Privacy Policy

Last Updated: September 29, 2026

1. Introduction

Welcome to PrepCook.Pro ("we," "our," or "us"). PrepCook.Pro is a recipe management and costing platform designed for chefs, restaurants, and food businesses. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our web application at prepcook.pro, including when you install it to your device's home screen (the "Service").

By using PrepCook.Pro, you agree to the collection and use of information in accordance with this policy. If you do not agree with our policies and practices, please do not use our Service.

2. Information We Collect

2.1 Account Information

When you create an account, we collect:

If an administrator invites you, they enter your email address and name, and your account is created at that point. Your email address and name are also added to our preview list (2.7), with the date and the administrator who invited you.

If a member of a kitchen workspace invites you to join it, they enter your email address. It is stored on the invitation, with the role offered, and the invitation is deleted automatically 7 days after it is made. Until you answer it or it expires, the kitchen's owner, and for an invitation as a cook any member allowed to invite cooks, can see your address on the kitchen's list of pending invitations. Once you join, the kitchen's members can see each other's names and email addresses on its member list.

2.1.1 Authentication and Security Data

To protect your account, we record the following authentication and security data:

Legal Basis for Processing: We process this security data based on our legitimate interest in protecting your account, preventing fraud, ensuring platform security, and complying with legal obligations.

2.2 Optional Profile Information

You may choose to provide additional profile information when you set up your profile or in your Account settings:

2.3 Subscription and Payment Information

If you subscribe to a paid plan, we collect:

Our own billing record for your account holds your Stripe customer and subscription IDs, the subscription's status, price and billing period, and the plan it gives you. It holds no card details.

2.4 User Content

You create and store content through our Service, including:

2.5 Usage and Analytics Data

We collect information about how you use our Service:

2.6 Third-Party Integration Data

When you connect third-party services:

2.7 Preview Requests

If you ask to join the preview on our home page, we collect your email address and, if you give them, your name and what you would use PrepCook.Pro for, with the date. Our administrators use this list to send invitations. When an administrator invites someone, that person's email address and name are added to this list with the date and the administrator who invited them, whether or not they asked to join.

2.8 Automatically Collected Information

We automatically collect certain information when you use our Service:

3. How We Use Your Information

3.1 Service Operation

We use your information to:

3.2 AI-Powered Features

We use your content with AI services to provide:

When you use AI features, the content described above is sent to Google's Gemini API for processing. Our Gemini API key belongs to a Google Cloud project with billing enabled, so our use is a paid service under the Gemini API Additional Terms of Service. Under those terms, Google does not use the content we send, or the responses, to improve its products, and it logs them for a limited period to detect and prevent misuse and for any legal or regulatory disclosures it must make. When the model searches with Google Search, Google stores the request, the content we sent with it and the result for 30 days to produce the search results, and may use them to debug and test that feature.

3.3 Communications

We use your email address to:

We do not send marketing email.

Text messages - If you sign in with a phone number, we send one-time sign-in codes by text message through Firebase Authentication. We do not send marketing texts. Message and data rates may apply.

3.4 Analytics and Improvement

With your consent, we use pseudonymous usage data to:

Analytics runs only after you allow it: PostHog stays off, and stores nothing in your browser, until you choose "Allow analytics" on the consent bar or in your account settings, where, once signed in, you can change that choice at any time.

Until then, PostHog's code is not even loaded. Once you allow it, PostHog masks all text on the page, records no video of your session (session recording is off), and stops, with what it stored in your browser removed, when you decline or withdraw. When you are signed in, your choice is saved to your account and applies on your other devices, except that analytics stays off in any browser where you declined it. If you are not signed in, choose "Analytics choices" at the foot of our home page, or open your analytics choices: if you had allowed analytics it stops at once, and the consent bar asks again.

If you allow analytics, our servers also send PostHog a few events about your AI recipe imports and ingredient lookups: that one was queued, completed or failed, with its ID, whether it came from a link, text or a photo, the research mode, how long it took and, for a failure, only whether a plan limit stopped it. They are keyed to your account ID and never include the recipe, the link or text you gave us, ingredient names, costs or prices. They follow the choice saved to your account: none are sent before you allow analytics or after you withdraw it.

