Privacy Policy
Effective Date: September 27, 2026
At Chive, we believe managing your kitchen should be simple and private. This Privacy Policy explains how we collect, use, share, and protect your information.
We don't sell your data. We don't share it with third parties for marketing. We don't use it to train AI models. We're transparent about what we collect and why.
1. Information We Collect
Account Information
When you create a Chive account, we collect your name, email address, authentication method (Apple, Google, or email/password), and push notification preferences.
Pantry and Inventory Data
Items you add to your pantry (product names, brands, quantities, categories), storage zones, expiry dates, purchase dates, notes, photos, allergen information, and dietary preferences.
When you import pantry items from a file, such as a CSV or an export from another app, we keep a private copy of that file and a record of how each row was imported. We use it to fix import problems and to improve how Chive reads files from other apps. It is deleted with your account.
Purchase and Grocery List Data
Items on your grocery lists, purchase history (what you bought, when, where, and at what price), and order data you manually share from services like Instacart.
Recipe Data
Recipes you save, import, or scan from cookbooks, including ingredients, instructions, and associated photos.
Receipt and Photo Data
When you scan receipts or take photos, we process them using AI (Claude by Anthropic) to extract product names, quantities, prices, and expiry dates. We strip location metadata (EXIF GPS data) from photos before uploading to cloud storage. You can delete stored photos at any time.
Barcode Data
When you scan barcodes, we collect the barcode number and look up product information from third-party databases.
AI Conversation Data
When you chat with Chive's AI assistant, your messages are processed in real-time but are not permanently stored on our servers. Conversation history is kept in your browser session only and is cleared when you close the chat or clear your browser data. The one exception is a feedback report you choose to send from the chat: if you leave the quoted chat excerpt in place when you tap Send, those messages are emailed to our support inbox (see “Feedback and Support Email” below). Photos you attach to a chat are never included in a feedback report. When you use the AI assistant, relevant context from your account (including inventory items, grocery list, purchase history, and recipes) is sent to Anthropic for processing to provide helpful responses.
Voice and Audio Data
Chive only listens when you ask it to. There are two voice features:
- Talking in chat: the microphone records only while you hold the talk button. In the iPhone app, your speech is converted to text by Apple's speech recognition, which may process the audio on Apple's servers under Apple's terms, and replies you choose to hear are read aloud on your device. On the web, and in versions of the iPhone app before 1.5.5, the recording is sent to OpenAI to convert your speech to text, and replies you choose to hear are sent to OpenAI to generate spoken audio.
- Voice mode (iPhone app, where available): a live, hands-free conversation. While a voice-mode session is active, your voice is streamed to ElevenLabs, which converts it to text and speaks Chive's replies. Chive's answers are written by Claude (Anthropic) using what you said and relevant context from your account, just as in chat. A session ends when you tap End, after 60 seconds of silence, or when you leave the app, and the microphone is not used outside a session.
We use voice audio only to transcribe and speak your conversation; we do not create a voiceprint, perform speaker identification, or use your voice to identify you. Chive does not store your audio recordings. The text of a voice-mode conversation (what you said and Chive's replies) is held on our servers for about two hours, so it can appear in your chat and so a repeated request isn't carried out twice, and then it expires automatically. We also keep a record of each voice-mode session's start and end time, length, and number of turns, which we use for usage limits and troubleshooting. You can turn voice features off at any time in Settings. When voice is turned off, your device does not record or send any audio.
App Usage
We collect technical diagnostics such as crash reports and errors, plus limited first-party product events needed to understand whether key app flows work. We do not use tracking cookies, third-party analytics SDKs, advertising pixels, or cross-service behavioral profiling tools. We do not track your location or build advertising profiles.
Before you create an account, we may record which onboarding screens you reach, the timing and outcome of setup or sign-in attempts, and your app platform, version, and build. Random identifiers stored on your device help us recognize a resumed setup. If you sign in, we can associate that setup attempt with your account. These events do not contain your answers, email address, password, or other form contents. We use them to find and fix onboarding problems. A daily cleanup removes onboarding-attempt records older than 90 days; linked records are also removed when you delete your account.
Optional Feature Setup and Guidance
For supported optional features, Chive may store whether the feature is turned on, a coarse health state (for example healthy, permission denied, unavailable, or needing repair), the app platform and version, a random app-installation identifier, and timestamps or counts for successful use. We also store limited records of contextual guidance, such as whether a feature tip was shown, snoozed, selected, or permanently dismissed. We use this information to operate and troubleshoot the feature, avoid repetitive prompts, provide relevant in-app guidance, and evaluate feature adoption in aggregate.
Apple Reminders details stay on your device. EventKit list and reminder identifiers, titles, and other raw Reminders data stay on your device. Chive sends only privacy-minimized feature-state telemetry, not raw Reminders data; when feature-state reporting is enabled, Chive may count a successful grocery-list import once per sweep, regardless of how many items it contained. Once imported, an item's name and parsed quantity become ordinary Chive grocery-list or pantry data and are handled under this policy.
