CookFeed — Privacy Policy
Last updated: August 20, 2026
1. Information We Collect
When you use CookFeed, we collect the following information:
- Account and Authentication Information: Name, username, email address, authentication provider, and provider-specific account identifier when you use email registration, Google Sign-In, or Sign in with Apple. A profile photo is collected only if you choose to upload one. If you use Apple’s Hide My Email, we receive the private relay address Apple provides
- Recipe Data: Recipe titles, descriptions, ingredients, instructions, and images that you create
- Usage Data: AI feature usage counts (daily call limits, AI credit grants and balances, feature-specific usage limits, etc.), app language preference, and pricing region selection
- Social Interactions: Likes, comments, star ratings, shares, group memberships, and follow relationships
- Photos: Photos of dishes you submit for AI identification (Snap & Cook, Leftovers Transformer)
- Voice Data: Voice input for recipe text fields and voice commands in Cook Mode are processed by your device's speech-to-text engine and are not stored on our servers
- Barcode Data: Product barcodes scanned via the in-app barcode scanner for adding items to your pantry tracker or shopping list
- Location Preferences: Home region and current location selections used in the Cook Like Home (diaspora cooking) feature to adapt recipes with locally available ingredients
- Purchase and Entitlement Data: Your CookFeed account identifier, store and product identifiers, transaction and subscription status, renewal, expiration, refund and restore information, and AI-credit balance managed through RevenueCat and the applicable purchase platform. CookFeed does not receive your full payment-card details
- Search Data: Search queries you submit. Public recipe and public profile fields are indexed by Algolia to return search results
- Device Identifier: A randomly generated device installation ID stored locally on your device, used to prevent abuse of free AI credit grants. This ID is not linked to your personal identity and cannot be used to track you across apps
- Push Notification Tokens: Firebase Cloud Messaging (FCM) tokens used to deliver push notifications to your device. Tokens are stored in your user profile and automatically cleaned up when they become invalid
- Nutrition Estimates: AI-generated nutritional information (calories, protein, carbs, fat, fiber, sugar, sodium) calculated on demand for recipes. This data is displayed in the app but not permanently stored on our servers
2. How We Use Your Information
- To provide and maintain the recipe management service
- To enable social features (sharing recipes, comments, likes, star ratings, groups, following)
- To generate AI-powered features including: meal plans, recipe translations, nutrition estimates, ingredient substitutions, cost estimates, dietary adaptations, batch cooking plans, dish identification from photos, leftovers transformation, meal prep schedules, recipe generation from text or photos, recipe import from URLs, Cook Like Home diaspora recipe adaptation, and content moderation
- To send push notifications about activity on your recipes (likes, comments, shares, new followers, group additions)
- To track AI feature usage per user for daily rate limiting (100 AI calls per day for all users), AI credit enforcement, and feature-specific limits when enabled. These limits may change
- To moderate, review, feature, unpublish, or remove user-generated content for community safety, quality control, and compliance with our Terms of Service
- To manage user accounts, including blocking or deleting accounts that violate our rules
- To administer premium subscription features via RevenueCat (granting, revoking, or managing access to paid features, including free trial periods)
- To feature popular or selected public recipes within the app
- To estimate recipe costs based on your selected pricing region
- To send transactional emails including: welcome emails, email verification, password reset, subscription confirmation, account warnings, and account deletion confirmation. Emails are sent in your preferred app language via our email service (Zoho SMTP)
- To prevent abuse of free AI credit grants by tracking a device identifier (one grant per device)
3. Public Information
The following information is visible to other users of the app:
- Public Profile: Your username, display name, and profile photo are visible to other users
- Public Recipes: When you make a recipe public, its title, description, ingredients, instructions, images, and your name as the author are visible to all users. Public recipes may be featured or promoted based on popularity or editorial selection
- Social Activity: Your likes, comments, star ratings, followers, and following lists are visible to other users
- Groups: Other users can add you to recipe sharing groups. You can leave any group at any time
4. AI Features
When you use AI-powered features, your data is sent to Google's Gemini AI service for processing. This includes:
- Recipe text (titles, ingredients, instructions) for meal planning, translation, nutrition calculation, ingredient substitution, cost estimation, dietary adaptation, batch planning, meal prep scheduling, and Cook Like Home recipe adaptation
- Photos of dishes for Snap & Cook (dish identification) and Leftovers Transformer
- URLs for recipe import from websites
- Recipe content for automated content moderation of public recipes
- Country selections (home region and current location) for Cook Like Home diaspora cooking feature
We use this data to generate the requested AI response. Processing by Google Gemini is subject to Google's applicable terms and privacy practices. We log AI usage metadata (token counts, timestamps) for cost tracking and rate limiting purposes.
