Tasteze.
HomeSearchRecipesGroceryPlans
For creatorsSign inStart free
HomeSearchRecipesGroceryPlansFor creators
Sign inStart free
Privacy· Last updated · 2026-09-11

What we know about you, and why.

We collect what we need to make your kitchen work: your recipes, your pantry, your meal plans. Not much else. No third-party ad tracking, ever. If something here reads vaguely, write to privacy@tasteze.app and we’ll fix it.

Articles
  • № 00The summary
  • № 01What we collect
  • № 02How we use it
  • № 03Who sees it
  • № 04AI & your recipes
  • № 05Your rights
  • № 06The iOS app
  • № 07Storage & security
  • № 08Children
  • № 09Changes to this policy
  • № 10How to reach us
Table of contents
  • № 00The summary
  • № 01What we collect
  • № 02How we use it
  • № 03Who sees it
  • № 04AI & your recipes
  • № 05Your rights
  • № 06The iOS app
  • № 07Storage & security
  • № 08Children
  • № 09Changes to this policy
  • № 10How to reach us

The short version: we collect the recipes you save, the meals you plan, the pantry you track. We use it to make those features work for you, your household, and (if you opt in) the AI recipe generator. We don’t sell anything to advertisers and we don’t run third-party trackers. The long version is below, written in plain English, in articles you can skim.

Tasteze runs on the web and as an app on iPhone and iPad, and the two are not identical. Where they differ, this policy says so on the spot and marks the platform. If you’re here about the iOS app specifically, Article 06 collects every iOS answer in one place.

№ 00

The summary.

What we collect: the recipes you import or generate, the meal plans and shopping lists you build, the items in your pantry, your dietary profile, the household you share with, your subscription tier, and the device + analytics signals necessary to run the app reliably.

What we don’t: third-party advertising identifiers, contact lists, location histories, biometric data, or anything else you didn’t volunteer. Tasteze does not sell or rent personal information. There is no behavioural ad targeting. The iOS app declares no tracking in its App Store privacy manifest and contains no third-party analytics SDK.

Where it lives: on Supabase (PostgreSQL) in US-East, with row-level security on every table. Files (recipe photos, banners, cookbook drafts) live in Supabase Storage. The partner blog serves published posts publicly; everything else requires authentication.

Who else sees it: a short list of vendors that run specific features (payments, AI, recipe importing, email, hosting). Each is named in Article 03, with the platform it applies to. Search is not on that list: it runs on our own servers.

Deleting your account: always available, from inside either app, and never refused for any reason. Article 05 has the exact path for each platform.

What you can switch off: in the iOS app, app-performance diagnostics, at Settings → Privacy & Data → Share Diagnostics. Turning it off stops the collection and deletes anything still waiting to be sent from that device.

№ 01

What we collect.

We group your data into three buckets so it’s easy to reason about.

You give us this directly. Account email + password (or Apple or Google sign-in). Display name. Optional avatar. Saved recipes (title, ingredients, instructions, photos, nutrition you edited). Meal plans, shopping lists, pantry inventory, cookbooks. Dietary profile + allergens. Household membership. Notes and ratings you leave on recipes.

The platform generates this from your activity. Cooking-mode progress, mise en place plans, AI generation history, usage counters (how many imports this month, how many AI generations), suggestion-engine signals (which recipes you saved, which you cooked, which you ignored), and search queries.

What the system collects automatically on the web. Device type, browser, app version, IP address (used only to detect abuse, then truncated), session timestamps, product analytics (PostHog — events only, no cross-site identifiers).

What the system collects automatically in the iOS app. The iOS app runs no PostHog and no other third-party analytics SDK, sets no advertising identifier and does no tracking. What it does send, to Tasteze’s own servers and nowhere else, is an app-performance report:

  • normalised aggregates derived from Apple’s MetricKit: launch, hang, scroll and resume timing histograms;
  • how long a handful of named journeys took (opening the app, loading home, opening a recipe, searching, reading the cache, downloading and decoding an image);
  • counts of hangs and crashes, never a raw crash log, stack trace, symbol or call stack;
  • app version and build, OS version, and whether the device is an iPhone or iPad.

