Legal
Privacy Policy
Effective date: June 22, 2026
This policy is written for Cheftal's current product behavior across the iOS app, web share pages, API, and supporting services. It is not a substitute for legal advice.
1. Scope
This Privacy Policy explains how Cheftal collects, uses, discloses, and protects information when you use Cheftal's iOS app, website, shared recipe/profile/cookbook pages, admin-supported services, and related APIs.
Cheftal is a social recipe app. The app lets you create and import recipes, save recipes and cookbooks, follow or friend other users, share links, discover contacts who use Cheftal, maintain pantry and shopping-list data, receive notifications, and purchase optional Pro features.
2. Information we collect
Account and profile information: username, display name, bio, avatar, social links, email address, phone number, authentication identifiers, account status, badges, privacy settings, contact-discoverability settings, and session/device records.
Content you provide: recipes, recipe drafts, ingredients, steps, descriptions, cooking times, servings, source URLs, source names/authors, photos, videos, captions, cook logs, ratings, cookbook names/sections/items, direct messages that share recipe/profile/cookbook cards, reports, appeals, and support or admin communications.
Preference and personalization information: onboarding answers, diet preferences, allergies, favorite cuisines, goals, cooking skill, time budget, taste profiles, saved searches, recently viewed recipes, feed impressions, searches, and other in-app interaction events used to operate recommendations and app features.
Pantry, shopping, and household information: pantry items and staples, barcode scan results, receipt scan jobs and extracted items, household memberships, shopping lists, shopping-list collaborators, and shopping-list sync events.
Contacts information: if you grant Contacts access, Cheftal hashes contact identifiers on your device and uploads hashes so we can show contacts already on Cheftal and help you invite others. We do not store your address book in readable form.
Device, app, and security information: device platform, push token, app version, locale, session identifiers, Apple App Attest information, device trust state, moderation/audit logs, share-link opens, and operational logs.
Payment and subscription information: Cheftal uses RevenueCat and Apple in-app purchase systems for Pro subscriptions. We receive subscription entitlement information such as app user ID, entitlement ID, product ID, store, status, renewal state, expiration date, and related webhook/audit data; we do not receive your full payment card details.
Analytics information: Cheftal uses PostHog to understand app usage and reliability. Events may include sign-in/sign-up method, onboarding completion, recipe views, searches, shares, published recipes, cook activity, paywall views, and subscription events, along with device/app context provided by the SDK.
3. Permissions and device features
Camera and Photos: used to import recipe photos, add cover/avatar/cook-log photos, scan pantry items, barcodes, and receipts, and upload selected media to Cheftal-hosted storage.
Microphone and Speech Recognition: used for hands-free cooking commands and voice-based recipe creation or notes where available.
Contacts: used only after permission to hash contact identifiers on-device for friend discovery and invitations.
Notifications: used to send push notifications for social activity, cookbook activity, creator following, recipe/cook activity, moderation outcomes, and similar account or app updates. You can manage notification preferences in the app or through iOS settings.
4. How we use information
To provide, maintain, secure, and improve Cheftal, including account authentication, sessions, device trust, feed ranking, search, recipe parsing/importing, photo moderation, recommendations, sharing, direct-message card delivery, pantry/shopping features, notifications, and customer support.
To process and enforce privacy choices, including private profiles, content visibility, blocks, contact-discoverability opt-outs, deleted/banned account states, and public-content handling after account deletion.
To personalize your experience, such as using preferences, allergies, pantry data, viewing history, saved items, search events, and social signals to recommend recipes or features.
To process subscriptions, entitlements, trials, feature limits, purchase restoration, and related support.
To detect, prevent, investigate, and respond to spam, abuse, security incidents, policy violations, copyright/IP concerns, fraud, and safety issues.
To comply with legal obligations and enforce our Terms of Service.
5. Sharing and disclosure
Other users and the public: public profiles, public recipes, public cookbooks, creator pages, share links, usernames, display names, avatar URLs, badges, and approved public content may be visible to other users or anyone with a link. Private-account identity fields such as username, display name, and avatar may still appear in search, friend discovery, or social surfaces; private content remains gated according to product rules.
Collaborators and social features: cookbook collaborators, friends, followers, invite recipients, direct-message recipients, and users you interact with may see information needed for those features, such as your profile, shared cards, relationship status, cook activity, or collaborator activity.
Service providers: we use third-party providers for authentication (Clerk), subscriptions and purchase status (RevenueCat and Apple), analytics (PostHog), cloud hosting/storage/CDN/database infrastructure, push-notification delivery, AI-assisted parsing/tagging/moderation, and Instacart shopping-link generation. These providers process information for us or to provide their integrated services.
Instacart: when you choose to shop a recipe with Instacart, Cheftal sends recipe ingredient information and your all-vs-missing selection to generate a pre-filled Instacart shopping link, and then opens Instacart's experience.
Moderation, safety, and legal: we may disclose information if we believe it is necessary to enforce our Terms, protect users or the public, respond to lawful requests, investigate abuse, or complete a merger, acquisition, financing, or sale of assets subject to appropriate protections.
We do not sell your personal information for money. We do not use readable address-book contacts for advertising.
6. AI and automated processing
Cheftal uses automated and AI-assisted systems to parse recipes from URLs, photos, voice, or mixed inputs; generate or normalize recipe drafts; transcribe or interpret social video imports; tag recipes; estimate nutrition/allergen-related labels; personalize feeds/search; scan pantry/receipt images; and review photos or content for moderation. AI results can be imperfect, and nutrition, allergen, and dietary outputs are informational only and should be independently verified.
7. Retention and deletion
We retain information for as long as needed to provide Cheftal, comply with legal obligations, resolve disputes, enforce agreements, maintain security, and support legitimate business operations.
When you request account deletion, Cheftal marks the account deleted, records deletion timing, schedules a purge after a grace period, and applies the selected public-content policy where supported. Some information may remain longer where necessary for safety, fraud prevention, legal compliance, backup integrity, audit records, or where content has been shared with or saved by others.
You may also delete or change many kinds of content directly in the app. Deleted media and database records may persist for a limited time in backups or logs.
8. Your choices and rights
You can update profile information, choose private/public content settings where available, manage contact discoverability, manage notification preferences, revoke iOS permissions, block users, unsubscribe or manage Pro through Apple, and request account deletion or support help.
Depending on where you live, you may have rights to access, correct, delete, port, or object to certain processing of your personal information. To make a privacy request, contact hello@cheftal.app. We may need to verify your identity before acting on a request.
9. Children
Cheftal is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided personal information to Cheftal, contact hello@cheftal.app.
10. Security and international processing
We use technical, organizational, and administrative safeguards designed to protect information, including authentication, access controls, device/session checks, hashed contact matching, and moderation/security review processes. No online service can be guaranteed completely secure.
Cheftal and its providers may process information in the United States and other locations where they operate. By using Cheftal, you understand that information may be transferred to and processed in those locations.
11. Changes and contact
We may update this Privacy Policy from time to time. If changes are material, we will provide notice as required by law, such as by updating this page, in-app notice, or other reasonable means.
Questions or requests: hello@cheftal.app.