Privacy Policy — Receptli

Effective from 17 September 2026 — version 2026-09-17. English translation; the Slovak version is the original.

1. Who processes your data

The controller is OnIT s. r. o., company ID 55 010 903, registered office Ľudovíta Fullu 3012/6, 841 05 Bratislava — Karlova Ves, Slovakia, entered in the Commercial Register of the Bratislava III City Court, section Sro, insert 164718/B. Contact: support@onit.sk. We have not appointed a data protection officer.

2. Summary

3. What we process and why

3.1 Account and sign-in

We store your e-mail address, account creation date, app language and recipe language. Sign-in uses a six-digit code sent to your e-mail; the code is valid for 10 minutes and we store only its hash together with the IP address it was requested from, the number of attempts and timestamps. The IP address limits the number of requests and ensures the code is verified by the same device that requested it. After sign-in we store hashes of the access token (15 minutes) and the refresh token (30 days of inactivity, at most 90 days). You can also sign in with Apple or Google. For such sign-in we store the provider's user identifier and the e-mail it supplied; the provider is an independent controller for its own sign-in service.

Legal basis: performance of a contract (Art. 6(1)(b) GDPR); securing sign-in and limiting abuse: legitimate interest (Art. 6(1)(f)).

3.2 Age confirmation and consents

Receptli is for people aged 18 and over. We keep a record of your age confirmation and of granting or withdrawing AI processing consent: type, text version, language, time granted and time withdrawn. We do not collect your date of birth.

Legal basis: performance of a contract and demonstrating consent (Art. 7(1) GDPR); legitimate interest in protecting a service intended for adults.

3.3 Recipes and household content

We store recipes (title, ingredients, quantities, steps, notes, classifications, tags, language, and the link to the source page where a recipe came from one), recipe drafts awaiting review, one recipe photo, your household's meal plan and shopping list, and for each record who created or last changed it. Content belongs to the household: all its members see and edit it. Household members see each other's e-mail addresses and who added a recipe; the owner also sees the number of AI drafts used by each member.

Recipes and notes may indirectly reveal diet, health or religion (for example gluten-free, diabetic or fasting cooking). You save them voluntarily for your own use; we build no profiles from them. Photos of notebooks and pages may contain other people's data — upload only what you are allowed to, and remove unnecessary data first.

Legal basis: performance of a contract (Art. 6(1)(b)).

3.4 Import source files

For an import we store the source the draft is made from: photos and screenshots (JPEG, PNG, WebP, HEIC), PDF pages, text downloaded from a link, pasted text, the caption and video of a social media post, and a suggested recipe photo downloaded from the page or post. Source files are encrypted in storage (AES-256-GCM), have non-public identifiers and are read only by a signed-in household member while reviewing the draft. Once the draft is saved as a recipe or discarded, we delete the source files within 24 hours; a saved recipe no longer has access to them. A post video is never displayed and is deleted immediately after processing.

Legal basis: performance of a contract (storage and display during review); sending them to the AI provider rests on the consent in 3.5.

AI import starts only after your explicit consent in the app ("Privacy & AI"), which you can withdraw in the same place at any time. Withdrawal stops further sending; recipes already created remain and you can delete them yourself.

What is sent to the AI provider Google (Gemini API): the selected photos and PDF pages as full images, text downloaded from a link or pasted text, a post's caption and its video, together with our instruction and, where requested, a request to translate into the app language. The model therefore sees everything on the submitted pages, including any handwritten notes. Not sent: your e-mail, account or household identifier, the recipe photo, other recipes. A video larger than 12 MB is uploaded to Google's temporary file storage and deleted after processing.

We use AI through the paid tier of the Gemini API (Google LLC, USA) with billing enabled, not through a public chat product or the free tier. Under Google's terms for paid Gemini API services, inputs and outputs are not used to improve Google products, and Google processes them as our processor under its Data Processing Addendum; Google does, however, document temporary retention for abuse monitoring. We do not promise zero retention at Google.

