Data safety
Last updated 13 September 2026
Google Play shows a Data safety summary on every app's store listing. This page is the same information in full sentences, with the reasoning attached — the store's version has to fit in a card, and a card cannot explain why an app wants something.
On this page
The short version
- Your data is encrypted in transit.
- You can request that your data be deleted — and you do not have to ask us, the button is in the app.
- No data is shared with third parties for advertising. There are no advertising or analytics SDKs in RecipeGo.
- Nothing is sold.
What is collected
"Collected" means the data leaves your device and reaches our servers. Every row below is required for the app to do the job you opened it for; none of it is optional-but-encouraged.
| Data type | Collected | Why | Required |
|---|---|---|---|
| Email address | Yes | To create your account, sign you in, and send account email such as password resets | Required |
| Name | Yes | A display name shown in the app and used to greet you in email. You choose it; it can be anything | Optional |
| Photos | Yes | Photographs you import a recipe from, and photographs you add to a recipe | Optional |
| Health and fitness — dietary preferences and allergens | Yes | To flag allergens in a recipe and to suggest substitutions. Only what you enter yourself | Optional |
| App activity — your recipe library and in-app actions | Yes | Your recipes, notes, cook logs, lists and plans. This is the product: it is stored so it is on every device you sign in to | Required |
| App activity — search history | No | Searching your library happens against data already on our servers; the queries themselves are not stored | — |
| Web browsing — addresses you import | Yes | The specific address you paste or share to RecipeGo, so we can read the recipe at it and show you where it came from | Optional |
| Purchase history | Yes | Which plan you are on and what you have bought, so your entitlements are correct | Required for purchases |
On "web browsing". Google's category name makes this sound broader than it is. RecipeGo sees one address at the moment you deliberately paste or share it into the app. It has no access to your browser, your history, or any other page you visit.
What is shared, and with whom
"Shared" means data reaches another company. Under Google's definition, a service provider processing data on our behalf is not "sharing" — but we would rather list them than rely on that distinction, so this table includes everyone.
| Recipient | What reaches them | Purpose |
|---|---|---|
| Supabase | Everything listed above | Our database, accounts, file storage and server functions |
| Google (Gemini) | The content of an import you confirmed | Reading a page, photograph or text into a structured recipe |
| OpenAI | The content of an import you confirmed | Same, when the primary model is unavailable |
| Anthropic | The content of an import you confirmed | Same, for some import types |
| USDA FoodData Central | Ingredient names only | Nutrition lookup |
| Resend | Your email address and the message | Delivering account email |
| RevenueCat | An account identifier and purchase events | Managing subscriptions. No card details |
| Google Play | Your payment details | Taking payment. These go to Google and never to us |
Nothing above is for advertising, and none of it is sold. The AI providers are used under business terms that do not permit your content to be used to train their models. Our Privacy Policy covers this in more detail.
What is not collected
Listed because absence is worth stating as clearly as presence:
- Location — of any precision. The app never asks.
- Advertising ID or any other tracking identifier.
- Contacts, calendar, SMS or call logs.
- Audio or video. The app takes still photographs only. The microphone permission that the image picker would normally bring with it is explicitly removed from our app.
- Financial information. Card details go to Google Play; we never see them.
- Installed apps, or any behavioural analytics profile.
Security practices
- Encrypted in transit. Every connection between the app and our servers, and between our servers and the companies above, uses TLS.
- Encrypted at rest by our hosting provider.
- Passwords are never stored in a readable form — only as cryptographic hashes.
- Separation is enforced in the database, not just in the app. Row-level security means one account cannot read another's library even if the application layer asked it to.
- You can request deletion at Settings → Data & export in the app. The same screen exports everything as JSON first, which we recommend doing before you delete.
Permissions the app asks for
| Permission | When it is used |
|---|---|
| Camera | Only when you choose to photograph a cookbook page or recipe card |
| Photos | Only when you pick an existing picture to import or to add to a recipe |
| Notifications | Cook timers, so an alert reaches you with the app in the background |
| Internet | Syncing your library and importing recipes |
The app asks for each of the first three at the moment you first use the feature that needs it, not on launch, and declining leaves everything else working.