouble-free operation) and Art. 6 (1) (b) GDPR, insofar as the processing serves the provision of the features you request.

Local storage on your device. Pastro is an installable progressive web app. For its operation, information is stored on and read from your device:

  • a session cookie of our backend provider that identifies you as signed in after sign-in. If your browser blocks this cookie (it belongs to the provider's address, not to pantry.pastro.app), the app instead places the session key in your browser's local storage (cookieFallback). Either exists until you sign out, for one year at most;
  • a service worker with a cache for app files (faster delivery, offline capability),
  • an offline mirror (IndexedDB) with a copy of your household data (pantry, purchase history of the last 12 months, shopping lists, recipes, recipe requests, product adjustments) and your account data (user ID, display name, email address, settings, time of last access), so that the app starts immediately and shows your pantry even without an internet connection; your preferences for recipes are not mirrored. It is completely overwritten on every successful connection to the server and is deleted when you sign out, delete your account, switch household or when your session expires,
  • an offline queue (IndexedDB) in which changes to your data are buffered when there is no internet connection and which is transmitted to the server the next time a connection is established,
  • the data of the emoji picker (IndexedDB): the emoji list itself, your chosen skin tone and which emojis you used most recently, so that they appear first,
  • entries in local storage (localStorage) for pure device settings: the chosen colour theme, whether the hints on swiping and on installation have already been shown, whether the hint on product adjustments has been shown, as well as a timestamp of when the hint on voluntary support last appeared and a counter of successful AI requests that determines when it appears for the first time (section 15).

None of these entries contains an identifier by which you could be recognised outside your account, and none is used for advertising or tracking purposes. This storage is necessary to provide the app you explicitly requested – sign-in, offline operation, your settings and remembering hints already shown so that you are not asked again – and is therefore exempt from consent under Section 25 (2) no. 2 TDDDG (German Telecommunications Digital Services Data Protection Act). You can delete all entries at any time via your browser's website data; the app creates them anew the next time it starts, where they are needed.

Camera, files and microphone. For photographing or uploading a receipt or a PDF file and for voice input, Pastro accesses the camera, file picker or microphone only after your selection or your permission in the browser. A photo is transmitted only after you have cropped and confirmed it. Microphone access exists only during an ongoing recording; if you discard a recording, it is deleted on your device and never transmitted. During a recording, Pastro may keep the screen awake (Wake Lock) so that the recording is not interrupted by the screen lock; no data is collected in doing so.

10. Registration, sign-in and user account

A user account is required to use Pastro. Pastro is aimed at people aged 16 and over (section 2 of the Terms of Use). You have two ways to sign in:

  • One-time code by email (passwordless): You enter your email address and receive a one-time code with which you sign in. Requesting the code already technically creates an account with your email address; if you never enter the code, it is deleted automatically after 10 days (section 7). These emails – as well as the invitation emails for households – are sent via our backend provider and its email delivery services (sections 5 and 6).
  • Google account: The sign-in is handled via Google; Google acts under its own responsibility in doing so. We receive from Google your email address and your name as stored in your Google account, as well as the information whether Google has verified the address. The name is used as the display name in Pastro; you can change it at any time in the settings. Our backend provider stores the link to your Google account (Google user identifier and the access tokens issued by Google) so that later sign-ins can be assigned to your account; we do not use these tokens for any other purpose. We do not request any further permissions from Google. Display name and email address are visible to the members of your household (section 11).

As part of the user account, we process:

  • your email address (sign-in, necessary service messages, assignment of voluntary support – section 15),
  • your display name,
  • your user ID, the time of registration and of your last access, and the verification status of your email address,
  • session data: For each sign-in, our backend provider stores the IP address, the country derived from it, browser, operating system and device type. This serves the management of your sessions and the security of your account. A session ends when you sign out, at the latest after one year (section 7).
  • account settings: assignment to your household, colour theme, app language, hidden navigation areas, desired number of recipes per request, order of your shopping lists, the version of the Terms of Use you accepted, and the times of your AI consent and its withdrawal (these only control whether the AI features are unlocked; the proof is kept separately, section 7),
  • a supporter flag set server-side, if you support Pastro via Buy Me a Coffee (section 15),
  • optionally your preferences for recipes (section 13.3), which are stored separately and encrypted and are readable by you alone.

