Privacy

Privacy Policy

Effective date: 5 August 2026.

BKZ Lab Pty Ltd (ACN 698 679 051) trading as "RecipeRun" ("we", "our", "us") respects your privacy and is designed to minimise data collection. This policy explains what information the RecipeRun app and website handle, when information may leave your device, and the choices you have.


1. Summary

  • Recipes, meal plans, and shopping lists you create on your own are stored only on your device unless you use a feature that needs online processing or sync, such as Family Group, AI-assisted recipe imports from photos, videos, text, or supported social-media links, subscriptions, diagnostics, or cloud backup and sync (Google Drive on Android, iCloud on iOS).
  • We do not sell or rent your data to anyone.
  • We use a small number of third-party services to provide account, sync, subscription, AI import, backup, security, and diagnostics features. These are listed below.
  • The RecipeRun website uses Google Analytics 4 to understand visits and app-store-link clicks. Website analytics do not receive your private in-app recipes, submitted or imported media and text, meal plans, or shopping lists.

2. Account and authentication

When the app first runs, it creates an anonymous app account using Firebase Authentication. This lets RecipeRun apply feature limits and keep cloud-enabled features tied to the correct app user. No name, email, or password is required at this stage.

On Android, if you tap "Sign in with Google" to join or create a Family Group, your app account is linked to your Google account. Google may provide your display name, email address, and profile photo URL so other Family Group members can identify you. You can sign out of Google from Settings → Account at any time.

On iOS, you sign in with Apple. The first time you sign in, Apple shares your name and email address only if you allow it. If you choose Hide My Email, Apple gives us a private relay address (ending @privaterelay.appleid.com) instead of your real one. Apple does not resend your name or email on later sign-ins, so we store them at first sign-in to show you to your Family Group. You can sign out from Settings → Account, which unlinks your Apple ID, and you can revoke RecipeRun's access entirely from Settings → your name → Sign in with Apple on your device.


3. Local data storage

When you use the app without Family Group, AI-assisted imports, or another cloud-enabled feature described below:

  • Recipes (including text, ingredients, instructions, your own photos), meal plans, shopping lists, and cooking history live in a local database on your device only.
  • Nothing is transmitted to our servers unless you actively use a feature listed below. (On iOS, if you keep iCloud sync on, this data is also stored in your own iCloud account — not on our servers — as described in section 10.)
  • Uninstalling the app deletes this local data permanently.

4. Standard recipe webpage imports

When you import a recipe from a standard recipe website:

  • The app downloads the web page on your device to extract recipe details such as the title, ingredients, instructions, cooking times, source URL, and related images.
  • The extracted recipe is saved on your device.
  • The web page request goes directly from your device to the recipe's website; we do not see or store the URL on our servers.
  • This section does not apply to supported social-media links or uploaded video files. Those imports are processed as described in section 5.
  • Imported recipes are personal-use only. If you choose to share an imported recipe through a Family Group, the recipe content and source URL are visible to your group members. You are responsible for ensuring you have the right to import, store, and share that content.

5. AI-assisted photo, video, text, and social-media imports

When you import a recipe from a photo, an uploaded video file, pasted text, or a supported social-media link:

  • The material you submit is sent securely to RecipeRun for processing.
  • For a supported social-media link, the URL is sent to our cloud services. We may retrieve publicly available source information such as the post title, description or caption, creator or account name, thumbnail, available captions, and links to recipe webpages. We may inspect a limited number of publicly visible comments solely to locate a linked recipe webpage.
  • Depending on the platform and the public information available, we may use the platform's public API or oEmbed service, or an external media-resolution service, to retrieve public text, images, audio, or video for temporary processing. The particular platform and media-resolution services may change as support and availability change.
  • Text, images, captions, and linked-page text may be processed by one of our AI providers, such as Anthropic, Google, or OpenAI. Video content may be processed using Google Gemini, which may analyse video frames, audio, speech, and captions to extract the recipe.
  • An uploaded video file may be staged temporarily in Firebase Storage and temporary processing storage before it is sent to Google Gemini.
  • The AI provider returns recipe details such as the title, ingredients, serving size, cooking times, and instructions.
  • The returned recipe is stored on your device. For a social-media import, its source URL and a public thumbnail may also be saved with the recipe. These details can be included in your own cloud backup or sync and can become visible to Family Group members if you share the recipe.
  • We do not intentionally keep submitted photos, videos, or text after processing, except where temporarily required for processing, cleanup, security, debugging, or legal compliance.
  • We may cache the extracted recipe result for up to 24 hours to prevent duplicate processing and quota issues. For a social-media import, this cache may also include the source URL and thumbnail URL.
  • We keep a monthly import count for your app account so we can apply free and Pro feature limits. This count does not include your submitted media, text, or extracted recipe content.
  • Only submit cooking content that you have the right and permission to process. Photos and videos can contain faces, voices, usernames, locations, private documents, addresses, financial information, or other personal or sensitive information about you or other people. Avoid submitting this information unless it is necessary and you have permission to do so.

