This Privacy Policy explains how Palit ("we," "us," "our," or the "App") collects, uses, shares, and protects your information when you use our mobile application and related services. By using the App, you agree to the practices described in this policy.
If you have questions, contact us at support@cookonpalit.com.
1. Information We Collect
a. Account Information
When you create an account, you sign in with Google Sign-In (there is no separate email-and-password sign-up). We collect:
- Username (required)
- Full name (required)
- Email address (required for the account — Google shares your email with us as part of authentication, and it is stored in our authentication system)
- Phone number (optional — only collected if you choose to add one; used only to match friends already on the App)
- Profile photo (optional — you may upload one, or we may receive a profile photo URL from Google and store it as your initial avatar)
- Bio (optional — you can add a short bio later in Edit Profile)
On the profile-confirmation screen, email and phone are labeled optional. That optional email/phone is stored privately for Find Friends matching and is separate from the email Google already provided for sign-in. You can leave those matching fields blank.
If you sign in using Google Sign-In, we receive basic profile information (such as your name, email address, and profile photo) from Google as part of the authentication process — Google does not share your phone number, so that field remains empty unless you add it yourself in the App. We do not receive or store your Google password.
b. Contacts (Find Friends)
If you choose to use the "Find Friends" feature (during onboarding or later in Settings), we will ask for permission to access your device's contacts (on iOS, via Apple's Contacts permission). We use this information solely to match your contacts against existing users of the App so we can suggest people you may know. You can decline this permission and still use the App; declining will simply disable the friend-suggestion feature.
How matching works: the App reads email addresses and phone numbers from your contacts on the device, normalizes them, and sends those identifiers to a backend function that compares them against emails and phone numbers that other users have optionally saved on their own accounts. Names, postal addresses, and the rest of the contact card are not sent. We do not hash the identifiers on the device, and we do not store your full contact list on our servers. The matching request is processed to return matching public profiles (username, name, and avatar) and is not saved as a contact book. We do not share your contacts with third parties for advertising purposes.
Separately, if you add your own email or phone number on your profile, we store those values so that other people who have you in their contacts can find you. That row is visible only to your account (it is not shown on your public profile).
c. Photos
If you choose to upload a profile photo, a recipe cover image, or a photo of something you cooked, we will request permission to access your device's photo library (on iOS, via Apple's Photos permission). Importing a recipe from a photo of handwritten notes, a printed page, or a screenshot also uses the photo library, and you can optionally take a new photo with the camera (on iOS, via Apple's Camera permission).
Photos you upload are stored in Supabase Storage in public buckets (avatars for profile photos, recipe-covers for recipe images, and activity-photos for cook photos) and are visible to other users of the App. The App does not currently offer separate per-post privacy settings; usernames, profile photos, recipes, cook logs, and comments are generally readable by other users. You can hide a cook from the feed without deleting it by turning off "Post to your feed" when you edit that cook.
A photo used only to import a recipe (camera or library) is sent to our recipe-extraction service for processing and is not kept as a recipe cover unless you later upload one yourself.
d. Recipe Data
Users can add recipes in several ways: create them manually, import from a website URL, import from a photo, or paste structured text from an AI tool they use on their own.
When you submit a website URL, we fetch the linked webpage and parse it on our backend to extract:
- Recipe steps/instructions
- Ingredient lists
- Title, cook time, and servings when those are present in the page's structured recipe data
We do not copy photos or descriptive/marketing text from the source webpage into the App. After import, you review and edit the recipe before it is saved to your recipe book.
When you import from a photo, we extract the same kinds of recipe fields from the image (see Section 1(f)).
This parsed or authored content is stored in our database and associated with your account and recipe book. Because imported content originates from third-party websites or from images you provide, its accuracy and copyright status depend on the original source; see Section 6 (Third-Party Content) below.
We also store other content you create in the App, including cook logs (notes, ratings, written reviews, and optional photos), comments on cooks, recipes you save from other people, and who you follow.
e. Backend Infrastructure
We use Supabase as our backend provider for:
- Authentication (Google Sign-In sessions; your account email lives here)
- Postgres database (profiles, recipes, cook logs, comments, follows, and related data)
- Storage (profile photos, recipe covers, and cook photos)
- Edge Functions (contact matching, website recipe import, and photo recipe import)
We do not use Supabase Realtime for a user-facing feature. Account data, recipe data, and associated content you provide are stored on Supabase's servers, including your email address in the authentication system and any phone number you choose to add for friend matching. Supabase's own privacy and security practices govern how they process data on our behalf; see Supabase's Privacy Policy for details.
f. AI-Assisted Recipe Parsing
When you import a recipe from a photo, we use Anthropic's AI models (via API) on our backend to read the image and extract ingredients and cooking steps into a usable recipe format. The image you submitted is sent to Anthropic's API for this processing. We do not send your personal account information (name, email, phone number, contacts) to Anthropic as part of this process — only the recipe image and extraction instructions.
When you import a recipe from a website URL, we do not send that webpage to Anthropic. URL import uses our own parser (structured recipe data on the page, such as JSON-LD or HTML microdata).
The App also lets you copy a prompt and paste recipe text you obtained from an AI tool you use yourself; that paste is parsed on the device and is not sent to Anthropic by us.
See Anthropic's Privacy Policy and Commercial Terms for how they handle API data.
g. Push Notifications
During onboarding we may ask for permission to send notifications. The App does not currently send push notifications, and we do not collect or store a device push token. Friend-post alerts and the in-app Notifications tab are not implemented yet. Granting the system permission does not currently cause a token to be uploaded to us or to a third-party push provider (we do not use Expo's push service, OneSignal, or similar for delivery). You can disable the permission at any time in your device settings; that does not affect your ability to use the rest of the App.
h. Automatically Collected Information
The App does not currently include an analytics SDK (such as PostHog, Firebase Analytics, Mixpanel, or Amplitude) or a crash-reporting SDK (such as Sentry, Firebase Crashlytics, or Bugsnag). We do not collect device type, operating system version, app version, or crash logs through a third-party monitoring tool.
