Privacy Policy
1. Who we are
Fork & Spoon ("we", "us") is a recipe-management and AI-cooking-assistant app operated by Fork & Spoon, a sole proprietorship (eenmanszaak) established in the Netherlands at Voorstraat 44, 5334 JV Velddriel, registered with the Dutch Chamber of Commerce (KvK) under number 42137788. For the purposes of the EU GDPR, Fork & Spoon is the data controller. Privacy contact: [email protected].
2. Scope
This Policy applies when you use the Fork & Spoon mobile or web application (the "App"), visit forkandspoon.app or our share-link pages (the "Website"), or communicate with us. It does not cover third-party services you reach through links in the Service.
3. The data we collect
3.1 Data you provide directly
| Category | Examples | Why we need it |
|---|---|---|
| Account data | E-mail, display name, password (hashed), authentication provider (Apple, Google) | Create and secure your account |
| Profile data | Profile picture, first and last name, language, measurement system, and your sharing and e-mail notification preferences | Show your account and display recipes in your language and units |
| Content you create | Recipes, cookbooks, photos, shopping lists, weekmenu entries | Deliver the core Service |
| Sharing data | E-mail addresses of people you invite; household and cooking-buddy connections | Send invitations and manage access |
| Communications | Support requests, feedback | Respond to you and improve the Service |
| Payment data | Subscription status, plan, renewal date — via RevenueCat / Apple / Google. We never receive card numbers or bank details. | Manage your subscription |
If you join a household or connect with a cooking buddy, content you share in that context (such as shopping lists, weekmenus, cookbooks or recipes) is visible to those people until you revoke access or leave.
3.2 Data collected automatically
- Device & technical data — device model, OS, App version, language, timezone, crash reports, network type.
- Usage data — features used, AI actions performed, credits consumed, errors.
- Identifiers — pseudonymous install identifier, Supabase user ID, RevenueCat user ID.
- Approximate location — derived from IP at country/region level. No GPS or precise location.
3.3 Data from third parties
- Sign in with Apple — e-mail (or private relay), name (first time only).
- Google Sign-In — e-mail, name, profile picture.
- RevenueCat / Apple App Store / Google Play — subscription status, entitlements, purchase receipts.
3.4 What we do not collect
- No precise GPS location; no access to contacts, calendar, microphone, SMS or your photo library beyond images you explicitly pick.
- Biometric authentication is handled by your OS on your device — we only receive a yes/no result.
- We do not knowingly collect data from children (see §11).
4. How we use your data
Under the GDPR we need a legal basis for each purpose: (a) performance of a contract, (b) legitimate interests, (c) consent, (d) legal obligation.
| Purpose | Legal basis |
|---|---|
| Account management, storage and sync of your content, AI features and credit metering, subscriptions, transactional e-mail | Contract (a) |
| Customer support | Contract (a) / Legitimate interest (b) |
| Fraud and abuse prevention; aggregate usage analysis to improve the Service | Legitimate interest (b) |
| Marketing e-mails about new features | Consent (c) — opt-in |
| Legal obligations (tax, accounting) | Legal obligation (d) |
You may object to processing based on legitimate interest at any time (see §10). We do not use your data for automated decisions with legal or similarly significant effects; AI features generate content, they do not score or profile you.
4.1 AI processing
When you use AI features, the minimum necessary content is sent to our AI provider(s), currently routed via OpenRouter (see §6). We do not use your content to train third-party foundation models, and our providers are prohibited from using your prompts and outputs for model training. AI output may be inaccurate — verify recipes, especially for allergens, before relying on them.
5. Cookies and local storage
The App uses no browser cookies; it uses local storage and identifiers to keep you signed in, cache content offline and meter AI usage. The Website uses only functional and security cookies — no analytics or advertising cookies, so no cookie banner is needed. If that changes, we will update this Policy and ask consent where required.
6. Service providers (sub-processors)
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication, file storage, edge functions | EU (Ireland) |
| Cloudinary | Image storage and delivery | EU / US |
| OpenRouter | AI gateway | US |
| Supadata | YouTube transcript extraction for recipe import | EU / US |
| RevenueCat | Subscription management, receipt validation | US |
| Resend | Transactional e-mail (invitations) | US |
| Sentry | Crash and error reporting | US |
| Cloudflare | Website and web-app hosting, CDN, DNS | Global (EU data centres) |
| Apple / Google | App distribution, in-app purchases, optional sign-in | Global |
We do not sell or rent your personal data, and we do not share it with advertisers.
7. International transfers
Some providers are located outside the EEA, in particular in the United States. For those transfers we rely on the EU Standard Contractual Clauses and, for participating US providers, the EU-US Data Privacy Framework. You can request details via [email protected].
8. How long we keep your data
| Data | Retention |
|---|---|
| Account, profile and content (recipes, photos, cookbooks, lists and weekmenus) | While your account is active; deleted within 30 days after account deletion (backups within a further 90 days) |
| Server logs and AI request logs | Up to 12 months, for abuse prevention |
| Crash reports (Sentry) | 90 days |
| Subscription records held by us | 7 years (Dutch tax retention obligation) |
| Support correspondence | 24 months after the case is closed |
9. Security
We use TLS in transit, encryption at rest, row-level security so users can only access their own and explicitly shared data, server-side receipt validation, AI requests proxied through an authenticated edge function (the client never holds AI keys), and least-privilege access. If a data breach is likely to pose a risk to your rights, we will notify the Dutch Data Protection Authority within 72 hours and inform you where the law requires it.
10. Your rights
If you are in the EU/EEA, UK or Switzerland, you have the rights of access, rectification, erasure, restriction, portability and objection, and you can withdraw consent at any time. You can lodge a complaint with the Autoriteit Persoonsgegevens or your local supervisory authority.
If you live elsewhere (including the United States), we honour equivalent requests for access, correction and deletion under your local law. We do not sell or share personal data for advertising, and we do not engage in targeted advertising or profiling.
How to exercise your rights: you can delete your account directly in the App (Profile → Settings → Delete my account). For access, export, correction or any other request, e-mail [email protected]. We respond within the statutory time limit (EU: one month, extendable for complex requests).
11. Children
The Service is not directed at children under 13 (16 in the EEA/UK). We do not knowingly collect children's data; if you believe a child has provided us data, contact [email protected] and we will delete it.
12. Changes to this Policy
We may update this Policy. For material changes we will update the date above, notify you in the App and, where appropriate, by e-mail at least 14 days in advance, and re-ask consent where the law requires it.
13. Contact
Fork & Spoon · KvK 42137788
Voorstraat 44, 5334 JV Velddriel, Netherlands
[email protected]