Privacy Policy
Last updated: 16 August 2026
Effective date: 15 August 2026
ReciDeck is operated by Bruno Dini, an individual developer established at Via Vecchia Pesciatina 912B, 55100 Lucca (LU), Italy. Bruno Dini is the data controller for the personal data described here.
This policy explains what data we collect, why, and what your rights are. The short version: we collect what the app needs to work — your account, your recipes — plus a small set of product-usage events so we can see how the app is used. No ads, no data sales, no cross-app tracking, and we do not use your content to train AI models.
1. What we collect
Account data. Your email address, name, optional @username, and optional avatar photo. If you sign in with Apple or Google, we receive your email and name from them; we never see your Apple or Google password.
Your content. The recipes you save or import, your collections, grocery lists, photos you upload, ratings and notes.
Links you import. When you import a recipe from a link (TikTok, Instagram, YouTube, a website) or a photo, we process that link or image on our servers to extract the recipe. Extracted recipe content from public links may be cached on our servers so the same public post doesn't need to be re-processed for other users; this cache contains the public post's recipe content, not your identity.
Subscription data. Your plan tier and subscription status, and the anonymous purchase identifiers our subscription provider receives from the App Store. We never see your payment card, bank details, or billing address — those stay with Apple (and, in future, Google).
Technical data. A user ID, and a push-notification token for your device, so we can deliver share and import notifications. Push tokens are never visible to other users. Our analytics tool also receives your device model, operating system and app version, language, timezone, screen size, network type, and IP address.
Usage analytics. We record a small, fixed set of product events — an import started or failed, a paywall shown, onboarding completed, a photo pack bought — together with the screens you visit. Screens are recorded as route patterns such as /recipe/[id], never the recipe itself, so a screen view can never identify a recipe. These events are tied to your account ID so we can understand how the app is used and what to improve.
We do not use session recording, screen capture, or automatic tap tracking, and we do not send your recipes, links, photos, grocery lists, names or email address to our analytics provider. Our provider is PostHog, hosted in the European Union. Their SDK also receives the technical data listed above, including your IP address, which is used to derive an approximate country and region.
We have no crash-reporting or performance-monitoring tool. If we add one, we will update this policy and our App Store privacy labels first.
What we do not collect: contacts, health data, browsing history, advertising identifiers, or your device's location. The app never requests location access; our analytics provider derives an approximate country and region from your IP address, which is not the same as device location. We do not track you across apps or websites, as defined by Apple's App Tracking Transparency framework, and we do not build advertising or behavioural profiles.
2. Why we use it, and on what legal basis
To perform our contract with you (Art. 6(1)(b) GDPR) — because these are the things you signed up for:
storing and syncing your recipes, and running the sharing features
processing the links, captions, transcripts, and images you import, including with AI models, to produce a structured recipe
generating a recipe cover image when no usable photo exists
sending account emails: sign-up codes, password reset, email-change codes, and the welcome email
managing your subscription and unlocking your plan
For our legitimate interests (Art. 6(1)(f) GDPR) — you may object to any of these at any time:
caching recipe content extracted from public links, so the same public post isn't processed repeatedly, which keeps the service fast and cheap to run
detecting and preventing abuse of the import system, to keep the service available and affordable for everyone
product analytics, to understand how the app is used and where it fails, so we can improve it
writing to you once after you cancel a trial or a subscription, to ask why and whether we could have done better. It is a single message, it contains no offer and nothing to buy, and one reply telling us to stop is enough, we will not write again
With your consent (Art. 6(1)(a) GDPR):
email that is not about your account: product updates, new features, articles and cooking tips. We do not send this today. If we ever do, it will be opt-in only, never pre-ticked, and never assumed from signing up or subscribing, and you will be able to withdraw at any time from the unsubscribe link in every message. It would never affect account emails, the cancellation message above, or anything about how the app works for you.
We do not sell your data, and we do not share it with anyone except the processors listed in §5, acting on our instructions.
Three commitments that will not change, whatever else we add later: we will never sell or rent your personal data, we will never show you advertising inside ReciDeck, and we will never use your recipes or your content to train AI models.
We do not use your content to train AI models. All model calls are routed through OpenRouter to Google's Gemini models for text, vision, and image generation, and to Groq running Whisper for audio transcription. Prompt logging and training-enabled endpoints are disabled on our OpenRouter account, and neither Google's paid-API terms nor Groq's terms permit training on customer data. Google retains prompts briefly to detect abuse of its service; Groq does not permanently retain prompts or outputs.
3. Who can see what, inside the app
Public accounts (the default) can be found in search by name or @username. Private accounts never appear in search; a private profile is readable only by you and people you have exchanged a share or invite with. This is enforced in our database, not just in the app.
