Privacy Policy
Last Updated: 4 September 2026 · Effective Date: 4 September 2026
At a quiet counter, we respect your privacy. This Privacy Policy explains what personal information we collect, how we use it, and your rights in relation to it. We operate under the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
1. Information We Collect
Information you provide directly
- Account data: Your email address and optional display name when you register. Passwords are hashed and managed entirely by Google Firebase Authentication; we never see or store your plaintext password.
- Profile preferences: Your hemisphere/region, dietary preferences, household size, pantry exceptions, nutritional baseline (age, sex, weight, height, activity level), and onboarding responses.
- App content: Recipes you import, create, or edit; weekly Ledger plans; grocery lists; cook notes; and library organisation choices.
- Audio and visual inputs: If you use OCR, Snap-a-Meal, or Voice Import, you provide photos or temporary microphone audio. Audio is processed in-memory only and is never stored on our servers after transcription.
- Assistant conversations: If you use the Assistant chat, the messages you send and the replies you receive are saved to your own account so you can return to a conversation later. They are private to you, are never shown to other users, and are automatically deleted after 30 days. The one exception is if you choose to report a bad answer and separately agree to include the conversation: see 'Reporting a bad answer' below. See Section 5 for the commitment that they are also never used in any aggregated or commercial dataset.
Reporting a bad answer
If you rate an Assistant reply with a thumbs down, we receive the rating, the reason you chose, anything you typed in the report, and the reply itself. If, and only if, you separately agree to it, we also receive the messages in that conversation and a record of which of the Assistant’s tools it chose for them.
We do not receive your nutrition figures, your meal plan, your recipe library, or your grocery list, even when you have agreed to share the conversation. Those are stripped before the report leaves your device. You can withdraw your agreement at any time: the report window always shows your current choice, and switching it off there stops that report and any future report from including your conversation. Reports are used only to find and fix faults in the Assistant. They are never aggregated, licensed, sold, or used to train or evaluate a model, and they are deleted when you delete your account.
Information collected automatically
- Usage analytics: We log anonymised interaction events (e.g., features opened, import method used) via Google Firebase Analytics (GA4) to improve the Service. These events do not contain recipe content or personally identifiable information.
- Cooking analytics on creator recipes: When you cook a recipe published by a Partner Creator using Cook Mode, we log which steps you view and how long you spend on them, in addition to the planning and shopping interactions we already log for every recipe. We collect this so the recipe's creator can see where cooks get stuck and which steps need clearer instructions; it helps them improve the recipe for everyone. The timing data is derived and aggregated on your device before it reaches our servers. We do not attach any per-user analytics identifier to it server-side, so it cannot be traced back to your account once received. It is combined with the same interactions from other households before anyone outside our engineering team sees it.
- Crash reports: We use Sentry for error monitoring. Crash reports include device metadata (OS version, app version, device type) and an anonymised user identifier, but never recipe content or PII.
- Local storage and IndexedDB: The app stores session state, offline recipe data (via Firestore offline cache), draft import data, and cover photos in your browser's local storage and IndexedDB. This data never leaves your device unless you explicitly save or sync it.
2. How We Use Your Information
- To provide and personalise the Service (meal planning, recipe import, nutrition targets, grocery lists).
- To manage your subscription entitlement via RevenueCat.
- To improve the app through anonymised analytics and crash reports.
- To operate shared features such as household plans and the Discover feed.
- To compile de-identified, aggregated datasets for market research (see Section 5).
- To send transactional communications (email verification, password reset); we do not send marketing emails unless you opt in.
3. Third-Party Processors
We share the minimum data necessary with the following third-party services to operate the Service. Each is bound by its own privacy commitments.
- Google Firebase (Auth, Firestore, Storage, Analytics, Hosting): Your account, profile, recipe library, and usage events are stored on Firebase infrastructure, operated by Google LLC in the United States.
