Privacy
Spoon & Ledger is one app for feeding a household. This page says what it keeps, where, and what leaves the server. It is short because the app does little with your data beyond showing it back to you.
One copy is one household
Each copy of the app has its own database and its own password, run by whoever set it up: for the public demo, the app’s author; for a copy of your own, you or the person who made it for you. Everyone who knows a copy’s password sees and edits the same plan, pantry, recipes and log. The demo is a sample household anyone can use, and it is reset from time to time.
What is stored
Everything you put in: meal plans, recipes, the pantry, shopping trips and receipts, the food log, people’s names and serving sizes, and any body figures or targets you choose to enter. It lives in that copy’s database and nowhere else. Nothing is analysed for any purpose other than showing it back to you.
Signing in sets a cookie that lasts thirty days. It holds a signed token, not the password. A second cookie remembers which person a device belongs to, so the food log knows who ate. Your browser also keeps a few small conveniences of its own, such as whether you have seen the welcome card and notes made in cooking mode; these never reach the server.
The beta sign-up
The beta form asks for a name, an email address, who you cook for, and what you want from the app. That is used to get in touch about testing and for nothing else. It is never shown inside the app, never passed to anyone, and is deleted when you ask through the same form.
What leaves the server
The app talks to a few outside services, each for one job and each sent only what that job needs:
- Wikipedia, for ingredient pictures. Only the ingredient’s name is sent.
- USDA FoodData Central, for nutrition lookups. Only the search term is sent, and only if the copy’s owner has set up a key.
- Open Food Facts, for packaged foods. Only the barcode is sent.
- Instacart, to hand a shopping list to a cart. Only the list’s lines are sent, and only if the copy’s owner has set up a key. Signing in to Instacart to read order history happens in a browser on the owner’s own machine; the app never sees the password.
- The address you paste when importing a recipe, which the server fetches once.
- The owner’s own mailbox, if they have set it up, read on demand for grocery receipts. The mailbox’s app password stays on the server that runs the copy.
Pictures of recipes and products load from wherever they came from, so those sites see your device’s address when a picture loads, as they would for any web page.
What is not done
No analytics, no advertising, no trackers, no selling or sharing of anything. The phone app is a shell around this site with no third-party code in it; the one thing it keeps on the device is which copy you chose to open.
Where it runs
On whatever servers the copy’s owner chose. The public demo runs on Vercel with its database on Turso, both in the United States.
Deleting
A copy is one database, so it can be removed whole: ask the person who runs it. To have a beta sign-up deleted, say so on the beta form.
Last updated 23 September 2026. Questions go through the beta form; see Help for the rest.