← Back to Pick & Cook

Privacy Policy

Last updated: September 7, 2026

This Privacy Policy ("Policy") describes how Pick & Cook ("we," "us," or "our") collects, uses, discloses, and protects your personal information when you use the Pick & Cook mobile application and related services (collectively, the "Application"). By accessing or using the Application, you acknowledge that you have read, understood, and consent to the practices described in this Policy.

DISCLAIMER: This document is provided for informational purposes only and does not constitute legal advice. Consult a qualified attorney before relying on this policy.

1. Data Controller

1.1 Pick & Cook is operated by Pick & Cook L.L.C. ("we," "us," or "our"), which acts as the data controller for personal data processed through the Application, as defined under the European Union General Data Protection Regulation ("GDPR") and other applicable data protection laws.

1.2 For questions regarding our data processing practices, you may contact our Privacy Contact at: admin@pickcook.net

2. Categories of Personal Data Collected

2.1 Account Information

We collect information you provide during account registration, including your username and a cryptographically hashed password. If you provide an email address for account recovery or communication purposes, we store that information as well.

2.2 Health and Nutritional Data

The Application processes health-related and nutritional data, including but not limited to: (a) caloric intake and macronutrient data (protein, carbohydrates, fats, sodium, fiber, etc.); (b) meal logs and dietary history; (c) allergen profiles and dietary restrictions; (d) nutritional goals and progress tracking; and (e) data exchanged with Apple HealthKit when integration is enabled. This data may constitute "sensitive personal data" or "special category data" under applicable data protection laws, and we process it with heightened safeguards.

2.3 Pantry, Recipe, and Shopping Data

We collect and store information about the ingredients in your pantry, shopping lists, meal plans, saved recipes, and dietary preferences. This data is cached locally on your device. When you sign in, account-linked pantry, shopping, meal plans, recipes, and preferences are stored on our servers and synchronized automatically. Some meal-log entries remain local to the device.

2.4 Location Data

When you use the Store Finder feature, the Application may access your device's geolocation data to identify nearby grocery stores via the Google Places API. If location permission has already been granted, approximate coordinates may also be sent to Open-Meteo for weather-aware recipe context. Location data is processed transiently, is not stored on our servers, and is not used for advertising or cross-app tracking.

2.5 Photos You Upload

Grocery-receipt photos you choose to scan are stored temporarily in private object storage and sent to OpenAI to extract purchased items. After successful extraction, we immediately attempt to delete every source image. An upload that is never processed becomes eligible for deletion after 24 hours; a photo from a failed extraction becomes eligible after 7 days. A daily cleanup job retries eligible objects until deletion succeeds. Structured receipt details remain with your account. Recipe-page scan photos are not retained by us after the extraction request. Recipe cover photos you choose to publish are stored so they can be displayed.

2.6 Community Contribution Data

If you submit product edits, barcode scans, ingredient information, or recipe contributions, this User Content is associated with your account and may be visible to other users and moderators for quality assurance and community purposes.

2.7 Device and Usage Data

We may collect device type, operating-system version, application version, product-interaction events, performance data, and crash signals to improve stability and the user experience. Signed-in product-interaction events may be linked to your account so we can de-duplicate records, support you, and honor deletion requests. Guest events are recorded without an account identifier. You may stop new product-interaction analytics at any time in Settings → Privacy → Opt out of analytics. Account-unlinked crash and API-error diagnostics are separate service telemetry and may continue after this opt-out. Safety or abuse reports you deliberately submit are service records, not optional analytics, and remain available for human review.

3. Legal Basis for Processing

We process your personal data on the following legal bases, as applicable under the GDPR and similar data protection frameworks:

3.1 Contractual Necessity. Processing of account information, pantry data, and recipe data is necessary for the performance of our contract with you (i.e., providing the Application's services).

3.2 Consent. Processing of Health Data (including Apple HealthKit integration), and location data is based on your explicit, informed consent, which you may withdraw at any time through the Application's settings.

3.3 Legitimate Interests. Processing of device and usage data for Application improvement, security, and fraud prevention is based on our legitimate business interests, balanced against your rights and freedoms.

3.4 Legal Obligation. We may process personal data as required to comply with applicable laws, regulations, legal processes, or enforceable governmental requests.

