CookFeed — Privacy Policy

Last updated: August 20, 2026

1. Information We Collect

When you use CookFeed, we collect the following information:

2. How We Use Your Information

3. Public Information

The following information is visible to other users of the app:

4. AI Features

When you use AI-powered features, your data is sent to Google's Gemini AI service for processing. This includes:

We use this data to generate the requested AI response. Processing by Google Gemini is subject to Google's applicable terms and privacy practices. We log AI usage metadata (token counts, timestamps) for cost tracking and rate limiting purposes.

5. Moderation and Admin Access

We maintain a secure admin interface accessible only to authorized members of our team. Through this interface, we may access, review, moderate, feature, unpublish, or delete user content and accounts when necessary to enforce our rules, ensure app quality, prevent abuse, respond to reports, or meet legal obligations.

6. Third-Party Services

We use the following third-party services:

These services have their own privacy policies. We encourage you to review Firebase Privacy Policy, Google AI Terms, and RevenueCat Privacy Policy.

7. Data Storage & Security

8. Your Rights

9. Legal Basis for Processing (GDPR)

If you are located in the European Economic Area (EEA), we process your personal data under the following legal bases:

10. Your Rights Under GDPR (EEA Users)

If you are located in the EEA, you have the following additional rights under the General Data Protection Regulation (GDPR):

To exercise any of these rights, contact us at hello@cookfeed.app. We will respond within 30 days.

11. International Data Transfers

Your data is stored on Google Firebase servers which may be located outside the European Economic Area, including in the United States. These transfers are protected by Google's Standard Contractual Clauses (SCCs) and compliance with applicable data protection frameworks. RevenueCat may also process subscription data in the United States under similar safeguards.

12. Data Retention

Deleted recipes are moved to a recycle bin and scheduled for permanent deletion after 30 days. When account deletion is completed, we remove associated personal data from active CookFeed systems, except where retention is required or permitted by law, security, fraud prevention, dispute resolution, backup integrity, or third-party provider obligations. Anonymous guest accounts inactive for 7 days are automatically cleaned up.

13. Premium Subscriptions

CookFeed offers optional auto-renewing Premium subscriptions and one-time consumable AI-credit packages. On iOS, Apple processes mobile purchases through the Apple App Store/StoreKit; on Android, Google processes them through Google Play Billing. RevenueCat manages product, transaction, entitlement, purchase-restoration, and AI-credit data. Web purchases, where available, are processed through RevenueCat Web Billing. CookFeed does not receive your full payment-card details. Premium features may include AI credit grants or enhanced AI access, advanced cooking tools, and additional storage. We may provide starter AI credits to eligible new users for AI features. Where AI credits are unavailable or not enforced, some AI features may instead be subject to feature-specific usage limits. A free trial period may be offered. Subscription and purchase details and prices are displayed before purchase.

14. Device Permissions

CookFeed may request the following device permissions:

All permissions are optional and requested only when you use the relevant feature. You can revoke permissions at any time through your device settings.

15. Voice Data

CookFeed uses voice input for text field dictation and Cook Mode voice commands. Voice data is processed by your device's built-in speech-to-text engine (provided by Google or Apple) and is not sent to or stored on CookFeed servers. Text-to-Speech in Cook Mode uses your device's built-in TTS engine to read recipe steps aloud in your selected language.

16. Web Application

CookFeed is available on the web and as iOS and Android apps. These versions share the same Firebase backend and user accounts. All data processing, storage, and privacy practices described in this policy apply equally to CookFeed on the web and mobile.

17. Children's Privacy

CookFeed is not directed at children under 13 (or under 16 in the EEA). We do not knowingly collect personal information from children under these ages. If you believe a child has provided us with personal data, please contact us and we will promptly delete it.

18. Referrals, Device Identifier and Abuse Prevention

CookFeed generates a device identifier for your app or browser installation and stores it when you use a promotional offer such as starter AI credits or the referral program. We use this device identifier, together with your account identifier and a one-way SHA-256 hash of your email address, only to prevent abuse of those offers — for example, several accounts claiming a referral reward from the same device, or someone using their own code on a second account.

This device identifier is not an advertising identifier, is not used for advertising or profiling, and is not shared with advertisers. Your email address is stored with a referral record only as a hash, never in readable form. Referral and abuse-prevention records may be kept after an account is deleted, for as long as needed for fraud prevention, security and dispute resolution.

19. Changes to This Policy

We may update this privacy policy from time to time. We will notify you of any significant changes by posting the new policy on this page, updating the "Last updated" date, and where appropriate, notifying you through the app.

20. Data Controller

The data controller for CookFeed is the app developer, based in Sweden. For any questions about data processing or to exercise your rights, contact us at: hello@cookfeed.app