Privacy Policy
Last updated August 4, 2026
CookRight is made by 8x Social. This policy describes what we collect when you use the CookRight app and cookright.app, why we collect it, and how to get rid of it. The short version: we collect what the product needs to work, some of it is sensitive and we treat it that way, we sell none of it, and you can erase all of it in one action.
What we collect
- Your email address — used to sign you in with a one-time code. There are no passwords.
- Your household's eater profiles — the names or labels you give them, an age bracket (never a birthdate), allergies, diets and other food rules, dislikes, goals, and a portion size (never a body weight).
- Your dinners — generated recipes, the ones you save, and cook outcomes, plus the lightweight preferences the app learns from your answers.
- Subscription status — your plan (for example trial or paid) and a coarse country code. Payment itself is handled by Apple; we never see card details.
- Usage and crash data — which screens are used and what breaks, so we can fix it. These events never contain profile names, allergy names or recipe content.
Health information, handled like it matters
Allergies and dietary restrictions are health-related information, and profiles in your household can describe children. We designed for that: children never sign in and have no accounts — a child's profile is data the household admin manages, like a name on a grocery list. Dietary data stays inside our infrastructure with one exception: generating a recipe requires sending the dietary rules for that request to OpenAI, our AI provider, which is the product working as described. Dietary data never appears in analytics, crash reports or marketing.
Who processes data for us
- Supabase — Hosts our database and sign-in. All household data lives here, protected by row-level security.
- OpenAI — Generates recipes. Receives the dietary rules and portion needs for a request — never your email.
- RevenueCat — Manages subscription state. Sees an anonymous user ID and purchase status; Apple handles payment, so no one here sees card details.
- PostHog — Product analytics. Events carry no profile names and no constraint names — a tier and a category at most.
- Sentry — Crash reporting. Reports are scrubbed of profile, constraint and recipe data before they leave our servers.
- Resend — Delivers the sign-in code email. Sees your email address and nothing else.
- Vercel — Hosts this site and our APIs, and derives the coarse country code we store (never a precise location).
What we never do
- We never sell your data, to anyone, for anything.
- We show no ads and share nothing with advertisers or data brokers.
- We never use your household's dietary data for marketing.
- We do not track you across other companies' apps or websites.
How long we keep it
As long as your account exists, so your household doesn't have to be rebuilt. Delete your account and everything goes with it.
Deleting your data
In the app: Settings → Delete account. On the web: the deletion page. Either way the purge is server-side and complete — your account, every eater profile, every constraint, every saved recipe, the learned preferences and the analytics rows go together, and it is not reversible.
Your rights
Wherever you live, we honour the strong version: ask us what we hold about you, ask for a copy, ask us to correct it, or delete it yourself at any time. Write to privacy@cookright.app and a person will answer.
Changes
If this policy changes in a way that matters, we'll say so in the app before the change applies — never silently.
Contact
privacy@cookright.app · 8x Social, operator of CookRight