Privacy Policy
Last updated October 4, 2026
The short version.
- Your kitchen (pantry, recipes, settings, photos) is stored in its own private database that only your account can reach.
- To write a recipe, Stovebird sends the AI only what that recipe needs: never your name, email or account.
- No ads, no tracking cookies, no selling or sharing your data for advertising.
- You can download everything or delete your account at any time, from Account in the app.
- The Android and iPhone apps are the same Stovebird, with the same account; they collect nothing more.
This policy explains what Stovebird (“we”, “us”), operated by its owner, an individual sole proprietor based in Tennessee, USA, collects, why, who helps us process it, and your choices. Allergy, diet and similar details are covered in more depth in the Health Data Notice.
What we collect
| What | Examples | Why |
|---|---|---|
| Account | A random account ID; the name you give (optional); your email address if you sign in with Google or give it to us; when you joined and agreed to our terms; which invite you used. | To run your account and keep invites working once. |
| Sign-in | Your passkeys’ public keys (never your fingerprint, face or screen lock: those stay on your device); a Google account identifier if you use Google; sign-in sessions. | To sign you in securely. |
| Your kitchen | Pantry items and rough amounts; staples; household settings (whether kids eat too, foods to never use, foods you’d rather not, equipment, usual servings); recipes; your feedback; cooking timers; photos you add. | To make, save and sync your recipes and run cooking timers. |
| Recipe requests | What you asked for (meal, effort, servings, notes) and a snapshot of the kitchen details the recipe needs. | To write that recipe. The snapshot is deleted when the recipe is done; the request’s record goes after 30 days. |
| Plan and billing | Your plan; how many recipes you’ve used; what each request cost us; Stripe’s customer and subscription IDs and payment status. Never your card number. | To give you your plan’s allowance, bill Pro, and keep costs in check. |
| Messages and the waitlist | What you write to us, and your email if you give it; your email if you join the waitlist. | To answer you and fix what you report; to tell you when there’s room for you. Waitlist emails are used for nothing else. |
| How the app is working | Which steps you’ve reached (your pantry set up, a recipe made, rated or cooked); the ratings you give, with that recipe’s title; the days you open Stovebird; how each request went (how long it took, and whether it worked or why not); which photos were made; the kind of browser you use (such as “Safari on an iPhone” or “Instagram’s built-in browser”), or that it’s Stovebird’s Android or iPhone app, when you open an invite, sign up or run into a problem; the screens opened before signing in (just which one, whether sign-up was open, and the kind of browser); and error reports from the app: the screen, and what went wrong, with anything that looks like an address, link or number removed. Never your pantry, your household or the recipes themselves. | To find and fix problems, and to learn whether Stovebird is useful to people, so we know what to improve. |
| Technical | Your IP address, briefly, to limit repeated sign-in, sign-up and contact attempts (for new accounts, a one-way code made from it, kept for a week, never the address itself); our host’s short-lived request logs. | Security and abuse prevention. Kept a day or two in our own records. |
| On your device | A copy of your kitchen in your browser’s storage (in the apps, the app’s own storage), so it works offline; one sign-in cookie (in the apps, a sign-in token kept in the app’s private storage instead). | Offline use and staying signed in. Signing out clears this copy. |
The Android and iPhone apps
The apps show the same Stovebird as the website and use the same account, server and providers. In addition:
- Camera and photos: used only when you choose to take or pick a photo of a dish you cooked. The photo goes to your kitchen, as on the website.
- Notifications: cooking-timer alerts are scheduled on your phone itself. Nothing about them is sent to us beyond the timers already in your kitchen.
- Passkeys: the apps use your phone’s own passkey manager. We only ever see a passkey’s public key.
- No backups: the apps keep nothing in your phone’s backups or transfers to a new phone. Sign in again there and your kitchen comes back from our server.
- The app stores: Google Play and Apple’s App Store handle your download under their own privacy policies. They give us only totals (such as installs, and crash reports from people who chose to share them), never who you are.
What the AI sees
Recipes are written by Claude, Anthropic’s AI, through Anthropic’s commercial API. For each request Stovebird sends only what that recipe needs: the request, the relevant pantry items and amounts, your staples, your household settings (including foods to avoid), a short summary of what you’ve liked, and the titles of recent recipes so it doesn’t repeat itself. To rework a recipe, it also sends that recipe and your changes. It never sends your name, email address, account ID or IP address. After a recipe photo is made, Claude may check the photo against the recipe and your foods to avoid. Anthropic processes this under its commercial terms, which don’t allow it to train its models on it, and keeps it only for a limited time.