- Google Cloud Vision and Gemini AI: When you use OCR, Snap-a-Meal, or Voice Import, the relevant photo, text, or audio is sent to Google's AI APIs for analysis. Audio is never retained after transcription.
- Sentry: Anonymised crash diagnostics. No recipe content or PII is included in error reports.
- RevenueCat: For a quiet counter PLUS subscribers, we share your anonymised Firebase UID and device platform identifier to verify and manage your subscription entitlement. We do not process or store your payment card details.
- Supadata: When you import a recipe from a social video (e.g., Instagram, TikTok, YouTube), the video URL is sent to Supadata to retrieve captions or transcripts.
- Open Food Facts: Barcode numbers and product search queries are sent to the Open Food Facts API to retrieve nutritional data. Open Food Facts is an open-database project operating under its own open licence.
- TheMealDB and Brave Search: In-app recipe search queries are routed through these services to find matching recipes on the web.
4. Shared Caches and Aggregate Features
- Import caches: Successful URL and video recipe imports are stored in a shared global cache to speed up the Service for all users. Your personal identity is never attached to cached import results.
- Discover feed counters: When you add or cook a recipe from the Discover feed, we increment aggregate counters ("times added," "times cooked") on that Creator's public analytics record. Your individual identity is never disclosed to Creators.
- Social graph: Your list of followed or muted creators is stored privately on your account. Creators cannot see who follows them, and no follower counts are displayed anywhere in the app.
- Creator and brand metrics: We compile aggregate metrics from planning, shopping, and cooking interactions with a creator's published recipes, such as how often a recipe is cooked again, how many households a recipe reaches, and (for Cook Mode) how households move through the steps. We compile these so creators can see what genuinely works in real kitchens and make their recipes better, and so brands can judge a partnership on real cooking rather than clicks. Creators, and brands running a paid deal with a creator, can see these metrics as statistics only. A statistic is only ever shown once at least approximately 25 households contribute to it; below that threshold, we show nothing rather than a number that could point back to a smaller group. No creator or brand ever sees your individual activity, your identity, or any list tied to your account.
5. Market Research and Data Commercialisation
To support the platform, we aggregate and de-identify behavioural and consumption data (such as aggregate ingredient trends, seasonal planning patterns, and grocery list compositions) and may licence or sell these macro-level insights to third parties such as food manufacturers and consumer research firms.
Our anonymisation commitment: Any data used for commercial purposes is structurally stripped of all PII (names, email addresses, household codes, exact locations). Data is grouped into large statistical cohorts, making individual re-identification technologically infeasible. No third party receives data from which they could identify you.
Assistant conversations are excluded entirely. What you type into the Assistant chat is never included in any aggregated dataset, cohort, market-research product, or dataset used to train or evaluate a model, in any form, anonymised or otherwise. This is a stricter commitment than the one above: the rest of this section describes data we may aggregate and licence, and your conversations are simply not part of it. This holds for a conversation you choose to send us in a bad-answer report as well: we read it to fix the fault, and it enters no dataset of any kind.
6. Data Storage, Security, and Retention
Your data is stored on Google Cloud Platform (Firebase) infrastructure, using industry-standard encryption in transit (TLS/HTTPS) and at rest. While we implement robust security controls, no internet transmission or electronic storage is completely secure.
Assistant conversations are kept for 30 days. Each conversation is automatically deleted 30 days after you last used it, whether or not you delete it yourself; you can also remove any conversation immediately from the chat history list. Deleting your account removes them along with everything else. A bad-answer report you have sent is kept separately from your chat history, so we can still act on it after the conversation itself has expired; deleting your account deletes those reports too.
We retain your personal data for as long as your account is active. If you delete your account, your Firebase profile, recipe library, nutrition history, Assistant conversations, and plan data are purged from active databases. Anonymised, de-identified aggregate data derived from your usage may be retained indefinitely as it cannot be traced back to you. Crash logs and analytics events are retained according to each processor's standard retention period (typically 90 days for Sentry; up to 14 months for GA4).
