Privacy Policy
Last Updated: September 29, 2026
1. Introduction
Welcome to PrepCook.Pro ("we," "our," or "us"). PrepCook.Pro is a recipe management and costing platform designed for chefs, restaurants, and food businesses. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our web application at prepcook.pro, including when you install it to your device's home screen (the "Service").
By using PrepCook.Pro, you agree to the collection and use of information in accordance with this policy. If you do not agree with our policies and practices, please do not use our Service.
2. Information We Collect
2.1 Account Information
When you create an account, we collect:
- Email address or mobile phone number - You need one of them to create an account. If you sign up with a phone number, adding an email address is optional, but you need one to pay for a subscription and to use AI features on the free plan, and it is how you can recover the account if you lose the number
- Phone number - If you sign in with one: verified by a code we text you, and stored by Firebase Authentication (Google) with your sign-in account. We do not copy it into our database
- Password - If you sign in with an email address and password, Firebase Authentication stores your password only as a hash; it is never stored in plaintext, and we never store it ourselves
- Display name - Your chosen name for your account
- Profile photo - The address (URL) of your Google profile picture, if you sign in with Google
- Authentication tokens - Firebase sign-in tokens, and the Google access tokens described in 2.6
- Account records - Your role, when you joined, when you last signed in and were last active, and your analytics choice with the time you made it
If an administrator invites you, they enter your email address and name, and your account is created at that point. Your email address and name are also added to our preview list (2.7), with the date and the administrator who invited you.
If a member of a kitchen workspace invites you to join it, they enter your email address. It is stored on the invitation, with the role offered, and the invitation is deleted automatically 7 days after it is made. Until you answer it or it expires, the kitchen's owner, and for an invitation as a cook any member allowed to invite cooks, can see your address on the kitchen's list of pending invitations. Once you join, the kitchen's members can see each other's names and email addresses on its member list.
2.1.1 Authentication and Security Data
To protect your account, we record the following authentication and security data:
- Sign-in events - Each sign-in to your account (with the sign-in method) and each sign-out, with the time and your browser (user agent). Sign-in events recorded on or before 25 September 2026 also include your email address, until they are deleted 365 days after they were recorded (7.2). You can see your recent sign-ins in your Account settings
- Failed sign-in attempts and password-reset requests - A keyed code derived from the email address that was entered, not the address itself; a keyed code derived from the IP address the request came from; the browser (user agent); and the time. These are recorded before anyone is signed in, and are used to limit repeated attempts. Older records hold the email address and IP address themselves, until they are deleted 365 days after they were recorded (7.2)
- Session records - When you sign in with an email address and password: a random device identifier stored in your browser, the type of device (for example "Mac" or "iPhone"), your browser's user agent, and when the session started, was last active and expires
- Request logs - Google Cloud records the IP address and browser of each request to our servers (see 7.6)
- Text-message counters - To limit abuse and cost, we count the texts sent to each phone number, from each IP address, and in total each day. The counters for a number or an address are stored under a keyed code derived from it, not the number or address itself, and are deleted automatically, normally within three days of the last text
Legal Basis for Processing: We process this security data based on our legitimate interest in protecting your account, preventing fraud, ensuring platform security, and complying with legal obligations.
2.2 Optional Profile Information
You may choose to provide additional profile information when you set up your profile or in your Account settings:
- First name and last name
- Date of birth
- Occupation
2.3 Subscription and Payment Information
If you subscribe to a paid plan, we collect:
- Subscription tier (Free, Pro, or Kitchen)
- Subscription status and billing dates
- Stripe customer ID and subscription ID (processed securely by Stripe)
- Billing name and address, collected by Stripe at checkout to calculate sales tax and VAT (Stripe Tax).
- Payment method information (handled directly by Stripe, not stored by us)
Our own billing record for your account holds your Stripe customer and subscription IDs, the subscription's status, price and billing period, and the plan it gives you. It holds no card details.
