Recipe Buddy

Privacy in the kitchen

Who runs Recipe Buddy

Wae Fezari, France, is responsible for Recipe Buddy account data. Contact waelfezari@gmail.com for support, privacy questions, access, correction, export, objection or deletion requests. Updated October 3, 2026.

Your account and recipes

We process email, chef name, basic Google identity when used, password hashes, preferences, recipes, photos, cooking activity, friend connections, shares and contributions to provide the service you request. Google sign-in requests basic identity only, not Gmail, Drive, Calendar or contacts. Passwords are hashed; native session credentials are protected by Android Keystore. Your collection stays private until you choose each recipe to share. Friends see your chef name and shared content. Email invitations use the exact email you enter, not an uploaded address book.

Photos and optional AI

The Android app uses the camera or system photo picker only when you choose them. Selected photos are resized and re-encoded to remove metadata before upload. An ingredient photo is sent for recognition only when you tap Analyze after the disclosure. Recognition does not determine freshness, allergens or food safety; you review suggestions. Optional import, roasts and saved recipe translations send relevant recipe text to Groq; enabled photo recognition sends the selected image. Your Google tokens and profile are not sent to Groq. Manual entry works without recognition. Saved recipe photos are stored with your recipe; analysis does not retain the source image in the app database.

Voice Chef and microphone

Voice Chef reads only the current step when you tap Play, using an installed offline speech voice. Scrolling, reopening a card or moving between steps does not start speech. Pro explanations send the selected recipe step, relevant ingredients, servings and language to Groq. Pro voice commands are single requests after a disclosure and explicit tap: the phone’s chosen speech recognition service processes microphone audio under that provider’s privacy terms; recognized command text is sent to Groq to classify a small set of cooking controls. Recipe Buddy does not store microphone recordings or retain command transcripts in its database. You can cancel recognition; the app does not listen continuously. AI can make mistakes and cannot see or verify cooking. The original recipe remains visible. Playful roasts remain optional.

Your device and widget

Recipes and viewed social content are cached per account on your device. Recipe edits, comments, twists, ratings and cooked records made offline are stored in a persistent queue and sent when connectivity returns. Shopping lists, confirmed pantry ingredients, cooking progress and timer deadlines are synchronized with your account. Drafts and downloaded images remain device-local. Synchronization receipts prevent duplicate saves; conflicting edits remain on your device for your choice. Cached AI guidance and saved roasts can remain on your device until sign-out. Revoked sharing is checked when reconnecting; downloaded copies cannot be recalled while a device is offline. Sign-out/account deletion on this device clears private caches, local account data, timers and widget selections. Android backups are disabled. Other offline devices clear their local data when they reconnect and discover account revocation; uninstall or sign out to clear them immediately.

Providers, purposes and rights

Vercel hosts the website and provides website usage/performance analytics; Neon hosts PostgreSQL; Google handles optional Google authentication; Groq handles enabled recipe AI requests. Android contains no advertising or analytics SDK. Essential processing provides your requested service; security, abuse prevention and report review protect it. Optional camera/microphone access and optional recognition require your choice. Website analytics and hosting can process device/network metadata. Data may be processed outside France by these providers under their applicable safeguards. We do not sell personal data or use it for advertising. You may also complain to the CNIL at cnil.fr. We respond to rights requests within one month, subject to lawful identity checks and permitted extensions.

Retention and deletion

Account content is retained while your account is active. Delete account in Settings or use /delete-account on the website; verified deletion immediately removes the account and associated active-database recipes, photos, contributions, shares, friend connections, sessions, linked identities and attributable analysis results. Copies already made by others cannot be recalled. Account-related authentication attempts are removed. Unattributable temporary security counters and legacy analysis cache entries have expiry times and are purged by maintenance. Hosting logs and any provider-managed backups follow the operator’s configured retention; contact us for the applicable retention before sharing sensitive information. Reports are private to the operator and retained while needed for review, then removed by maintenance; account deletion removes your reports and reports identifying your deleted content.

Browser extension

The extension reads HTTPS recipe metadata locally to offer an Add prompt; it does not retain browsing history. Only clicking Add sends the selected URL and recipe metadata into a reviewable draft. No recipe is saved until you choose Save. The extension stores its suggestions preference and chosen app address locally. It has no advertising/analytics SDK and does not read passwords, authentication cookies, contacts or private tokens. You can disable suggestions, limit Chrome site access or uninstall to remove extension preferences.

Pro purchases

Google Play processes subscription payment details; Recipe Buddy does not receive card information. We store the subscription state, expiry and an encrypted purchase token linked to a hashed account identifier to verify access, restore purchases and prevent reuse. These records are deleted with your account. Deleting the account does not cancel Google Play billing; cancel the subscription in Google Play first.

Connected meals and private health profiles

Meal plans, pantry batches, confirmed purchases, cooking occasions, eating records and leftovers are stored to connect your kitchen tasks. Cooking records stock use; it does not imply you ate the meal. Optional occasion photos are re-encoded and kept private. Sharing a cooking result explicitly publishes only your caption and selected photo/rating fields to current unblocked friends; recipe access remains separate. Removing friendship revokes future post/media access. Household roles permit plans or stock editing without exposing another adult’s private health details. A profile manager can consent to private restriction checks, export data or delete the profile and eating history to withdraw. Child profiles require an authorized caregiver. No raw health data is sent to AI, friends or general analytics by these features. Drafts and pending changes on Android are stored in account-scoped app storage and purged on logout. Server records remain until deletion; account deletion removes private profiles/publications and private occasion/eating records, retaining shared stock totals without personal attribution. Backups and operator access follow the service retention policy; independent privacy and intended-purpose review are required before health launch. No country/age/condition capability is clinically validated. Missing ingredients, labels, cross-contact, nutrients and unlogged meals remain unknown; the app does not provide dosing, diagnoses or food-safety certification.

Check-in, preparation and grocery handoff

Kitchen check-in is optional. Each answer saves separately; skipped questions remain unknown. Preparation tasks record user instructions and optional known timing. Actual preparation ingredient use is credited once against linked final cooking. Calendar reminders are managed by the calendar service you choose; no health details are placed in reminder titles. Pro rescue previews future meal changes and creates no purchases or eating records. Online grocery selection is distinct from purchased checkmarks. Instacart development handoff shares only selected ingredient requirements, after your action, and requires provider access; it is not proof of an order. No France retailer checkout or service location is verified. Orders can be reconciled manually using actual retailer evidence, and only actual received products replenish stock. Retailer login and payment details are not stored by Recipe Buddy. Refunds alone remove no stock. Account deletion removes an owned household kitchen and its shared records; export needed household records before deleting the owner account. Backup expiry and operator access controls must be verified before production health launch.

Daily nutrition and prescribed targets

Private nutrition records may include user-entered composition for the actual consumed portion, its source, nutrient target bounds, prescription references, issue/review dates and an explicit day-completeness confirmation. These are accessible only to the profile manager and are included in export, profile withdrawal and account deletion. Prescription references are user declarations, not verified medical prescriptions. A recorded-day comparison is not a diagnosis or a complete vitamin/mineral assessment. Medical profiles require explicitly confirmed clinician-prescribed targets. Recipe Buddy generates no prescriptions or insulin doses. Independent clinical and privacy/intended-purpose review remain required before health launch.

Delete my account · Terms of use

waelfezari@gmail.com