Skip to content

Privacy Policy

Effective 30 September 2026

The short version

  • We use your data to run Chefer: your plans, recipes, logs and workouts.
  • We never sell your data, and we show no ads.
  • AI features send your data to an AI provider only after you allow it.
  • Usage analytics use no cookies, and are linked to your account only if you opt in.
  • You can download your data or delete your account yourself, at any time.

Who we are

Chefer is run by Pop Dan-Vlad, an individual based in Romania, who is the data controller for the personal data described here. In this policy, “we” and “us” mean him. For anything about your data, email cheferapp.help@gmail.com. Chefer has no data protection officer, so write to the same address.

What we collect and why

For each kind of data: what it is, what we use it for, and the legal basis.

  • Your account: name, email address and password (stored only as a secure hash). Used to sign you in, to send account emails (confirming your address, resetting your password) and to keep your account safe. Basis: our contract with you.
  • What you put into the app: dietary preferences, disliked ingredients, goals, meal plans, recipes and the photos you add, shopping lists, pantry items, food logs, household members, units and an optional delivery address. Used to provide the features you ask for. Basis: our contract with you.
  • Health-related data: see the next section.
  • Weekly emails: a Monday “your week is ready” email and a Sunday recap, sent to your confirmed address. Basis: our legitimate interest in helping you use the plan you made. You can switch each one off in Preferences or with the unsubscribe link in the email.
  • Feedback you send with Send feedback, together with the page you were on. Used to fix and improve Chefer. Basis: legitimate interest.
  • Security and error data: IP address, browser or device type, and technical details of requests and errors. Used to keep Chefer running, to stop abuse (for example with limits on sign-in attempts) and to fix crashes. Basis: our legitimate interest in a secure, working service.
  • Usage analytics: which pages and features are used. Basis: legitimate interest for anonymous counts, and your consent for analytics linked to your account. See Cookies and analytics.

To create an account we need your name, email and a password. Everything else is up to you, but some features cannot work without it: calorie targets, for example, need your body metrics.

Health-related data

Some of what you can enter says something about your health: body metrics (age, sex, height, weight and weight history), goals and calorie targets, allergies and dietary restrictions, the meals you log, and your workouts, training history and training breaks. Details about the household members you add, such as their allergies, can be health-related too.

Under the GDPR this can be special-category data (Art. 9), so we process it only with your explicit consent. All of it is optional. The website and the app ask for that consent before the first time you save any of it, in a sheet that is separate from the AI permission below. If you choose Don't save it, none of it is stored. You can withdraw the consent at any time: on the website in Profile → Health information, in the app in Profile → Privacy & data → Health information, using Withdraw and delete. That deletes the allergies, diets, dislikes, goal, measurements and weigh-ins stored for you and your household. You can also delete individual entries or your whole account. Withdrawing does not affect what we did with the data before. If you already had an account before this consent existed, we keep what you entered and ask you the next time you open the app or website. We use the data only to run the features you use, such as working out your targets, filtering recipes and planning your training. We never use it for advertising.

When you add a household member, only add details they are happy for you to share.

AI processing

Plan generation, meal swaps, meal-photo scanning, recipe import, chat and AI shopping-list tidy-up send the relevant data (your preferences and allergies, goals and body metrics, the photo, recipe or message you submitted) to an AI provider — currently Groq; if Groq is busy, a request may be handled by our backup AI provider, Cloudflare Workers AI — to produce the result. We do not use your data to train models. Photos you scan or import are sent to the AI provider to be read; we do not store them. When you import a video link that has no caption or subtitles, its audio is transcribed by Groq and deleted right after.

We ask for your permission before the first AI feature sends anything, and tell you what that feature sends. If you choose Not now, nothing is sent. You can withdraw permission at any time in Profile → AI & your data, on the web or in the app; we then ask again before the next AI feature runs. The weekly plan and weekly review we prepare for you automatically follow the same choice: without your permission, nothing is sent to the AI provider for them. Basis: your consent (explicit consent for any health-related data included).

AI output and the targets Chefer calculates are automated suggestions. They do not lead to decisions with legal or similarly significant effects on you, and you can always change or ignore them.

Camera & photos

The iOS and Android app use your camera or photo library only when you choose to take or attach a photo — for example to scan a meal or add a recipe photo. Nothing is read in the background. Photos you attach to a recipe or an ingredient are stored on our server so you can see them.

Who receives your data

We share data only with the service providers below. They process it for us under contract, and each gets only what it needs.

  • Oracle Cloud Infrastructure hosts our servers and database in Frankfurt, Germany (EU).
  • Groq runs the AI features, only with your permission (see above). United States. Under its services agreement Groq does not use what we send to train models.
  • Cloudflare (Workers AI) is a backup AI provider, with the same permission. Cloudflare is a US company and runs the models on its global network, so a request may be processed outside the EU. Cloudflare does not use what we send to train models.
  • Sentry receives error reports and performance data from the website and our server. These can include your IP address, browser type and the page involved. The data is stored in Sentry's EU region (Germany); Sentry is a US company.
  • PostHog provides usage analytics for the website and, in app versions that have analytics switched on, for the app, stored in PostHog's EU cloud; PostHog is a US company. See Cookies and analytics.
  • Our email provider delivers account emails and weekly emails, so it receives your email address and the content of those emails. It may process data outside the EU.
  • Expo delivers updates to the iOS and Android app. When the app checks for an update, Expo sees your IP address and technical details of the app and device, but no account data. United States.