2.4 User Content
You create and store content through our Service, including:
- Recipes - Ingredients, instructions, costing data, notes, technical specifications (ABV, Brix, pH, etc.), yield information, and scaling parameters. Each saved version of a recipe is kept
- Ingredients - Custom ingredient entries with technical specifications, cost information, vendor details, and storage requirements
- Vendors - Supplier information including names, contact details (email, phone), websites, and notes
- Kitchen operations - Prep tasks, inventory and supplies records, where your plan includes them
- Folders and Tags - Organizational data for your recipes
- Purchase prices - If you use price updates: the purchase prices you record or accept, with the vendor, the item as it was described and who reviewed it; the receipts, invoices, price lists and emails they were read from (7.9); and the sender addresses you trust to send price emails. How long we keep them is in 7.8
- Price links - Product page addresses you save for an ingredient, to check its price. They are kept with the workspace until you remove them or delete the workspace
- Recipe import inputs - The link, text or photo you submit for an AI recipe import, and the result (see 3.2). A photo is stored without the details your camera or phone saved in the file, such as when and where it was taken: your browser makes a fresh copy of the image before it is uploaded, and our servers remove any such details that remain. It is deleted automatically within about two days of upload (7.7)
2.5 Usage and Analytics Data
We collect information about how you use our Service:
- AI Usage Records - Request types (recipe import from a link, text or a photo; ingredient research), model used, status, latency, token counts, and cost estimates, with the job's ID and, for ingredient research, the IDs of the ingredient and its recipe; and this month's usage counts for your plan's limits
- AI Job Records - The status, progress, timestamps and logs of each recipe import or ingredient research job, including the link or text you submitted
- Analytics Events - Only if you allow analytics: the address (URL) of each page you view and of the page you came from (a shared recipe's link with the part that opens the recipe removed), and which features and controls you use, keyed to a pseudonymous identifier (your account ID once you sign in, a random ID before) rather than your name or email, and error reports. The text on the page is masked, so recipe content, costs and text you type are not sent, and error reports are scrubbed of quoted text, numbers and email addresses. With your account ID we send your role, your plan and the date you joined. Events recorded before we began removing that part of a shared recipe's link may still hold the full link, which PostHog keeps as described in 7.6
- App Settings and Preferences - Your display preferences, view modes, sort order, and the library ingredients you hide or pin
2.6 Third-Party Integration Data
When you connect third-party services:
- Google Account - When you sign in with Google, we receive your name, email address and profile photo. Google sign-in asks only for your basic profile and email address. If you signed in with Google before 27 September 2026, your Google Account may still list a read-only Google Drive permission for PrepCook.Pro; we hold nothing that can use it, and you can remove it from your Google Account (6.4)
- Google Drive backup (optional) - If you connect Google Drive for automatic recipe backups in your Account settings, you give PrepCook.Pro Google's full Drive permission, which allows an app to see, create, edit and delete files in your Drive; the backup needs it to write into a folder you choose. We store a refresh token so backups keep working, the name and ID of the folder you choose, and the Drive ID of each backup file. We use the permission only to list your Drive folders while you choose one, and to save a spreadsheet copy of each recipe to that folder when you save the recipe
- Gmail (optional) - If you connect Gmail, PrepCook gets read-only access to your mailbox through Google's gmail.readonly permission. We search it only for purchase receipts and invoices: messages from senders you list as trusted, from common food distributors, or with words such as "invoice" or "receipt" in the subject. From each such message we read the text and attachments to find the items bought and their prices, and we keep those prices and the sender's domain name (for example, the distributor's web domain), which we show beside each price as its source. We do not keep the message, its subject or any other email. We store the address of the connected mailbox, to show it to you, and one-way fingerprints of message identifiers so the same receipt is not read twice. How we handle Gmail data is described in 4.6
- Your forwarding address (optional) - If you set one up, we receive the emails that you, or a filter you create, send to your private PrepCook address. We read them in the same way and keep the prices we find. We keep that address, the workspace it sends prices to, counts of the emails it has received, and, while you need it, a confirmation code Gmail sends to it. The address is shown only to you; anyone who learns it can send email to it, so you can change or remove it at any time. It is deleted when you remove it or delete your account, and included (without internal sync details) when you download your data
2.7 Preview Requests
If you ask to join the preview on our home page, we collect your email address and, if you give them, your name and what you would use PrepCook.Pro for, with the date. Our administrators use this list to send invitations. When an administrator invites someone, that person's email address and name are added to this list with the date and the administrator who invited them, whether or not they asked to join.
2.8 Automatically Collected Information
We automatically collect certain information when you use our Service:
- Device and browser information (device type, operating system and browser, from your browser's user agent)
- IP address - in our servers' request logs; as a keyed code derived from it, not the address itself, in records of failed sign-in attempts and in the counters that limit requests made before sign-in (each sign-in check, each request to join the preview, and each opening of a shared recipe, including by people without an account), which are deleted after 2 days; and, if you allow analytics, in what PostHog receives and stores with each event. PostHog derives an approximate location from your IP address (city, region, country, postal code, time zone and approximate coordinates) and adds it to your analytics events and to the profile PostHog keeps for your identifier (4.1)
