Introduction
This Privacy Policy describes how Karhucode (“we”, “us”) handles information when you use the Cookbook mobile application (“the App”). The App helps you manage recipes, shopping lists, menus, and related content.
By using the App, you agree to this policy. If you do not agree, please do not use the App.
Contact
For privacy questions or requests, contact us using the developer contact email shown on this app’s listing in the Google Play Store (Android) or the App Store (iOS).
Website: https://sites.google.com/view/karhucode/home/
1. Information the App processes
Account and profile (optional sign-in)
If you create an account or sign in, we use Supabase for authentication and backend services. This may include:
• Account identifiers (for example a user ID managed by Supabase).
• Information you provide for your profile, such as display name and profile image URL, stored in our database.
Recipe and app content
The App stores recipes, categories, tags, shopping lists, menus, and related data on your device (local database). If you use cloud sync (when available for your account), that content is also stored in our Supabase project so it can be synced between your devices.
Photos, camera, and gallery
The App may access your camera and photo library so you can attach images to recipes (for example recipe photos). With your permission:
• Images you choose are used inside the App (display, editing, optional upload).
• Text recognition (OCR) uses Google ML Kit on your device to read text from images you provide. Processing for that feature is designed to run on the device; see Google’s ML Kit terms at https://developers.google.com/ml-kit/terms
If you use cloud sync, recipe images you associate with synced recipes may be uploaded to our Supabase storage so they can appear on your other signed-in devices.
Content shared from other apps
If you share text or links into the App from another app (for example “Share” to Cookbook), the App receives that content so you can import or save it. It is handled according to how you use the App (for example saved locally and optionally synced if you use cloud sync).
Subscriptions and purchases
In-app purchases and subscriptions are processed by Google Play (on Android) and/or Apple (on iOS), together with RevenueCat, which helps us manage subscription status. We receive information needed to confirm your subscription tier (for example purchase status and identifiers linked to your account in our systems). We do not receive your full payment card details from the stores.
Subscriptions, plan features, and changes to what each plan includes are governed by our Terms of Service (https://sites.google.com/view/karhucode/terms-of-service), not only this Privacy Policy.
Optional AI-assisted recipe parsing
If you choose to use OpenAI and/or Google Gemini features, you may enter an API key in the App (or use configuration we document). In that case, recipe or import text you submit for parsing is sent from your device to OpenAI and/or Google according to the provider you selected. Those requests are governed by that provider’s privacy policy and terms, not only this policy. You can stop this by not enabling those features or by removing the API keys from the App.
App settings
Preferences and keys you save in the App (for example AI provider settings stored on the device) are kept in local storage on your device.
Technical data
Like most apps, the App and our service providers may process technical information needed to operate the service (for example device type, app version, crash or diagnostic data if you or we enable such tools). The exact items depend on what we configure in Supabase, RevenueCat, and the stores.
2. How we use information
We use the information above to:
• Provide, maintain, and improve the App.
• Authenticate you and sync your data when you use sign-in and cloud features.
• Show subscription options and enforce plan limits where applicable.
• Respond to your requests and comply with legal obligations.
We do not sell your personal information.
3. Legal bases (EEA/UK users)
If applicable law requires a “legal basis”, we rely on:
• Contract — to provide the App and features you request.
• Legitimate interests — to secure the service, fix issues, and improve the product, where not overridden by your rights.
• Consent — where we ask for permission (for example camera or photos), or where you voluntarily enable optional features such as third-party AI APIs.
4. Sharing with service providers
We use trusted processors to run the App, including:
• Supabase — authentication, database, and file storage for accounts and synced data.
• RevenueCat — subscription management and entitlements.
• Google Play / Apple — payment processing for in-app purchases.
• Google ML Kit — on-device text recognition from images you choose.
• OpenAI / Google — only if you enable optional AI parsing with your API keys or as documented in the App.
We share only what is needed for each service to function. Each provider has its own privacy policy.
5. Retention
We keep account and synced data while your account is active and as needed to provide the service. You may delete content in the App where the feature exists; synced copies may be removed according to our backend rules or when you ask us to delete your account (contact us via the developer email on the app store listing).
Local data on your device remains until you uninstall the App or clear app data.
6. Security
We use industry-standard practices appropriate to the nature of the service (for example encrypted connections to our backend). No method of transmission or storage is 100% secure.
7. Your rights
Depending on where you live, you may have rights to access, correct, delete, or export personal data, or to object to or restrict certain processing. To exercise these rights, contact us using the developer contact email on this app’s Google Play or App Store listing. You may also lodge a complaint with your local data protection authority.
8. Children
The App is not directed at children under 13 (or the minimum age required in your country). We do not knowingly collect personal information from children. If you believe we have, contact us via the developer email on the app store listing and we will delete it.
9. International transfers
If you are outside the country where our servers are located, your data may be processed in other countries. We use providers (such as Supabase) that offer appropriate safeguards where required by law.
10. Changes
We may update this Privacy Policy from time to time. We will post the new version on this page and update the “Last updated” date. Continued use of the App after changes means you accept the updated policy.
11. Third-party policies (reference)
Supabase Privacy: https://supabase.com/privacy
RevenueCat Privacy: https://www.revenuecat.com/privacy
Google Privacy Policy: https://policies.google.com/privacy (Play, ML Kit, Gemini as applicable)
OpenAI Privacy: https://openai.com/policies/privacy-policy (only if you use OpenAI from the App)