Skip to main content
Scrappy AI
HomeProductCompany
Download on theApp Store
HomeProductCompanyDownload on theApp Store

Legal

Privacy Policy

Last updated: 2026-07-28. Scrappy AI is a company based in the United States. This policy covers the Scrappy AI iOS app and this website, scrappyai.app. It is written in plain language, and it tells you the parts that are easy to get wrong, including what leaves your phone.

  • Scope
  • The short version
  • Account information
  • Fridge photos
  • AI requests
  • Anonymous device identifier
  • Ingredient corrections
  • Superwall
  • Subscriptions and payment
  • What stays on your device
  • Website analytics
  • Website cookies and your consent
  • Service providers
  • Why we process your information
  • We do not sell your data
  • Data retention
  • Your choices
  • Managing your subscription
  • Security
  • International processing
  • Children
  • Changes to this policy
  • Contact

Scope

This policy applies to two things: the Scrappy AI iOS app and the scrappyai.app website. They collect very different data, so wherever it matters we say which one we mean. The website sections are near the end and are clearly labeled.

The short version

Almost everything Scrappy knows about you stays on your phone: your scans, recipes, pantry, cooking history, savings, and photos of meals you cooked. Three things do leave the device, and we want to be direct about them:

  • Fridge photos are sent to our server and on to an AI provider so we can identify ingredients. They are not stored on our server.
  • Recipe requests (your ingredients, diet, allergies, equipment, and any notes you type) are sent to an AI provider to generate recipes.
  • Subscription and onboarding answers go to Superwall, the service that runs our paywall.

We do not sell your data, and we do not use it for advertising or cross-app tracking.

Account information

You sign in with Apple or Google. From that we receive a stable account identifier, and — on first sign-in only — your name and email address.

All three are stored on your device: the identifier in the iOS Keychain, your name and email in the app's local preferences. Scrappy has no server-side accounts. Our backend never receives your name, your email, or your Apple/Google identifier, and it has no user database to put them in. Signing in is a conversation between your phone and Apple or Google; our server is not part of it.

Fridge photos

When you scan, the app prepares the photo on your device first: it is resized so its longest edge is at most 1536 pixels, re-encoded as a JPEG, and stripped of metadata — the EXIF and GPS tags from your camera are not copied into the version that is sent. Only this prepared image is transmitted; the original camera file is never uploaded.

The prepared photo is then sent off your device to Scrappy's Cloudflare backend, which passes it to Google (Vertex AI / Gemini) for ingredient detection. We want to state that plainly because it is the single most important thing to understand about how Scrappy works: your fridge photos do leave your phone.

Our server does not store the image. It holds it in memory only long enough to pass it to the AI provider and return the detected ingredients, and it is not written to any database, bucket, or log by our code. We also explicitly disable payload logging on the photo path at our AI gateway. A copy of the prepared photo is kept on your device so your scan history has thumbnails; the app keeps only the 30 most recent and deletes older ones automatically.

Google processes the image under its own terms as our AI provider. We cannot see or control Google's internal handling beyond the settings we configure.

AI requests

To generate recipes we send the AI provider the information the request needs: your detected or entered ingredients, your dietary restrictions and allergies, your kitchen equipment and pantry staples, your cooking skill level and doneness preference, and any free-text notes or direction you type into the meal box. Generated recipes come back and are stored on your device.

Two honest details. First, your allergies and dietary restrictions are sent as written, including anything you type yourself, because they act as hard safety constraints on the recipe. Second, unlike the photo path, the recipe request passes through Cloudflare AI Gateway with request logging enabled, which means the contents of a recipe prompt are retained in that gateway's logs under Cloudflare's retention settings. If you would rather not have something recorded, do not type it into the notes field.

Recipe imagery is generated by a different provider: Cloudflare Workers AI, not Google. Only the recipe's title, summary, and ingredient names are sent — never a photo of yours. The generated image is returned to your device and cached there; we do not store it on our server.

Anonymous device identifier

The app generates a random identifier the first time it runs and sends it with each request to our backend. It is a random value created on your device — it is not an advertising identifier, not Apple's IDFA, and not derived from your hardware, your account, or anything else about you. Scrappy does not use App Tracking Transparency because it does not track you across apps or websites.