- App Check signals - reCAPTCHA Enterprise, which Google runs on our pages to check that requests come from our app, collects information about your device and browser and sends it to Google
- Usage timestamps
- Error logs - our servers log errors with your account ID; if you allow analytics, error reports from your browser are sent to PostHog (2.5)
3. How We Use Your Information
3.1 Service Operation
We use your information to:
- Create and manage your account
- Provide, maintain, and improve our Service
- Process transactions and manage subscriptions
- Authenticate your identity and secure your account
- Store and sync your recipes, ingredients, and vendor data across devices
- Enable recipe sharing features (when you choose to share recipes)
- Back up your recipes to Google Drive (when you turn this on)
- Account Protection - Limit repeated failed sign-in attempts, rate-limit requests to our AI features and shared recipe links, and check that requests come from our app
- Login History and Audit Trails - Keep records of authentication events for security analysis and so you can review your recent sign-ins
3.2 AI-Powered Features
We use your content with AI services to provide:
- Recipe Import - Turning a recipe link, pasted text or a photo into a structured recipe. For a link, our servers fetch the page and send its text; if the page cannot be fetched, the AI model may look the recipe up with Google Search. A photo is stored privately in our Google Cloud Storage, where it is not publicly accessible: only our servers, and our administrators through Google Cloud, can open it, and our servers use it only to read the recipe while the import runs: it is sent to the AI model without the details saved in the file, such as when and where the photo was taken. The recipe you save does not include the photo, and the photo is deleted automatically within about two days of upload (7.7)
- Ingredient Research - Filling in an ingredient's technical specifications, sources and suppliers. The ingredient's name, the recipe's source and your notes on that ingredient are sent, and the AI model searches the web with Google Search
- Purchase Prices - Receipts and invoices you upload or forward, or that we find in a connected Gmail account, are sent to Google's Gemini API to read the items and prices. You can upload invoices, receipts, order confirmations, price lists and photos of them
- Price Checks - About once a week, and when you ask, PrepCook fetches each saved page as PrepCookPriceCheck (prepcook.pro/bot.html). It honours the site's robots.txt and paces its requests. The page's text is sent to Google Gemini only to read the price shown for that product; prices found join your price history (7.8) like a receipt line
When you use AI features, the content described above is sent to Google's Gemini API for processing. Our Gemini API key belongs to a Google Cloud project with billing enabled, so our use is a paid service under the Gemini API Additional Terms of Service. Under those terms, Google does not use the content we send, or the responses, to improve its products, and it logs them for a limited period to detect and prevent misuse and for any legal or regulatory disclosures it must make. When the model searches with Google Search, Google stores the request, the content we sent with it and the result for 30 days to produce the search results, and may use them to debug and test that feature.
3.3 Communications
We use your email address to:
- Send account emails through Firebase Authentication: password-reset links, and email-verification links when you ask for one
- Send you an invitation, with a link to set your password, if an administrator invites you (sent through Mailgun)
- If you turn on the weekly price email (Price updates → Settings), we send you a summary each Monday of the price changes in your kitchen: ingredient names, vendors, the old and new prices, and how many recipes use a changed ingredient. It is off until you turn it on, and only owners and managers can receive it
- Sign-in links - When you ask to sign in by email, we send a one-time link to your address through Mailgun, with Mailgun's link and open tracking turned off. The link works once and expires 6 hours after it is sent
- Let Stripe send you receipts and invoices for a paid plan
- Respond to your inquiries and support requests
We do not send marketing email.
Text messages - If you sign in with a phone number, we send one-time sign-in codes by text message through Firebase Authentication. We do not send marketing texts. Message and data rates may apply.
3.4 Analytics and Improvement
With your consent, we use pseudonymous usage data to:
- Understand how users interact with our Service
- Identify and fix bugs and errors
- Improve performance and user experience
- Develop new features
- Monitor system health and security
Analytics runs only after you allow it: PostHog stays off, and stores nothing in your browser, until you choose "Allow analytics" on the consent bar or in your account settings, where, once signed in, you can change that choice at any time.
Until then, PostHog's code is not even loaded. Once you allow it, PostHog masks all text on the page, records no video of your session (session recording is off), and stops, with what it stored in your browser removed, when you decline or withdraw. When you are signed in, your choice is saved to your account and applies on your other devices, except that analytics stays off in any browser where you declined it. If you are not signed in, choose "Analytics choices" at the foot of our home page, or open your analytics choices: if you had allowed analytics it stops at once, and the consent bar asks again.
If you allow analytics, our servers also send PostHog a few events about your AI recipe imports and ingredient lookups: that one was queued, completed or failed, with its ID, whether it came from a link, text or a photo, the research mode, how long it took and, for a failure, only whether a plan limit stopped it. They are keyed to your account ID and never include the recipe, the link or text you gave us, ingredient names, costs or prices. They follow the choice saved to your account: none are sent before you allow analytics or after you withdraw it.
