Privacy Policy

Last updated: August 5, 2026

Effective date: 5 August 2026

ReciDeck is operated by Bruno Dini, an individual developer established at Via Vecchia Pesciatina 912B, 55100 Lucca (LU), Italy. Bruno Dini is the data controller for the personal data described here.

This policy explains what data we collect, why, and what your rights are. The short version: we collect what the app needs to work — your account, your recipes — and nothing else. No ads, no data sales, no tracking, no analytics profiles, and we do not use your content to train AI models.

1. What we collect

Account data. Your email address, name, optional @username, and optional avatar photo. If you sign in with Apple or Google, we receive your email and name from them; we never see your Apple or Google password.

Your content. The recipes you save or import, your collections, grocery lists, photos you upload, ratings and notes, and your family group membership.

Links you import. When you import a recipe from a link (TikTok, Instagram, YouTube, a website) or a photo, we process that link or image on our servers to extract the recipe. Extracted recipe content from public links may be cached on our servers so the same public post doesn't need to be re-processed for other users; this cache contains the public post's recipe content, not your identity.

Subscription data. Your plan tier and subscription status, and the anonymous purchase identifiers our subscription provider receives from the App Store. We never see your payment card, bank details, or billing address — those stay with Apple (and, in future, Google).

Technical data. A user ID, and a push-notification token for your device, so we can deliver share and import notifications. Push tokens are never visible to other users.

What we do not collect: location, contacts, health data, browsing history, or advertising identifiers. We do not track you across apps or websites, as defined by Apple's App Tracking Transparency framework, and we do not build advertising or behavioural profiles.

Diagnostics and product analytics. We do not use analytics or crash-reporting tools today. We may introduce them as ReciDeck grows. If we do, they would collect technical data only — errors and their context, which screens and features are used — in aggregate, never linked to the content of your recipes, and never used for advertising, profiling, or sale. We will update this policy and our App Store privacy labels before switching anything on, and you will be able to object in the app.

2. Why we use it, and on what legal basis

To perform our contract with you (Art. 6(1)(b) GDPR) — because these are the things you signed up for:

  • storing and syncing your recipes, and running the sharing and family features

  • processing the links, captions, transcripts, and images you import, including with AI models, to produce a structured recipe

  • generating a recipe cover image when no usable photo exists

  • sending account emails: sign-up codes, password reset, email-change codes, and the welcome email

  • managing your subscription and unlocking your plan

For our legitimate interests (Art. 6(1)(f) GDPR) — you may object to any of these at any time:

  • caching recipe content extracted from public links, so the same public post isn't processed repeatedly, which keeps the service fast and cheap to run

  • detecting and preventing abuse of the import system, to keep the service available and affordable for everyone

  • diagnostics, crash reports, and aggregated product analytics, if we introduce them (see §1)

With your consent (Art. 6(1)(a) GDPR):

  • marketing email, if we ever send it. Opt-in, withdrawable at any time, and it never affects account emails.

We do not sell your data, and we do not share it with anyone except the processors listed in §5, acting on our instructions.

Three commitments that will not change, whatever else we add later: we will never sell or rent your personal data, we will never show you advertising inside ReciDeck, and we will never use your recipes or your content to train AI models.

We do not use your content to train AI models. All model calls are routed through OpenRouter to Google's Gemini models for text, vision, and image generation, and to Groq running Whisper for audio transcription. Prompt logging and training-enabled endpoints are disabled on our OpenRouter account, and neither Google's paid-API terms nor Groq's terms permit training on customer data. Google retains prompts briefly to detect abuse of its service; Groq does not permanently retain prompts or outputs.

3. Who can see what, inside the app

  • Public accounts (the default) can be found in search by name or @username. Private accounts never appear in search; a private profile is readable only by you, your family members, and people you have exchanged a share or invite with. This is enforced in our database, not just in the app.

  • Profile data ever visible to other users: name, @username, avatar, plan tier, family membership. Your email address is never shown to other users.

  • Family members see your content only inside collections and grocery lists that were explicitly shared with the family — never your personal library. Sharing collections and lists this way is available only within a family group.

  • When you share a recipe, its content snapshot is visible only to you and the recipient.

