Introduction
This Privacy Policy describes how imkitchen ("imkitchen," "we," or "us") collects, uses, and shares information when you use our mobile app and website (together, the "Service").
We've tried to write this in plain English. Where we use a legal term, we explain what it means in practice. If anything is unclear, tell us — we'll simplify it.
Data we collect
We collect the minimum amount of data needed to make the Service work.
- Account info. Email address, chosen display name, and password hash.
- Your content. Recipes, meal plans, shopping lists, notes. You own this. You can export or delete it at any time.
- Usage data. Anonymised events (feature used, crash logs, page timings) so we can fix bugs and improve the app.
- Device info. Operating system, app version, and a device identifier needed for push notifications.
- Payment info. If you subscribe to Premium, Stripe handles the card details — we only see the last 4 digits and billing country.
How we use your data
We use your data to:
- Provide the Service (generate plans, sync devices, render lists).
- Send transactional email — password resets, receipts, important security notices.
- Show aggregate product insights to ourselves. Never tied to an individual.
- Detect fraud and enforce our Terms of Service.
- Comply with legal obligations.
Sharing your data
We share data with:
- Service providers that run our infrastructure — hosting, email delivery, error monitoring. Contractually bound to only use data as we instruct.
- Other community members see only the recipes you choose to share publicly.
- Legal authorities when required by valid legal process. We challenge overbroad requests.
We never share your recipes, messages, or identity with third parties for marketing.
Storage & retention
Your data is hosted on encrypted servers operated by OVHcloud in France. Backups are encrypted at rest and retained for 30 days.
- Account data is kept while your account exists.
- Deleted recipes / plans are purged within 30 days.
- A deleted account is fully erased after a 30-day grace period.
- Anonymised usage analytics are kept for up to 24 months.
Your rights
Depending on where you live, you may have rights to access, correct, delete, or export your data. Regardless of jurisdiction, we offer the following to everyone:
Cookies & tracking
We use first-party cookies to keep you logged in. We use no third-party advertising cookies, pixels, or SDKs. Our analytics provider is self-hosted and stores no cross-site identifiers.
Security
All traffic uses TLS 1.3. Passwords are hashed with Argon2id. Backups are encrypted with AES-256.
If you discover a vulnerability, please email security@imkitchen.app.
Children
The Service is not intended for children under 13, and we do not knowingly collect data from them. If you believe a child has signed up, email us and we'll delete the account promptly.
International transfers
If you are in the European Economic Area, UK, or Switzerland, your data is processed under the Standard Contractual Clauses when transferred outside your region.
Changes to this policy
We may update this policy. Material changes will be announced in-app and by email at least 30 days before taking effect.
Contact
Questions, concerns, or just want to chat about privacy?