Privacy Policy
Last updated: 2026-10-08
This policy explains what the Hello Pantry Telegram bot
(@hello_pantry_bot) and its Mini App do with data.
The short version: there is no account and no password, because Telegram already knows who you are. What you write down is stored on one server so that it can be shown back to you, and it is used for nothing else. There is no analytics, no advertising, no profiling and no third party with a copy.
Who is responsible
Gabriele Proietti Mattia (https://gpm.name), reachable at apps@gpm.name, is the data controller. The server is in Germany.
What is stored
Everything below is stored because the bot cannot do its job without it, and nothing is stored that it can do its job without.
- Who you are on TelegramYour Telegram numeric id, first and last name, username and language code. The id is what ties your pantry to you; the name is what the bot greets you by, and what the other members of a shared pantry see; the language sets which of the two translations you read.
- What you keep in your pantryPantries, their storage places, and the products in them: name, brand, barcode, size, picture, category, amounts, expiry dates, the day something was frozen, the warning settings, and the shopping list. For a shared pantry, who the members are, their role, and who added or used up what.
- Your notification settingsWhich pantries and which people you have muted, whether you get a digest, and when the last expiry warning for each product was sent, so that it is not sent twice.
- Where you are in the conversationThe screen you are on and the message the bot last sent you, so a button pressed tomorrow still knows what it refers to.
- Whether you are a subscriberWhether Pro is active and until when, whether it renews, and the payment identifier Telegram gives the bot so that a refund is possible.
- Your email, if you give oneOptional. See below.
- Reports you sendThe text of a bug report or an idea, and a screenshot if you attach one. See below.
What is never stored
- No payment details. Pro is paid in Telegram Stars. Telegram tells the bot that a payment happened and gives it an identifier for it; a card number, a name on a card or a billing address never reach the bot, because Telegram never sends them.
- No location. The bot never asks for it and has nowhere to put it.
- No contacts, and no files.
- No pictures kept. A photo of a barcode that you send to the bot is read for the number on it and is not stored. The live camera scan in the Mini App and the web app happens on your device and no video or picture leaves it.
- No analytics and no advertising identifiers. There is no third-party SDK anywhere in this bot: nothing measures how you use it and nothing reports on it.
- No message history. The bot reads a message to act on it and keeps what that message was about — a product, an amount — not the message.
Open Food Facts
When you scan or type a barcode, the number may be looked up on Open Food Facts, a free, open database of food products. Only the barcode is sent: nothing that says who you are, which pantry it is for, or what else is in it. What comes back (name, brand, size, picture) is shown to you to confirm. Open Food Facts handles that request under its own privacy policy, not this one.
Email, licences and reports: apps-management
An email address is optional. The bot works, and Pro can be bought, without one.
If you choose to link one (you confirm it with a code sent to it), it is used with apps-management, the service that handles licences and feedback for the apps in this family. It is used for three things only: your licence, so that Pro can follow you to a new Telegram account (it is valid for one Telegram account at a time); the replies to the reports you send; and the votes you cast on the features still to be built. apps-management knows people only by a verified email and does not receive your Telegram id.
Two other things are recorded there whether or not you link an email:
- Pro purchases. A purchase made with Telegram Stars is recorded in apps-management under the Telegram payment identifier, which is how a licence is checked and a refund traced. No card or billing details are involved, because there are none.
- Bug reports and ideas. What you send from the information section of the bot or of the app is forwarded to apps-management, together with the version you were using and the email, if you have linked one. A report without a linked email is anonymous.
Telegram’s part
You are talking to this bot through Telegram, and Telegram carries what you send. What Telegram does with that is covered by Telegram’s own privacy policy, not by this one.
Two consequences worth stating plainly:
- Telegram knows you use this bot, and when.
- A Telegram chat with a bot is not end-to-end encrypted. Telegram can read it, the same way it can read any cloud chat.
Shared pantries
In a shared pantry the other members see its contents, your Telegram name, and who added or used up each thing. They are also sent a notification when you do, unless they have muted it. Only an owner can invite or remove people. Leaving a pantry, or being removed, ends your access to it.
The Mini App and the web app
The Mini App is a page served from https://hello-pantry-tg.gpm.name. It stores one thing in your
browser: a note that you have seen the welcome screen. That note never leaves the device
and is not readable by anyone else.
Inside Telegram, every request the Mini App makes carries the session Telegram signs for it, which is what proves the request is yours.
The web app at https://hello-pantry-app.gpm.name is the same page, opened in a browser, with a sign in
of its own: a link sent to your email, Google, or the Telegram login button. It needs the
same data, and keeps a session cookie in the browser so that you stay signed in until you
sign out. Signing in with an email or with Google stores that address, or the Google
account identifier, to recognise you the next time.
The page loads its fonts from Google Fonts, which means Google sees the request for those files. Nothing about you is sent with it beyond what any browser sends when it fetches a file.
Retention
What you keep in your pantry is kept until you delete it.
Settings → Delete all data, inside the bot, deletes your pantries, products and shopping lists permanently and immediately. It is not a request that gets processed: the rows are gone when the confirmation comes back. Your profile and the conversation itself survive, so the bot still works afterwards; deleting those too is a request to the address above.
Backups of the server exist for disaster recovery and are retained for a limited period. Data deleted from the live database is not restored from them.
Legal basis (GDPR)
- Performance of a contract for everything you write down: a pantry tracker that does not keep your pantry is not the thing you asked for.
- Legitimate interest for the operational logs the server keeps to stay working and to investigate abuse.
- Legal obligation for the records a payment leaves behind.
Your rights
You may ask for a copy of your data, its correction, or its deletion, and you may object to its processing. One of those needs nobody’s help: Settings → Delete all data is the deletion. For anything else, write to apps@gpm.name.
You also have the right to complain to a supervisory authority.
Children
Hello Pantry is not directed at children and asks for nothing that would identify one.
Changes
This page carries the date it was last substantively changed. A change that affects what is collected will be said in the changelog as well, rather than only here.