The app converts each MetricKit delivery into that summary in memory and throws away Apple’s raw payload before anything is written to disk. The report carries no account, household, device, installation, vendor or advertising identifier, no recipe, search, URL or free text. Your signed-in session authorises the upload and limits how often your account may send. That is why the app’s privacy manifest declares this data as Performance Data and Crash Data linked to you, for App Functionality and Analytics. The caller’s identity is not written into the stored report. We delete each report 90 days after we receive it.

You can turn this off. Settings → Privacy & Data → Share Diagnostics. Switching it off stops the collection and deletes anything still queued on that device. The choice belongs to your account, not to one installation: it follows you to every device you sign in on, and a device that has not heard the latest answer is corrected the next time it syncs. The app works exactly the same either way.

What the iOS app asks your device for. Only two things, and only when you use the feature that needs them:

  • Camera, to scan a product barcode while you shop, and to photograph a recipe so we can import it. iOS asks you first; the prompt reads “Tasteze uses the camera to scan recipes and product barcodes.”
  • Photos, read through Apple’s system photo picker, which runs outside the app. Because of that the app requests no photo-library permission at all and never gains access to your library: it receives only the specific image you chose.

The “Save to Tasteze” share extension. When you share a link to Tasteze from another app, the extension receives that link and sends it to our recipe-import endpoint. The shared link and your sign-in token travel through Tasteze’s own App Group and Keychain on your device. Nothing is read from the app you shared from beyond the item you shared.

What the iOS app never asks for. No location. No contacts. No microphone. No push notifications. No health, motion, calendar or Bluetooth access.

The decisions you record. When you answer the agreement prompts (terms, privacy, AI processing, diagnostics), we keep your answer and the date you gave it, against your account rather than a device. You can change any of them in Settings → Privacy & Data, and we keep the earlier answer so there is a record of what you agreed to at the time. We never assume an answer you haven’t given: a question you have not been asked is not a no.

Reports you file about someone else’s note. Reporting a note sends us the note, its author, your reason, and a copy of the note as it read when you reported it. We keep that copy deliberately, so the report still makes sense if the note is later edited or deleted. You can see the report you filed; the author cannot, and is not told who reported them.

Authors you block. We keep your block list so we can hide those authors’ notes from you. It is visible only to you, and the person you blocked is not told.

If you become a Tasteze partner, we additionally collect the answers you submitted on the application form, your voice interview transcript and AI-distilled voice profile, your blog posts and their generation history, and (if you connect a custom domain) the domain configuration.

№ 02

How we use it.

Seven things, full stop.

  • Run the kitchen features. Save recipes, build plans, track pantry, generate shopping lists, run cooking mode, sync your household.
  • Train the suggestion engine, but only on your own data, weighted to your preferences, never combined with anyone else’s profile.
  • Fulfil AI requests you initiate. Send the necessary inputs to Anthropic, OpenAI, xAI, or Google to import a recipe, generate a story, or render an image. We don’t send anything you didn’t ask for. Article 04 lists exactly what gets sent.
  • Process payments via RevenueCat (App Store + Stripe). We see your subscription tier; we don’t see card numbers.
  • Email you when something requires your attention: password reset, weekly summary if you opted in, partner-blog publish notifications. No marketing without explicit opt-in.
  • Make the iOS app faster and stop it crashing. The app-performance report described in Article 01 is used for two things and nothing else: keeping the app working (finding the launches, screens and scrolls that are slow, and the builds that hang or crash), and the release-over-release analytics that tell us whether a change helped. It is never used to profile you, to target anything at you, or to build a picture of what you cook. It cannot be, since the stored report holds no identifier and no content. Off by your choice, at Settings → Privacy & Data → Share Diagnostics.
  • Keep the lights on. Detect abuse, debug errors, monitor performance. We use the minimum signal necessary.
“We do not sell, rent, or trade personal information. There is no behavioural ad targeting on Tasteze. The recipes you save are yours.”
№ 03

Who sees it.

A short list of vendors, each with a specific job. We picked them because they’re contractually limited to processing data on our behalf and because they’re appropriate for the kind of data they touch.

Not all of them apply to both platforms, so each card says which. Most are reached by Tasteze’s own servers rather than by your device. Inside the iOS app itself there are exactly two third-party SDKs, Supabase (sign-in and session handling) and RevenueCat (subscriptions), and no analytics, attribution, advertising or crash- reporting SDK of any kind.

