Harvest Nutrition helps users find recipe suggestions, price ingredients at saved grocery stores, plan meals, manage pantry items, and build shopping lists. This policy explains what information Harvest collects, how it is used, how long it is kept, and the controls available in the app.
For privacy questions or support requests, contact support@harvestnutrition.app.
Information Harvest Collects
Account and Authentication
Harvest uses Supabase for account creation, sign-in, password recovery, session management, and authentication. Depending on how a user signs in, account data may include email address, name, Supabase user ID, authentication provider metadata, and session information.
Harvest supports email/password authentication and may support Apple and Google sign-in. Apple and Google may process sign-in data according to their own privacy policies.
Nutrition Profile and Preferences
Harvest may collect information users provide during onboarding or profile editing, including:
- name or display name
- age, height, weight, sex, activity level, and nutrition goals
- macro targets, calorie goals, diet preferences, budget preferences, and meal preferences
- liked foods, disliked foods, proteins, allergens, dietary restrictions, and other recipe preference inputs
Harvest uses this data to personalize recipes, avoid unsuitable ingredients, estimate nutrition targets, and improve grocery planning.
Stores and Location
If a user grants When-In-Use location permission, Harvest uses device location to help find nearby grocery stores. Harvest does not need continuous background location access for this feature.
When a user saves a store, Harvest stores the selected store name, address, provider identifiers, and coordinates or address-derived location details needed to price ingredients and build store-specific shopping lists.
Recipes, Pricing, Pantry, and Shopping Lists
Harvest stores account-linked app data needed to provide the product, including:
- saved stores
- pantry items and stock status
- recipe favorites and recipe selections
- shopping lists, shopping-list items, and purchase status
- recipe match and pricing outputs shown to the user
- logged meals, when the user chooses to track them: the meal name, date, serving count, and calorie/protein/carb/fat totals for each entry
- if the user scans a food barcode, the camera is used on-device only to read the barcode; no photos are captured or stored, and only the numeric barcode is sent to look up nutrition data
- account export audit metadata, such as export timestamps and row counts
Harvest also uses shared backend caches for recipe-source responses and grocery pricing responses so the app can respond faster and reduce repeated calls to third-party providers.
Subscription and Purchase Status
Harvest may process subscription status information for base app access, including product identifiers, transaction identifiers, entitlement status, trial status, renewal/expiration dates, cancellation or billing-state signals, and related support/debug metadata. Harvest does not receive or store payment card details.
Device, Diagnostics, and Operational Data
Harvest and its infrastructure providers may process technical information such as API request metadata, server logs, error messages, timing information, device/app version information, and security diagnostics. This data is used to operate, debug, protect, and improve the service.
Harvest does not currently use third-party advertising tracking or cross-app tracking SDKs.
How Harvest Uses Information
Harvest uses collected information to:
- create and secure user accounts
- personalize recipe recommendations
- filter recipes for preferences, allergens, diet settings, and saved stores
- price recipe ingredients through grocery provider integrations
- build pantry-aware recommendations and shopping lists
- verify subscription access and free-trial status
- sync user data across devices
- provide account export and account deletion controls
- diagnose bugs, monitor performance, prevent abuse, and maintain security
- satisfy legal, safety, and support obligations
Harvest does not sell personal information.
Third-Party Services
Harvest uses third-party processors and providers to operate app features:
- Supabase for authentication, database, and account identity
- Spoonacular or another configured recipe-source provider for recipe data
- an Instacart wrapper/API provider for grocery product search and pricing
- Open Food Facts for barcode-based product nutrition lookups in the food tracker
- Anthropic for recipe validation or AI-assisted recipe filtering when enabled
- Apple App Store for in-app subscription purchase, free-trial, renewal, and billing status
- RevenueCat for subscription validation and status tracking if Harvest chooses to use RevenueCat
- Apple and Google for supported sign-in flows
- hosting, logging, and infrastructure providers for backend operation
Third-party providers may receive the minimum information needed for their feature. For example, grocery pricing calls may include selected store information and ingredient search terms, subscription providers may receive app account or transaction identifiers, and recipe validation may include recipe names, ingredients, and preference-relevant context.
Data Retention
Harvest keeps information only as long as needed for the purposes described in this policy, unless a longer retention period is required for security, legal, tax, dispute, or compliance reasons.
| Data category | Current retention period |
|---|---|
| Account and profile data | Retained while the account is active. Deleted when the user deletes their account, subject to backup, security, legal, or abuse-prevention exceptions. |
| Nutrition profile, macros, and preferences | Retained while the account is active. Latest values replace older values unless history is added in a future version. Deleted with account deletion. |
| Saved stores and selected-store location details | Retained until the user deletes the store or deletes the account. |
| Pantry items | Retained until the user deletes the item, clears pantry data, or deletes the account. |
| Shopping lists and shopping-list items | Retained until the user deletes the list or deletes the account. |
| Recipe favorites | Retained until the user removes the favorite or deletes the account. |
| Logged meals | Retained until the user removes the entry or deletes the account. Meal logging is optional; entries are created only when the user logs a meal. |
| Subscription status records | Retained while needed to provide app access, support purchases, reconcile provider events, and satisfy legal, tax, dispute, fraud-prevention, or compliance obligations. |
| Account export audit metadata | Successful self-service exports create a minimal audit row with timestamps and section counts. The audit row does not store the exported file. When an account is deleted, the direct profile link is removed from the audit row. |
| Local app cache on device | Retained until the app clears local data, the user signs out or deletes the account, the user uninstalls the app, or the data is overwritten. |
| Grocery price cache | Shared backend price cache rows are currently removed after 168 hours, or 7 days. |
| Recipe search cache | Shared backend recipe search rows are currently removed after 24 hours. Recipe information rows are currently removed after 168 hours, or 7 days. |
| Operational logs and diagnostics | Normally retained for up to 30 days, unless a longer period is needed for security, support, abuse prevention, legal, or infrastructure-provider requirements. |
| Aggregated or de-identified metrics | May be retained longer when they do not identify a specific user. |
Account deletion removes user-owned Harvest application rows and then deletes the Supabase Auth user through a server-side process. Some copies may remain temporarily in encrypted backups, infrastructure logs, or provider systems until those systems complete their normal retention cycle.
User Controls
Harvest provides privacy controls in the app under Privacy & Data:
- export account data as a JSON file
- clear local app data from the device
- delete the Harvest account
Users can also delete specific saved stores, pantry items, shopping lists, and recipe favorites in the app where those features are available.
Apple subscriptions are managed through the user's Apple Account subscription settings. Deleting a Harvest account does not automatically cancel an Apple subscription; users should cancel or manage the subscription through Apple.
Security
Harvest uses HTTPS/TLS for network communication and relies on Supabase authentication for account sessions. Backend routes verify authenticated user tokens before returning or changing account data.
No app or internet service can guarantee perfect security. Users should protect their device passcode, email account, Apple or Google account, and Harvest password if using email/password sign-in.
Children
Harvest is not intended for children under 13. Harvest does not knowingly collect personal information from children under 13. If Harvest learns that it has collected information from a child under 13, it will take reasonable steps to delete that information.
Changes to This Policy
Harvest may update this policy as the app, infrastructure, provider set, or legal requirements change. When material changes are made, Harvest will update the "Last updated" date and provide notice where appropriate.
