This Privacy Policy explains how SHARP SHUTTER PHOTOGRAPHY ("we," "us," or "our")
collects, uses, and protects information when you use CookwithFriends (the "App").
By using the App, you agree to the practices described here.
Privacy in one line: CookwithFriends works fully on your
device without an account. The App contains no advertising and no
third-party analytics or tracking SDKs. We do not sell your personal
information. Your recipes and other content stay on your device unless you
choose to sign in to sync them or to use an optional social or cloud feature.
1.Information We Collect
The App is designed to work on your device with a minimum of personal data. By
default, everything you create — your recipes, cook logs and their photos,
ratings and notes, comments, grocery lists, cooking groups, your encrypted
Family Secrets, your profile, your yearly cooking challenge, and your app
settings — is stored locally on your device and is only sent to
us if you choose to sign in to sync it or to use an optional social or cloud
feature.
On-device data (default). Recipes and their ingredients,
steps, source, and photos; cook logs with photos, star ratings, notes
("tweaks"), reactions, and comments; grocery lists and trip/meal plans;
cooking groups; your encrypted Family Secrets; your profile; your yearly
challenge; and your preferences (units, theme, view mode). This lives in your
device's local app storage and does not leave the device unless you enable a
feature below.
Account information you provide (only if you sign in). Signing
in is optional and handled by our authentication provider (Google Firebase).
Depending on the method you choose, we collect: your email
address (Email/Password, Google, or Apple sign-in), a display
name and avatar (from Google, if used), or your phone
number (only if you choose phone sign-in). With Sign in with
Apple, you may choose to hide your email address, in which case Apple
provides only a private relay address. You may also sign in as a
Guest (anonymous) account, which creates an account with no
personal identifier. We use this to create your account, sign you in, and keep
your account secure.
Synced app data (only if you sign in). So your kitchen follows
you across devices, the data you choose to sync is stored in a single document
tied to your account (users/{your id}): your recipes, cook
logs, grocery lists, cooking groups, encrypted Family Secrets, profile, yearly
challenge, settings, and view mode. It is protected by per-user security rules
so that only your signed-in account (or, for support, an administrator) can
read it.
Photos. Recipe and cook-log images you capture with your
camera or import from your library are used as the dish photos shown in the
App. They are stored on your device and, if you enable sync or sharing, travel
with the associated recipe or cook log.
Social & sharing data (only if you use those features). If
you add friends or share content, we store: a small public
profile (your display name, avatar, an @handle, and a
short friend code) that other signed-in users can look up to add you — this
profile also includes a lowercase copy of your display name so friends can
find you by name search, and a one-way cryptographic
hash of your email address so someone who already knows your
email can find you; your email address itself is never published or
readable by other users; a
friendship record for each connection; a group
you create (its name, optional description, member list, shared recipes, and
challenge); and, for a shared grocery list, the list's contents
and the set of people you shared it with, so it can sync live to those members.
Your public profile never contains your private data (settings, Family Secrets,
or tokens).
Messages & chats (only if you message someone). If you use
in-app Messages (direct messages to a friend or a group chat),
we store the conversation and its messages — the text you send, any
recipe cards you share into a chat (which include the recipe's
name, details, and photo), and any meal plans you share (day
labels and meal names for the week) — in the cloud so they can be delivered to
the other members of that conversation. Each conversation is readable only by its members.
Messages you send are visible to, and may be retained by, the people you send
them to. A per-device record of which conversations you have read stays on your
device and is not synced.
Recipe photo search (only if you use "Find a photo"). If you ask
the App to find a cover photo for a recipe that has none, the App sends your
search terms (typically the recipe's name) to third-party
stock-photo services (Pexels, TheMealDB, and Openverse) to fetch matching images
for you to choose from. We do not send your account details; the chosen image's
web address and a photographer credit are then saved with the recipe.
Nutrition estimates (only if calorie figures are shown). To
estimate calories for a recipe, the App first uses a built-in offline food table,
and for ingredients it does not recognise it sends the ingredient
name (not your identity) to free nutrition databases (USDA FoodData
Central, Open Food Facts, and wger). The results are cached on your device so the
same ingredient is not looked up again. All figures are labelled estimates.
Moderation reports. If you report a piece of content, we store
the report (what was reported, that you reported it, and a timestamp) so the
App owner can review it. Reports are not readable by other users.
Push notification token (only if you enable notifications). If
you allow notifications, we store the push token your device's operating system
issues so our service can deliver notifications to your device. It is removed
when you sign out or delete your account.
