Privacy Policy — Hungry Shelf
Effective date: 25 August 2026 Last updated: 25 August 2026 Version: 1.2
The short version
Hungry Shelf is a personal recipe organiser. Your recipe library and cookbooks live on your phone (local database). You can use the app without an account ("guest mode").
If you sign in, we merge your on-device recipes with a copy on our servers (via Supabase) so recipes can survive a phone change. That is a merge when you sign in / open a signed-in session — not a live sync of every edit, and cookbooks stay on the device only.
Link import (Instagram, TikTok, Pinterest) works as a guest or signed-in; it sends the URL you shared to our servers and AI providers. Photo scan and hands-free cook mode require a signed-in account. Photo scan sends a resized image to OpenAI vision (we do not store the image). Cook mode streams microphone audio live to OpenAI Realtime over WebRTC (we do not keep that audio).
The free tier may show ads served by Google AdMob. Hungry Shelf Plus is ad-free. We collect email (and name / avatar URL if Google or Apple supplies them) only when you create an account. We do not use a separate analytics or crash-reporting SDK, and we do not send marketing push notifications.
Please read this Policy together with our Terms of Use.
1. Who we are
This Privacy Policy explains how Udaya Shree Donthula, an individual / sole proprietor trading as Hungry Shelf ("Hungry Shelf", "the app", "we", "us", "our"), collects, uses, stores, shares and protects your personal data when you use the Hungry Shelf mobile application and related services.
We are the Data Fiduciary in respect of the personal data described in this Policy, as that term is defined under India's Digital Personal Data Protection Act, 2023 ("DPDP Act").
| Data Fiduciary | Udaya Shree Donthula (individual / sole proprietor), trading as Hungry Shelf |
| Address | H.No. 8-8-30, Nehru Nagar, Sircilla – 505301, India |
hungryshelfinfo@gmail.com |
There is no separate company, Data Protection Officer, or EU/UK representative. Privacy questions, data requests and grievances go to the email above (see also Section 11).
2. How the App is built — please read this
2.1 Guest mode — on your device
You can browse, save and organise recipes without an account. Guest mode means you are signed out. Your recipes, cookbooks and most settings are stored in the app's private database on your device.
Because that data lives on the device:
- If you uninstall the app, clear its data, reset the phone, or lose the device without signing in and merging, that library can be permanently lost and we cannot restore it.
- Guest link imports still hit our servers (see §3.4) because extraction runs in the cloud — but we do not create a cloud recipe library for guests.
2.2 Signed-in recipes — merge to our servers
When you sign in (email/password, Google, or Apple), the app runs a guest merge: it can upload your local recipes to our backend and pull down recipes already linked to your account. After that, the working copy you edit day to day is still the on-device library.
Important limits of what we actually ship today:
- Recipes can be stored on our servers as part of that merge.
- Cookbooks (collections of recipes) are stored on your device only — the app does not sync cookbooks to the server.
- Day-to-day creates/edits are written to the local database first; they are not pushed on every save.
2.3 Features that leave the device
| Feature | Account required? | What leaves the device |
|---|---|---|
| Link import | No (guest allowed) | Source URL; fetched captions/transcripts/page text sent to AI for extraction |
| Photo scan | Yes | Resized image (base64) → OpenAI vision; draft text returned |
| Hands-free cook mode | Yes | Live mic audio + recipe text → OpenAI Realtime via WebRTC |
| Onboarding quiz | No locally; cloud copy if signed in | Goals / sources you pick |
3. Personal data we collect
We collect only what is listed below for running the app — not for advertising or profiling.
3.1 Account data — only if you create an account
| Data | Required? | Why we collect it |
|---|---|---|
| Email address | Yes, for account | Identify your account, sign you in, recover access, support and deletion |
| Password | Email sign-up only | Authentication — handled by Supabase Auth (hashed; we never store plain text) |
| Display name | If you or Google / Apple supply it | Shown in the app (from auth user_metadata) |
| Profile picture URL | If Google / Apple supply it | Shown as avatar. We do not upload or host the image file |
| Account ID | Automatic | Links server-side recipes, onboarding rows and import jobs to you |
We do not receive your Google or Apple password. Apple's "Hide My Email" is supported — we only see the relay address Apple gives us.