2. How We Use Your Information
We use your information to:
- Provide core app features (pantry tracking, grocery lists, expiry estimates, recipe management)
- Deliver AI-powered assistance (chat, receipt scanning, food photo identification, cookbook scanning, voice transcription and read-aloud, and voice-mode conversations)
- Enrich product data (names, categories, images, allergens) using third-party databases
- Send push notifications based on your preferences (expiry alerts, shopping reminders)
- Operate and troubleshoot optional integrations, and show limited contextual guidance without repeating dismissed prompts
- Troubleshoot and improve file imports using the import files and row records described above
- Improve the app through de-identified, aggregated analytics
We do not use your data for marketing, targeted advertising, or AI model training.
3. How We Share Your Information
Household Members
If you join or create a household in Chive, all household members can view and edit the shared pantry inventory, grocery list, purchase history, and recipes. The household owner controls membership and can invite or remove members. You can leave a household at any time.
Share Links
If you choose to share a recipe or your grocery list, Chive creates a public link. Anyone who has that link can view the shared content without signing in or having a Chive account — the link itself is the only access control, so treat it like a password and share it only with people you trust.
- A shared recipe publishes its title, description, photo, ingredients, steps, tags, and original source attribution.
- A shared grocery list publishes your household's name and the items currently on the list. It is a live view — recipients always see the current list, not a snapshot from when you shared it.
Share links do not expose your account, email address, pantry inventory, purchase history, or any other household data. We ask search engines not to index them, but an unlisted page can still be seen by anyone the link is forwarded to.
You can turn a link off at any time from the same Share menu you created it in. Revoking takes effect immediately: the link goes dead for everyone, including people who already had it. Turning sharing back on creates a brand-new link, so the old one stays dead.
AI Processing (Anthropic)
When you use AI-powered text and photo features, the following data is sent to Anthropic (the maker of Claude AI) for processing:
- Chat assistant: Your messages, plus relevant pantry inventory, grocery list, purchase history, and recipes as context
- Voice mode: The text of what you say (converted from speech by ElevenLabs), plus the same account context as the chat assistant and the recipe or cooking step on your screen
- Receipt scanning: Receipt photos for item extraction
- Food photo identification: Photos for product identification
- Cookbook scanning: Cookbook page photos for recipe extraction
Anthropic does not use your data to train or improve Claude. Anthropic retains conversation data briefly for safety monitoring, then deletes it. You can review Anthropic's privacy policy and usage policy for full details. You can choose not to use AI features; all other app features work without them.
AI Processing (OpenAI)
Chive uses OpenAI as a service provider for these features:
- Voice-to-text (web, and iPhone app versions before 1.5.5): Audio you record in chat is sent to OpenAI to transcribe your speech into text.
- Read-aloud replies (web, and iPhone app versions before 1.5.5): When you choose to hear a response, the assistant's reply text is sent to OpenAI to generate natural-sounding speech.
- Recipe import from video: When you import a recipe from a public Instagram reel, the reel's audio is sent to OpenAI to transcribe it.
OpenAI does not use data sent through its API to train its models. Chive does not store your audio recordings or transcripts. OpenAI may retain API content briefly (up to 30 days) to monitor for misuse before deleting it. You can review OpenAI's privacy policy for full details. You can disable voice features at any time in Settings.
Voice Mode (ElevenLabs)
Voice mode uses ElevenLabs as a service provider. While a voice-mode session is active, ElevenLabs receives your live voice audio to convert it to text, and the text of Chive's replies to turn into speech. It also receives internal session identifiers (not your name or email address) so Chive can verify the session. ElevenLabs does not write Chive's answers; those come from Chive's servers.
ElevenLabs is set not to store your call audio, and we have opted out of ElevenLabs using this data to train or improve its models. Conversation transcripts are kept by ElevenLabs for up to 14 days to operate the service, then deleted. You can review ElevenLabs' privacy policy for full details. Voice mode is optional and only runs when you start a session.
Authentication (Google)
If you sign in with Google, we use Google's authentication service. We receive your name and email address. We do not request access to your contacts, calendar, or other Google data.
Authentication (Apple)
If you sign in with Apple, we use Apple's authentication service. We receive the name and email address that Apple makes available to us. When you delete your account, we revoke the associated Sign in with Apple authorization where possible.
Cloud Infrastructure (Supabase)
Your data is stored on Supabase cloud infrastructure. Supabase acts as a data processor on our behalf under a data processing agreement.
Feedback and Support Email (Resend, Cloudflare)
When you send feedback, report a bug, or request a feature — from Settings, from the chat assistant, or from our website — we email your submission to our support inbox using Resend (our email provider), and Cloudflare Email Routing forwards it to our team. That email includes your message, the reply-to address you enter, your app version, device and platform information, and, if you chose to include them, the chat messages shown to you in the composer before you sent it. You can remove that chat excerpt before sending; nothing is sent until you tap Send.
