Legal · CookingSocial LLC

Privacy Policy

Effective Date: April 6, 2026 Last Updated: April 6, 2026 Contact: legal@pantoh.app
01

Our Privacy Commitments

🚫
We don't sell your data
We do not sell your personal information. Ever.
👤
Open Door is truly anonymous
No sign-in means no personal data and no persistent identifier.
📱
AI conversations stay on your device
We do not store your Pantoh AI chat history on our servers.
🔒
Field reports are permanently anonymous
No link between a field report and its author is ever stored.
🛡
Sensitive access is protected
DV, immigration, mental health resources get stricter protections.
📵
No advertising
We do not use personal information for advertising.
02

Information We Collect

2a. End Users — Signed-In Accounts

When you create an account using Google Sign-In or Apple Sign-In, we receive your name, email address, profile photo (if provided), and a unique identifier to maintain your session. We do not offer email/password accounts.

In-app activity we collect: volunteer sign-ups, shifts, check-ins, and hours; badges earned; resource saves; daily intent entries; event RSVPs.

Location: We use your ZIP code to surface local resources. We do not collect precise GPS location unless you explicitly grant permission for map features.

2b. End Users — Open Door Mode

Without signing in, we do not collect your name, email, or any personally identifiable information, and we do not create a persistent identifier tied to your device.

2c. Sensitivity-Tier Resources

Resources related to domestic violence, immigration status, mental health, and substance use are classified under Sensitivity Tier 2 or Tier 3. We do not send push notification previews that could expose sensitive resource use, suppress prompts and upsell that could associate a person with a sensitive resource, and do not store resource identifiers in our anonymous signal database.

2d. Field Reports

Field reports are permanently anonymous. We generate a one-way hash for deduplication only — it cannot be reversed to identify you. We cannot link a field report to your identity even in response to a legal request, because the data architecture does not retain it.

2e. Partner Organizations

When your organization onboards, we collect your organization name, address, contact information, billing details for paid subscription tiers (handled by Stripe), and content you post including listings, events, bulletins, volunteer postings, and impact stories.

03

How We Use Your Information

PurposeInformation UsedLegal Basis
Authenticate your accountSign-in provider ID, emailContract
Surface relevant resourcesZIP code, resource savesLegitimate interest
Manage volunteer activityShifts, hours, check-insContract
Process partner subscription paymentsBilling details (via Stripe)Contract
Send transactional notificationsEmail, preferencesContract / Consent
Improve the platformAggregate, de-identified dataLegitimate interest
Safety and abuse preventionAccount identifiers, activity flagsLegitimate interest

We do not use your information for targeted advertising and do not build behavioral profiles for sale or transfer to data brokers.

For partner organizations, we use information to operate your profile and listings, process volunteer management and reporting, bill paid subscription tiers via Stripe, send transactional communications, issue certifications, provide analytics, and enforce platform policies.

04

AI Features and Pantoh AI

Pantoh Commons includes an AI assistant called Pantoh AI, powered by Anthropic's Claude.

Conversation history is stored on your device only. We do not store your conversations on our servers. Pantoh AI uses only session context — your ZIP code and the resource you're viewing — not your full account history.

Pantoh AI includes references to crisis resources including DV hotlines, mental health support, and SAMHSA. This is a safety requirement, not optional behavior.

We do not use AI or machine translation for SNAP/WIC legal advisory language, crisis references, or immigration safety notices. These are always translated by qualified human translators.

05

Information We Share

We do not sell your personal information. We share information only with the following parties:

ProviderPurpose
StripePayment processing for partner subscription billing
Firebase (Google)Authentication and infrastructure
PostmarkTransactional email delivery
AnthropicAI features (session context only; no conversation history retained)
GoogleMaps and location features (Powered by Google where applicable)

These vendors are contractually prohibited from using your information for their own purposes. If you volunteer with a partner organization, we share your name, contact information, and volunteer hours with that organization. We may disclose information as required by law; however, field reports are permanently anonymous and AI conversations are device-only, so we cannot produce this data even in response to legal requests.

06

Data Retention

Data TypeRetention Period
Account informationUntil account deletion request
Volunteer recordsUntil account deletion; partner copy per their legal obligations
Partner billing records7 years (financial record-keeping)
Aggregate analyticsPer the retention window of the partner's subscription tier
Field reportsNo personal data (permanently anonymous)
AI conversation historyNot on our servers — device only
Open Door session dataNo personal data retained

When you delete your account, we delete your personal information within 30 days, except where retention is required by law.

07

Sensitive Information

We treat the following categories with heightened protection: domestic violence or safety situations, immigration status, mental health or substance use, sexual orientation or gender identity, and information about minors. These protections are enforced at the system level and cannot be disabled by administrators or users.

08

Children's Privacy

Pantoh Commons is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us with personal information, contact legal@pantoh.app and we will delete it promptly. Users between 13 and 18 should use the platform only with parental or guardian involvement.

09

Security

We implement TLS encryption in transit, encryption at rest, a physically separate database instance for sensitive signal data with separate encryption keys and no cross-application join keys, need-to-know access controls, and regular security testing. If you believe your account has been compromised, contact legal@pantoh.app immediately.

10

Your Choices and Rights

You may access and correct your account information in-app at any time, manage notification preferences in settings, and use Open Door mode without an account. To request account deletion, contact legal@pantoh.app.

California Residents (CCPA): You have the right to know what personal information we collect, the right to delete it, the right to opt out of sale (we do not sell personal information), and the right to non-discrimination for exercising your rights.

Other State Privacy Laws: Residents of Virginia, Colorado, Connecticut, Texas, and other states with comprehensive privacy laws may have similar rights. We respond to verified requests within 45 days.

11

Third-Party Links and Services

This Privacy Policy does not apply to third-party sites. Data sources including OpenStreetMap, USDA FoodData Central, and Google Places are subject to their own terms. Attribution is displayed within the app.

12

Changes to This Policy

We may update this Privacy Policy from time to time. We will update the "Last Updated" date and notify you through the app or by email for material changes. Continued use after the effective date constitutes acceptance.

13

Contact Us

CookingSocial LLC
legal@pantoh.app
Terms of Service: commons.pantoh.app/tos