Cuisy Legal

Privacy Policy for iOS and Android

Privacy Policy

Your data, your control.

This policy explains how Cuisy collects, uses, stores, and protects data across free offline-first usage and premium cross-device features.

Last Updated: October 6, 2026 Effective Date: October 6, 2026 Bundle ID: com.hardal.cuisy

1. Who We Are

Cuisy is the controller for privacy requests related to the Cuisy app.

If local law requires entity name or address details, this section will be updated accordingly.

2. Scope of This Policy

This policy applies to Cuisy iOS and Android apps, backend services for premium sync and AI features, and account/support communication flows.

It does not apply to third-party sites or apps opened externally from Cuisy.

3. Data We Collect

3.1 Account and Identity Data
  • Email address and display name
  • Authentication provider (email/password, Google, Apple)
  • Authentication identifiers and session/token data
3.2 Recipe and Content Data
  • Recipes, ingredients, steps, notes, ratings, favorites, tags, and cooking history
  • Submitted video links for parsing
  • Uploaded PDF cookbooks for indexing and search
  • Uploaded meal and fridge photos for AI analysis
  • Source metadata such as URL and citation/page details
  • PDF cookbook search is user-scoped; each account searches only its own uploaded books
3.3 Kitchen Management Data
  • Fridge items: quantity, units, expiration, and notes
  • Shopping list items: status, ordering, and notes
  • Ingredient matching results
3.4 Preferences and Settings
  • Unit system, theme, haptics, dietary and meal preferences, notification preferences
3.5 Subscription and Transaction Metadata
  • Subscription status, tier, store, renewal and expiry dates
  • RevenueCat identifiers and entitlement metadata

Cuisy does not receive full payment card details from Apple or Google.

3.6 Technical and Usage Data
  • Device model, OS version, app version
  • Push notification token
  • Request metadata used for security and service operation, such as IP address, request path, request ID, and timestamps
  • Quota, rate-limit, cache, and capture-job status needed to operate requested features
  • Platform/store diagnostics may be available under your device settings; Cuisy has no app-integrated analytics SDK
  • Crash and error reports sent to Sentry (EU data region) when the app crashes, freezes, or hits an unexpected error: error type and stack trace, app version and build, device model and OS version, the screen in use with a short trail of recent technical events (screen changes, taps, request paths, and status codes), and a random per-install identifier. Reports exclude your account, email, recipe content, and IP address, are not linked to your account, and are deleted automatically within 90 days
3.7 Data We Do Not Intentionally Collect
  • Precise GPS location
  • Contacts, call logs, or SMS
  • Stored voice audio or transcripts (Cook Mode voice commands are matched in memory; see Section 7)

4. Permissions We Request

Permissions are requested only when needed by a feature.

  • Camera and Photos: meal photo capture, fridge scan, profile image
  • Files and Documents: selecting PDF cookbooks
  • Microphone and Speech Recognition (optional): Cook Mode push-to-talk voice commands, requested the first time you use them
  • Notifications (optional): capture/job/account notifications

If permission is denied, some features may be limited while core local features remain available.

5. How We Use Data

  • Account authentication and security
  • Recipe, fridge, and shopping list functionality
  • AI capture and AI search operations initiated by the user
  • Quota and subscription entitlement enforcement
  • Optional premium cloud sync across devices
  • Requested notifications and support responses
  • Abuse prevention, crash and error diagnostics, and legal compliance
Cuisy does not sell personal data.

6. Free Tier vs Premium Tier Processing

Offline-First Design
  • Core recipe-library, fridge, matching, and shopping-list data is stored locally in SQLite and remains available offline
  • Capture, AI, authentication validation, notifications, and cross-device features require network services
Premium Backend Mirror
  • For premium features, selected recipe, fridge, and shopping data may be mirrored to the Cuisy backend for cross-device access
  • SQLite remains the on-device source of truth, and backend mirroring is asynchronous

7. AI and Voice Processing

When AI features are used, Cuisy processes data needed to fulfill the request:

  • Video URL parsing
  • PDF text extraction, chunking, embedding, and retrieval
  • Meal and fridge image understanding
  • Recipe suggestion and ingredient matching

AI output may include structured recipes, ingredient lists, and citation-based responses.

Provider retention, training, and deletion are governed by the applicable provider terms; Cuisy does not claim an unverified fixed retention period.

Private PDF Retrieval Scope
  • Indexed cookbook data is linked to the uploading account
  • Other users cannot search or access your uploaded books in-app

You are responsible for having rights to content you upload.

Voice Commands (Cook Mode)
  • Cook Mode voice control is push-to-talk: the microphone listens only while you hold the mic button, and microphone permission is requested only the first time you use it
  • Where your device supports it, speech is recognized on-device; otherwise audio is processed by your device's speech service (Apple or Google), which the app discloses before asking for permission
  • Cuisy does not store, log, or send voice audio or transcripts to the Cuisy backend; the recognized phrase is matched to a cooking command in memory
  • If a platform speech service is used, its processing and retention follow your device settings and that provider's terms

8. Third-Party Services and Data Sharing

Data is shared with processors only for service operation.

