Privacy Policy

Last updated: August 2026

1. What data we collect

When you register, we collect your name, email address, and password (stored as a secure bcrypt hash — we never store your plain-text password). You may optionally provide a profile photo, location, bio, and links.

If you register or sign in with Google, we receive your name, email, and profile picture from Google.

If you use a BYOK (Bring Your Own Key) subscription and save an AI API key, it is stored encrypted with AES-256-GCM — it is never stored or transmitted in plain text.

Recipes you create or save, comments, and likes are stored to provide the service.

We set a session cookie (cookbook_session) to keep you logged in for up to 7 days. In the Android app, this cookie can last up to 400 days and is automatically renewed while you remain signed in; logout or account invalidation ends the session.

The iPhone and iPad app cannot use this cookie, so it keeps you signed in with access tokens instead. A short-lived token stays only in the app's memory, and a long-lived renewal token is placed in the device's secure storage. We never keep the token itself: on our side there remains only its hash, together with the platform name, the app or browser identifier (user-agent), and the creation and last-use dates. We need this data to keep you signed in and to let you end sessions. You can end sessions on all devices in Settings, and they also end automatically when you change your password or delete your account.

When you use the calorie reference, your search query is sent to our server to find matching products. We do not link these queries to your account and do not use them to build a profile of you.

2. How we use your data

Your data is used solely to provide the Cookbook Social recipe-sharing service: to authenticate you, display your profile, store your recipes, and enable social features (likes, comments, follows).

We do not sell, rent, or share your personal data with third parties for marketing purposes.

3. Third-party services

Google OAuth (optional): if you choose to sign in with Google, your authentication is handled by Google. Google's privacy policy applies to that interaction.

AI providers: we use Google Gemini and OpenAI to power AI features. With your own key (BYOK), your key is sent to the provider only when you request an AI recipe import or translation. On server-paid plans, recipe imports and translations use our server-side keys.

Smart (semantic) search: recipe text — titles, descriptions, ingredients, steps, dietary labels, and allergen labels, including private recipes you create — is sent to Google Gemini (or OpenAI as a fallback) to generate search embeddings. When you use smart search, your search query is also sent to Google Gemini to compute an embedding used only to rank results; queries are processed transiently and never used for advertising. These providers process data under their own privacy policies.

YouTube imports: when you submit a YouTube URL, we may send the video ID or URL to YouTube API Services to retrieve public metadata such as title, description, channel, thumbnail, and duration. Google Privacy Policy (https://policies.google.com/privacy) and YouTube Terms of Service (https://www.youtube.com/t/terms) apply to YouTube API Services.

Payment providers: subscription payments are processed by our web payment provider and Google Play, which receive the information needed to process your payment. We do not store full card details.

4. Data security

Passwords are hashed with bcrypt (12 rounds) and never stored in plain text.

AI API keys are encrypted at rest with AES-256-GCM using a server-side secret.

Data is stored in a PostgreSQL database on Railway infrastructure. Recipe photos and other uploaded images are stored in Cloudflare R2 object storage.

5. Your rights

You can edit or delete your profile and all your recipes at any time from your Profile → Settings page.

Deleting your account schedules removal after a 14-day restoration window. During that period the account is inactive and can be restored by signing in again.

After the window expires, your profile, recipes, likes, comments, follows, credentials, jobs, and other account-linked data are removed. Recipe copies already saved by other users remain in their accounts, but the link back to your deleted account is removed.

6. Contextual advertising

CookbookSocial may show internal sponsored placements based only on the current app context, such as the page, recipe category, interface language, and ad placement.

We do not use cross-site tracking, behavioral advertising profiles, third-party ad networks, or ad-specific cookies/local storage identifiers for this. Ad events are recorded as operational metrics, such as creative ID, surface, event type, and revenue fields, to measure impressions, clicks, hides, and reports. These ad metrics do not include recipe text, search queries, payment data, or the content of your private recipes.

7. API usage data

If you use our paid food data API, we record what is needed to enforce plan limits and to bill correctly: the time a key was last used and the number of requests made in the current month and minute. These counters are reset at the end of each billing month.

We do not store the search queries you send to the API, request bodies, or the responses returned to you. Usage counters are tied to the API key and its owning account, not to the end users of your application — we never receive their identity.

8. Apple app, Sign in with Apple, and notifications

In the iPhone and iPad app, Sign in with Apple is optional. If you use it, Apple sends us the information needed to sign you in, such as your Apple account identifier and, when Apple provides it, your name and email address. If you choose Apple's private relay email, we store that relay address as your account email.

App Store purchases are processed by Apple through StoreKit. We receive transaction identifiers, product identifiers, subscription status, renewal, refund, and restore information needed to unlock paid features and keep your account in sync. We do not receive your full payment card details from Apple.

If you enable push notifications, we store the APNs device token and environment needed to deliver notifications to your device. You can disable notifications in iOS settings.

For the first native iOS release, the app does not load client-side Google tags or Google Ads conversion tracking inside the iOS app and does not use IDFA or cross-app tracking. Server-side operational events, billing verification, fraud prevention, and diagnostics may still be processed to provide and secure the service.

9. Cookies and analytics

On the website and in the Android app, we use necessary local storage and the cookbook_session cookie for sign-in, security, language, and your privacy choices. These functions do not require optional-cookie consent.

Only with your permission, we load Google tags for Google Analytics. Google may then receive usage events and technical browser or device information under its own privacy policy. We do not enable personalized advertising. You can accept or reject analytics and change your choice at any time through Cookie settings in the footer.

The native iPhone and iPad app does not load these client-side Google tags.

10. Recipe import suggestions

When you browse the feed or search for recipes, we may show suggestion cards from our own index — recipes from public websites and YouTube videos that you can import into your collection.

Your search query is not sent to any external search provider. If you use smart (semantic) search — a premium feature — the query text is sent to our AI provider for the sole purpose of turning it into a numeric vector; the search itself runs on our own infrastructure. We do not use these queries to build an advertising profile.

The index itself is built from public sources: the Common Crawl web archive and the official YouTube Data API. We store titles, descriptions, metadata, and links — never cooking steps or ingredient quantities.

An import starts only when you press the import button. It uses your credits and follows the same rules as importing a link yourself.

11. Contact

For any privacy-related questions, contact us at: support@cookbooksocial.app