Privacy policy
Last updated: July 2026. The short version: we store your recipes, we never sell anything, and there is exactly one cookie.
1. Who is responsible
The data controller is [DraftedBy legal name, registered address, company number], reachable at [email protected].
2. What we store
- Your email address, used only to sign you in.
- The books, recipes, notes, and photos you create.
- Your Stripe customer reference if you subscribe (we never see card numbers).
3. What we never do
- We never sell or rent your data to anyone.
- We never show advertising and never run ad trackers.
- We never use your content to train machine learning models.
- We never set analytics or marketing cookies. The only cookie is the session cookie that keeps you signed in.
4. Processors
Your data passes through these processors, strictly for the purpose listed:
- Stripe: payments and subscriptions.
- Cloudflare: hosting, object storage (photos), and email delivery.
- OpenRouter: optional AI drafting. Only the text or photo you explicitly submit for drafting is processed, under OpenRouter's no-training policy.
- MXRoute: transactional email delivery.
5. Retention and deletion
We keep your data while your account exists. You can delete books, recipes, and photos yourself at any time; deleting an account removes everything associated with it within 30 days, except records we must keep for legal or accounting reasons.
6. Your rights
You have the right to access, rectify, export, and erase your personal data, and to object to or restrict processing. Write to [email protected] and we will answer within 30 days. You also have the right to lodge a complaint with your local data protection authority (for France, the CNIL).
7. Security
Access is by magic link (no passwords to leak), sessions are hashed at rest, and connections are encrypted in transit. Backups are encrypted and retained for [backup retention period to confirm].