Instagram and TikTok posts are read for us by Apify (Apify Technologies s.r.o., Prague, Czech Republic). Apify receives only the cleaned link to the post (without tracking parameters) and returns its caption, video and thumbnail; it never sees your account or e-mail. Videos longer than 3 minutes are not downloaded.

A link to an ordinary web page is fetched directly by our server; we write the page's domain, your account identifier and the outcome to the operations log so that we can limit abuse of our service against third-party sites.

AI output may be wrong or incomplete; you review every draft before saving. This is not automated decision-making with legal effects.

Legal basis: your consent (Art. 6(1)(a)); to the extent a source contains your own sensitive data, explicit consent (Art. 9(2)(a)). Your consent does not authorise processing other people's sensitive data.

3.6 Subscription

The household owner buys the subscription in the App Store or Google Play. At purchase the app sends your household identifier to RevenueCat as the customer identifier, together with the purchase data supplied by the store and the SDK (transaction and product identifiers, platform and technical device data). Our server reads the subscription state from RevenueCat and stores: store, product, purchase identifier, start and end of the paid period, whether renewal is on, and the state (active, grace period, ending, refunded, locked). We also keep an AI allowance ledger: the time, number of drafts and pages of each successful import and who performed it. We never receive card numbers or billing details; the stores are independent controllers for the payment.

Legal basis: performance of a contract (Art. 6(1)(b)).

3.7 Invitations and sharing

A household invitation is a code valid for 7 days; we store its hash and the time it was created, accepted or revoked. A recipe share link is valid for 7 days; we store the token hash and your display name derived from the part of your e-mail address before "@". Whoever opens the link sees, without signing in, the recipe's title, ingredients, method and photo and this name; a copy saved by the recipient carries it permanently. Source files are never shared.

Legal basis: performance of a contract (a feature you triggered).

3.8 Notifications and device permissions

Cooking timers use your device's local notifications; they are scheduled on the phone and send nothing to our server. We collect no push tokens. Camera and photo access is used only to pick a source or a recipe photo when you ask for it; metadata is stripped from photos when they are resized.

3.9 Data on the device

The app keeps a copy of recipes, the meal plan and the shopping list on the device (SQLite) for offline use, a queue of unsent changes, sign-in tokens in the system's secure storage, and your settings. This data syncs with the server; signing out and uninstalling removes it from the device. We use no cookies.

3.10 Operations, security and support

Server logs contain the request identifier, error code, timings and limits; never recipe content, sources or e-mails in error text. We back up the database and the encrypted file storage daily on the same server. If you write to us, we process your message and whatever you attach; do not send sign-in codes or other people's sensitive documents.

Legal basis: legitimate interest in secure and reliable operation and in defending claims (Art. 6(1)(f)); support: performance of a contract.

4. Recipients and transfers outside the EU

Recipient Role What it receives Location Contract and transfer safeguard
Hetzner Online GmbH hosting of the server, database, storage and backups all server-side data Germany (EU) processor; data does not leave the EU
Google LLC (Gemini API) AI processing of sources with your consent the selected sources per 3.5 USA; processing may also occur outside the EEA processor under the Google Cloud Data Processing Addendum; EU-U.S. Data Privacy Framework certification and standard contractual clauses
Apify Technologies s.r.o. reading Instagram and TikTok posts the cleaned link to the post Prague, Czech Republic (EU); Apify's sub-processors may run outside the EU, their list is available from Apify processor under the Apify Data Processing Addendum (docs.apify.com/legal/data-processing-addendum)
RevenueCat, Inc. verifying and recording store purchases household identifier, purchase and device data from the SDK USA processor under the RevenueCat DPA (revenuecat.com/dpa); EU standard contractual clauses
Resend (Plus Five Five, Inc.) delivery of sign-in code e-mails e-mail address and code USA processor under the Resend DPA (part of the agreement for every account); EU-U.S. Data Privacy Framework certification and standard contractual clauses
Apple (App Store) and Google (Google Play) sale of subscriptions, payments, refunds; app distribution your store data; we receive only transaction identifiers independent controllers the store's own terms

For transfers to the USA we rely, for each recipient, on the safeguard listed in the table: certification under the EU-U.S. Data Privacy Framework (a Commission adequacy decision) and the Commission's standard contractual clauses, which form part of the data processing addendum with that recipient. Support can provide a copy of the relevant clauses on request. We disclose data to no other third parties unless required by law.

