This Privacy Policy explains how Roll Cookbook ("the App", "we", "us") collects, uses, stores, and protects information when you use our recipe management application available on Android and the web. By creating an account or using Roll Cookbook, you agree to the practices described in this policy.
๐ค
Username
Your chosen display name, visible to other users in social features such as following, community posts, and shared lists.
๐ง
Email Address (optional)
Collected only if you choose to secure your account with email and password authentication. Used solely for login, password reset, and account recovery. Never shared with other users or used for marketing.
๐
Password
If you set a password, it is hashed and stored securely by Supabase Auth. We never store or have access to your plain-text password.
๐ฝ๏ธ
Recipe Data
Recipes you add, import, or create โ including titles, ingredients, instructions, cook times, ratings, notes, tags, and source URLs. Stored privately unless you explicitly share them to the Community tab.
๐ผ๏ธ
Photos & Images
Profile pictures and recipe photos you upload are stored in Supabase Storage, associated with your account.
๐
Usage & Activity Data
Favourites, collections, meal plans, cooking journal entries, planner entries, and follow relationships. Used to power the App's features and activity feeds visible to users who follow you.
๐ฌ
Messages & Community Posts
Direct messages between users and posts you share to the Community tab. Messages are private between participants. Community posts are visible to all users of the App.
๐
Shopping Lists
Your personal shopping list is stored locally on your device and never sent to our servers. Shared shopping lists are stored in our database and visible to all members you invite.
All user data โ recipes, profiles, follows, messages, planner entries, and community content โ is stored in Supabase, a PostgreSQL-based backend hosted on secure cloud infrastructure. Authentication credentials are managed by Supabase Auth.
The App's frontend is hosted on Vercel. Serverless API functions on Vercel handle recipe importing, AI-powered features, and authentication. These functions do not log or retain your personal data beyond a single request.
Your personal shopping list is stored in your device's local storage and is never transmitted to our servers.
We do not sell, rent, or trade your personal information to any third parties.
Guest Accounts: You may use Roll Cookbook with a username only, without providing an email or password. In this case, anyone who knows your username can access your account. We strongly recommend securing your account with an email and password via Settings โ Account Security.
When you secure your account, passwords are hashed using industry-standard bcrypt by Supabase Auth and are never stored in plain text. We have no access to your password.
Password reset links are sent to your registered email and expire after a short period. You can change your email or password at any time from Settings โ Account Security.
We recommend choosing a username that does not contain personally identifiable information, especially if you opt not to set a password.
We use the information we collect solely to operate and improve Roll Cookbook:
- Provide core features including recipe storage, meal planning, shopping lists, and collections
- Enable social features such as following users, messaging, sharing to the community, and shared shopping lists
- Send password reset and account verification emails when requested by you
- Power the Recipe of the Day, seasonal suggestions, and discover features
- Allow recipe import from external websites via AI-assisted extraction
- Improve App performance and fix issues
- Process account deletion requests you initiate
We do not use your data for advertising, profiling, or any purpose unrelated to operating the App.
Roll Cookbook relies on the following third-party services. Each handles data according to its own privacy policy:
Supabase
Provides our database, file storage, and authentication system. Your recipes, profile, and account credentials are stored here.
Supabase Privacy Policy โ
Google Gemini API
Used when you import a recipe by URL. The web page content is sent to Google's Gemini API to extract recipe data. No personally identifiable information is included in these requests.
Google Privacy Policy โ
Google Fonts
Fonts used in the App's interface are loaded from Google Fonts, which may involve a request to Google's servers.
Google Privacy Policy โ
The following is visible to other users of the App:
- Your username and profile picture
- Recipes you share to the Community tab
- Your bio and collections you set to public
- Your activity visible to users who follow you (e.g. recipes you have cooked)
- Items you add to shared shopping lists, visible to all members of that list
If you generate a shareable recipe link, that recipe will be accessible to anyone with the link โ no login required. You control this and can stop sharing at any time.
Your private recipes, personal shopping list, meal planner, cooking journal, and direct messages are never visible to other users.
Your data is retained for as long as your account is active. You can request account deletion at any time from within the App via Settings โ Danger Zone โ Request Account Deletion. You have a 12-hour window to cancel before deletion is processed.
Upon deletion, the following is permanently removed: your profile, all recipes, collections, planner entries, shopping data, follow relationships, messages, notifications, community posts, and authentication credentials.
Some aggregated or anonymised data (such as community post upvote counts) may remain in an unidentifiable form after deletion.
Roll Cookbook is not directed at children under the age of 13. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided information to the App, please contact us and we will remove it promptly.
You have the right to:
- Access the personal data we hold about you
- Correct inaccurate data via Settings within the App
- Request deletion of your account and all associated data
- Update your email address or password at any time via Settings โ Account Security
- Export your recipes via Settings โ Export
To exercise any of these rights, use in-app settings where available, or contact us at the address below.
We may update this Privacy Policy as the App evolves. We will notify users of significant changes by updating the effective date at the top of this document. Continued use of the App after changes are posted constitutes your acceptance of the updated policy.
If you have questions about this Privacy Policy, wish to exercise your rights, or need to report a privacy concern, please contact us: