This Privacy Policy explains what personal data the Spoon & Sketch mobile application (the “App”) collects, why, and what rights you have. We keep it in plain language on purpose — if anything is unclear, write to us.
The App is operated by Anhelina Yermakova, an individual developer based in Montreal, Quebec, Canada (the “Operator”, “we”).
Contact for all privacy matters: privacy@spoonsketch.com
Under the EU General Data Protection Regulation (“GDPR”), the Operator is the data controller for the personal data described in this Policy. Under Quebec’s Act respecting the protection of personal information in the private sector (as amended by Law 25) and Canada’s PIPEDA, the Operator is the person in charge of the protection of personal information (privacy officer); contact them at the email above.
This Policy covers the App (iOS and web), the @spoonsketch_bot Telegram bot, and any related services. It does not cover third-party services you use alongside the App (e.g., Telegram itself, your email provider) — their own policies apply there.
We collect only what the App needs to work. You can use most features without granting optional permissions.
3.1 Account data. Your email address and — if you create a password account — a password, which our authentication provider stores only as a salted hash (we can never read it). If you sign in with Apple or Google instead, we receive the identifier and (if you share it) the name/email those services provide.
3.2 Age verification. To confirm you meet the minimum age (16), the sign-up form asks for your date of birth. Only the year of birth ever leaves your device — the day and month are used on the device for the calculation and are never transmitted or stored. Our server records its own timestamp of the check alongside the year.
3.3 Content you create. Recipes (text, ingredients, steps, tags), photos and screenshots of recipes you upload or send to the bot, drawings and decorations you make in the editor, cookbooks, dedications, and similar content.
3.4 Telegram data (only if you connect Telegram). Your Telegram ID and @handle, and the messages (links, photos, captions) you send to our bot for recipe import. Connecting Telegram is optional.
3.5 AI processing records. When you use AI features (recipe extraction, “Make me Sketch” sticker matching), we keep a record of each job: its type, status and token usage (kept for quota and abuse-prevention purposes), and the request we sent (the link, a reference to the image or file, or the length of text you pasted — not the article text we fetched, which we do not keep) together with the model’s response. The raw payloads are automatically erased after 30 days; the counters remain (see §5).
3.6 Technical and usage data. IP address, device model, OS version, app version, language; crash and error reports (via Sentry); and — only with your consent — product analytics events (via PostHog), such as which screens you use. Crash reports and analytics events are tagged with your account’s internal identifier (a random ID, not your email or name) so we can count users and investigate account-specific problems — this makes them linked to your account even though they are pseudonymous to the vendors. Analytics events do not include your recipe content.
3.7 Payment data (when paid features are offered). Purchases are processed by Apple’s App Store and managed via RevenueCat. We receive subscription status and transaction identifiers — never your card number.
3.8 Print order data (when book printing is offered). If you order a printed cookbook, we collect the recipient name and shipping address and share them with our print partner (Lulu xPress) solely to produce and deliver your order.
3.9 Consent and acceptance records. We keep a log of when you accepted the Terms and this Policy and which document version; your on/off choices for AI features, print and marketing (the analytics choice is different — it is stored only on your device, so switching phones asks you again and we hold no server-side record of it); and — for the Terms — which language version you expressly accepted and the fact that French was presented first (a record Quebec’s Charter of the French language requires). The GDPR likewise requires us to be able to demonstrate consent.
3.10 Bug reports. If you send a bug report from the app, we receive your description, an optional screenshot you attach, and technical context (device model, OS and app version, language, the screen you were on) so we can reproduce the problem. So that we see it quickly, a copy of the report text and that context is delivered to the Operator through a private Telegram message; your screenshot stays in our own storage and is not sent to Telegram.
3.11 Content reports. If you report objectionable content, we record what was reported, the reason you selected and any details you add.