Support email is retained separately from your account. Because a report is delivered to a mailbox rather than stored against your account, deleting your account does not remove messages you have already sent us. If you want a past submission deleted, email privacy@chive-app.com and we will remove it.
Payments and Subscriptions
Apple processes purchases made through the App Store. Stripe processes web subscription payments. We use RevenueCat to manage App Store subscription status and entitlements. We do not receive or store your full payment-card number.
Diagnostics (Sentry)
We use Sentry to monitor crashes and errors. Sentry may receive technical diagnostic information, such as device or browser information, app version, and error details. We configure Sentry not to send default personally identifiable information.
Push Notifications
We use the Web Push API to deliver notifications. Push services receive device tokens and notification content, but not your pantry data.
Product Data Services
To enrich product information (names, categories, images, nutrition, allergens), we query the following services using only product identifiers (names and barcodes). No personal data is sent:
- Open Food Facts (open-source product database)
- UPC Item DB (barcode lookup)
- Loblaw / PC Express API
- Metro Canada
- Food Basics
- LCBO (alcohol products)
- Flipp (flyer data)
- USDA FoodData Central (US nutrition data)
- Kroger Product API (US product data)
Our service providers operate under data processing agreements or terms of service that govern how your data is handled in compliance with applicable privacy laws.
We require service providers that process personal data on our behalf to protect it in a manner consistent with this Privacy Policy and applicable law.
4. Cookies, Local Storage, and Tracking
Chive does not use tracking cookies, third-party analytics, or advertising pixels. We use browser local storage and service workers for offline caching, session management, UI preferences, optional-feature configuration, and prompt cooldowns. We also use local storage for random onboarding identifiers and a small, temporary queue of onboarding events, so an interrupted setup can be measured when you return. These identifiers are not used to track you across websites.
Chive does not perform cross-site tracking. Browser Do Not Track (DNT) signals do not change the first-party diagnostics and onboarding measurement described above.
5. Data Storage and Security
Your data is stored on Supabase cloud infrastructure with encryption in transit (HTTPS/TLS) and at rest. We use row-level security policies to isolate your data so that only you and your household members can access it.
If we discover a data breach affecting your personal data, we will notify you as required by applicable law, and in any event within 30 days of discovery, via email with details of what was compromised and steps taken.
6. Your Privacy Rights
Access and Export
You can export a copy of your data through app settings at any time. The full account export is available as a JSON file.
Deletion
You can delete individual items at any time. You can delete your entire account through app settings. We start removing your account data from active systems immediately after you confirm deletion, and backup copies are deleted within 30 days. Data in a shared home remains available to its other members. We may retain limited information where required or permitted by law.
Notifications
You control whether to receive push notifications and can disable them at any time in settings.
AI Features
You can choose not to use AI-powered features. All core app features (pantry tracking, grocery lists, manual item entry, barcode scanning) work without AI.
7. Children's Privacy
Chive requires users to be at least 13 years old. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has created an account, contact privacy@chive-app.com and we will delete it promptly.
8. International Data and Privacy Regulations
GDPR (EU/UK)
If you are in the EU or UK, you have rights under GDPR including: access, correction, deletion, restriction of processing, data portability, and objection. Our lawful basis for processing is your consent (account creation) and legitimate interest (app functionality). Contact privacy@chive-app.com to exercise these rights; we will respond within 30 days.
Where we transfer your personal data outside the EEA or UK to service providers in other countries (including OpenAI, Anthropic, and ElevenLabs in the United States), those transfers are covered by Standard Contractual Clauses and the provider's data processing terms, which provide appropriate safeguards under Article 46 of the GDPR.
CCPA/CPRA (California)
If you are in California:
- We do not sell or share your personal information as defined by the CCPA/CPRA
- We do not use sensitive personal information for purposes beyond what is necessary to provide the app
- You have the right to know what data we collect, request deletion, and opt out of any future sale or sharing
- Contact privacy@chive-app.com to exercise your rights
PIPEDA (Canada)
We comply with Canada's Personal Information Protection and Electronic Documents Act. Your data is collected and used only with your knowledge and consent for identified purposes. You may withdraw consent at any time by deleting your account.
9. Data Retention
We retain your data for as long as your account is active. Optional-feature records from an app installation are deleted after that installation has been silent for 15 months. A permanent feature-tip dismissal is kept until you delete your account so we can honor your choice not to be asked again. When you delete your account, we start removing account data from active systems immediately, and backup copies are deleted within 30 days. Data in a shared home remains available to the other members. De-identified, aggregated analytics may be retained indefinitely. Server error logs that may contain technical request data are retained for up to 30 days. We may retain limited information where required or permitted by law.
10. Changes to This Policy
We'll notify you of significant changes via email or in-app notification at least 14 days before they take effect.
11. Contact Us
- Privacy: privacy@chive-app.com
- Legal: legal@chive-app.com
- Support: support@chive-app.com
Last Updated: September 25, 2026