Privacy policy

Last updated 23 September 2026

Recepti is a recipe-saving app made by Tamara Martinović and Jessyka Mathews ("we", "us"). This one policy explains what data the app and website collect, why, and how you can control it. It applies to everyone, wherever you live, including people in the EU, the UK, the EEA and the United States. Where a privacy law gives you specific rights, we say so below, and we give those rights to all users.

What we collect

We collect this information directly from you, or from your device when you use Recepti:

We don't use advertising, tracking or analytics SDKs, and we don't intentionally collect sensitive personal information, such as health data, precise location or government ID numbers.

How recipe imports are processed

To turn a link, screenshot or video into a recipe, the content you submit is sent to these processors:

These providers process the content only to complete your import. We don't use it to train our own models.

Who we share data with

We don't sell your personal information, and we don't share it for advertising. In the past 12 months we haven't sold or shared personal information. We share it only with the service providers that help us run Recepti, and only so they can do that job:

We may also disclose information if the law requires it, or to protect our rights, our users or the public.

Cookies and local storage

Our website uses only essential local storage. No tracking or advertising cookies. We store, in your own browser only:

Neither value is sent to us or shared with anyone. You can clear them anytime by clearing your browser's site data. Cloudflare may set a small number of strictly necessary cookies for security, for example to tell a real visitor from a bot. These don't track you across other websites.

Because we don't track visitors across websites, and we don't sell or share personal information, our website works the same way whether or not your browser sends a Do Not Track or Global Privacy Control signal.

Where data is stored and international transfers

Your account, saved recipes and any uploaded images or import files are stored with our database, sign-in and file-storage provider. Our server runs on Fly.io, hosted in London, UK. Only your own account can access your data. Temporary import files are deleted automatically after processing.

Some of our providers, including Google Gemini, Groq and our database provider, may process data outside the UK and EU, including in the United States. If you're in the EU, the EEA or the UK, we rely on the safeguards those providers offer, such as Standard Contractual Clauses, to protect your data to EU and UK standards. By using Recepti you understand that your information may be processed in the UK, the US and other countries where our providers operate.

Legal basis for processing (EU, UK and EEA)

Where the UK GDPR or EU GDPR applies to you, we rely on these legal bases: performance of a contract, to provide the app, your account and your recipe imports; and our legitimate interest in keeping the service secure and working correctly.

Data retention

We keep your account and recipes for as long as your account stays active. Temporary files used to import a recipe are deleted automatically once processing finishes. If you delete your account, we delete your data as described below.

Security

We use HTTPS for our website and server, and only your own account can access your saved data. No online service is completely secure, so we can't promise absolute security, but we work to protect your data.

Deleting your data

You can permanently delete your account and all its data (saved recipes, uploaded files and preferences) at any time:

Deletion is immediate and can't be undone. If you only used an anonymous session and never set a password, contact us and we'll delete it manually once we've verified you.

Your privacy rights

We give these rights to all users, wherever you live. You can:

How to use them. We won't treat you differently for using these rights. Email us at the address below, or delete your account in the app. We may ask you to confirm it's really you, for example by emailing from the address on your account. We'll reply within one month if you're in the EU or UK, or within 45 days if you're in the US. Where the law allows, we may extend this and we'll tell you why. An authorized agent can make a request for you, and we may ask for proof that you gave them permission. If we decline a request, you can appeal by replying to our email, and we'll answer within the time the law requires.

EU, UK and EEA. These are your rights under the EU and UK GDPR. We don't make decisions about you based only on automated processing that have legal or similarly significant effects. You can also complain to your local data protection authority, for example the Croatian Agencija za zaštitu osobnih podataka (AZOP) or the UK Information Commissioner's Office (ICO).

United States. These rights include those under the California Consumer Privacy Act (as amended by the California Privacy Rights Act) and comparable laws in other US states. Under California's Shine the Light law, California residents can also ask which personal information we disclose to third parties for their direct marketing. We don't disclose personal information for that purpose. You can also contact your state attorney general.

Children's privacy

Recepti is not directed at children under 13, and we don't knowingly collect personal information from them. In some countries the minimum age to use online services without a parent's permission is higher than 13, up to 16. If that applies where you live, please get a parent or guardian's permission first. If you think a child has given us personal information, email us and we'll delete it.

Changes to this policy

If this policy changes, we'll update the date at the top of this page.

Contact