The short version: a subscription, and a pantry only if you opt in. Never your diary.
Shared
| Thing | When |
|---|---|
| Premium entitlement | Whenever the organizer holds their own active subscription |
| Shared pantry items and quantities | Only while you have turned participation on |
| Your name beside items you added | Only while you have turned participation on |
Never shared
Food and meal logs. Food photos. Body weight. Water intake. Vital signs. Body measurements. Physical activity. Supplements. Menstrual cycle data. Health goals and targets. Progress photos. Your allergen guard. Your never-eat list. Your personal pantry.
None of it. In either direction. Including with the organizer.
How we make that true rather than just saying it
The rule is enforced on our servers, at the API layer. No family group endpoint reads any health table, and we have an automated test that fails our build if one ever does. It holds for features we add later, not just the ones that exist today.
Why the pantry is treated carefully anyway
A cupboard is not a health record. But a pantry full of only gluten-free products says something, and our meal planner reads the pantry to plan around your allergens. So we treat shared pantry contents as consumer health data: opt-in before anything is shared, consent you can withdraw instantly, no sale, no advertising, and deletion with your account.
The short version: a **subscription**, and a **pantry** only if you opt in. Never your diary. ## Shared | Thing | When | |---|---| | Premium entitlement | Whenever the organizer holds their own active subscription | | Shared pantry items and quantities | Only while you have turned participation on | | Your name beside items you added | Only while you have turned participation on | ## Never shared Food and meal logs. Food photos. Body weight. Water intake. Vital signs. Body measurements. Physical activity. Supplements. Menstrual cycle data. Health goals and targets. Progress photos. Your allergen guard. Your never-eat list. Your personal pantry. None of it. In either direction. Including with the organizer. ## How we make that true rather than just saying it The rule is enforced on our servers, at the API layer. No family group endpoint reads any health table, and we have an automated test that fails our build if one ever does. It holds for features we add later, not just the ones that exist today. ## Why the pantry is treated carefully anyway A cupboard is not a health record. But a pantry full of only gluten-free products says something, and our meal planner reads the pantry to plan around your allergens. So we treat shared pantry contents as consumer health data: opt-in before anything is shared, consent you can withdraw instantly, no sale, no advertising, and deletion with your account.