Our profiles table stores your account id and timestamps — not a separate copy of email/name/avatar columns.
3.2 Content you create
| Data | Where it is stored |
|---|---|
| Recipe fields (title, ingredients, steps, notes, timers, source links, cover URLs, etc.) | On device; a copy may exist on our servers after you sign in and merge |
| Cookbooks and which recipes are in them | On device only |
3.3 Onboarding answers
Goals and recipe sources you pick during setup are stored in on-device preferences. If you are signed in, they may also be upserted to our user_onboarding_responses table. Used to tailor the app; not for advertising.
3.4 Import data (link import)
When you import from a link, we create an import job on our servers containing the source URL, status, timing, error codes and an extracted recipe draft. Guests and signed-in users can create jobs (guests use the anonymous API key).
Rate limits (abuse prevention):
- Guest (no account): about 10 imports per hour per IP address
- Signed-in: about 60 imports per hour per user
We read the client IP from standard proxy headers for that counter. It is used for rate limiting, not for building a marketing profile.
Device free-tier caps (stored only on the device): limited full video/link extractions, daily caption-only imports, and photo scans — shown in the app.
3.5 Photos (recipe photo scan)
Photo scan requires a signed-in account. The app resizes the image and sends it to our Edge Function, which forwards it to OpenAI vision. We do not write the image to our database or file storage — only the returned recipe draft text (if you save it).
Camera and photo-library access are requested only for this feature. Server-side fair-use limit: about 20 photo scans per hour per user.
3.6 Microphone and voice (hands-free cook mode)
Cook mode requires a signed-in account. The app opens a WebRTC session to OpenAI Realtime (ephemeral credentials minted by our server). Microphone audio is streamed live; recipe title, ingredients and steps are sent as session context.
Hungry Shelf does not record cook-mode audio to files or keep it in our database. When you leave cook mode, the session ends and the mic track is released. Session minting is rate-limited (about 30 per hour per user). A Google STUN server may see connection metadata needed to set up the WebRTC link.
OpenAI processes the live stream under its API terms; we do not control their internal processing beyond using their API.
3.7 Purchases
Hungry Shelf Plus is sold through Google Play / Apple App Store using the store billing APIs (not a third-party billing SDK like RevenueCat). We never see your card. The app stores a local flag that Plus is active (and related trial/prefs) in on-device preferences. An active Plus subscription is also used to stop showing ads.
3.8 Advertising (free tier)
The free version of Hungry Shelf may display third-party advertisements through Google AdMob (and related Google advertising services).
When ads are shown, Google’s advertising SDK may automatically process data such as:
- Advertising identifiers (for example Android Advertising ID or Apple’s Identifier for Advertisers, where available and permitted)
- IP address and coarse device / network information
- Device and app information (model, OS version, app version)
- Ad performance data (impressions, clicks, and similar events)
That processing is performed by Google under its advertising / AdMob terms and Google’s Privacy Policy. We use it to show ads and to measure that ads are delivered. We do not send your recipe library, cook-mode audio, or scanned photos to AdMob for advertising.
Hungry Shelf Plus removes ads. If you do not want ads, upgrade to Plus or adjust device ad / tracking settings (for example reset or opt out of the advertising ID on Android, or App Tracking Transparency / Limit Ad Tracking on iOS where those controls apply).
We do not operate our own ad auction. Ad content is chosen by Google and its advertiser partners, not by Hungry Shelf.
3.9 Device settings and quotas
Stored only on your device, for example: units, voice hints, keep-screen-on, language, onboarding completion, free-tier usage counters, and the Plus active flag.
3.10 What we do not collect or do
Hungry Shelf does not:
- Use a separate analytics or crash-reporting SDK for product analytics
- Send marketing or promotional push notifications
- Collect contacts, calendar or health data for the core recipe features
- Sell your personal data for money
- Train our own models on your content
AI calls go through provider API endpoints. Providers' default API policies typically disallow training on API data; their privacy terms still apply.
4. Why we process your data
- Create and secure your account when you sign in.
- Provide the on-device library and, after sign-in merge, server-side recipe backup.
- Run link import, photo scan and cook mode when you use those features.