Profile data ever visible to other users: name, @username, avatar, plan tier. Your email address is never shown to other users.
When you share a recipe, its content snapshot is visible only to you and the recipient.
4. Where your data is stored and processed
Storage. Your account, recipes, images, and all other persistent data are stored in the European Union (Frankfurt). Database backups are taken daily and retained for 7 days, in the same region.
Processing. Some processing happens elsewhere:
Application functions execute at the network edge nearest to you. If you are in Europe your requests are handled in Europe; if you are elsewhere, they are handled closer to you. Persistent data always returns to Frankfurt.
Video frame sampling for imports runs in the EU (Belgium).
Product analytics are processed in the European Union.
AI processing — recipe extraction, transcription, and image generation — runs on our providers' global infrastructure, primarily in the United States. See §5.
5. Processors and international transfers
We use a small set of providers to run ReciDeck, each receiving only what its function requires:
Supabase — database, authentication, and file storage. EU (Frankfurt, eu-central-1); functions run at the edge nearest you.
PostHog — product analytics. European Union.
RevenueCat — subscription status and entitlements. United States.
Loops — Loops — sending our email: account emails, and the one-off message after a cancellation. Receives your email address, first name, and app language. United States.
Expo — delivering push notifications. United States.
OpenRouter — routing our AI requests. United States.
Google (Gemini via OpenRouter) — recipe extraction from text and images, and cover image generation. Google's global infrastructure, primarily United States.
Groq (Whisper) — transcribing the audio of videos you import. United States.
Google Cloud Run — sampling video frames of imports. EU (Belgium, europe-west1).
ScrapeCreators and HikerAPI — fetching the public posts you ask us to import. United States.
Apple and Google — sign-in and payment, if you choose those methods. Global.
Content-fetching providers. ScrapeCreators and HikerAPI receive only the public URL you asked us to import. No account data, email address, or user identifier is sent to them.
Analytics provider. PostHog receives your account ID, the product events and screen names described in §1, device and app metadata, and your IP address. It never receives your email address, your name, or any of your content.
Changes to this list. We may add, replace, or remove providers as the service develops — for example if we introduce diagnostics, or change email or AI providers. Any new provider is bound by the same terms, and we will update this list when it happens.
Your account and content sit in the EU. Some processing takes place outside it, including in the United States. Where that happens, the transfer is covered by the European Commission's Standard Contractual Clauses, incorporated in a Data Processing Agreement with each provider, and by the EU–US Data Privacy Framework where the provider is certified.
6. How long we keep it
Your account data and content are kept while your account exists.
When you delete your account (in the app, under My Account), deletion is immediate. Your recipes, images, collections, lists, and notifications are removed from our live systems within seconds, your sessions are revoked, and your records with our email, subscription, and analytics providers are deleted at the same time. There is no grace period and no way to recover the account afterwards.
What survives, and why
Backups. Our database backups are taken daily and retained on a rolling 7-day cycle. A copy of your data persists in those backups until they age out, after which it is gone.
Copies other users accepted. Recipes you shared that another user accepted are their own independent copies, and remain theirs.
Anonymous cached content. Recipe content extracted from public links, and the generated cover images reused across accounts, are kept without any link to your identity.
Your App Store subscription. Deleting your ReciDeck account does not cancel a subscription bought through Apple. Apple holds that record and continues billing until you cancel it in your Apple Account settings.
7. Your rights
Under the GDPR, and under equivalent laws including Brazil's LGPD, you have the right to access, correct, export, delete, and restrict or object to the processing of your personal data, and to withdraw consent where processing is based on it.
Most of this you can do directly in the app. For anything else, email privacy@recideck.com and we will respond within 30 days.
You also have the right to lodge a complaint with a supervisory authority. Ours is the Italian Garante per la protezione dei dati personali (www.gpdp.it), and you may also complain to the authority where you live.
8. Security
Your data is stored in the EU with access controls enforced at the database level, so the visibility rules in §3 hold regardless of the app. Connections are encrypted in transit. No system is perfectly secure, but if a breach ever affects your personal data, we will notify the Garante within 72 hours and tell you directly where the law requires it.
9. Children
ReciDeck is for users aged 16 and over. We do not knowingly collect data from anyone younger, and we will delete any account we become aware of. If you believe a child has created an account, email privacy@recideck.com
10. Changes
If this policy changes materially, we will notify you in the app or by email before the change takes effect.
11. Contact
Privacy questions and requests: privacy@recideck.com
Operator
Bruno Dini
Via Vecchia Pesciatina 912B
55100 Lucca (LU), Italy