Privacy Policy
Last updated: August 31, 2026
RecipeStorage works locally and without an account by default. Data leaves your device only when you deliberately use an online feature such as synchronization, family sharing, voice input, a bug report, or a support request.
1. Controller
Jan Priorc/o IP-Management #11356
Ludwig-Erhard-Str. 18
20459 Hamburg
Germany
Email: support@recipestorage.app
2. Local use without an account
Recipes, ingredients, instructions, shopping and pantry lists, shopping areas, weekly and calendar planning, cooking sessions, settings, and locally added images or PDFs are stored on your device. When you use the app exclusively in local mode, the provider does not receive this content. You can delete it in the app or remove it by uninstalling the app. You manage and delete exported backups yourself.
3. Account and optional synchronization
If you sign in with Google and enable synchronization, RecipeStorage may process:
- Firebase user ID, email address, and, where available, Google display name.
- recipes, source URLs, ingredients, instructions, serving information, and timestamps.
- shopping and pantry lists, entries, quantities, states, shopping areas, and mappings.
- weekly plans, calendar entries, cooking sessions, wishes, and ratings where synchronized.
- custom ingredient mappings.
- recipe images and retained original PDFs when media synchronization is used.
- family name, memberships, roles, display names, and temporary invitation codes.
- the version and time of acceptance of the family-sharing terms.
We process this data to provide the account, device, and family synchronization you request. For users in the EEA, the legal basis is Article 6(1)(b) GDPR. Cloud use is optional and the local app remains available without it.
4. Family spaces
Members can view and edit content in a family space. When one member leaves or deletes their account, shared family content remains available to the other members. Deleting the entire family space removes its shared content. Share invitation codes only with people you intend to invite.
5. Google and Firebase services
- Google Sign-In / Firebase Authentication for account access.
- Cloud Firestore for synchronized structured data.
- Firebase Storage for synchronized images and retained PDF originals.
- Firebase Hosting for these information pages and invitation links.
Recipients and processors include Google Ireland Limited and the Google companies and subprocessors identified in the Firebase terms. Technical connection data such as IP address, device information, timestamps, and security logs may be processed. International transfers use the safeguards provided by Google, including adequacy decisions and/or standard contractual clauses as applicable. See Firebase Privacy and Security and the Google Privacy Policy.
6. Images, PDFs, and text recognition
Text recognition for selected images and PDF pages runs on the device. Drafts and rendered PDF pages are not sent to an OCR server. If you retain an original PDF or transfer media into a synchronized space, the file is stored in Firebase Storage like a recipe image and is shared with family members in a family space.
7. Optional voice input
When you start voice input, RecipeStorage requires microphone access and passes the recording to the speech recognition service configured on your Android device. Depending on the device, installed language, and settings, recognition may take place on the device or on servers operated by the selected service provider. If Speech Services by Google is used, Google Ireland Limited may process speech recordings, recognized text, technical connection data, and device information under Google’s privacy terms. RecipeStorage receives the recognized text, does not store the audio recording itself, and does not send the recording to Firebase or to its own servers. Voice input is optional. You can review every entry before adding it and can always use the keyboard instead. Processing initiated by you is based on Article 6(1)(b) GDPR. You can manage the speech recognition service and available offline languages in Android settings. See the Google Privacy Policy for further information.
8. Recipe websites and external images
Importing or opening a recipe URL connects your device to the relevant third-party site. Automatically displayed preview images may also load directly from that site's server. The third party may receive your IP address, access time, and device or browser information under its own privacy policy. RecipeStorage does not sell this data and currently uses no advertising or analytics trackers.
9. Optional import bug reports
If you submit an import problem while signed in, the recipe URL and host, selected issue area and type, your description, response preference, app version, platform, language, timestamp, and Firebase user ID are sent to Cloud Firestore. If you request a response, your verified account email is also stored and used as the reply address on the operator notification. For EEA users, processing is based on Article 6(1)(f) GDPR after your deliberate submission. Our legitimate interest is debugging and product quality. You may object or request deletion. Without sign-in, the app creates only a local JSON file that you may choose to share manually. The operator email contains the host, issue type, app version, and description, but not the complete recipe URL or recipe content.
10. Family content reports
If you report a recipe or member in a family, your Firebase user ID and contact email, the family ID and name, the type, identifier, and displayed label of the reported entry, the selected reason, your explanation, response preference, app version, active app language, and timestamp are stored in Cloud Firestore. Recipe text, images, and other family content are not copied into the report automatically.
To investigate a concrete report, RecipeStorage may review the affected family, including its content, membership information, and relevant activity, to the extent necessary. Other families are not accessed and there is no automatic content monitoring. For EEA users, processing is based on Article 6(1)(f) GDPR. The legitimate interests are complaint handling, protecting users and third-party rights, and complying with platform rules. These interests are balanced against members' rights and access is limited to what is needed.
11. Support requests and email notifications
A signed-in support request stores its category, topic, message, response preference, app version, platform, language, timestamp, Firebase user ID, and verified account email in Cloud Firestore. Without sign-in, the app opens a prepared message in your email app instead, where you decide whether to send it. Local recipes, shopping lists, and family content are not attached automatically.
New support, import, and family reports generate an operator email. General requests and import reports include the voluntary message. Sensitive family emails contain only the type, reference ID, time, response preference, target type, standardized reason, whether an additional explanation exists, and a protected Firebase link. Names, target labels, family content, and the submitted explanation are not copied into that operator email. Where a contact route exists, a content-minimal acknowledgement containing the reference ID is sent and clearly marked as automatic and not yet personally reviewed. Operator emails and acknowledgements use German or English according to the active app language. Legacy family reports without a language value use German. Proton AG processes email metadata and content such as sender, recipient, headers, message body, and time. For EEA users, processing is based on Article 6(1)(b) GDPR for the requested communication and additionally Article 6(1)(f) GDPR for secure operation, abuse prevention, and handling requests.
12. AI handoff
RecipeStorage does not submit recipe content to an AI service. It creates text that you can copy and optionally paste into a separate app. You decide whether to share it, and the selected service's terms and privacy policy apply.
13. Retention and deletion
- Local data remains until you delete it in the app or uninstall the app.
- Personal sync data remains until the account and associated data are deleted.
- Shared family content remains while the family space exists.
- Import reports are retained only as long as needed to investigate and fix the issue.
- Family reports are deleted or anonymized after review unless legal retention is required.
- Support requests are deleted after the communication and any necessary follow-up are complete.
- User-created exports and backups are not deleted automatically.
See Account and data deletion for the in-app and web request paths.
14. Your rights
Subject to applicable law, you may request access, correction, deletion, restriction, portability, or object to processing. You may withdraw consent prospectively where processing relies on consent and may complain to a competent data protection authority. Contact support@recipestorage.app.
15. Security, children, and changes
Transfers to Firebase are encrypted. Access rules separate personal areas and restrict family spaces to their members. The app is not directed specifically at children. We update this policy when features or legal requirements materially change. The date above identifies the current version.