Privacy
Last updated 27 June 2026
EatFirst is a small household food-inventory app. We collect only what we need to run it, we don't sell your data, and there are no ads, analytics, or trackers.
Who we are
EatFirst (“we”, “us”) is operated by an individual based in the United Kingdom. For any privacy question or request, email hello@eatfirst.app. For UK data-protection purposes, we are the controller of the personal data described here.
What we collect
- Your account: your email address. We don't use passwords; you sign in with a one-time link sent to your inbox.
- Your fridge data: the items you add (name, expiry/best-before date, barcode if scanned, location, quantity, whether it's opened) and your shopping list.
- Household info: the household(s) you create or join, and who is a member, so a shared fridge stays in sync.
- Optional extras you switch on: a push-notification subscription (if you enable alerts), a fridge-display token (if you connect a TRMNL panel), and connected-app tokens (if you link another app such as CookNext).
- Technical data: a single sign-in session cookie, and your IP address used only briefly to rate-limit sign-in attempts and prevent abuse.
How we use it
- To run the app: store your inventory, sort it by what to eat first, and keep households in sync.
- To sign you in (the one-time email link).
- To send the optional daily “eat first” email digest and optional push alerts, only if you turn them on.
- To keep the service secure and prevent abuse.
Our legal bases (UK GDPR)
- Performance of a contract: to provide the app you signed up for.
- Consent: for the optional email digest and push notifications (you can withdraw at any time).
- Legitimate interests: to keep the service secure and prevent abuse.
Who we share it with
We do not sell your data and we do not share it for advertising. We use a small number of service providers to run the app:
- Open Food Facts: when you scan a barcode, only that barcode is sent to Open Food Facts to look up the product name and image. None of your account or fridge data is sent.
- Hosting & email: our hosting provider (DreamHost) stores the app and its database and delivers our emails on our behalf.
We may also disclose data if required by law.
Where your data is stored
EatFirst is hosted by DreamHost, whose servers are in the United States, so your data is stored and processed outside the UK. When personal data is transferred internationally, we take steps to keep it protected to UK standards.
Cookies
We use one essential cookie to keep you signed in. We don't use tracking, advertising, or analytics cookies, so there's no cookie banner to click through.
How long we keep it
We keep your account and fridge data for as long as your account exists. When you delete your account, your data is removed (see Your data). Short-lived items such as sign-in links, sessions, and rate-limit records are pruned automatically.
How we protect it
Sign-in is passwordless. Sign-in links and connected-app tokens are stored only as hashes, sensitive secrets are encrypted at rest, and the site is served over HTTPS with a strict content-security policy. Every request is scoped to your household so people only see their own data.
Your rights
You can access and correct your data in the app, change your email, and delete your account and all its data yourself (Settings → Account). You also have the right to object to or restrict certain processing, and to ask for a copy of your data, just email hello@eatfirst.app. If you're in the UK and think we've mishandled your data, you can complain to the Information Commissioner's Office (ico.org.uk).
Children
EatFirst isn't directed at children under 13, and we don't knowingly collect their data.
Changes
If we change this policy we'll update the date above and, for significant changes, let you know in the app or by email.
Contact
Questions or requests: hello@eatfirst.app.