Skip to content
Legal

Privacy Policy

Last updated September 19, 2026

Kitchenry is operated by Amarkay LLC. Contact: support@kitchenry.app (privacy: privacy@kitchenry.app).

Effective date: August 1, 2026 · Last updated: September 19, 2026

This Privacy Policy describes how Kitchenry ("we", "our", "us"), operated by Amarkay LLC, collects, uses, and shares information about you when you use the Kitchenry mobile and web applications (the "Service"). By using the Service, you agree to the practices described here.

1. Information We Collect

Account information

When you create an account we collect your email address and, optionally, your name. Authentication is handled by Supabase Auth — we do not store your password. If you sign in with Google or Apple, we receive the name and email address associated with that account. During sign-up we also use a bot-protection service that processes technical browser signals to distinguish people from automated scripts.

Recipe and content data

Recipes, cookbooks, meal plans, shopping lists, pantry items, and any other content you create or import are stored on our servers so you can access them across devices.

Profile images

Avatar photos you upload are stored in private cloud object storage (Tigris, on Fly.io). They are never publicly accessible — access requires a short-lived signed URL. We strip EXIF metadata (including GPS location) from images before storing them, where our image pipeline supports it.

Recipe images

Images attached to recipes are stored in cloud object storage (Tigris, on Fly.io) and may be served via a content-delivery network. We strip EXIF metadata (including GPS) from recipe images before storage, where our image pipeline supports it. Public reference images such as ingredient icons are served from Microsoft Azure Blob Storage and contain no account data.

Kitchenry browser extension (Chrome clipper)

If you install our optional browser extension, it helps you save recipes from recipe websites into your Kitchenry account. When you choose to import a page, the extension sends the URL of the current tab to our API so we can fetch and parse the recipe for you. We do not continuously scrape or upload browsing history — the page URL is transmitted only when you explicitly start an import.

To associate imports with your account, the extension stores authentication tokens from your Kitchenry (Supabase) session in the browser's local extension storage after you sign in through our secure web bridge. Tokens are used only to call our API as you, and are cleared when you sign out of the extension. The extension does not sell data, and it does not share page URLs with third parties other than our own backend services that process recipe imports (including the AI/parse providers described in Section 3 when you use import features that require them).

Permissions the extension requests (for example access to the active tab when you import) are used solely for that purpose: detect that you initiated a save and send the chosen page URL to Kitchenry. Host and content-script permissions, if present, support showing a lightweight badge when recipe markup is detected; they do not grant us access to unrelated account data on third-party sites.

Device and usage data

We collect usage analytics (such as which features are used and basic device information) through PostHog to understand how the Service is used and to improve it. You can opt out of analytics in the app's settings. If the app crashes, a crash report (device model, operating system version, and error details) is sent to Sentry so we can diagnose and fix problems.

We also use LaunchDarkly to deliver feature flags and A/B tests. It receives an opaque, non-reversible user identifier — it does not receive your email address, name, or any other personally identifiable information.

This website

Our marketing website (kitchenry.app) uses cookieless analytics. It sets no cookies and stores no identifier in your browser's local or session storage, so there is nothing to consent to and no banner to dismiss. We record which pages are viewed and which calls-to-action are clicked, in aggregate, to understand what people find useful. This is not linked to your Kitchenry account, and website activity is never joined with the in-app analytics described above.

Bot protection (Cloudflare Turnstile)

When you create an account or send us a message through the support form, we use Cloudflare Turnstile to tell people apart from automated abuse. It runs in invisible mode: the check happens in the background and does not show you a challenge. To do this, Cloudflare processes technical signals from your browser, such as your IP address, TLS fingerprint and User-Agent header. We receive the result of the check, not these signals. Cloudflare's handling of this data is described in its Turnstile Privacy Addendum.

Payment information

Subscription payments on the web are processed by Stripe; purchases made in our mobile apps are billed by the Apple App Store or Google Play. We never receive or store your full card number — our payment processors handle all payment data under PCI-DSS compliance. We store a customer identifier to manage your subscription.

Push notification tokens

If you enable push notifications, a device push token is stored so we can send you notifications (e.g. cook-mode timers). Push delivery is handled by Expo's push notification service.

Transactional email

Account emails — such as sign-up verification, password resets and service notices — are sent through our transactional email providers (MailerSend or Resend), which receive your email address and the message content.

Nutrition data sources

Nutritional estimates are derived from the USDA FoodData Central database and Open Food Facts. No personal information is sent to these services.

2. How We Use Your Information

PurposeData UsedLegal Basis
Provide and improve the ServiceAccount data, recipe content, usage dataContract performance
Authenticate and secure accountsAccount data, tokensContract performance
Process paymentsEmail / customer id (processors hold card data)Contract performance
AI-powered featuresRecipe text/images you submit for that featureContract performance
Error diagnosis and stabilityCrash reports, device dataLegitimate interest
Usage analytics and product improvementAnalytics eventsLegitimate interest / consent where required
Feature flags and experimentsOpaque user idLegitimate interest
Transactional communicationsEmailContract performance
Legal complianceAccount dataLegal obligation
Customer supportAccount data, issue detailsLegitimate interest

We do not sell your personal data to third parties.

3. AI Features and Third-Party AI Providers

Kitchenry offers AI-powered features including recipe import and parsing, recipe generation, nutritional analysis, and conversational assistance. When you use these features, the recipe content you provide — including text and, for image-based import, the photos you submit — is processed on our behalf by these AI service providers: OpenAI, Anthropic, Groq, xAI (Grok) and Microsoft Azure OpenAI.

We send only the minimum content needed to fulfill your specific request. Our AI providers process your content under data-processing agreements, and under our API and service agreements they are instructed not to use it to train their models. Your recipes are not shared with other users through AI systems. Availability of AI features and usage limits depend on your subscription plan.

