Privacy policy
Version : 2026-10-07
1. Controller
Controller: . Address: . Country: . Privacy contact: . Data protection officer if appointed: . This draft requires verification of actual production settings, purposes and processors before publication.
2. Data and purposes
Account data includes email, technical ID, profile names, username, sign-in information, acceptance records and the adulthood confirmation. Recipe, shopping list, photo, preference and conversation data is processed for requested features. Recipes and lists are stored locally; optional sync may create remote copies. Contract performance is the proposed basis for necessary account and service functions, subject to review.
Purchase references, subscription status, expiry and credit balance support verified entitlements. Necessary technical records support security and troubleshooting. Proposed bases include contract, legal duties for records and legitimate interests for security after assessment. Actual log contents and retention: .
3. Sensitive preferences
Allergies and dietary preferences may disclose health or other sensitive information. Avoid unnecessary medical details. Remote processing requires an appropriate assessment and, where necessary, separate explicit, withdrawable consent. Article 9 GDPR condition and consent mechanism before production use: . Accepting general terms alone is insufficient.
4. Local and remote AI
A feature actually executed on the local device processes that query locally. Other features contact the backend and external AI providers with the selected text, culinary context or image. Local AI does not imply that the entire app is offline or local.
The code integrates Google Gemini and other models offered in the interface. Actual active providers, countries, retention, contracts and any training use: . Verify these for each service before publication. Avoid unnecessary secrets or third-party personal data.
5. Storage and recipients
The current code uses Supabase for accounts and backend data, Apple for App Store and enabled iCloud functions, RevenueCat for purchase entitlements, and a Stripe backend integration. Widgets and Watch features receive the content needed for enabled sharing.
A separate Cuisly VPS migration is being prepared and must not be described as completed until verified. Actual host, countries, Supabase region, processors and support access: . Cuisly, Tralo and Azertix are intended to have separate services and data. No cross-service account sharing is announced here.
Transfers outside the EEA, destinations, legal mechanisms and safeguards must be documented against real contracts: .
6. Retention and rights
Local data remains until removed through the app or system. Other devices and backups may retain copies. Signing out retains an account-specific local copy to support reconnection. Retention for accounts, remote conversations, logs, support, payment records and backups: . Deletion and backup purge periods: . No unverified automatic purge is promised.
Subject to legal conditions, you may request access, correction, erasure, restriction and portability or object to processing. Consent can be withdrawn without affecting prior lawful processing. Rights contact: . Proportionate identity verification may be required. GDPR requests normally receive a response within one month, with extensions where legally allowed. You may complain to the competent authority, including the CNIL in France at cnil.fr. Controller’s competent authority: .
7. Choices, websites and updates
Manage system photo, camera and notification permissions and the app’s optional sync settings. The export covers the categories shown on screen. Account deletion and purchase cancellation are separate operations.
Bundled legal pages work offline without JavaScript. Public sites may load external resources or a support widget. Their final tracker and recipient inventory must be audited: . Consent-requiring trackers must remain off until valid consent, with an equally accessible refusal choice.
Access controls, protected communication and separated services must be implemented and tested; absolute security is not guaranteed. Security contact: . Material processing changes require updated information. Effective date following review: .