Loading...
Loading...
Last Updated: 28 July 2026
Pantri is a grocery and meal-planning app for Australian households. It is operated by NTWRK PTY LTD (ABN 59 619 107 336), referred to in this policy as “we”, “us” or “Pantri”.
This policy explains what personal information we collect, why we collect it, who we give it to, where it is stored, and how you can access it, correct it or complain. It applies to the Pantri website (pantri.app), the Pantri app (app.pantri.app) and any email we send you.
We handle personal information in accordance with the Privacy Act 1988 (Cth) and the 13 Australian Privacy Principles (APPs) set out in Schedule 1 of that Act. Marketing email is also governed by the Spam Act 2003 (Cth).
“Personal information” has the meaning given in the Privacy Act: information or an opinion about an identified individual, or an individual who is reasonably identifiable. It does not include information that has been aggregated or de-identified so that you can no longer be reasonably identified from it.
If you use Pantri from outside Australia, other privacy laws may also give you rights. We will honour a request made under those laws where it applies to us.
You do not have to identify yourself to browse pantri.app. You do need an account to use the app, because the app is built around your own pantry and household.
We do not sell your personal information, and we do not disclose it to third parties for their own marketing.
Other members of your household. When you create or join a household, your pantry items, shopping lists, meal plans and your display name are visible to the other members of that household. Leave the household to stop sharing.
Our service providers. We use the following providers to run Pantri. Each receives only what it needs, and is bound to use it only to provide its service to us:
| Provider | What it does | Where it processes data |
|---|---|---|
| Supabase | Database, sign-in, and file storage — including your receipt images. This is where the bulk of your Pantri data lives. | Singapore (provider based in the United States) |
| Vercel | Hosts pantri.app and app.pantri.app and serves pages to your browser. Vercel Speed Insights also measures how fast pages load for you. Speed Insights requires consent — see section 9. Hosting does not; it is how the site reaches you at all. | Sydney, Australia (provider based in the United States; global edge network) |
| Cloudflare | Sits in front of our application server. Every request the app makes to our API passes through Cloudflare, which terminates the secure connection and filters malicious traffic. | Edge locations worldwide, typically Melbourne or Sydney for Australian users (provider based in the United States) |
| Hetzner | Hosts our application server, which handles every request you make in the app. | Helsinki, Finland |
| Gemini reads the text on some receipt images you upload, generates meal and recipe suggestions from your pantry contents and preferences, and extracts recipes from links you import. Google also provides “Sign in with Google” if you use it. | United States | |
| Anthropic | Claude reads the text on some receipt images you upload, answers pantry questions, and acts as the fallback for recipe extraction. | United States |
| Bright Data | Fetches the page content of a social-media or website recipe link that you paste in to import. It receives the link you supply, not your pantry or account data. | United States and Israel |
| Supadata | Returns the audio transcript of a TikTok recipe video when you import one. It receives the link you supply. | United States |
| Resend | Sends our email and records delivery, open and click events. | United States |
| Amazon Web Services (Amazon SES) | Backup email delivery when our primary provider is unavailable. | ap-southeast-2 |
| PostHog | Product analytics and session replay. Consent required — see section 9. | United States |
| Microsoft (Clarity) | Session replay and heatmaps. Consent required — see section 9. | United States |
| Sentry | Error and crash reporting, so we can find and fix bugs. When an error occurs it also receives a masked replay of the moments before it. Runs for everyone — see the exception noted in section 9. | United States |
Our staff. A small number of authorised people can view account information (such as your name, email address and usage metadata) to provide support and operate the service. When that information is viewed through our internal admin dashboard, we record the access: when it happened, the network address and browser it came from, and which part of the dashboard was used.
Two limits on that, stated plainly rather than glossed over. The log records that the admin dashboard was used, not which individual person used it — the dashboard is protected by a single shared credential rather than named staff logins, so there is no personal identity for it to capture. And it covers the admin dashboard only, not direct database administration, which is not separately logged by us.
Others, where the law requires or permits it — for example in response to a court order or a law enforcement request, or where disclosure is necessary to prevent a serious threat to life, health or safety.
A buyer or successor. If the business is sold, merged or restructured, your information may transfer as part of that transaction. We would tell you before your information became subject to a different privacy policy.
