Who is responsible for your data?
CookIt is a recipe app for Android and iOS published by Martin Confais, the controller for the processing described here. Contact: cookit.app.contact@gmail.com.
This policy covers the CookIt app and its account, sync, sharing, import and subscription services. It describes the current version. Older versions could keep a device-only library; uninstalling the app does not erase data already synced to the cloud.
The data we process
| Data | Use |
|---|---|
| Account | Firebase user ID, Google or Apple provider, and name, email or profile picture when supplied by that provider. Used to authenticate you, identify the correct account and protect your library. |
| Library | Recipes, titles, descriptions, ingredients, steps, selected photos, source links, categories, ratings, favourites and nutrition or duration information you enter. Cooking progress, meal plans and shopping lists support their respective features and sync. |
| URL imports | Confirmed public URL, accessible public source content, app language, extracted draft, optional cover, corrections and processing status. |
| Notifications | Random installation ID, hash linked to the account and import job, notification token, language, platform and delivery status. Used to notify the installation that requested an import. |
| Subscription | RevenueCat user ID linked to your CookIt account, purchased products, receipts or transaction IDs, dates and Premium entitlement status. Card numbers and bank details are handled by the Store and are not provided to us. |
| Operation and security | Technical information needed to serve requests and protect the service: IP address, platform, app version, integrity attestation, timestamps, technical errors, job status and latency or model usage measurements. |
| Support | Email address, message content and information needed to resolve a request or verify account ownership. |
A Google or Apple account is required to access the current version of CookIt. Photos, imports, sharing and notifications depend on the features you use. Avoid putting sensitive personal information in recipes or content you share.
Purposes and legal bases
- Provide the service you request: account management, storage and sync, cooking, planning, shopping, voluntary sharing and requested imports. These activities are based on performance of the CookIt service contract.
- Manage Premium: verify purchases, unlock paid features and restore purchases when you expressly request it, to perform the subscription contract.
- Protect and maintain the service: account security, abuse prevention, reliability, troubleshooting and support. We rely on our legitimate interest in providing a safe, working service and limit the data used.
- Meet applicable obligations: respond to data rights requests and retain records required by law.
- Display optional notifications: with your system permission, which you can revoke in device settings. Camera and photo permissions allow the access you request; they do not authorise unrelated uses.
Imports create drafts for your review. CookIt does not make automated decisions producing legal or similarly significant effects on you.
On your device and in the cloud
CookIt keeps a local copy for fast access and offline use after an initial sign-in. Saved recipes, their photos and associated data are synced through Firebase services under your account. Offline changes remain pending until connectivity returns.
Language, theme and some display preferences remain device-specific. Pending import sessions and ready drafts belong to the installation that requested them; the recipe syncs across devices after you explicitly save it.
We can process hosted data to operate the service, resolve support or deletion requests and maintain security. Sync does not guarantee that a change still pending on a device has already been backed up remotely.
AI-assisted imports
When you confirm a public URL with Premium, CookIt sends that URL to its Firebase and Google Cloud backend. Accessible public content is fetched and sent to Vertex AI to extract a draft and, where necessary, translate it into the app language. Your existing saved private recipes are not sent to the model for this operation.
For a TikTok video post, the import uses accessible public text, such as the caption and embed text; it does not analyse video, audio or comments. For a TikTok photo post, accessible public slides may be analysed in order with the caption. Those images are processed temporarily; a compressed copy of the first may be kept as the draft cover and then as the saved recipe cover. A public cover image may also be fetched for other supported sources.
CookIt does not bypass private, paywalled or inaccessible content. Results can be incomplete or incorrect: review ingredients, quantities, steps, durations and any nutrition values before saving or cooking. CookIt does not offer allergen analysis.
CookIt does not authorise using these inputs to train the provider’s models. Google’s processing remains subject to its Vertex AI terms and retention and security rules; we do not promise zero retention across all infrastructure.
What a share link makes accessible
Sharing creates a hosted copy of a recipe, including its content and shareable photos. Anyone with the link can view the recipe and forward it. Access is not limited to CookIt users. The link expires after 30 days.
Review the content before sharing, especially photos, notes and source links. Recipients can save or copy the recipe. Account deletion or link expiry cannot erase copies already kept by others. An existing link is a sharing snapshot and may not reflect every later edit to your recipe.
Photos, permissions and notifications
The camera and photo library are accessed when you choose to add a photo. CookIt copies the selected image into app storage and may resize and compress it before sync or sharing. The app does not upload your entire photo library.
Import notifications use Firebase Cloud Messaging and Apple’s push notification service on iOS. Permission is requested in the import flow; you can deny or revoke it in system settings. Result alerts are generic, without recipe titles, ingredients or recipe text, and target only the installation that requested the import. Tokens are renewed or revoked on account changes and sign-out.
