Privacy Policy
This Privacy Policy explains how Recipi (“Company,” “we,” “us,” or “our”) collects, uses, shares, and protects personal data when you use Recipi (the “Service”), including our mobile apps, websites, and APIs.
If you do not agree with this Policy, please do not use the Service.
Contact (privacy): [email protected]
Postal address: Recipi
EU/EEA representative (if required): N/A
Data Protection Officer (if appointed): N/A
1. Who We Are (Controller)
For personal data processed in connection with the Service, the data controller is:
Recipi
Email: [email protected]
2. Scope
This Policy covers personal data we process about:
- app and website users;
- account holders;
- people who contact support; and
- visitors interacting with our public recipe content or marketing pages (if any).
It does not cover third-party websites, apps, or services that we link to or integrate with, which have their own privacy practices.
3. Personal Data We Collect
We collect the categories below depending on how you use the Service.
3.1 Account and profile data
- Email address
- Display name
- Avatar / profile image URL (if provided)
- Authentication identifiers (for example a Supabase user ID)
- Country and language settings
- Account status and timestamps (created, last login, deletion)
- Role (for staff/admin accounts)
3.2 Preferences and personalization
- Preferred language and country
- Unit system (metric / imperial)
- Diet preferences, excluded allergens, disliked ingredients, preferred cuisines
- Max cook time and notification preferences
3.3 Content and activity you create
- Saved recipes and private/imported recipes
- Cookbooks / collections
- Shopping lists and pantry items
- Meal planner entries
- Swipe / recommendation interactions
- Images you upload (for example recipe photos or import images)
- Import jobs (URLs, text, images you submit for recipe extraction)
- AI chat messages / prompts and related responses
3.4 Subscription and purchase data
- Subscription / entitlement status (for example Pro)
- Billing period, renewal status, and related subscription events
- App store / RevenueCat identifiers needed to verify purchases
We typically do not receive full payment card numbers; those are handled by Apple, Google, and/or other payment processors.
3.5 Device, push, and technical data
- Push notification tokens and platform (for example iOS / Android)
- IP address
- User agent / device and app information
- Approximate location derived from IP (country-level)
- Session or request identifiers
- Log data related to API usage, errors, and security
3.6 Analytics and product usage
We may record product events such as recipe views, swipes, saves, imports, pantry updates, cook-mode usage, shares, ratings, and AI/image generation events, together with related metadata (for example event type, timestamps, language/country, IP, user agent).
3.7 Support and communications
- Messages you send us
- Related contact details and correspondence
3.8 Data from third parties
We may receive data from:
- authentication providers (for example account email and user ID);
- app stores and subscription platforms (for example RevenueCat, Apple, Google);
- AI, scraping, storage, or push providers when needed to deliver a feature you requested.
4. How We Collect Data
We collect data:
- directly from you (registration, preferences, imports, uploads, chat, support);
- automatically when you use the Service (logs, analytics, device/push data); and
- from third-party services you connect or that process purchases/authentication on our behalf.
5. Why We Process Personal Data (Purposes and Legal Bases)
If you are in the EU/EEA/UK (or similar regimes), we rely on the legal bases below.
| Purpose | Examples | Legal basis |
|---|---|---|
| Provide the Service | Account creation, login, syncing recipes, pantry, planner, shopping lists, imports, feed | Contract (Art. 6(1)(b) GDPR) |
| Personalization | Units, language, diet/allergen preferences, recommendations | Contract and/or legitimate interests (Art. 6(1)(b)/(f)) |
| Subscriptions | Verify Pro access, enforce free-plan limits, process entitlement webhooks | Contract (Art. 6(1)(b)) |
| AI features | Recipe extraction/generation, nutrition estimates, in-app assistant | Contract (Art. 6(1)(b)); legitimate interests for abuse prevention/quality |
| Push notifications | Notify you about import completion or other service messages you enable | Contract and/or consent where required |
| Analytics & improvement | Understand feature usage, fix bugs, improve ranking and UX | Legitimate interests (Art. 6(1)(f)); consent where required for non-essential tracking |
| Security & abuse prevention | Rate limiting, fraud prevention, investigating misuse | Legitimate interests (Art. 6(1)(f)); legal obligation where applicable |
| Support | Respond to requests | Contract and/or legitimate interests |
| Legal compliance | Tax, accounting, responding to lawful requests, consumer law | Legal obligation (Art. 6(1)(c)) |
| Marketing (if any) | Newsletters or promotional messages | Consent (Art. 6(1)(a)) and/or soft opt-in where allowed; you can opt out |
Special category data: Preferences such as allergens or diet may reveal health-related information. We process this only to provide the features you request (for example filtering). Where required, we rely on your explicit consent (Art. 9(2)(a)) and/or the fact that you clearly made the information public/provided it for that purpose. You can clear or change these preferences in the app where available.
6. AI Processing
Some features use artificial intelligence (including third-party AI providers) to:
- extract recipes from URLs, text, or images;
- generate or assist with recipe content;
- estimate nutrition;
- power the in-app assistant.
Important:
- Prompts, imported content, and outputs may be sent to AI providers to fulfill your request.
- AI outputs can be inaccurate; do not treat them as medical or dietary advice.
- We configure providers according to our agreements and aim to use enterprise/API settings that restrict use of your content for unrestricted model training where available. Provider practices may still change—see their policies.