3.5 Legal Compliance

We may use your information to:

4. How We Share Your Information

4.1 Third-Party Service Providers

We share your information with trusted third-party service providers who help us operate our Service:

Service Provider Purpose Data Shared
Google Cloud and Firebase (Google) Sign-in (Firebase Authentication), our database (Cloud Firestore), website hosting, server functions, file storage, background task queue, and server logs All account data, user content and usage data we store; photos uploaded for recipe import, for about two days, and then as a deleted copy we can recover for up to 7 days (7.7); a request for an email sign-in link (your email address, IP address and browser) in our task queue until the link is sent (7.7); server logs identified by your account ID, and request logs with IP address and browser. Firebase Authentication also sends our password-reset and email-verification emails, and the sign-in codes we text to phone numbers. Google may also use phone numbers sent for verification to prevent spam and abuse across its services, and may keep them for that purpose after you delete your account
Google Gemini API AI-powered recipe import, ingredient research and reading purchase prices Recipe text, the text of pages at links you import, photos (without the details saved in the file), ingredient names, recipe sources and ingredient notes; purchase documents you upload (invoices, receipts, order confirmations, price lists and photos of them), read to find item prices; the receipts and invoices in emails you forward or that we find in a connected Gmail account; the text of product pages you ask us to watch, read to find the price; and related prompts sent for processing. For ingredient research, and for links we cannot fetch, the model may run Google Search queries. Google's retention is described in 3.2
Google reCAPTCHA Enterprise (Firebase App Check) Checking that requests to our database and to our AI, shared-recipe and preview-request functions come from our app, and that requests to text a sign-in code are not automated, which makes it harder for automated scripts to reach them Device and browser information that reCAPTCHA collects on every page of the Service, whatever your analytics choice; for a request to text a code, the phone number too
Google Drive API Optional recipe backup to your own Google Drive OAuth tokens; the names and IDs of your Drive folders while you choose a backup folder; the recipe spreadsheets we save to it (only when you turn backups on)
Gmail API (Google) Reading receipts from your Gmail, only if you connect it Read-only access to your mailbox, used as described in 4.6
PostHog (US region) Product analytics and error tracking, only if you allow analytics Pseudonymous usage events and error reports, only after you allow analytics: keyed to your account ID (or a random ID before you sign in), with page text masked and error messages scrubbed. They include the address of each page you view and of the page you came from, with the part of a shared recipe's link that opens the recipe removed. PostHog also receives your IP address with each request and stores it with each event, and derives an approximate location from your IP address (city, region, country, postal code, time zone and approximate coordinates) and adds it to your analytics events and to the profile PostHog keeps for your identifier. Also, only after you allow analytics, events about your AI imports and lookups sent from our servers, which carry our server's address rather than yours.
Stripe Payment processing and subscription management Email address, your PrepCook account identifier, billing name and address, and payment method details (payment details are handled by Stripe in compliance with PCI DSS; we never see or store card numbers).
Mailgun Email delivery, and receiving email sent to your forwarding address Email addresses for account emails (for an invitation, also the name of the person invited and the invitation link; for a sign-in link you ask for, the link); the full content of emails sent to your forwarding address, which Mailgun holds for up to 3 days until we fetch and delete it; and the weekly price email, if you turn it on (your address, and the ingredient names, vendors and prices it summarises)

Note on Third-Party Services: Each of these providers processes the data listed for it under its terms with us and its own privacy policy.

reCAPTCHA Enterprise is subject to Google's Privacy Policy and Terms of Service.

4.2 Public Sharing

When you choose to share a recipe publicly using our sharing feature:

4.3 Legal Requirements

We may disclose your information if required by law or in response to:

4.4 Business Transfers

In the event of a merger, acquisition, or sale of assets, your information may be transferred to the acquiring entity. We will notify you of any such change in ownership or control of your personal information.

4.5 We Do Not Sell Your Data

We do not sell, rent, or trade your personal information to third parties for their marketing purposes.

