GYSTMeals planned. Groceries handled.
THE FINE PRINT, IN PLAIN ENGLISH

Privacy at GYST

Last updated August 18, 2026

GYST plans your meals and builds your grocery cart. To do that we keep some information about you — this page says exactly what, why, and what we’ll never do with it.

What we keep

  • Your email address — it’s how you sign in, and where we send confirmation and sign-in links.
  • Your password — scrambled, never stored as you typed it. We keep a one-way hash (PBKDF2-HMAC-SHA512, 100,000 rounds, with a random salt for every account), which lets us check a password without being able to read it. Nobody at GYST can see or recover your password, and we will never email it to you or ask you for it.
  • Your food profile — household size, preferences, dietary notes, and your grocery budget.
  • Your planning data — meal plans, recipes you’ve picked, what we estimate is in your pantry, and your grocery lists.
  • Your retailer connection — if you connect King Soopers, we store the secure tokens Kroger issues us and which store you shop at.

What we never see

  • Your password itself — only the one-way hash described above. If our database were ever stolen, your actual password would not be in it.
  • Your King Soopers password — you sign in on Kroger’s own site, never ours. We only receive the access tokens Kroger issues.
  • Payment details — checkout happens on your retailer’s site. Card numbers never touch GYST.

One ask, in your interest

Use a password here that you don’t use anywhere else. That’s true of every site, and we’d rather say it plainly than assume. If you’d rather not have a password at all, you don’t need one — “email me a sign-in link” still works, every time.

How we use it

To run GYST for you — that’s the whole list. We don’t sell your data, we don’t show ads, and we don’t share your information with anyone except the services that keep GYST running:

  • Cloudflare hosts the app and database.
  • Resend delivers your sign-in emails.
  • Kroger receives your grocery list items when you ask us to fill your cart — only after you’ve connected your account.
  • USDA FoodData Central and Open Food Facts answer our ingredient lookups. They get food search terms, never anything about you.
  • Have I Been Pwned tells us whether a password you’re choosing has already appeared in someone else’s data breach. It never receives your password, or even the full fingerprint of it — we send the first five characters of a one-way hash and do the matching ourselves, so it can’t tell which password was asked about. If the service is unreachable we let you carry on rather than block your sign-up.

Deleting your data

Email crispy@crispygaming.com from your sign-in address and we’ll delete your account and everything attached to it — profile, plans, kitchen, retailer connection, and your stored password hash. No questions, no retention games.

If this changes

We’ll update this page and the date at the top. Meaningful changes get an email, not a silent edit.

GYST is made by Crispy Games LLC in Longmont, Colorado. Questions about any of this? Email crispy@crispygaming.com — a person reads it. Back to GYST · Privacy · Terms · Sources