Providers and international transfers
- Google / Firebase / Google Cloud: authentication, database, photo and link hosting, server functions, processing queues, notifications, app integrity and Vertex AI extraction. Firebase privacy information.
- RevenueCat: purchase and Premium verification linked to your account ID. RevenueCat privacy policy.
- Apple and Google: sign-in, app distribution, payments and subscription management; Apple also delivers iOS push notifications. Their own services are covered by their respective policies: Apple and Google.
- Source websites and recipients: imports request content from the source you selected; shared copies become accessible to link holders.
Processing is not exclusively in France or the European Union. Import and deletion functions are configured in Europe, recipe photos are hosted in a US Google Cloud region, and Vertex AI uses a global endpoint. Providers may process data in other countries.
Transfers necessary for the service rely on applicable provider safeguards, including standard contractual clauses and, where their conditions are met, adequacy decisions. Contact us for information about relevant safeguards. See the Firebase processing agreement and Google Cloud processing agreement.
How long we keep data
| Data | Period or criterion |
|---|---|
| Account and saved library | While you keep the account or content, until deletion. Deletion markers may remain associated with the account to prevent older offline devices from restoring deleted data. |
| Unfinished import | The initial request expires after 24 hours. Raw source content is temporary; analysis images are processed in memory. The working URL and recovery data are cleaned up after processing or closure. |
| Ready unsaved draft | Expires after 7 days. Saving, cancellation, discarding or expiry triggers cleanup; scheduled jobs and retries catch up if cleanup fails. |
| Imported cover | Cleaned up when an import is discarded or expires. If you save the recipe with this cover, it follows the recipe’s retention period. |
| Share link | Accessible for 30 days, then removed by scheduled cleanup. Recipients control their own copies. |
| Notification registration | Valid for 60 days, renewed during use. Expired, invalid or revoked tokens are cleaned up. |
| Account deletion proofs | User ID, status and receipt hash kept for 90 days after processing completes to prevent unintended restoration and resolve interrupted responses. Unfinished requests remain until resolved. |
| Support, security and required records | For as long as needed to resolve the request or incident, protect the service or comply with an applicable obligation. Providers also retain purchase records and logs under their own obligations. |
Expiry makes content unavailable and triggers deletion; physical removal may depend on scheduled cleanup and retries. A source link you retain in a saved recipe is part of that recipe, not merely temporary import data.
Delete your account and data
In CookIt
Open Settings → Delete account and confirm your request. Google or Apple verification may be required to protect your account.
Without the app
Email cookit.app.contact@gmail.com from the address associated with your account and say you want to delete your CookIt account. We will verify ownership. Never send your password or a sign-in code.
Request deletionDeletion removes the Firebase account, cloud library, account-owned photos, shopping lists, meal plans, share links, import jobs, notification registrations and linked RevenueCat profile. Failed cleanup is retried, and a follow-up pass handles writes already in progress before deletion.
An offline device cannot be erased remotely immediately. Copies already exported or saved by recipients and records the Stores must retain are not removed by this request. Limited deletion proofs remain for the periods above.
Deleting your account or uninstalling CookIt does not cancel a subscription. Manage renewal separately in Apple subscriptions or Google Play subscriptions. Cancellation is not a prerequisite for requesting deletion.
Your rights and how to exercise them
Depending on applicable law, you may request access, correction, erasure, restriction of processing and portability of the data you supplied. You can object to processing based on our legitimate interests on grounds relating to your situation and withdraw consent where processing depends on it, without affecting earlier lawful processing.
Email cookit.app.contact@gmail.com. We may request only information necessary to verify your identity. We normally respond within one month and will inform you if a legally permitted extension is necessary. Sharing a recipe is not a complete data export; portability requests can be sent to the same address.
You may also complain to the CNIL or your country’s data protection authority.
Security, advertising and minors
We use encrypted connections, authentication and access controls to protect data. Firebase App Check integrity controls help limit abuse. No infrastructure guarantees absolute security. Production application logs are designed to exclude recipe text, raw model responses, full URLs and secret tokens.
CookIt does not show third-party advertising, sell your data, or use it for targeted advertising or tracking across apps. Technical data necessary for operation and security may still be processed by the services we use; this is not a promise that no data is collected.
CookIt is not directed at children under 13. Minors need a parent or legal guardian’s permission where the law requires it. Contact us if you believe a child has supplied data without required permission so we can review and delete it where necessary.
Updates and contact
This policy was updated on 7 October 2026. Material processing changes will be communicated appropriately. Updating this policy or continuing to use the app does not constitute consent to a new purpose where your consent is required.
For privacy questions: Martin Confais — cookit.app.contact@gmail.com.