Last updated 15 August 2026
plenti ("we", "us", "our") uses AI to generate a tailored grocery shop for you, drawing on the meals you plan to cook, your household's regular products, and your own preferences. plenti is operated by Adam Stone, a sole trader trading as "plenti", of The Bristol Office, 2nd Floor, 5 High Street, Westbury-on-Trym, Bristol, BS9 3BY, England. This policy explains, plainly, what personal data plenti actually collects, why, who we share it with, and the choices and rights you have over it. plenti is aimed only at users in the United Kingdom. We don't offer plenti, or knowingly make it available, in the European Union.
If anything on this page doesn't match what plenti actually does, tell us at help@shopwithplenti.com. This is a small, honestly-run product and we'd rather fix this document than let it drift from reality.
On this page
Adam Stone, trading as plenti, is the data controller for the personal data described in this policy. We're a small operation without a dedicated Data Protection Officer, so direct any privacy question or request to help@shopwithplenti.com and a real person will read and respond to it.
Your email address, collected via Supabase Auth's magic-link sign-in. You enter your email, we send a one-time sign-in link, and no password is ever set, sent, or stored.
The first names of the people you're planning meals for, plus the meals and ingredients each of them dislikes. You add these yourself, as the signed-in account holder. Household members don't register or provide this information themselves.
During onboarding, we ask you, the account holder, about your own cuisine preferences, your diet type (for example vegetarian, vegan, pescatarian, meat-and-veg, or meat-only), and any proteins you'd rather avoid. This is collected once, to tailor the meal suggestions you're shown, and is stored in our database only. Unlike household members' dislikes (section 2.2) and your planning notes (section 2.4), it is never sent to our AI provider (see section 4).
Free-text notes you type when creating a shop or meal plan (for example, "back from holiday Tuesday, keep it quick"). This is whatever you choose to write, and it can incidentally include things like another person's name or your schedule if you type it in, but we don't ask for or extract anything specific from it.
Connecting your Sainsbury's account is entirely optional. If you do, you sign in directly on Sainsbury's own page inside plenti. plenti never sees or stores your Sainsbury's password. What we store is the resulting session token, and it lives only in your device's own Keychain; it is never sent to plenti's servers or to any other third party. If, and only if, you connect your account, we also read and store your Sainsbury's order history (product names, prices paid, order dates) so it can inform future suggestions. If you use "send to basket," plenti uses that same session to add the items on your shopping list into your real, live Sainsbury's basket. Nothing is ever purchased without you completing checkout yourself, directly with Sainsbury's.
If you subscribe, Apple tells plenti your subscription status, which product you bought, and your renewal dates. plenti's own servers never receive or store your card details or any other payment information. That's handled entirely by Apple.
Like most backend systems, ours keeps a bounded number of recent technical event records for troubleshooting and security, not as a product feature. These records capture things like: whether a sign-in attempt or magic-link succeeded or failed; whether removing a household member succeeded or failed; whether a request for an AI meal or swap suggestion succeeded or failed, and roughly how long it took. They deliberately don't include the content of what you typed, a household member's actual name, the substance of anyone's dislikes, or anything an AI suggestion actually said back to you: just whether something worked, roughly how long it took, and a short error message if it didn't. The number of these records is capped per person, and older ones are automatically cleared out as new ones are added (see section 8). Sign-in-event records are the one exception: they share a single bounded cap across all users rather than a per-person one, since many of them, a failed magic-link for example, happen before we know who you are.
For the Sainsbury's connection specifically, we also keep a more detailed technical log of the sync and basket-send process (which cookies appeared or changed, order and product counts, timing, and which steps succeeded or failed) to diagnose connection problems. When diagnosing an issue with your session itself, this can include a short, non-identifying debug marker, but only in development builds; production builds (what real users run) never persist any part of a real session token. It never includes your name, address, postcode, or the content of any page you viewed.
plenti uses Google Firebase Crashlytics to find out when the app crashes or hits a serious error, so we can fix it. When that happens, it sends Google a report containing your device model, OS version, app version, and the technical stack trace of what the app was doing at the time. It does not include your email, household data, planning notes, or anything else described elsewhere in this section.