Purchases & subscriptions (only if you buy Premium). In-app
purchases are processed by Apple and validated through
RevenueCat. We and RevenueCat receive purchase and entitlement
information (such as which product you bought and whether Premium is active) —
we never receive your full payment-card details; Apple handles
payment. A complimentary-access flag may also be recorded on your account if we
grant you free access.
Sous Sprout AI assistant (Premium+ features). For free users,
the in-app assistant answers with local, rule-based replies and nothing leaves
your device. When you use a Premium+ AI feature — asking Sous
Sprout a question, simplifying or translating a recipe, AI nutrition estimates,
AI photo/video recipe import, or pantry cooking ideas — the content needed to
answer is sent to our AI service and processed by Anthropic's Claude
API to generate the reply. Depending on the feature, this can include:
the recipe you're viewing (title, ingredients, steps), your question and recent
assistant conversation, a photo you ask it to read, a video link's public
caption, your pantry item names, and — if you have set one — your
dietary preferences (see below). Requests are tied to your
account for rate-limiting and abuse prevention; we do not use this content for
advertising, and Family Secrets are never sent. As a legacy option, if you
supply your own Google Gemini API key, assistant questions are instead answered
via Google's Generative Language API under Google's terms.
Dietary preferences (optional). You may set a diet profile in
Settings — a diet style (for example vegetarian, low-carb, or low-FODMAP),
optional daily calorie and protein targets, and ingredients you want to avoid.
This is stored with your settings (on your device, and synced to your account
if you sign in) and is used to tailor meal-plan suggestions, nutrition displays,
and — when you use Premium+ AI features — the assistant's answers, in which
case it is included in the AI request described above. It is used for no other
purpose, and you can clear it at any time in Settings. Dietary features are
preferences, not medical advice.
Optional self-hosted sync (advanced). If you configure your own
sync endpoint, your synced data is stored on that server, which is under your
control and not operated by us.
Technical information processed automatically. To provide
authentication, database, messaging, and purchase-validation services, our
providers (Google Firebase, Apple, RevenueCat) may automatically receive and
process limited technical information, which can include device identifiers, IP
address, app version, and basic diagnostic data. This is inherent to operating
those services and is subject to those providers' own privacy policies.
We do not sell your personal information, and the App contains no
advertising or third-party analytics/tracking SDKs.
2.How We Use Information
We use the information we collect to:
Provide, operate, and maintain the App and its features;
Sync your recipes, cook logs, lists, groups, and settings across your devices when you sign in;
Power optional social features — friends, the activity feed, comments, groups, direct messages and group chats, and shared grocery lists;
Find cover photos and estimate calories for your recipes when you use those features;
Provide the Premium+ Sous Sprout AI features, and tailor meal-plan and recipe suggestions to any dietary preferences you set;
Keep the community safe — filter obviously objectionable text, and let you report and block content and users;
Process and validate in-app purchases and manage Premium/complimentary access;
Deliver notifications you have enabled;
Operate, secure, troubleshoot, and improve the App, and fix bugs; and
Comply with legal obligations and enforce our Terms of Service.
We do not use your information for advertising, and we do not sell
your personal information.
3.Social, Sharing & Family Secrets
CookwithFriends includes optional social features. When you use them, some of
your content becomes visible to other people you choose:
Friends & public profile. To let people add you, a small
public profile (name, avatar, @handle, friend code) is readable by
signed-in users. Other signed-in users can find you by your friend code, by
searching the start of your display name or handle, or by
entering your exact email address (matched against a one-way
hash — the address itself is never exposed). Adding a friend creates a
friendship record that only the two of you can see.
Shared content. A grocery list you share, or a recipe or cook
you post to a group or the activity feed, is visible to the people or group you
shared it with. Anything you make public or share may be re-shared or retained
by those recipients outside our control.
Direct messages & group chats. When you send a message or
share a recipe into a chat, its contents are visible to the other members of that
conversation and are stored so they can be delivered. As with any message, once
you send something you cannot control whether the recipients keep, copy, or
screenshot it. You can report a message and block
a user; blocked users' messages are hidden from you.
Family Secrets are encrypted on your device. Family Secrets are
encrypted locally with a passphrase you set (AES-GCM). The passphrase is never
sent to us, so we cannot read, recover, or reset your Family
Secrets. If you forget the passphrase, that content is permanently
unrecoverable. Only the encrypted form is ever stored or synced.
4.Third-Party Services
The App relies on a small number of third-party services that may process limited
information on our behalf or on yours:
Google Firebase — authentication, the cloud database that
stores your synced data and social records, and Cloud Messaging for
notifications
(Firebase privacy).
