PantryBee Privacy Policy

Effective date: 3 September 2026 Version: 1.0

PantryBee, LLC ("we," "us," "our") makes PantryBee products for household inventory and shopping. This policy explains what information we collect, why, and what you can do about it.

We have tried to write this so that it is actually readable. If anything here is unclear, email us at contact@pantrybee.buzz and we will explain it.


1. What this policy covers

Term Meaning
PantryBee, LLC The company. Referred to below as "we," "us," or "our"
PantryBee Our brand and product family
GroceryBee Our current product — both the app and the physical barcode scanning device
Device A GroceryBee scanner unit
Firmware The software we ship on the Device
App The GroceryBee mobile and Windows applications
Site grocerybee.buzz and pantrybee.buzz
Services The App, the Site, the Device, and our backend, together
Household A group of people who share a single PantryBee list

This policy covers all of the above. Where something applies only to the Device, we say so.

Where we operate. PantryBee is offered in the United States. We do not currently offer the Services in the European Economic Area, the United Kingdom, or Switzerland, and this policy is not written to satisfy the GDPR or other non-US frameworks. If you use the Services from outside the United States, your information will be processed in the United States.


2. How the GroceryBee Device works

This section is the heart of the policy, because the Device is where people have the most questions.

The Device reads barcodes and nothing else.

The GroceryBee uses an embedded barcode scanner module. That module contains a small image sensor, because that is how optical barcode readers work. The module decodes the barcode inside its own hardware and outputs only the decoded value — a string of characters such as 049000006344. The module provides no mechanism to read image data out of it, and the Firmware has no capability to capture, store, or transmit images.

No images ever leave the Device. We never receive an image of any kind.

Scanning happens only when you press a button. The scanner sits idle until you physically press the scan button. When you press it, the scanner switches on, looks for a barcode for a short window, and then shuts itself off. It does not scan continuously, it does not wake on motion, and it cannot be switched on remotely by us or by anyone else. The current length of that window is documented in the product manual; it is short, and it always ends on its own.

The scanner cannot operate invisibly. Whenever the scanner is active, its red aiming beam and white illumination LED are lit. Our firmware never turns those indicators off, and it re-applies the scanner's configuration every time the Device powers on. There are no silent scans. If the lights are off, the sensor is off.

The Device has no microphone. It cannot record or process audio.

The Device does not know where it is. It has no GPS. It never sends us your Wi-Fi network name (SSID), your router's hardware address (BSSID), or a list of nearby networks. Your Wi-Fi credentials are stored only on the Device itself and are never transmitted to us.

What the Device does send us: decoded barcode values with timestamps, its hardware identifier, its firmware version, and basic connectivity and error information.

These statements describe the Firmware that we publish and sign. See § 13 on modified firmware.

[FORWARD NOTE — do not publish. When QR-based product codes ship (GS1 Digital Link, SmartLabel) this section needs updating, and the change is material under § 19. Digital Link URIs carry GTIN (01), expiration date (17), and batch/lot (10) inside the URI itself, so all of it can be parsed locally without fetching the brand-hosted URL. If you also store serial numbers (21), that is a new data category for § 3.4 — see the separate note on why 21 is different from 01.]


3. Information we collect

3.1 Account information

  • Email address. Used to create your account, sign you in, and send service messages. This is the only piece of information we require.
  • Authentication credentials, handled by Firebase Authentication and stored in hashed form. We never see your password.

3.2 Mailing list

You can join our mailing list without buying anything and without creating an account. If you do, we keep your email address and the date you signed up, and nothing else.

The mailing list is opt-in and stays that way.

  • Buying a GroceryBee does not add you to it. If you want product news, you tick a box and say so. We will not tick it for you.
  • Creating an account does not add you to it. Account holders still get service messages — security notices, order updates, changes to these terms — but those are not marketing and are separate from this list.
  • Every marketing email has a working unsubscribe link. One click, no reason required, no "are you sure."
  • We keep the mailing list separate from your account and your Device. Unsubscribing does not affect your account, your data, or your warranty, and we do not use it to work out who owns which Device.

We do not sell, rent, or share the mailing list.