We use it for two things: counting daily requests so one device cannot exhaust the service, and — if you opted in — filing your ingredient corrections so they can improve your future scans. Using "Delete my data" replaces it with a new one.

Ingredient corrections

When you fix something Scrappy misidentified, that correction can be shared with us to sharpen detection — but only if you turn it on. The control is off by default, and the first time you correct a detection the app asks before anything is shared.

A shared correction is structured text only — in substance, "the model said X, the user corrected it to Y", along with category and freshness labels and a timestamp. No photo is ever included, and no name, email, or account identifier is attached. It carries only the anonymous device identifier, which is what lets your corrections improve your own later scans. Corrections are used to give the AI better context on your device's future scans; they are not used to train or fine-tune any model.

Shared corrections are stored for at most 90 days and then expire automatically.

Two limits worth knowing. Turning the setting off stops future uploads but does not retroactively delete corrections already shared — those expire on their own 90-day schedule. And corrections saved on your device may still be included as context in your own scan requests even after you turn sharing off; using "Delete my data" removes them.

Superwall

Our paywall and subscription handling run on Superwall. Superwall receives your subscription status, purchase and paywall activity, and device information its SDK collects, and uses it to decide which paywall to show and to report on how the paywall performs.

We also pass Superwall a set of answers from onboarding, used to tailor and analyze the paywall:

  • Diet
  • Allergies
  • Cooking skill
  • Household size
  • How often food goes to waste
  • Weekly grocery spending
  • Monthly savings goal
  • Biggest cooking frustrations
  • Where you heard about us — including the free-text box, which is sent exactly as you typed it

Please note that your allergies are among these, and allergy information is health-related. If you would rather not share something in the free-text "where did you hear about us" field, leave it blank.

Scrappy never gives Superwall your name, email, or Apple/Google identifier, and never assigns you a Superwall user ID. One consequence is worth stating: because we never identify you to Superwall, the app's "Delete my data" cannot reach data already sent there. To ask Superwall about that data, contact us and we will help.

Subscriptions and payment

Subscriptions are sold through Apple. Apple processes your payment and your payment details go to Apple, not to us. Scrappy and Superwall learn whether you have an active subscription and what you purchased. Neither of us ever sees your card number, bank details, or billing address.

What stays on your device

The following is stored locally in the app and is not uploaded to Scrappy's servers:

  • Scan history and detected ingredients
  • Saved recipes and cached recipe images
  • Dietary preferences, allergies, likes and dislikes
  • Pantry, inventory, and kitchen equipment
  • Cooking history, ratings, and notes
  • Savings totals
  • Your profile name, email, tagline, and avatar image
  • Photos of meals you cooked
  • Fridge photos from your 30 most recent scans

The app has no iCloud or CloudKit sync, so none of this follows you to another device. It may be included in your normal encrypted iPhone backup, which is Apple's system, not ours. The one thing to keep in mind is the distinction drawn above: your scan history stays local, but the photo itself was sent for analysis when you took it.

Website analytics

This section is about the website only — it has nothing to do with what the app collects.

We use Google Analytics 4 to understand how the site is used, for example which pages people read and how they got here, so we can make the site better. Google acts as our data processor for this. Analytics is off by default: nothing is sent to Google until you accept the consent banner. If you accept, Google may process a coarse, approximate location derived from your IP address, but we do not receive or store your full IP address ourselves, and we do not use analytics for advertising.

There are no accounts, no payments, no email signup, and no fridge photos on this website. If you decline analytics, we collect nothing about your visit beyond what our host needs to serve the page.

Website cookies and your consent

If you accept analytics, Google Analytics sets a small number of first-party cookies (named _ga and _ga_<id>) to tell repeat visits apart. We set no advertising cookies and no cross-site tracking cookies. If you decline, no analytics cookies are set.

The first time you visit, a banner asks whether to allow analytics. It is off until you choose. You can decline and the site works exactly the same. If you change your mind later, clear this site's data in your browser to see the banner again, or use Google's official browser opt-out add-on. We honor your choice with Google Consent Mode, so a declined visit sends nothing.

