Privacy policy
Last updated: 18 August 2026
1. Data controller
The controller is HADJADJI Mohamed, 27 rue de la Canardière, 67100 Strasbourg, France. Contact and privacy requests: no-reply@cookeat.info.
2. Data we process
- Pseudonymous profile: random installation ID and server ID, language, approximate country, and time zone.
- Onboarding and personalisation: age range, declared gender, cooking habits, budget, equipment, tastes, diet, and avoided ingredients. Detailed answers are no longer sent to PostHog.
- Content you provide: typed or dictated ingredients, food or receipt photos, video links, and information needed to generate or import a recipe.
- Recipes: titles, ingredients, steps, favourites, history, images, and import source when saved.
- Subscription: product, status, dates, storefront, country, currency, price, and transaction identifiers. CookEat AI does not receive payment-card details.
- Notifications: Expo push token, language, country, and time zone when you allow notifications.
- Analytics and attribution: screens and steps completed, features used, install source, campaign or ad, pseudonymous identifiers, and, with required permission, advertising identifier.
- Diagnostics: errors, technical traces, app version, device, and performance. Sentry receives a pseudonymous ID, not your name or email.
Diet and avoided-ingredient choices are optional and used only to adapt recipes. CookEat AI does not infer a religion or medical diagnosis from them. You may skip them, change your preferences, or delete your data.
3. Purposes and legal bases
- Create and synchronise the profile, generate/import recipes, and manage subscriptions: performance of the service and contract.
- Use optional food preferences that may reveal sensitive information: your explicit choice, withdrawable by changing or deleting the data.
- Measure use, prevent abuse, secure, and fix the service: legitimate interest with minimisation and pseudonymous identifiers.
- Notifications: consent granted through system settings.
- Advertising attribution and advertising identifier: consent where required, including Apple's tracking prompt. Refusal does not block core features.
- Legal retention and dispute management: legal obligation or legitimate interest as applicable.
4. Providers and recipients
- PostHog — pseudonymous product analytics and funnels.
- Sentry — errors, diagnostics, and performance.
- AppsFlyer — attribution, deep links, and advertising measurement.
- RevenueCat — subscriptions, entitlements, and purchase events.
- OpenAI, Google Gemini, and, depending on the task, Anthropic — AI processing of instructions, text, or images required for the requested feature.
- Expo — push notification delivery.
- Apple and Google — distribution, payment, billing, and subscription management.
- API, MongoDB database, and website hosting providers — storage and technical operation.
CookEat AI does not sell your data. Some data may be processed outside the European Economic Area. Depending on the country and provider, transfers rely on an adequacy decision, standard contractual clauses, or another GDPR-authorised mechanism.
5. Retention and security
- The profile, preferences, favourites, and history remain while the pseudonymous profile is active and are deleted when you use “Delete my data”.
- Temporary files sent to analyse ingredients or a video are deleted from CookEat's server after processing. An image or URL saved as part of a recipe remains in history until deleted.
- Subscription and transaction information is retained during the contractual relationship and then as needed for refunds, disputes, and applicable obligations.
- Analytics, attribution, and diagnostic events follow each provider's configured retention and may be deleted on request when the identifier can be located.
- API communications use HTTPS. System access is limited to operational and support needs.
6. Deletion and your rights
In the app, go to Profile → Delete my data. This removes the profile and its history from the CookEat server, resets local identifiers, and disconnects SDK identities on the device. It does not automatically cancel an Apple or Google subscription or instantly erase technical copies or data providers must retain for security, billing, or legal reasons.
Depending on your situation, you may request access, correction, erasure, restriction, objection, or portability, and withdraw consent. Email no-reply@cookeat.info. We may request only what is needed to locate your pseudonymous identifier and generally reply within one month. You may also complain to the French authority, the CNIL.
7. Children and changes
CookEat AI is not intended for children under 13 and does not knowingly collect their data. This policy is updated when features, providers, or applicable rules change; the date above identifies the latest version.