3.3 Household information

  • Display names. You may add names for the people in your Household so everyone can tell each other apart. These are freeform — "John," "Dad," "Kitchen," or anything else. We do not require real names and we recommend nicknames.
  • Household membership and roles.

3.4 List and scan data

  • Decoded barcode and QR code values and the time each was scanned.
  • Which Household member performed the scan, if names are in use.
  • Items you add, edit, or remove manually, including any quantities or notes you enter.

3.5 Device information

  • Hardware identifier, assigned during manufacturing.
  • Device authentication token, a random value we issue when a Device is first activated.
  • Firmware version and hardware revision.
  • Connectivity and error information, such as failed uploads, restarts, and battery-low indications.

3.6 App and Site information

  • Device and app information: operating system, app version, and general device model.
  • Diagnostic and crash information, including error reports and an application installation identifier.
  • IP address, which we use for security, abuse prevention, and approximate country-level location. We do not use it to determine your precise location.
  • Basic usage information about which features are used.

3.7 Purchase information

If you buy a Device directly from grocerybee.buzz or pantrybee.buzz, our payment processor collects your payment details, shipping address, and contact information. We never receive or store your full payment card number. See § 9.

We also record which Device we shipped against which order. That means we can look up your GroceryBee from your email address — useful for a warranty claim when you cannot find a receipt, or for support if the setup code on your Device becomes unreadable. It is a service record, and we do not use it for marketing.

If you buy a GroceryBee from Amazon, another online retailer, or a physical store, we receive nothing about that purchase. We do not know who you are until you create a PantryBee account, and we never receive purchase records from retailers. In that case the only link between you and your Device is the one created when you activate it. If you later send us a receipt to support a warranty claim, we keep it only for that purpose.


4. What barcode data can reveal

We want to be direct about this, because it is easy to assume a barcode is just a number.

A decoded barcode identifies a specific product. Over time, a household's scan history can imply things that feel personal — dietary restrictions, religious observance, health conditions, whether someone is pregnant, alcohol or tobacco use, and which over-the-counter medications are in the house.

We treat your list and scan data accordingly:

  • We do not sell it. See § 7.
  • We do not use it for advertising, and we do not share it with advertisers, data brokers, or analytics companies.
  • We do not use it to build profiles beyond what the Services need to show you your own list.
  • We do not use it to train machine learning models. See § 11.

5. Your Household can see your activity

This is a design consequence worth stating plainly.

If you belong to a Household, other members of that Household can see the list, the items that have been scanned, and — if display names are in use — which member scanned them. That is the point of a shared pantry, but it means your scanning activity is visible to the people you share a Household with.

If you do not want your activity attributed to you, use a generic display name or none at all.

If you have been added to a Household by someone else and you want your display name removed, the Household administrator can remove it, or you can email us at contact@pantrybee.buzz and we will handle it directly.


6. Publishing an item definition

The Services may let you publish an item definition — a label for something you made, so that another PantryBee user who scans your code can see what it is. The intended use is small-scale sellers: someone at a farmers market labels their jars once, and any buyer with PantryBee gets the name and date without typing.

This is opt-in, per item, and off by default. We do not offer it today. When we do, nothing about your pantry becomes visible unless you deliberately publish that specific item.

If you publish a definition:

  • It becomes readable by anyone, not just people you know. Treat it as public.
  • Only these fields are included: the item name, and optionally production and best-by dates, a description, and a source block — a seller name, website, email, phone, and a note about where to find you.
  • Think carefully before putting contact details in the source block. It is world-readable and it stays readable in other people's pantries after you unpublish. If you sell from home, use a business address and phone or none at all.
  • These are never included: your quantities, storage locations, notes, scan history, Household, email address, or anything identifying your account.
  • You can unpublish at any time. That stops future lookups, but it does not remove copies already saved by other households — those copies are their data now.
  • Published definitions can outlive your account. People may be holding your labels for years, so if you delete your account we keep the definition resolvable but remove your source block — seller name, website, email, phone, and location. The item name, dates, and description remain. If you would rather it all disappear, tell us when you delete and we will unpublish everything.
  • A name inside the item name stays. If you call it "Bob's Strawberry Jam," that is the item's identity, not a contact detail, and it is not stripped.

