Legal
Privacy Policy
Last updated: 22 July 2026
Cupboardful ("Cupboardful", "we", "us") is a personal recipe binder, shopping list and meal-planning service. This policy explains what data we collect, why, how it's handled, and the choices and rights you have. We've written it in plain English rather than boilerplate.
In short: we don't run ads, we don't track you, we don't use third-party analytics, and we never sell your data. We only collect what we need to run the service you signed up for.
Who we are
Cupboardful is operated as an independent, sole-operator product. For any privacy question, or to exercise the rights below, contact us at privacy@cupboardful.com.
What we collect and why
Account information
When you register we collect your email address and a display name. We use these to create and secure your account, to sign you in, and to send you essential service emails (see below). Your password is stored only as a secure one-way hash (argon2) — we can't see it.
Your content
We store the content you create so we can provide the service and sync it across your devices: recipes, ingredients, cooking steps, recipe images, tags and ratings; shopping lists; meal plans; and your cook history. This content belongs to you.
Subscription & billing state
We store your subscription status (for example, whether you're on a free trial or an active plan, and renewal dates). Payment card details are handled entirely by Stripe, our payment processor — Cupboardful never sees or stores your card number. Stripe's handling of your payment information is governed by the Stripe Privacy Policy.
Sign-in with Google or Apple (optional)
If you choose to sign in with Google or Apple, we receive a basic identity token confirming your account and email so we can create or match your Cupboardful account. We don't receive your Google/Apple password, and we don't post anything or read your other data there.
API keys (optional)
If you create an API key to let your own tools or AI agents add recipes on your behalf, we store a hashed form of that key and a label you give it, scoped to your account. You can revoke a key at any time in Settings.
Optional error telemetry
Our backend may use Sentry for error tracking to help us find and fix bugs. This is configured to protect your privacy: personally-identifying information is not sent by default, request bodies are never captured, and authentication headers and cookies are scrubbed before anything is recorded. Our mobile apps do not embed any crash-reporting or analytics SDK.
Importing recipes from videos
If you import a recipe from a video link (for example TikTok, Instagram or YouTube), we send that public video's web address to specialist providers to read the recipe for you: ScrapeCreators and the YouTube Data API retrieve the video's public caption, description and — where available — its transcript, and Google Gemini reads that text to extract the ingredients and steps. If the recipe can't be read from the caption alone, the video's audio may be transcribed by Groq. Only the public video link and its own public text are shared for this — no information about you or your account is sent, and it happens only when you choose to import from a video.
What we don't do
- No advertising and no ad networks.
- No third-party analytics or cross-app/cross-site tracking.
- No selling, renting or sharing of your data with data brokers.
- No tracking cookies. Cookies and local storage are used only for authentication/session and to remember your interface preferences (such as dark mode and view settings).
Lawful basis (UK/EU users)
Where UK GDPR / EU GDPR applies, we rely on: contract — to provide the service you signed up for (your account and content); legitimate interests — to keep the service secure, working and free of bugs (including limited, PII-scrubbed error logging); and consent — where you optionally choose to use social sign-in. You can withdraw consent or object to processing by contacting us.
Processors & sub-processors
We use a small number of trusted providers to run the service. They process data only on our instructions:
- Railway — cloud hosting for our application, API and database.
- Stripe — subscription billing and payment processing.
- Sentry — optional backend error tracking (PII-scrubbed, as described above).
- Resend — delivery of transactional emails (for example account verification and password resets).
- Google and Apple — identity verification, only when you choose to sign in with them.
- ScrapeCreators — retrieving a public video's caption or transcript, only when you import a recipe from a TikTok, Instagram, or YouTube link.
- Google (Gemini and the YouTube Data API) — extracting recipe details from a video's caption or transcript, and retrieving public YouTube video details, only when you import a recipe from a video link.
- Groq — optional speech-to-text transcription of a video's audio, only when a recipe can't be read from the caption alone.
Emails we send
We send transactional emails required to run your account — for example email verification and password-reset links. We do not send marketing emails.
Data retention
We keep your account and content for as long as your account is active. If you delete your account, we delete your account and associated content. Backups and provider logs may persist for a short period before being overwritten in the ordinary course of operations. Limited error logs are retained only as long as useful for diagnosing issues.
Your rights
You can access and export your data — recipes and shopping lists can be exported from within the app (CSV, Markdown or plain text). You can edit or delete your content at any time, and you can delete your account from within the app, which removes your associated content. Depending on where you live, you may also have rights to rectification, restriction, portability and objection, and the right to lodge a complaint with your local data-protection authority (in the UK, the Information Commissioner's Office). To make any request, contact privacy@cupboardful.com.
Children
Cupboardful is not directed at children under 13 (or the minimum age of digital consent in your country), and we do not knowingly collect their data. If you believe a child has provided us with personal data, contact us and we will delete it.
International transfers
Our providers may process data in countries outside your own. Where that happens, we rely on those providers' appropriate safeguards (such as standard contractual clauses) for the transfer.
Changes to this policy
We may update this policy from time to time. When we do, we'll revise the "last updated" date above, and for material changes we'll take reasonable steps to let you know.
Contact
Questions about this policy or your data? Email privacy@cupboardful.com.