5. Moderation and Admin Access
We maintain a secure admin interface accessible only to authorized members of our team. Through this interface, we may access, review, moderate, feature, unpublish, or delete user content and accounts when necessary to enforce our rules, ensure app quality, prevent abuse, respond to reports, or meet legal obligations.
6. Third-Party Services
We use the following third-party services:
- Google Firebase (Firebase Authentication, Firestore, Cloud Storage, Cloud Functions, Cloud Messaging, and Analytics): Account authentication, database and file storage, backend processing, push notifications, and product analytics. Firebase Analytics may receive your CookFeed user ID, app and device information, and events describing screens and features used
- Google Sign-In and Sign in with Apple: Optional account authentication. The provider gives CookFeed a provider-specific identifier and information you authorize, such as your name and email address. Apple may provide a private relay email address when you select Hide My Email
- Google Gemini AI: Processes the text, images, URLs, recipe content, and selections described in Section 4 to provide AI features and content moderation
- Algolia: Indexes public recipe and public profile fields, including internal record identifiers, and receives search queries to return search results
- RevenueCat: Manages subscriptions, one-time AI-credit purchases, entitlements, purchase restoration, and AI-credit balances. CookFeed sends RevenueCat your CookFeed/Firebase user ID and receives product, transaction, subscription, renewal, expiration, refund, and entitlement status
- Apple App Store/StoreKit and Google Play Billing: Process mobile purchases and store-account billing. CookFeed does not receive your full payment-card details
- Zoho Mail: Receives recipient email addresses and transactional-message content to deliver verification, password-reset, purchase and subscription, account, and support emails
- Open Food Facts: Receives the scanned barcode and ordinary network-request data to return product information. We do not intentionally send your CookFeed account or profile data
These services have their own privacy policies. We encourage you to review Firebase Privacy Policy, Google AI Terms, and RevenueCat Privacy Policy.
7. Data Storage & Security
- CookFeed app data is stored primarily in Google Firebase infrastructure
- Data is encrypted in transit using HTTPS/TLS
- Images are stored in Firebase Storage with access controls
- Subscription data is managed securely through RevenueCat
- We do not sell your personal data to third parties
8. Your Rights
- You can delete individual recipes at any time (moved to a recycle bin for 30 days, then scheduled for permanent deletion)
- You can export all your recipes as a JSON file or PDF for backup
- You can request account deletion (Settings → Delete Account), which removes your account data from active CookFeed systems, such as recipes, images, comments, likes, and account information, subject to any legally required or permitted retention
- You can delete comments on your own recipes
- You can accept or reject recipes shared with you
- You can leave groups you were added to at any time
- You can upload, change, or remove your profile photo at any time
- You can change your pricing region for cost estimates at any time
- If a moderation action has been taken on your content or account, you can contact us
- You can contact us at hello@cookfeed.app for any privacy-related requests
9. Legal Basis for Processing (GDPR)
If you are located in the European Economic Area (EEA), we process your personal data under the following legal bases:
- Contract: Processing your account data, recipe data, and social interactions is necessary to provide the CookFeed service you signed up for
- Consent: AI-powered features (meal plans, translations, photo identification, etc.) and push notifications are processed based on your explicit consent. You can withdraw consent at any time by stopping use of these features or disabling notifications
- Legitimate Interest: Usage tracking for rate limiting and abuse prevention, content moderation for community safety, and analytics for service improvement
10. Your Rights Under GDPR (EEA Users)
If you are located in the EEA, you have the following additional rights under the General Data Protection Regulation (GDPR):
- Right of Access: You can request a copy of all personal data we hold about you
- Right to Rectification: You can update your account information at any time through the app settings
- Right to Erasure: You can request deletion of your account and associated personal data (Settings → Delete Account), subject to any legally required or permitted retention
- Right to Data Portability: You can export your recipes as JSON or PDF files
- Right to Restrict Processing: You can request that we limit how we use your data
- Right to Object: You can object to processing based on legitimate interest
- Right to Withdraw Consent: Where processing is based on consent, you can withdraw it at any time without affecting the lawfulness of prior processing
- Right to Lodge a Complaint: You have the right to lodge a complaint with your local data protection authority. For users in Sweden, this is Integritetsskyddsmyndigheten (IMY)
To exercise any of these rights, contact us at hello@cookfeed.app. We will respond within 30 days.
