The short version
Pipkin contains no analytics SDK, no advertising SDK, and no third-party tracker. We do not build an advertising profile of you, we do not track you across other apps or websites, and we do not sell or share your personal data for advertising. We do not access your location, contacts, calendar, or health data.
What we hold is the account you created and the food and recipe data you entered. The rest of this document is the detail.
What we collect
Account information, when you sign up:
- Your email address, used to sign you in and to send password resets and confirmations.
- Your password, stored only as a salted hash by our authentication provider. We never see or store the password itself.
- The display name you choose. This is shown to other users on any recipe you submit and any review you write.
- The language you choose in the app. It is stored with your account so that confirmation and password-reset emails reach you in it.
Content you create
This is the substance of the app, and it is stored against your account so it is there on your next device:
- Kitchen items: the name, quantity, unit, category and expiry date of each item of food you add.
- Saved recipes, and your dietary preferences.
- Recipes you submit, including any photo you attach. See “What other people can see” — these are published.
- Reviews you write, including the star rating, the text, and your display name.
- Cooking history: when you mark a recipe cooked, we record which items left your kitchen, whether they were used or discarded, and an estimated weight and value for each. This is what the Impact figures are computed from.
- Your chosen language and whether expiry reminders are on.
Subscription information
If you subscribe to Pipkin+, our subscription infrastructure provider gives us a customer identifier, which store the purchase came from, your current tier, and the date the period ends. We use these to unlock paid features and for nothing else.
We never receive your card number, billing address, or any other payment credential. Payment is handled entirely by Apple or Google and never touches our systems.
Photographs
Two different things happen to photographs, and the difference matters:
- A photo you take to scan your kitchen is sent to our server, forwarded to our AI provider to identify the food in it, and then discarded. We do not save it, and it is not written to any database or storage of ours. See “Automated processing”.
- A photo you attach to a recipe you submit is uploaded and stored, and is served from a public address so it can appear on the recipe. Do not attach a photo you would not publish.
Technical information
Our backend keeps ordinary server logs, which include IP addresses and timestamps of requests. These exist to operate and secure the service — to investigate errors and abuse — and are not used to profile you.
Expiry and renewal reminders are local notifications scheduled on your device. There is no push token, no notification server, and nothing about your food leaves the device to produce them.
Automated processing and AI
Two features use artificial intelligence. The first is optional: scanning your kitchen by photograph. When you use it, the photograph is sent to Anthropic, PBC and processed by a Claude model, which returns a list of the foods it believes it can see. That list is shown to you and only added to your kitchen with your confirmation.
The second is translating community recipes. When a moderator approves a recipe somebody submitted, its title and method are sent to Anthropic and translated into the app's other languages, so a recipe written in Czech can be cooked by somebody reading Italian. Only the recipe text is sent — never the author's name, account or email. Translations made this way are labelled as automatic wherever they appear, and withdrawing a recipe removes them with it.
- It is optional. Barcode scanning and typing an item in do the same job without any AI, and both are always available.
- Under Anthropic's commercial terms, data sent through their API is not used to train their models. Anthropic may retain it briefly for abuse monitoring.
- It can be wrong. It identifies food, nothing else. There is no automated decision-making producing legal effects concerning you, or similarly significantly affecting you, within the meaning of Article 22 GDPR. You can edit or delete anything it adds.
- Photographs of people are not what it is for. Point it at a shelf.
- No other feature uses AI. Recipe matching, ranking and the Impact estimates are ordinary arithmetic, and the curated recipe catalogue is written and translated by people.
Who else processes your data
We use the following providers. Each acts on our instructions, except Apple and Google, who are independent controllers for the payment:
- Supabase — database, authentication and file storage. Holds everything described above. Hosted in the European Union.
- Anthropic — the AI model behind photo scanning and community recipe translation. Receives the photograph when you scan, and the text of a community recipe when it is approved. Never your account, your email, or your kitchen.
- RevenueCat — subscription state. Receives a customer identifier and purchase events.
- Apple and Google — take the payment and run the subscription. Their own privacy policies apply to that transaction.
- Open Food Facts — the barcode database. When you scan a barcode we send the number on the packet and nothing else: no account, no identifier, no photograph.
- Košík and Rohlík — the two grocery shops offered under the shopping list, and only if you tap an item there. That opens the shop's own site with that one ingredient as a search. Nothing about you is sent, and nothing at all is sent unless you tap.
- Resend — email delivery. Sends the confirmation and password-reset messages, and so receives your email address and the text of those messages. Nothing else about you reaches it, and it is never used for marketing.
- Vercel — hosts pipkin.eu, where this policy and the terms are published. It keeps ordinary request logs, including IP addresses, for pages you visit there. The app itself never talks to it, and the site sets no cookies and runs no analytics.
- Expo — the framework the app is built and delivered with.
What other people can see
Most of what you enter is private to your account. Your kitchen, your saved recipes, your dietary preferences, your cooking history and your Impact figures are visible only to you.