Your personal information is stored and processed outside Australia. We want to be direct about this, because it is a real trade-off and you deserve to know before you sign up.
ap-southeast-1 region. This is where most of your Pantri data is held at rest.Before disclosing personal information to an overseas recipient we take reasonable steps to ensure it is handled consistently with the Australian Privacy Principles — including relying on the provider’s contractual data-protection terms. You should be aware that these countries’ privacy laws differ from Australia’s, and that the Privacy Act may not be enforceable against an overseas recipient. By using Pantri you acknowledge this disclosure.
We use two AI providers — Google (Gemini) and Anthropic (Claude). Both are used across the features below, and which one handles a given request depends on the feature and on availability, so you should assume either may receive it:
These providers process this information to return a result to us. We send them only what is needed to produce that result, we do not use your information to train our own models, and we do not authorise these providers to use it for their own purposes. We rely on their standard commercial terms for that; we have not negotiated bespoke terms with either.
AI output can be wrong. Allergen and dietary information shown in Pantri is decision support, not a guarantee — always check the product label. We do not make any decision about you that has a legal or similarly significant effect using automated processing alone.
We use cookies and similar technologies that are essential to run the service — signing you in, keeping your session, and security. These cannot be turned off without breaking the app.
Product analytics, session replay and performance measurement only run if you accept them on the cookie banner. That covers PostHog (analytics and session replay), Microsoft Clarity (session replay and heatmaps) and Vercel Speed Insights (page-speed measurement). Session replay records how you move through the app; text you type and fields marked sensitive are masked. You can change your mind at any time in Settings → Preferences → Share Usage Data, or by clearing site data to see the banner again.
One exception, and we would rather name it than bury it. Our error monitor (Sentry) runs for everyone, because we cannot fix a fault we never hear about. It normally records nothing at all — no recording is made of a healthy visit. But when an error actually occurs, Sentry attaches a replay of the moments leading up to it so the fault can be reproduced. In that recording all text is masked and all images and video are blocked: it captures the shape of the page and what you clicked, not what you can read on it. This is not covered by the cookie banner.
Full detail, including cookie and storage names and how long each one lasts, is in our Cookie Policy.
We send two kinds of email. Service email — confirming your account, resetting your password, household invitations — is necessary to operate your account and is not marketing.
Marketing email — product tips, new features, guides — is sent only where you have opted in. Every marketing email contains a working unsubscribe link and identifies us as the sender, as required by the Spam Act 2003 (Cth). Unsubscribing takes effect immediately and always within 5 business days. You can also turn marketing off in Settings, or email us at privacy@pantri.app and we will do it for you.
Under APP 7 you may ask us not to use or disclose your personal information for direct marketing, and to tell you where we got it from. We will action that free of charge.
We take reasonable steps to protect your personal information from misuse, interference, loss and unauthorised access, modification or disclosure. Traffic between your device and our servers is encrypted with TLS; our database provider encrypts stored data at rest; passwords are stored only as one-way hashes; and one household cannot read another’s data — that separation is enforced both by database row-level security rules and by checks in our own application code.
No system is perfectly secure. Please use a strong, unique password and tell us promptly if you think your account has been accessed by someone else.
When you close your account we delete or de-identify your personal information within 30 days, except where we are required to keep it by law. Recipes you created are de-identified rather than deleted — the recipe stays, with your authorship removed, so other people who saved it do not lose it. This applies to every recipe you created, not only ones you shared.
You can see and edit most of your information directly in the app — your profile, dietary preferences, pantry, lists, meal plans and marketing preference.
For anything else — a full copy of the personal information we hold, a correction we cannot make in the app, or deletion of your account and its data — email privacy@pantri.app from the address on your account. We will respond within 30 days. There is no charge to make a request.
If we refuse access or a correction, we will tell you in writing why, and how to complain.
Pantri is intended for adults managing a household. We do not knowingly collect personal information from children under 13. If you believe a child has given us personal information, email privacy@pantri.app and we will delete it.
If we suffer a data breach that is likely to result in serious harm to you, we will notify you and the Office of the Australian Information Commissioner (OAIC) as required by the Notifiable Data Breaches scheme in Part IIIC of the Privacy Act.
We may update this policy as the product and the law change. The current version always lives at this address, with the “Last Updated” date at the top. If a change materially affects how we handle your personal information, we will tell you by email or in the app before it takes effect.
If you think we have mishandled your personal information or breached the Australian Privacy Principles, tell us first. Email privacy@pantri.app with the details, or write to us at Central House, 101 Moray Street, South Melbourne VIC 3205. We will acknowledge your complaint within 5 business days and give you a written response within 30 days.
If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner (OAIC):
For any question about this policy or about your personal information: