Privacy Policy
Last updated: August 4, 2026
At a glance
- We do not sell your personal data.
- We do not use your data for advertising tracking or behavioral ads.
- Cookstack needs an account so your shelf, recipes, and kitchen tools can sync securely in the cloud.
- You can update your profile, contact us, or delete your account from the app.
1. Who we are
This Privacy Policy explains how Cookstack (“Cookstack,” “we,” “us,” or “our”) collects, uses, stores, and shares information when you use:
- The Cookstack mobile applications for iOS and Android (the “App”)
- Our website and related pages (including cookstack.app and download, email confirmation, and share landing pages)
- Any related services, APIs, or support channels we operate (together, the “Services”)
By creating an account or using the Services, you agree to this Policy. If you do not agree, please do not use Cookstack.
Questions: [email protected]. Related documents: Terms of Service.
2. Information we collect
2.1 Account and profile information
When you register or manage your account, we collect:
- Email address and password (stored as a secure hash — we never store plaintext passwords)
- Display name, optional avatar, bio, and profile links you choose to add
- Email verification status and related confirmation tokens
- Account identifiers used to authenticate API requests (such as session tokens)
You must confirm your email before signing in. Confirmation links expire after a limited time (typically 48 hours).
2.2 Cookbook, recipe, and kitchen data you create
To provide Cookstack’s core features, we store content tied to your account, including:
- Books on your shelf and related metadata (for example ISBN lookups and catalog matches)
- Bookmarks, custom lists, meal plans, grocery lists, and cook logs
- Ratings, reviews, and comments you post on books or recipes
- Book index requests you submit when a cookbook is missing or incomplete
- Any other in-app content you intentionally save or publish
2.3 Camera and photo library
- Camera: Used on-device to scan ISBN barcodes on cookbook covers. We process the barcode to look up the book; we do not use the camera feed for advertising or continuous recording.
- Photo library: Used only if you choose to attach a screenshot or image to a bug report or similar support submission.
You can deny or revoke these permissions in your device settings. Some features (scanning or attachments) will not work without them.
2.4 Support, contact, and bug reports
If you contact support or submit a bug report, we collect the information you provide, such as name, email, subject, message, optional attachments, and basic device or app context that helps us diagnose issues (for example app version or OS).
2.5 Technical and usage information
We may automatically collect limited technical data needed to operate and secure the Services:
- Device type, operating system, and app version
- IP address and approximate network metadata when you connect to our servers
- Timestamps, request logs, and error or crash diagnostics
- Authentication and security events (for example failed logins or abuse signals)
We do not sell this data and do not use it to build advertising profiles.
2.6 Purchases and subscriptions (if offered)
If you purchase optional paid features through the Apple App Store or Google Play, payment is processed by Apple or Google. We do not receive or store your full payment card number. We may receive subscription status, product identifiers, and an anonymized or store-linked customer identifier (for example via RevenueCat) so the App can unlock entitlements and restore purchases.
2.7 Share links and website visits
When someone opens a shared recipe or book link on our website, we may load public catalog metadata (title, description, cover image) to show a preview and help open the App. Website visits may generate standard server logs. Email confirmation pages process the token in your link to verify your account.
2.8 Information we do not intentionally collect
- We do not request access to your contacts, calendar, or precise continuous location
- We do not sell personal information to data brokers
- We do not run third-party advertising SDKs for behavioral targeting inside the App
3. How we use information
We use information to:
- Create and secure your account, verify email, and authenticate sessions
- Provide shelf, search, recipes, meal plans, groceries, cook logs, lists, and social features
- Sync your data across devices and restore it when you sign in
- Process ISBN lookups, catalog matching, and book index requests
- Moderate community content and enforce safety rules
- Respond to support requests and investigate bugs
- Maintain reliability, prevent abuse, and improve the Services
- Communicate about account security, confirmation emails, and important service notices
- Manage optional subscription entitlements when applicable
- Comply with legal obligations
4. Legal bases (EEA/UK and similar regions)
Where required, we process personal data under one or more of these bases:
- Contract: to provide the Services you request (account, shelf sync, core features)
- Legitimate interests: to secure the platform, prevent fraud/abuse, improve reliability, and understand aggregate product usage
- Consent: where required for optional permissions (camera, photos) or certain communications
- Legal obligation: when we must retain or disclose information to comply with law
5. How we share information
We do not sell personal data. We may share information only as follows:
5.1 Service providers
Trusted vendors who help us run Cookstack, such as hosting, databases, object storage (for example covers or uploads), email delivery, crash reporting, and subscription status tooling. They are permitted to process data only to provide services to us and must protect it appropriately.
5.2 App stores and payment platforms
Apple, Google, and related subscription infrastructure process payments and may share limited purchase/entitlement signals with us.
5.3 Public or shared content
Content you choose to make public (for example reviews or comments) can be visible to other users. Shared web links may expose public catalog details for a recipe or book.
5.4 Legal, safety, and business transfers
- To comply with law, lawful requests, or legal process
- To protect rights, safety, and security of users, the public, or Cookstack
- In connection with a merger, acquisition, financing, or sale of assets, subject to appropriate confidentiality and this Policy’s principles
6. Community moderation
To keep Cookstack safe, we may review reports, remove content that violates our rules, and suspend accounts involved in abuse. Automated checks may assist human review. Moderation actions may use the content and account information necessary to investigate a report.
7. Data retention
We retain account and kitchen data while your account is active. After you delete your account, we delete or anonymize personal data associated with it within a reasonable period, except where we must retain limited records for security, dispute resolution, legal compliance, or backups that rotate out on a normal schedule. Support tickets and logs may be kept for a limited time to improve support quality and security.
8. Security
We use industry-standard measures appropriate to the sensitivity of the data, including encrypted transport (HTTPS), hashed passwords, access controls, and server hardening practices. No method of transmission or storage is 100% secure. Please use a strong unique password and keep your devices updated.
9. International transfers
We may process and store information on servers located outside your country of residence. Where required, we use appropriate safeguards for cross-border transfers.
10. Your rights and choices
Depending on your location, you may have rights to:
- Access the personal data we hold about you
- Correct inaccurate information
- Delete your account and related personal data
- Export or receive a copy of certain data
- Object to or restrict certain processing
- Withdraw consent where processing is consent-based
- Lodge a complaint with a supervisory authority
In the App you can typically update profile details and delete your account from settings. For other requests, email [email protected]. We may need to verify your identity before fulfilling a request.
Device permissions (camera, photos, notifications) can be changed in your OS settings.
11. Children’s privacy
Cookstack is not directed to children under 13 (or the minimum age required in your country). We do not knowingly collect personal information from children under that age. If you believe a child has provided personal data, contact us and we will take appropriate steps to delete it.
12. Third-party links and services
The Services may link to third-party sites or content (for example recipe sources or store pages). Their privacy practices are governed by their own policies. We are not responsible for third-party practices.
13. Changes to this Policy
We may update this Privacy Policy from time to time. We will post the revised version with an updated “Last updated” date. Material changes may also be communicated in-app or by email when appropriate. Continued use after changes become effective means you accept the updated Policy.
14. Contact
Privacy questions or requests: [email protected]
General support: use Contact Support in the App, or email us at the address listed in the App’s help section.