4. Purposes of Data Use

We use your personal data for the following purposes:

(a) To provide, operate, maintain, and improve the Application's core functionality, including pantry management, recipe recommendations, and nutritional tracking;
(b) To track and display your nutritional goals, caloric intake, and dietary progress;
(c) To synchronize your data across devices when you are signed in;
(d) To display personalized allergen warnings based on your allergy profile;
(e) To facilitate community contributions, including product edits, barcode data, and recipe sharing;
(f) To enable the Store Finder feature using your location (with your express permission);
(g) To exchange nutritional data with Apple HealthKit (with your express permission);
(h) To communicate with you regarding service updates, security alerts, and account notifications;
(i) To detect, prevent, and address fraud, abuse, security vulnerabilities, and technical issues; and
(j) To comply with applicable legal obligations and enforce our Terms of Service.

5. Third-Party Service Providers and Data Sharing

5.1 Integrated Third-Party Services. The Application integrates with the following third-party services, each of which may receive limited data necessary for its function:

(a) Google Places API — nearby-store location queries.
(b) USDA FoodData Central — food product and nutrition queries.
(c) Edamam API — recipe and nutritional-analysis queries.
(d) Open Food Facts — barcode and product lookups.
(e) TheMealDB — public recipe data.
(f) Apple HealthKit — on-device nutrition exchange when enabled.
(g) OpenAI — natural-language features and AI extraction for receipt and recipe-page photos. We do not send your password or username with these requests. OpenAI states that API data is not used to train its models.
(h) Open-Meteo — transient weather context based on approximate coordinates.
(i) Apple Sign-In and Google Sign-In — account authentication when selected.
(j) Google Cloud Storage or Replit Object Storage — temporary private receipt-photo storage and persistent recipe-cover storage, depending on the deployment environment.
(k) Expo — push-notification delivery when enabled.
(l) Sentry — crash and API-error diagnostics when monitoring is enabled. Events are scrubbed before transmission and carry no Pick & Cook account identifier, email, stored IP, request body, authentication header, cookie, or screenshot.

5.2 No Sale of Personal Data. We do not sell, rent, or lease your personal data to third parties for their marketing or advertising purposes.

5.3 Disclosure Circumstances. We may disclose your personal data: (a) to comply with a legal obligation, court order, or governmental request; (b) to protect and defend our rights, property, or safety; (c) to enforce our Terms of Service; (d) in connection with a merger, acquisition, or sale of assets, subject to appropriate confidentiality obligations; or (e) with your prior consent.

6. International Data Transfers

6.1 If you access the Application from outside the United States, your personal data may be transferred to, stored, and processed in the United States or other jurisdictions where our servers or service providers are located.

6.2 For transfers of personal data from the European Economic Area ("EEA"), the United Kingdom, or Switzerland to countries not deemed to provide an adequate level of data protection, we implement appropriate safeguards, including Standard Contractual Clauses approved by the European Commission, to ensure your data is protected in accordance with applicable law.

7. Data Security Measures

7.1 We implement commercially reasonable technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction, including but not limited to:

(a) Encryption of data in transit using TLS/HTTPS protocols;
(b) Cryptographic salting and hashing of passwords using industry-standard algorithms;
(c) Secure cloud infrastructure with access controls and regular security audits;
(d) Secure local storage on your device using platform-provided encryption; and
(e) Principle of least privilege access controls for internal personnel.

7.2 Notwithstanding the foregoing, no method of electronic transmission or storage is completely secure. We cannot guarantee the absolute security of your personal data and shall not be liable for any unauthorized access resulting from circumstances beyond our reasonable control.

8. Data Retention and Deletion

8.1 Active Accounts. Account, pantry, shopping, structured receipt, submitted safety-report, saved-recipe, and household data is retained while your account is active and needed to provide the service. Server access and error logs are retained for 90 days; encrypted rolling backups expire after 30 days; fraud and abuse signals may be retained for 180 days; anonymized aggregate analytics may be retained for trend analysis.

8.2 Photo Retention. Receipt source-photo deletion is attempted immediately after successful extraction. Unprocessed receipt uploads become eligible for deletion after 24 hours and failed extraction photos after 7 days; a daily cleanup job retries eligible objects until deletion succeeds. Recipe-page scan photos are not retained by us after extraction. Recipe cover photos remain while the recipe exists.

8.3 Account Deletion. You may delete your account in Settings → Account. Personal data is erased from live systems within 30 days and from rolling backups within the additional 30-day backup window, subject to legal retention requirements. We also attempt to delete any remaining receipt objects after the live account records are erased.

8.4 Anonymized Data. Accepted community contributions may be retained in de-identified form after account deletion when they can no longer be linked to you.

8.5 Legal Retention. We may retain limited data longer where required by law or necessary to establish, exercise, or defend legal claims.

