Privacy Policy

Last updated:

You can export or delete your data at any time from "Data & Privacy" in your account settings. Preferences

Introduction

This Privacy Policy describes how RecipeBase collects, uses, and protects your personal data when you use the service.

Data Controller

The data controller responsible for processing your personal data is Abla AB. You can reach us at [email protected] for any question about your personal data.

Information We Collect

Account data: email address, display name, password (hashed), and account settings.

Recipes and content: recipes you create or import, ratings, reactions, cook history, personal notes, and recipe personalizations.

Meal planning and shopping: weekly meal plans, shopping lists, pantry contents, and — if you use the feature — saved prices/offers ("receipts") from stores you add yourself.

Technical data: limited usage data (such as sign-in times and error logs) needed to operate and troubleshoot the service.

Household and Children’s Data

If you add household members (for example, children) for meal planning, we process the information you choose to enter about them — name, role (adult/child), optional birth date, allergies, and food preferences.

Any data about children is always entered by a parent or guardian, never by the child directly, and is used only to adjust portion sizes, allergy warnings, and recipe suggestions within your household.

We encourage you to enter only what you actually need — for example, an age range may be enough if you don’t need an exact birth date.

AI Processing of Recipe Content

RecipeBase uses language models (such as Google Gemini and Anthropic Claude) to interpret recipe content on import, suggest substitutions, rewrite instructions, and similar features.

When we send recipe content or your feedback to these services, it is only to perform the requested feature — this content is not used to train the provider’s own models.

We do not share sensitive personal data (such as data about children) with these services beyond what is required for the feature in question.

Where Your Data Is Stored

The service runs on Cloudflare (web app and API) and Supabase (database and authentication). Data is stored in EU (eu-west-1).

Our providers are bound by data processing agreements that ensure a level of protection consistent with GDPR.

Cookies

RecipeBase uses one cookie to keep you signed in — it is strictly necessary for the service to work and does not require consent.

We set no cookies for advertising or cross-site tracking. Your choice in the cookie banner is saved in your browser. Visit statistics and error reporting are described in their own sections below: visit statistics are cookieless and load only after you choose Accept.

Here we describe in more detail which services and data are involved when you use RecipeBase.

Visit statistics

We use Cloudflare Web Analytics to see how many people visit our pages. It is cookieless and only shows aggregated page view statistics.

The measurement loads only after you choose Accept in the banner. If you choose Decline it is never loaded, and the service works as usual.

Error reporting

When something goes wrong in the app or on the server we may receive an error report through Sentry, a debugging service. The report contains technical details about the error, such as the error message, where in the code it happened, the page address, browser and device type. A sample of page loads is also measured for performance.

The reports are used to find and fix errors, not for marketing. Error reporting is only active in the versions of the service where it has been switched on.

Usage events

When you do certain things in the service we store an event on our server, for example that you imported or changed a recipe, added a dinner to the week, made a shopping list, set a rating, shared a recipe, wrote a comment, exported your data or deleted your account.

An event contains its type, the time, your account and household identifiers and a few technical values such as ids and counts. It does not contain the text of recipes, your notes or your email address. We use the events to measure which features are used. When an account is deleted, its events are detached from it.

Photos and images you upload

Photos of recipe pages that you import are stored privately on your account in our storage (Supabase Storage). They are shown only to you, through links that expire after one hour. The photo is also sent to a language model to read out the recipe, see the section on AI processing above.

Images you add to a recipe or a comment are stored separately and can be fetched by anyone who has the image address. Do not upload images that show people or personal data.

Email

We send email about your account and the beta, for example invitations and password resets. For that we use an email provider, Forward Email or Resend, which receives your email address and the content of the message in order to deliver it.

When you delete your account

You can export or delete your data under Data and privacy in your preferences. Before you delete the account we warn you about what happens to the household.

If other adults remain in the household, the household's data stays with them: the members, week plans, shopping lists and the family's verdicts. Your own recipes are deleted, and planned dinners that used them show Recipe removed instead.

Data Retention

We retain your data for as long as your account is active or as needed to provide the service.

If you delete your account, your data is removed following the process described under "Your Rights" below, except where we are legally required to retain certain records.

Your Rights Under GDPR

Under GDPR you have the right to access your data (data portability), correct inaccurate data, erase your data ("the right to be forgotten"), and object to certain processing.

You can export all of your data and delete your account at any time from "Data & Privacy" in your account settings.

To exercise your rights another way, or if you have questions, contact us at [email protected]. You also have the right to lodge a complaint with the Swedish Authority for Privacy Protection (IMY).

Children

RecipeBase accounts are intended for adults (18 or older). We do not target children and do not knowingly collect data directly from children.

Child profiles within the household feature are created and maintained exclusively by a parent or guardian who holds the account.

Security

We use reasonable technical and organizational measures — including encryption in transit and restricted access — to protect your data. No method of transmission or storage is completely secure, however.

Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you in the service or by email of material changes before they take effect.

Contact Us

If you have questions about this Privacy Policy or want to exercise your rights, reach us at [email protected].

Abla AB

Sweden

[email protected]