Recipe photos are made by the image model Stovebird chooses: Google’s (Gemini, the usual one), or Cloudflare’s (Workers AI) when Google’s can’t make one; Stovebird may choose OpenAI’s or BytePlus’s (Seedream) instead of Google’s. For each photo it gets only a description of the dish, its ingredients and the foods the photo mustn’t show (which can include foods you avoid), never your name, email address, account ID or IP address.
Who helps us run Stovebird
- Cloudflare: hosts the app and its databases, and makes recipe photos when our usual photo maker can’t.
- Google: makes recipe photos (Gemini); it gets the description above for each photo.
- OpenAI or BytePlus: only if we choose one of them to make recipe photos instead of Google; it gets the description above for each photo.
- Anthropic: writes recipes and checks photos, as described above. Its Claude assistant also helps us run Stovebird: it reads our summaries of how the app is working and messages asking for help or reporting a problem with a recipe, so problems get fixed quickly.
- GitHub: stores Stovebird’s code and runs its automated checks, including a private summary of how the app is working. The summary has no names, email addresses, IP addresses, kitchens or invite links; people appear only as random labels.
- Stripe: processes Pro payments and runs the billing page. Stripe’s own privacy policy covers the payment details you give it.
- Google: only if you choose “Continue with Google”, or connect Google to your account as a second way in. Google’s sign-in button loads from Google on the sign-in screens and in your account’s sign-in settings when Google sign-in is switched on, and Google’s privacy policy applies to it.
- Google and Apple: distribute the Android and iPhone apps through Google Play and the App Store.
They process data for us under their terms, only to provide their service. We don’t sell your personal information, share it for targeted advertising, or use it for advertising at all. We may disclose information if the law requires it, to protect people’s safety, or as part of a transfer of Stovebird to a new owner, who would be bound by this policy.
Cookies
The website uses one cookie, to keep you signed in. It’s required for the app to work. There are no analytics, advertising or tracking cookies. The phone apps use no cookies; they keep a sign-in token instead.
How long we keep it
- Your account and kitchen: until you delete your account. Unused sign-in sessions expire after 180 days.
- When you delete your account, your kitchen database is erased at once, your sign-ins and messages are deleted, any subscription is cancelled first, and your account record is emptied of your name and email, the record of how the app worked for you is deleted (bare counts remain, so our totals still add up). Deleted data can remain in our host’s recovery copies for up to 30 days before it’s gone for good. Stripe keeps payment records as the law requires.
- Waitlist emails: until 30 days after we write to say there’s room, or sooner if you ask.
- Messages to us: until a year after we’ve dealt with them, or sooner if you delete your account or ask.
- How the app is working: up to a year, and error reports and screens opened before signing in 90 days; deleted with your account.
Your choices and rights
- Download your data: Account → Download my data.
- Correct it: edit your pantry, household settings and recipes in the app.
- Delete it: Account → Delete my account; or remove specific items in the app. Can’t sign in? See Delete your account.
- Ask us to confirm what we hold, correct or delete it, or withdraw consent, using the contact form (choose Privacy). We answer within 45 days. If we say no, you can appeal by replying, and we’ll answer the appeal within 45 days.
These rights are for everyone, wherever you live in the US. We won’t treat you differently for using them.
Security
Sign-in uses passkeys or Google, so there’s no password to steal. On the website your session is a secure cookie that page scripts can’t read; in the apps it’s a token in the app’s private storage. Each account’s kitchen lives in its own database, and every request is checked against your account. Data travels encrypted. No system is perfectly secure; if a breach affects your data, we’ll tell you as the law requires.
Children
Stovebird is for adults 18 and over. We don’t knowingly collect data from children. If you think a child has an account, tell us and we’ll delete it.
Where it’s stored
Stovebird is offered in the United States. Your data is stored by Cloudflare and processed by the providers above, which may process it in the United States and other countries.
Changes
We’ll update the date above when this policy changes, and tell you in the app before a material change takes effect.
Contact
Use the contact form; choose Privacy for privacy requests.