5. How long we keep data

Data Period
Account, e-mail, consents, settings for the life of the account; removed from active systems immediately when the account is deleted
Sign-in code records (including IP) the code is valid for 10 minutes; the record is deleted after 30 days
Sign-in sessions until sign-out or expiry (30 days of inactivity, at most 90 days); the record of an ended session is deleted after 30 days
Recipes, meal plan, shopping list, recipe photos until you or another household member deletes them, or until the account is deleted or the household dissolved
A replaced or removed recipe photo deleted 30 days after replacement or removal
Import source files (photos, PDF, text, link content) while the draft awaits your review; once the draft is saved as a recipe, discarded or the import fails, a daily server job deletes them within 24 hours; an interrupted import after 1 day at the latest
Social media post video deleted immediately after processing, at the latest 10 minutes after an interrupted import
Household invitations and share links valid for 7 days; the record is deleted 30 days after expiry, acceptance or revocation
Subscription state and AI allowance ledger for the life of the household
Locked household (subscription expired) kept so that you can come back, until you delete the account; you can export your data even from a locked household
Daily backups 14 days; data deleted from active systems disappears from backups after 14 days
Server operations logs at most 90 days

You delete your account directly in the app; if that is not possible, ask support by e-mail. Deletion is immediate: we remove the account, all sign-ins, the consent records and your own household with all its recipes, meal plan, shopping list, photos and source files; share links you created stop working. The owner of a household with other members transfers ownership first. Recipes, meal plan and shopping list entries you added to a shared household stay with that household and its owner is shown as their author from then on. Deleting the account does not cancel the subscription in the App Store or Google Play — cancel it in the store. Data disappears from backups after 14 days.

6. Your rights

You have the right of access, rectification, erasure, restriction, portability and objection under Art. 15 to 21 GDPR. You withdraw AI processing consent in the app as easily as you granted it; withdrawal does not affect the lawfulness of earlier processing. You may object to processing based on legitimate interest on grounds relating to your particular situation.

You download your recipes via the basic export in the app (a JSON file with your household's recipes, without photos; it also works in a locked household) or by asking support. Send requests to support@onit.sk, even if you have no account or are a person captured in someone else's photo. We verify identity proportionately to the risk, usually via the account e-mail. We respond without undue delay and within one month at the latest; for complex requests we may extend by a further two months and will tell you.

You may lodge a complaint with the Office for Personal Data Protection of the Slovak Republic (Úrad na ochranu osobných údajov SR), Galvaniho 7/B, 821 04 Bratislava, www.dataprotection.gov.sk, or with the supervisory authority in the state of your habitual residence.

We make no automated decisions with legal or similarly significant effects (Art. 22 GDPR). An AI recipe draft is an aid that you edit.

7. Children

Receptli is not intended for people under 18 and we do not knowingly process their data. If we learn that an account belongs to a minor, we delete it.

8. Security

The connection to the app is encrypted (TLS). Source files and recipe photos are encrypted on disk with a key kept separately from the data, tokens and codes are stored only as hashes, the server runs under its own account with restricted access, and the database is separated from the operator's other services. Only people who need access for operation and support have it.

9. Changes

When processing changes materially we update this document and inform you in the app or by e-mail. If a change requires new consent, we ask for it before the processing in question; continued use does not replace it. The Terms of Use are a separate document: https://receptli.onit.sk/en/terms.