6. Family Group feature

If you create or join a Family Group (a Pro-tier feature):

  • The following data may be stored in cloud services so it can be shared with your group members:
    • Group metadata (group name, owner, member list, group code)
    • Each member's display name and profile photo URL
    • Weekly meal plans
    • Shared recipes (including their source URL and any image or thumbnail saved with the recipe)
    • Shopping lists for the group
  • Access controls are used so only authenticated members of your group can read or change your group's data.
  • When you leave a group, your member profile is removed. If you are the group owner, the group may be deleted along with its shared recipes, plans, and shopping lists unless an ownership transfer option is available.
  • When a member is removed from a group, their shared recipes and attached images may be deleted from the group.

7. Pro subscription

If you purchase a Pro subscription:

  • Subscriptions are processed by your app store — Google Play on Android or the App Store on iOS — and tracked by RevenueCat, our subscription-management provider.
  • We send RevenueCat your app account identifier, app version, and, if you have signed in (with Google on Android or Apple on iOS), your email address and display name. These help link your purchase to your account and help our support team find your subscription if you contact us.
  • The app store handles the actual payment; we never see your card or billing details.
  • You can manage or cancel your subscription at any time in the Google Play Store or, on iOS, in Settings → your name → Subscriptions.

8. Crash diagnostics

To help us fix bugs, the app can send crash reports to Firebase Crashlytics:

  • Reports may include: device model, operating system version, app version, crash details, and a pseudonymous app identifier.
  • Reports do not include: your recipes, submitted or imported media and text, meal plans, shopping lists, name, email, address, or any other content you have created in the app.
  • Default behaviour by region:
    • Outside the EEA, UK, and Switzerland: crash reporting is on by default. You can turn it off in Settings → Privacy → "Send crash reports".
    • Inside the EEA, UK, or Switzerland: crash reporting is off until you actively opt in. The app shows a one-time dialog on first launch asking for your choice. You can change your choice any time in Settings.

9. App integrity

To help prevent abuse of online features, RecipeRun may use app integrity checks — Google Play Integrity on Android and Apple App Attest on iOS. These checks help confirm that requests come from a genuine copy of the app. They do not include your recipes, submitted or imported media and text, meal plans, shopping lists, or other content you create in RecipeRun.


10. Cloud backup and sync

Android — Google Drive

If you choose to back up your recipes to Google Drive:

  • The app uploads a backup file to your own Google Drive account in storage reserved for RecipeRun.
  • The backup may include source URLs and images saved with your recipes.
  • The backup is only accessible to RecipeRun on the device where you authorised it. RecipeRun cannot see other files in your Drive.
  • We do not store a copy of your backup on our servers.
  • You can revoke RecipeRun's access at any time from your Google Account permissions page.

iOS — iCloud

If iCloud sync is on:

  • Your recipes (including source URLs and images saved with them), meal plans, shopping lists, cooking history, and recipe photos are continuously synced to your own iCloud account (a private iCloud database) so they are available across your Apple devices and can be restored after you reinstall the app.
  • This data lives in your iCloud under Apple's privacy policy. RecipeRun cannot see anything else in your iCloud, and we keep no copy of it on our servers.
  • The local grocery price cache is not synced and stays only on the device.
  • Your app display preferences (such as hidden sections, custom item names, and store choices) also sync across your Apple devices via iCloud.
  • You can turn iCloud sync off in your iOS Settings and delete this data from your iCloud storage at any time.

11. Third-party services and website analytics

RecipeRun uses third-party services to operate the app, including:

  • Google Firebase for authentication, cloud functions, temporary file storage, Family Group data, app integrity, and crash diagnostics.
  • Anthropic, Google Gemini, and OpenAI for AI-assisted recipe extraction.
  • Supported social-media platforms, their public APIs or oEmbed services, and external media-resolution services where needed to retrieve publicly available source information or media.
  • RevenueCat, Google Play, and the Apple App Store for subscription management and purchases.
  • Apple and Google for account sign-in, app integrity, and optional cloud backup or sync through Apple iCloud and Google Drive.

Our contracted service providers may process information only as needed to provide their services to RecipeRun. We do not sell or rent your data, and we do not allow our contracted providers to use your RecipeRun content for their own marketing or advertising purposes. Requests made to public platforms or external media-resolution services are also subject to those services' privacy practices.