Your email address is not used for advertising purposes and is not passed on to anyone other than the service providers named in section 5 and, within your household, the other members (section 11).

Legal basis: Art. 6 (1) (b) GDPR; for the session data additionally Art. 6 (1) (f) GDPR (our and your interest in the security of the account).

Necessity of provision: The email address (or a Google account) is required to create a user account; without it, we cannot provide the app. All further details are voluntary; the AI features require your consent, all other features can be used without it. There is no statutory or contractual obligation to provide us with any further data.

11. Shared households

Pastro lets you use a household together with other people. Invited members can access the shared content: pantry, purchase history and statistics, shopping lists, saved product adjustments, recipes and the history of recipe requests.

  • Invitations: You enter the email address of the person to be invited; only invite people who agree to it (Terms of Use, section 2). They receive an invitation email with a link via our backend provider; on the page that opens with it, they see this privacy policy and the Terms of Use before accepting the invitation. The invitation is valid for 10 days and is deleted automatically afterwards. If an address is invited for which no account exists yet, a provisional account is technically created that contains only the email address and a randomly assigned display name; if the invitation is not accepted, this account is deleted automatically after 10 days.
  • Visibility: Within a household, the shared content as well as the display name, email address and role of the members are visible to the other members (member list in the household management), as are open invitations with the invited email address. This also applies to the free text of your recipe requests. Deleting a recipe or entry removes it for all members. Your preferences for recipes and your settings are not visible to others.
  • AI features in the household: If a member uses the AI features (section 13), shared household data is also transmitted to the AI provider: for recipe suggestions the entire pantry of the household (names, amounts, remaining shelf life), for receipt capture and voice input the saved product adjustments. Therefore, only enter data into a shared household that may be processed in this way.
  • What happens to the data: If a member leaves or deletes their account, the shared household data remains available to the other members (section 7). If you accept an invitation into another household, you switch to it; your previous household is deleted if you were its only member, otherwise it remains available to the other members. Therefore, please only enter data into a shared household that is intended for the other members.

Legal basis: Art. 6 (1) (b) GDPR (provision of the household feature you chose, including the use of the shared data by the other members – also in the AI features). Towards the invited person, the processing of their email address for delivering the invitation is based on Art. 6 (1) (f) GDPR (legitimate interest of the inviting member and the invited person in using the household together); the invitation email serves solely to deliver the invitation and contains no advertising. The automatic deletion of expired invitations and never-used accounts is based on Art. 6 (1) (f) GDPR (data minimisation, Art. 5 (1) (e) GDPR).

12. Core features: pantry, shopping list, recipes and statistics

To fulfil the actual purpose of the app, we process the content data you enter or create:

  • Pantry: name, category, amount, price, purchase date, estimated expiry date and an optional icon per grocery, plus whether the entry was created manually or by AI.
  • Purchase history: For every grocery created, an entry with category, price, amount and purchase date is stored – without the name and without assignment to a person – which remains after the grocery has been used up (section 7).
  • Shopping lists: lists you create and their entries, including ingredients you take over from a recipe.
  • Product adjustments (“Pastro learns from you”): If you adjust the shelf life, category or icon of a grocery, Pastro remembers name, shelf life in days, category and icon for your household and takes them into account in future captures (section 13). You can view and delete the saved adjustments in the settings.
  • Recipes: your own recipes as well as AI suggestions (section 13.3) with title, ingredients, instructions, tip, category, tags, servings and an estimated calorie figure; plus the favourite flag. If you mark a recipe as “cooked”, the amounts used are deducted from your pantry.
  • Statistics: evaluations of your household for the last 12 months: spending and a roughly estimated saving derived from it (from the purchase history), distribution by category, and an overview of how much of your pantry is still fresh, expiring soon or expired (from the pantry).

