Privacy Policy
The short version. RecipeReel is a social app for sharing recipes. We collect what the app needs to work — your account details, what you post, who you follow and message — and nothing for advertising. We do not sell your data and do not run third-party ads or trackers. Photos are re-encoded on upload so location data embedded by your camera is removed. You can export or delete everything from inside the app. Questions: support@recipereel.app.
- Who is responsible
- What we collect and why
- Legal bases
- How long we keep it
- Who processes it for us
- Who else sees it
- Your rights
- Age requirement
- Security
- International transfers
- Changes to this policy
- Contact and complaints
1. Who is responsible
The data controller for RecipeReel is [FULL LEGAL NAME], [POSTAL ADDRESS], Romania (“we”, “us”). We are the single point of contact for users and authorities, including under the EU Digital Services Act: support@recipereel.app. We have not appointed a Data Protection Officer because we are not required to; privacy requests go to the same address.
2. What we collect and why
| Data | Why we need it | Source |
|---|---|---|
| Email address, username, password (stored only as a salted hash) | To create and secure your account, to send you security emails (verification codes, password changes, login alerts) and to let you sign in | You |
| Date of birth | To check that you are at least 16 (we keep the date to be able to show this later; it is never shown to other users) | You |
| Consent record (the Terms version you accepted and when) | To prove you agreed to the Terms and this Policy | You |
| Profile: bio, profile photo, favourite cuisines | Shown on your public profile | You |
| Recipes, photos, step-by-step instructions, ingredients, tags | The content you publish; shown to other users in feeds, search and on your profile | You |
| Comments, likes, saves and save collections, follows | The social features of the app; shown to other users as appropriate (your saves and collections are private to you) | You |
| Grocery lists and ingredients copied from recipes | Your personal shopping lists (private). The author of a recipe is shown only a count of how many people added its ingredients to a list, never who | You |
| Direct messages and message requests | Delivered to the people you write to; stored so both sides can read the conversation | You |
| Blocks and reports you make | To hide blocked users from you (and you from them) and to moderate reported content | You |
| Activity notifications (who liked, commented on or saved your recipes, replied to you, followed you) | Your in-app Activity inbox and, when enabled, push notifications | Generated from other users’ actions |
| Device push token and platform (iOS/Android) | To deliver push notifications to your phone, if you turn them on | Your device, with your permission |
| Login sessions: device type, sign-in time, last use | To show you where you are signed in and let you log out other devices | Your device |
| Technical data: IP address, user agent, request logs, error logs | To keep the service running, rate-limit abuse (for example password guessing), diagnose problems and investigate security incidents | Your device, automatically |
What we deliberately do not do. We do not use advertising SDKs, analytics trackers or fingerprinting. Photos you upload are re-encoded on our servers, which removes camera metadata such as GPS location before anyone else can see them. The original upload is deleted after processing.
3. Legal bases (GDPR Article 6)
- Performance of the contract (Art. 6(1)(b)) — everything needed to provide the app you signed up for: account, content, social features, messages, notifications.
- Legal obligation (Art. 6(1)(c)) — the age check, keeping the consent record, handling reports under the Digital Services Act, and responding to lawful requests.
- Legitimate interests (Art. 6(1)(f)) — security and abuse prevention (rate limiting, login lockout, security alert emails), moderation, and keeping technical logs for a short period. You can object to processing based on legitimate interests (see “Your rights”).
- Consent (Art. 6(1)(a)) — push notifications (asked for by your phone) and optional profile fields. You can withdraw consent at any time from Settings or your phone’s settings.
4. How long we keep it
| Data | Retention |
|---|---|
| Account and everything you posted | Until you delete your account. Deletion takes effect after a 14-day grace period during which you can change your mind; after that your data is erased from every part of the service. |
| Backups | Deleted data may persist in encrypted backups for up to 30 days, after which it is gone. |
| Activity notifications | 90 days. |
| Login sessions | 14 days of inactivity, or until you log the device out. |
| Email verification and password reset codes | 24 hours and 15 minutes respectively; only a hash of the code is stored. Spent and expired codes, and expired or revoked sign-in tokens, are deleted after 30 days. |
| Reports and moderation decisions | 12 months after the report is resolved, so that repeat abuse can be recognised and decisions can be reviewed. |
| Technical and security logs | 30 days. |
| Rate-limiting counters (IP address) | Seconds to minutes, in memory. |
When you delete your account, your comments and messages are removed too. Other people’s replies to your comments are removed with them; their own messages in a conversation with you remain visible to them.
5. Who processes it for us
We use a small number of service providers (“processors”) that act only on our instructions under a data processing agreement:
| Provider | What for | Where |
|---|---|---|
| Hetzner Online GmbH | Servers and database hosting | Germany (EU) |
| Cloudflare, Inc. | Domain, DNS, this website, photo storage (R2), email routing for our support addresses | EU data centres for storage; global network for delivery. Cloudflare is bound by the EU Standard Contractual Clauses and the EU–US Data Privacy Framework. |
| Resend, Inc. | Sending account emails (verification codes, security alerts) | USA, under Standard Contractual Clauses |
| Expo (650 Industries, Inc.) | Delivering push notifications to your phone | USA, under Standard Contractual Clauses. Receives only your device token and the notification text. |
| Apple Inc. / Google LLC | App distribution and the final delivery of push notifications (APNs / Firebase Cloud Messaging) | Per their own terms |
6. Who else sees your data
Other users see what you make public: your profile, your published recipes, your comments, your likes on recipes, and who you follow. People you message see your messages. Nobody sees your email address, date of birth, saved collections, grocery lists or the list of people you have blocked.
Authorities. We disclose data only when legally required to, and we tell you unless the law prevents it.
Nobody else. We do not sell, rent or share personal data with advertisers or data brokers.
7. Your rights
- Access and portability — Settings → Privacy → Export my data gives you a zip of everything we hold about you (JSON, plus links to your photos) within minutes; the link is also emailed to you and works for 24 hours.
- Rectification — edit your profile, recipes and email address in the app.
- Erasure — Settings → Delete account, or this page if you no longer have the app.
- Restriction and objection — email us; we will stop the processing you object to unless we have compelling grounds.
- Withdraw consent — turn off push notifications in Settings or on your phone.
- Complain — to your local data protection authority (see “Contact”).
We answer within one month. To protect your account we may ask you to confirm the request from the email address on it.
8. Age requirement
RecipeReel is for people aged 16 and over. We ask for your date of birth at sign-up and refuse younger accounts. If you believe someone under 16 has an account, tell us at abuse@recipereel.app and we will remove it.
9. Security
Passwords are stored as bcrypt hashes; sign-in tokens are short-lived and rotated; accounts lock briefly after repeated failed logins; all traffic is encrypted in transit (HTTPS); storage is encrypted at rest; we notify you by email when your password changes or a suspicious sign-in is detected. If a breach affects your data we will inform you and the supervisory authority as the GDPR requires.
10. International transfers
Your data is stored in the European Union. Where a provider processes data outside the EU (email delivery, push notifications), we rely on the EU Standard Contractual Clauses or an adequacy decision, and share only what that function needs.
11. Changes to this policy
Each version carries a date at the top. For material changes we will ask you to accept the new version in the app before continuing to use it; minor clarifications are simply published here.
12. Contact and complaints
Privacy questions and requests: support@recipereel.app.
Reports of illegal content, abuse or under-age users: abuse@recipereel.app.
You may lodge a complaint with the Romanian supervisory authority, Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP), B-dul G-ral. Gheorghe Magheru 28-30, Bucharest, dataprotection.ro, or with the authority of the EU country where you live.