4.6 Google User Data

PrepCook's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We use Gmail data only to find purchase prices for you. We do not use it for advertising, do not sell it, and do not use it to train AI models. We transfer it only to Google's Gemini API to read receipts, and to Mailgun to deliver the weekly price email to the people who turn it on (3.3), which can include prices found in your Gmail, and otherwise only as needed for security or to comply with the law. No person at PrepCook reads your email unless you ask us to for support and agree to it, or it is needed for security or required by law. If you connect Gmail for a shared kitchen workspace, the prices found are visible to that workspace's owners and managers.

5. Data Storage and Security

5.1 Storage Location

Your data is stored on Google Cloud Platform servers operated by Firebase, in the United States: our database and its daily backups in Google's United States multi-region, and our server functions and file storage in Iowa (us-central1). Our server logs are kept in Google Cloud Logging's global location, which is not limited to the United States. Our other service providers process data as described in section 9.

5.2 Security Measures

We implement industry-standard security measures to protect your information:

5.3 Data Minimization

We aim to collect and store only what the Service needs; section 2.6 describes one permission we still request that no feature uses. Analytics is off until you allow it, and what it sends is pseudonymous: keyed to your account ID, not your name or email, with text you type, recipe content and costs left out and error messages scrubbed before transmission.

5.4 Your Responsibility

You are responsible for maintaining the confidentiality of your account credentials. Please use a strong, unique password and do not share your account information with others.

6. Your Rights and Choices

6.1 Access and Portability

You have the right to:

6.2 Correction and Updates

You can update your account information, profile details, and content at any time through your account settings or by editing your recipes and ingredients directly in the Service.

6.3 Deletion

You have the right to delete your account and data:

Note: When you delete your account, we remove your identity from the security events recorded under your account (your account ID, IP address, browser and the event details are cleared) rather than deleting them, so the audit log keeps its shape until those events expire (7.2). Invoices and payment records held by Stripe are kept as described in 7.5.

6.4 Opt-Out Rights

You can:

Note on Core Security Features: The security data described in 2.1.1 is necessary for the operation and security of the Service and cannot be disabled. This processing is based on our legitimate interest in protecting your account and preventing fraud.

6.5 California Privacy Rights (CCPA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):

To exercise these rights, please contact us using the information provided in the "Contact Us" section below.

6.6 European Privacy Rights (GDPR)

If you are located in the European Economic Area (EEA) or United Kingdom, you have additional rights under the General Data Protection Regulation (GDPR):

Our legal basis for processing your data includes:

To exercise these rights, please contact us using the information provided in the "Contact Us" section below.

7. Data Retention

7.1 Active Accounts

We retain your account information and content for as long as your account is active and you continue to use our Service.

7.2 Authentication and Security Data

We retain authentication and security data for the following periods:

7.3 Deleted Accounts

When you delete your account in your Account settings, or we delete it at your request, deletion is immediate. We:

If you delete your account, we remove our copy of your billing records; invoices and payment records held by Stripe are kept as required for tax and accounting (see 7.5).

Deleting your account does not remove:

Some information may also be retained for legal or legitimate business purposes as required by law.

7.4 Soft Delete Policy

When you delete individual recipes or ingredients:

7.5 Subscription and Payment Records

Invoices, receipts and payment records are held by Stripe, which retains them as required by law for tax, accounting, and legal purposes, under its own privacy policy. Our record of each Stripe notification we have processed holds the event's type, times and outcome and the ID of the subscription it concerns; it is not removed when you delete your account, and is deleted 30 days after we receive it.

7.6 Analytics and Logs

PostHog keeps analytics data and error reports for the retention period of our PostHog plan (1 year on its free plan, 7 years on its paid plans); PostHog does not let us set a shorter period. Analytics data is pseudonymous: it is keyed to your account ID rather than your name or email, and when you delete your account we ask PostHog to delete it. Our server logs, which identify you only by your account ID, and Google Cloud's request logs, which record IP addresses and browsers, are kept for 30 days. Google Cloud's administrative audit logs, which record administrative changes to our project, including changes to who can access stored files, and can include your account ID where it is part of a file's name, are kept for 400 days.

