CookAI
Legal

Privacy Policy

Controller

The controller responsible for data processing on this website within the meaning of Art. 4(7) GDPR is:

«First name Last name»
«Street and house number»
«Postal code City»
Email: «contact@example.com»

No data protection officer has been appointed because the statutory requirements for doing so are not met.

Processing of photos

Uploaded photos are not stored. As part of the individual request, the image is sent to Anthropic as the AI provider for processing. It is not subsequently stored in file storage or in the database. Only the names of ingredients identified from the image are stored.

The legal basis is Art. 6(1)(b) GDPR: processing is necessary to provide the service you requested—identifying your food and creating recipes.

Please do not upload photos showing people, documents, or other content that is not relevant to identifying food.

Pseudonymous browser ID

On your first visit, CookAI generates a random ID and stores it in your browser's LocalStorage. The ID contains no personal information and is not derived from any device characteristics. However, it permanently identifies this browser profile and is therefore pseudonymous, not anonymous.

The ID serves two purposes: it limits the number of scans per browser (protecting against misuse and uncontrolled AI costs), and it makes it possible to measure whether the same person uses the app again. The legal basis is Art. 6(1)(f) GDPR; the legitimate interest lies in the technical protection of the service and in evaluating whether the product is used repeatedly at all.

If you clear this website's LocalStorage, a new ID will be generated on your next visit and the link to previous data will be lost.

Usage data and cost protection

CookAI stores technical usage events and scan metrics together with the pseudonymous browser ID or the associated scan. These include the names of ingredients initially identified, the ingredient names ultimately removed and added before recipe generation, and your answer about your intention to cook. The title, missing ingredients, cooking time, and recipe index are also stored for the rated recipe. If you reject a recipe, the reason you select from a fixed list is stored as well; there is no free-text field.

Ingredient names are also stored in a standardized form so that singulars, plurals, and synonyms are not counted separately during analysis. Purely technical deployment information is also stored for each scan: the AI model used, an identifier for the instruction provided to the model, the app version, and the environment. The legal basis is Art. 6(1)(f) GDPR; the legitimate interest lies in evaluating and improving an early product test.

To limit the number of scans, the IP address is processed exclusively in hashed form. Without the server-side secret, the hash cannot be traced back to the IP address. No IP addresses are stored in the event table. The legal basis is Art. 6(1)(f) GDPR (protection against misuse and uncontrolled costs).

No device, location, or fingerprinting data is collected, in particular no user agent, screen size, or language setting.

Recipients of the data

We use the following service providers as processors pursuant to Art. 28 GDPR to operate the service:

  • Anthropic PBC, USA – processing the photo to identify ingredients and the confirmed ingredient list to create recipes.
  • Vercel Inc., USA – hosting and delivery of the application. Technically necessary connection data, including the IP address, is processed in the course of this.
  • Neon Inc. – operation of the PostgreSQL database, database region «EU/US».

According to Anthropic, API inputs and outputs are deleted by default within 30 days of receipt or generation. If content is flagged by Anthropic's automated safety systems, it may be retained for up to two years. Retained data is not used to train models without express permission. Because the photo is transmitted only as part of the request and is not stored by us, it may therefore be held by Anthropic—not by us—for up to 30 days.

Transfers to third countries

The providers named above process data in the USA, among other places. Transfers take place on the basis of standard contractual clauses under Art. 46(2)(c) GDPR or—where the respective provider is certified—on the basis of the adequacy decision for the EU–US Data Privacy Framework under Art. 45 GDPR. Despite these safeguards, access by US authorities cannot be ruled out entirely.

Retention periods

  • Usage events and scan metrics: deleted as soon as they are more than 90 days old. Deletion runs once a day, so records may remain for almost 91 days.
  • Hashed identifiers used for the scan limit: deleted after the 24-hour window expires.
  • Photo: not stored by us; according to Anthropic, deleted by Anthropic within 30 days.
  • Browser ID in LocalStorage: until you delete it in your browser.

Your rights

You have the following rights with respect to the controller:

  • Access to the data processed (Art. 15 GDPR)
  • Rectification of inaccurate data (Art. 16 GDPR)
  • Erasure (Art. 17 GDPR)
  • Restriction of processing (Art. 18 GDPR)
  • Data portability (Art. 20 GDPR)
  • Objection to processing based on Art. 6(1)(f) GDPR (Art. 21 GDPR)

Important when exercising these rights: we do not store any data that enables us to identify you as a person. Without the pseudonymous browser ID, we therefore cannot associate your data with you (Art. 11 GDPR). If you wish to exercise your rights, please provide us with the ID stored in LocalStorage; it begins withsession_.

Regardless of this, you have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The competent authority is the «competent supervisory authority of the federal state».

Provision of data

Use of CookAI is voluntary. You are under no statutory or contractual obligation to provide data. However, the app cannot generate recipes without a photo and without transmitting the identified ingredients.

Automated decision-making

No automated decision-making, including profiling, that produces legal effects or similarly significantly affects you takes place within the meaning of Art. 22 GDPR. Recipe suggestions are non-binding.

Tracker

CookAI does not use advertising trackers or third-party analytics services.

Last updated: «DD Month YYYY»

Legal NoticePrivacy Policy