Privacy Policy

Last updated: August 18, 2026

1. Introduction

Welcome to What's Cookin. This Privacy Policy explains how we collect, use, and safeguard your information when you use our web application and the "What's Cookin" Chrome Extension. By using What's Cookin, you agree to the practices described in this policy.

2. Information We Collect

We collect only the information necessary to provide our service:

  • Account information — your email address and display name, provided either directly or via Google Sign-In.
  • App data — recipes, ingredients, the ingredients you save to your fridge, shopping lists, and preferences you create within the app.
  • Photos you upload — a photo you attach to a recipe is stored so it can be shown in your library. Photos you scan into your fridge are handled differently: they are sent to our AI provider to identify the food in them, and we keep only the resulting ingredient names. The fridge photos themselves are never stored.
  • Webpage Content (Chrome Extension Only) — when you explicitly click the extension to clip a recipe, we temporarily read the HTML content, meta tags, and images of your currently active tab to extract recipe information. We do not track your browsing history or record background tabs.
  • Shared Recipe Links — when you send a recipe link to What's Cookin (for example via the iOS share-sheet shortcut), our server fetches that publicly accessible page once to extract the recipe. We keep the extracted recipe and its image address in your library; we do not store the page itself and we do not track your browsing. For clipped recipes we also record the page address and the site/author credited there, so we can display attribution if you later make the recipe public.
  • Public Recipes & Bylines — recipes are private by default. If you publish one, its page (visible to anyone) shows your profile display name as a byline; for your own original recipes you can choose to post anonymously when publishing. Clipped recipes always show who clipped them, along with the source site, credited author, and a link to the original.
  • Usage & error data — basic analytics and crash reports to understand how the app is used, identify bugs, and improve stability (e.g., page views, recipe clipping success rates).

3. Google Sign-In

If you choose to sign in with Google, we receive your name, email address, and profile picture from Google. We do not receive access to your Google Drive, Gmail, contacts, or any other Google services. We use this information solely to create and identify your What's Cookin account.

4. How We Use Your Information

  • To provide, maintain, and improve the What's Cookin service.
  • To authenticate you and keep your account secure.
  • To save and sync your recipes, fridge inventory, and shopping lists across the web app and Chrome extension.
  • To send transactional emails (e.g., password reset, magic link sign-in).

5. Data Sharing

We do not sell, rent, or share your personal information with third parties for marketing purposes. We use the following trusted service providers to operate the app:

  • Supabase — database and authentication hosting.
  • OpenAI — AI-powered recipe and ingredient features.
  • Vercel — web application hosting.
  • Sentry & PostHog — error tracking and anonymous usage analytics.

Each of these providers processes data only as necessary to provide their services and is bound by their own privacy policies.

AI assistant connectors. You can choose to connect What's Cookin to an AI assistant (for example ChatGPT or Claude) so it can save recipes to your library, add items to your shopping list, or search recipes you have saved. When you do, the recipe information that assistant requests is sent to the company that operates it, and from that point it is handled under their privacy policy and retention rules, which we do not control. This only ever covers your own data, only while a connection is active, and only when you or your assistant asks for it. You can disconnect an assistant at any time in Settings, which immediately revokes its access.

6. Data Retention & Deletion

Your data is retained for as long as your account is active. If you wish to delete your account and all associated data, please contact us at the email below and we will process your request within 30 days.

7. Security

We use industry-standard security measures including encrypted connections (HTTPS), secure authentication via Supabase, and row-level security on our database to protect your data.

8. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page. Continued use of the app after changes constitutes acceptance of the updated policy.

9. Contact

If you have any questions about this Privacy Policy or your data, please contact us at: legal@whats-cookin.ai