3.5 Legal Compliance
We may use your information to:
- Comply with legal obligations
- Respond to legal requests and court orders
- Enforce our Terms of Service
- Protect our rights, privacy, safety, and property
- Prevent fraud and abuse
4. How We Share Your Information
4.1 Third-Party Service Providers
We share your information with trusted third-party service providers who help us operate our Service:
| Service Provider |
Purpose |
Data Shared |
| Google Cloud and Firebase (Google) |
Sign-in (Firebase Authentication), our database (Cloud Firestore), website hosting, server functions, file storage, background task queue, and server logs |
All account data, user content and usage data we store; photos uploaded for recipe import, for about two days, and then as a deleted copy we can recover for up to 7 days (7.7); a request for an email sign-in link (your email address, IP address and browser) in our task queue until the link is sent (7.7); server logs identified by your account ID, and request logs with IP address and browser. Firebase Authentication also sends our password-reset and email-verification emails, and the sign-in codes we text to phone numbers. Google may also use phone numbers sent for verification to prevent spam and abuse across its services, and may keep them for that purpose after you delete your account |
| Google Gemini API |
AI-powered recipe import, ingredient research and reading purchase prices |
Recipe text, the text of pages at links you import, photos (without the details saved in the file), ingredient names, recipe sources and ingredient notes; purchase documents you upload (invoices, receipts, order confirmations, price lists and photos of them), read to find item prices; the receipts and invoices in emails you forward or that we find in a connected Gmail account; the text of product pages you ask us to watch, read to find the price; and related prompts sent for processing. For ingredient research, and for links we cannot fetch, the model may run Google Search queries. Google's retention is described in 3.2 |
| Google reCAPTCHA Enterprise (Firebase App Check) |
Checking that requests to our database and to our AI, shared-recipe and preview-request functions come from our app, and that requests to text a sign-in code are not automated, which makes it harder for automated scripts to reach them |
Device and browser information that reCAPTCHA collects on every page of the Service, whatever your analytics choice; for a request to text a code, the phone number too |
| Google Drive API |
Optional recipe backup to your own Google Drive |
OAuth tokens; the names and IDs of your Drive folders while you choose a backup folder; the recipe spreadsheets we save to it (only when you turn backups on) |
| Gmail API (Google) |
Reading receipts from your Gmail, only if you connect it |
Read-only access to your mailbox, used as described in 4.6 |
| PostHog (US region) |
Product analytics and error tracking, only if you allow analytics |
Pseudonymous usage events and error reports, only after you allow analytics: keyed to your account ID (or a random ID before you sign in), with page text masked and error messages scrubbed. They include the address of each page you view and of the page you came from, with the part of a shared recipe's link that opens the recipe removed. PostHog also receives your IP address with each request and stores it with each event, and derives an approximate location from your IP address (city, region, country, postal code, time zone and approximate coordinates) and adds it to your analytics events and to the profile PostHog keeps for your identifier. Also, only after you allow analytics, events about your AI imports and lookups sent from our servers, which carry our server's address rather than yours. |
| Stripe |
Payment processing and subscription management |
Email address, your PrepCook account identifier, billing name and address, and payment method details (payment details are handled by Stripe in compliance with PCI DSS; we never see or store card numbers). |
| Mailgun |
Email delivery, and receiving email sent to your forwarding address |
Email addresses for account emails (for an invitation, also the name of the person invited and the invitation link; for a sign-in link you ask for, the link); the full content of emails sent to your forwarding address, which Mailgun holds for up to 3 days until we fetch and delete it; and the weekly price email, if you turn it on (your address, and the ingredient names, vendors and prices it summarises) |
Note on Third-Party Services: Each of these providers processes the data listed for it under its terms with us and its own privacy policy.
reCAPTCHA Enterprise is subject to Google's Privacy Policy and Terms of Service.
4.2 Public Sharing
When you choose to share a recipe publicly using our sharing feature:
- The recipe becomes accessible to anyone with the share link, without signing in
- Only the specific recipe you share is made public, not your account or other recipes
- Anyone with the link receives what the shared page shows and what a copy saved from it keeps: the recipe's name, source and category, its yields and scaling settings, its ingredients with their quantities, units and your notes on them, the ingredient entry each one is linked to, its method, your notes on the recipe, and its specifications (such as ABV, Brix, pH, storage and shelf life). It leaves out your pricing settings (target margin, pricing method and target food-cost percentage), folders, tags, the supplier chosen for each ingredient, version history, inventory settings, and when and by whom the recipe was created, imported or last changed
- Anyone with the link can save a copy of the recipe to their own PrepCook.Pro account
- When someone opens the link, our servers count the request against their IP address to limit abuse, and delete the count after 2 days. If that person has allowed analytics, the page's address is included in what PostHog receives, with the part of the link that opens the recipe removed (2.5)
- You can turn sharing off at any time, for one recipe or for all your recipes at once in your Account settings; the link then stops working. If you turn sharing back on for a recipe, the same link works again
4.3 Legal Requirements
We may disclose your information if required by law or in response to:
- Valid legal process (subpoenas, court orders, search warrants)
- Government requests
- Legal investigations
- Protection of rights, property, or safety
4.4 Business Transfers
In the event of a merger, acquisition, or sale of assets, your information may be transferred to the acquiring entity. We will notify you of any such change in ownership or control of your personal information.
4.5 We Do Not Sell Your Data
We do not sell, rent, or trade your personal information to third parties for their marketing purposes.
4.6 Google User Data
PrepCook's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We use Gmail data only to find purchase prices for you. We do not use it for advertising, do not sell it, and do not use it to train AI models. We transfer it only to Google's Gemini API to read receipts, and to Mailgun to deliver the weekly price email to the people who turn it on (3.3), which can include prices found in your Gmail, and otherwise only as needed for security or to comply with the law. No person at PrepCook reads your email unless you ask us to for support and agree to it, or it is needed for security or required by law. If you connect Gmail for a shared kitchen workspace, the prices found are visible to that workspace's owners and managers.
5. Data Storage and Security
5.1 Storage Location
Your data is stored on Google Cloud Platform servers operated by Firebase, in the United States: our database and its daily backups in Google's United States multi-region, and our server functions and file storage in Iowa (us-central1). Our server logs are kept in Google Cloud Logging's global location, which is not limited to the United States. Our other service providers process data as described in section 9.