Supabase
Database + storage · US-East · iOS and web · SDK in the iOS app
PostgreSQL with row-level security. Files (photos, PDFs) on Storage. The iOS app links the supabase-swift SDK for sign-in and session handling.
Anthropic
AI text · Claude · US · iOS and web
Recipe generation, story drafting, ingredient analysis. Reached from our servers, never from your device. No training on your data.
OpenAI
AI images · US · iOS and web
Recipe photography. We send only the recipe + style inputs. Server-side only.
xAI
AI images + video · US · iOS and web
Recipe banners, partner hero imagery, video generation. Server-side only.
Google AI
AI images + voice · US · iOS and web
Imagen for stills, Veo for video, Gemini TTS for narration. Server-side only.
RevenueCat + Stripe
Payments · US · iOS and web · SDK in the iOS app
Subscription state. The iOS app links the RevenueCat purchases-ios SDK; the purchase itself is Apple’s. Stripe handles web checkout and partner payouts. Card data lives at Stripe or Apple, not with us.
Resend
Transactional email · US · iOS and web
Password resets, partner notifications, household invites. Sent from our servers.
PostHog
Analytics · US · Web only
Events only, no cross-site identifiers. Runs in the web app. There is no PostHog SDK in the iOS app and no third-party analytics of any kind in it.
Jina AI (an Elastic company)
Recipe import · page fetching · US · iOS and web
Receives the URL you ask us to import and returns the page. Server-side only. Does not train on what we send.
Vercel + Fly.io
Hosting · US/Global edge · iOS and web
Vercel serves the web and blog apps; Fly serves the API, the workers and the search index that the iOS app talks to. The search index runs on our own private Fly network with no public address.

We may also disclose information when required by law (a valid subpoena), to prevent fraud or abuse, or in connection with a sale or merger of the company, in which case the acquirer inherits this policy.

№ 04

AI & your recipes.

Tasteze is built around AI features. We want to be specific about what that means for the recipes you save.

What we send, and when. Nothing goes to an AI provider until you use a feature that needs one. When you do, what that feature works on is sent to a provider acting on Tasteze’s behalf:

  • the text of a recipe you write, paste or import;
  • a link you ask us to import, and the page we fetch from it. The link goes to a fetching service, Jina AI, which loads the page and returns it. That service receives the full address you gave us, including anything after the ?, and nothing else about you;
  • a photo or PDF you upload for us to read;
  • the food preferences, pantry contents and meal plans used to personalise a result. Taste matching, suggestion scoring and smart shopping read your saved data, so this is not limited to imports;
  • your allergens, dietary preferences and nutrition goals, sent with anything we generate or analyse for you, because a result that ignored them would be unsafe. If you have set a life stage, including pregnant or lactating, that is sent too;
  • a note you write on a recipe, with the recipe’s title, checked for offensive, harmful or off-topic content before it becomes visible. The check answers yes or no; your words are published exactly as you wrote them and are never rewritten;
  • pantry items and scanned products — the name and brand — so we can file them under the right category;
  • what is on a shopping list or meal plan, when you ask us to make a cover image for it;
  • a cookbook’s title, description, chapter plan, recipe titles and the author name printed on it, when its cover art and foreword are written.

Support investigations. If you raise a support ticket and we run an AI investigation on it, your ticket goes to a provider along with the part of your account you reported a problem with: your recent recipes, plans, pantry, lists, household or subscription, depending on the subject. We start that, not you, so we name it here rather than leave it to be inferred.

Not every AI feature leaves your device. On iPhone and iPad, the home screen greeting and the cookbook name suggested from a description you type are written by Apple’s on-device model and transmit nothing.

We send the inputs the feature needs and no more. Your email address, password and payment details are never part of an AI request. A support investigation does carry references to the things it is about (a household, a recipe, a plan) so we can find what you are describing.

Saying no, and what that does. The iOS app asks you once, before you start using it, whether AI processing is allowed; you can change the answer in Settings → Privacy & Data. We would rather be exact than flattering about what declining achieves: the iOS app enforces it, and it will tell you why it is not starting a feature. But it is not a platform-wide switch. It does not turn AI off on the web, or stop work that something other than your phone begins, such as a support investigation on a ticket you filed. To have AI processing stopped everywhere, email privacy@tasteze.app and we will do it by hand and tell you when it is done.