Some providers may process information outside Australia, including in the United States and other countries where they or their subprocessors operate. RecipeRun cloud requests normally use an Australian endpoint where available, but may use a United States endpoint for availability or fault recovery.

Website analytics

The RecipeRun website uses Google Analytics 4 to understand how people find and use the website and whether they select links to the app stores. Google documents that its default website implementation collects user and session statistics, approximate location, and browser and device information, and stores a pseudonymous client identifier in a first-party _ga cookie.

The website may send page views and interactions such as app-store-link clicks to Google Analytics. The app-store event can include the selected platform, the page or article slug, and the link position. We do not send your name, email address, or private in-app recipes, submitted or imported media and text, meal plans, or shopping lists to Google Analytics from this website.

We use this information to understand website traffic and improve RecipeRun's pages. The website tag is configured to disable Google signals and advertising-personalisation signals. Google processes the analytics data under its Privacy Policy. You can also read Google's documentation about Analytics data collection and Google tag privacy controls. You can limit this collection by blocking analytics cookies or scripts in your browser.


12. Data retention

We keep information only for as long as needed to provide RecipeRun, meet legal obligations, protect the service, or support your requests.

Recipes, meal plans, shopping lists, and other local app data stay on your device until you delete them or uninstall the app. This can include an imported recipe's source URL and saved image or thumbnail. Family Group data remains available while the group exists and is deleted when the group is deleted.

Submitted photos, pasted text, uploaded video files, and temporary social-media copies are processed for recipe extraction and are not intentionally retained as part of a permanent RecipeRun server-side library. We attempt to delete uploaded media and temporary working copies when processing completes or fails. If immediate cleanup does not complete, a copy may remain temporarily in Firebase Storage, temporary function storage, a media-resolution service, or an AI provider's systems until automated expiry, deletion, security review, or fault recovery completes.

We may cache an extracted recipe result for up to 24 hours. A social-media import cache may also include the source URL and thumbnail URL. We may retain monthly import counts until they reset, crash reports for a limited diagnostics period, and operational logs for the period configured in our cloud services. Operational logs may include pseudonymous account identifiers, processing metadata, error information, and a limited portion of AI-generated recipe output for debugging and security. Access to these logs is restricted.

AI providers may retain temporary processing copies and security records according to their service terms and RecipeRun's configured account settings. Subscription records are kept for as long as needed to manage your subscription and meet tax or accounting requirements. Google Drive backups remain in your own Google Drive account until you delete them. On iOS, data synced to your iCloud remains in your iCloud account until you delete it or turn off iCloud sync.


13. Your rights

You have the right to:

  • Access the data we hold about you (the bulk of it lives on your device — open the app to see it).
  • Correct inaccurate information by editing it in the app.
  • Delete your data. Locally: uninstall the app, or use Settings → Delete all data. Server-side: leave any Family Groups you're in (which deletes your member profile and shared content) and contact us to delete any remaining account record or active import cache where practicable. On iOS, you can also use Settings → Delete account to delete your account and shared content and revoke RecipeRun's Sign in with Apple token; turning off iCloud sync and deleting RecipeRun data from iCloud removes your synced copy.
  • Object to or withdraw consent for crash reporting at any time in Settings → Privacy.
  • Port your data. Use the Export recipes feature in Settings to download your recipes as a backup file.

If you live in Australia and believe we have mishandled your personal information, please contact us first so we can try to resolve it. If you are not satisfied with our response, you can lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au or by phone on 1300 363 992.

If you live in the EEA, UK, or Switzerland, you additionally have the right to lodge a complaint with your local data-protection authority if you believe we've handled your data unlawfully.

To exercise any of these rights, email support@reciperun.com.au with the subject line "Privacy request". We will respond within 30 days.


14. Children's privacy

RecipeRun is intended for general audiences and is not directed at children under 13 (or under 16 in the EEA, where applicable). We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us at the email below and we will delete it.


15. Security

We protect your data with:

  • Encrypted network connections for data sent between the app and online services.
  • App integrity checks to help protect online features from abuse.
  • Access controls so only authenticated Family Group members can access their group's shared data.
  • Limited access to operational logs and support information.

No system is perfectly secure. If you become aware of a security issue, please email us at support@reciperun.com.au.


16. Changes to this policy

We may update this Privacy Policy from time to time. We will update the "Effective date" at the top of this page. For material changes, we will surface a notice in the app on the next launch. Continued use of the app after a change indicates acceptance.


17. Contact

If you have any questions or want to exercise any of the rights above, contact:

BKZ Lab Pty Ltd (ACN 698 679 051)

Email: support@reciperun.com.au