7.7 Other Records

7.8 Purchase Prices and Price History

If you use price updates, we keep the purchase prices you record or accept (from receipts, vendor price lists and your own entries), together with the vendor, the item as it was described, who reviewed or applied each price, and the history of earlier prices. We keep them for as long as your account exists or, for prices kept in a shared kitchen workspace, for as long as that kitchen workspace exists. They are deleted when the account (or the kitchen workspace) is deleted, and they are included when you download your data.

7.9 Emails and Receipts

Messages read from Gmail are held only while we read them, and at most 30 days if reading keeps failing. Emails sent to your forwarding address, and their attachments, are kept for up to 30 days so a failed read can be retried, then deleted. Mailgun's copy is deleted when we fetch it, and within 3 days in any case. The prices we find are kept as your price history for as long as your account exists.

The original file you upload is kept for 30 days so it can be read again if something fails, then deleted. Photos are re-encoded on your device and stripped of location and camera data on our servers before they are stored. The item lines we read are kept as your price history (7.8).

8. Children's Privacy

PrepCook.Pro is not intended for children under the age of 13. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately. If we become aware that we have collected personal information from a child under 13, we will take steps to delete such information from our systems.

9. International Data Transfers

Your information may be transferred to and processed in countries other than your country of residence. These countries may have data protection laws that differ from those in your country. Specifically:

Each provider handles the data transferred to it under its terms with us. If you are in the EEA or United Kingdom and want to know the safeguards that apply to a transfer of your data, contact us (12).

10. Cookies and Tracking Technologies

We do not use advertising cookies. The Service stores the following in your browser:

reCAPTCHA Enterprise also runs on every page (4.1). You can control cookies and site data through your browser settings. Clearing them signs you out on that browser and resets your analytics choice there.

10.1 Privacy Preferences

Analytics is the only optional data collection that asks for your consent (3.4). You can review and change that choice at any time in Account → Security → Privacy Preferences. If you are not signed in, use "Analytics choices" at the foot of our home page.

The Service does not ask your device for its location, and does not build a device fingerprint. The reCAPTCHA Enterprise device and browser checks (2.8) run on every page and are not an optional choice. A photo you upload for recipe import is kept, for about two days (then recoverable by us for up to 7 days, 7.7), as the image you chose, without the details saved in the file, such as where it was taken (2.4). If you allow analytics, PostHog derives an approximate location from your IP address (city, region, country, postal code, time zone and approximate coordinates) and adds it to your analytics events and to the profile PostHog keeps for your identifier (4.1).

Core Security Features: Some security features (the sign-in records, IP addresses and browser information described in 2.1.1) are necessary for the operation and security of the Service and do not require separate consent. These are processed based on our legitimate interest in protecting your account and preventing fraud.

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we do, we post the updated Privacy Policy on this page with a new "Last Updated" date.

Your continued use of the Service after the effective date of any changes constitutes your acceptance of the updated Privacy Policy. We encourage you to review this Privacy Policy periodically.

12. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

PrepCook.Pro
Email: privacy@recipeai.pro
Support: support@recipeai.pro

For data protection inquiries, account deletion requests, or to exercise your privacy rights, please include:

We will respond to your request within 30 days, or as required by applicable law.

13. Additional Information

13.1 Third-Party Links

Our Service may contain links to third-party websites or services. We are not responsible for the privacy practices of these third parties. We encourage you to review the privacy policies of any third-party sites you visit.

13.2 Do Not Track Signals

Some browsers include a "Do Not Track" (DNT) feature that signals to websites you visit that you do not want to have your online activity tracked. Currently, there is no standard for how DNT signals should be interpreted. Our Service does not currently respond to DNT browser signals.

13.3 Data Processing Agreement

If you are using PrepCook.Pro in a business context and require a Data Processing Agreement (DPA) for GDPR compliance, please contact us at privacy@recipeai.pro.


This Privacy Policy is effective as of September 29, 2026.