5.2 Security Measures
We implement industry-standard security measures to protect your information:
- Encryption - Data in transit is encrypted using TLS, and the Service is served over HTTPS only. Data stored in Firestore and Cloud Storage, including the backups Google keeps for us, is encrypted at rest by default.
- Authentication - Passwords are hashed by Firebase Authentication. Google OAuth tokens are stored in your account's records, where only your own sign-in and our servers can read them. If you sign in with a link on an account whose email address was never verified, any password on that account is removed and Firebase Authentication signs your other devices out once their current sign-in token expires, within an hour. This stops anyone who registered your address before you did from keeping access. You can set a new password afterwards.
- Access Controls - Firestore security rules limit each account to its own data, with two exceptions. Any signed-in user can look up a display name, which shows whether it is taken and the account ID that holds it. PrepCook.Pro administrators can read every account's profile, content, usage, session and security records and preview requests. They can also change an account's profile details, display name and plan, delete an account (other than the owner's), delete session records, and change or delete AI usage records and preview requests. We use this access to operate and support the Service. Shared recipes are served to anyone with the link through our servers (4.2). Photos uploaded for recipe import are kept in storage that is not publicly accessible: our servers read them only to run the import (3.2), and our administrators can open them through Google Cloud.
- App Check - Requests to our database and to our AI, shared-recipe and preview-request functions must carry a Firebase App Check token from reCAPTCHA Enterprise, which makes it harder for scripts outside our app to reach them. Our other functions and Firebase Authentication do not require it.
- API Security - Requests that read or change your data require a valid Firebase sign-in token, sent in a request header rather than a cookie. What works before sign-in: opening a shared recipe and the sign-in attempt checks, which are rate-limited by IP address; Stripe's payment notifications, which must carry Stripe's signature and are rate-limited by the address they come from; the last step of connecting Google Drive or Gmail, which needs a single-use code that expires after 5 minutes; Mailgun's notices of email sent to a forwarding address, which must carry Mailgun's signature; the unsubscribe link in a weekly price email, which works only with the signed link from that email and is rate-limited; and the preview-request form on our home page, which needs an App Check token and is limited by our security rules to the expected fields and sizes, but is not rate-limited. Endpoints for email sign-in links and email verification also exist, but those features are switched off and the endpoints refuse requests.
- Regular Security Updates - We keep our dependencies and infrastructure updated with security patches.
- Rate Limiting and Account Protection - Our sign-in page checks with our servers before each attempt: after 5 failed attempts within 15 minutes, it pauses sign-in for that email address from the same IP address for 15 minutes. This pause is applied by our sign-in page only; Firebase Authentication, which checks passwords, also limits repeated failed sign-ins on its own. Requests to our AI features and to shared recipe links are rate-limited. Deleting your account requires a sign-in from the last five minutes.
- Session Records - Your Account settings list the sessions recorded for your email-and-password sign-ins, with the device type and browser, and let you remove them from the list. Removing a session does not sign that device out. Resetting your password ("Forgot password") does: Firebase Authentication then signs your other devices out once their current sign-in token expires, within an hour.
- Security Headers - We implement security headers including Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, and Strict-Transport-Security.
5.3 Data Minimization
We aim to collect and store only what the Service needs; section 2.6 describes one permission we still request that no feature uses. Analytics is off until you allow it, and what it sends is pseudonymous: keyed to your account ID, not your name or email, with text you type, recipe content and costs left out and error messages scrubbed before transmission.
5.4 Your Responsibility
You are responsible for maintaining the confidentiality of your account credentials. Please use a strong, unique password and do not share your account information with others.
6. Your Rights and Choices
6.1 Access and Portability
You have the right to:
- Access your personal information and content through your account
- Export individual recipes using the Service's export features
- Download Your Data - Account → Security → "Download my data" gives you one machine-readable (JSON) file with your profile and the records you own: recipes, ingredients, vendors, prep, inventory and supplies records, preferences and display name, AI jobs and usage records, your plan's usage counts, your billing record, if you use price updates your price history and its related records (7.8), price links, trusted senders, forwarding address, Gmail connection and weekly-email setting, the security events recorded under your account, such as sign-ins and sign-outs, and your sign-in record at Firebase Authentication: your email address and phone number (if any), the sign-in methods and second steps you use, and when the account was created and last signed in. It never includes passwords or second-step secrets. It does not include your session records, your Google Drive backup settings, backup records and connection tokens, photos you uploaded for recipe import, the original files and emails read for prices (7.9), your preview request (2.7), the workspace record described in 7.3, or the records of failed sign-in attempts and password-reset requests made with your email address; you can ask us for these (12). If your download is cut, contact us and we will send the full export
- View Login History - See your most recent sign-in events (up to the last 50) in your Account settings
- View Active Sessions - See the sessions recorded for your email-and-password sign-ins, with device type and browser, and remove them from the list. Removing a session does not sign that device out (5.2)
6.2 Correction and Updates
You can update your account information, profile details, and content at any time through your account settings or by editing your recipes and ingredients directly in the Service.