9. Your Data Protection Rights

Subject to applicable law, you have the following rights with respect to your personal data:

9.1 Right of Access. You have the right to request confirmation of whether we process your personal data and to obtain a copy of such data.

9.2 Right to Rectification. You have the right to request correction of inaccurate or incomplete personal data.

9.3 Right to Erasure. You have the right to request deletion of your personal data, subject to applicable legal retention requirements.

9.4 Right to Data Portability. You have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to request transmission of such data to another controller where technically feasible.

9.5 Right to Restriction. You have the right to request restriction of processing of your personal data under certain circumstances, such as when you contest the accuracy of your data.

9.6 Right to Object. You have the right to object to the processing of your personal data based on our legitimate interests or for direct marketing purposes.

9.7 Right to Withdraw Consent. Where processing is based on your consent (e.g., Apple HealthKit integration), you may withdraw your consent at any time through the Application's settings without affecting the lawfulness of processing prior to withdrawal.

To exercise any of the above rights, please contact us at admin@pickcook.net. We will respond to your request within thirty (30) days, or such shorter period as required by applicable law.

10. Children's Privacy (COPPA Compliance)

10.1 The Application is not directed at, and we do not knowingly collect personal information from, children under the age of thirteen (13) in compliance with the U.S. Children's Online Privacy Protection Act ("COPPA").

10.2 If we become aware that we have inadvertently collected personal data from a child under 13, we will take reasonable steps to promptly delete such data from our records.

10.3 If you are a parent or guardian and believe your child has provided us with personal information without your consent, please contact us immediately at admin@pickcook.net.

11. California Privacy Rights (CCPA)

11.1 If you are a California resident, you have additional rights under the California Consumer Privacy Act ("CCPA") and the California Privacy Rights Act ("CPRA"), including:

(a) Right to Know: The right to request disclosure of the categories and specific pieces of personal information we have collected about you, the sources of collection, the business purposes for collection, and the categories of third parties with whom we share your data;
(b) Right to Delete: The right to request deletion of your personal information, subject to certain exceptions;
(c) Right to Opt-Out of Sale: We do not sell your personal information. If this practice changes, we will provide a "Do Not Sell My Personal Information" mechanism;
(d) Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA rights.

11.2 To submit a verifiable consumer request, please contact us at admin@pickcook.net. We will verify your identity before processing your request and will respond within forty-five (45) days.

12. European Privacy Rights (GDPR)

12.1 If you are located in the European Economic Area ("EEA"), the United Kingdom, or Switzerland, you are entitled to the rights set forth in Section 9 of this Policy, as well as the following additional protections under the General Data Protection Regulation ("GDPR"):

(a) The right to lodge a complaint with your local supervisory authority (Data Protection Authority) if you believe your data protection rights have been violated;
(b) The right to be informed of appropriate safeguards for international data transfers as described in Section 6;
(c) The right to obtain human intervention in any automated decision-making or profiling that produces legal effects or similarly significant effects concerning you.

12.2 Pick & Cook does not engage in automated decision-making or profiling that produces legal or similarly significant effects on Users.

13. Cookie and Tracking Technologies

13.1 The Application is primarily a mobile application and does not use browser cookies in its native form. However, if you access any web-based interfaces associated with the Application, we may use:

(a) Essential Cookies: Required for the proper functioning of authentication and session management;
(b) Analytics Cookies: Used to collect anonymized usage data for Application improvement.

13.2 The Application may use local storage mechanisms on your device (such as AsyncStorage or SecureStore) to persist your preferences, session tokens, and application data. These are essential to Application functionality and do not track your activity across other applications or websites.

13.3 We do not use third-party advertising trackers or cross-app tracking technologies.

14. Changes to This Privacy Policy

14.1 We reserve the right to update or modify this Privacy Policy at any time. Any changes will be effective upon posting the revised Policy within the Application, with an updated "Last updated" date at the top of this page.

14.2 For material changes that substantively affect how we collect, use, or share your personal data, we will provide you with prominent notice through one or more of the following methods: (a) an in-app notification; (b) a notice on the Application's settings page; or (c) an email to the address associated with your account, if provided.

14.3 Your continued use of the Application following the posting of a revised Policy constitutes your acceptance of and consent to the updated practices. If you do not agree to the revised Policy, you must discontinue use of the Application and delete your account.

15. Contact Information

If you have any questions, concerns, or requests regarding this Privacy Policy, your personal data, or wish to exercise any of your data protection rights, please contact us at:

Privacy Contact: admin@pickcook.net
General Support: admin@pickcook.net