Expiry dates, calorie figures and the “saving” are estimated automatically and are non-binding; what this means for you is set out in section 3 of the Terms of Use.

Legal basis: Art. 6 (1) (b) GDPR.

13. AI-assisted features

Pastro offers three optional features based on artificial intelligence: receipt capture from receipts (13.1), voice input of pantry items (13.2) and recipe suggestions from your pantry (13.3). The following applies to all three:

Consent. Neither the app nor our server functions run any of these features without your prior consent. Before first use, the app shows you a notice about which data goes to which provider for which purpose and what happens to it there, and you can consent or decline. Without consent, no AI processing takes place; all other features remain usable (you can also record groceries and recipes manually). We record your consent and its withdrawal as proof (section 7). The consent expressly also covers the case that a receipt, a recording or an entry exceptionally contains details that allow conclusions about your health or beliefs (section 3).

Withdrawal. In the settings in the “Account” section via “Withdraw consent and delete details”, at any time with effect for the future. This deletes your preferences for recipes; entries, recipes, recipe requests and product adjustments already created remain until you delete them. We record the withdrawal as well. The lawfulness of the processing carried out until then remains unaffected.

Household data. The AI features work with the data of your household: recipe suggestions with the entire pantry, receipt capture and voice input with the saved product adjustments. This data therefore also goes to the AI provider when another member of your household uses the feature (section 11).

Place of processing and provider. Processing begins in server-side functions at our backend provider in Frankfurt am Main (EU). As the AI provider, we use exclusively Mistral AI (Mistral AI, 15 rue des Halles, 75001 Paris, France, EU) – for text recognition (OCR), speech transcription and text generation. According to its own statements, Mistral processes the data in the EU by default (sections 5 and 6). No other AI service and, in particular, no speech recognition of the browser or operating system is used.

Storage at the AI provider. Mistral AI processes the data as our processor on the basis of a data processing agreement. The transmitted inputs and outputs are not used to train the models; we have expressly excluded this use in our account. To automatically detect abuse of its interface, Mistral AI retains the transmitted inputs and outputs for up to 30 days according to its privacy policy and deletes them afterwards; Mistral AI itself is responsible for this check, and Mistral AI's privacy policy (legal.mistral.ai) applies in this respect.

Background processing. Processing continues on our servers even if you close the app in the meantime. Results appear the next time you open the app or via real-time update.

Limit. The number of AI requests is limited to 10 per week; the counter applies to the entire household, is kept server-side and is additionally counted per person, so that switching household does not bring a new allowance (section 7). Voluntary support (section 15) does not raise this limit.

Labelling and limits of the AI (Regulation (EU) 2024/1689, Art. 50). All results of the AI features are generated automatically and may contain errors: recognised items, estimated shelf lives, recipes, calorie figures. In the recipe chat you interact with an AI system; AI-generated recipes are labelled as such in the app and marked as AI results in our data. Please check the results – in particular ingredients, if you have allergies or intolerances. There is no decision based solely on automated processing with legal effect or similarly significant impact within the meaning of Art. 22 GDPR.

Legal basis: Art. 6 (1) (a) GDPR (consent), for indirectly sensitive details Art. 9 (2) (a) GDPR (section 3); towards the other members of your household for the shared data Art. 6 (1) (b) GDPR (section 11); for the proof of consent Art. 6 (1) (c) in conjunction with Art. 7 (1) GDPR; for the limit on requests Art. 6 (1) (f) GDPR.

13.1 Receipt capture (receipt as photo, image or PDF)

You can photograph a receipt, upload an image or submit the receipt as a PDF file (up to 10 pages). You can crop images before sending. The file is transmitted to our server function, read there by text recognition, and the items are extracted in structured form from the recognised receipt text. In doing so, the language model receives the complete recognised receipt text – including date, store, total and payment method, insofar as they appear on the receipt –, the current date and your saved product adjustments (name, shelf life, category, icon; at most 200) so that your corrections are taken into account. The recognised items end up in your pantry; the estimated expiry dates are calculated by our system from the purchase date and the estimated shelf life.

