Privacy Policy
Last updated: July 26, 2026
Butler is a family kitchen assistant. We collect what we need to plan meals with you and keep your household's data safe. This page explains what that means in plain terms.
Who we are
Butler is operated by LoRoCo LLC, a Washington limited liability company based in Seattle, Washington, USA. LoRoCo LLC is the data controller for the information described on this page. You can reach us at [email protected], and we'll provide a postal address on request. By using Butler you agree to the practices below.
If you are in Washington State, please also read our separate Consumer Health Data Privacy Policy, which covers health-related information under the Washington My Health My Data Act.
What we collect
- Account info — your name and email from Sign in with Apple or Sign in with Google, plus an optional display name and profile picture you set yourself.
- Household data you create — family members (including names, ages, dietary preferences and dietary restrictions), recipes, meal plans, pantry items, grocery lists, cooked-meal logs, and meal ratings.
- Photos you take — pantry, fridge, receipt, and cooked-meal photos uploaded inside the app.
- Chat messages — what you send to Butler and what Butler replies. Used to provide the service.
- Optional Gmail data — only if you connect Gmail: we read order-confirmation emails from Whole Foods, Amazon Fresh, and Instacart to import items into your pantry. We never read other email and we don't store the message bodies after parsing.
- Optional calendar data — only if you connect Google Calendar: we read upcoming events to flag busy nights when planning meals.
- Optional connected-service data — only if you connect them: Kroger (store and product lookup), Instacart (sending a grocery list to order), and CellarTracker (your wine cellar inventory).
- Device tokens — an Apple push notification token, so we can send expiry alerts and prep reminders.
- Diagnostics — error reports and feedback you submit, plus app and server version metadata.
Health-related information
Some of what you enter can reveal health information. Food allergies, intolerances, and medically motivated dietary restrictions live in your family members' profiles, and you may describe a health reason in chat when you tell Butler why someone avoids a food. We treat this category of information with extra care and describe it in full in our separate Consumer Health Data Privacy Policy.
You are never required to give a reason for a dietary restriction. Butler works fine if you simply record that someone doesn't eat something.
What we don't collect
- We don't track you across other apps or websites.
- We don't sell or share your data for advertising, under any definition of "sell" or "share" in California, Washington, or elsewhere.
- We don't show ads.
- We don't read Gmail messages outside the order-confirmation senders you opt into.
- We don't use your household data, chat messages, or photos to train AI models, and our AI providers are contractually prohibited from doing so with data sent through their APIs.
- We don't collect precise location, contacts, health-app data, or biometric identifiers.
Why we use it
We use the information above to run the service you asked for: to plan meals, track your pantry, build grocery lists, send the reminders you turned on, answer you in chat, keep accounts secure, and fix bugs. If you are in the EU or UK, our legal bases are performance of a contract (running the app for you), your consent (optional connections like Gmail, Calendar, and health-related details), and our legitimate interests (security, abuse prevention, and diagnostics).
Who processes your data
Butler relies on a small set of providers to run the service:
- Anthropic — powers the AI chat. Messages and the relevant household context are sent to Anthropic's API to generate responses.
- Google (Gemini) — used only for image analysis when you scan a pantry, fridge, or receipt photo.
- Supabase — hosts our PostgreSQL database and image storage.
- Railway — runs the Butler backend.
- Apple — handles push notifications and Sign in with Apple.
- Google — handles Sign in with Google, Gmail, and Calendar OAuth (only if you connect those).
- Resend — sends transactional email such as account and support messages.
- Kroger, Instacart, and CellarTracker — only if you connect them, and only for the specific feature you connected them for.
These providers act as our processors: they may only use the data to provide their service to us. We don't give any of them permission to use your data for their own purposes.
Google user data — Limited Use
When you connect Gmail or Google Calendar, Butler receives data from Google APIs under the scopes you grant during sign-in. Butler's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Concretely:
- Gmail message data is read only to find order-confirmation emails from Whole Foods, Amazon Fresh, and Instacart, and to extract the line items from those receipts.
