plenti

Privacy Policy

Last updated 15 August 2026

plenti ("we", "us", "our") uses AI to generate a tailored grocery shop for you, drawing on the meals you plan to cook, your household's regular products, and your own preferences. plenti is operated by Adam Stone, a sole trader trading as "plenti", of The Bristol Office, 2nd Floor, 5 High Street, Westbury-on-Trym, Bristol, BS9 3BY, England. This policy explains, plainly, what personal data plenti actually collects, why, who we share it with, and the choices and rights you have over it. plenti is aimed only at users in the United Kingdom. We don't offer plenti, or knowingly make it available, in the European Union.

If anything on this page doesn't match what plenti actually does, tell us at help@shopwithplenti.com. This is a small, honestly-run product and we'd rather fix this document than let it drift from reality.

1. Who we are

Adam Stone, trading as plenti, is the data controller for the personal data described in this policy. We're a small operation without a dedicated Data Protection Officer, so direct any privacy question or request to help@shopwithplenti.com and a real person will read and respond to it.

2. Information we collect

2.1 Account information

Your email address, collected via Supabase Auth's magic-link sign-in. You enter your email, we send a one-time sign-in link, and no password is ever set, sent, or stored.

2.2 Household members

The first names of the people you're planning meals for, plus the meals and ingredients each of them dislikes. You add these yourself, as the signed-in account holder. Household members don't register or provide this information themselves.

2.3 Your own food preferences

During onboarding, we ask you, the account holder, about your own cuisine preferences, your diet type (for example vegetarian, vegan, pescatarian, meat-and-veg, or meat-only), and any proteins you'd rather avoid. This is collected once, to tailor the meal suggestions you're shown, and is stored in our database only. Unlike household members' dislikes (section 2.2) and your planning notes (section 2.4), it is never sent to our AI provider (see section 4).

2.4 Planning notes

Free-text notes you type when creating a shop or meal plan (for example, "back from holiday Tuesday, keep it quick"). This is whatever you choose to write, and it can incidentally include things like another person's name or your schedule if you type it in, but we don't ask for or extract anything specific from it.

2.5 Sainsbury's connection (optional)

Connecting your Sainsbury's account is entirely optional. If you do, you sign in directly on Sainsbury's own page inside plenti. plenti never sees or stores your Sainsbury's password. What we store is the resulting session token, and it lives only in your device's own Keychain; it is never sent to plenti's servers or to any other third party. If, and only if, you connect your account, we also read and store your Sainsbury's order history (product names, prices paid, order dates) so it can inform future suggestions. If you use "send to basket," plenti uses that same session to add the items on your shopping list into your real, live Sainsbury's basket. Nothing is ever purchased without you completing checkout yourself, directly with Sainsbury's.

2.6 Subscription data

If you subscribe, Apple tells plenti your subscription status, which product you bought, and your renewal dates. plenti's own servers never receive or store your card details or any other payment information. That's handled entirely by Apple.

2.7 Basic operational and security logs

Like most backend systems, ours keeps a bounded number of recent technical event records for troubleshooting and security, not as a product feature. These records capture things like: whether a sign-in attempt or magic-link succeeded or failed; whether removing a household member succeeded or failed; whether a request for an AI meal or swap suggestion succeeded or failed, and roughly how long it took. They deliberately don't include the content of what you typed, a household member's actual name, the substance of anyone's dislikes, or anything an AI suggestion actually said back to you: just whether something worked, roughly how long it took, and a short error message if it didn't. The number of these records is capped per person, and older ones are automatically cleared out as new ones are added (see section 8). Sign-in-event records are the one exception: they share a single bounded cap across all users rather than a per-person one, since many of them, a failed magic-link for example, happen before we know who you are.

For the Sainsbury's connection specifically, we also keep a more detailed technical log of the sync and basket-send process (which cookies appeared or changed, order and product counts, timing, and which steps succeeded or failed) to diagnose connection problems. When diagnosing an issue with your session itself, this can include a short, non-identifying debug marker, but only in development builds; production builds (what real users run) never persist any part of a real session token. It never includes your name, address, postcode, or the content of any page you viewed.

2.8 Crash and diagnostic reports

plenti uses Google Firebase Crashlytics to find out when the app crashes or hits a serious error, so we can fix it. When that happens, it sends Google a report containing your device model, OS version, app version, and the technical stack trace of what the app was doing at the time. It does not include your email, household data, planning notes, or anything else described elsewhere in this section.

What we don't collect

There's no location tracking and no advertising SDK anywhere in plenti today. We don't send push notifications either, since that feature doesn't exist yet. plenti doesn't track how you use the app (which features you tap, how often, or anything like that) beyond the crash and diagnostic reporting described above. If we introduce in-app usage analytics in future, we'll update this policy first, and any such tool would still be held to the same principles as the rest of this document: we won't use it to sell your data or to serve you advertising. Separately, the marketing website (section 4) uses Google Analytics for basic visitor statistics; this is unrelated to and does not run inside the app itself.

3. How we use it

  • To create and run your account, and let you sign back in (your email).
  • To generate your tailored shopping list, including adding in products you buy regularly, and remembering your own food preferences and household members' dislikes so your meal planning can inform it (household data, planning notes).
  • To rank and suggest meal ideas, generate swap suggestions, and match the right ingredients and products to the meals you add, using AI (see section 4 for exactly what this sends to our AI provider).
  • To show your Sainsbury's order history and let you send items to your basket, only if you've connected your account.
  • To manage your subscription and unlock paid features.
  • To keep the service secure and working, and to investigate problems when something breaks.