Service providers

These are the third parties involved in running Scrappy, and what each one handles:

  • Apple — Sign in with Apple, App Store distribution, and all subscription payments.
  • Google Sign-In — the optional Google sign-in option.
  • Cloudflare — hosts our backend and this website, and operates the AI gateway our requests pass through.
  • Google Cloud (Vertex AI / Gemini) — ingredient detection from your fridge photos, and recipe generation.
  • Cloudflare Workers AI — recipe image generation.
  • Superwall — paywall delivery, subscription status, and paywall analytics.
  • Google Analytics — website analytics only, and only with your consent.

Why we process your information

  • To run the app's core features
  • To generate ingredient detections, recipes, and recipe imagery
  • To manage subscriptions and entitlements
  • To apply daily limits and prevent abuse of the service
  • To personalize the paywall and understand how it performs
  • To improve ingredient detection, where you have opted in
  • To measure website usage, where you have consented

We do not sell your data

We do not sell or rent your data to anyone, ever. We do not use it for advertising, and we do not track you across other apps or websites. The app contains no advertising SDK, no attribution SDK, and no general-purpose analytics or crash-reporting SDK.

Data retention

  • On your device: kept until you delete it or remove the app. Fridge photos are capped at the 30 most recent and cached recipe images at 60; older ones are deleted automatically.
  • Fridge photos on our server: not stored at all.
  • Shared ingredient corrections: at most 90 days, then they expire automatically.
  • Daily request counters: expire at the end of each day (UTC).
  • Website analytics: deleted automatically by Google after the retention window we configure, which never exceeds Google's 14-month maximum for this kind of data.
  • Third parties: Apple, Google, Cloudflare, and Superwall retain data under their own policies and retention obligations, which we do not control.

Your choices

  • Correction sharing is off unless you turn it on, and you can turn it off at any time in Profile → Account & Privacy.
  • Delete my data, in the same place, erases your profile, preferences, scans, cooks, savings, saved recipes, and every photo stored on the device, and replaces your anonymous device identifier with a new one.
  • Sign out, also in that card, ends your session but keeps your history on the device.
  • Camera access can be revoked at any time in iOS Settings.
  • Website analytics can be declined on the consent banner, or reset by clearing this site's data in your browser.

Being straight with you about the limits of deletion: "Delete my data" clears what is on the device and is best-effort — it is designed to remove as much as possible rather than to fail if one part cannot be cleared. It does not reach corrections you already shared, which stay on our server until they expire within 90 days, though once your device identifier is replaced they are no longer connected to your app. It also does not delete data held by Superwall, and it does not cancel or refund a subscription. If you want something removed that the button cannot reach, email us and we will handle it by hand.

Managing your subscription

Subscriptions are managed and cancelled through Apple, in your Apple Account settings under Subscriptions (in the Settings app or the App Store). Deleting your data in Scrappy does not cancel a subscription.

Security

Everything the app sends travels over encrypted HTTPS connections. Your sign-in identifier is held in the iOS Keychain, and the rest of your app data sits inside the app's private container, protected by iOS. Our backend stores no photos and no account records. No system is perfectly secure, and we will not pretend otherwise, but we have kept the amount of data we hold deliberately small.

International processing

Our providers operate globally, so your requests may be processed on servers outside your country, including in the United States, under those providers' own safeguards. Google Analytics likewise may process website data outside your country.

Children

Scrappy is not directed to children under 13, and we do not knowingly collect their information. If you believe a child has provided us data, email us and we will delete it.

Changes to this policy

We will update this policy as the app changes. When we make a meaningful change, we will update the "Last updated" date above.

Contact

Questions about your data, or want it removed? Email us at hello@scrappyai.app and a real human (one of the two of us) will get back to you.

Read the Terms of UseBack to home

Footer

Scrappy AI

Turn what's already in your fridge into dinner, and watch the savings add up.

Download on theApp Store

Product

How it worksReviewsGet the app

Company

AboutSupport

Legal

PrivacyTerms
© 2026 Scrappy AISupportBack to top