7. How We Share Personal Data
We do not sell your personal data.
We share data only as needed with:
7.1 Service providers (processors / sub-processors)
Categories may include:
- Authentication / identity (for example Supabase)
- Hosting / infrastructure / databases / storage
- AI providers (for example OpenAI or successors)
- Image generation providers (if used)
- Content retrieval / scraping providers used for imports you request
- Push notification services (for example Expo / Apple / Google push infrastructure)
- Subscription & entitlement services (for example RevenueCat)
- Analytics, logging, and error monitoring (if enabled)
- Customer support tools
These providers may process data only on our instructions and under appropriate agreements.
7.2 App stores and payment platforms
Apple, Google, and similar platforms process purchase and account data under their own privacy policies.
7.3 Legal and safety
We may disclose data if reasonably necessary to:
- comply with law, regulation, legal process, or governmental request;
- enforce our Terms;
- protect rights, safety, and security of users, the public, or the Company.
7.4 Business transfers
If we are involved in a merger, acquisition, financing, or sale of assets, personal data may be transferred as part of that transaction, subject to appropriate safeguards.
7.5 With your direction
We may share information if you ask us to (for example sharing a recipe link).
8. International Transfers
We may process and store data in the EU and other countries where our providers operate.
If personal data is transferred from the EU/EEA/UK to countries without an adequacy decision, we use appropriate safeguards such as the European Commission Standard Contractual Clauses (SCCs) (and UK equivalents where applicable), plus supplementary measures where needed.
Contact [email protected] for more information about transfer safeguards.
9. Retention
We keep personal data only as long as needed for the purposes above, including:
| Data type | Typical retention |
|---|---|
| Account profile | For the life of the account |
| App content (recipes, lists, pantry, planner, etc.) | For the life of the account or until you delete it |
| Subscription records | For the subscription lifecycle + period required for accounting/disputes |
| Analytics/events and logs | 12–24 months, unless needed longer for security/legal reasons |
| Support tickets | Up to 24 months after closure |
| Audit / security records related to account deletion | As needed for legitimate interests and legal compliance |
Account deletion
You can request account deletion in the app (or by contacting us). When you delete your account:
- we disable/ban further authentication access where applicable;
- we mark the account as deleted (soft-delete);
- some related records may be retained or anonymized for a period for security, abuse prevention, backups, legal, or operational integrity;
- analytics events may be retained in de-identified/unlinked form where the user reference is removed or nullified.
Active paid subscriptions must also be cancelled in your Apple/Google account settings; deleting the app account does not automatically refund or cancel store billing.
10. Your Rights
Depending on your location (especially EU/EEA/UK), you may have the right to:
- Access your personal data
- Rectify inaccurate data
- Erase data (“right to be forgotten”)
- Restrict processing
- Object to processing based on legitimate interests
- Data portability
- Withdraw consent at any time (where processing is consent-based)
- Lodge a complaint with your local supervisory authority
In Sweden, the supervisory authority is Integritetsskyddsmyndigheten (IMY) — https://www.imy.se.
To exercise rights, email [email protected]. We may need to verify your identity before fulfilling the request.
11. Children
The Service is not directed to children under 16 years of age. We do not knowingly collect personal data from children below that age. If you believe a child has provided personal data, contact us and we will take appropriate steps to delete it.
12. Cookies and Similar Technologies
Our website/app may use cookies, local storage, SDKs, or similar technologies for:
- essential functionality and authentication;
- security and rate limiting;
- analytics/performance (where used);
- remembering preferences.
Where required by law, we will request consent for non-essential cookies/trackers. You can control cookies through your browser/device settings. Some features may not work if essential storage is disabled.
13. Security
We use administrative, technical, and organizational measures designed to protect personal data, including access controls, encrypted transport (HTTPS/TLS) where applicable, and least-privilege practices.
No method of transmission or storage is 100% secure. You are responsible for keeping your login credentials confidential.
14. Push Notifications
If you enable push notifications, we store a device push token to deliver messages (for example import-completion notices). You can disable notifications in your device settings and/or remove tokens through the app where available.
15. Do Not Track / Global Privacy Controls
Some browsers send “Do Not Track” signals. Our Service may not respond to all such signals uniformly. Where legally required (for example under certain US state laws), we will honor applicable opt-out preference signals for targeted advertising if we engage in such activity.
16. Region-Specific Disclosures
16.1 EU/EEA/UK
See Sections 5, 8, and 10 for legal bases, transfers, and rights.
16.2 California / US state privacy laws (if applicable)
If you are a resident of California or another US state with consumer privacy laws, you may have rights to know/access, delete, correct, and opt out of certain data “sales” or “sharing” for cross-context behavioral advertising. We do not sell personal information for money. If we use advertising SDKs that constitute “sharing,” we will provide an opt-out mechanism.
To exercise US state privacy rights, contact [email protected].
17. Changes to This Policy
We may update this Privacy Policy from time to time. We will change the “Last updated” date and, for material changes, provide additional notice (for example in-app or by email) when appropriate. Continued use after the effective date means you acknowledge the updated Policy, except where applicable law requires express consent.
18. Contact
Questions or privacy requests:
Recipi
Email: [email protected]
Support: [email protected]
Address: Recipi