← Cookbook

Privacy Policy

Last updated: 3 October 2026

1. Who we are

Cookbook Company ("we", "us", "our") provides the Cookbook app, as a mobile app and as a web app. We are the controller of the personal data described in this policy: we decide why and how it is processed. This policy explains what we collect, why, who receives it, how long we keep it, and what you can do about it.

2. Data we collect

Data you give us:

  • Account data: your name and email address, and your password. The password is never stored as such, only as a salted Argon2id hash.
  • Account settings: the account name, your preferred language and measurement system (metric or imperial), and the optional custom instructions you write for the AI assistant.
  • Your recipes and organisation: recipe names, ingredients, directions, descriptions, nutrition information and notes, categories, favorites, archive and trash state, and your ingredient and measure dictionaries.
  • Photos and videos you attach to recipes, and their file names.
  • AI assistant data: your chat messages and the assistant's replies, and the "memories" you or the assistant save.

Data created while you use the App:

  • Session data: when you log in the server creates a session. It is valid for 30 days or until you log out. The session token is kept on your device: in secure storage (Android Keystore / iOS Keychain) in the mobile app, and in the local storage of your browser in the web app.
  • Audit log: for every action that changes data (creating or editing a recipe, logging in, changing a setting, and so on) we record who did it, when, which kind of action it was, the affected record before and after the change, the request that was sent (with passwords removed) and whether it succeeded. You can see your account's audit log in the App. We do not record your IP address or device information in the audit log.
  • Technical logs: the servers and cloud services that run the App may keep standard technical and security logs (for example request time and IP address) for a limited period.
  • Information that stays on your device: your timers, the light/dark theme, the cached language, your user profile, struck-through ingredient lines, your last selected category and, in the mobile app, cached images. In the web app this is kept in the local storage of your browser. It is not sent to us. The web app does not use cookies.

What we do not collect: we do not use advertising, analytics or crash-reporting services in the App, we do not track you across other apps or websites, and we do not access your location or contacts. We do not sell your personal data.

3. Device and browser permissions

  • Camera (mobile app): only when you choose to take a photo or video for a recipe. On iOS the microphone is also used while you record a video.
  • Photos and videos: the App uses the system or browser file picker, so it only receives the files you select. It does not get access to your whole gallery or your files.
  • Notifications (mobile app): only to tell you that a cooking timer has finished (Android 13 and later ask when you start your first timer). These are local notifications created on your device; no push notification service is used.
  • The screen is kept awake while you view a recipe. This needs no permission and no data leaves your device.

In the web app your browser asks for access itself when you pick or capture a file, and the screen wake lock is requested through the browser. You can withdraw any permission at any time in the settings of your device or browser. The related feature then stops working, the rest of the App keeps working.

4. Why we use your data

  • To create and secure your account, log you in, and send you confirmation and password-reset codes by email.
  • To store, show and search your recipes, categories, dictionaries and media, and to keep them in sync between your devices.
  • To run the AI assistant and to turn the ingredients text of a recipe into a structured ingredient list in the background.
  • To keep an audit trail of changes to your account, to detect and prevent abuse, and to keep the service secure and working.
  • To answer your questions, to comply with legal obligations and to establish or defend legal claims.

Where the EU/UK GDPR or similar laws apply, our legal bases are: performing our contract with you (running your account and the features you use), our legitimate interests (security, abuse prevention, the audit log and improving reliability), your consent (device permissions such as camera and notifications) and legal obligations.

5. Who receives your data

We share data only with service providers that process it for us, and only as far as needed:

  • AI provider (Anthropic): powers the assistant and the ingredient parsing. When you chat, we send it your messages, your name, your account language and measurement system, your custom instructions and memories, and the recipe, category, dictionary and account information that the assistant looks up to answer you. When a recipe is created or its ingredients change, we send it the ingredients text and your dictionary entries to produce the structured list. We do not send it your email address, your password, or your photos and videos. The provider handles this data under its own terms and privacy policy.
  • Cloud infrastructure (Amazon Web Services): runs the backend API and its background job scheduling, and stores your photos and videos in cloud storage. Media files are stored under randomly generated names.
  • Email delivery: your email address and the confirmation or reset code are passed to the email delivery service we use to send you that message.

Other people in a shared account can see the content of that account, including recipes, categories, media and the audit log entries of the account. Chat conversations and your user profile belong to you personally.

We may also disclose data if the law or a valid legal request requires it, to protect our rights and the safety of users, or to a successor if the business is transferred. We will keep this to what is necessary.

6. International transfers

Our API runs on AWS in the eu-west-2 (London) region. Our AI provider may process data in other countries, including the United States. Where the law requires it, these transfers rely on safeguards such as adequacy decisions or standard contractual clauses.

7. How long we keep your data

  • We keep your data for as long as your account exists.
  • Recipes you delete go to the trash and stay there until you delete them permanently or delete your account.
  • When you remove a photo or video from a recipe it disappears from the App immediately. The file may remain in cloud storage until it is cleaned up.
  • Sessions expire after 30 days or when you log out. Password-reset codes expire after a limited time.
  • Technical logs are kept for a limited period and then deleted.

8. Deleting your account and data

Open Account in the App, enter your password in "Delete account" and confirm. This is immediate and cannot be undone. All your sessions stop working at once.

  • If you are the last user of the account, we erase the user and the whole account: recipes with their media, categories, ingredient and measure dictionaries, chat conversations and messages, memories and the audit log. Uploaded media files are also removed from cloud storage.
  • If other people still belong to the account, we erase your user, your sessions, your chat conversations and your audit entries. The shared content of the account stays for the other users.

Copies in backups, if any are kept, and in technical logs are removed when they expire. If you cannot use the App, contact us and we will help you delete your data.

9. Security

We protect your data with measures such as: password hashing with Argon2id, encrypted connections (HTTPS) between the App and the server in production, storing your session token in the secure storage of your device (mobile app) or in your browser (web app), and access rules that limit each request to the data of the logged-in account. No system is completely secure, so we cannot guarantee absolute security. Choose a strong, unique password.

10. Your rights

Depending on where you live, you may have the right to:

  • access the personal data we hold about you and get a copy of it;
  • correct inaccurate data (you can edit your name, account settings and content in the App);
  • delete your data (see the previous section);
  • restrict or object to certain processing, including processing based on our legitimate interests;
  • receive your data in a portable format;
  • withdraw consent you have given, without affecting what was done before;
  • complain to your local data protection authority.

To use a right that you cannot use inside the App, contact Cookbook Company using the support contact shown on the App's store page. We may need to confirm your identity first. We do not sell or share personal information for advertising, and we do not make decisions about you based only on automated processing that have legal or similarly significant effects on you.

11. Children

The App is not intended for children under 16. We do not knowingly collect personal data from them. If you believe a child has given us personal data, contact us and we will delete it.

12. Changes to this policy

We may update this policy when the App or the law changes, for example if we add a new service provider or a new kind of data. The date at the top shows when it was last updated. If a change is material we will tell you in the App before it takes effect.

13. Contact

For any question about this policy or your data, contact Cookbook Company using the support contact shown on the App's store page.