11. International Data Transfers
Your data is stored on Google Firebase servers which may be located outside the European Economic Area, including in the United States. These transfers are protected by Google's Standard Contractual Clauses (SCCs) and compliance with applicable data protection frameworks. RevenueCat may also process subscription data in the United States under similar safeguards.
12. Data Retention
Deleted recipes are moved to a recycle bin and scheduled for permanent deletion after 30 days. When account deletion is completed, we remove associated personal data from active CookFeed systems, except where retention is required or permitted by law, security, fraud prevention, dispute resolution, backup integrity, or third-party provider obligations. Anonymous guest accounts inactive for 7 days are automatically cleaned up.
13. Premium Subscriptions
CookFeed offers optional auto-renewing Premium subscriptions and one-time consumable AI-credit packages. On iOS, Apple processes mobile purchases through the Apple App Store/StoreKit; on Android, Google processes them through Google Play Billing. RevenueCat manages product, transaction, entitlement, purchase-restoration, and AI-credit data. Web purchases, where available, are processed through RevenueCat Web Billing. CookFeed does not receive your full payment-card details. Premium features may include AI credit grants or enhanced AI access, advanced cooking tools, and additional storage. We may provide starter AI credits to eligible new users for AI features. Where AI credits are unavailable or not enforced, some AI features may instead be subject to feature-specific usage limits. A free trial period may be offered. Subscription and purchase details and prices are displayed before purchase.
14. Device Permissions
CookFeed may request the following device permissions:
- Camera: For taking recipe photos, Snap & Cook dish identification, Leftovers Transformer photo input, and barcode scanning in the shopping list and pantry tracker
- Microphone: For voice input in text fields and voice commands in Cook Mode (e.g., "next step", "set timer")
- Notifications: For push notifications about social activity (likes, comments, shares, followers, group additions)
- Photo Library: For selecting existing photos to attach to recipes or use with AI features
All permissions are optional and requested only when you use the relevant feature. You can revoke permissions at any time through your device settings.
15. Voice Data
CookFeed uses voice input for text field dictation and Cook Mode voice commands. Voice data is processed by your device's built-in speech-to-text engine (provided by Google or Apple) and is not sent to or stored on CookFeed servers. Text-to-Speech in Cook Mode uses your device's built-in TTS engine to read recipe steps aloud in your selected language.
16. Web Application
CookFeed is available on the web and as iOS and Android apps. These versions share the same Firebase backend and user accounts. All data processing, storage, and privacy practices described in this policy apply equally to CookFeed on the web and mobile.
17. Children's Privacy
CookFeed is not directed at children under 13 (or under 16 in the EEA). We do not knowingly collect personal information from children under these ages. If you believe a child has provided us with personal data, please contact us and we will promptly delete it.
18. Referrals, Device Identifier and Abuse Prevention
CookFeed generates a device identifier for your app or browser installation and stores it when you use a promotional offer such as starter AI credits or the referral program. We use this device identifier, together with your account identifier and a one-way SHA-256 hash of your email address, only to prevent abuse of those offers — for example, several accounts claiming a referral reward from the same device, or someone using their own code on a second account.
This device identifier is not an advertising identifier, is not used for advertising or profiling, and is not shared with advertisers. Your email address is stored with a referral record only as a hash, never in readable form. Referral and abuse-prevention records may be kept after an account is deleted, for as long as needed for fraud prevention, security and dispute resolution.
19. Changes to This Policy
We may update this privacy policy from time to time. We will notify you of any significant changes by posting the new policy on this page, updating the "Last updated" date, and where appropriate, notifying you through the app.
20. Data Controller
The data controller for CookFeed is the app developer, based in Sweden. For any questions about data processing or to exercise your rights, contact us at: hello@cookfeed.app
English
العربية
Svenska
Türkçe
Français
Deutsch
Español
Nederlands
Italiano
हिन्दी