Our service providers (including Supabase and Google) may process technical information such as IP address transiently as part of handling a request (for example, to complete sign-in or serve the API). We do not have application code that stores IP addresses in our database.
i. Food Preferences
During onboarding we ask optional questions about cuisines you like, dietary needs (for example vegetarian, gluten free, or kosher), and cooking experience. Those answers are stored on your profile. They are not currently used to personalize the feed or to recommend content, and they are not sold or used for advertising.
2. How We Use Your Information
We use the information we collect to:
- Create and manage your account
- Enable core app features (posting, saving, and sharing recipes; logging cooks; comments; following other users)
- Suggest friends via contact matching (only if you opt in)
- Parse and structure recipe content you submit (website pages on our backend; photos via Anthropic)
- Provide customer support
- Maintain security and prevent abuse
- Improve and troubleshoot the App
We do not sell your personal information. We do not currently send push notifications.
3. How We Share Your Information
We share information only in the following circumstances:
- With other users: Your username, full name, profile photo, bio, public user number, recipes, cook logs (including photos, ratings, and reviews you save), comments, and follow relationships are visible to other users as intended by the App's social features. Your email address, phone number, and contact list are not shown to other users.
- With service providers: We share data with Supabase (authentication, database, file storage, and Edge Functions), Google (authentication, if you use Google Sign-In), and Anthropic (AI-based extraction when you import a recipe from a photo) solely to operate the App's core functionality. We do not use a third-party push-notification provider.
- For legal reasons: If required by law, regulation, legal process, or governmental request, or to protect the rights, property, or safety of our users or the public.
- Business transfers: If we are involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction; we will notify you of any such change.
We do not share your contacts list, phone number, or email address with other users or third parties for marketing purposes.
4. Your Choices and Controls
- Contacts permission: You can enable or disable contacts access at any time in your device settings.
- Photos permission: You can enable or disable photo library access at any time in your device settings.
- Camera permission: You can enable or disable camera access at any time in your device settings (used only if you import a recipe by taking a photo).
- Notifications permission: You can enable or disable notifications in your device settings. The App does not currently send notifications even if this is enabled.
- Account information: You can update your username, name, optional matching email, phone number, bio, or profile photo in Edit Profile.
- Delete a cook post: You can permanently delete a cook you logged (the photo, ratings, review, likes, and comments on that cook). The recipe stays on your shelf.
- Delete a recipe: If you created the recipe (or imported one that has no other author), you can permanently delete it from the edit-recipe screen. That removes the shared recipe, including other people's saved copies and cooks on that recipe.
- Unsave a recipe: If you saved someone else's recipe, you can remove it from your shelf without deleting the original.
- Account deletion: The App does not currently include an in-app "delete my account" button. You can request deletion of your account and associated data by contacting us at support@cookonpalit.com. We will process that request within a reasonable period, except where retention is required by law. See Section 5 for what deletion covers.
5. Data Retention
We retain your account and recipe data for as long as your account remains active.
Content you delete in the App is removed immediately (no undo window):
- Delete a cook post removes that cook only (photo, ratings, review, likes, comments). The recipe stays, including on other people's shelves.
- Delete a recipe (available to the author, or to a book owner of an imported recipe with no author) deletes the shared recipe row. Because everyone points at the same recipe, that also removes it from everyone's shelves and deletes all cooks on that recipe (then their likes and comments).
Account deletion is separate: there is no in-app control, so you request it by emailing support@cookonpalit.com. When we process that request we delete the authentication account. That removes your profile, private contact-matching row (email/phone), your cook logs, likes, comments, follow relationships, and your own shelf entries. Recipes you authored that nobody else has saved or cooked are deleted. Recipes that other people still have on a shelf or have cooked are kept, with the author field cleared so they are no longer attributed to you. Uploaded files (profile photo, cook photos, and covers for recipes that are deleted) are removed when we process the request; covers for recipes we keep stay so other people's shelves still have an image. We do not currently store a push token, so there is none to delete. Recent profile searches are stored only on your device and are not in our database.
We may retain information where we are required to do so for legal or security purposes. If an account is banned for abuse, we may keep the email, phone, or Google account identifier needed to prevent a new signup.
6. Third-Party Content
Recipe content parsed from external links originates from third-party websites that we do not control. We are not responsible for the accuracy, legality, or copyright status of that third-party content. If you are a content owner and believe your material has been used improperly through the App, please contact us at support@cookonpalit.com.
7. Children's Privacy
The App is not intended for children under 13 (or the applicable minimum age in your jurisdiction). We do not knowingly collect personal information from children. Sign-up does not include an age gate or date-of-birth field. If we learn that we have collected information from a child without appropriate consent, we will delete it.
8. Data Security
We use reasonable administrative, technical, and physical safeguards to protect your information, including relying on Supabase's and Google's security infrastructure for authentication and data storage, and using HTTPS/TLS for API calls from the App. However, no method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
9. International Data Transfers
Your information may be processed and stored on servers located outside your country of residence, including in the United States, depending on where our service providers (Supabase, Google, Anthropic) operate their infrastructure.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy in the App or on our website, with a revised "Last updated" date.
11. Contact Us
If you have questions or requests regarding this Privacy Policy or your data, contact us at:
Palit
Email: support@cookonpalit.com