Privacy policy
Last updated: 22 July 2026
This privacy policy applies to AI Chef on ai-chef.info and to the iOS and Android app. It transparently describes what data we process, how long we retain it and what happens when an account is deleted.
1. Controller and contact
The controller under the GDPR is Anton Alpha GmbH, Maurer Lange Gasse 64, Top 3, 1230 Vienna, Austria, email: info@anton-alpha.com, commercial register number FN 538589v. You can also submit privacy requests through the Support page on ai-chef.info.
2. Use, account and sign-in
Public community recipes can be viewed and searched on the website without an account. Personalised features require a Firebase account; the app may initially create a technical anonymous account for this purpose. Firebase Authentication (Google Ireland Ltd./Google LLC) processes the account ID, email address, display name, sign-in provider, authentication times and security tokens.
3. Private account and usage data
We process your private recipes, favourites and recipe lists, meal plan, shopping list, profile and language settings, dietary preferences, allergy information, default servings, generation allowances and subscription entitlements. These data are used only for the features you choose and for synchronisation between your devices.
4. Public community content
When you publish a recipe, its text and image are publicly visible in the app and on the web. A pseudonymous account ID is used internally for creation, likes, ratings and moderation; your name and email address are not displayed as author details. Do not publish personal or confidential information in recipes, prompts or images.
When an account is deleted, recipes and images that you deliberately published remain part of the public collection, but are technically and permanently detached from your account. If published content itself contains personal data or you also want the content removed, please submit a separate request through Support.
5. AI processing
For recipe suggestions, recipe details, image analysis and image generation, we transmit the required text and any ingredient photos you choose to upload to OpenAI, LLC (USA). The data are used only to provide the requested output. OpenAI does not use API data for training by default; safety and abuse-monitoring logs may be retained for up to 30 days by default. We delete temporary ingredient photos from our intermediate storage immediately after the analysis succeeds or fails. Do not transmit sensitive personal data.
6. Storage, images and search
Account data and app content are stored in Google Firebase/Firestore. Public recipes are also mirrored to PostgreSQL and a self-hosted Meilisearch service on European infrastructure at Hetzner/Webbase. Some still-installed app versions additionally use Algolia for search. Generated images are stored redundantly in Google Cloud Storage and S3-compatible storage at Hetzner and served through img.ai-chef.info. Account deletion removes only images used exclusively in private content; images belonging to retained public recipes remain.
7. Subscriptions and payments
Web subscriptions are handled by Stripe Payments Europe Ltd./Stripe, Inc. We store the Stripe customer reference and subscription status, but not complete card data. App subscriptions are billed by Apple or Google. RevenueCat, Inc. processes a pseudonymous customer ID and product, purchase and entitlement status so the subscription can be recognised across devices.
When an account is deleted, we delete the associated Stripe customer and therefore end a web subscription immediately; records required for accounting law are retained separately. RevenueCat customer data are submitted for deletion. A subscription purchased from Apple or Google is not cancelled by deleting the AI Chef account and must also be cancelled in the relevant store.
8. Technical app telemetry
Currently published older versions of the mobile app contain Firebase Analytics and the Meta App Events SDK. Even though we do not run advertising campaigns with them, these SDKs may send technical initialisation, app, device and interaction events to Google or Meta Platforms Ireland Ltd./Meta Platforms, Inc. We use these data solely for technical operations, stability and aggregate product improvement, not for personalised advertising. The next app version removes these SDKs, which AI Chef does not use. Statistics that have already been anonymised or aggregated cannot be linked to an account and are unaffected.
9. Support and email
When you contact Support or submit feedback, we process the message, time, optional contact details and, if you are signed in, your account ID in order to handle the request. Emails are delivered through Resend, Inc. Support content is not used for advertising.
10. Technical data, logs and local storage
When you access the service, the website, Cloud Functions, hosting and security services process the IP address, time, requested resource, HTTP status, device/browser information and technical error data. This is used for delivery, troubleshooting, rate limiting and protection against attacks. The website uses only technically necessary sign-in and language/display storage and sets no advertising cookies.
11. Purposes and legal bases
We process account, content, AI, synchronisation and subscription data to perform the contract and take pre-contractual steps (Art. 6(1)(b) GDPR). We process security, operations, support and non-personalised reach/stability data for our legitimate interest in a secure and reliable service (Art. 6(1)(f) GDPR); where required by law, we obtain consent (Art. 6(1)(a) GDPR). We process invoice and evidence data to comply with legal obligations (Art. 6(1)(c) GDPR).
12. Recipients and transfers to third countries
Data are received only by the processors and platform providers required for the relevant feature: Google/Firebase/Google Cloud, Hetzner, Webbase infrastructure, self-hosted Meilisearch, where applicable Algolia, OpenAI, Stripe, RevenueCat, Apple, Google Play, Resend and, for older app versions, Meta. For recipients outside the EEA we rely on an adequacy decision, in particular the EU-US Data Privacy Framework where applicable, or EU Standard Contractual Clauses and supplementary safeguards. Apple, Google and Stripe may act as independent controllers for their own payment processing.
13. Retention and account deletion
You can initiate deletion at any time in the app, in your web profile or at ai-chef.info/account-deletion. For registered accounts, we require a recent sign-in for security. If you no longer have access to the account, contact Support so we can verify your identity. After a successful request, active private account data are normally removed during the process and no later than 24 hours.
- Private recipes, lists, meal plan, shopping list, profile, preferences, comments, likes, ratings, feedback associations, allowances, MCP access and the Firebase Auth account are deleted.
- Public recipes and associated images remain; the creator ID and other links to the account are removed. Counts are recalculated without your interactions.
- A technical write block containing the plain account ID remains for no more than 24 hours. A deletion receipt containing only a SHA-256 hash of the account ID remains for 60 days so backups and delayed webhooks cannot restore the data.
- Application and database backups are retained for no more than 14 days and used only for recovery. After a restore, deletion receipts are reapplied before the service is reopened.
- Normal operational logs are retained for 30 days. Locked audit/system logs required by Google may remain for up to 400 days and are used only for security, evidence and platform operation.
- Support and feedback cases are generally deleted 12 months after receipt unless longer retention is necessary to handle the case or defend legal claims.
- Invoices and accounting records are retained for seven years after the end of the relevant calendar year under Austrian retention law; only the required information remains.
- OpenAI may retain safety and abuse-monitoring logs for up to 30 days by default as described above. Payment and store records held by providers are subject to each provider’s statutory periods.
14. Your rights and changes
Subject to the GDPR, you have rights of access, rectification, erasure, restriction, data portability and objection, and the right to withdraw consent for the future. Contact info@anton-alpha.com or use Support. You may also complain to the Austrian Data Protection Authority at dsb.gv.at. We update this policy following material changes; the version published here applies.