3.12 Website waitlist. If you join the waitlist on spoonsketch.com, we store the email address you submit, the page language you used, which form you came from, and — if you picked one — whether you are waiting for the iPhone or Android version. To prevent abuse of the form we also keep a salted, one-way hash of your IP address (the address itself is never stored), which is automatically deleted within 48 hours.
| Purpose | Data | Legal basis (GDPR Art. 6) |
|---|---|---|
| Provide the App: accounts, sync, storage | 3.1, 3.3, 3.4 | Contract (6(1)(b)) |
| Verifying you meet the minimum age | 3.2 | Legal obligation (6(1)(c)) — COPPA / GDPR Art. 8 / Law 25 |
| AI features: recipe extraction, sticker matching | 3.3, 3.4, 3.5 | Consent (6(1)(a)) — off until you enable it; withdraw any time in Me → Privacy |
| Product analytics | 3.6 (PostHog) | Consent (6(1)(a)) |
| Crash diagnostics, bug reports, security, abuse and quota enforcement, content moderation, waitlist rate-limiting | 3.5, 3.6, 3.10, 3.11, 3.12 | Legitimate interests (6(1)(f)) — keeping the service working and safe |
| Payments and subscription management | 3.7 | Contract (6(1)(b)) |
| Printing and shipping your book | 3.8 | Contract (6(1)(b)) |
| Legal compliance (consent and acceptance records, unlawful-content reports) | 3.9, 3.11, moderation logs | Legal obligation (6(1)(c)) |
We do not sell personal data, do not show ads, and do not use your data for third-party marketing.
When you enable AI features and use them:
Recipe links you share are fetched and their text is sent to Anthropic (Claude model) to extract a structured recipe. Photos and screenshots you submit are sent the same way, as are PDFs or documents you upload and recipe text you paste in. If you import a file of recipes you exported from somewhere else, its contents travel the same path. “Make me Sketch” sends your recipe’s title, description, ingredients and tags to Anthropic to choose matching stickers; sticker placement is computed on our servers. Every photo you upload — in the app or via Telegram — is automatically scanned by an AI safety classifier (an App Store content-safety requirement). To be precise about the order: the file is transferred to our storage first, scanned immediately, and deleted right away if it fails — it is never shown, shared or used for anything else in between. This scan runs for all uploads regardless of your AI-features toggle: it is a safety check, not an AI feature.
Anthropic does not use API content to train its models; under its standard commercial terms, API inputs and outputs are retained for a limited period (typically up to 30 days), and may be kept longer in specific cases such as abuse investigations or legal obligations. If and when stylized photo effects are offered, photos you select for stylizing will be processed by OpenAI under the same consent toggle, with API inputs excluded from model training.
AI output can be wrong. Review extracted recipes (especially quantities and cooking times) before relying on them.
| Service | What | Where |
|---|---|---|
| Supabase | Database, authentication, file storage, server functions | EU/US |
| Anthropic | AI processing (§5) | US |
| OpenAI | Stylized photo effects (when offered; only photos you choose to stylize; not used to train models) | US |
| Sentry | Crash and error reports | US/EU |
| PostHog | Analytics (consent-based) | US |
| Apple | App distribution, in-app purchases, Sign in with Apple | US |
| Sign in with Google (if you choose it) | US | |
| RevenueCat | Subscription management (when offered) | US |
| Lulu xPress | Printing and shipping your book (when offered; receives name + shipping address) | US + its delivery partners |
| Telegram | Recipe import for users who connect the bot; also the private channel your bug reports reach us through (§3.10), which applies whether or not you use the bot | per Telegram’s policy |
| Railway / Upstash | Hosting for the Telegram bot and its job queue | US/EU |
| Cloudflare R2 · Backblaze B2 | Off-site backup storage — configured, not yet in use (§7) | US/EU |
| GitHub (Actions) | Will run the backup job; the database export would pass through it before encryption — not yet in use (§7) | US |
| Vercel | Hosts spoonsketch.com, including this page and the waitlist form | US/EU |
Each provider processes personal data only to deliver its service to us, under its published data-processing terms; we maintain a register of these vendors and review their terms and safeguards as part of our privacy impact assessment. Note for Quebec residents (Law 25): your personal information is stored and processed on servers located outside Quebec (EU/US, per the table above); we assess each such transfer to ensure adequate protection. Where data leaves the EEA, transfers rely on the EU–Canada adequacy decision, EU Standard Contractual Clauses, and/or the EU–US Data Privacy Framework, as applicable.
Account and content — for as long as your account exists. Deleting your account (Me → Danger zone → Delete my account) removes your recipes, photos, drawings, cookbooks, Telegram connection, and AI logs. We hold no backups today (§7), so there is no second copy for it to survive in.
Backups — we currently keep none. A nightly encrypted backup to Cloudflare R2 and Backblaze B2 is built and configured but has never yet run successfully, so today nothing you delete survives in a second copy, and nothing you keep is protected by one either. When backups do start, deleted data may persist in them for up to 35 days before automatic expiry, and we will say so here on the day that becomes true rather than in advance.
