Legal
Privacy
Last updated 2 October 2026.
Thyme to Cook is a cookbook. It holds recipes you saved, what you cooked and what you keep in your kitchen. That is personal, and the short version is that it stays yours.
What never leaves
- Your recipes, ingredients, steps, notes and ratings.
- Your photos of your own cooking.
- Your pantry, shopping lists, meal plans and cooking journal.
- Who is in your cookbooks, and any invite codes.
- Your password, if you set one, is stored only as a salted hash and is never recoverable, by us or anyone.
- Which person in your household each dietary restriction belongs to. Sprig is told what the kitchen avoids, never whose allergy it is.
- Which devices you are signed in on.
What survives deleting your account
Deleting your account removes everything above. There is one exception, and this is it.
Reports filed about content or people.
A safety record that the person it is about can erase is not a safety record. Deleting an account removes your NAME from any report you filed or that was filed about you -- the record itself is kept, anonymised, along with the copy of the content that was reported.
Encrypted backups, for up to 90 days.
Nightly backups exist so a failure cannot lose everyone's cookbook. They are encrypted, kept for at most 90 days, and then destroyed; a copy of your data that was already inside one is gone when that backup is, not before. Nothing is restored from a backup into a live account without a person deciding to.
A count of what was removed, and how much the AI features cost.
Deletion writes one record saying how many rows were removed, under a random label that cannot be turned back into you. Records of AI calls keep their token counts and timings under the same label, with no content. Neither carries your name, email, recipes or messages.
What does leave, and when
Only these, only for the reason given, and only when you take the action that needs it.
Google (Gemini)
For a video, PDF or photo import, the file you chose to import. Recipe text and captions only if DeepSeek could not read them.
To read a recipe out of it. This only happens when you start an import or ask a question about a recipe.
Anthropic (Claude)
The same recipe text DeepSeek or Gemini would have read, when both of them failed.
The backup, so an import still works when the others are down. Only if an Anthropic key is configured.
PostHog
That an import finished or was refused, how long it took, which platform it came from, and counts -- never the recipe itself. No titles, no ingredients, no captions, no search terms, no email addresses. You are identified by the random id your account already has, which means nothing outside this database.
To see which parts of the app work and which are ignored. Only sent when an analytics key is configured; there is no key by default, and none in the app you are using unless it says otherwise on this page.
OpenStreetMap / Nominatim
A restaurant name or location you searched for.
Opening hours and addresses for restaurants you save. The only place lookup the app uses — it is free and needs no account.
DeepSeek
When you import a link or type a recipe in: the post's caption, the web page's recipe text, or what you typed, so it can be read into a recipe; the same for tidying up or filling in a recipe you asked about. When you ask Sprig a cooking question: the question, the last few questions and answers in that conversation, and what you have told the app about your kitchen — including any dietary restrictions you recorded, because an assistant that suggests something you cannot eat is worse than useless. When you ask whether a substitution works in a recipe: that recipe's ingredients and method.
To read the recipe or answer the question. Only when you import or edit a recipe, or when you ask — nothing is sent in the background, and a question the app refuses is never sent anywhere. Only if a DeepSeek key is configured.
Apple
For a subscription: the signed receipt your device produces. We never see or store a card number — Apple keeps that.
To check that a purchase is real before unlocking anything, and to hear about renewals, refunds and cancellations.
Who holds it for us
These providers store or carry your data so the service can run. They act on our instructions.
Supabase
Your account, your cookbook and the emailed sign-in codes. It hosts our database and sign-in.
To run the service. It holds your data on our behalf and may not use it for anything else.
Railway
The server that runs the app, and the photos you add.
Hosting. It carries your requests and stores your photos on our behalf.
Resend
Your email address and the one-time code we send you.
To deliver the sign-in email. Only when you ask for a code.
Cloudflare
This website and our domain. The website sets no cookies and runs no analytics.
To serve the website and route email.
Sharing a recipe
When you create a share link, that one recipe becomes readable by anyone holding the link, without an account. The link expires, and you can revoke it at any time from the recipe. A shared page deliberately shows only the recipe: never your comments, ratings, cooking journal, or who else is in your cookbook.
Shared cookbooks
Everyone in a shared cookbook sees its recipes, plan and shopping list, and who added what. Each person keeps their own login, cravings and dietary flags. You can leave a cookbook you joined at any time; the owner can remove anyone from theirs.
Deleting everything
The app has a delete-account option that destroys your data rather than hiding it: recipes, photos, plans, sessions, and the keys that made them readable. It cannot be undone, which is the point. You can take a full copy of everything first from the same place.
No advertising, no sale
There is no advertising, no tracking for advertising, and nothing here is sold or handed to a data broker. There is no analytics service watching what you cook.
This website
This website sets no cookies and runs no analytics or advertising trackers. The only thing it asks of your browser is the page, its pictures and its font.
Dietary information
What you cannot eat is health information, and privacy law treats it more carefully than the rest. We ask for it once, it is optional every time, and it is used for exactly two things: flagging a recipe that trips one of your restrictions, and telling the assistant what to avoid when you ask it something.
It is never used for advertising, never sold, and never sent to analytics. When the assistant is told what a kitchen avoids, it is told what and never whose: no name and no account goes with it. You can clear any of it at any time, and deleting your account deletes all of it.
Where the law requires a legal basis, ours is your explicit consent, given when you switch it on. You can withdraw it by clearing the flags, and withdrawing it does not affect anything done before you did.
Your rights over your data
Wherever you live, you can do all of this yourself, without asking us and without giving a reason:
- See and take a copy of everything, in a format you can read.
- Correct anything wrong, by editing it.
- Delete your account and everything in it, subject only to the exceptions listed above.
- Withdraw consent to dietary screening by clearing your flags.
If you are in the UK or the EEA, you also have the right to object to or restrict processing, the right to data portability (the export), and the right to complain to your data protection authority. If you are in California, you have the right to know what is collected and who receives it (the lists above), the right to delete, the right to correct, and the right to limit the use of sensitive personal information; ours is already limited to providing the feature you switched on. We do not sell or share personal information for cross-context behavioural advertising, so there is no opt-out to offer. Exercising any of these rights never makes the app worse for you.
Legal bases, where they are required: performing our contract with you (running the app and your subscription), your consent (dietary information, and anything optional), and our legitimate interest in keeping the service safe and working (abuse reports, backups, fraud prevention).
The data controller is Thyme to Cook. Everyone listed above acts as a processor or sub-processor on our instructions, except Apple, which handles your payment as its own controller under Apple’s privacy policy; we never see a card number. Anything you cannot do yourself, ask at [email protected] and we will answer within 48 hours and act within 30 days.
Children
Thyme to Cook is for people aged 13 and over. It is not directed at younger children and we do not knowingly collect anything from them. If you believe we have, write to [email protected] and the account and its contents will be deleted.
Questions: [email protected]. See also the terms and the community rules.