Definitions published by other people are written by those people. We do not verify them. That matters most for ingredient and allergen information — see § 13 of the Terms of Service, and read the actual package.


7. What we do not do

To be unambiguous:

  • We do not sell your personal information, as "sell" is defined under the California Consumer Privacy Act or any other US state privacy law.
  • We do not share your personal information for cross-context behavioral advertising, including targeted advertising.
  • We do not serve advertising in the Services, and we do not choose what to show you based on a profile of you.
  • We do not use your list or scan data to train AI models.
  • We do not transmit images or audio. The Device cannot produce either.
  • We do not collect precise geolocation.

Shopping links. We may at some point offer links to buy items already on your list from retailers, and may earn a commission if you use them. We do not offer these today. If we do: the links will be generated from the product itself, never from a profile of you; we will not send your information to the retailer to create them; and we will say so plainly wherever they appear.

If any of this changes, we will update this policy, give notice before the change takes effect, and — where the change is material — obtain your consent as described in § 19.


8. Cookies and similar technologies

We use as few of these as we can get away with.

On our website:

Purpose What it is Can you refuse?
Keeping you signed in A session cookie set by us No — the site cannot work without it
Checkout and fraud prevention Cookies set by Stripe when you buy No — required to take payment securely
Remembering preferences A local setting stored in your browser Yes, and nothing breaks

We do not use advertising cookies, cross-site tracking, or third-party marketing pixels. No advertiser, data broker, or social network receives anything about your visit.

Stripe sets its own cookies during checkout to detect fraud and process your payment. Those are governed by Stripe's privacy policy, not this one.

If we add website analytics — we are considering Google Analytics — we will say so here before switching it on, configure it to avoid collecting more than we need, and honor Global Privacy Control and browser Do Not Track signals where they are sent. We will not use it to build advertising profiles.

In the App: the App does not use cookies. It stores your sign-in token and your preferences on your own device, and it uses Firebase Crashlytics for error reports as described in § 9.

You can clear or block cookies in your browser settings. Blocking the sign-in and checkout cookies will prevent you from signing in or buying anything, but you can browse the site without them.


9. Service providers

We use a small number of outside services to operate PantryBee. They act on our instructions, are contractually barred from using your information for their own purposes, and are required to delete it when our relationship ends.

Provider What it does What it receives
DigitalOcean Hosts our backend and database All Service data, as our processor
Firebase Authentication (Google) Signs you in and manages account credentials Email address, authentication tokens
Firebase Crashlytics (Google) Reports app crashes and errors App version, operating system, device model, crash traces, an app installation identifier
Stripe Processes purchases made on our store Payment, billing, and shipping details
Go-UPC Resolves barcodes into product names and details Individual barcode values only
Resend Sends account and service email Email address and message contents
Google Gemini Shortens product names and assigns store sections Product names and category information returned by Go-UPC. No personal information. See § 11.

A note on barcode lookups. When you scan an item we do not recognize, we query Go-UPC to find out what it is. We send only the barcode value. We do not send your account identifier, your Household, or anything else that would let Go-UPC connect that lookup to you.

We may also disclose information:

  • to comply with law, legal process, or a lawful government request;
  • to investigate fraud, protect the security of the Services, or protect the rights and safety of our users or others;
  • in connection with a merger, acquisition, or sale of assets, in which case we will give notice before your information becomes subject to a different privacy policy.

10. How we use information

  • To operate the Services and keep your list in sync.
  • To authenticate you and your Devices.
  • To verify that a Device is genuine. See § 12.
  • To provide customer support.
  • To diagnose problems, fix bugs, and improve reliability.
  • To detect and prevent fraud, abuse, counterfeiting, and security incidents.
  • To send you service messages — account notices, security alerts, and changes to these terms. These are not marketing and you cannot opt out of them while you have an account.
  • To send you product news and marketing, only if you opt in. You can withdraw that at any time using the unsubscribe link in any marketing email, from the App, or by emailing us. See § 3.2.
  • To comply with our legal obligations.

11. Artificial intelligence

We use AI for two narrow jobs, and neither one involves your personal information.