Recipe pictures are made by an image-generation service (currently Pollinations) from the recipe's name and cuisine only, and supermarket prices are looked up by ingredient name only. Neither receives anything about you.

Some pictures and videos in Chefer load from other hosts: recipe images (Unsplash, Pollinations) and exercise video thumbnails and videos (YouTube, in its privacy-enhanced mode). Your browser or app then contacts that host directly, which shows it your IP address, as with any website.

If you download the app, Apple (App Store) or Google (Google Play) handle the download under their own privacy policies. We may also disclose data where the law requires it, for example to a court or an authority.

Transfers outside the EU

Our servers and database are in the EU. Some of the providers above are based in the United States or other countries outside the European Economic Area, or may access data from there. When that happens we rely on the safeguards the GDPR provides: the European Commission's adequacy decision for the EU-US Data Privacy Framework, where the provider is certified under it, or the Commission's Standard Contractual Clauses. Email us for more information about these safeguards.

How long we keep your data

  • Your account and everything in it: as long as you have an account. When you delete it, it is removed from the live database straight away (see below).
  • Backups: the database is backed up daily. The server keeps the last 14 daily backups, and a second copy of the last 30 is kept on the operator's own computer in case the server fails. Deleted data therefore disappears from all backups within about 30 days. Backups are used only to restore the service after a failure.
  • Sign-in sessions expire after 30 days. Password-reset links expire after 1 hour.
  • Server logs, error reports and analytics are kept only as long as needed for security, fixing problems and understanding usage. They are then deleted automatically under the retention settings of our server, Sentry and PostHog.

Deleting your account

You can delete your account yourself at any time: Profile → Delete account, on the web or in the iOS and Android app (you confirm with your password). This removes your account and everything in it — preferences, plans, logs, recipes, uploaded photos, workouts, household and feedback — from the live database immediately, and signs you out on every device. Recipes that Chefer's AI generated for you contain no personal data; they may stay in the shared recipe collection with no link to you. You can download all your data first from Profile → Your data.

Your rights

Under the GDPR you have the right to:

  • access your data and get a copy (Profile → Your data, or email us);
  • have wrong data corrected (you can edit most of it in the app);
  • have your data erased (Profile → Delete account, or email us);
  • get your data in a portable, machine-readable format (the download is a JSON file with your account, plans, recipes, logs, workouts, consent history and a log of the AI requests made for you; your workouts can also be exported as a CSV from the Gym settings);
  • restrict how we use your data in some cases;
  • object to processing based on legitimate interest, such as weekly emails or anonymous analytics;
  • withdraw any consent at any time: AI in Profile → AI & your data, analytics in Profile → Usage analytics, health information in Profile → Health information (Withdraw and delete). This does not affect what we did before.

To use a right, email cheferapp.help@gmail.com from the address on your account. We reply within one month. You can also complain to a data protection authority. In Romania that is ANSPDCP (Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal), dataprotection.ro. You can also go to the authority in the country where you live or work.

Children

Chefer is for people aged 16 and over, the age of digital consent in Romania. We do not knowingly collect data from anyone younger. If you think a child under 16 has an account, email us and we will delete it.

Cookies and analytics

Cookies. The website sets only the cookies it needs to work: your sign-in session, and one that remembers whether you last used Food or Gym mode. We use no advertising or cross-site tracking cookies. The website also keeps a few of your own settings in your browser's storage (for example your notes on an exercise, or your analytics choice). They stay on your device.

Analytics. The website uses PostHog, hosted in the EU, to count which pages and features are used. It stores nothing on your device: no cookies and no local storage. When you are signed out, or signed in without opting in, the events are anonymous and not linked to you or your account. If you turn on Profile → Usage analytics, events are linked to your account ID and plan (never your name or email) so we can see how Chefer is used over time. You can turn it off again at any time. The choice applies to the browser you set it in. If your browser sends a “Do Not Track” signal, we send no analytics at all.

In the app. The iOS and Android app shows no ads and uses no advertising identifier. It can send the same kind of anonymous usage counts to PostHog (EU) as the website, but only in app versions that have analytics switched on; where they do, Profile → Privacy & data → Usage analytics has two switches. “Send anonymous usage counts” is on by default and sends counts of which screens and features are used, tagged with a random identifier made each time the app starts and never stored, with no name, email or health information. “Link usage to my account” is off unless you turn it on; when it is on, the counts can carry your account ID instead (never your name or email). Turning the first switch off stops all analytics requests from the app at once. The choice applies to the phone you set it on. The app keeps your sign-in in the device's secure storage and saves workouts on the device until they sync. Reminders are scheduled on your device.

Security

All traffic to Chefer is encrypted (HTTPS), passwords are stored only as secure hashes, and access to the servers is restricted. No system is perfectly secure. If a breach puts your data at risk, we will tell you and the authorities as the law requires.

Changes to this policy

When we change this policy, we update the effective date at the top. For important changes, such as a new use of your data or a new kind of provider, we tell you in the app or by email before they take effect, and ask for your consent again where the law requires it.

Contact

Questions about your data or this policy? Email cheferapp.help@gmail.com or see Help & support.

← Back to Chefer · Terms of Service · Support