1. Who we are
Chefenie (“we”, “our”, or “us”) operates the website chefenie.ai — an AI-powered recipe generator. This Privacy Policy explains what personal data we collect, why we collect it, and how we protect it.
2. Data we collect
2a. Data you provide
- Account information — email address and password (hashed) when you create an account, or OAuth tokens if you sign in via Google.
- Pantry & ingredients — the ingredients you enter to generate recipes. These are stored in your browser (localStorage) and optionally synced to our servers if you are signed in.
- Saved recipes & preferences — recipes you save, mood preferences, dietary settings.
- Chat messages — messages you send to the Chefenie AI assistant are sent to our AI provider and are not stored persistently on our servers.
- Scanned images — photos you take or upload for ingredient detection. Images are processed in real time and are not stored on our servers.
2b. Data collected automatically
- IP address — used for rate limiting and abuse prevention. Not stored beyond the current rate-limit window (60 minutes maximum).
- Usage analytics — page views, session duration, feature usage via Google Analytics (anonymised). You can opt out via our cookie banner.
- Cookies & local storage — see Section 5 for details.
3. How we use your data
- To provide and improve the Chefenie recipe generation service.
- To authenticate you and maintain your session.
- To save your preferences, pantry, and favourite recipes across devices.
- To enforce rate limits and protect against abuse.
- To analyse aggregate usage patterns and improve product features.
- To send transactional emails (password reset, account verification) — no marketing without consent.
We do not sell your personal data to third parties. We do not use your ingredients or recipe history to train AI models.
4. Third-party services
- Google Gemini / AI providers — recipe generation, chat, and ingredient scanning requests are processed by Google Gemini. Your input is sent to Google's API. Refer to Google's Privacy Policy.
- Google Analytics — anonymised analytics. IP addresses are anonymised. You can opt out via our cookie banner or Google's opt-out tool.
- Supabase / database — account data, saved recipes, and preferences are stored on Supabase infrastructure hosted in the EU/US.
- Vercel — our hosting platform. Processes request logs (including IP) for up to 30 days per their data policy.
5. Cookies & local storage
We use the following storage mechanisms:
| Name | Type | Purpose | Expires |
|---|
| chefenie_theme | localStorage | Saves light/dark mode preference | Never (local) |
| chefenie_pantry | localStorage | Saves your pantry ingredients locally | Never (local) |
| chefenie_cookie_consent | localStorage | Records your cookie consent choice | Never (local) |
| chefenie_session | Cookie (HttpOnly) | Authenticates your session | 7 days |
| _ga, _ga_* | Cookie | Google Analytics tracking (opt-in) | 2 years |
Analytics cookies are only set after you accept via the cookie banner. You can withdraw consent at any time by clicking “Cookie Settings” in the footer.
6. Data retention
- Account data is retained until you delete your account.
- Generated recipes stored in our database are retained for 12 months after last access.
- Rate-limit records (IP only, no content) are purged within 60 minutes.
- Server/access logs are retained for 30 days by our hosting provider (Vercel).
7. Your rights
Depending on your location (EU/EEA, UK, California, etc.) you may have the right to:
- Access the personal data we hold about you.
- Request correction of inaccurate data.
- Request deletion of your account and associated data.
- Object to or restrict processing.
- Data portability (receive your data in a machine-readable format).
- Withdraw consent for analytics cookies at any time.
To exercise any of these rights, email us at privacy@chefenie.ai. We will respond within 30 days.
8. Security
We use industry-standard security measures: HTTPS everywhere, bcrypt password hashing, HttpOnly session cookies, and strict input sanitisation on all API endpoints. No system is 100% secure; if you discover a vulnerability please email security@chefenie.ai.
9. Children
Chefenie is not directed at children under 13. We do not knowingly collect personal data from children. If you believe a child has provided us data, contact us and we will delete it promptly.
10. Changes to this policy
We may update this policy. We will notify you of material changes by updating the effective date and, for significant changes, by posting a notice in the app. Continued use after changes constitutes acceptance.