We don't use your data for advertising, and we don't sell your personal data to anyone.

4. Who we share it with

plenti uses a small number of specialist providers to run the service. We don't sell your data, and each provider only receives what it needs to do its job:

ProviderWhat it doesWhat it receives
Anthropic (Claude API) Generates meal and swap suggestions, and matches ingredients to the meals you add Household members' first names paired with their dislikes, your free-text planning notes, and, when matching ingredients, the names and categories of products you've bought before (never prices, dates, or how often). Never your email, your own diet or cuisine preferences, or your Sainsbury's credentials/session.
Supabase Our database, authentication, and backend hosting Supabase is our database, so it stores essentially everything described in section 2, on an ongoing basis, not a one-off transmission. The one exception is your Sainsbury's session token, which stays in your device's Keychain and never reaches Supabase either.
Sainsbury's Reads your order history, and adds items to your basket when you send a list, using your own account Nothing of your plenti data, no email, household information, meal plans, or planning notes. Your own sign-in happens directly on Sainsbury's page, never through plenti. The one thing plenti does send to Sainsbury's is the product SKUs and quantities from your shopping list, and only when you choose to send items to your basket. Fully optional; disconnect any time.
Postcodes.io Free, public UK postcode lookup, used only to find your nearest Sainsbury's store when we can't already tell it from an active delivery or collection slot Your Sainsbury's account postcode, and only that, sent in a single anonymous request. If connected, only if this fallback is actually needed.
Apple Processes subscription purchases Your payment details, held by Apple alone. plenti receives back only status/entitlement data.
Resend Sends the sign-in magic-link email Your email address, for that single purpose.
Google (Firebase Crashlytics) Tells us when the app crashes, so we can fix it Device model, OS version, app version, and a technical stack trace when the app crashes or hits a serious error. Never your email, household data, or planning notes.
Google (Analytics) Basic traffic statistics for the plenti marketing website (the pages outside the app itself, like this one), so we can see how people find and use the site Standard web-analytics data: pages visited, referring site, approximate location (from IP), and device/browser type, via a cookie set in your browser. This runs on the marketing website only, never inside the app, and never includes your account, household, or planning data.

5. International transfers

Some of these providers (including Anthropic, Google, and Supabase depending on the service used) may process data outside the UK, including in the United States. Where that happens, we rely on the legal safeguards required for such a transfer (such as the UK's International Data Transfer Addendum to the EU Standard Contractual Clauses) being in place with that provider.

6. AI features and fair use

AI plays a central role in plenti: it ranks and suggests meal ideas, matches the right ingredients and products to the meals you add, and offers swaps. These are generated using a third-party AI model (see section 4). These features currently have no automatic limit on how much any one account can use them. We reserve the right to limit, throttle, delay, or temporarily suspend AI-powered features on any account, without notice, if usage is excessive or looks automated or abusive. This protects the service for everyone else.

AI-generated suggestions are just that: suggestions. Always check ingredients yourself, particularly if anyone you're planning for has an allergy or a medical dietary requirement. See also our Terms of Service.

7. Household members and children's data

plenti has no age-verification step anywhere, and no birthdate or age is recorded for the account holder, household members, or anyone else. Household members are added by the signed-in adult account holder, using only a first name and food preferences. No other identifying detail is collected, and they don't interact with plenti themselves. We don't treat this as sensitive data today because, functionally, it isn't: a first name and "doesn't like mushrooms" doesn't carry special-category status under UK GDPR.

If you're a parent or guardian adding your children as household members, you're doing so as the account holder, and you stay in control of that data: you can edit or remove it, or delete the whole account, from Settings at any time. plenti isn't directed at children and isn't designed to be used by children directly. The account holder is expected to be a capable adult.

8. Data retention

We keep your account data for as long as your account exists. Operational and security logs (section 2.7) are capped to a bounded number of recent records, with older ones automatically cleared out as new ones are added, not kept indefinitely. If you delete your account (section 9), your data is removed as described there.

9. Deleting your account

Settings → Account → "Delete my account" is a real, working feature. Type "delete my account" to confirm, and it permanently deletes your data across every part of our database, including shops, meal plans, household members and their preferences, planning notes, and your Sainsbury's connection, then deletes the account itself. This can't be undone.

One real constraint: if you have an active paid subscription running through Apple, deletion is blocked until you cancel it. This isn't us being precious about losing a customer: plenti has no technical ability to cancel an Apple subscription on your behalf, so deleting your account first would leave you still being charged with no account left to manage it from. Cancel your subscription in your Apple ID settings first, then come back and delete your account.

10. Your rights

As a UK resident, you have rights under UK GDPR, including the right to: access the personal data we hold about you; have inaccurate data corrected; have your data erased (the delete-account feature above covers this, or ask us directly); object to or restrict certain processing; and receive your data in a portable format. To exercise any of these, email help@shopwithplenti.com. If you're unhappy with how we've handled your data, you also have the right to complain to the UK's Information Commissioner's Office (ico.org.uk).

11. Security

We rely on Supabase's infrastructure and access controls, database-level rules that keep your data reachable only through your own account and no one else's, and your device's own Keychain for anything as sensitive as your Sainsbury's session. No method of storage or transmission is perfectly secure, and we can't guarantee absolute security, but we don't trade your data for convenience beyond what's described in this policy.

12. Changes to this policy

We'll update this page whenever what plenti actually does changes, and update the date at the top when we do. We won't quietly expand what we collect without saying so here first.

13. Contact

help@shopwithplenti.com, a real inbox read by a real person.