Data processed: the receipt file and the content recognised from it. A receipt may contain personal data (e.g. date/time, store, payment method, purchased products, names of checkout staff). Please do not submit receipts that you do not want to have processed, and receipts of other people only with their agreement. The file is not stored in Pastro (section 7).

13.2 Voice input (dictate your pantry)

You can dictate your pantry. The recording takes place locally on your device after you have granted microphone access; you can pause, discard or finish it. After finishing, it is transmitted to our server function, converted into text by a transcription model from Mistral AI and then structured into grocery entries by a language model. For better recognition, the set app language and up to 100 names from your product adjustments are passed to the transcription and, afterwards, the product adjustments with all details (name, shelf life, category, icon; at most 200, as in 13.1) to the language model.

Data processed: the voice recording, the text created from it and the recognised items. The recording serves exclusively the conversion into text; your person is not identified by voice. Please only dictate what you want to record, and make sure that no other people are recorded. The recording is not stored in Pastro (section 7).

13.3 Recipe suggestions

In the recipe chat, you can have dishes suggested that match your pantry – optionally with a wish in free text (e.g. “something light for dinner”). Your request is transmitted to our server function together with a list of your household's pantry (names, amounts and remaining shelf life, at most 150 entries), the app language, the current date, the desired number and – if stored – your preferences. From this, the AI generates the desired number of recipe suggestions, which are stored in your household and displayed in the chat. If a suggestion does not match the pantry, the server function asks the model a second time with the same conversation history.

Preferences (optional). You can store preferences that are sent automatically with every recipe request – for example “spicy, no mushrooms, 30 minutes max”. They are meant for taste and cooking habits; please do not enter allergies, intolerances, illnesses or religious reasons (see section 3). The preferences are stored encrypted, are readable by you alone and are not visible to household members. You can save them even without AI consent; they are only sent with a recipe request. You can change or delete them at any time; when you withdraw your AI consent, they are deleted.

Data processed: your request text, the pantry list, the preferences where applicable, and the generated recipes. Suggestions that are not favourites and their requests are cleaned up automatically (section 7). Request texts are visible to the members of your household (section 11).

14. Audience measurement with Umami

We use the web analytics service Umami (provider: Umami Software, Inc., San Francisco, USA) to see how many people use Pastro, which features they use and where errors occur, and to improve the app accordingly. When the app loads, your browser loads a script from the provider's servers and sends usage events there; in doing so, it technically transmits your IP address.

What is collected:

  • Page views within the app and events that we trigger in the code (e.g. “scan started”, “recipe generated”, “onboarding completed”), in each case without content: no receipt texts, transcripts, recipe or request texts, preferences, names or email addresses are transmitted. For individual events, technical attributes are collected, such as an error reason, a category or a count. Parameters from web addresses are removed before transmission.
  • Technical details that the script reads from your browser or that your browser sends along: browser, operating system, device type, language, screen size and the previously visited page (referrer).
  • Derived from the IP address: the approximate location (country, region, city). According to its own statements, Umami does not store the IP address itself; sub-processors in the USA process it temporarily to deliver the script, for network security and for logging (section 6).

How Umami works:

  • No cookies are set and no identifiers are stored on your device.
  • To distinguish visits by the same person, Umami forms a hash value from details such as website, browser identifier and IP address together with a secret value. This secret value changes at the beginning of each month. Within a month, Umami can therefore pseudonymously attribute recurring visits to the same person; after that, it cannot. There is no recognition across other websites.
  • We do not link the audience data to your account and do not evaluate individual people; we see totals, trends and event frequencies.
  • The data is stored in the EU region of the service (sections 5 and 6) and is deleted automatically by the provider after 6 months.

Objection. You can switch off audience measurement for your device at any time: in the settings under “Usage statistics”. The app then places an entry umami.disabled in your local storage, which mutes the script; nothing else is stored. In addition, the script respects your browser's “Do Not Track” setting.