OCR (optical character recognition): Recipe scanning may extract text on your device (where supported) or on our own servers first. When AI processing is needed, the image or extracted text is handled only by the AI providers listed above — never by any service outside our data-processing agreements.

AI-generated content may not be accurate. Always verify critical nutritional or allergen information with a qualified professional.

4. Information Sharing

We do not sell, rent, or trade your personal information. We share data only:

  • With the service providers named in this policy (each under a data-processing agreement where applicable), listed together below
  • At your direction, with the intended recipient when you share a recipe, as described below
  • When required by law, court order, or to protect the rights and safety of Kitchenry and our users
  • In connection with a merger, acquisition, or sale of assets — in which case you will be notified

Our service providers

ProviderRole
SupabaseAuthentication and database
Fly.ioHosting for the web app, API and AI service
TigrisStorage for images you upload
Microsoft AzurePublic reference images; Azure OpenAI (AI provider)
OpenAI, Anthropic, Groq, xAIAI features (import, parsing, generation, nutrition, assistant)
Stripe; Apple App Store; Google PlayPayments and subscriptions
PostHogProduct analytics (you can opt out)
SentryCrash and error reporting
LaunchDarklyFeature flags (opaque user id only)
MailerSend; ResendTransactional email
ExpoPush notification delivery
Cloudflare TurnstileBot protection on sign-up and the support form
USDA FoodData Central; Open Food FactsNutrition reference data (no personal data sent)

Sharing recipes with other users

When the intended recipient accepts a recipe you share, the Service creates an independent copy they can save and edit in their own library. To identify who sent it, we make your display name, email address, and avatar (if you have one) available to that recipient. The recipient does not gain access to your other recipes or other account details.

The sharing recipient picker lets signed-in users search for another Kitchenry user. If someone enters your full email address, the Service may confirm that a Kitchenry account exists for that address and return your display information. Name-based suggestions do not expose your raw email address unless the searcher already entered that exact address. These searches are rate limited to reduce account-enumeration and abuse risk.

We retain a share record after a recipient accepts or rejects a recipe so we can track delivery state, investigate abuse, provide support, and maintain the copyright audit trail. If an account is deleted, its profile is replaced with a former-user label and denormalised recipient email addresses in share records are replaced with non-deliverable per-record placeholders. A recipe copy a recipient already accepted remains in that recipient's library as their independent copy.

5. Data Storage and Security

The Service is hosted on Fly.io. Your account and app data are stored in a PostgreSQL database managed by Supabase, and images you upload are stored in Tigris object storage. Data is stored and processed in the United States and other locations where our infrastructure providers operate. We use industry-standard security measures including encryption in transit (TLS) and at rest.

International transfers: if you are in the EU/UK, your data may be transferred to and processed in the United States. For these transfers, we rely on appropriate safeguards — such as Standard Contractual Clauses (SCCs) — as configured with each processor.

No method of transmission over the internet is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.

6. Your Rights

Depending on your location, you may have the right to:

  • Access — request a copy of the personal data we hold about you
  • Correction — request that we correct inaccurate data
  • Deletion — request that we delete your account and personal data; see how to delete your account
  • Portability — export your recipes in standard formats (TXT, Markdown and JSON on every plan; PDF and DOCX on paid plans)
  • Opt-out of analytics — disable usage analytics in the app's settings
  • Withdraw consent — at any time, without affecting processing before you withdrew it

To delete your account, use Profile → Delete Account in the app. To exercise any other right, email privacy@kitchenry.app.

GDPR (EU/UK users): we act as a data controller for the personal data described in this policy. Our legal bases for processing are set out in the table in Section 2: contract performance, legitimate interests, and legal obligation. You may lodge a complaint with your local supervisory authority.

CCPA/CPRA (California users): we do not sell personal information. California residents have the right to know and to delete their personal information, and the right to opt out of sale (which does not apply because we do not sell it). Contact us at privacy@kitchenry.app.

7. Cookies and Similar Technologies

This marketing website (kitchenry.app) sets no cookies and uses no browser storage — see "This website" in Section 1. The Service itself (app.kitchenry.app on web) sets a small set of strictly-necessary cookies to keep you signed in; none require consent under ePrivacy Directive art. 5(3) because they are essential to providing the service you requested:

CookiePurposeLifetime
kc_access_tokenAuthenticates API requests (HttpOnly)~1 hour
kc_refresh_tokenRenews your session without re-entering credentials (HttpOnly)24 hours, or 30 days with "Remember me"
kc_rememberRecords whether you chose "Remember me" (HttpOnly)Matches kc_refresh_token
kc_auth_sourceMarks that you're signed in, for the app's own UIMatches kc_refresh_token
kc_pkce_stateProtects the sign-in flow against interception during Google/Apple login5 minutes
kc_recovery_sessionMarks an in-progress password-recovery session10 minutes

We do not use these cookies for advertising or cross-site tracking. Usage analytics (see "Device and usage data" in Section 1) is a separate, non-cookie mechanism you can opt out of in the app's settings; it is not one of the cookies listed above.

8. Data Retention

We retain your personal data for as long as your account is active. If you delete your account, your account profile and personal data under our control are permanently deleted or de-identified within 30 days, subject to the share-record handling described in Section 4 and records we must retain for legal claims or compliance. Content another user already accepted as an independent copy remains in that user's library. Anonymised, non-identifiable analytics may be retained for service improvement.

9. Children

The Service is not directed at children under 13 (or 16 in the EU). We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, contact us at privacy@kitchenry.app.

10. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email or in-app notification and update the "Last updated" date above. Continued use of the Service after changes constitutes acceptance of the updated policy.

11. Contact

Questions or concerns about this policy? Email us at privacy@kitchenry.app.