← Back
WhatToCook Privacy Policy
Last updated: 9 September 2026
This Privacy Policy explains how personal data is processed when you use the WhatToCook mobile application and related websites (together, the “Service”).
Controller
The controller of your personal data is Yuliia Mykytiuk, an individual publisher established in Portugal, reachable at support@what-to-cook-app.com.
Postal address: Praçeta dos Navegantes 11, Colares, 2705-293, Portugal.
If you have questions about this policy or wish to exercise your rights, contact support@what-to-cook-app.com.
1. Scope
This policy applies to the WhatToCook iOS and Android apps and any official WhatToCook website pages that link to this policy (including Privacy and Terms pages).
2. Data we process
Depending on how you use the Service, we may process:
Account and identity
- Email address and password (if you create an account with email)
- Display name
- Authentication identifiers from sign-in providers you choose (for example Apple or Google), as provided by those providers
App preferences and content you create
- Language preference
- Cuisine, diet, allergy, liked and disliked ingredient preferences
- Staple pantry items and fresh ingredients you enter
- Favorites and ratings (on device; some favorites may sync to our servers when you are signed in)
- Cook history stored on your device
- Optional custom meals you save on your device, including an optional photo you attach for display in “My meals”
- Household / family size setting
Purchases
- Subscription status and related entitlement records needed to provide Pro features
- Product identifiers and purchase / restore metadata from Apple App Store or Google Play (payment card details are processed by Apple or Google, not by WhatToCook)
Optional Pro features
- Photos you choose for ingredient detection (taken with the camera or selected via the system photo picker)
- Ingredient lists and preference context (including diet and allergy settings) sent to our servers to generate meal ideas with AI
On-device content (not uploaded as personal data by default)
- The optional “fact of the day” is bundled in the app, selected by calendar day, and does not require an account or send personal data to our servers
- Photos attached to your custom “My meals” recipes are stored on your device for display and are not uploaded to WhatToCook databases or file storage
Device and technical data
- Device type, operating system, app version
- Basic diagnostics needed to operate and secure the Service
- Push notification permission status and your preferred local notification time (notifications are scheduled locally on your device for inactivity reminders)
We do not require you to create an account to browse free catalog content on device. Some features (including Pro subscription binding and cloud sync of favorites) require an account.
Diet and allergy settings
You may enter diet and allergy preferences so the Service can filter or guide meal suggestions. These settings are processed to operate the Service. They are not medical records, and we do not verify their accuracy. The Service does not guarantee allergen-free or diet-compliant results (see our Terms of Use).
3. How we obtain data
- Directly from you (forms, settings, fridge ingredients, photos you choose to submit)
- Automatically from the app and your device (technical and permission status data)
- From Apple or Google when you purchase or restore a subscription
- From authentication providers when you choose Apple or Google sign-in
Photos and camera
- For gallery selection we use the operating system’s photo picker. The Service does not request broad photo-library access to browse your library. You choose a single image; only that image is provided to the app.
- Camera access is requested only if you take a photo with the in-app camera for ingredient detection.
4. Purposes and legal bases (GDPR)
We process personal data to:
Provide the Service (contract — Art. 6(1)(b) GDPR)
- Match meals to ingredients and preferences
- Deliver Pro AI meal generation and photo ingredient detection when subscribed
- Maintain your account, preferences, favorites, and subscription entitlement
Communicate about the Service (contract / legitimate interests — Art. 6(1)(b)/(f))
- Respond to support requests
- Send local push reminders you enable (you can turn these off in Settings or system settings)
Security, abuse prevention, and service integrity (legitimate interests — Art. 6(1)(f))
- Authenticate users, prevent fraud, enforce rate limits, protect AI endpoints
Legal obligations (Art. 6(1)(c))
- Keep records required by applicable tax, accounting, or consumer law
- Respond to lawful requests by authorities
Where we rely on legitimate interests, we balance those interests against your rights and expectations as a user of a consumer cooking app.
Where consent is required (for example camera or notification permissions, and the in-app confirmation before your first photo is sent for AI detection), we process that data based on your consent (Art. 6(1)(a)). You may withdraw consent by changing device or in-app permissions or by not using the relevant feature; withdrawing consent does not affect prior lawful processing.
5. AI and photo processing
If you use Pro AI features, relevant inputs are sent to our servers hosted with Supabase in the European Union. Our servers call Google Gemini through the paid Gemini API (or a successor model we configure) to generate outputs.
