PRIVACY POLICY
Last Updated: August 8, 2026
1. ABOUT THIS POLICY
This Privacy Policy explains how DishKeeper ("DishKeeper," "we," "us," or "our") collects, uses, stores, and shares personal data when you use the DishKeeper website, application, and related services (the "Service"). It also explains your privacy rights.
For additional information applicable to people in the European Economic Area (EEA), see our GDPR Compliance Statement.
The data controller is the person or legal entity that operates DishKeeper. Questions and privacy requests may be sent to:
Email: [email protected]
2. PERSONAL DATA WE COLLECT
Account and profile data
When you create or use an account, we may receive and store:
- Your email address, first and last name, and profile information
- An identifier assigned by our authentication provider, Clerk
- Login and account-activity timestamps
- Account tier, token balances, and token transactions
- Authentication and security information
Recipes, cookbooks, and other content
We process content you provide to the Service, including:
- Recipes, cookbooks, notes, ingredients, instructions, and related metadata
- Recipe images
- Drafts and preferences stored in your browser
- Content you choose to publish or share
- URLs you submit for extraction
- Social-media or video metadata, descriptions, and transcripts obtained when you ask us to process a supported URL
Please avoid submitting personal or sensitive information that is not needed to use the Service.
AI-processing data
When you use AI-assisted features, we process and may store:
- Your submitted text or URL
- Extracted webpage, social-media, or transcript content
- Prompts, moderation results, provider and model details
- Raw and structured AI output
- Token counts, cost information, timestamps, duration, status, and error details
- Your approval, rejection, or feedback concerning generated content
AI task records currently may retain the submitted input, extracted content, and raw model output as part of the task record. These records are not limited to anonymous usage metadata.
Payment and transaction data
If you purchase tokens or another paid feature, Polar processes the checkout and payment. We receive and store information needed to fulfil and document the purchase, such as customer and order identifiers, product information, payment status, amount, currency, refund status, and webhook transaction data. We do not receive or store your full payment-card number.
Contact and support data
If you contact us, we process your name, email address, message, and related correspondence.
Technical, analytics, and security data
We and our service providers may process:
- IP address, browser type, operating system, device and request information
- URLs, referrers, page interactions, and approximate location derived from network information
- Application logs, error reports, request headers, performance traces, and diagnostic context
- Information used to detect fraud, abuse, automated traffic, and security incidents
Umami provides website analytics without advertising cookies. Depending on its configuration and the request lifecycle, technical information such as IP addresses and user agents may still be processed before aggregation or anonymization.
3. COOKIES, LOCAL STORAGE, AND SIMILAR TECHNOLOGIES
The Service uses cookies and browser storage for functions such as:
- Clerk authentication and session management
- Storing an authentication token and token-refresh timestamp
- Theme, language, display, and filter preferences
- Unsaved recipe drafts
- Caching shared recipes and cookbooks for performance or offline access
- Cloudflare security and bot-protection functionality when enabled
Some browser-storage entries remain until they expire, are replaced, you sign out, or you clear site data. Cached shared content may remain on a device after the original content changes or is unpublished. You can clear cookies and local storage through your browser settings, but doing so may sign you out or remove drafts and offline data.
We do not use advertising cookies. Our current Umami analytics script does not set analytics cookies. If we add non-essential cookies or similar technologies that legally require consent, we will request that consent before using them.
4. WHY WE PROCESS PERSONAL DATA
We process personal data to:
- Create, authenticate, secure, and administer accounts
- Store, organize, display, share, import, and export recipes and cookbooks
- Provide AI-assisted extraction and recipe processing at your request
- Process purchases, allocate tokens, prevent duplicate transactions, and handle refunds
- Operate, maintain, troubleshoot, and improve the Service
- Measure aggregate usage and performance
- Detect fraud, abuse, malicious content, and security incidents
- Communicate about transactions, security, support, and material Service changes
- Establish, exercise, or defend legal claims and comply with law
For EEA users, the legal bases for this processing are described in the GDPR Compliance Statement.
5. WHEN WE SHARE PERSONAL DATA
We disclose data only as needed for the purposes described in this Policy, when you direct us to do so, or when required by law.
Service providers
Depending on the feature and production configuration, our providers include:
- Clerk: authentication, account security, and session management
- OpenAI, Azure OpenAI, DeepSeek, and OpenRouter: AI inference, moderation, and recipe processing
- Cloudflare: content delivery, browser rendering of submitted URLs, bot protection, and private object storage for images and export files
- Supadata: extraction of supported social-media or video metadata, descriptions, and transcripts
- Langfuse: AI request tracing, performance monitoring, and diagnostics when tracing is enabled
- Sentry: application error monitoring and diagnostics; reports may include account, request, IP, header, and other diagnostic context
- Umami Cloud: website usage analytics
- Resend: transactional and support-related email delivery
- Polar: checkout, payment, customer, order, and refund processing
A provider may act as our processor, subprocessor, or an independent controller for some activities. Its own terms and privacy notice may also apply.
