Privacy Policy
Last updated: August 24, 2026
The short version
softboiled is a personal recipe management app. We do not sell your data, show ads, or track your behavior. Your recipes are yours. You can export them anytime and delete your account whenever you want.
What we collect
- Email address — for login and account recovery
- Display name — shown in the app
- Recipe data — titles, ingredients, steps, tags, images, source info, notes, ratings. This is the core of what softboiled stores for you.
- Photos you upload — cookbook pages, handwritten cards, clippings, and pantry labels, plus the text we extract from them
- Simmer history — the AI variants you generate and save (“softboilds”), and the prompt you asked for, so you can revisit them
- Household and dietary information — if you use Family Members, we store the names, allergies (including severity), dietary requirements, dislikes and likes you enter for the people you cook for. This can include children and other people who are not softboiled users. It is used to filter and rank your recipes, and it is sent to the AI provider below when you use a feature that needs it, such as generating a menu. Only you can see it.
- Pantry, menus, meal plans, and comments — the items you track, the menus and plans you build, and any comments or feedback you write
What we do NOT collect
- No tracking cookies or analytics cookies
- No behavioral profiling or usage tracking
- No location data
- No contact list access
- No device fingerprinting
Cookbook indexing — what stays on your device
When you use the cookbook indexing feature to photograph pages from cookbooks you own, our long-term goal is for the photo itself never to leave your device — only the extracted ingredient list and steps reach our servers. We are migrating toward client-side text recognition for this feature; until that migration is complete, photos are sent to Anthropic for text extraction (see “AI features” below). We do not keep the photo after extraction.
Recipes you index from cookbooks are kept private to your account. We never make them public, never share them with third parties beyond what is required to operate the service, and never include their contents in any analytics shared outside softboiled.
Each time you upload from a cookbook, we record an ownership attestation (a timestamped log of your confirmation that you own the book) along with the cookbook's title, author, and ISBN where known. This is an audit record retained for compliance purposes.
Logs and audit data
We retain server logs containing IP addresses and request metadata for up to 90 days for security and abuse-prevention purposes. DMCA notices are kept indefinitely as legal records. Ownership attestations are kept for as long as your account exists and are deleted with it.
How we protect your data
- Encryption in transit: All connections use HTTPS with TLS 1.2+. HSTS is enforced.
- Encryption at rest: Supabase encrypts the database at the infrastructure level.
- Row Level Security: Database rules ensure you can only access your own recipes.
- Log sanitization: Passwords, tokens, and email addresses are automatically redacted from logs.
AI features
Anthropic processes essentially all AI requests in softboiled. An earlier version of this policy said AI ran on our own private infrastructure with Anthropic as a rare fallback for vision. That is not accurate and we have corrected it.
What gets sent to Anthropic depends on the feature, and can include: the text of a recipe, your own notes on it, photos you upload of cookbook pages, handwritten cards and pantry labels, your saved preferences and household dietary information when a feature needs them, and the parts of your library that are relevant to what you asked.
Anthropic processes this to answer the request and returns it to us. Their handling is governed by the Anthropic commercial terms and their published data-usage policy. We do not send them your email address or your account identifier.
Which features use AI. Most are things you explicitly start — Simmer, the recipe help chat, menu and meal-plan generation, ingredient suggestions, and importing a recipe from a URL, a photo, or a PDF. Some run automatically when you save a recipe, to fill in tags. We say so in the app where a feature has done this, with a ✨ marker.
Eva. softboiled can run against Eva, a self-hosted AI service, instead of Anthropic. That mode is off, and no user traffic goes through it today. If we turn it on we will update this policy first.
Third-party services
- Supabase — hosts our database and handles authentication
- Vercel — hosts the website
- Upstash — provides rate limiting (stores request counts, not personal data)
- Anthropic — all AI processing: recipe text, photos you upload, and the library context a feature needs
We do not use Google Analytics, Facebook Pixel, or any advertising network.
Your rights
You can:
- See your data — your recipes, collections, and tags are all visible in the app
- Export your data — download your entire library as JSON from Settings
- Delete your account — permanently removes your account, all recipes, collections, tags, and Kitchen Lab history. Available in Settings.
We will never
- Sell, license, or trade your data
- Show you ads
- Build behavioral profiles
- Share your recipes with anyone unless you choose to make them public
Contact
For privacy questions: privacy@jessicathornton.dev