Language
Legal
Version 2026-08-11 · Effective 11 August 2026
The individual sole operator of Reciphy determines how personal data is processed and is the data controller where applicable. Complete controller identity and contact details are pending as described above.
Depending on your location, the legal bases may include performing the contract with you, legitimate interests in operating and securing the service, compliance with law, and consent where required. Sensitive allergy or health information should only be supplied voluntarily for personalization and requires appropriate explicit-consent handling before final production launch.
Information needed to generate a recipe may be sent to the configured AI model provider. Do not include names, contact details, secrets or other unnecessary personal information in recipe prompts. Reciphy also relies on service providers including Google for authentication, Stripe for payments, infrastructure/database providers for hosting, and Cloudflare for delivery and security. Each provider processes data under its own terms and applicable data-processing arrangements.
Personal data is not sold. It may be shared with service providers only as needed to operate Reciphy, with professional advisers under confidentiality, in a business reorganization, or when legally required. Provider names, processing locations and transfer safeguards must be finalized in the production vendor register.
Providers may process data outside your country. Where required, Reciphy will use a lawful transfer mechanism such as an adequacy decision or approved contractual safeguards. The final notice must identify the applicable controller jurisdiction and safeguards.
Account and recipe data is kept while your account is active. The normal self-service deletion workflow immediately removes the account and private recipe data from the live application database. Limited transaction, security or legal records may be retained only where needed for accounting, fraud prevention, dispute resolution or legal obligations; retained application records are deleted or anonymized where possible. Residual copies may remain in restricted disaster-recovery backups until those backups are retired. Exact production retention schedules must still be documented and enforced.
Reciphy uses essential cookies for authentication, security, language and core application operation. Essential cookies do not require advertising consent. Any future non-essential analytics, personalization or advertising cookies must remain disabled until an appropriate consent mechanism is added.
Reciphy uses measures such as encrypted HTTPS transport, access controls, signed sessions, CSRF protection, payment-provider tokenization and logging. No online service can guarantee absolute security. Please report suspected account or data issues through the privacy contact below.
Depending on your location, you may have rights to access, correct, delete, restrict or object to processing, receive portable data, withdraw consent and complain to a data-protection authority. Withdrawing consent does not invalidate earlier lawful processing. Identity may need to be verified before fulfilling a request. See the Data Deletion page for the current self-service, Facebook/Instagram and assisted-request procedures.
Reciphy is not directed to children and does not knowingly create accounts for people below the applicable digital-consent age. Contact the operator if you believe a child has provided personal data.
AI generates recipe content, but Reciphy does not currently make decisions that produce legal or similarly significant effects about you solely through automated processing.
Material changes will be identified by a new version and communicated appropriately. Renewed acknowledgement or consent will be requested when required. Data and privacy requests can be sent to [email protected]. The controller's formal legal name, postal address and jurisdiction must still be supplied before this notice is treated as final.