Moderation records — the outcome of each safety scan (which bucket and file, the verdict, the time) is kept on a schedule, which continues after account deletion: a scan that found nothing is deleted after 12 months; a scan that rejected a file, or that failed, after 24 months. Only records under a legal hold — a suspected child-safety case, or an open report or law-enforcement request — are kept beyond that, for as long as the matter requires. When you delete your account, your account reference is removed from these records. They are not fully anonymous even then: each record names the storage path of the file that was scanned, and that path contains your account identifier. Reports you file about content are kept until they are resolved and for 24 months after that.
Consent records — retained as long as needed to demonstrate compliance.
Analytics data — kept no longer than 12 months; crash reports — no longer than 90 days. Neither is anonymous in the strict sense: both carry your account's internal identifier (§3.6). Deleting your account does not automatically erase what these two services already hold — that data expires on the schedules above, and if you want it removed sooner, write to privacy@spoonsketch.com and we will request its deletion.
AI request payloads — erased automatically after 30 days (§3.5). Waitlist IP hashes — deleted within 48 hours (§3.12).
Everyone, in-app, no email needed — all of it on the Me tab: export your data (Me → Privacy → “Export my data”; JSON, once per 24h — it contains your profile, recipes, cookbooks, page decoration, order history, Telegram connection, AI-usage counts and your full consent and Terms-acceptance history); delete your account and all data (Me → Danger zone → “Delete my account”); turn AI features or analytics on or off (Me → Privacy).
If you are in Canada (PIPEDA and, in Quebec, Law 25): you have the rights of access and rectification, the right to withdraw consent, and — under Law 25 — the rights to data portability and to be informed about and have reviewed any decision based exclusively on automated processing. You may complain to the Office of the Privacy Commissioner of Canada (OPC) or, in Quebec, to the Commission d’accès à l’information (CAI).
If you are in the EU/EEA/UK (GDPR): you also have the rights of access, rectification, erasure, restriction, portability, objection, and the right to withdraw consent at any time (without affecting prior processing). You may complain to your local supervisory authority.
If you are in Ukraine (Law No. 2297-VI): we extend you the rights set out in Article 8, including to know whether your data is processed, to access it, and to demand correction or deletion; you may also complain to the Ukrainian Parliament Commissioner for Human Rights (Ombudsman). When Ukraine’s new data protection law (draft No. 8153) enters into force, the rights it grants will apply automatically.
If you are a California resident (CCPA/CPRA): we do not sell or “share” personal information and have not done so in the preceding 12 months. You have the rights to know, delete, correct, and to non-discrimination for exercising them. The categories we collect are listed in §3 (identifiers; customer records; internet activity; coarse IP-derived region; user content). Exercise rights in-app (above) or by email. We honor requests regardless of whether the CCPA’s thresholds technically apply to us.
We respond to privacy requests within 30 days (GDPR/Ukraine) or 45 days (CCPA).
The App's App Store age rating describes its content (no objectionable material), not its audience. The App is not directed at children, and you must be at least 16 years old to create an account — a single global threshold. We do not knowingly collect personal data from anyone younger (this also satisfies COPPA, GDPR Art. 8 and Quebec Law 25). If you believe a child has created an account, contact us and we will delete it promptly.
Data is encrypted in transit (TLS) and at rest. On iPhone, session tokens are stored in the device’s secure keychain; in the web version the browser’s local storage is used instead, which is why we recommend the app for shared computers. One deliberate exception to “private by default”: a recipe’s cover photo is stored in a public bucket so it can be rendered in shares and print files, which means anyone holding its link can open it. Everything else — your uploaded photos, sources and bug screenshots — is private. Access to production data is restricted to the Operator. Database access is enforced with row-level security so each account can only ever read its own data. No system is perfectly secure — if a confidentiality incident presents a risk of serious injury, we will notify you and the relevant authority as required by law: the CAI and affected persons under Quebec’s Law 25, and the competent supervisory authority within 72 hours where the GDPR applies. We maintain the incident register Law 25 requires.
Each version of this Policy is dated, and the version you accepted is recorded with your account. When we change it materially we will tell you — by email to the address on your account, and by publishing the new version here with a new date. Continued use after a change constitutes acceptance. We are building an in-app prompt that shows a changed Policy and asks you to review it before continuing; until it ships, the notice is by email and on this page.
Anhelina Yermakova, Montreal, Quebec, Canada
Email: privacy@spoonsketch.com
We answer in English, Ukrainian, and French.