What we send
- For meal generation: fresh ingredients, staple items, diet preference, allergy and restriction lists, liked and disliked ingredients, cuisine preferences, mood, serving size, and language
- For photo ingredient detection: the image you submit and a short instruction to list visible ingredients
What we do not store (photo detection)
- We do not store ingredient-detection photos in WhatToCook databases or file storage after processing
- We do not retain full AI-generated recipe text in server logs
- We may retain limited AI request metadata (for example user ID, a summary of ingredients submitted, and number of meals generated) for security, abuse prevention, and service reliability, then delete or anonymize it
Custom meal photos (“My meals”)
- If you attach a photo to a custom meal, that image stays on your device so the meal can be shown in the app. It is not uploaded to our servers for storage as part of that feature.
Google Gemini (paid API)
We use Google’s paid Gemini API tier with an active Cloud billing account. Under Google’s Paid Services terms, Google does not use your prompts or responses (including images) to improve Google products. That processing is handled under the Google Cloud Data Processing Addendum, where Google acts as our processor for applicable content. Google’s own account, billing, and operational data may be processed under Google’s privacy terms. We do not use your content to train a public WhatToCook model, and we do not sell your photos.
Photo detection flow
When you submit a photo for ingredient detection, it is transmitted over HTTPS to our edge function and forwarded to Gemini for analysis. The app asks you to confirm before your first photo is sent for AI processing. The returned result is an ingredient list shown to you. Temporary processing or logging on Google’s side is governed by Google’s API terms and policies.
Accuracy and safety
AI outputs may be inaccurate or incomplete. Diet and allergy settings are used to filter or instruct suggestions but do not guarantee safety. Do not rely on the Service as medical, nutritional, or allergen-safe advice. Always verify ingredients, labels, and allergens yourself.
6. Sharing and processors
We do not sell your personal data.
We use service providers that process data on our instructions:
- Supabase (EU region) — authentication, database, and edge functions
- Google (paid Gemini API) — Pro AI generation and photo ingredient detection when you use those features
- Apple and Google — account sign-in (if chosen) and in-app subscription payment processing
- Hosting providers for the WhatToCook website and email for support@what-to-cook-app.com
These providers may process data in the EU/EEA or in other countries. Where transfers outside the EEA occur, we rely on appropriate safeguards such as Standard Contractual Clauses or the provider’s approved transfer mechanism.
We may disclose data if required by law, to protect rights and safety, or in connection with a merger, acquisition, or transfer of the Service (in which case we will continue to protect data as described here or give notice of changes).
7. Retention
- Account data: kept while your account is active; deleted when you delete your account in the app (see section 8), subject to limited legal retention needs
- Preferences, favorites, and similar account content: while the account remains, or until you delete them or your account
- On-device data (fresh ingredients for the day, cook history, custom meals and their local photos, local notification schedule): stored on your device and cleared when you delete your account in the app, clear app data, or uninstall the app
- Purchase / entitlement records on our servers: removed when your account is deleted; Apple or Google may retain billing records under their own policies
- AI request metadata: short-term retention for security and reliability, then deletion or anonymization; removed with your account when still linked to your user ID
- Support emails: retained as needed to resolve your request and for legitimate follow-up
8. Your rights and account deletion (EEA / UK and similar laws)
Subject to applicable law, you may request:
- Access to your personal data
- Rectification of inaccurate data
- Erasure (“right to be forgotten”)
- Restriction of processing
- Data portability
- Objection to processing based on legitimate interests
- Withdrawal of consent where processing is consent-based
In-app account deletion
You can permanently delete your account from Settings → Delete account while signed in. This deletes your authentication account and related server data we hold (including profile, synced favorites, AI request metadata linked to your account, and Pro entitlement records on our side) and clears WhatToCook data stored on that device.
Account deletion does not cancel an App Store or Google Play subscription. Manage or cancel billing in your Apple or Google account settings. Deleting the app without using Delete account also does not cancel a subscription.
You may also email support@what-to-cook-app.com to exercise your rights. We may need to verify your identity.
You may lodge a complaint with the Portuguese Data Protection Authority (CNPD) or your local supervisory authority in the EU/EEA.
9. Children
WhatToCook is not directed to children under 13, and we do not knowingly collect personal data from children under 13. Where a higher age of digital consent applies in your country, we do not knowingly collect data from children below that age. If you believe a child has provided personal data, contact support@what-to-cook-app.com and we will take appropriate steps.
10. Security
We use appropriate technical and organizational measures to protect personal data, including encrypted transport (HTTPS/TLS), access controls on backend systems, and limiting Pro AI access to entitled accounts. No method of transmission or storage is completely secure.
11. International users
The Service is operated from Portugal in the European Union. If you use the Service from outside the EEA, your data may be processed in the EU and in other countries where our processors operate.
12. Changes
We may update this Privacy Policy from time to time. The “Last updated” date will change when we do. Material changes will be indicated in the app or on the website where appropriate. Continued use after an update constitutes acceptance of the revised policy where permitted by law.
13. Contact
Email: support@what-to-cook-app.com
Subject line suggestion: “Privacy request”