Retsepa Privacy Policy
Last updated: 7 September 2026
Retsepa is a recipe and meal planning app. This policy explains what we collect, why we collect it, who we share it with, and how you can get rid of it.
Who we are
Retsepa is operated by Potapov Oleksandr Persoană Fizică Autorizată, a sole trader registered in Romania, at B-dul Bucureştii Noi 136, et. Parter, ap. 5, Sector 1, Bucureşti, Romania. Fiscal code (CUI): 51609262. VAT number: RO51875094.
We are the data controller for the personal data described in this policy. For anything here, including privacy requests, contact us at support@retsepa.com.
What we collect
Account information
You sign in with Google or with Apple. We never see or store a password. From that sign in we receive and store your email address, your display name, and your profile picture URL, along with the identifier your provider assigns you. If you use Sign in with Apple and choose to hide your email, we only ever see Apple's relay address.
Content you create
Recipes you save, write, or import, along with their photos, your pantry contents, your meal plans, and your shopping lists. If you join a household, this content is shared with the other members of that household, which is the entire point of the feature.
Some of this content, like allergies or a halal or kosher preference, can be adjacent to health or religious information. We do not treat it as a special category of data, and we do not analyze it to draw health or religious conclusions about you; we only use it to filter and generate recipes.
Preferences
Your language, your choice of metric or imperial units, and how you prefer your menu displayed.
Technical and diagnostic data
Server logs of requests to our API, including IP address, timestamps, and error traces. We use these to keep the service running and to debug failures.
What we do not collect
- We do not collect your precise location.
- We do not collect your contacts.
- We do not read your photo library. The app only receives the specific images you pick.
- We do not sell your personal data, and we never have.
- We do not show ads, and we share nothing with advertising networks.
How your data is used
- To give you an account and sync your recipes across your devices and your household.
- To turn a link or a photo you import into a structured recipe.
- To generate meal plans and recipe suggestions when you ask for them.
- To manage your subscription.
- To keep the service secure, diagnose faults, and prevent abuse.
Legal basis for processing
If you are in the European Economic Area or the UK, we rely on the following legal bases: performance of a contract, to create your account and give you the app's core features; legitimate interest, to keep the service secure, diagnose faults, and prevent abuse; and consent, where we ask for it, such as before sending marketing email. You can withdraw consent at any time by contacting us.
We do not use your data to make any decision that produces a legal or similarly significant effect on you without a person involved. Meal plans and recipe suggestions are just that, suggestions, and you decide whether to use them.
Service providers we share data with
We use the following processors. Each receives only what it needs to do its job.
| Provider | What it receives | Why |
|---|---|---|
| Google Firebase | Sign in identity, synced recipe and menu data | Authentication and realtime sync |
| Google Cloud | All stored account and recipe data, server logs | Hosting and database, in the United States |
| Google Gemini | Recipe text, imported captions and transcripts, photos you import | Parsing imports and generating suggestions |
| Apify | The public URL you choose to import | Fetching public TikTok, Instagram, and Threads posts |
| YouTube Data API | The public video URL you choose to import | Fetching public video metadata |
| RevenueCat | A pseudonymous user id and your purchase receipts | Managing subscriptions |
| Sentry | Crash reports: a pseudonymous user id, the error and its stack trace, and your device model and OS version | Diagnosing crashes in the app |
Content sent to Gemini is used to answer your request. It is not used to train Google's models under the paid API terms we operate on. When you import a public post, we fetch that public post; we do not access your account on any of those platforms and never ask for those credentials.
Where your data lives
We are established in Romania, but our servers and databases run in Google Cloud in the United States, so your data is transferred out of the European Economic Area. We rely on the European Commission's Standard Contractual Clauses, which each of the providers listed above has in place, together with the EU-US Data Privacy Framework where the provider is certified under it.
How long we keep it
- Account and recipe data: until you delete it or delete your account.
- Import job records: 30 days.
- Deletion records for synced recipes: 90 days, so that your other devices learn about the deletion.
- Server logs: up to 30 days.
Deleting your data
You can delete your account from inside the app, under Settings. This permanently removes your account, your recipes, your pantry, your meal plans, and your household membership from our systems. It cannot be undone. If you would rather we did it for you, email support@retsepa.com.
Recipes you shared into a household may remain visible to the other members of that household after you leave, in the same way a shared document does.
Your rights
Because we are established in Romania, the EU General Data Protection Regulation applies to everyone we serve, wherever you live. You have the right to access your data, correct it, export it in a portable format, delete it, restrict or object to how we process it, and withdraw consent. Email support@retsepa.com and we will respond within one month, as Article 12 requires.
If you are unhappy with our response you can complain to the Romanian supervisory authority, ANSPDCP (dataprotection.ro), or to the authority in your own country of residence.
If you are in California, note that we do not sell or share personal information as those terms are defined by the CCPA, and we will not discriminate against you for exercising your rights.
Business transfers
If Retsepa is acquired, merges with another company, or sells some or all of its assets, your data may be transferred as part of that deal. We will notify you before your data becomes subject to a different privacy policy.
Children
Retsepa is not directed at children under 13, or a higher age where your country's law requires it (up to 16 in some EU countries), and we do not knowingly collect data from them. If you believe a child has given us personal data, contact us and we will delete it.
Security
Data is encrypted in transit with TLS and encrypted at rest by our cloud providers. Access to production systems is restricted. No system is perfectly secure, and we cannot guarantee absolute security, but we will notify you of a breach affecting your data as required by law.
Changes to this policy
If we change this policy in a way that materially affects you, we will update the date at the top and notify you in the app before the change takes effect.