Privacy Policy

Last updated: August 2026

At ChefsBook, we believe your recipes and your data are yours. We built this app for people who love cooking — not for advertisers. Here's exactly what we collect and why.

1. What we collect

  • Account information — your email address, display name, and username
  • Recipe data — recipes you import, scan, speak, or create
  • Usage data — which features you use (we use this to improve the app, never sold)
  • Photos — images you upload to recipes, stored on our own server
  • Shopping lists, meal plans, and preferences you create
  • Cooking activity and notes — when you cook a recipe and any notes you write about it (see "Cooking activity and notes" below)
  • Feedback messages you submit through the app

2. What we do NOT collect

  • We do not sell your data to anyone — ever
  • We do not show ads
  • We do not share your data with third parties except the services listed below
  • We do not collect payment information directly — if billing is active, it's handled securely by Stripe

3. Third-party services

These are every external service ChefsBook sends data to, and what each one receives.

  • Supabase — database and file storage (self-hosted on our own server, not Supabase cloud).
  • Anthropic (Claude) — used for two separate things, which section 4 explains because they are not governed the same way. AI features you ask for: recipe extraction, scanning, translation, suggestions, the Sous Chef. Recipe text and photos you scan are sent for processing. Safety checks: recipes you publish, comments, tags, usernames and messages are sent to be checked before and after they appear. Under Anthropic's API terms none of this content is used to train their models.
  • Replicate — AI image generation. A recipe's title and description are sent to generate an illustrative image.
  • Resend — transactional email (welcome, password reset). Receives your email address.
  • ScrapingBee — fallback page fetching when a recipe site blocks a direct request. Receives only the URL you asked us to import.
  • YouTube / Google — importing a recipe from a video. Receives the video URL you provide.
  • Google Books — looking up cookbook details. Receives the book title or ISBN you search for.
  • Google Photos — optional. Only if you choose to import a photo from it. You pick the photos in Google's own picker; we download those photos server-side and re-host them, so we never store a Google link. The access token lives in a session cookie and no long-lived refresh token is kept.
  • Lulu — print-on-demand, only if you order a physical cookbook. Receives your order and shipping details in order to print and deliver it.
  • Stripe — payment processing, if and when billing is active. Card details go directly to Stripe; we never receive or store them.
  • Pexels and Unsplash — stock photo suggestions. Receive the search term only; no personal data.
  • Logo.dev — store logo lookup. Receives only the store name.
  • Cloudflare — CDN and secure tunnel. Handles web traffic with standard CDN privacy practices.

4. AI features, and the safety checks you cannot turn off

Two different things here use AI, and they are not governed the same way — one is yours to decline and the other is not. This mirrors section 11 of the Terms of Service; this section is what it means for your data.

AI features you choose. Scanning a recipe, importing from a link or a video, translation, suggestions, generated images, the Sous Chef. These run because you asked for them. We ask your permission once before the first one runs, and you can withdraw that permission at any time in Settings — the features then stop.

Safety checks you cannot turn off. Anything you make visible to other people — a recipe you publish, a comment, a tag, a username, a direct message — is checked automatically before and after it appears. Some of that is simple pattern matching for spam; some of it uses AI. We also keep operational records of AI usage, cost and rate limits so we can spot misuse of the AI features themselves.

We do not ask your permission for those checks, and turning AI features off does not switch them off. Our lawful basis for them is legitimate interest — ours and every other user's, in a service that is safe and lawful to be in — not your consent. Asking an author's permission to check that author's own content would let anyone opt out of being checked simply by saying no.

What declining actually costs you. You keep private ChefsBook in full: your recipes, meal plans, shopping lists, cooking, printed cookbooks. You lose the parts other people can see — publishing publicly or by link, comments, likes, follows, direct messages, sharing with other users. We would rather make those unavailable than put unchecked content in front of someone else.

The checks themselves are limited: they flag content for a person to look at, and in serious cases hide it immediately pending that review. They do not decide anything final on their own — a human makes the call on anything contested. You can object to this processing, or ask a human to look again, at support@chefsbk.app.

5. Browser extension

The ChefsBook browser extension captures the HTML of pages you explicitly choose to import. This HTML is sent to our servers for recipe extraction only. We do not capture your browsing history or any pages you did not choose to import. The extension stores your ChefsBook login token locally in Chrome storage.

6. Data storage

All user data is stored on our own dedicated self-hosted server, located in the United States. Your data is not stored in third-party cloud services — we self-host the database and all uploaded images. Backups are stored locally on the same server.

7. Your rights

  • You can delete your account and all associated data at any time from Settings
  • You can export your recipes in CSV or JSON format from Settings
  • You can withdraw your permission for AI features at any time in Settings. This does not stop the safety checks in section 4 — those do not run on your consent.
  • You can object to the safety checks, or ask a human to look again at a decision. Section 4 is honest about the consequence: we cannot leave the social parts of ChefsBook unchecked, so objecting means using ChefsBook privately.
  • You can ask us to correct anything we hold about you that is wrong.
  • You can contact us at support@chefsbk.app with any data questions
  • If you are in the UK, EU or EEA, you can complain to your data protection authority. We would rather you told us first, but it is your right either way.

8. Cooking activity and notes (admin visibility)

When you cook a recipe in ChefsBook, we record cooking activity — what you cooked, when, and whether the session was completed — to power features like your cooking history and the Sous Chef's guidance. If you write a note during or after a cooking session (for example, a substitution or a reminder for next time), that note is stored with your account and is visible only to you in the app — it is never shown to other users, on public recipe pages, or in any feed.

Administrators can view aggregate cooking activity (such as how many sessions happen per day, or which recipes are cooked most) to understand how the app is used. Administrators can also look up individual cooking activity, including who cooked what and when, and can read the text of cooking notes, when needed to operate, support, or improve the app. This admin access is a deliberate exception to the "visible only to you" rule above, and is limited to administrators — it does not change who else can see your activity or notes.

9. Cookies

We use session cookies for authentication only. We do not use tracking cookies, advertising cookies, or any third-party analytics cookies.

10. Children

ChefsBook is not directed at children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal data, please contact us and we will delete it.

11. Changes to this policy

If we make significant changes to this privacy policy, we will notify registered users by email. Minor wording changes may be made without notification.

12. Contact

Questions about your privacy? We're happy to help.

Email: support@chefsbk.app
Website: chefsbk.app