This Privacy Policy explains how Azat Berdimyradov (“ChefBook”, “we”, “us”, or “our”) collects, uses, shares, and protects personal data when you use the ChefBook mobile application for iOS and Android (the “App”), our website at https://chefbook.net, and the related backend services (together, the “Service”).
By using the Service you agree to this Privacy Policy. If you do not agree, please do not use the Service.
1. Who we are
| Data controller | Azat Berdimyradov, established in Türkiye |
| Privacy contact | [email protected] |
| Postal address | Available on request — email [email protected] |
| App identifier | ai.chefbook.app (iOS App Store and Google Play) |
For users in the European Economic Area (EEA), the United Kingdom, and Switzerland, we act as the data controller for the personal data described in this policy.
2. Data we collect
We collect only what the App needs in order to work. The categories below reflect what the App actually sends to our servers or to our service providers.
2.1 Account data
Collected when you create an account or sign in:
- Email address — used as your account identifier and for security notifications and account-deletion confirmation codes.
- Username — chosen by you; visible to other users on content you publish.
- First and last name — optional profile fields.
- Profile picture (avatar) — optional; uploaded by you.
- Authentication identifiers — if you sign in with Google or Apple, we receive a unique identifier from that provider plus the email address and name you agree to share. We never receive your Google or Apple password. If you use Sign in with Apple and choose “Hide My Email”, we only ever see Apple’s private relay address.
- Session tokens — stored on your device so you stay signed in.
2.2 Content you create
- Recipes you write, import, or edit (titles, ingredients, steps, notes, times, servings, tags, and photos you attach).
- Cookbooks you create, and the recipes you save, like, or add to them.
- Grocery lists and their items.
- Meal plans and the dates you assign recipes to.
- The visibility setting of each recipe or cookbook — private (visible only to you) or public (visible to other ChefBook users in Discover and search).
2.3 Recipe import and AI processing data
When you use an import or AI feature, the input you supply is transmitted to our servers and processed by our AI providers:
| Feature | What is sent |
|---|---|
| Import from link | The URL you paste, and the public page content fetched from it |
| Import from text | The text you paste or share into the App |
| Import from photo | The image you select or capture, for text recognition |
| AI recipe completion | The partial recipe fields you have entered |
| Nutrition calculation | The ingredient list and servings of the recipe |
| Recipe translation | The recipe text and target language |
| “What to cook” | The ingredients, preferences, and filters you enter in the wizard |
These inputs are processed to return a result to you. We instruct our AI processors not to use your content to train their general-purpose models.
2.4 Onboarding preferences
During onboarding we ask optional questions and store your answers to personalise recommendations: cooking goals, cooking frequency, dietary preference, where you usually get recipes from, and how you heard about ChefBook.
2.5 Subscription and purchase data
Purchases are processed by Apple or Google, not by us. We never receive or store your card number, bank details, or billing address. Through our subscription provider RevenueCat we receive: the product you purchased, purchase and expiry dates, trial and renewal status, the store used, and an anonymous subscriber identifier linked to your account. We also store your remaining free-tier usage quotas (for example, imports left this period).
2.6 Usage and diagnostic data
- Analytics events (via Google Firebase Analytics): screen views, sign-in and sign-up events, recipe created/imported/shared, search queries you enter in the App, cookbook and grocery actions, meal-plan actions, paywall views, trial starts, purchases, and feature gates reached. Events are tied to a pseudonymous app-instance identifier.
- Crash and stability data (via Firebase Crashlytics): crash stack traces, device model, OS version, app version, and the sequence of events before a crash.
- Technical data: app version, platform, language, timezone, and IP address (used to deliver responses and for security and abuse prevention; we do not use it to build a location profile).
2.7 Push notification data
If you allow notifications, we store a push token (Firebase Cloud Messaging / Apple Push Notification service) so we can send cooking reminders, meal-plan prompts, and product updates. You can withdraw this at any time in your device settings.
2.8 Device permissions
The App requests these permissions only when you use the related feature:
- Camera — to photograph a recipe or a dish. Images are used only for the action you started.
- Photo library — to attach an existing image to a recipe or profile.
- Notifications — to send the reminders described above.
Denying a permission disables only that feature; the rest of the App keeps working.
2.9 What we do not collect
We do not collect precise location, contacts, calendar, microphone audio, health data, biometric data, browsing history outside the App, or payment card details. We do not sell personal data, and we do not use your data for third-party advertising or cross-app tracking.
3. Why we use your data, and our legal bases
For users protected by the GDPR/UK GDPR, we rely on the following legal bases:
| Purpose | Legal basis |
|---|---|
| Create and maintain your account; sync your recipes across devices | Performance of a contract (Art. 6(1)(b)) |
| Provide import, AI, nutrition, translation and recommendation features you invoke | Performance of a contract (Art. 6(1)(b)) |
| Process subscriptions, trials, entitlements and usage quotas | Performance of a contract (Art. 6(1)(b)) |
| Publish content you explicitly mark as public | Consent (Art. 6(1)(a)) — you choose the visibility |
| Send push notifications | Consent (Art. 6(1)(a)) — via the OS permission prompt |
| Analytics and product improvement | Consent where required, otherwise legitimate interests (Art. 6(1)(f)) |
| Crash reporting, security, fraud and abuse prevention | Legitimate interests (Art. 6(1)(f)) |
| Respond to support requests | Legitimate interests (Art. 6(1)(f)) |
| Comply with tax, accounting and legal obligations | Legal obligation (Art. 6(1)(c)) |
Where we rely on consent, you may withdraw it at any time — this does not affect processing carried out before withdrawal.