Apple — processes in-app purchases and delivers push
notifications to your iOS device (APNs)
(Apple privacy).
RevenueCat — validates purchase receipts and reports your
subscription/entitlement status back to the App
(RevenueCat privacy).
Anthropic (Claude API) — powers the Premium+ Sous Sprout AI
features via our own AI service, which forwards only the content described in
Section 1 (recipe text, your question, a photo you ask it to read, pantry item
names, and any dietary preferences you set) to generate a reply
(Anthropic privacy).
Our AI service is hosted on Render
(Render privacy).
Google Generative Language API (Gemini) — a legacy option used
only if you supply your own key, to answer assistant questions
(Gemini API terms).
Stock-photo services — Pexels, TheMealDB, and Openverse — used
only when you tap "Find a photo," to search for a recipe cover image by name and
return options to choose from. Images are provided under those services' and
their contributors' licenses
(Pexels,
TheMealDB,
Openverse).
Nutrition databases — USDA FoodData Central, Open Food Facts, and
wger — used only when calorie estimates are shown, to look up an
ingredient's energy value by name
(USDA FoodData Central,
Open Food Facts,
wger).
Recipe websites you import from. If you import a recipe from a
web page, the App reads that page to extract the recipe. Those sites are
governed by their own terms and privacy policies.
These providers process information under their own privacy policies. We do not
control, and are not responsible for, their practices.
5.How We Share Information
We share information only in the following limited circumstances:
With the service providers described above, who perform functions on our behalf under appropriate confidentiality obligations;
With third-party stock-photo and nutrition services, but only the search term (a recipe or ingredient name) you cause to be sent when you use the "Find a photo" or calorie-estimate features;
With our AI provider (Anthropic), but only the content you cause to be sent when you use a Premium+ Sous Sprout feature, as described in Section 1;
With other users, but only the content you choose to make public or share (your public profile, shared lists, feed/group posts, and the messages you send in a direct or group chat);
When required by law, regulation, legal process, or a valid governmental request;
To protect the rights, property, or safety of our users, the public, or us; and
In connection with a merger, acquisition, or sale of assets, in which case we will continue to protect your information.
We do not sell or rent your personal information, and we do not share it for advertising.
6.Data Retention
We retain personal information only as long as necessary to provide the App and for
the purposes described in this Policy, unless a longer retention period is required
or permitted by law. Data stored locally on your device remains there until you
clear it or uninstall the App. Cloud data tied to your account is removed when you
delete your account (see Section 9). Content you shared with other people or groups
may remain with those recipients even after you delete your copy. When information
is no longer needed, we take reasonable steps to delete or anonymize it.
7.Data Security & No Guarantee
We use reasonable technical and organizational measures designed to protect your
information, including per-user security rules that restrict your cloud data to your
own signed-in account, and client-side encryption for Family Secrets. However,
no method of transmission or storage is completely secure, and we cannot
guarantee absolute security or that your data will never be lost. The App
is not a backup service; you are responsible for keeping your own copies of your
content (there is an in-app Export). Our responsibility for lost or inaccessible
data is addressed in our Terms of Service.
8.Children's Privacy
The App is not directed to children under the age of 16 (or the equivalent minimum
age in your jurisdiction), and we do not knowingly collect personal information from
them. If you believe a child has provided us with personal information, please
contact us so we can take appropriate action.
9.Your Rights, Choices & Account Deletion
Depending on where you live, you may have rights regarding your personal
information, including the right to access, correct, delete, or restrict its use,
and the right to object to certain processing. Residents of the European Economic
Area, the United Kingdom, and California, among others, may have specific rights
under laws such as the GDPR and the CCPA/CPRA.
You also have direct controls in the App: you can use it without an account, sign
out at any time, and choose what to sync or share. You can delete your
account and all synced cloud data at any time from
Profile → Account → Delete account; deletion removes your account and its cloud
document and is irreversible. Data already stored locally on your device stays on
your device until you clear it or uninstall. You can also block and report other
users' content from the feed. To exercise any other right, contact us using the
details below.
10.International Users
The App may be operated from, and information may be processed in, countries other
than the one in which you reside. Those countries may have data-protection laws that
differ from your own. By using the App, you consent to the transfer of your
information as described in this Policy.
11.Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will revise the
"Last updated" date above and, where appropriate, provide additional notice within
the App. Your continued use of the App after changes take effect constitutes
acceptance of the updated Policy.