Privacy Policy
How Cookbook handles information you provide.
Last updated: September 13, 2026.
Who we are
Cookbook is a recipe-sharing service. This Privacy Policy describes how we handle information when you use this site and related services.
What we collect
- Account details (name, nickname, email, password credentials, and optional phone)
- Group memberships and invites
- Recipes, cooks, ingredients, photos, and related content you create or upload
- Two-factor enrollment data (authenticator secret and backup codes; not your password)
- AI usage records (feature, provider, and tokens or cost) when you use optional AI features
- Bug and feedback reports you submit (including page URL, browser details, and optional screenshot)
- Technical logs needed to run and secure the service
How we use information
- Provide sign-in, groups, and recipe sharing features you request
- Send transactional email (invites, sign-in codes, and operator alerts)
- Run optional AI features you choose (recipe scan, text import, recipe image generation, blog draft)
- Operate, secure, and improve the service
- Limit optional AI usage so the service stays available
- Send two-factor email codes when that method is used
- Keep backups so we can restore the service if needed
AI features
- Some features are optional and only run when you use them: scanning a recipe photo, importing recipe text, generating a recipe photo, or drafting a blog post from recipes.
- For those actions we send the photos, text, or recipe content you submit to our AI provider (currently xAI / Grok) so they can return a result. We do not send your password.
- We store per-call usage metadata (not your password) so we can limit optional AI usage.
- That provider processes the submission to perform the feature. Do not submit photos or text you are not allowed to share with that provider.
- We do not sell this content. The AI provider may have its own retention and training practices — see their terms as well.
Sharing and visibility
- Content you mark GROUP is visible to members of those groups
- Content you mark PUBLIC (or list publicly) may be readable by anyone with the link or on explore surfaces
- We do not sell personal information
- We use service providers under our instruction. We host the app on a virtual private server we operate.
- DNS, TLS, and proxy: Cloudflare when the hostname is proxied
- Email: Resend when email sending is configured
- Photos: stored on the server, or in Cloudflare R2 (private bucket, served through the app) when that storage is enabled
- AI: xAI / Grok when you run recipe scan, text import, recipe image generation, or blog draft
Cookies
We use cookies and similar technologies needed to run the service (for example sign-in and preferences). Details and controls are on the Cookies page. We do not currently run advertising or analytics cookies.
Retention
- Leave a group (members only): we remove your membership and that group’s recipe and photo shares. Recipes you created stay with you and become private if no other group shares remain. Your account stays. The household owner cannot leave this way.
- Delete a recipe: we hide it from lists. We may keep the record until an operator permanently removes it.
- Remove a photo: we delete the stored file and its record. If that photo was attached as a bug-report screenshot, the report stays and the screenshot link is cleared.
- Delete profile (Settings): we hide your account, your recipes, and photos you own; we revoke your sessions; we keep your email on the account so we can recover it if needed. Empty households you own are also hidden. You cannot delete your profile while you own a household that still has other members.
- Cooks, AI usage records, and bug reports are not automatically erased when you leave a group, delete a recipe, or delete your profile.
- Weekly backups can retain data until they rotate. Local weekly backups keep the newest two copies. Off-site backups, when enabled, are kept as needed to operate the service.
- Hidden records remain until an operator permanently removes them. We have not set a numbered retention period.
Your choices and contact
- Update your profile in Settings
- Leave a group you do not own from Groups
- Delete your profile in Settings (not available if you own a household with other members)
- Change cookie preferences on the Cookies page
- Email support for privacy questions
- There is no self-serve data export. Contact us if you need a copy of your information
Contact us about privacy questions at [email protected].
Changes
We may update this policy as the product evolves. The “Last updated” date at the top will change when we do. Continued use after an update means you accept the revised policy.
Related
See also our Terms of Service and Cookies page.