There's no location tracking and no advertising SDK anywhere in plenti today. We don't send push notifications either, since that feature doesn't exist yet. plenti doesn't track how you use the app (which features you tap, how often, or anything like that) beyond the crash and diagnostic reporting described above. If we introduce in-app usage analytics in future, we'll update this policy first, and any such tool would still be held to the same principles as the rest of this document: we won't use it to sell your data or to serve you advertising. Separately, the marketing website (section 4) uses Google Analytics for basic visitor statistics; this is unrelated to and does not run inside the app itself.
We don't use your data for advertising, and we don't sell your personal data to anyone.
Some of these providers (including Anthropic, Google, and Supabase depending on the service used) may process data outside the UK, including in the United States. Where that happens, we rely on the legal safeguards required for such a transfer (such as the UK's International Data Transfer Addendum to the EU Standard Contractual Clauses) being in place with that provider.
AI plays a central role in plenti: it ranks and suggests meal ideas, matches the right ingredients and products to the meals you add, and offers swaps. These are generated using a third-party AI model (see section 4). These features currently have no automatic limit on how much any one account can use them. We reserve the right to limit, throttle, delay, or temporarily suspend AI-powered features on any account, without notice, if usage is excessive or looks automated or abusive. This protects the service for everyone else.
AI-generated suggestions are just that: suggestions. Always check ingredients yourself, particularly if anyone you're planning for has an allergy or a medical dietary requirement. See also our Terms of Service.
plenti has no age-verification step anywhere, and no birthdate or age is recorded for the account holder, household members, or anyone else. Household members are added by the signed-in adult account holder, using only a first name and food preferences. No other identifying detail is collected, and they don't interact with plenti themselves. We don't treat this as sensitive data today because, functionally, it isn't: a first name and "doesn't like mushrooms" doesn't carry special-category status under UK GDPR.
If you're a parent or guardian adding your children as household members, you're doing so as the account holder, and you stay in control of that data: you can edit or remove it, or delete the whole account, from Settings at any time. plenti isn't directed at children and isn't designed to be used by children directly. The account holder is expected to be a capable adult.
We keep your account data for as long as your account exists. Operational and security logs (section 2.7) are capped to a bounded number of recent records, with older ones automatically cleared out as new ones are added, not kept indefinitely. If you delete your account (section 9), your data is removed as described there.
Settings → Account → "Delete my account" is a real, working feature. Type "delete my account" to confirm, and it permanently deletes your data across every part of our database, including shops, meal plans, household members and their preferences, planning notes, and your Sainsbury's connection, then deletes the account itself. This can't be undone.
One real constraint: if you have an active paid subscription running through Apple, deletion is blocked until you cancel it. This isn't us being precious about losing a customer: plenti has no technical ability to cancel an Apple subscription on your behalf, so deleting your account first would leave you still being charged with no account left to manage it from. Cancel your subscription in your Apple ID settings first, then come back and delete your account.
As a UK resident, you have rights under UK GDPR, including the right to: access the personal data we hold about you; have inaccurate data corrected; have your data erased (the delete-account feature above covers this, or ask us directly); object to or restrict certain processing; and receive your data in a portable format. To exercise any of these, email help@shopwithplenti.com. If you're unhappy with how we've handled your data, you also have the right to complain to the UK's Information Commissioner's Office (ico.org.uk).
We rely on Supabase's infrastructure and access controls, database-level rules that keep your data reachable only through your own account and no one else's, and your device's own Keychain for anything as sensitive as your Sainsbury's session. No method of storage or transmission is perfectly secure, and we can't guarantee absolute security, but we don't trade your data for convenience beyond what's described in this policy.
We'll update this page whenever what plenti actually does changes, and update the date at the top when we do. We won't quietly expand what we collect without saying so here first.
help@shopwithplenti.com, a real inbox read by a real person.