Harvest← Back to home

Legal

Privacy Policy

Last updated: July 11, 2026

Harvest Nutrition helps users find recipe suggestions, price ingredients at saved grocery stores, plan meals, manage pantry items, and build shopping lists. This policy explains what information Harvest collects, how it is used, how long it is kept, and the controls available in the app.

For privacy questions or support requests, contact support@harvestnutrition.app.

Information Harvest Collects

Account and Authentication

Harvest uses Supabase for account creation, sign-in, password recovery, session management, and authentication. Depending on how a user signs in, account data may include email address, name, Supabase user ID, authentication provider metadata, and session information.

Harvest supports email/password authentication and may support Apple and Google sign-in. Apple and Google may process sign-in data according to their own privacy policies.

Nutrition Profile and Preferences

Harvest may collect information users provide during onboarding or profile editing, including:

  • name or display name
  • age, height, weight, sex, activity level, and nutrition goals
  • macro targets, calorie goals, diet preferences, budget preferences, and meal preferences
  • liked foods, disliked foods, proteins, allergens, dietary restrictions, and other recipe preference inputs

Harvest uses this data to personalize recipes, avoid unsuitable ingredients, estimate nutrition targets, and improve grocery planning.

Stores and Location

If a user grants When-In-Use location permission, Harvest uses device location to help find nearby grocery stores. Harvest does not need continuous background location access for this feature.

When a user saves a store, Harvest stores the selected store name, address, provider identifiers, and coordinates or address-derived location details needed to price ingredients and build store-specific shopping lists.

Recipes, Pricing, Pantry, and Shopping Lists

Harvest stores account-linked app data needed to provide the product, including:

  • saved stores
  • pantry items and stock status
  • recipe favorites and recipe selections
  • shopping lists, shopping-list items, and purchase status
  • recipe match and pricing outputs shown to the user
  • logged meals, when the user chooses to track them: the meal name, date, serving count, and calorie/protein/carb/fat totals for each entry
  • if the user scans a food barcode, the camera is used on-device only to read the barcode; no photos are captured or stored, and only the numeric barcode is sent to look up nutrition data
  • account export audit metadata, such as export timestamps and row counts

Harvest also uses shared backend caches for recipe-source responses and grocery pricing responses so the app can respond faster and reduce repeated calls to third-party providers.

Subscription and Purchase Status

Harvest may process subscription status information for base app access, including product identifiers, transaction identifiers, entitlement status, trial status, renewal/expiration dates, cancellation or billing-state signals, and related support/debug metadata. Harvest does not receive or store payment card details.

Device, Diagnostics, and Operational Data

Harvest and its infrastructure providers may process technical information such as API request metadata, server logs, error messages, timing information, device/app version information, and security diagnostics. This data is used to operate, debug, protect, and improve the service.

Harvest does not currently use third-party advertising tracking or cross-app tracking SDKs.

How Harvest Uses Information

Harvest uses collected information to:

  • create and secure user accounts
  • personalize recipe recommendations
  • filter recipes for preferences, allergens, diet settings, and saved stores
  • price recipe ingredients through grocery provider integrations
  • build pantry-aware recommendations and shopping lists
  • verify subscription access and free-trial status
  • sync user data across devices
  • provide account export and account deletion controls
  • diagnose bugs, monitor performance, prevent abuse, and maintain security
  • satisfy legal, safety, and support obligations

Harvest does not sell personal information.

Third-Party Services

Harvest uses third-party processors and providers to operate app features:

  • Supabase for authentication, database, and account identity
  • Spoonacular or another configured recipe-source provider for recipe data
  • an Instacart wrapper/API provider for grocery product search and pricing
  • Open Food Facts for barcode-based product nutrition lookups in the food tracker
  • Anthropic for recipe validation or AI-assisted recipe filtering when enabled
  • Apple App Store for in-app subscription purchase, free-trial, renewal, and billing status
  • RevenueCat for subscription validation and status tracking if Harvest chooses to use RevenueCat
  • Apple and Google for supported sign-in flows
  • hosting, logging, and infrastructure providers for backend operation

Third-party providers may receive the minimum information needed for their feature. For example, grocery pricing calls may include selected store information and ingredient search terms, subscription providers may receive app account or transaction identifiers, and recipe validation may include recipe names, ingredients, and preference-relevant context.

Data Retention

Harvest keeps information only as long as needed for the purposes described in this policy, unless a longer retention period is required for security, legal, tax, dispute, or compliance reasons.

Data categoryCurrent retention period
Account and profile dataRetained while the account is active. Deleted when the user deletes their account, subject to backup, security, legal, or abuse-prevention exceptions.
Nutrition profile, macros, and preferencesRetained while the account is active. Latest values replace older values unless history is added in a future version. Deleted with account deletion.
Saved stores and selected-store location detailsRetained until the user deletes the store or deletes the account.
Pantry itemsRetained until the user deletes the item, clears pantry data, or deletes the account.
Shopping lists and shopping-list itemsRetained until the user deletes the list or deletes the account.
Recipe favoritesRetained until the user removes the favorite or deletes the account.
Logged mealsRetained until the user removes the entry or deletes the account. Meal logging is optional; entries are created only when the user logs a meal.
Subscription status recordsRetained while needed to provide app access, support purchases, reconcile provider events, and satisfy legal, tax, dispute, fraud-prevention, or compliance obligations.
Account export audit metadataSuccessful self-service exports create a minimal audit row with timestamps and section counts. The audit row does not store the exported file. When an account is deleted, the direct profile link is removed from the audit row.
Local app cache on deviceRetained until the app clears local data, the user signs out or deletes the account, the user uninstalls the app, or the data is overwritten.
Grocery price cacheShared backend price cache rows are currently removed after 168 hours, or 7 days.
Recipe search cacheShared backend recipe search rows are currently removed after 24 hours. Recipe information rows are currently removed after 168 hours, or 7 days.
Operational logs and diagnosticsNormally retained for up to 30 days, unless a longer period is needed for security, support, abuse prevention, legal, or infrastructure-provider requirements.
Aggregated or de-identified metricsMay be retained longer when they do not identify a specific user.

Account deletion removes user-owned Harvest application rows and then deletes the Supabase Auth user through a server-side process. Some copies may remain temporarily in encrypted backups, infrastructure logs, or provider systems until those systems complete their normal retention cycle.

User Controls

Harvest provides privacy controls in the app under Privacy & Data:

  • export account data as a JSON file
  • clear local app data from the device
  • delete the Harvest account

Users can also delete specific saved stores, pantry items, shopping lists, and recipe favorites in the app where those features are available.

Apple subscriptions are managed through the user's Apple Account subscription settings. Deleting a Harvest account does not automatically cancel an Apple subscription; users should cancel or manage the subscription through Apple.

Security

Harvest uses HTTPS/TLS for network communication and relies on Supabase authentication for account sessions. Backend routes verify authenticated user tokens before returning or changing account data.

No app or internet service can guarantee perfect security. Users should protect their device passcode, email account, Apple or Google account, and Harvest password if using email/password sign-in.

Children

Harvest is not intended for children under 13. Harvest does not knowingly collect personal information from children under 13. If Harvest learns that it has collected information from a child under 13, it will take reasonable steps to delete that information.

Changes to This Policy

Harvest may update this policy as the app, infrastructure, provider set, or legal requirements change. When material changes are made, Harvest will update the "Last updated" date and provide notice where appropriate.

Harvest

Personalized nutrition that fits your budget.

Product

How it worksFeaturesPricing

Legal

Privacy Policysupport@harvestnutrition.app

© 2026 Harvest Nutrition. All rights reserved.