Last updated: April 18, 2026
We collect only the data necessary to provide you with the service. Specifically: email address (for your account and communications); password (stored exclusively in encrypted hash form); name or display name (optional); avatar image (optional); saved recipes, including title, ingredients, steps, personal notes, tags, times, and servings; images uploaded for recipes; screenshots or photos used for OCR import; original links of imported recipes; consent data (acceptance date and version of Terms and Privacy Policy); essential technical data such as IP address and browser type, collected automatically from server logs.
We use your data exclusively to: create and manage your account; save, organize, and display your recipes; allow you to import recipes from links and screenshots; personalize your profile (name and avatar); ensure the security of the service and prevent abuse; improve product functionality. We do not use your data for advertising profiling, we do not sell it, and we do not share it for marketing purposes.
When you upload screenshots or photos to import a recipe, StashRecipe uses optical character recognition (OCR) to extract ingredients and steps. Images used exclusively as OCR input are processed to extract text and are not permanently retained as separate files, unless you choose to use an image as a recipe photo or avatar. In that case, the image is saved as part of your content.
Your data is stored in a PostgreSQL database managed by Supabase. Uploaded images (recipes and avatars) are stored on Supabase Storage. The application is hosted and deployed via Vercel. These services may process data on servers located in the European Union or the United States, in compliance with applicable data protection regulations.
StashRecipe uses a single technical session cookie, strictly necessary to maintain authentication. We do not use profiling, tracking, or marketing cookies. We do not use third-party analytics tools.
We do not sell your personal data. We do not share your data with third parties for commercial purposes. We may share data only when strictly necessary for the operation of the service (e.g., the hosting provider) or when required by law by a competent authority.
StashRecipe uses the following third-party services: Vercel for application hosting and deployment; Supabase for the PostgreSQL database and image storage; Brevo for sending transactional emails related to your account (such as password reset). These providers were chosen for their data protection guarantees. If we change the services used, we will update this Policy.
We take reasonable measures to protect your data: passwords are stored exclusively as cryptographic hashes (bcrypt); sessions use signed tokens (JWT); communications use encrypted connections (HTTPS in production). No system is completely immune to risks. We cannot guarantee absolute security, but we are committed to following best practices and acting promptly in case of issues.
Your data is retained as long as your account is active and for as long as necessary to provide the service. When you delete your account, all your data — including recipes, images, notes, and personal information — is permanently and irreversibly removed. Technical server logs may be retained for a limited period for security and diagnostic purposes.
You have the right to: access your personal data at any time through the application; modify your information (name, avatar) from the profile page; export your recipes (planned for future versions); delete your account and all associated data at any time; withdraw consent by contacting us or deleting your account. To exercise your rights, you can use the app's features or contact us at the address listed below.
You can delete your account from the application's profile page. Deletion is permanent and results in the irreversible removal of: profile data (email, name, avatar); all saved recipes with ingredients, steps, notes, and tags; all uploaded images; consent data. This action cannot be undone. We do not keep individual backups of user data after deletion.
We may update this Privacy Policy to reflect changes in the service, infrastructure, or for legal reasons. In the event of significant changes, we will notify you via email or through an in-app notice. The current version is always available on this page.
For questions, requests, or reports related to privacy and the processing of your data, you can reach us at: mirproductit@gmail.com. We will do our best to respond within a reasonable time.
Version: privacy_v1_beta