Privacy Policy
The short version. CookDrop has no account and no login. The recipes you save are stored on your iPhone. When you import a recipe, the link, pasted text or photo you chose is sent to our import service, which reads it with the help of AI model providers and sends the recipe back; we do not keep the recipe content after that, apart from short-lived logs. The app sends usage events, error reports and masked session replays to PostHog under a random install id. Purchases are handled by Apple. If we add ad measurement from Meta or TikTok later, it will track you only if you allow it in the iOS prompt.
1. Who we are
CookDrop ("CookDrop", "we", "us", "our") is an iPhone app that saves recipes from social posts, websites, photos and pasted text, and helps you cook from them. It is developed and operated by an independent developer based in Canada. You can reach us at hello@cookdropapp.com.
This policy explains what the app can access on your device, what it stores, what leaves your phone and who receives it. The summary above is accurate on its own.
2. What the app accesses on your device
Photos and camera
When you import a recipe from a photo, CookDrop asks iOS for the photo you pick or for the camera. It sees only the photo you choose or take for that import, or the photo you add to a recipe yourself. It does not scan your photo library. You can change either permission in the iOS Settings app under Privacy & Security.
The share sheet and clipboard
When you share a post or page to CookDrop from another app, iOS hands the app the link or text you shared. When you paste a link or text into the app, the app reads what you pasted. It does not read your clipboard in the background.
Other apps
CookDrop checks whether Instagram, TikTok, Facebook, YouTube and Pinterest are installed so it can open them for you from the import tutorial and from a recipe's source link. It cannot see anything inside those apps, and it does not ask for your login to any of them.
3. What is stored, and where
Everything CookDrop keeps is stored in the app's own private area on your iPhone, in a local database. This includes:
- Your recipes: titles, ingredients, steps, servings, times, photos, tags, source links, nutrition estimates, and your notes, ratings and "cooked" marks.
- Your cookbooks, pinned recipes, meal plan and grocery list.
- Your preferences and progress: the answers you gave during setup (such as your cooking goals and when you usually cook), units, language, reminder time, and how many imports you have used this week.
- Whether CookDrop Plus is active on this device (see Purchases below).
We have no copy of your recipe library. It is protected by the same iOS sandbox and device encryption that protects the rest of your phone, and it is included in your device backup if you back up your iPhone (iCloud Backup or a computer). Deleting the app deletes all of it, and because there is no account, we cannot restore it for you.
4. Imports and the import service
Turning a reel, a web page or a photo into a recipe is done on our server, not on your phone. When you start an import, the app sends the import service:
- the link you shared or pasted, or
- the text you pasted, or
- the photo you chose or took,
together with the random install id described in section 8 and technical details such as the app version. As with any internet request, the server also sees your IP address.
The import service is hosted by Vercel (Vercel Inc., United States). For a link, it fetches the public page or post the link points to, the same way a browser would. It does not log in to any of your accounts and cannot see private posts. It then sends the page content, text or photo to AI model providers through OpenRouter (OpenRouter, Inc., United States), which read it and return the recipe in a structured form. The same service answers when you use "Calculate nutrition" or "Ask CookDrop" in CookDrop Plus: the recipe and your question are sent, and the answer comes back.
Ordering groceries
If you choose to order your grocery list online, the app sends the names and amounts of the items you selected to our server, which passes them to Instacart (Maplebear Inc., United States) to build a shopping page. The app then opens that page in the Instacart app or in your browser. We do not send Instacart your name, your email or your install id, and we never see what you buy, your address or your payment details: everything from that point on is between you and Instacart, under Instacart's own privacy policy. Nothing is sent to Instacart unless you tap the button.
We do not keep recipe content on the server beyond the time needed to process the request. Server logs, which can include the link, the install id, the IP address, timings and error details, are short-lived and are used to keep the service working and to stop abuse. We do not use what you import to train models. OpenRouter and the model providers process the content under their own terms; do not import text or photos that contain personal or confidential information.
5. What we do not collect
- We do not require an account, so we do not collect your name, email address, phone number or password.
- We do not receive your recipe library, cookbooks or meal plan.
- We do not collect your location or your contacts.
- We do not show ads in the app, and we do not sell personal information or give it to data brokers.
6. Purchases
CookDrop Plus is sold through Apple's App Store as an auto-renewing subscription (yearly or monthly). Apple processes the payment. We never see your payment card, billing address, or Apple ID password.
To unlock Plus, the app receives from Apple a signed record of your purchase: the product bought, its status, and when it renews or expires. This record is stored on your device and checked when the app opens. If you tap Restore purchases, Apple sends the same record again for the Apple ID signed in on the device.
Apple's handling of your payment information is described in Apple's Privacy Policy. Apple also gives us aggregated, anonymous sales reports that do not identify you.
7. Notifications
If you turn notifications on for CookDrop in iOS, the app can remind you to plan your meals and, if you start a free trial, remind you before it ends. These reminders are scheduled on your device by the app itself. CookDrop does not run a notification server and does not collect a push token. You can turn them off at any time in iOS Settings → Notifications → CookDrop.
8. Diagnostics and analytics
CookDrop sends us usage events so we can see which screens are used, where people stop, and whether imports work: for example "onboarding step", "import started", "import succeeded" with the kind of source (such as Instagram or a website), "recipe viewed", "paywall shown", "trial started", with the app version, iOS version, device model, language and the variant of any test the install is in. The answers you give during setup are sent as events too. Events carry a random install id that is created on your device and is not tied to your name, email, Apple ID or advertising identifier. We use PostHog (PostHog Inc., United States) to store and chart these events; PostHog acts as our processor and does not use the data for its own purposes.
