GDPR COMPLIANCE STATEMENT

Last Updated: August 5, 2026

This Statement supplements our Privacy Policy for people whose personal data is protected by the European Union General Data Protection Regulation (GDPR) or substantially equivalent EEA law.

1. CONTROLLER AND CONTACT

DishKeeper is operated by the person or legal entity responsible for determining why and how personal data is processed through the Service. That operator is the data controller.

For data-protection questions or rights requests, contact:

Email: [email protected]

Suggested subject: Data Protection Request

DishKeeper has not represented in this Statement that it has appointed a Data Protection Officer. Data-protection inquiries are handled through the address above.

2. PROCESSING PURPOSES AND LEGAL BASES

We rely on the following legal bases, depending on the activity.

Performance of a contract — GDPR Article 6(1)(b)

We process data as necessary to provide features you request, including:

  • Creating and administering your account
  • Authenticating you and maintaining your session
  • Storing, organizing, displaying, sharing, importing, and exporting content
  • Processing submitted text or URLs with AI when you request that feature
  • Administering token balances and completing purchases
  • Providing support and communicating about the Service

Requesting an AI feature instructs us to send the required content to the providers used for that feature. Manual recipe creation is available if you do not want content processed by AI providers.

Legitimate interests — GDPR Article 6(1)(f)

We may process data where necessary for interests such as:

  • Securing accounts, infrastructure, and public sharing links
  • Detecting abuse, fraud, malicious input, and automated traffic
  • Diagnosing errors and maintaining Service reliability
  • Measuring aggregate usage and improving functionality
  • Managing provider costs and enforcing reasonable usage limits
  • Establishing, exercising, or defending legal claims

We consider the nature of the data, the expected use of the Service, safeguards, and the effect on users before relying on this basis. You may object to this processing as described below.

Legal obligations — GDPR Article 6(1)(c)

We process data where required for tax, accounting, consumer protection, law-enforcement cooperation, sanctions compliance, data-breach response, or other legal obligations.

Consent — GDPR Article 6(1)(a)

We use consent only where an optional activity legally requires it, such as optional marketing or a future non-essential cookie. Consent is not treated as the basis for processing that is objectively necessary to provide an account or feature you request.

Where we rely on consent, you may withdraw it at any time through the available preference control or by contacting us. Withdrawal does not affect processing that occurred lawfully before withdrawal.

3. DATA CATEGORIES, RECIPIENTS, AND RETENTION

The categories of personal data, sources, recipients, public-sharing consequences, and retention criteria are described in our Privacy Policy.

Recipients may include Clerk, OpenAI, Azure OpenAI, DeepSeek, OpenRouter, Cloudflare, Supadata, Langfuse, Sentry, Umami, Resend, and Polar, depending on production configuration and the feature used. Public content is also disclosed to people who access the relevant sharing link.

When providing data is necessary to create an account, process a purchase, or perform a feature you request, failure to provide it means we may be unable to provide that account, purchase, or feature. Optional profile fields and manual recipe creation may remain available without AI processing.

4. COOKIES AND SIMILAR TECHNOLOGIES

DishKeeper uses authentication cookies and browser storage needed to sign users in, secure sessions, save preferences and drafts, and cache selected shared content. The Service also uses a cookie-free Umami analytics configuration and may use Cloudflare security storage.

A technology being cookie-free does not necessarily mean that no personal data is processed. Analytics and security requests may process IP addresses, user agents, URLs, or request information before aggregation, anonymization, or deletion.

Strictly necessary storage does not require consent under applicable ePrivacy rules where it is genuinely required to provide a user-requested service. If DishKeeper introduces non-essential storage that requires consent, it will be disabled until the user makes a choice.

Browser controls can delete or block cookies and local storage, but this may sign you out, remove drafts, or disable functionality.

5. INTERNATIONAL TRANSFERS

Providers may process personal data outside the EEA. The destination depends on provider routing, deployment region, and the feature used.

Where Chapter V GDPR requires a transfer mechanism, DishKeeper uses an applicable lawful mechanism, which may include:

  • An adequacy decision covering the recipient or destination
  • European Commission Standard Contractual Clauses
  • Another mechanism recognized by EU law

Where required, supplementary technical, contractual, and organizational measures are considered in light of the transfer. You may contact us for information about the mechanism applicable to a particular recipient and to request an available copy of relevant safeguards, subject to lawful redactions.

6. YOUR GDPR RIGHTS

Subject to the conditions and exceptions in the GDPR, you may have the right to:

  • Access: obtain confirmation, information about processing, and a copy of your data
  • Rectification: correct inaccurate or incomplete data
  • Erasure: request deletion where a legal ground for erasure applies
  • Restriction: limit processing in specified circumstances
  • Portability: receive data you provided in a structured, commonly used, machine-readable format where Article 20 applies
  • Object: object to processing based on legitimate interests, including profiling based on that ground
  • Withdraw consent: withdraw consent at any time where consent is the basis
  • Complain: lodge a complaint with the supervisory authority in your habitual residence, place of work, or place of an alleged infringement

You will not be subject to a decision based solely on automated processing that produces legal or similarly significant effects merely because you use DishKeeper's AI recipe features.

A list of EEA supervisory authorities is available from the European Data Protection Board.

7. EXERCISING YOUR RIGHTS

Send requests to [email protected]. We may need to verify your identity and clarify the scope of your request.

We will respond without undue delay and generally within one month after receiving a valid request. Where permitted by Article 12 GDPR, that period may be extended by up to two additional months because of complexity or the number of requests; we will notify you of an extension within the first month.

Requests are generally free. Where a request is manifestly unfounded or excessive, the GDPR permits a reasonable fee or refusal, with an explanation.

8. AI-ASSISTED PROCESSING

AI processing may include URL rendering, social-video metadata or transcript extraction, content moderation, model inference, and diagnostic tracing. The submitted input, extracted material, provider details, raw output, and resulting recipe may be stored as described in the Privacy Policy.

The feature assists with content transformation. It is not used to evaluate your legal rights or eligibility for employment, credit, housing, insurance, or similar services. You control whether to request AI processing and can create recipes manually.

9. PERSONAL-DATA BREACHES

DishKeeper maintains processes intended to detect, assess, and respond to personal-data breaches. Where GDPR Articles 33 or 34 apply, we will notify the competent supervisory authority without undue delay and, where feasible, within 72 hours after becoming aware of a notifiable breach. We will notify affected people without undue delay when the breach is likely to result in a high risk to their rights and freedoms.

10. CHILDREN

The Service is not intended for anyone under 16. DishKeeper does not knowingly permit children under 16 to create accounts. If we learn that a child under 16 provided personal data, we will investigate and take appropriate action, which may include deleting the account and data.

11. CHANGES TO THIS STATEMENT

We may update this Statement as the Service, our providers, or applicable law changes. We will update the date above and provide additional notice where required.

© 2025 DishKeeper - A clean, simple way to collect and share your recipes

Why DishKeeperPrivacy PolicyTerms of ServiceGDPR