- Enforce free-tier and abuse rate limits.
- Process subscriptions via the app stores.
- Show ads on the free tier (via Google AdMob) and measure ad delivery.
- Diagnose failed imports and keep the service secure.
- Respond to support, grievances and rights requests under the DPDP Act and other law.
- Comply with law and lawful requests from authorities.
We will not use personal data for a new purpose without telling you and, where required, asking for fresh consent.
5. Legal basis and your consent
Under the DPDP Act (India): consent for the features you use (Section 6), and where allowed legitimate uses under Section 7 (for example legal obligations).
Where GDPR / UK GDPR applies, we also rely on:
| Purpose | Legal basis |
|---|---|
| Provide the app, merge recipes when you sign in | Performance of a contract |
| Link import / photo scan / cook mode you start | Contract and/or consent (camera, mic) |
| Rate limits and abuse prevention | Legitimate interests |
| Diagnose failed imports | Legitimate interests |
| Store subscriptions | Performance of a contract |
| Show ads / measure ads (AdMob) on the free tier | Consent and/or legitimate interests, and platform consent (e.g. ATT) where required |
| Comply with law | Legal obligation |
We do not make automated decisions with legal or similarly significant effect about you. Ad targeting decisions are made by Google / advertisers, not by Hungry Shelf as a credit or eligibility decision about you.
5.1 Consent is per feature
- Account — email / Google / Apple sign-in
- Recipe merge — when you sign in
- Link import — URL you choose to import
- Photo scan — camera/photos + image upload (signed-in)
- Cook mode — microphone + live audio (signed-in)
- Purchases — via Google Play or the App Store
- Ads (free tier) — device / tracking permissions where the OS asks; Plus removes ads
Guest mode works without an account. Refusing camera or mic in system settings disables those features. Refusing tracking / resetting the advertising ID may limit personalised ads.
5.2 Withdrawing consent
Revoke permissions in device settings, delete content in the app, subscribe to Plus (stops ads), or delete your account (§9). Withdrawal does not undo lawful processing already done; the related feature stops working.
6. Who we share your data with
We do not sell your personal data for money. On the free tier we use Google AdMob to show ads, which means device and ad-related data may be processed by Google and its advertising partners as described in §3.8.
6.1 Service providers
| Provider | What it receives | Purpose |
|---|---|---|
| Supabase | Auth, account id, merged recipes, onboarding rows, import jobs, rate-limit buckets | Backend, auth, database, Edge Functions |
| OpenAI | Import text / transcripts / page content; scan images; live cook-mode audio + recipe context | Extraction and Realtime voice |
| Supadata | Import URLs (metadata / transcripts / extract stages) | Social/video fetch for import |
| Jina Reader | Some web URLs (e.g. Pinterest article fetch) | Page text for import |
| Instagram / TikTok / Pinterest oEmbed | Public post URL | Public metadata for import |
| Google Sign-In / Apple Sign in with Apple | Auth tokens / profile fields they return | Sign-in |
| Google STUN | Connection metadata | WebRTC setup for cook mode |
| Google Play / Apple App Store | Purchase transaction | Billing |
| Google AdMob (and related Google advertising services) | Advertising ID (where available), IP / device / app info, ad events | Show and measure ads on the free tier |
6.2 Legal disclosures
We may disclose data where required by law or in good faith to comply with a lawful request, enforce our Terms, or protect users or Udaya Shree Donthula.
6.3 Business transfer
If Hungry Shelf is sold or transferred, personal data may move with it. We will notify you before a different privacy policy applies.
7. Where your data is stored
- On device: recipes (working copy), cookbooks, settings, free-tier counters, Plus flag.
- Supabase: auth, merged recipes, onboarding responses, import jobs, rate-limit buckets — infrastructure may be outside India (commonly including the United States).
- OpenAI / Supadata / Jina: processing for the features above, often outside India.
- Google AdMob: ad serving and measurement may use Google infrastructure in multiple countries.
Under the DPDP Act, cross-border transfers are allowed except to countries restricted by notification. Your access, correction and erasure rights still apply to copies we control. Where GDPR/UK GDPR requires it, providers' Standard Contractual Clauses or equivalent safeguards may apply.