Five things are public: your display name, the profile photo you choose if you upload one, any review you write, any recipe you submit once it is approved, including its photo, and — once you have submitted a recipe — a profile page carrying your display name, your photo, the year you joined, and the recipes of yours that have been approved. A profile photo is optional; without one, the first letter of your display name is shown instead. Changing your display name updates it on your past reviews.
The profile page shows nothing beyond those. Your kitchen, your cooking history, your streak, your dietary preferences, your allergens and your subscription are not on it and are not visible to anyone else. If you have never submitted a recipe, you have no profile page.
Why we are allowed to hold it
The legal bases under the GDPR — and, for users in Switzerland, the corresponding grounds under the revised Federal Act on Data Protection — are:
- Performance of a contract (Art. 6(1)(b)) — your account, your kitchen data, and your subscription. Without these the app cannot function.
- Consent (Art. 6(1)(a)) — camera access, notifications, and each individual photo scan. Each is asked for separately and can be withdrawn at any time in your device settings, without losing the rest of the app. Withdrawal does not affect the lawfulness of what was done before it.
- Legitimate interests (Art. 6(1)(f)) — security logging, preventing abuse, and moderating submitted recipes. Our interest is in running a service that works and is not defrauded; we consider this proportionate because none of it profiles you or is used to market to you.
How long we keep it
- Your account data, for as long as the account exists.
- Kitchen items, until you remove them or cook with them. A cooking history record then remains, so the Impact totals stay correct.
- Server logs, for a short operational period.
- Scan photographs are not kept by us at all.
- Published recipes and reviews may remain after you delete your account, with your name removed — see below.
Your rights
You have the right of access, rectification, erasure, restriction of processing, data portability, and objection to processing based on legitimate interests. Where processing rests on consent, you may withdraw it at any time.
You can see and change most of your data directly in the app: your display name and preferences in Settings, your kitchen on the Kitchen tab, your reviews on each recipe.
You can delete your account from Settings. Doing so permanently removes your profile, your kitchen, your saved recipes, your cooking history and your login. Recipes and reviews you published are kept, with your name replaced and the link to your account removed, because other users have saved those recipes and deleting them would take away someone else's. If you want a published recipe or review taken down as well, ask us before you delete, while we can still identify it as yours.
Deleting your account does not cancel a Pipkin+ subscription. That is held by Apple or Google, not by us, and we cannot cancel it on your behalf — cancel it in your store account settings first, or you will continue to be charged for an account that no longer exists.
To exercise any of these, write to privacy@pipkin.eu. We will respond within one month, and will say so if we need longer.
If you are in California, we do not sell or share personal information as the CCPA defines those terms, and have not done so in the preceding twelve months. Exercising a right will never get you a worse version of the app.
Complaining to a regulator
If you think we have handled your data unlawfully, please tell us first — most problems are a misunderstanding we can fix quickly. You may also complain to a supervisory authority, in the country you live in, the country you work in, or where the problem happened:
- Czechia — Úřad pro ochranu osobních údajů (uoou.gov.cz)
- Slovakia — Úrad na ochranu osobných údajov SR (dataprotection.gov.sk)
- Germany — your state data protection authority, or the BfDI (bfdi.bund.de)
- Austria — Datenschutzbehörde (dsb.gv.at)
- Switzerland — Federal Data Protection and Information Commissioner (edoeb.admin.ch)
- Italy — Garante per la protezione dei dati personali (garanteprivacy.it)
- France — CNIL (cnil.fr)
Where your data is
Our database and file storage are hosted in the European Union. Our AI, email, subscription, store and website-hosting providers are established in the United States, so a photo scan, an account email, your subscription state and a visit to our website involve a transfer there. Those transfers are made under the European Commission's standard contractual clauses, which the Swiss authority also recognises with its own amendments.
Users in Switzerland
If you are in Switzerland, the revised Federal Act on Data Protection (revFADP) applies to you alongside this policy. Your rights of access, correction and deletion are as described above; the supervisory authority is the Federal Data Protection and Information Commissioner (edoeb.admin.ch).
Our representative in Switzerland, where one is required under art. 14 revFADP, is «Swiss representative, if one is required».
Children
Pipkin is not directed at children and is not for anyone under 16, or under the lower age your country sets for consent to information society services (13 in some member states). We do not knowingly collect anything from them. Write to privacy@pipkin.eu if you believe a child has created an account and we will delete it.
Security
Traffic is encrypted in transit. Data is stored with row-level access rules so one account cannot read another's, and the keys for our AI provider and our subscription webhook are held on the server and are not present in the app you install. No system is perfectly secure and we do not claim otherwise; if a breach ever puts your rights at risk we will tell you, and the regulator, as the GDPR requires.
Changes
If we change this policy materially we will update the date at the top and tell you in the app before the change takes effect.
Contact
Jakub Andrejco
Lopuchová 56/17, Antošovice, 711 00 Ostrava
29914477
privacy@pipkin.eu