Privacy Policy
Effective date: July 1, 2026 · Last updated August 15, 2026
Grocery Fresh Chef ("we," "our," or "us") builds your weekly meal plan around real sale prices at your grocery store and, if you choose, adds the ingredients to your real cart. This policy explains what information we collect to do that, how we use it, who we share it with, and how we protect it.
Information We Collect
- Account information: your email address and password, used to create and secure your account. Your password is never stored by us in readable form.
- Household & meal preferences: household size, dietary needs, cuisine styles, and your "meal style" settings (freshness vs. savings, and quick vs. advanced prep). We save these so future visits are pre-filled instead of starting from scratch.
- Store location: the ZIP code you provide, used to find the nearest participating store. We don't collect or store your full street address.
- Kroger account connection: if you choose to add a plan's ingredients to your real cart, you're redirected to Kroger's own login page to authorize us. We receive and store an access token (and refresh token) that lets us add items to your cart on your behalf. We never see or store your Kroger password.
- Payment information: if you subscribe, your payment details are collected directly by our payment processor. If you subscribe through our website, that's Stripe; if you subscribe through our iOS app, that's Apple, through your Apple ID account. We never receive or store your full card number — only your subscription status and a reference ID for your account from whichever processor you used.
- Plan & order history: the meal plans generated for you, which meals you keep or swap, and your cart/checkout history, so we can show you your own past plans and send order confirmations.
How We Use Your Information
- To generate a weekly meal plan built around real, current sale prices at your selected store.
- To find and, at your direction, add the ingredients for that plan to your real grocery cart.
- To remember your household and meal-style preferences so returning visits are pre-filled.
- To send a confirmation summarizing your order after checkout.
- To process your subscription payment, if you have one.
- To maintain the security and reliability of the service.
We do not use your information to build an advertising profile, and we do not sell your personal information to anyone.
How Information Is Shared, and How
We share the minimum information each of the following parties needs to do its specific job for you, always through a direct, encrypted (HTTPS) connection between servers — never by email, fax, physical mail, or manual hand-off.
- Kroger: your ZIP code, to locate nearby stores; and — only after you separately log in and authorize it on Kroger's own site — cart-add requests made using the access token Kroger issues to us for that purpose.
- Anthropic or ChatGPT (our AI recipe providers): the store name, this week's sale prices, and your household/dietary/cuisine/meal-style preferences, to generate your recipes. We never send your email, password, or payment information to AI.
- xAI: the name and short description of each meal (no personal information), to generate a representative photo.
- Stripe: if you subscribe through our website, your payment details are collected and processed directly by Stripe. We receive back only a subscription status and Stripe's own reference IDs, via Stripe's encrypted API and webhook notifications.
- Apple: if you subscribe through our iOS app, your purchase is collected and processed directly by Apple through your Apple ID account. We receive back only a subscription status and a transaction reference ID from Apple's App Store, via Apple's StoreKit APIs — never your payment details.
- Supabase (our infrastructure provider): stores your account credentials (securely hashed), preferences, and Kroger tokens on our behalf. Supabase acts as our data processor, not an independent party that uses your data for its own purposes.
We do not disclose your personal information to any other party, and we do not sell it.
Security
- All data in transit between your browser, our servers, and the parties above is encrypted via HTTPS/TLS.
- Your password is never stored by us in readable form — authentication is handled by our provider, which stores only a securely hashed version.
- Your Kroger access token is stored on our servers and used solely to fulfill cart requests you initiate. It is never exposed to your browser or to any party other than Kroger.
- Your payment details are collected and stored directly by our payment processor — Stripe for web subscriptions (a PCI-DSS compliant processor), or Apple for iOS subscriptions, made through your Apple ID account. Our servers never receive or store your full card number.
- Access to backend systems and data is restricted to what's necessary to operate the service.
Data Retention
We retain your account, preference, and plan history for as long as your account is active, so we can keep providing the service. If you close your account, we delete your stored preferences and Kroger access tokens; we may retain records required for legal, tax, or fraud-prevention purposes for a limited period afterward.
Your Choices
- You can review and change your household and meal-style preferences at any time in Step 2 of the app.
- You can revoke our access to your Kroger account at any time from your Kroger account settings, or by contacting us.
- You can request a copy of, correction to, or deletion of your personal information by contacting us at the email below.
Children's Privacy
Grocery Fresh Chef is not directed at children and is not intended for use by anyone under 18 — creating an account requires being at least 18 years old, or the age of majority in your jurisdiction, consistent with our Terms of Service. We do not knowingly collect personal information from anyone under 13.
Changes to This Policy
If we make material changes to this policy, we'll update the effective date above and, where appropriate, notify you directly.
Contact Us
Questions about this policy or your information? Contact us at support@groceryfreshchef.com.