6.3 Deletion
You have the right to delete your account and data:
- Account Deletion - You can delete your account yourself in Account → Security → "Delete account", or ask us to delete it (12). Deletion in your Account settings happens as soon as you confirm it and cannot be undone: there is no grace period and no way to restore the account. You need to have signed in within the last five minutes, and to have cancelled any subscription that would renew. Section 7.3 describes what is deleted and what is not; a deletion we make at your request takes the same steps.
- Content Deletion - You can delete individual recipes, ingredients, or vendors at any time
- Soft Delete - Deleted recipes and ingredients are kept for 30 days in a "trash" state, allowing you to restore them if needed
- Permanent Deletion - After 30 days, deleted recipes and ingredients are permanently deleted automatically, and they leave our daily database backups within 14 days after that (7.7)
Note: When you delete your account, we remove your identity from the security events recorded under your account (your account ID, IP address, browser and the event details are cleared) rather than deleting them, so the audit log keeps its shape until those events expire (7.2). Invoices and payment records held by Stripe are kept as described in 7.5.
6.4 Opt-Out Rights
You can:
- Decline or withdraw analytics - Choose "Decline" on the consent bar; when signed out, choose "Analytics choices" at the foot of our home page to withdraw or change your answer; when signed in, change your choice at any time in Account → Security → Privacy Preferences (3.4)
- Turn off or disconnect Google Drive backups in your Account settings. Disconnect also revokes the backup access we hold with Google; the backups already in your Drive stay there. To remove PrepCook.Pro's access to your Google Drive, including any read-only permission granted at a Google sign-in before 27 September 2026, use the third-party access page of your Google Account (myaccount.google.com). Deleting your account also revokes the backup access we hold
- Disconnect Gmail or remove your forwarding address on the Connections page (Account & Data → Connections). Disconnecting Gmail removes our access with Google immediately; because Gmail and Drive backup share one Google sign-in, disconnecting one may also end the other, and the page tells you when it does. You can also remove PrepCook's access at https://myaccount.google.com/permissions
- Stop the weekly price email - Every weekly price email has a one-click unsubscribe link; you can also turn it off in Price updates → Settings. We store only that preference and the week we last sent it; the email's contents are not kept
- Stop sharing recipes - Turn sharing off for one recipe, or for all of them in your Account settings (4.2)
Note on Core Security Features: The security data described in 2.1.1 is necessary for the operation and security of the Service and cannot be disabled. This processing is based on our legitimate interest in protecting your account and preventing fraud.
6.5 California Privacy Rights (CCPA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):
- Right to know what personal information we collect, use, and disclose
- Right to delete your personal information (subject to certain exceptions)
- Right to opt-out of the sale of personal information (we do not sell your data)
- Right to non-discrimination for exercising your privacy rights
To exercise these rights, please contact us using the information provided in the "Contact Us" section below.
6.6 European Privacy Rights (GDPR)
If you are located in the European Economic Area (EEA) or United Kingdom, you have additional rights under the General Data Protection Regulation (GDPR):
- Right of Access - Obtain confirmation of whether we process your data and access to that data
- Right to Rectification - Correct inaccurate or incomplete data
- Right to Erasure - Request deletion of your data under certain circumstances
- Right to Restrict Processing - Limit how we use your data
- Right to Data Portability - Receive your data in a structured, machine-readable format
- Right to Object - Object to processing based on legitimate interests
- Right to Withdraw Consent - Withdraw consent where processing is based on consent
Our legal basis for processing your data includes:
- Contract Performance - To provide the Service you've requested
- Legitimate Interests - To improve our Service, ensure security, and prevent fraud
- Consent - For optional analytics
- Legal Obligations - To comply with applicable laws
To exercise these rights, please contact us using the information provided in the "Contact Us" section below.
7. Data Retention
7.1 Active Accounts
We retain your account information and content for as long as your account is active and you continue to use our Service.
7.2 Authentication and Security Data
We retain authentication and security data for the following periods:
- Security Events and Audit Logs - Sign-in events, sign-outs, failed sign-in attempts and password-reset requests are retained for 365 days, then deleted automatically
- Phone Number - Kept while it is on your account, with your sign-in record at Firebase Authentication
- Session Records - Deleted automatically once they expire, 24 hours after the session started or was last refreshed
- Login History - Shown from the security events above; your Account settings show the most recent 50
- Rate Limiting Data - Counters that limit repeated requests are deleted 2 days after their last update (the monthly counts for your plan's limits, 2 days after the month ends). They are keyed to your account ID (for example, for AI features, data export and account deletion), to a keyed code derived from the email address and IP address entered, not the address itself (failed sign-ins and password-reset requests), to a keyed code derived from your email address (requests to join the preview), or to a keyed code derived from an IP address (sign-in checks, requests to join the preview, and opening a shared recipe, including by people without an account). A pause on sign-in attempts lasts 15 minutes
7.3 Deleted Accounts
When you delete your account in your Account settings, or we delete it at your request, deletion is immediate. We:
- Revoke the Google Drive backup access we hold
- Permanently delete your profile; your recipes (every saved version, and the trash), ingredients, vendors, prep, inventory and supplies records; your AI jobs and usage records, sessions, preferences, display name and usage counts; your billing record; the internal workspace record for your account, which holds your display name, email address, account ID and plan; and any preview request made with your email address
- Remove your identity from the security events recorded under your account: your account ID, IP address, browser and the event details are cleared
- Ask PostHog to delete the analytics data keyed to your account ID, if you ever allowed analytics
- Delete your sign-in record from Firebase Authentication, including your phone number and any second steps
If you delete your account, we remove our copy of your billing records; invoices and payment records held by Stripe are kept as required for tax and accounting (see 7.5).
