The short version
Pipkin contains no analytics SDK, no advertising SDK, and no third-party tracker. We do not build an advertising profile of you, we do not track you across other apps or websites, and we do not sell or share your personal data for advertising. We do not read your device's location, contacts, calendar, or Apple Health and Google Fit data.
One piece of health information is held, and only because you typed it in: the allergens you ask us to keep out of your results. It is optional, it is private to your account, and it is covered in detail below.
What we hold is the account you created and the food and recipe data you entered. The rest of this document is the detail.
What we collect
Account information, when you sign up:
- Your email address, used to sign you in and to send password resets and confirmations.
- Your password, stored only as a salted hash by our authentication provider. We never see or store the password itself.
- The display name you choose. This is shown to other users on any recipe you submit and any review you write.
- The language you choose in the app. It is stored with your account so that confirmation and password-reset emails reach you in it.
Content you create
This is the substance of the app, and it is stored against your account so it is there on your next device:
- Kitchen items: the name, quantity, unit, category and expiry date of each item of food you add.
- Saved recipes, and your dietary preferences.
- The allergens you choose to avoid, if you set any. Allergy information is health data, which the law treats as a special category, so it is worth being exact: we hold it only because you entered it, we use it only to hide recipes listing those ingredients from your own results, we never show it to anyone else, and clearing the list deletes it. Leaving it empty costs you nothing else in the app.
- Recipes you submit, including any photo you attach. See “What other people can see” — these are published.
- Reviews you write, including the star rating, the text, and your display name.
- Cooking history: when you mark a recipe cooked, we record which items left your kitchen, whether they were used or discarded, and an estimated weight and value for each. This is what the Impact figures are computed from.
- Your chosen language and whether expiry reminders are on.
Subscription information
If you subscribe to Pipkin+, our subscription infrastructure provider gives us a customer identifier, which store the purchase came from, your current tier, and the date the period ends. We use these to unlock paid features and for nothing else.
We never receive your card number, billing address, or any other payment credential. Payment is handled entirely by Apple or Google and never touches our systems.
Photographs
Three different things happen to photographs, and the differences matter:
- A photo you take to scan your kitchen is sent to our server, forwarded to our AI provider to identify the food in it, and then discarded. We do not save it, and it is not written to any database or storage of ours. See “Automated processing”.
- A photo you attach to a recipe you submit is uploaded and stored, and is served from a public address so it can appear on the recipe. Do not attach a photo you would not publish.
- A profile photo, if you upload one, is stored and served from a public address so it can appear beside your reviews and on your cook profile. It is optional — without one we show the first letter of your display name — and you can remove it at any time in Settings.
Technical information
Our backend keeps ordinary server logs, which include IP addresses and timestamps of requests. These exist to operate and secure the service — to investigate errors and abuse — and are not used to profile you.
Expiry and renewal reminders are local notifications scheduled on your device. There is no push token, no notification server, and nothing about your food leaves the device to produce them.
Automated processing and AI
Two features use artificial intelligence. The first is optional: scanning your kitchen by photograph. When you use it, the photograph is sent to Anthropic, PBC and processed by a Claude model, which returns a list of the foods it believes it can see. That list is shown to you and only added to your kitchen with your confirmation.
The second is translating community recipes. When a moderator approves a recipe somebody submitted, its title and method are sent to Anthropic and translated into the app's other languages, so a recipe written in Czech can be cooked by somebody reading Italian. Only the recipe text is sent — never the author's name, account or email. Translations made this way are labelled as automatic wherever they appear, and withdrawing a recipe removes them with it.
- It is optional. Barcode scanning and typing an item in do the same job without any AI, and both are always available.
- Under Anthropic's commercial terms, data sent through their API is not used to train their models. Anthropic may retain it briefly for abuse monitoring.
- It can be wrong. It identifies food, nothing else. There is no automated decision-making producing legal effects concerning you, or similarly significantly affecting you, within the meaning of Article 22 GDPR. You can edit or delete anything it adds.
- Photographs of people are not what it is for. Point it at a shelf.
- No other feature uses AI. Recipe matching, ranking and the Impact estimates are ordinary arithmetic, and the curated recipe catalogue is written and translated by people.
Who else processes your data
We use the following providers. Each acts on our instructions, except Apple and Google, who are independent controllers for the payment:
- Supabase — database, authentication and file storage. Holds everything described above. Hosted in the European Union.
- Anthropic — the AI model behind photo scanning and community recipe translation. Receives the photograph when you scan, and the text of a community recipe when it is approved. Never your account, your email, or your kitchen.
- RevenueCat — subscription state. Receives a customer identifier and purchase events.
- Apple and Google — take the payment and run the subscription. Their own privacy policies apply to that transaction.
- Open Food Facts — the barcode database. When you scan a barcode we send the number on the packet and nothing else: no account, no identifier, no photograph.
- Resend — email delivery. Sends the confirmation and password-reset messages, and so receives your email address and the text of those messages. Nothing else about you reaches it, and it is never used for marketing.
- Vercel — hosts pipkin.eu, where this policy and the terms are published. It keeps ordinary request logs, including IP addresses, for pages you visit there. The app itself never talks to it, and the site sets no cookies and runs no analytics.