Public and user-directed sharing
If you publish a recipe or cookbook or generate a public sharing link, the selected content and associated metadata become available to anyone with access to the link and may be copied or cached by recipients, browsers, search engines, or other services. Public URLs may contain a portion of the content title.
Legal and business disclosures
We may disclose data where reasonably necessary to comply with law, protect rights or safety, investigate misuse, respond to lawful requests, or complete a merger, acquisition, financing, reorganization, or transfer of the Service, subject to applicable law.
We do not sell personal data or use it for cross-context behavioural advertising.
6. INTERNATIONAL DATA TRANSFERS
Some providers may process personal data outside your country, including outside the EEA. Where data-protection law requires a transfer safeguard, we use an available lawful mechanism appropriate to the provider and transfer, such as an adequacy decision, approved contractual clauses, or another legally recognized mechanism. You may contact us to request information about safeguards relevant to your data.
The actual processing country can depend on the selected AI provider, configured cloud region, provider routing, and the feature you use.
7. DATA RETENTION
We retain personal data only for as long as reasonably needed for the purposes described above, including to provide the Service, meet legal and accounting obligations, resolve disputes, and enforce agreements.
In general:
- Account data, recipes, cookbooks, images, and associated AI task records may remain while the account is active.
- AI task records may contain input, extracted content, and raw model output; they are deleted with the related account unless an exception applies.
- Completed export artifacts stored in object storage are normally scheduled to expire after 48 hours. Export-job records may remain longer for history, security, and troubleshooting.
- Payment and transaction records may be retained for the period required by tax, accounting, fraud-prevention, and legal obligations.
- Public content remains available until it is unpublished, deleted, or otherwise removed, although third-party copies and browser caches may persist.
- Logs, analytics, email records, and provider-side records follow operational or provider retention schedules and may be retained longer where needed for security or legal claims.
Retention may be extended when preservation is required by law, a dispute, fraud investigation, or security incident. We may anonymize data instead of deleting it where the result can no longer identify you.
8. ACCOUNT DELETION AND DATA EXPORT
You may request account deletion or a copy of your data by emailing [email protected] from the address associated with your account. We may need to verify your identity.
Before requesting deletion, disable any public sharing links you no longer want available and export any content you wish to keep.
While the Service is operating, you may export your recipe and cookbook content without charge through the available export tools. If those tools are unavailable to you, you may request an export by emailing [email protected] from the address associated with your account. We may take reasonable steps to verify your identity. At least one commonly usable export format will be provided; available options may include PDF and Markdown/Obsidian-compatible exports. Specific formats, layouts, images, version history, and included metadata may vary with the content and current Service functionality. The contractual export commitment and Service-discontinuation process are described in Section 2 of the Terms of Service.
Deletion is subject to technical processing time and lawful retention exceptions. Data may also remain temporarily in backups until the applicable backup cycle completes. Deleting your account cannot remove copies previously downloaded or independently stored by other people, and the export right does not require DishKeeper to retain content after you request its deletion.
9. YOUR PRIVACY RIGHTS
Depending on where you live, you may have rights to:
- Access personal data we hold about you
- Correct inaccurate or incomplete data
- Delete personal data
- Restrict or object to processing
- Receive portable data
- Withdraw consent where processing relies on consent
- Appeal or complain to a privacy regulator
- Opt out of certain sale, sharing, targeted advertising, or profiling activities
- Receive equal service when exercising applicable privacy rights
These rights may be subject to legal exceptions. To exercise a right, contact [email protected]. We may ask for information needed to verify your identity and authority. Authorized agents may submit requests where permitted by law.
EEA rights and complaint information are explained further in our GDPR Compliance Statement.
10. AI PROCESSING AND AUTOMATED DECISIONS
AI features convert submitted or extracted content into proposed recipe content. AI output may be inaccurate or unsafe and should be reviewed before use. DishKeeper does not use recipe processing to make decisions that produce legal or similarly significant effects about you, and it does not use this feature to profile your eligibility for employment, credit, housing, insurance, or similar services.
We do not intentionally use your recipe content to train DishKeeper-owned general-purpose AI models. Third-party AI providers process data under their applicable service terms and configured data controls; their retention and model-improvement practices may vary by provider and service tier.
You can avoid this processing by using manual recipe creation rather than AI features.
11. SECURITY
We use administrative, technical, and organizational measures designed to protect personal data. No storage or transmission method is completely secure, and we cannot guarantee absolute security. You are responsible for protecting your account, devices, and sharing links and for notifying us if you suspect unauthorized access.
12. CHILDREN
The Service is not intended for anyone under 16. We do not knowingly permit children under 16 to create accounts or provide personal data. If you believe a child under 16 has provided data to us, contact [email protected] so we can investigate and take appropriate action.
13. CHANGES TO THIS POLICY
We may update this Policy to reflect changes to the Service, law, or our processing practices. We will change the date above and, where required, provide additional notice. Material changes apply prospectively unless law permits otherwise.
14. CONTACT US
For privacy questions, rights requests, or complaints, contact:
Email: [email protected]