Privacy Policy
Effective 2026-09-07
Peristyle Grocery Cart ("Peristyle", "we") is an API and MCP connector that lets an AI assistant such as Claude or ChatGPT find a recipe, match its ingredients to real products at Kroger or Walmart, and fill a Kroger cart or build a Walmart cart link for you. This policy explains what data the connector and its tools handle, why, who receives it, how long we keep it, and the controls you have. It covers shoppers using the connector, readers using the Peristyle widget or concierge chat on a recipe creator's site, and recipe creators with a Peristyle account.
What the tools take in and give back
Every tool the assistant can call sends its inputs to our API and returns its outputs to the assistant, which shows them to you. The inputs are the data you (or the assistant on your behalf) type:
- Recipe discovery — search phrases, recipe page URLs you paste, and recipe identifiers. A URL we have never seen is fetched and its recipe is indexed into our shared catalog so it can be shopped later.
- Product matching — ingredient lines or a free-form shopping list, product names or UPCs, the ZIP code or store you shop at, and whether you want pickup or delivery.
- Cart creation — the products and quantities you confirm. For Kroger these are added to the cart on your connected Kroger account. For Walmart we return an Add-to-Cart link you open yourself; no Walmart account is connected. Household essentials you ask to send to Amazon (paper towels, detergent, foil and the like) go to a Peristyle page with a button that opens Amazon's own add-to-cart confirmation; no Amazon account is connected.
- Preferences — dietary needs, preferred brands, default store, ZIP, and pickup/delivery choice you ask the assistant to remember.
- Pantry (opt-in only) — kitchen items you have or are out of, products or ingredients you love or hate (with an optional free-text note), and your yes/no answer to "did that order go through?".
- Concierge chat (widget on a creator's site) — the messages you type to the recipe assistant.
The outputs are recipe details from our catalog, product listings (name, brand, size, price, stock, image) from Kroger's or Walmart's APIs, cart results, and your own saved preferences and pantry. Walmart cart links include affiliate identifiers so Walmart can attribute the cart to Peristyle; they do not identify you. Amazon cart links work the same way: as an Amazon Associate, Peristyle earns from qualifying purchases.
Data we collect and store
Account and store connection
- The email address you sign in with (magic link or one-time code), or the email Kroger returns when you link your Kroger account, plus an optional contact address you type after connecting (used only for our welcome email).
- Your Kroger profile identifier and the OAuth access and refresh tokens Kroger issues. Tokens are encrypted at rest. We never see or store your Kroger password, and we hold no Walmart credentials or identity.
- API keys minted for your assistant, stored only as a hash.
- Whether and when you opted into the pantry, when we sent your welcome email, and whether you unsubscribed from our email.
Preferences
The keys above, stored on your account when you are signed in through a remote connector (claude.ai, ChatGPT). With a local (stdio) connection they live only in a file on your device, along with a recent-recipes history that is never uploaded.
Pantry (only after you opt in)
Pantry items and their state, and product/ingredient feedback and notes. Nothing pantry-related is recorded before you opt in.
Carts you build
An itemized record of each cart you build (products, quantities, store, recipe), held as a pending purchase confirmation until you answer whether the order went through or it expires after 14 days. This is kept for every signed-in shopper, whether or not the pantry is on: checkout happens in the store's own app and no store tells us what was actually bought, so your answer is the only record of it there is. Answering adds those items to your pantry only if you have one — without it, we record the answer and nothing about your kitchen.
Usage analytics
We record an event when a recipe is searched or viewed, products are searched or matched, a list is reviewed, a cart is created, a store is connected, or the pantry is used. Events carry your account id (if signed in), a client session id, the recipe and creator involved, the store and store location, item counts, an estimated cart value, which assistant made the call (e.g. "claude", "chatgpt"), and ingredient names we could not match. Search text is stored only as a truncated hash, except that the wording of a search that returned nothing is kept (up to 80 characters) so we can fix the catalog. Analytics events do not contain your IP address, user agent string, or email.
Operational logs
Our servers log each request's method, path, status code, timing, request id, your account id when signed in, and your IP address. Logs of our own outbound calls include the URL we called, which can contain a search term, ZIP code, or store id. Email sends log the recipient address and subject. Request bodies, tokens, and credentials are not logged.
Recipe URLs from other sites
When you paste a recipe URL from a site that is not yet in our catalog, we keep the domain, the pasted URL, a request count, and the account or session id that asked, so we can invite that creator to Peristyle.
Creators
For recipe creators we store the name, contact email, site URL, social handles, and notes you submit; domain-verification results; login and session tokens (hashed); and, if you subscribe, your Stripe customer and subscription identifiers and plan status. Card details go directly to Stripe and never touch our servers.
Stored in your browser or on your device
The widget on a creator's site keeps your Peristyle API key, chosen store, session id, and display settings in that page's browser storage. We do not set cookies. The local (stdio) connector keeps your API key and a preferences and history file in your user config directory.