- Calendar event data is read only to detect busy nights when planning your week's meals.
- We do not use Google user data for advertising, do not sell or transfer it, do not use it to train generalized AI models, and do not let humans read it except (a) with your explicit consent, (b) for security or abuse investigations, or (c) where required by law.
- You can disconnect Gmail or Calendar at any time from Settings inside the app, or revoke access at myaccount.google.com/permissions.
Security
Butler talks to its servers over HTTPS only. Data at rest in Supabase is encrypted with AES-256. OAuth tokens for Gmail, Calendar, and other connected services are stored encrypted and scoped to your household. Access to production data is limited to the maintainer(s) and used only to operate the service or investigate reported issues. No system is perfectly secure, and we can't guarantee absolute security.
How long we keep it
Your household data is kept as long as your account is active. Diagnostic logs (error reports, feedback) are retained for up to 90 days unless we need them longer to fix a reported bug. Deleted accounts and their associated data are removed from active databases immediately and from backups within 30 days.
Where your data is processed
Butler is operated from the United States. Our database (Supabase) and backend host (Railway) run in U.S. regions. If you use Butler from outside the U.S., your data is transferred to and processed in the U.S. by us and our sub-processors listed above. For transfers out of the EU or UK, we rely on the European Commission's Standard Contractual Clauses as incorporated into our providers' data processing terms.
Your rights
You can access, correct, export, or delete your household data at any time:
- Access & correct — view and edit family members, recipes, pantry items, meal plans, and grocery lists directly inside the app.
- Delete — Settings → Account → Delete account removes everything (see below).
- Export — email [email protected] from your account email and we'll send a JSON dump of your household data within 30 days.
- Withdraw consent — disconnect Gmail, Calendar, or any connected service from Settings at any time. Withdrawing consent doesn't affect processing we already did while consent was in place.
- Object or restrict — if you're in the EU or UK, you have the right to object to processing, request restriction, and lodge a complaint with your local data protection authority.
California residents. Under the CCPA as amended, you have the right to know what personal information we collect and why, to delete it, to correct it, and to not be discriminated against for exercising those rights. We do not sell or share personal information, and we do not use or disclose sensitive personal information for purposes other than providing the service you requested — so there is nothing to opt out of. You can exercise any of these rights through the app or by emailing us, and you may use an authorized agent.
Washington residents. Rights specific to consumer health data — including the right to withdraw consent and to have that data deleted — are described in our Consumer Health Data Privacy Policy.
We'll respond to any request within 45 days, and will tell you if we need a further 45 days. We don't charge for this. If we deny a request, you can appeal by replying to our response; we'll answer the appeal within 45 days and, if we still deny it, tell you how to complain to your state attorney general.
Deleting your account
You can delete your account from inside the app under Settings → Account → Delete account. This permanently removes your household, family members, recipes, pantry items, meal plans, grocery lists, cooked-meal logs, photos, chat history, and connected service tokens. Deletion is irreversible.
If you can't access the app, email [email protected] from your account email and we'll do it for you within 7 days.
Children
Butler is a general-audience app designed for adults running a household. It is not directed to children, and we don't knowingly let anyone under 13 create an account.
A parent or guardian may enter a child's first name, age, and food preferences into their household's family profiles so that meal planning accounts for the whole family. That information is provided by the parent, is visible only to members of that household, is never sold or shared, and is deleted when the parent deletes the family member or the account. Butler does not let children sign in, does not collect information directly from children, and does not use children's information for advertising or profiling. A parent can review or delete anything they entered about a child at any time in the app, or by emailing [email protected]. If we learn that a child under 13 has created an account, we'll delete it.
Changes
If we materially change how we handle your data, we'll update this page and notify account holders by email or in-app message before the change takes effect.
Contact
Questions or requests: [email protected].
LoRoCo LLC, Seattle, Washington, USA.