Privacy Policy
Last updated: August 21, 2026
ChefMindAI ("ChefMindAI," "we," "our," or "us") provides a cooking and meal-planning application and website (the "Service"). This Policy explains what information we collect, why we use it, the service providers that process it, how long it is kept, and the choices available to you.
We do not sell personal information and do not use personal information for third-party targeted advertising.
1. Information we collect
- Account and profile information: name, email address, Supabase user ID, authentication provider, profile image, app language, and account settings. Apple may provide a private relay email address when you use Sign in with Apple.
- Cooking and user content: pantry and shopping-list items, recipes, recipe photos, meal plans, households, prompts, cooking questions, imported recipe links, and preferences you choose to save.
- Dietary and sensitive preferences: allergies, intolerances, health-oriented food goals, and lifestyle or belief-related food choices such as Halal or Kosher. These fields are optional and are used to personalize cooking results. They are not used for advertising.
- Photos and camera data: images you select or take for ingredient scanning, profile images, and recipe photos. Camera access occurs only after you choose a camera feature. Scanner images may be sent through our Supabase backend to Google Gemini for analysis.
- Voice input: microphone audio is accessed only when you start voice input or a voice cooking feature. Speech may be processed by operating-system speech services. ChefMindAI does not intentionally retain raw microphone recordings on its servers.
- Purchases: subscription product, entitlement, transaction status, store, renewal, cancellation, and expiration information supplied by RevenueCat, Apple, or Google. Payment-card information is handled by the app store and is not available to us.
- Device and operational information: Firebase installation and push tokens, device platform, notification and language preferences, IP address, request metadata, authentication events, generation-job status, usage counters, and security or diagnostic logs produced by Supabase and our backend.
2. Device permissions
- Camera and photo library: scan ingredients, choose a profile image, or attach a photo to a recipe.
- Microphone and speech recognition: accept a voice search or cooking command when you explicitly start listening.
- Notifications: deliver recipe-ready, service, security, household, and product-announcement messages. The app may request notification permission for a new account, but the operating system controls whether permission is granted. You can disable notifications in ChefMindAI Settings or device Settings.
- Biometrics: Face ID, Touch ID, or Android biometrics can unlock a locally protected sign-in session. The biometric template remains with the operating system; ChefMindAI receives only the success or failure result.
3. How we use information
- Operate accounts, sync data, and provide offline-capable features.
- Generate and personalize recipes and cooking guidance.
- Save and share content when you request those actions.
- Process subscriptions and enforce feature entitlements.
- Deliver enabled notifications and product announcements.
- Prevent abuse, secure the Service, diagnose failures, and improve reliability.
- Respond to support requests and comply with legal obligations.
4. Service providers and disclosures
We disclose only the information reasonably needed for a provider to perform the service described below. Provider processing is also governed by that provider's contractual terms and privacy protections.
| Provider | Purpose | Information involved |
|---|---|---|
| Vercel | Host and deliver the ChefMindAI website, including the privacy, support, account-deletion, and password-reset pages. | IP address, browser and device information, requested page, request time, and hosting or security logs generated when you visit the website. |
| Supabase | Cloud hosting, account authentication, database storage, file storage, Edge Functions, security events, and operational logs. | Account identifiers, profile and app content, uploaded files, IP/device and request information, and service logs. |
| Firebase Cloud Messaging (Google) | Deliver recipe-ready, service, security, and optional product-announcement push notifications. | Firebase installation and push registration identifiers, device platform, notification preference, and app language. |
| RevenueCat, Apple App Store, and Google Play | Offer subscriptions, verify entitlements, restore purchases, and prevent billing fraud. | ChefMindAI account identifier, product and entitlement identifiers, store, purchase status, renewal and expiration information. ChefMindAI does not receive full payment-card details. |
| Apple and Google | Provide optional Sign in with Apple and Google Sign-In. | Provider account identifier, email address, and name when the provider makes them available and you authorize sharing. |
| Google Gemini | Generate recipes, answer cooking questions, interpret recipe links, and analyze ingredient-scanner images. | Prompts, selected pantry and dietary context, recipe content, shared-link content, and scanner images needed to complete the requested AI feature. |
| Pexels | Provide optional food imagery for generated recipes. | A recipe-related image search query and standard network request information; not your ChefMindAI account profile. |
We may also disclose information when required by law, to protect the Service or its users, or as part of a business transaction subject to appropriate safeguards. We do not allow service providers to use ChefMindAI data for their own advertising.
5. AI processing
When you request an AI feature, the prompt and the context needed for that request may be sent to Google Gemini through a ChefMindAI Supabase Edge Function. Context can include pantry items, dietary preferences, a recipe, conversation history for the active request, the contents of a recipe link, or a scanner image.
Do not submit information that you do not want processed for the requested feature. AI output may be inaccurate and must not be treated as medical advice or a guarantee that a recipe is allergen-free.
6. Retention
- Account, profile, pantry, recipe, meal-plan, household, preference, and uploaded content is kept while your account remains active or until you delete the content.
- Ingredient-scanner uploads are temporary and are scheduled for deletion immediately after the scan is processed, including when analysis fails.
- Firebase push tokens are kept while registered to your account and removed or disabled when you turn notifications off, sign out, the token is replaced, or you delete your account.
- Recipe-generation job results expire for app access after seven days and are removed during routine backend cleanup or when the account is deleted. Security, authentication, and operational logs may be retained for up to 90 days, unless a longer period is necessary to investigate abuse or meet a legal obligation.
- Subscription and transaction history may be retained by Apple, Google, and RevenueCat for billing, tax, fraud-prevention, and legal purposes according to their policies, even after a ChefMindAI account is deleted.
- Deleted data may remain in encrypted provider backups until the applicable backup cycle completes, normally within 30 days, and is not used in the live Service during that period.
7. Account and data deletion
You can permanently delete a signed-in account inside the app from Settings → Delete Account. This removes the ChefMindAI authentication account and associated profile, recipes, pantry, cart, prompts, meal plans, household ownership or membership, push registrations, generation records, usage records, and uploaded profile or recipe images from active systems.
Deleting ChefMindAI does not automatically cancel an active App Store or Google Play subscription. Cancel it in the store's subscription settings to prevent future renewal.
If you used Sign in with Apple, the app also directs you to remove ChefMindAI under Apple Account Settings → Sign in with Apple. This revokes the separate Apple authorization when a revocable Apple token is not available to ChefMindAI.
If you cannot access the app, follow the instructions on our account deletion page or email support@chefmindai.ai from the registered address. Verified requests are processed within 30 days.
8. Security and international processing
We use access controls, encrypted network transport, private scanner storage, row-level database authorization, and restricted backend credentials. No security measure can eliminate all risk.
Our providers may process information in countries other than yours. Where required, we rely on contractual and legal safeguards for those transfers.
9. Children
ChefMindAI is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child provided information in violation of this section, contact us so we can investigate and delete it.
10. Your choices and rights
Depending on where you live, you may have rights to access, correct, export, object to, restrict, or delete personal information. You can edit profile and dietary preferences in the app, disable permissions in device Settings, disable push notifications in ChefMindAI Settings, and delete your account in the app. Contact us for other requests.
11. Policy changes
We may update this Policy as the Service changes. We will post the current version here, update the date above, and provide additional notice when required by law.
12. Contact us
Questions or privacy requests: support@chefmindai.ai