Shortening product names. Barcode databases return names like KELLOGGS FROSTED FLAKES CEREAL ORIGINAL FAMILY SIZE 24 OZ BOX. We use an AI model to turn that into something readable, like Frosted Flakes.

Assigning store sections. We use an AI model to work out which part of a store a product is usually found in, so your shopping list can be sorted sensibly.

Both jobs run on product information returned by Go-UPC — names and categories that are identical for every customer and are not about you. The model does not receive your list, your scan history, your Household, your email address, or anything else identifying you.

This happens once per product, not once per person. The first time anyone scans a product we have not seen before, we look it up, run these two steps, and store the result in our shared product catalog. Every later scan of that product by anyone reads from the catalog. We re-run the process only when a catalog entry is old enough to be worth refreshing. The model is never invoked in response to an individual person's activity.

We use Google Gemini for this, on a paid API account whose terms prohibit Google from using submitted data to train or improve its models.

We do not use your personal information, list, or scan history to train machine learning models, and we do not provide that data to anyone else for model training.

One exception, stated plainly. When we are diagnosing a specific technical problem — usually one you have reported to us — an engineer may use AI-assisted tools that process data associated with your account. When that happens, we use only what the diagnosis requires, only under agreements that prohibit the provider from training on it or using it for their own purposes, and never for any other purpose.

No feature of the Services makes decisions about you that produce legal or similarly significant effects.


12. Device records and counterfeit prevention

We keep a permanent record of every GroceryBee we manufacture, identified by its hardware identifier. When a Device activates, we check it against that record and refuse activation if it does not match. This is how we prevent counterfeit hardware from connecting to the Services.

That manufacturing record contains no information about you. It is created when the Device is built, before it is sold to anyone, and it consists of the hardware identifier, hardware revision, and build information.

Separately, once you activate a Device, we store a link between that Device and your Household. That link is information about you, and it is deleted when you unbind the Device or delete your account. The manufacturing record survives, because it is not about you and it has to, in order to keep working.

If a Device you legitimately bought is refused at activation, email contact@pantrybee.buzz. That is a problem on our end, not yours, and we will fix it.


13. Modified firmware

The GroceryBee ships with an unlocked bootloader. You own the Device and you are free to run your own software on it. We think that is how hardware should work.

Everything in this policy describes the Firmware that we build and sign, running on hardware in its factory configuration. A Device running modified firmware may behave in ways we do not control and cannot describe, including collecting or transmitting information that our Firmware does not. Our privacy statements do not extend to modified firmware, or to a Device whose hardware has been reconfigured by someone with physical access to it.

Over-the-air updates are cryptographically signed and a Device will only install an update that verifies against our signing key.


14. How long we keep information

Category Retention
Account information Until you delete your account, then up to 30 days
List and scan data Until you delete it or delete your account. This is your data and it stays until you say otherwise.
Device-to-Household link Until the Device is unbound or the account is deleted
Device manufacturing record Indefinitely — see § 12. Contains no information about you.
Diagnostic and error data Up to 12 months
Mailing list Until you unsubscribe, then removed within 30 days. We keep a minimal record that you unsubscribed, so we do not email you again by mistake.
Device-to-order record 2 years — the 1-year warranty plus a margin for late claims. Deleted separately from, and earlier than, the financial record below.
Purchase and transaction records As long as required by tax and accounting law, typically 7 years. These are financial records and do not include which Device shipped to you.
Published item definitions While published. Survive account deletion with the source block removed, unless you ask us to unpublish — see § 6
Aggregate statistics that do not identify anyone Indefinitely

When you delete your account we delete your information from our production systems within 30 days. Backups are overwritten on a rolling basis and are purged within 90 days.


15. Your choices and rights

Roughly twenty US states have comprehensive privacy laws granting rights over personal information. Rather than sort out which of them technically apply to a company our size, we extend the following rights to everyone who uses PantryBee, regardless of where you live.

