Privacy policy
Last updated: 3 August 2026
This policy explains what happens to your data when you use Chefkin, the app that turns a link, a video or a photo of a cookbook page into a structured recipe. It is written to be read rather than endured — if something here does not sit right, tell us.
Who handles your data
The data controller is Le Hung Martino.
For anything to do with this policy or your data, write to privacy@chefkin.app.
What we collect
We collect what the app needs to work. We do not buy data from anyone and we do not sell yours.
| Data | Where it comes from | What it is for |
|---|---|---|
| Email address, the sign-in method you used (Apple, Google or an email link), language and unit system | from signing up | identifying your account and syncing your devices |
| Dietary preferences, allergies and intolerances, household size, goals, cooking level, optional calorie target | from the onboarding quiz, which you can skip entirely | filtering recipes and building plans that respect your constraints |
| Recipes you import or write, ingredients, steps, tags, collections, shopping lists, weekly plans | from your use of the app | this is your library |
| Diary: what you cooked or ate, photos of dishes you take, the nutrition estimates attached to them | from your use of the diary and food scan | keeping the diary and adding up totals |
| Files you upload: Paprika archives, photos of cookbook pages, audio pulled from videos | from imports you start | running that one import, nothing else |
| Subscription status | from RevenueCat, which receives the purchase result from Apple or Google | knowing which plan is active |
| Usage events, AI pipeline consumption, error reports | generated by the app | seeing what breaks and what each feature costs to run |
We never receive your card details. Purchases go entirely through the App Store and Google Play — all we see is whether the subscription is active.
Files you upload for an import are a staging step, not storage: once the job finishes the row is deleted. Photos you choose to attach to your diary stay, because those you want to look at again.
Allergies and health data
Under the GDPR, allergies, intolerances and nutrition targets are health data: a special category (Article 9) that has to be handled more carefully than the rest.
We process them only with your explicit consent, which we ask for at the moment you fill in that part of the quiz. You can skip it — the app stays fully usable, you just lose the automatic filter. You can withdraw consent at any time by clearing those fields in your profile settings, and the values are erased when you do.
We do not use this data for advertising or profiling, we do not pass it to third parties for their own purposes, and we do not combine it with anything else.
One warning that matters more than compliance: the allergen filter is a help, not a safety guarantee. Recipes come from external sources interpreted by a model, and the model can misread an ingredient. If an allergy puts you at real risk, always check the ingredient list yourself.
Why we process data, and on what legal basis
| Purpose | Legal basis |
|---|---|
| Creating and keeping your account, syncing devices, running the library, imports, shopping list and cooking mode | performance of the contract (Art. 6.1.b) |
| Managing the subscription and free-plan limits | performance of the contract (Art. 6.1.b) |
| Filtering recipes and plans by diet, allergies and goals | explicit consent (Art. 9.2.a) |
| Diagnosing errors, measuring AI pipeline costs, understanding which features get used | legitimate interest in running and sustaining the service (Art. 6.1.f) |
| Sending service email: sign-in links, receipts, important notices | performance of the contract (Art. 6.1.b) |
| Non-essential push notifications | consent, revocable in your system settings |
| Keeping tax and accounting records | legal obligation (Art. 6.1.c) |
What gets sent to the AI models
This is worth being explicit about, because it is the heart of the app. When you start an import or use an AI feature, the content that operation needs is sent to a model provider:
- Text and URLs — the page or text you paste, so the recipe can be extracted from it.
- Images — the photo of the cookbook page or of the dish, to read it or estimate its nutrition.
- Audio — the audio track pulled from the video, to transcribe it. We never re-upload or re-host the video itself.
- Your food profile — only when you generate a plan or talk to the assistant, and only so your constraints are respected.
The providers are listed in the table below. With each of them we have, or will have before launch, an agreement that rules out using your content to train their models.
Of each call we keep the result and a cryptographic fingerprint of the input, not the input itself: it lets us recognise that a source has already been processed and avoid doing — and paying for — the same work twice.
Who else touches your data
These are all providers acting on our behalf, contractually bound to use the data only to deliver the service to us.
| Provider | What it does | What it sees |
|---|---|---|
| Anthropic | Claude models that extract and structure recipes | the content of the import |
| OpenAI | GPT models and image generation | the content of the import, dish photos |
| Groq | transcribing audio from videos | the audio track |
| Cloudflare | image storage (R2), encrypted database backups, and the HTTPS entry point for traffic | the photos you attach, and the database contents inside backups |
| Supabase | managed Postgres database, in Frankfurt | everything in your account |
| RevenueCat | subscription management | an identifier and the subscription status |
| PostHog | product analytics | pseudonymous usage events |
| Sentry | error reporting | technical crash data |
| Resend | sending service email | your email address |
| Hetzner | the server running the API, worker and queues | data as it passes through processing |
We disclose data to public authorities only where the law requires it.
Where the data lives
The database sits in Frankfurt, on Supabase. The application servers, the worker and the job queues run on Hetzner, in its European Union datacentres. Images and backups live on Cloudflare R2, stored in the European region.
The AI model providers and some supporting services are US-based, so for those calls data leaves the European Economic Area. Those transfers rely on the European Commission's Standard Contractual Clauses, or on the Data Privacy Framework where the provider is certified under it.
How long we keep it
- Account and content — as long as the account exists. Delete it and they go.
- Files uploaded for an import — for the duration of the job, then deleted.
- Technical logs and errors — 90 days at most.
- Usage events — aggregated and no longer traceable to you, kept without a time limit.
- Tax records — 10 years, as the law requires. They are the only data that survives account deletion.
Your rights
You can ask for access, rectification, erasure, restriction, portability, and object to processing. Where processing rests on consent, you can withdraw it at any time without affecting what was lawful before.
Two of these are built into the app, so you never have to ask anyone's permission:
- Portability — export your whole library as JSON or as a Paprika archive, so leaving stays a real option.
- Erasure — delete your account from the settings. It is a real deletion, not a deactivation: linked data is removed by cascade and your photos are purged from storage. See the dedicated page.
For everything else write to privacy@chefkin.app and we will answer within 30 days. If you think we are getting it wrong, you can complain to the data protection authority where you live.
Security
Traffic is encrypted in transit, access to production systems is limited to the people who need it to work, and there are no passwords: you sign in with Apple, Google or a temporary email link, which removes the reused-password problem at the root.
Children
Chefkin is not meant for anyone under 16 and we do not knowingly collect their data. If we find an account belonging to someone younger, we delete it. If you are a parent and think that has happened, write to us.
This website
chefkin.app is a static site and does not profile you. It uses no analytics or marketing cookies.
It stores exactly two things on your device, both technical and both triggered by something you did: a chefkin_lang cookie, which remembers for a year the language you picked with the switch at the top, and a chefkin-theme entry in local storage, which remembers whether you prefer the light or dark theme. Neither ever leaves your device.
Changes
If we change something substantial we update the date at the top, and where the change affects your rights or widens the purposes, we tell you by email or in the app before it takes effect.