7. International Data Transfers
Your personal information is processed and stored on servers operated by Google LLC in the United States, and by other processors whose infrastructure may be located outside Australia. By using the Service, you consent to this transfer. We take reasonable steps to ensure overseas recipients handle your information consistently with the Australian Privacy Principles.
8. Your Rights and Choices
- Access: You can view your profile data and export a snapshot of your recipe library from within the app.
- Correction: You can update your profile preferences and nutritional baseline at any time in Profile settings.
- Connected apps: You can see every app or assistant you have connected, and disconnect any of them, under Profile, then Connected apps (see Section 11).
- Deletion: You may delete your account at any time via Profile, then Account settings. This permanently removes your personal data from our active systems.
- Complaints: If you believe we have mishandled your personal information, please contact us first at [email protected]. If we cannot resolve your concern, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
- Creator metrics visibility: If you are a Partner Creator, your aggregate metrics (Section 4) are visible to you and, where applicable, to a brand you are running a paid deal with, by default. You can turn off the version shown to brands at any time in Partner Studio, under My public profile, in the Directory visibility setting. Turning this off removes the published aggregate figures at the next nightly refresh; it does not affect the private metrics you can still see about your own recipes, and it does not affect any household's underlying app data, which was never identifiable to begin with.
9. Children's Privacy
The Service is not directed at children under 16. We do not knowingly collect personal information from anyone under 16. If you become aware that a child under 16 has provided us with personal information, please contact us at [email protected] and we will delete the account and data promptly.
10. Cookies and Local Storage
The Service is a Progressive Web App (PWA). We do not use third-party advertising cookies. The app uses browser-native storage mechanisms (localStorage and IndexedDB) to persist session state, offline data, and draft imports on your device. Firebase and Google Analytics may set first-party cookies for session management and anonymised analytics. You can clear this data at any time via your browser's storage settings.
11. Connected Apps and Assistants
With a quiet counter PLUS, you can connect an app or an AI assistant of your choosing (for example Claude or ChatGPT on your computer, or a fitness or coaching service) so that it can read your data and act on your behalf. Connecting is always your decision: it starts from the other app, you sign in to your account at a quiet counter on a consent screen we run, and you approve exactly what that app may do before it can do anything.
What a connected app can be given. You approve some or all of these, in these words, and nothing beyond them:
- Read your saved recipes.
- Read your meal plan, kitchen stock and grocery list.
- Read your nutrition figures.
- Add and remove items on your grocery list.
- Schedule, move and remove meals on your plan.
- Save new recipes to your library.
- Log meals you have eaten.
A connected app never receives your email address, your password, your subscription or billing details, your Assistant conversations, or any other person's data. If you are in a shared household, a connection you approve acts as you in the shared plan, in the same way you can.
Once data leaves us, it is theirs to govern. What a connected app does with the data you let it read is covered by that app's own privacy policy, not this one. Please read it before you approve a connection.
You are in control. Every connection is listed in the app under Profile, Connected apps, with what it may do and when it last used that access. You can disconnect any of them there at any time; disconnection takes effect within a minute and stops all future access. It cannot recall data the app has already read. If your PLUS subscription lapses, connected apps lose access automatically and regain it if you resubscribe, without reconnecting.
What we keep about a connection. The name of the app, what you approved, when you connected it and when it last used its access, and a count of how often it does, so we can stop a misbehaving app. We never sell, licence, aggregate or use for market research anything about your connections or anything a connected app reads or writes, over and above the commitments in Section 5, which apply unchanged.
12. Changes to This Policy
If we make material changes to how we handle your data (especially regarding third-party sharing or commercialisation), we will notify you via an in-app modal that requires explicit review before you can continue using the Service. The "Last Updated" date at the top of this policy reflects the date of the most recent revision.
Questions or concerns? Contact us at [email protected]