- Expo — the framework the app is built and delivered with.
What other people can see
Most of what you enter is private to your account. Your kitchen, your saved recipes, your dietary preferences, your cooking history and your Impact figures are visible only to you.
Five things are public: your display name, the profile photo you choose if you upload one, any review you write, any recipe you submit once it is approved, including its photo, and — once you have submitted a recipe — a profile page carrying your display name, your photo, the year you joined, and the recipes of yours that have been approved. A profile photo is optional; without one, the first letter of your display name is shown instead. Changing your display name updates it on your past reviews.
The profile page shows nothing beyond those. Your kitchen, your cooking history, your streak, your dietary preferences, your allergens and your subscription are not on it and are not visible to anyone else. If you have never submitted a recipe, you have no profile page.
Why we are allowed to hold it
The legal bases under the GDPR are:
- Performance of a contract (Art. 6(1)(b)) — your account, your kitchen data, and your subscription. Without these the app cannot function.
- Consent (Art. 6(1)(a)) — camera access, notifications, and each individual photo scan. Each is asked for separately and can be withdrawn at any time in your device settings, without losing the rest of the app. Withdrawal does not affect the lawfulness of what was done before it.
- Explicit consent (Art. 9(1) and 9(2)(a)) — the allergen list, and only that. Allergy information is data concerning health, which Art. 9 prohibits processing unless one of its conditions is met; ours is your explicit consent, given by entering the list. We never infer it from anything else you do in the app, and clearing the list withdraws the consent and erases the data.
- Legitimate interests (Art. 6(1)(f)) — security logging, preventing abuse, and moderating submitted recipes. Our interest is in running a service that works and is not defrauded; we consider this proportionate because none of it profiles you or is used to market to you.
How long we keep it
- Your account data, for as long as the account exists.
- Kitchen items, until you remove them or cook with them. A cooking history record then remains, so the Impact totals stay correct.
- Server logs, for a short operational period.
- Scan photographs are not kept by us at all.
- Published recipes and reviews may remain after you delete your account, with your name removed — see below.
Your rights
You have the right of access, rectification, erasure, restriction of processing, data portability, and objection to processing based on legitimate interests. Where processing rests on consent, you may withdraw it at any time.
You can see and change most of your data directly in the app: your display name and preferences in Settings, your kitchen on the Kitchen tab, your reviews on each recipe.
You can delete your account from Settings. Doing so permanently removes your profile, your kitchen, your saved recipes, your cooking history and your login. Recipes and reviews you published are kept, with your name replaced and the link to your account removed, because other users have saved those recipes and deleting them would take away someone else's. If you want a published recipe or review taken down as well, ask us before you delete, while we can still identify it as yours.
Deleting your account does not cancel a Pipkin+ subscription. That is held by Apple or Google, not by us, and we cannot cancel it on your behalf — cancel it in your store account settings first, or you will continue to be charged for an account that no longer exists.
A step-by-step page on deleting your account — the procedure, what is deleted, what is kept and for how long — is at https://pipkin.eu/delete-account.
To exercise any of these, write to privacy@pipkin.eu. We will respond within one month, and will say so if we need longer.
If you are in California, we do not sell or share personal information as the CCPA defines those terms, and have not done so in the preceding twelve months. Exercising a right will never get you a worse version of the app.
Complaining to a regulator
If you think we have handled your data unlawfully, please tell us first — most problems are a misunderstanding we can fix quickly. You may also complain to a supervisory authority, in the country you live in, the country you work in, or where the problem happened:
- Czechia — Úřad pro ochranu osobních údajů (uoou.gov.cz)
- Slovakia — Úrad na ochranu osobných údajov SR (dataprotection.gov.sk)
- Germany — your state data protection authority, or the BfDI (bfdi.bund.de)
- Austria — Datenschutzbehörde (dsb.gv.at)
- Italy — Garante per la protezione dei dati personali (garanteprivacy.it)
- France — CNIL (cnil.fr)
- Anywhere else in the EU or the EEA — your own national data protection authority. The European Data Protection Board lists every one of them at edpb.europa.eu.
Where your data is
Our database and file storage are hosted in the European Union. Our AI, email, subscription, store and website-hosting providers are established in the United States, so a photo scan, an account email, your subscription state and a visit to our website involve a transfer there. Those transfers are made under the European Commission's standard contractual clauses.
Children
Pipkin is not directed at children and is not for anyone under 16, or under the lower age your country sets for consent to information society services (13 in some member states). We do not knowingly collect anything from them. Write to privacy@pipkin.eu if you believe a child has created an account and we will delete it.
Security
Traffic is encrypted in transit. Data is stored with row-level access rules so one account cannot read another's, and the keys for our AI provider and our subscription webhook are held on the server and are not present in the app you install. No system is perfectly secure and we do not claim otherwise; if a breach ever puts your rights at risk we will tell you, and the regulator, as the GDPR requires.
Changes
If we change this policy materially we will update the date at the top and tell you in the app before the change takes effect.
Contact
Jakub Andrejco
Lopuchová 56/17, Antošovice, 711 00 Ostrava
29914477
privacy@pipkin.eu