4. Who we share data with
We share personal data only with the service providers below, only to the extent needed, and under contracts that require them to protect it. We never sell your personal data.
| Provider | Purpose | Privacy policy |
|---|---|---|
| Google Firebase (Analytics, Crashlytics, Cloud Messaging) | Analytics, crash reporting, push delivery | https://firebase.google.com/support/privacy |
| Google Sign-In | Authentication | https://policies.google.com/privacy |
| Apple (Sign in with Apple, APNs, App Store) | Authentication, push, purchases | https://www.apple.com/legal/privacy/ |
| Google Play Billing | Purchases on Android | https://policies.google.com/privacy |
| RevenueCat, Inc. | Subscription management and entitlements | https://www.revenuecat.com/privacy |
| Our cloud hosting and storage provider | Running the ChefBook backend and storing your content | Available on request |
| Our AI processing provider(s) | Recipe import, AI completion, nutrition, translation | Available on request |
We may also disclose data (a) to comply with a valid legal request or court order, (b) to enforce our Terms of Service, (c) to protect the rights, safety, or property of ChefBook, our users, or the public, and (d) to a successor entity in a merger, acquisition, or asset sale — in which case we will notify you and this policy will continue to apply until replaced.
5. Content you make public
Recipes and cookbooks you set to public are visible to other ChefBook users — including your username and avatar — in Discover, search results, and shared links. Anyone who can see them may copy or re-share them. Do not put personal or sensitive information in public content. Setting content back to private removes it from public surfaces, but copies already made by other users, or pages already cached by search engines, are outside our control.
6. International data transfers
Our servers and our providers may be located outside your country, including in the United States and the European Union. When we transfer personal data out of the EEA, the UK, or Switzerland, we rely on the European Commission’s Standard Contractual Clauses (and the UK Addendum where applicable), together with additional technical and organisational safeguards. You may request a copy of the relevant safeguards at [email protected].
7. How long we keep data
| Data | Retention |
|---|---|
| Account and profile data | Until you delete your account |
| Your recipes, cookbooks, grocery lists, meal plans | Until you delete them, or you delete your account |
| Import / AI inputs | Processed transiently; not retained beyond what is needed to return and store the result |
| Analytics events | Up to 14 months (Firebase Analytics retention setting) |
| Crash reports | Up to 90 days |
| Push tokens | Until you disable notifications or delete your account |
| Purchase and subscription records | As long as required by tax and accounting law (typically up to 10 years) |
| Support correspondence | Up to 24 months after the request is closed |
When you delete your account we erase or irreversibly anonymise your personal data within 30 days, except records we are legally required to keep (for example, purchase receipts). Encrypted backups are purged on their normal rotation cycle, within 90 days.
8. Your rights
Depending on where you live, you may have the right to:
- Access the personal data we hold about you and receive a copy.
- Rectify inaccurate or incomplete data — most profile fields are editable in the App.
- Erase your data (“right to be forgotten”).
- Restrict or object to certain processing, including profiling for recommendations.
- Data portability — receive your data in a structured, machine-readable format.
- Withdraw consent at any time.
- Lodge a complaint with your local data protection authority.
Deleting your account: open the App → Profile → Settings → Delete account. We send a confirmation code to your email address; entering it permanently deletes your account and content. You can also email [email protected] and we will action the request.
Exercising other rights: email [email protected]. We respond within 30 days (extendable by two further months for complex requests, with notice). We may ask you to verify ownership of the account email before we act.
California residents (CCPA/CPRA)
You have the right to know what personal information we collect, to delete it, to correct it, and to opt out of its “sale” or “sharing”. ChefBook does not sell or share personal information as those terms are defined by the CPRA, and we do not knowingly process the personal information of consumers under 16 for those purposes. We will not discriminate against you for exercising your rights. To make a request, email [email protected].
9. Children’s privacy
ChefBook is not directed to children. You must be at least 13 years old (or 16 in the EEA and UK, or the minimum digital-consent age in your country) to create an account. We do not knowingly collect personal data from children below that age. If you believe a child has provided us with personal data, contact [email protected] and we will delete it promptly.
10. Security
We protect your data with encryption in transit (HTTPS/TLS), encryption at rest for stored content, access controls limiting staff access to what is strictly necessary, secure token storage in the platform keystore on your device, and regular dependency and security updates.
No system is perfectly secure. If a data breach is likely to result in a high risk to your rights and freedoms, we will notify you and the competent supervisory authority without undue delay, and within 72 hours where the GDPR requires it.
11. Offline and on-device data
The App stores a local copy of your recipes, cookbooks, grocery lists, meal plans, and settings on your device so it works offline. This data stays on your device and is removed when you sign out or uninstall the App.
12. Third-party links
Imported recipes may link to external websites. We are not responsible for the privacy practices or content of those sites; their own policies apply.
13. Changes to this policy
We may update this Privacy Policy. The “Last updated” date at the top always reflects the current version. For material changes we will notify you in the App or by email at least 30 days before they take effect. Continuing to use the Service after the effective date means you accept the updated policy.
14. Contact us
| Privacy enquiries and general support | [email protected] |
| Controller | Azat Berdimyradov, established in Türkiye |
| Postal address | We will provide our full registered postal address on request — email [email protected] |
Email is the fastest way to reach us and is monitored for all privacy requests. Our registered address is also published on our App Store and Google Play listings.
If you are in the EEA or UK and are not satisfied with our response, you may complain to your national data protection authority.
See also our Terms of Service.