Privacy Policy
Last updated: July 2025
1. Who we are
RecipeVault (“we”, “our”, “us”) is operated by CXS Technology. If you have questions about this policy, contact us at privacy@cxstechnology.com.
2. What we collect
- Account data — email address and password hash (stored securely by Supabase Auth).
- Profile data — display name, avatar image, dietary preferences, and cooking preferences you optionally provide.
- Recipe data — recipes, ingredients, steps, and meal plans you create or import.
- Usage data — page views, feature interactions, and error reports used to improve the service.
- Payment data — subscription billing is handled by Stripe. We never store card numbers.
3. How we use your data
- To provide and improve the RecipeVault service.
- To process payments and manage subscriptions.
- To power AI features (OCR, recipe generation, ingredient substitutions) using third-party AI providers (Anthropic, Groq).
- To send transactional emails (password reset, subscription receipts).
- To detect and prevent abuse.
We do not sell your personal data to third parties.
4. Third-party services
We use the following third-party services to operate RecipeVault:
- Supabase — database, authentication, and file storage.
- Stripe — payment processing.
- Anthropic / Groq — AI recipe extraction and generation. Recipe images and text are sent to these providers when you use AI features.
- Edamam — nutrition analysis (ingredients sent when you use the nutrition feature).
- MeiliSearch — search indexing (recipe metadata only, no personal data).
5. Cookies
We use only essential cookies: session cookies required for authentication and a preference cookie to remember your cookie consent. We do not use advertising or tracking cookies.
6. Data retention
Your data is retained for as long as your account is active. You may delete your account and all associated data at any time from the settings page. We retain anonymized usage statistics after deletion.
7. Your rights
Depending on your jurisdiction, you may have the right to access, correct, port, or delete your personal data. Email privacy@cxstechnology.com to exercise these rights.
8. Security
Data is encrypted in transit (TLS) and at rest. Authentication tokens are stored securely. We use row-level security in our database to ensure users can only access their own data.
9. Changes to this policy
We may update this policy from time to time. Significant changes will be notified via email or an in-app banner. Continued use of the service after changes constitutes acceptance.