4. Where your data is stored and processed

Storage. Your account, recipes, images, and all other persistent data are stored in the European Union (Frankfurt). Database backups are taken daily and retained for 7 days, in the same region.

Processing. Some processing happens elsewhere:

  • Application functions execute at the network edge nearest to you. If you are in Europe your requests are handled in Europe; if you are elsewhere, they are handled closer to you. Persistent data always returns to Frankfurt.

  • Video frame sampling for imports runs in the EU (Belgium).

  • AI processing — recipe extraction, transcription, and image generation — runs on our providers' global infrastructure, primarily in the United States. See §5.

5. Processors and international transfers

We use a small set of providers to run ReciDeck, each receiving only what its function requires:

Provider Function Processing location Supabase Database, authentication, file storage EU — Frankfurt (eu-central-1); functions at the edge nearest you RevenueCat Subscription status and entitlements United States Loops Sending account emails United States Expo Delivering push notifications United States OpenRouter Routing our AI requests United States Google (Gemini via OpenRouter) Recipe extraction from text and images; cover image generation Google's global infrastructure, primarily United States Groq (Whisper) Transcribing audio of videos you import United States Google Cloud Run Sampling video frames of imports EU — Belgium (europe-west1) ScrapeCreators, HikerAPI Fetching the public posts you ask us to import United States Apple, Google Sign-in and payment, if you choose those methods Global

Content-fetching providers. ScrapeCreators and HikerAPI receive only the public URL you asked us to import. No account data, email address, or user identifier is sent to them.

Changes to this list. We may add, replace, or remove providers as the service develops — for example if we introduce diagnostics, or change email or AI providers. Any new provider is bound by the same terms, and we will update this list when it happens.

Your account and content sit in the EU. Some processing takes place outside it, including in the United States. Where that happens, the transfer is covered by the European Commission's Standard Contractual Clauses, incorporated in a Data Processing Agreement with each provider, and by the EU–US Data Privacy Framework where the provider is certified.

6. How long we keep it

  • Your account data and content are kept while your account exists.

  • When you delete your account (in the app, under My Account), deletion is immediate. Your recipes, images, collections, lists, family memberships, and notifications are removed from our live systems within seconds, your sessions are revoked, and your records with our email and subscription providers are deleted at the same time. There is no grace period and no way to recover the account afterwards.

What survives, and why

  • Backups. Our database backups are taken daily and retained on a rolling 7-day cycle. A copy of your data persists in those backups until they age out, after which it is gone.

  • Copies other users accepted. Recipes you shared that another user accepted are their own independent copies, and remain theirs. The same applies to recipes merged into a family collection where another member holds a claim.

  • Anonymous cached content. Recipe content extracted from public links, and the generated cover images reused across accounts, are kept without any link to your identity.

  • Your App Store subscription. Deleting your ReciDeck account does not cancel a subscription bought through Apple. Apple holds that record and continues billing until you cancel it in your Apple Account settings.

7. Your rights

Under the GDPR, and under equivalent laws including Brazil's LGPD, you have the right to access, correct, export, delete, and restrict or object to the processing of your personal data, and to withdraw consent where processing is based on it.

Most of this you can do directly in the app. For anything else, email privacy@recideck.com and we will respond within 30 days.

You also have the right to lodge a complaint with a supervisory authority. Ours is the Italian Garante per la protezione dei dati personali (www.gpdp.it), and you may also complain to the authority where you live.

8. Security

Your data is stored in the EU with access controls enforced at the database level, so the visibility rules in §3 hold regardless of the app. Connections are encrypted in transit. No system is perfectly secure, but if a breach ever affects your personal data, we will notify the Garante within 72 hours and tell you directly where the law requires it.

9. Children

ReciDeck is for users aged 16 and over. We do not knowingly collect data from anyone younger, and we will delete any account we become aware of. If you believe a child has created an account, email privacy@recideck.com

10. Changes

If this policy changes materially, we will notify you in the app or by email before the change takes effect.

11. Contact

Privacy questions and requests: privacy@recideck.com

Operator
Bruno Dini
Via Vecchia Pesciatina 912B
55100 Lucca (LU), Italy