Privacy Policy

Last updated: August 31, 2026

RecipeStorage works locally and without an account by default. Data leaves your device only when you deliberately use an online feature such as synchronization, family sharing, voice input, a bug report, or a support request.

1. Controller

Jan Prior
c/o IP-Management #11356
Ludwig-Erhard-Str. 18
20459 Hamburg
Germany
Email: support@recipestorage.app

2. Local use without an account

Recipes, ingredients, instructions, shopping and pantry lists, shopping areas, weekly and calendar planning, cooking sessions, settings, and locally added images or PDFs are stored on your device. When you use the app exclusively in local mode, the provider does not receive this content. You can delete it in the app or remove it by uninstalling the app. You manage and delete exported backups yourself.

3. Account and optional synchronization

If you sign in with Google and enable synchronization, RecipeStorage may process:

We process this data to provide the account, device, and family synchronization you request. For users in the EEA, the legal basis is Article 6(1)(b) GDPR. Cloud use is optional and the local app remains available without it.

4. Family spaces

Members can view and edit content in a family space. When one member leaves or deletes their account, shared family content remains available to the other members. Deleting the entire family space removes its shared content. Share invitation codes only with people you intend to invite.

5. Google and Firebase services

Recipients and processors include Google Ireland Limited and the Google companies and subprocessors identified in the Firebase terms. Technical connection data such as IP address, device information, timestamps, and security logs may be processed. International transfers use the safeguards provided by Google, including adequacy decisions and/or standard contractual clauses as applicable. See Firebase Privacy and Security and the Google Privacy Policy.

6. Images, PDFs, and text recognition

Text recognition for selected images and PDF pages runs on the device. Drafts and rendered PDF pages are not sent to an OCR server. If you retain an original PDF or transfer media into a synchronized space, the file is stored in Firebase Storage like a recipe image and is shared with family members in a family space.

7. Optional voice input

When you start voice input, RecipeStorage requires microphone access and passes the recording to the speech recognition service configured on your Android device. Depending on the device, installed language, and settings, recognition may take place on the device or on servers operated by the selected service provider. If Speech Services by Google is used, Google Ireland Limited may process speech recordings, recognized text, technical connection data, and device information under Google’s privacy terms. RecipeStorage receives the recognized text, does not store the audio recording itself, and does not send the recording to Firebase or to its own servers. Voice input is optional. You can review every entry before adding it and can always use the keyboard instead. Processing initiated by you is based on Article 6(1)(b) GDPR. You can manage the speech recognition service and available offline languages in Android settings. See the Google Privacy Policy for further information.

8. Recipe websites and external images

Importing or opening a recipe URL connects your device to the relevant third-party site. Automatically displayed preview images may also load directly from that site's server. The third party may receive your IP address, access time, and device or browser information under its own privacy policy. RecipeStorage does not sell this data and currently uses no advertising or analytics trackers.

9. Optional import bug reports

If you submit an import problem while signed in, the recipe URL and host, selected issue area and type, your description, response preference, app version, platform, language, timestamp, and Firebase user ID are sent to Cloud Firestore. If you request a response, your verified account email is also stored and used as the reply address on the operator notification. For EEA users, processing is based on Article 6(1)(f) GDPR after your deliberate submission. Our legitimate interest is debugging and product quality. You may object or request deletion. Without sign-in, the app creates only a local JSON file that you may choose to share manually. The operator email contains the host, issue type, app version, and description, but not the complete recipe URL or recipe content.

10. Family content reports

If you report a recipe or member in a family, your Firebase user ID and contact email, the family ID and name, the type, identifier, and displayed label of the reported entry, the selected reason, your explanation, response preference, app version, active app language, and timestamp are stored in Cloud Firestore. Recipe text, images, and other family content are not copied into the report automatically.

To investigate a concrete report, RecipeStorage may review the affected family, including its content, membership information, and relevant activity, to the extent necessary. Other families are not accessed and there is no automatic content monitoring. For EEA users, processing is based on Article 6(1)(f) GDPR. The legitimate interests are complaint handling, protecting users and third-party rights, and complying with platform rules. These interests are balanced against members' rights and access is limited to what is needed.

11. Support requests and email notifications

A signed-in support request stores its category, topic, message, response preference, app version, platform, language, timestamp, Firebase user ID, and verified account email in Cloud Firestore. Without sign-in, the app opens a prepared message in your email app instead, where you decide whether to send it. Local recipes, shopping lists, and family content are not attached automatically.

New support, import, and family reports generate an operator email. General requests and import reports include the voluntary message. Sensitive family emails contain only the type, reference ID, time, response preference, target type, standardized reason, whether an additional explanation exists, and a protected Firebase link. Names, target labels, family content, and the submitted explanation are not copied into that operator email. Where a contact route exists, a content-minimal acknowledgement containing the reference ID is sent and clearly marked as automatic and not yet personally reviewed. Operator emails and acknowledgements use German or English according to the active app language. Legacy family reports without a language value use German. Proton AG processes email metadata and content such as sender, recipient, headers, message body, and time. For EEA users, processing is based on Article 6(1)(b) GDPR for the requested communication and additionally Article 6(1)(f) GDPR for secure operation, abuse prevention, and handling requests.

12. AI handoff

RecipeStorage does not submit recipe content to an AI service. It creates text that you can copy and optionally paste into a separate app. You decide whether to share it, and the selected service's terms and privacy policy apply.

13. Retention and deletion

See Account and data deletion for the in-app and web request paths.

14. Your rights

Subject to applicable law, you may request access, correction, deletion, restriction, portability, or object to processing. You may withdraw consent prospectively where processing relies on consent and may complain to a competent data protection authority. Contact support@recipestorage.app.

15. Security, children, and changes

Transfers to Firebase are encrypted. Access rules separate personal areas and restrict family spaces to their members. The app is not directed specifically at children. We update this policy when features or legal requirements materially change. The date above identifies the current version.