Skip to content
Panno Panno
How it works Trust Support
Launch preview

Privacy boundary · draft for review

Private by default.
Clear by design.

This page describes the current source boundary: a local-first kitchen, optional anonymous product analytics, and an optional App Store subscription managed with RevenueCat. It is still a draft until the final operator, hosting, retention, and support terms receive legal review.

Release gate: publish a legally reviewed version at the final HTTPS domain and reconcile it with the submitted binary, RevenueCat configuration, and App Store privacy labels.

What stays on-device now

The local beta stores pantry items, plans, shopping items, profile choices, capture drafts, and exportable kitchen state in the app’s Application Support container. The core does not require an account or a network connection.

Photos and receipts

When you choose a photo, the app uses Apple Vision text recognition locally to create a draft. The user reviews candidates before saving. The final policy must be updated if a future feature sends an image or extracted text to a hosted provider.

Optional analytics

Anonymous product analytics is off by default and starts only if you enable it in Settings in a provider-configured build. Panno then sends a random resettable identifier and closed categorical product events to its reviewed PostHog region. Automatic screen, element, replay, survey, crash, and person-profile collection is disabled. Food names, quantities, dates, receipt text, photos, barcodes, allergens, notes, store or budget text, email, prices, and advertising IDs are excluded. Turn sharing off to opt out and reset that identity; deleting local data also resets it. A separate content-free JSONL test log may be enabled only by a local build flag.

Subscriptions

When Plus is configured, RevenueCat receives an anonymous app user ID and Apple purchase history to validate purchases, provide entitlement access, restore purchases, and support subscription analytics. Panno does not send pantry items, photos, receipt text, allergens, notes, email, or advertising identifiers to RevenueCat. Apple processes payment. Prices and any trial terms come from the current App Store offering.

Your controls

Settings provides analytics opt-in and identity reset, export/import and local kitchen deletion, Restore Purchases, and Apple subscription management. Deleting the local kitchen also opts out and resets local analytics state, but it does not cancel a subscription, erase Apple purchase history, or prove deletion from a provider that has not yet been production-configured. Panno has no hosted pantry account in this source boundary; any future sync account would require a separate authenticated deletion flow.

Contact

For beta questions or privacy requests, email support@pannoapp.com. Please do not include pantry contents, receipt images, addresses, or account credentials in a support message.

Source boundary reviewed: 2026-08-08 · Draft pending legal, provider, and hosted verification

Panno
Panno

A clearer next dinner from what you already bought.

Privacy Terms Support Email support

Local-first beta · US English · Privacy draft