The AI providers don’t train on your data. Our contracts with Anthropic, OpenAI, xAI, and Google opt out of training on customer prompts and outputs. Inputs we send are processed for a single request and not retained for model improvement. Jina AI does not train on what we send it either.

How long a provider keeps what it receives. Beyond serving the request, each provider may hold an input briefly for abuse monitoring and legal compliance. That window is fixed by the provider’s own enterprise terms, which govern our account with them, and it differs between them, so rather than quote a single number that would be wrong for at least one of them, we point you at each provider’s published terms: Anthropic, OpenAI, xAI, and Google. If you want the exact figure that applies to your data under our agreements, email privacy@tasteze.app and we will tell you.

Tasteze does use your data to improve Tasteze. We log generation history (with the prompt, tokens used, cost, and your feedback) to debug and improve our prompts and suggestion engine. This stays inside the platform and is never shared externally. It lives as long as your account does, and is removed when you delete the account.

Public partner content is publicly published. If you’re a partner and you publish a blog post, that post is public, including the AI-generated narrative around your recipe. The partner blog renders it as soon as you click publish.

№ 05

Your rights.

Regardless of where you live, you have the following rights over your data. We honour them everywhere, whether or not the law where you live requires it.

  • Access. Email privacy@tasteze.app to request a full export of your library. We deliver it within 30 days as a structured JSON archive.
  • Correction. Edit anything you submitted directly in the app.
  • Deletion. You can delete your account yourself, from either platform. Both paths delete the same account, and both ask you to type your account email address to confirm.
    • iOS app · Settings → Personal Information → Delete Account.
    • Web · Settings → Profile & Preferences → Account → Danger Zone → Delete Account.
    Your recipes, meal plans, shopping lists, pantry and profile are removed, and any household you created passes to its longest-standing member (or is deleted if you were its only member). It happens immediately: the account and everything in it is removed in a single database transaction the moment you confirm, not flagged and queued for later. After that the only copies that can still exist are inside encrypted backups, which age out on our host’s own rotation; we never restore a deleted account from one.
    Deletion is never refused. There is no state your account can be in (a live subscription, a past purchase, an unpaid balance) that makes us keep it. If you bought or sold something, tax and accounting law requires us to keep the record of the transaction: the amount, the date, the payment reference. So we keep that and detach you from it. Your name, email, address and account are erased on the same schedule as everything else, and what remains in the ledger carries no identifier that leads back to you, not even the internal one your account used. You do not have to email us, cancel anything, or wait for a human.
  • Portability. The same export works for re-import elsewhere. Bring your library wherever you go.
  • Objection. Email privacy@tasteze.app to opt out of analytics, transactional summaries, or any specific processing.
  • Withdraw consent, in the iOS app. Turn off app-performance diagnostics at Settings → Privacy & Data → Share Diagnostics; that stops the collection immediately and deletes anything still queued on the device. Your subscription is Apple’s to cancel, not ours: Settings → Subscription → Manage subscription opens Apple’s own management sheet. Your second factor is a TOTP authenticator app, at Settings → Security. The iOS app does not use passkeys and has no OAuth-disconnect control.
  • Withdraw consent, on the web. Settings → Subscription → Manage Subscription opens the store that sold your plan, where you can cancel. Your second factor is a TOTP authenticator app, at Settings → Security. To opt out of web product analytics, email privacy@tasteze.app.

If you’re in the EU, UK, California, Colorado, Virginia, or another jurisdiction with extended privacy rights, the same controls apply. We’ve appointed a representative for GDPR inquiries; contact details are below.

№ 06

The iOS app.

Everything in this article also appears in its subject-matter article above. It is gathered here so that the iOS answer can be read in one pass, without reconstructing it from a policy written across two platforms.

Deleting your account. Settings → Personal Information → Delete Account, then type your account email to confirm. It always works: no subscription, purchase or balance can block it, and you never have to contact us to get it done. See Article 05 for exactly what is removed and how long it takes.

Diagnostics, and the switch that stops them. The app sends Tasteze how fast it launched, how long screens took, and how often it hung or crashed. No recipes, photos, searches or account details are included. Turning off Settings → Privacy & Data → Share Diagnostics stops the collection and deletes anything still waiting to be sent from that device. The answer is stored against your account and applies on every device you sign in on. Your phone keeps a copy so it knows what to do before it has spoken to us, but our record is the one that decides. The full field list, and what we do and don’t store, is in Article 01.