Deleting your account does not remove:
- Copies in our daily database backups, which expire within 14 days (7.7)
- Records of failed sign-in attempts and password-reset requests made with your email address, which expire after 365 days (7.2)
- Server and request logs, which expire after 30 days, and Google Cloud's administrative audit logs, which expire after 400 days (7.6)
- A note of your account ID, deleted automatically 3 days after your account, which lets us ask PostHog a second time to delete analytics data that a device still signed in to your account sent after the deletion
- Photos you uploaded for recipe import shortly before, which are deleted automatically within about two days of upload, and then stay recoverable by us for up to 7 days (7.7)
- Recipe backups already saved to your Google Drive, which are yours and stay in your Drive
- The permission you gave Google when signing in with Google, which stays in your Google Account until you remove it there (6.4)
Some information may also be retained for legal or legitimate business purposes as required by law.
7.4 Soft Delete Policy
When you delete individual recipes or ingredients:
- They are moved to a "trash" state and retained for 30 days
- You can restore them during this 30-day period
- After 30 days, they are permanently deleted through an automated cleanup process
7.5 Subscription and Payment Records
Invoices, receipts and payment records are held by Stripe, which retains them as required by law for tax, accounting, and legal purposes, under its own privacy policy. Our record of each Stripe notification we have processed holds the event's type, times and outcome and the ID of the subscription it concerns; it is not removed when you delete your account, and is deleted 30 days after we receive it.
7.6 Analytics and Logs
PostHog keeps analytics data and error reports for the retention period of our PostHog plan (1 year on its free plan, 7 years on its paid plans); PostHog does not let us set a shorter period. Analytics data is pseudonymous: it is keyed to your account ID rather than your name or email, and when you delete your account we ask PostHog to delete it. Our server logs, which identify you only by your account ID, and Google Cloud's request logs, which record IP addresses and browsers, are kept for 30 days. Google Cloud's administrative audit logs, which record administrative changes to our project, including changes to who can access stored files, and can include your account ID where it is part of a file's name, are kept for 400 days.
7.7 Other Records
- AI Job Records - Recipe import and ingredient research jobs, including the link or text you submitted, are deleted automatically 90 days after they were queued. If you cancel a job while it is waiting or running, a record of the cancellation is also kept separately: the kind of job and when it was queued and cancelled, but not the link or text you submitted or any result (a record made by an earlier version of PrepCook also holds a copy of the job, including the link or text you submitted and any result). It is deleted automatically 30 days after you cancel, or sooner if you delete your account, and is included in your data download
- Recipe Import Photos - Photos you upload for a recipe import are kept privately in our Google Cloud Storage, as the images you uploaded, without the details saved in the file, and are used only to read the recipe while the import runs. A rule on that storage deletes them automatically within about two days of upload, whether or not the import succeeded; deleting your account does not delete them sooner. They are not in your data download (6.1). Photos uploaded before 24 September 2026 were deleted on that day
- Sign-in Link Requests - When you ask for an email sign-in link, the request waits in our task queue, with your email address, IP address and browser, until the link is sent, normally within seconds
- Preview Requests - Kept until you ask us to delete them, or until an account created with that email address is deleted
- Backups - We keep daily backups of our database for 14 days, and can restore it to any point in the previous 7 days, so data you delete leaves those backups within 14 days. A file deleted from our Google Cloud Storage, such as an import photo, stays recoverable by us for up to 7 days after it is deleted, and is then gone for good
7.8 Purchase Prices and Price History
If you use price updates, we keep the purchase prices you record or accept (from receipts, vendor price lists and your own entries), together with the vendor, the item as it was described, who reviewed or applied each price, and the history of earlier prices. We keep them for as long as your account exists or, for prices kept in a shared kitchen workspace, for as long as that kitchen workspace exists. They are deleted when the account (or the kitchen workspace) is deleted, and they are included when you download your data.
7.9 Emails and Receipts
Messages read from Gmail are held only while we read them, and at most 30 days if reading keeps failing. Emails sent to your forwarding address, and their attachments, are kept for up to 30 days so a failed read can be retried, then deleted. Mailgun's copy is deleted when we fetch it, and within 3 days in any case. The prices we find are kept as your price history for as long as your account exists.
The original file you upload is kept for 30 days so it can be read again if something fails, then deleted. Photos are re-encoded on your device and stripped of location and camera data on our servers before they are stored. The item lines we read are kept as your price history (7.8).