Why we use it
- To run the service: find recipes, match products at your store, add to your Kroger cart, build Walmart cart links, and remember your preferences.
- To personalize matching for you: with your opt-in, your pantry, likes and dislikes bias which products we suggest and which ingredients we skip. One person's pantry never influences another person's results.
- To sign you in, keep your store connected, and send transactional email (sign-in links, a one-time welcome email).
- To measure and improve the product: aggregate funnel and match-quality analytics, fixing searches that return nothing, and inviting creators whose recipes people paste.
- To give creators aggregate statistics about their recipes (views, matches, carts, estimated cart value, commonly unmatched ingredients). These are counts only; creators never see who you are.
- To secure the service: rate limiting, abuse prevention, and debugging.
- To bill creators who subscribe.
We do not sell your data, do not share it with advertisers, and do not use it to train AI models.
Who receives it
- Kroger — your OAuth token, search terms, brand filters, ZIP code or store id, and the UPCs and quantities you add to your cart, sent to Kroger's API. Requests to Kroger pass through a relay we operate on Cloudflare Workers.
- Walmart — search terms, item ids, and ZIP code sent to Walmart's affiliate catalog API; the products and quantities in any cart link you open on walmart.com, together with our affiliate tracking ids (Impact Radius).
- Amazon — only when you open an Amazon cart link: the products and quantities in it, together with our Amazon Associates tracking id, go to amazon.com from your own browser. We send Amazon nothing about you.
- AI model providers (concierge chat only) — when you use the chat on a creator's site, your messages, together with your saved dietary and brand preferences, your opt-in pantry and feedback, and your recent activity with that creator's recipes, are sent to Venice.ai and, as a fallback, Anthropic to generate the reply. Tool calls from Claude or ChatGPT do not involve these providers; those assistants are governed by their own policies.
- Email delivery — Cloudflare Email Service (or Resend) receives the recipient address and message content.
- Stripe — creators' contact email and Peristyle creator id, for billing.
- Infrastructure — Google Cloud (hosting, secrets, logging), Neon (managed Postgres), and Cloudflare (DNS and proxy) process all data on our behalf under their standard processor terms. Google Public DNS is queried to verify creators' domains.
- Recipe creators — aggregate statistics only, as above.
- Peristyle staff — the operator dashboard shows shopper contact addresses and activity for support and to follow up when a cart was started but not finished.
We may also disclose data if required by law or to protect the service and its users.
How long we keep it
- Account, preferences, store connection, pantry, and feedback — for as long as your account exists, or until you disconnect the store, turn the pantry off, or delete the account. Store tokens are refreshed rather than deleted when they expire.
- Purchase confirmations — marked expired after 14 days if unanswered; the itemized record is kept with your account until you delete the account or turn the pantry off (which erases them whether or not you ever turned it on).
- Usage analytics events — kept while we operate the service; deleting your account unlinks them from you, and turning the pantry off deletes the itemized cart records.
- Sign-in and OAuth artifacts — magic links and codes expire within minutes and are purged; cart de-duplication records are purged after 10 minutes.
- Operational logs — kept by our hosting provider's logging service for its standard short retention window, then deleted; they are not archived or exported elsewhere.
- Creator data — for the life of the creator account and as required for tax and billing records.
Your controls
- Preferences — view them with get_preferences or
GET /v1/preferences; change or clear any key with set_preference orPUT /v1/preferences. - Pantry — it is off until you enable it. View everything with get_pantry; remove individual items or change any feedback with update_pantry and record_product_feedback; answer or dismiss a purchase confirmation with confirm_purchase.
- Email — every marketing-style email carries a one-click unsubscribe link. Sign-in emails are sent only when you request them.
- Kroger connection — ask the assistant to disconnect
Kroger (disconnect_kroger, or
DELETE /v1/me/stores/kroger) to delete the stored tokens and account link. Also remove Peristyle under connected apps in your Kroger account settings to revoke the grant on Kroger's side. - Turn the pantry off — disable_pantry (or
POST /v1/pantry/opt-out) switches it off and permanently deletes every pantry item, feedback row, and purchase confirmation. - Delete your account — delete_account (or
DELETE /v1/me) permanently removes the account, store connections, API keys, preferences, and pantry. Usage analytics are kept only in aggregate, unlinked from you. The assistant will ask you to confirm; there is no undo. - Export — there is no self-service export yet. Email [email protected] from your sign-in address and we will send your data within 30 days. The same address handles any request you cannot complete with the tools above.
- Local data — delete the connector's config directory or the widget's site data in your browser at any time.
Security
Data is encrypted in transit (TLS). Store tokens are encrypted at rest; API keys, sign-in tokens, and session tokens are stored as hashes. Secrets live in a managed secret store, not in code.
Children
The service is not directed to children under 13 and we do not knowingly collect their data.
Changes
We will update this page when our data practices change and revise the effective date above. Material changes to what we collect or who receives it will be called out here.
Contact
Questions or requests about this policy: [email protected]