Privacy
What we actually do with data
This is a description of the product, not a certification. Guest Scan still works without an account.
What Recipe Solver collects
Guests can scan, solve, and cook without an account. Guest cooking — pantry, people, needs, list, and what you cooked — lives on this device. We do not sell it.
If you sign in, we keep a Recipe Solver account: a user id, name, email, and profile photo from Google, X, or the email you typed. Sessions may also store a technical IP and browser string so the login stays valid. That is not used to advertise. You can see that identity on Account. A full kitchen download is not offered yet.
What stays on your device
Finished-dish photos stay on this device. Pantry, shopping list, household names, person notes, and allergen flags stay on this device. Signing out hides the signed-in kitchen on that phone; it does not upload it.
After you add the app to your home screen, the shelf, photos of food we ship, and this kitchen stay available when the network drops.
What is sent to our servers
Ingredient-label, nutrition-panel, and front-of-package photos are sent to our server so we can read the package and reconstruct a recipe. We do not keep a photo gallery of your kitchen. Typed ingredient lists take the same reconstruction path without a camera.
A barcode is sent to public package directories (Open Food Facts and UPCitemdb) so we can find a name and, when they have it, an ingredients list. We do not store barcodes in the activity log.
If you sign in, we may keep a first-party activity log for that kitchen — screens used, scans, Recipe Solves, and cooks — so we can improve the product. We do not store ingredient-label photos, family names, or dietary notes in that log.
How AI processing works
Catalog classics are written by us. Custom solves, photo reads, and pantry-tonight use Grok (xAI) on our server. You never connect ChatGPT, Claude, or paste an API key.
Label images and the ingredient text we extract may be sent to that model. Allergen flags you selected may be included so Allergen-aware versions can avoid them. Household names and private notes are not sent with those flags. We do not send your Recipe Solver account id to xAI.
We have not independently verified how long the model provider keeps inputs. Do not send secrets or medical records in a photo or note. Grok can be wrong — taste and read labels in your own kitchen.
Error monitoring
Speech in cook mode stays on the phone. A short error log of crashes and slow taps stays on this device. If crash reporting is configured, we also send a privacy-scrubbed error report (what broke, which screen, browser) to Sentry so we can fix bugs. We do not send ingredient-label photos, finished-dish photos, OCR text, pantry contents, allergen or health details, prompts, model replies, passwords, or sign-in tokens.
Analytics
Guest product analytics stay on this device unless we turn on a limited first-party session log. That session log is off today. When that log is on, we may record that this tab opened a public page, started a scan, was asked for a label, finished or failed a Solve, or began sign-in. The session id lives only in this tab and disappears when the tab closes. We do not use it to identify you, attach it to an account, or send it to HubSpot.
Signed-in activity from the website and a future iPhone app uses the same Recipe Solver account id and the same event names; we store the platform (web or iOS) so quality can be compared, not to fingerprint the device.
Accounts
An account is optional. It is a persistent identity for sign-in, future cross-device save, and Plus. It is not required for guest Scan, Solve, or Cook.
Google and X sign-in go through Grok's auth broker (auth.grok.me). The broker talks to Google or X; this app never sees those passwords or their access tokens. We keep only a Recipe Solver session (name, email, photo) so the kitchen can follow you to another phone later. Email-and-password accounts live in this app's database — not at Google, X, or the broker. Microsoft, Apple, and a standalone "Sign in with Grok" are not offered on the web.
If you sign in with an email, we may send a single kitchen-welcome message. That is a transactional note, not a newsletter. We do not sell your address. Creating an account does not sign you up for marketing.
Cross-device sync
If you sign in, we may later save a small account copy of Recipe Solves you chose to keep, cook-session scores, and progress — so a new phone can show that history. That copy is off until we turn account sync on.
We do not upload finished-dish photos, ingredient-label photos, pantry contents, household names, or allergen details unless you later opt in to those specifically. Guest kitchens stay on the device. Signing in does not silently upload a guest kitchen.
Photos
Camera and barcode: photos and codes are used only to identify a food so we can solve it, or to keep a finished-dish memory on this phone. Label photos go to our server for a read, then are not kept as a gallery. Finished-dish photos stay on this device.
Allergens and household data
Needs you tap stay on this phone. They are not a medical record we sell. Selected allergen flags may be sent with a reconstruction request so Allergen-aware versions can try to avoid them. Always verify ingredient labels before cooking.
Third-party services
Active today: xAI (reconstruction and label reads), Open Food Facts and UPCitemdb (barcode lookup), the Grok auth broker plus Google or X if you sign in that way, and our database/host. Sentry and welcome email (Resend) run only if those keys are configured. If you tap Shop and a grocery partner key is set, item names on the list may be sent to Instacart to open a cart. HubSpot is off. Sign in with Apple, App Store billing, and RevenueCat are not in this product yet.
Data retention
Account rows, signed-in activity, and entitlement rows last until you delete the account. We have not published a shorter activity-log window — that duration is not yet defined. Guest kitchens last on the device until you clear them. Anonymous session rows, if that log is ever turned on, are kept 14 days (raw) and 90 days (counts). Model-provider and Sentry retention are not controlled from this app.
Account deletion
Signed-in users can delete the Recipe Solver account from Account. That removes the user, sessions, provider accounts, identified activity, email log, entitlement row, and any cloud kitchen/sync rows for that id.
It does not automatically erase the kitchen still on this phone — you can keep cooking as a guest, or choose to clear this phone too. Anonymous counts that were never tied to you are not rebuilt into a person. Crash reports already sent to Sentry are not guaranteed to vanish.
If you join the Plus list, the address you type stays on this phone for now. We do not charge a card today. Family testing is not a paid subscription. Deleting your Recipe Solver account does not cancel an App Store subscription — there isn't one yet.
Children
Recipe Solver is a general-audience cooking tool. It is not directed at children under 13. We do not collect date of birth. This page is not a COPPA, GDPR, or HIPAA compliance claim.
Changes and contact
This privacy explanation is version 2026-08-25, effective August 25, 2026. Product questions and account deletion are on Account and Support. We will update this page when the behavior changes.
Privacy 2026-08-25 · Terms 2026-08-25 · Effective August 25, 2026