  • Know what information we hold about you.
  • Access a copy of it.
  • Correct anything inaccurate.
  • Delete your information. One narrow exception: item definitions you chose to publish stay resolvable for people holding your labels, with your contact details removed — and you can ask us to remove those too. See § 6.
  • Port your data in a portable, machine-readable format.
  • Opt out of any sale, sharing, targeted advertising, or profiling. We do none of these, so there is nothing to opt out of — but the right stands if that ever changes.
  • Withdraw consent where processing is based on it.
  • Not be discriminated against for exercising any of these rights.

How to exercise them. Use the controls in the App, or email contact@pantrybee.buzz. We respond within 45 days and will tell you if we need more time. We may ask you to verify control of your account email before acting on a request.

Appeals. If we decline a request, you may appeal by replying to our response. We will answer within 45 days. If we deny the appeal, you may contact your state attorney general.

Authorized agents may submit requests on your behalf with written proof of authorization.


16. Deleting data from the Device itself

The Device stores your Wi-Fi credentials, its authentication token, and a small cache of recent scans locally.

To erase all of it: hold the settings button for 10 seconds and release. The Device will erase its stored data and return to its unconfigured state.

Do this before you sell, give away, recycle, or return a GroceryBee, so the next owner does not inherit your network credentials.

This erasure clears stored credentials and data from the Device. Because the bootloader is unlocked and flash memory is not encrypted, we cannot represent that erasure is unrecoverable against someone with physical possession, the right equipment, and the intent to recover it. If that is part of your threat model, destroy the Device rather than reselling it.

Uninstalling the App does not delete your account data. Use the account deletion control in the App, or email us.


17. Children

PantryBee is not directed to children under 13, and we do not knowingly collect personal information from children under 13.

A parent or guardian may add a child's name or nickname to a Household. That information comes from the adult account holder, not from the child, and we do not use it for advertising, profiling, or any purpose beyond letting Household members recognize one another. We recommend using a nickname rather than a child's full name.

If we learn that a child under 13 has created an account, we will delete it. If you believe a child has provided us information, contact contact@pantrybee.buzz.

We do not knowingly process the personal information of anyone under 18 for targeted advertising, sale, or profiling. We do not engage in those activities at all.


18. Security

We protect your information with:

  • TLS encryption for all traffic between the App, the Device, and our servers, with strict certificate validation.
  • Per-device credentials. Every GroceryBee receives its own randomly generated authentication token. No secret is shared across devices, and no credential is embedded in the Firmware.
  • Encrypted provisioning. Wi-Fi credentials are encrypted in transit when you set up a Device.
  • Signed firmware updates, verified by the Device before installation.
  • Hashed storage of credentials and device tokens.
  • Access controls limiting which of our systems can reach your data.

No system is perfectly secure, and we do not claim otherwise.

Reporting a vulnerability. We welcome security research. See our Security Policy or email security@pantrybee.buzz.

Breach notification. If a breach affects your personal information, we will notify you and any required regulator as the law requires, describing what happened, what information was involved, and what we are doing about it.


19. Changes to this policy

We distinguish between changes that affect what we do with your information and changes that do not.

Administrative updates take effect when posted. These include corrections to contact details or addresses, typographical and formatting fixes, clarifications that do not change our practices, and substituting one service provider for another that performs a function already described in this policy, in the same category, receiving the same information. We will note the change in the version history below.

Material changes get 30 days' notice. A change is material if it introduces a new category of information we collect, a new purpose for using it, a new category of recipient, a new disclosure of your information, or any reduction in the rights described in § 15. We will notify you by email or in the App at least 30 days before the change takes effect, and where the law requires consent, we will ask for it rather than assume it.

We keep prior versions of this policy and will provide any of them on request.

Version history

Version Date Change
1.0 10 August 2026 Initial publication

20. Contact

PantryBee, LLC 9A RD 5821 Farmington, NM 87401 Email: contact@pantrybee.buzz


This document is a draft prepared for review by a licensed attorney. It has not been reviewed by counsel and is not legal advice.

← All legal documents
GroceryBee
The first product from PantryBee.
Contact
contact@pantrybee.buzz
Get notified →
Privacy Policy Terms of Service Terms of Sale & Limited Warranty Security Policy Open Source Attributions FCC Compliance All legal
© 2026 PantryBee, LLC · pantrybee.buzz · A PantryBee product