Permissions the app requests. Camera, for barcode scanning and photographing a recipe to import. That is the whole list. Photos are read through Apple’s system picker, so no photo-library permission is requested and the app never has access to your library. There is no location, contacts, microphone, push notification, health, motion, calendar or Bluetooth access.

Third-party code in the app. Two SDKs: Supabase (sign-in and session handling) and RevenueCat (subscriptions). No analytics SDK, no attribution SDK, no advertising SDK, no third-party crash reporter. The app’s privacy manifest declares no tracking, and it sets no advertising identifier. Every other vendor in Article 03 is reached by Tasteze’s servers, or applies to the web only.

Subscriptions. Bought through the App Store and managed by Apple. Tasteze cannot cancel an App Store subscription; Settings → Subscription → Manage subscription hands you to Apple’s own sheet. We see your entitlement tier, not your card.

The share extension. “Save to Tasteze” receives the link you shared and sends it to our recipe-import endpoint. The link and your sign-in token move through Tasteze’s own App Group and Keychain. Nothing else is read from the app you shared from.

AI, and the choice you are asked to make. What gets sent is described in Article 04 and is the same list as the web: recipe text, an imported link and the page behind it, an uploaded photo or PDF, your dietary profile, a note you write, pantry and product names, and the preferences, pantry and plans used to personalise a result. All of it goes from our servers, not from your device.

Two things differ on iOS. The app asks you first, before onboarding, whether AI processing is allowed, and you can change that in Settings → Privacy & Data. And two features never leave the phone: the home screen greeting and the cookbook name suggested from a description you type are written by Apple’s on-device model and transmit nothing.

Declining is enforced by this app. It will not start an AI feature, and it will tell you why. It does not switch AI off on the web, or stop work that something other than your phone begins. Article 04 has the detail, and how to have it applied everywhere.

Reporting a note, and blocking its author. Reporting sends us the note, its author, your reason, and a copy of the note as it read at the time, so the report survives the note being changed or deleted. You can see the report you filed; the author cannot, and is not told who reported them. Blocking is private to you and the person blocked is not told.

№ 07

Storage & security.

Your data lives in Supabase’s US-East region (Postgres + Storage). Encryption at rest is on by default. Connections are TLS 1.2+ from the client all the way to the database.

API keys for partner-side integrations live in an encrypted vault (AES-256-GCM) keyed by a master key that’s rotated quarterly. Admin access requires TOTP MFA in addition to the primary credential.

We retain account data while your account is active. If you cancel, your account stays as Free with all your recipes intact until you delete it. Deletion itself is immediate (one transaction, no soft-delete flag, no grace period), after which the only remaining copies live in encrypted backups that age out on our host’s rotation and are never used to bring an account back.

App-performance reports from the iOS app are kept on a fixed clock of their own: we delete each one 90 days after we receive it, and the daily aggregates it contributed to are deleted on the same 90-day boundary. Because those records hold no identifier, they are not tied to your account and are not affected by deleting it.

№ 08

Children.

Tasteze is not directed at children under 13 (or under 16 in the EU/UK). We don’t knowingly collect personal information from them. Households can include minors as members at the discretion of the household owner. The owner’s account is the legal counterparty. If you believe a minor has signed up directly, email us and we’ll investigate within 30 days.

№ 09

Changes to this policy.

When we change this policy, we update the date at the top and email everyone with an active account at least 30 days before the changes take effect (unless required to apply them sooner by law). Past versions of this policy are kept at /privacy/history so you can see what changed.

№ 10

How to reach us.

For privacy questions, data requests, or anything that reads unclearly above:

  • Email · privacy@tasteze.app
  • Mail · DND Media Group LLC · State of Florida, USA
  • EU representative · listed at /privacy/eu-rep

We respond to data requests within 30 days. If we need additional information to verify your identity, we’ll ask before we act.

Tasteze.

Tasteze Privacy Policy. Personal data, rights, and choices.

Product
  • Search
  • Recipes
  • Grocery
  • Meal plans
  • Cookbooks
  • Pricing
For creators
  • The blog network
  • The partner program
  • Publish a cookbook
  • Apply to publish
Legal
  • Terms
  • Privacy
  • privacy@tasteze.app
  • Contact
© 2026 DND Media Group LLC. All recipes belong to their authors.Privacy Policy