8. Children's Privacy
PrepCook.Pro is not intended for children under the age of 13. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately. If we become aware that we have collected personal information from a child under 13, we will take steps to delete such information from our systems.
9. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence. These countries may have data protection laws that differ from those in your country. Specifically:
- Our primary data storage is on Google Cloud Platform servers in the United States (5.1)
- Third-party service providers (Google, Stripe, PostHog, Mailgun) may process data in various countries; PostHog stores our analytics in its United States region
Each provider handles the data transferred to it under its terms with us. If you are in the EEA or United Kingdom and want to know the safeguards that apply to a transfer of your data, contact us (12).
10. Cookies and Tracking Technologies
We do not use advertising cookies. The Service stores the following in your browser:
- Your sign-in - Firebase Authentication keeps your login session in your browser's storage
- Security tokens - On every page, whatever your analytics choice, Firebase App Check keeps a short-lived token in your browser's storage, and reCAPTCHA Enterprise may keep its own data there, so that our database and our AI, shared-recipe and preview-request functions can check that requests come from our app (5.2)
- A copy of your data - Our database keeps a cache of your data on your device, so the Service keeps working offline. It is removed from this browser when you sign out. If you sign out while changes you made offline have not reached us yet, we tell you and keep you signed in until they have; if your sign-in ends another way (you sign out in another tab, or your sign-in expires or is ended from another device), changes not yet sent are lost
- Your analytics choice - Whether you allowed or declined analytics and, until it reaches your account, a decline that could not be saved to it yet. This records your choice; it does not track you
- Your address for a sign-in link - When you ask for a sign-in link, we keep your email address in this browser's local storage so you don't have to type it again. It is removed when you sign in with the link in this browser; once the link has expired it is no longer used, and it is removed the next time the Service reads it. If you open the link in a different browser, we ask for your address instead
- A kitchen invitation you open - If you open a link inviting you to a kitchen workspace, the invitation (which kitchen, which invitation, and its code) is kept in that browser tab until you answer it or close the tab
- The workspace you are working in - When you choose your personal workspace or a kitchen, that choice (your account identifier, the workspace's identifier, whether it is personal or a kitchen, and its name) is kept in that browser tab so a reload keeps it. It is removed when you sign out or switch workspace, or when you are no longer a member of that kitchen, and it is not kept once the tab is closed
- Preferences and settings - Your display settings and sort order, cached feature settings, whether you have finished setting up your profile, where to return to after signing in, and the random device identifier used in your session records
- A recipe you are copying - If you choose to copy a shared recipe before signing in, a copy of it is kept in your browser until you sign in and it is saved to your account
- Local records - The last 50 error messages on this device, kept for troubleshooting, and any list of AI requests that older versions of the Service kept in your browser (the current version adds none). They stay in your browser
- App files - The Service's code and fonts, so it loads quickly and works offline
- PostHog analytics - Only if you allow analytics: an identifier and PostHog's settings, in local storage, session storage and a first-party cookie. They are removed when you decline or withdraw
reCAPTCHA Enterprise also runs on every page (4.1). You can control cookies and site data through your browser settings. Clearing them signs you out on that browser and resets your analytics choice there.
10.1 Privacy Preferences
Analytics is the only optional data collection that asks for your consent (3.4). You can review and change that choice at any time in Account → Security → Privacy Preferences. If you are not signed in, use "Analytics choices" at the foot of our home page.
The Service does not ask your device for its location, and does not build a device fingerprint. The reCAPTCHA Enterprise device and browser checks (2.8) run on every page and are not an optional choice. A photo you upload for recipe import is kept, for about two days (then recoverable by us for up to 7 days, 7.7), as the image you chose, without the details saved in the file, such as where it was taken (2.4). If you allow analytics, PostHog derives an approximate location from your IP address (city, region, country, postal code, time zone and approximate coordinates) and adds it to your analytics events and to the profile PostHog keeps for your identifier (4.1).
Core Security Features: Some security features (the sign-in records, IP addresses and browser information described in 2.1.1) are necessary for the operation and security of the Service and do not require separate consent. These are processed based on our legitimate interest in protecting your account and preventing fraud.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we do, we post the updated Privacy Policy on this page with a new "Last Updated" date.
Your continued use of the Service after the effective date of any changes constitutes your acceptance of the updated Privacy Policy. We encourage you to review this Privacy Policy periodically.
13. Additional Information
13.1 Third-Party Links
Our Service may contain links to third-party websites or services. We are not responsible for the privacy practices of these third parties. We encourage you to review the privacy policies of any third-party sites you visit.
13.2 Do Not Track Signals
Some browsers include a "Do Not Track" (DNT) feature that signals to websites you visit that you do not want to have your online activity tracked. Currently, there is no standard for how DNT signals should be interpreted. Our Service does not currently respond to DNT browser signals.
13.3 Data Processing Agreement
If you are using PrepCook.Pro in a business context and require a Data Processing Agreement (DPA) for GDPR compliance, please contact us at privacy@recipeai.pro.
This Privacy Policy is effective as of September 29, 2026.