Amalthea Privacy Policy
Effective date: September 8, 2026
Amalthea is made by Zachary Morain, in Florida, United States. This page says what Amalthea collects, what we do with it, who else touches it, and how you delete it. It is short on purpose. If a sentence here is unclear, email us and we will fix the sentence.
What we collect
Your account. Your email address. If you sign in with a password, our sign-in provider stores a scrambled version of it. We never see the password itself. If you sign in with a magic link, there is no password. Every account gets an ID number that ties your data to you.
Your household. When you sign up you can name your household. It is optional. Many people use a family name here. Inside the household we store what you put in:
- Pantry items: name, category, quantity, unit, status, purchase date, expiry date, and whether you typed it in or it came from a receipt.
- Receipts you confirm: the store name, the purchase date, and the total.
- Saved prices: the item, its price, the quantity, the unit, the store, and the date you saw it. These come from your receipts.
- Your shelf-life settings.
- An activity history: what was added, changed, removed, or confirmed, and when.
Receipt photos. When you scan a receipt, the photo goes to our server and on to Google's Gemini API, which reads the text on it. We do not save the photo. It is not written to our database, to a file, or to any storage. The text comes back to you to review and edit before anything is saved. Google keeps what it receives for a limited period to check for abuse. More on that below.
What we do not collect. Your location. Your contacts. Photos other than the receipt you choose to scan. Advertising IDs. We run no outside analytics or tracking service in the app.
Logs. Two kinds exist. Our host keeps standard request logs, including the IP address your device connects from, for a short time. Our sign-in system keeps a security log of sign-in events in our database. That log records your email address, the IP address, and the browser you signed in from.
How we use it
- To run the app. Show your pantry, estimate how long food lasts, and remember what you paid.
- To see how the app is used. The activity history sits in our own database. We may look at counts from it, such as how many receipts get confirmed, to see which parts of the app people use. No outside service sees it.
- To keep the app safe. Rate limits on receipt scanning and the sign-in log.
We do not sell your data. We do not show ads. We do not use your data to train AI models, and under the terms we use, neither does Google.
Who else touches your data
Three companies run parts of Amalthea. Each one works under our instructions and its own privacy terms.
- Supabase stores the database and handles sign-in. Your data lives in its East US (North Virginia) data center. Supabase keeps its own service logs for one day.
- Vercel hosts the app and runs our server code, in the United States.
- Google's Gemini API reads receipt photos. We use it on Google's paid terms. Under those terms Google does not use your photo or the text it reads to improve Google's products. Google logs what it receives for a limited period, only to detect abuse.
Nobody else. We do not share your data with any other company. We would only hand data to someone else if the law required it.
Where your data is stored
In the United States. If you use Amalthea from outside the United States, your data still lives here.
How long we keep it
As long as your account exists. When you delete your account, your household pantry, receipts, saved prices, activity history, and the account itself are deleted right away. This cannot be undone.
Three things outlast deletion:
- Sign-in records in our security log, which hold your email address, sign-in IP address, and browser. They are cleared within 30 days of deletion.
- Our host's request logs, which clear on their own after a short time.
- Google's abuse-detection log of scanned receipts, which Google clears after its limited period.
Your choices
Delete your account. Open Settings in the app, find Delete account, type DELETE, and tap the Delete account button. You can also read the steps at https://www.amalthea.app/delete-account without signing in. If you cannot sign in, email us from the address on the account and we will delete it by hand within a few days.
Ask what we hold. Email us and we will tell you what is stored under your account.
Fix or remove something. Pantry items can be edited or removed in the app. Receipts and saved prices have no delete button yet. They go when your account goes. If you want one removed sooner, email us and we will remove it by hand.
Sign out. Settings, then Sign out.
Children
Amalthea is for adults. You must be 18 or older to create an account, and the app is not directed to children. We do not knowingly collect data from anyone under 13. If you believe a child has created an account, email us and we will delete it.
Security
Every connection to Amalthea is encrypted in transit. In the database, each household's data is walled off from every other household, and that wall is enforced by the database itself, not just by the app. Passwords are scrambled by our sign-in provider. The key that lets our server talk to Google never reaches your device.
Changes to this policy
When we change what we collect, who touches it, or how sign-in works, we update this page and change the effective date at the top. If a change is significant, we also email the address on your account before it takes effect.
Contact
Zachary Morain