Legal basis: Art. 6 (1) (f) GDPR (legitimate interest in privacy-friendly audience measurement and improvement of the app). In favour of this balance: no cookies, no advertising, no selling or sharing of data, no link to your account, no content, pseudonymous attribution only within one month, storage in the EU and a simple objection. The script stores nothing on your device and reads only the technical details named above that it needs for counting; we therefore do not obtain consent under Section 25 TDDDG.

15. Voluntary support via Buy Me a Coffee

Pastro is free and has no advertising. Anyone who wishes can support the project voluntarily via the platform Buy Me a Coffee. Support does not unlock any features and does not lift any limit; all features are available to all users equally.

  • External provider: The support page opens in a new tab at Buy Me a Coffee; nothing from Buy Me a Coffee is embedded in the app. The provider is Publisherr Inc., 2193 Fillmore Street, San Francisco, CA 94115, USA, with payment processing via Stripe. Buy Me a Coffee is independently responsible for all data you enter there (payment details, name, email address, message); its privacy policy applies (buymeacoffee.com/privacy-policy). Processing there also takes place in the USA.
  • What we receive from Buy Me a Coffee: When a monthly support starts, changes, pauses or ends, Buy Me a Coffee informs us automatically about this event and transmits the details stored there (in particular email address and status of the support, depending on the event also name, amount and message). We use only the email address and the status: we match the address against the accounts in Pastro and set or remove a supporter flag on a matching account. We do not store anything else; amounts, names or payment details are neither stored nor logged. If there is no account with this address, we discard the information.
  • What the flag is for: It solely controls whether the hint about the option to support is shown to you in the app. When this hint appears for the first time and how often it appears is counted only locally on your device (section 9).
  • One-off support: We store nothing for this; a flag is created only for monthly support.

Legal basis: Art. 6 (1) (f) GDPR (our legitimate interest in recognising supporters and not asking them for support repeatedly – and your interest in no longer seeing the hint); insofar as the flag is part of the support you chose, also Art. 6 (1) (b) GDPR.

16. Contact

If you contact us – for example via the app's feedback feature, which opens your email program with the address contact@pastro.app –, we process your email address, the content of your message and any further details you provide voluntarily in order to handle your enquiry.

The contact mailbox is operated via Google Workspace. The provider is Google Cloud EMEA Limited, 70 Sir John Rogerson's Quay, Dublin 2, Ireland, with which a data processing agreement is in place. Google receives, stores and technically processes the messages; this may involve a transfer to Google LLC in the USA, which is secured by the EU-US Data Privacy Framework and additionally by standard contractual clauses (section 6). If you do not want this, you can also write to us by post at the address in section 1.

We delete enquiries once they have been dealt with conclusively, at the latest twelve months afterwards. If a message is subject to statutory retention obligations – for example as business correspondence under commercial and tax law –, we keep it for up to ten years.

Legal basis: Art. 6 (1) (b) GDPR (enquiries in connection with the use of the app) or Art. 6 (1) (f) GDPR (legitimate interest in handling enquiries); for retention under commercial and tax law Art. 6 (1) (c) GDPR.

17. Changes to this privacy policy

We adapt this privacy policy as soon as changes to the processing make this necessary (new features, changed service providers or sub-processors, changed legal situation). The current version linked in the app (pantry.pastro.app) applies; the date of the last update is stated at the beginning, and we will send you earlier versions on request. In the event of significant changes, we will inform you in an appropriate manner, for example by a notice in the app. If the AI processing changes significantly, we will ask for your consent again.

This is a translation provided for convenience. The German version is the authoritative text, as the underlying obligations arise from German law.

Pastro

Photograph a receipt, build a live pantry, and waste less food. A Progressive Web App for home kitchens.

Product
Features How it works FAQ Start for free
Legal
Imprint Privacy Terms of Use Deutsch
© 2026 Pastro. Made for less food waste. Privacy Imprint Terms of Use