← Back to the site

Privacy policy

Last updated: 3 August 2026

This policy explains what happens to your data when you use Chefkin, the app that turns a link, a video or a photo of a cookbook page into a structured recipe. It is written to be read rather than endured — if something here does not sit right, tell us.

Who handles your data

The data controller is Le Hung Martino.

For anything to do with this policy or your data, write to privacy@chefkin.app.

What we collect

We collect what the app needs to work. We do not buy data from anyone and we do not sell yours.

DataWhere it comes fromWhat it is for
Email address, the sign-in method you used (Apple, Google or an email link), language and unit systemfrom signing upidentifying your account and syncing your devices
Dietary preferences, allergies and intolerances, household size, goals, cooking level, optional calorie targetfrom the onboarding quiz, which you can skip entirelyfiltering recipes and building plans that respect your constraints
Recipes you import or write, ingredients, steps, tags, collections, shopping lists, weekly plansfrom your use of the appthis is your library
Diary: what you cooked or ate, photos of dishes you take, the nutrition estimates attached to themfrom your use of the diary and food scankeeping the diary and adding up totals
Files you upload: Paprika archives, photos of cookbook pages, audio pulled from videosfrom imports you startrunning that one import, nothing else
Subscription statusfrom RevenueCat, which receives the purchase result from Apple or Googleknowing which plan is active
Usage events, AI pipeline consumption, error reportsgenerated by the appseeing what breaks and what each feature costs to run

We never receive your card details. Purchases go entirely through the App Store and Google Play — all we see is whether the subscription is active.

Files you upload for an import are a staging step, not storage: once the job finishes the row is deleted. Photos you choose to attach to your diary stay, because those you want to look at again.

Allergies and health data

Under the GDPR, allergies, intolerances and nutrition targets are health data: a special category (Article 9) that has to be handled more carefully than the rest.

We process them only with your explicit consent, which we ask for at the moment you fill in that part of the quiz. You can skip it — the app stays fully usable, you just lose the automatic filter. You can withdraw consent at any time by clearing those fields in your profile settings, and the values are erased when you do.

We do not use this data for advertising or profiling, we do not pass it to third parties for their own purposes, and we do not combine it with anything else.

One warning that matters more than compliance: the allergen filter is a help, not a safety guarantee. Recipes come from external sources interpreted by a model, and the model can misread an ingredient. If an allergy puts you at real risk, always check the ingredient list yourself.

Why we process data, and on what legal basis

PurposeLegal basis
Creating and keeping your account, syncing devices, running the library, imports, shopping list and cooking modeperformance of the contract (Art. 6.1.b)
Managing the subscription and free-plan limitsperformance of the contract (Art. 6.1.b)
Filtering recipes and plans by diet, allergies and goalsexplicit consent (Art. 9.2.a)
Diagnosing errors, measuring AI pipeline costs, understanding which features get usedlegitimate interest in running and sustaining the service (Art. 6.1.f)
Sending service email: sign-in links, receipts, important noticesperformance of the contract (Art. 6.1.b)
Non-essential push notificationsconsent, revocable in your system settings
Keeping tax and accounting recordslegal obligation (Art. 6.1.c)

What gets sent to the AI models

This is worth being explicit about, because it is the heart of the app. When you start an import or use an AI feature, the content that operation needs is sent to a model provider:

  • Text and URLs — the page or text you paste, so the recipe can be extracted from it.
  • Images — the photo of the cookbook page or of the dish, to read it or estimate its nutrition.
  • Audio — the audio track pulled from the video, to transcribe it. We never re-upload or re-host the video itself.
  • Your food profile — only when you generate a plan or talk to the assistant, and only so your constraints are respected.

The providers are listed in the table below. With each of them we have, or will have before launch, an agreement that rules out using your content to train their models.

Of each call we keep the result and a cryptographic fingerprint of the input, not the input itself: it lets us recognise that a source has already been processed and avoid doing — and paying for — the same work twice.

Who else touches your data

These are all providers acting on our behalf, contractually bound to use the data only to deliver the service to us.

ProviderWhat it doesWhat it sees
AnthropicClaude models that extract and structure recipesthe content of the import
OpenAIGPT models and image generationthe content of the import, dish photos
Groqtranscribing audio from videosthe audio track
Cloudflareimage storage (R2), encrypted database backups, and the HTTPS entry point for trafficthe photos you attach, and the database contents inside backups
Supabasemanaged Postgres database, in Frankfurteverything in your account
RevenueCatsubscription managementan identifier and the subscription status
PostHogproduct analyticspseudonymous usage events
Sentryerror reportingtechnical crash data
Resendsending service emailyour email address
Hetznerthe server running the API, worker and queuesdata as it passes through processing

We disclose data to public authorities only where the law requires it.

Where the data lives

The database sits in Frankfurt, on Supabase. The application servers, the worker and the job queues run on Hetzner, in its European Union datacentres. Images and backups live on Cloudflare R2, stored in the European region.

The AI model providers and some supporting services are US-based, so for those calls data leaves the European Economic Area. Those transfers rely on the European Commission's Standard Contractual Clauses, or on the Data Privacy Framework where the provider is certified under it.

How long we keep it

  • Account and content — as long as the account exists. Delete it and they go.
  • Files uploaded for an import — for the duration of the job, then deleted.
  • Technical logs and errors — 90 days at most.
  • Usage events — aggregated and no longer traceable to you, kept without a time limit.
  • Tax records — 10 years, as the law requires. They are the only data that survives account deletion.

Your rights

You can ask for access, rectification, erasure, restriction, portability, and object to processing. Where processing rests on consent, you can withdraw it at any time without affecting what was lawful before.

Two of these are built into the app, so you never have to ask anyone's permission:

  • Portability — export your whole library as JSON or as a Paprika archive, so leaving stays a real option.
  • Erasure — delete your account from the settings. It is a real deletion, not a deactivation: linked data is removed by cascade and your photos are purged from storage. See the dedicated page.

For everything else write to privacy@chefkin.app and we will answer within 30 days. If you think we are getting it wrong, you can complain to the data protection authority where you live.

Security

Traffic is encrypted in transit, access to production systems is limited to the people who need it to work, and there are no passwords: you sign in with Apple, Google or a temporary email link, which removes the reused-password problem at the root.

Children

Chefkin is not meant for anyone under 16 and we do not knowingly collect their data. If we find an account belonging to someone younger, we delete it. If you are a parent and think that has happened, write to us.

This website

chefkin.app is a static site and does not profile you. It uses no analytics or marketing cookies.

It stores exactly two things on your device, both technical and both triggered by something you did: a chefkin_lang cookie, which remembers for a year the language you picked with the switch at the top, and a chefkin-theme entry in local storage, which remembers whether you prefer the light or dark theme. Neither ever leaves your device.

Changes

If we change something substantial we update the date at the top, and where the change affects your rights or widens the purposes, we tell you by email or in the app before it takes effect.