8.1 Hosting and Infrastructure
8.2 Authentication
8.3 AI Providers
8.4 Speech Recognition (Cook Mode)
8.5 Subscription and Billing
8.6 Notifications
8.7 Source Platforms
8.8 Crash and Error Diagnostics
8.9 Legal and Corporate Transfers
  • Disclosure may occur when required by law or legal process
  • Disclosure may occur to protect rights, safety, and security
  • Disclosure may occur in merger/acquisition scenarios with proper notice where required
No cross-context behavioral advertising data sharing. No public cross-user cookbook library search.

9. Data Retention

  • On-device data: retained until deleted by user, account deletion, or uninstall
  • Premium synced data: retained while account remains active, and for 30 days after you delete it (see below)
  • Operational logs: retained only as needed for service, fraud prevention, security, and legal obligations
  • Crash and error reports: deleted automatically by Sentry within 90 days

After an in-app account deletion request:

  • Your account is deactivated immediately: you are signed out on every device, the account can no longer be used, and owner-scoped local app data on your device is removed at once
  • Cuisy backend account records are kept, inaccessible, for 30 days so you can change your mind, and are then permanently deleted. To keep your account, sign in again before then and choose Restore
  • We keep your device's notification token for those 30 days only to tell you when the deletion is complete
  • Deleting your account does not cancel a Premium subscription; cancel it in your App Store or Google Play subscription settings
  • Deletion requests sent by email are completed within 30 days of verification
  • Records held by external processors (for example AI providers, RevenueCat, or Sentry) follow those processors' own retention and deletion processes
  • Cuisy does not promise an unverified fixed deletion period for provider-held records

If law requires longer retention, only minimum necessary data is retained.

10. Account Deletion and Data Export

10.1 In-App Deletion

Account deletion can be initiated from account/settings screens in-app. The account is deactivated immediately and its Cuisy backend records are permanently deleted 30 days later, unless you sign in again before then and choose Restore. See Delete your account.

10.2 Out-of-App Deletion Request

If app access is not available, send request to tolga@getcuisy.com from your registered address.

10.3 Data Export

The app can download the account, recipe, fridge, and shopping data currently held by the Cuisy backend in JSON format. Local-only settings and files are not included. Other access requests are handled through support, subject to identity verification.

10.4 Crash and Error Reports

Crash and error reports are not linked to your account, so they cannot be looked up, exported, or deleted per account. They are deleted automatically within 90 days.

11. International Data Transfers

Data may be processed in countries other than your own depending on infrastructure and region.

Crash and error reports are stored by Sentry in its EU data region.

Where required, lawful transfer mechanisms and reasonable technical safeguards are applied.

12. Security Measures

  • HTTPS/TLS for data in transit
  • Access controls and authentication tokens
  • Secure credential handling and password hashing
  • Platform security features such as Keychain/Keystore where applicable
  • Monitoring and rate limiting for abuse-sensitive endpoints

No transmission or storage method is fully risk-free; controls are continuously improved.

13. Children's Privacy

Cuisy is not intended for users under 13 years of age (16 in the EU), or a higher minimum age where required by local law.

If you believe child data was submitted, contact tolga@getcuisy.com for investigation and required deletion.

14. Your Privacy Rights

Depending on jurisdiction, rights may include:

  • Access, correction, and deletion
  • Data export/portability
  • Restriction or objection to certain processing
  • Withdrawal of consent for consent-based processing
  • Non-discrimination for exercising rights
  • Platform controls: manage permissions (camera, photos, microphone, notifications) and OS/store diagnostics in device and store settings

Rights requests can be sent to tolga@getcuisy.com. Identity verification may be required.

15. App Store and Google Play Disclosure Alignment

This policy is maintained to align with Apple App Store App Privacy and Google Play Data Safety disclosures.

Typical categories declared
  • Contact info
  • User content
  • Identifiers
  • App activity, crash data, and diagnostics
  • Purchases/subscription metadata (not card numbers)
Data handling principles
  • Purpose-limited collection
  • No personal data sale
  • No default cross-app ad tracking
  • Contextual permission requests

16. iOS 2026 Privacy Compliance Notes

  • Privacy policy availability in-app and App Store metadata
  • In-app account deletion initiation for account-based apps
  • Privacy manifest and required-reason API declarations where applicable
  • Third-party SDK privacy manifest/signature requirements where applicable
  • ATT prompt only if tracking is introduced in the future

Current default posture: no cross-app targeted ad tracking design.

17. Google Play Compliance Notes

  • Privacy policy URL in Play Console and accessible in-app
  • Data Safety declarations aligned with actual app and SDK behavior
  • Account deletion support via in-app and out-of-app request channels
  • Policy and disclosures updated when data behavior changes

18. Changes to This Policy

This policy may be updated periodically.

Material updates are communicated by updating this page and, where appropriate, via in-app notice.

19. Contact

For privacy, support, data export, and account deletion requests:

tolga@getcuisy.com
By using Cuisy, you acknowledge this Privacy Policy.