If the app crashes or hits an error, an error report goes to the same PostHog project so we can fix it. A report contains the stack trace, the device model, iOS version, app version and the screens visited just before the error. We also record replays of how the app's screens were used in some sessions. In these recordings text fields and images are masked, so what you type and your photos are not visible; the app's own interface is. Apple may also share crash logs with us if you have opted in to "Share with App Developers" in iOS Settings → Privacy & Security → Analytics & Improvements; those reports are controlled by Apple and can be turned off in the same place.
9. Advertising and attribution partners
CookDrop shows no ads. We may pay for ads for CookDrop on Facebook, Instagram and TikTok, and to know which ads bring people to the app we may add measurement software from Meta (the Meta SDK) and from TikTok (the TikTok Business SDK) in a later version. At the effective date of this policy, that measurement is not switched on. We will update this section when it is.
What would be sent
When measurement is on, the app sends each partner a few events: that CookDrop was installed and opened, that a free trial started, and that a purchase was made (the product and price, never card details). Each event carries technical details about your device: model and iOS version, app version, language and time zone, IP address, the vendor identifier Apple assigns to our apps on your device (IDFV), whether you allowed tracking, and, only if you did, the advertising identifier (IDFA). Your recipes and what you import are never part of these events.
Your choices
Before anything can be linked to you across other companies' apps, iOS shows its "Allow tracking" prompt. Choose "Ask App Not to Track" and the app cannot read the advertising identifier. You can change the choice later in iOS Settings → Privacy & Security → Tracking, for CookDrop alone or for every app. Turning tracking off never limits what the app does. Separately, Apple's own attribution system (SKAdNetwork and AdAttributionKit) can tell an ad network that an ad led to an install; that signal carries no identifier for you or your device.
California and other US states
While measurement is on, sending device identifiers and events to Meta and TikTok can count as "sharing" personal information for cross-context behavioural advertising under California law. To opt out, choose "Ask App Not to Track" when iOS asks, or turn tracking off for CookDrop in iOS Settings. We do not knowingly sell or share the personal information of anyone under 16. Their policies: Meta, TikTok.
10. Support email
If you email hello@cookdropapp.com, we receive your email address and whatever you write, including any screenshots you attach. We use it only to answer you and to fix problems you report, and we keep it as long as needed for that. Our email is handled by an email service provider that processes messages on our behalf.
11. Retention and deletion
- App data stays on your device until you delete a recipe or delete the app. Deleting the app removes the local database completely.
- Import requests are processed and then discarded. Server logs are short-lived.
- Analytics events, error reports and session replays are kept in PostHog for as long as we need them to understand and fix the app, and are deleted or aggregated after that. They are keyed by the random install id; to have them deleted, write to us and we will tell you how to find your install id.
- Purchase records are held by Apple under your Apple ID for as long as Apple keeps them.
- Support emails are deleted when they are no longer needed to help you, unless we must keep them to meet a legal obligation.
12. Children
CookDrop is a general-audience app and is not directed at children under 13 (or the equivalent minimum age in your country). We do not knowingly collect personal information from children. If you think a child's data reached us or one of our partners through CookDrop, write to us and we will delete it or ask the partner to delete it.
13. Security
Your recipe library stays on your device, so its security depends mostly on your iPhone: the app's private storage is protected by the iOS sandbox and by device encryption when your phone is locked with a passcode. The app communicates with Apple (purchases and system services), our import service on Vercel, and PostHog, all over HTTPS. This website is served over HTTPS, sets no cookies, and loads no third-party resources.
14. Your rights
We hold very little personal information about you, and most of what the app keeps is on your phone, where you can view and delete it yourself. Where a law gives you rights over personal information we do hold (for example, a support email, or analytics events under your install id), you can ask us to access, correct, or delete it by writing to hello@cookdropapp.com. We will respond within 30 days.
- Canada. We handle personal information in accordance with the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial laws. You may complain to the Office of the Privacy Commissioner of Canada if you are not satisfied with our answer.
- European Economic Area, United Kingdom and Switzerland. Our legal bases are your consent (camera and photo access, notifications, and any ad measurement identifiers in section 9), performance of a contract (processing an import you asked for, unlocking a purchase you made), and our legitimate interest in answering support requests, keeping the app and the import service working, and understanding how the app is used. We have not appointed a data protection officer; the law does not require one for an operation of our size. You have the rights of access, rectification, erasure, restriction, portability and objection, and the right to lodge a complaint with your supervisory authority. Vercel, OpenRouter, the model providers and PostHog process data in the United States and elsewhere; transfers are covered by standard contractual clauses or the EU–US Data Privacy Framework.
- California and other US states. We do not sell personal information. Section 9 explains how ad measurement, if switched on, can count as "sharing" and how to opt out. You have the rights to know, delete and correct, and we do not discriminate against anyone for exercising them.
15. Changes to this policy
If we change this policy, we will post the new version here with a new effective date. If a change adds data collection, such as switching on ad measurement, the app will tell you before that version starts collecting it. Continued use of the app after a change means you accept the updated policy.
16. Contact
Questions about privacy, or anything else: hello@cookdropapp.com. We read every message.