8. How long we keep your data
| Data | Retention |
|---|---|
| Account | Until you delete the account |
| Merged cloud recipes / onboarding rows | Until you delete them or the account (cascade on account delete) |
| On-device library, cookbooks, settings | Until you clear app data / uninstall, or delete account in-app (clears local recipes/cookbooks) |
| Import jobs (URL, status, draft) | On account delete, profile_id is set to null (detached, not instantly wiped). Guest import jobs are also stored with no profile. A scheduled job deletes rows with profile_id is null older than 90 days (purge_detached_import_jobs) |
| Rate-limit counters (IP / user) | Rolling one-hour windows for enforcement; bucket rows are operational data, not a profile |
| Scan images | Not stored by us after the request finishes |
| Cook-mode audio | Not stored by us |
| Support emails | As needed to resolve the request, then typically up to 24 months unless law requires longer |
Local free-tier / Plus preference flags may remain on the device after account deletion until you clear app data — they are not your cloud account.
9. Your rights
9.1 Under the DPDP Act (India)
Access, correction, erasure, withdraw consent, grievance redressal, nomination (email us to register a nominee), and complaint to the Data Protection Board of India. These cover data we hold on our servers. On-device-only data (including cookbooks) you control by editing the app or clearing app storage.
9.2 Delete your account
In the app: Profile → Settings → Delete account (calls our delete_own_account RPC, then clears local recipes/cookbooks).
Without the app: email hungryshelfinfo@gmail.com from your account email with subject "Delete my account". See delete-account. We respond within 30 days.
Deleting the account does not cancel Hungry Shelf Plus — cancel in Google Play or App Store settings.
9.3 Verifying it is you
We may require email from the address on the account (or Apple relay) before acting.
9.4 California (CCPA/CPRA)
We do not sell personal information for money. Showing ads through Google AdMob may involve sharing device identifiers and related data with Google for advertising in the sense used by the CCPA/CPRA. You may opt out of personalised ads using your device settings (and, where available, platform advertising controls). You may exercise rights to know, delete and correct using the contacts above; we will not discriminate against you for doing so. Hungry Shelf Plus removes in-app ads.
9.5 EEA / UK
Where GDPR/UK GDPR applies, you may also request restriction or object to legitimate-interest processing, and complain to your local authority. Prefer contacting us first at hungryshelfinfo@gmail.com.
10. Security
Reasonable safeguards we use include:
- HTTPS/TLS to our backend and providers
- Passwords handled by Supabase Auth (hashed)
- Row-level security so one account cannot read another's server recipes
- Server rate limits on import, photo and voice session endpoints
- Not retaining scan images or cook-mode audio in our systems
No system is perfectly secure. Protect your device with a screen lock.
11. Grievances and how to contact us
| Grievance Officer | Udaya Shree Donthula |
hungryshelfinfo@gmail.com | |
| Address | H.No. 8-8-30, Nehru Nagar, Sircilla – 505301, India |
| Response time | Aim to acknowledge within 72–120 hours; resolve within the period required by law and no later than 90 days |
You may also complain to the Data Protection Board of India.
12. Personal data breaches
If a breach affects your data, we will tell you without undue delay in plain language, and report to authorities required by law (including, where required, the Data Protection Board of India and CERT-In) within applicable timelines.
13. Children
Hungry Shelf is not directed to children. Age rules are in our Terms of Use. We do not knowingly collect children's data. If you believe we have, email hungryshelfinfo@gmail.com and we will delete it. DPDP rules on children's data apply where relevant; we do not knowingly offer the service to children under that Act.
14. Changes to this Policy
Material changes (new data categories or purposes) will update the date above and be notified in the app or by email where practicable; fresh consent where required. The "Last updated" date shows the latest revision.
15. Language and territory
This Policy is published in English. Hungry Shelf is operated from India. The app may be available in other countries via Google Play and the App Store. Non-excludable local rights still apply. Other Eighth Schedule languages: email us and we will provide one where reasonably practicable.
Udaya Shree Donthula, trading as Hungry Shelf H.No. 8-8-30, Nehru Nagar, Sircilla – 505301, India hungryshelfinfo@gmail.com