Legal
Privacy policy
Last updated: 26 August 2026
The short version
We collect personal data, and this page says plainly what it is: your account email and name, a securely hashed password, basic Google profile details if you sign in with Google, your saved recipes, plans and preferences, ratings and feedback taps, lead-form emails, marketing-consent records, your membership status and - if you buy a membership - a payment-customer reference, plus technical data such as IP address and user agent that our infrastructure provider processes to serve and protect the site. Marketing email is strictly opt-in. We do not run ads, we do not sell personal data, and we use no tracking cookies - our only analytics is cookieless and aggregate (see the cookies section).
We never ask for medical information
No form on this site asks for a due date, symptoms, diagnoses, conditions or medical records, and we do not want them - please do not put medical details in free-text fields like recipe notes. Be aware, though, that some things you choose in the app - a selected life phase, saved recipes, a meal plan - may indicate that you or someone in your household is trying to conceive, pregnant or postpartum. We treat that kind of preference data with special care: we use it only to operate the service for you and to send email you have consented to, we never sell it or share it for advertising, and we erase it when we erase your account.
What stays on your device
Display preferences (dark mode, units, filters) are stored in your browser's local storage. Without an account, planner entries, saved recipes, shopping lists, notes and ratings exist only for your current visit and are not sent to us.
Two small, deliberately anonymous exceptions: we keep an aggregate count of recipe searches - the search text and how often it was searched, including when it found nothing - and when you tap "I made this" or a rating-feedback reason we log that tap. Search text never carries any account or visitor identifier; feedback taps carry your account id only when you are signed in. We use this only to fix content gaps and recipes.
Cookies, browser storage and anti-bot checks - the complete list
We set only what the service needs, and nothing that tracks you across sites:
- Sign-in session cookies (set only when you sign in) - strictly necessary to keep you signed in; HTTP-only and first-party.
- Local storage - your display preferences (and, before you sign in, nothing else that persists); signed in, a small hint that you have a session.
- Session storage - briefly remembers a consent-checkbox choice across a Google sign-in redirect, then is cleared.
- Cloudflare Turnstile protects our sign-up and notify forms from bots. When one of those forms is on screen, Cloudflare processes technical signals such as your IP address, user agent and TLS characteristics strictly to tell humans from bots; per Cloudflare's published Turnstile policy these signals are not used to identify, profile or target individuals. This is an essential security check, not tracking.
There are no advertising or tracking cookies. For traffic statistics we use two cookieless tools. Cloudflare Web Analytics, per Cloudflare's published description, is cookieless and aggregate: it sets no cookies, stores nothing in your browser, builds no visitor profiles and does no cross-site tracking - we see page counts and performance, never individuals. We also run Rybbit, an open-source analytics tool self-hosted on our own server: it sets no cookies, stores nothing in your browser and does no cross-site tracking; to count visits it uses a salted identifier that resets every day, so it cannot recognize you across days or build a profile - we see aggregate page and session counts, never individuals. Because we use only strictly necessary cookies and checks, no cookie consent banner is required. Our infrastructure provider (Cloudflare) may process technical request data such as IP address and user agent to deliver and protect the site. This section is the complete list of what we knowingly set; if that ever changes, this page changes first.
Email signups
When you submit the "get notified about membership" form, we store: your email address, the page it was submitted from, and a timestamp. We use it only to send you the thing you asked for. The form also has an optional, unticked checkbox for occasional tips, guides and offers - if you tick it, we record the time and the wording you agreed to, and you can unsubscribe at any time; if you leave it unticked, the launch email is the only email you get. We may also add it to our own customer-relationship tool. You can request deletion at any time by emailing us.
Accounts and your saved content
If you create an account we store: your email address, your name if you provide one, a securely hashed password (never the password itself), your membership status, and session records so you stay signed in. If you sign in with Google, we receive your name, email and profile picture from Google; we do not receive or store your Google password.
Signed in, your saved recipes, weekly planner, shopping lists, private notes and ratings are stored with your account on our servers so they follow you across devices. On your first sign-in we ask before importing anything previously saved in that browser. This content is yours: ask us to erase your account and it goes with it (see Your rights).
Marketing emails (opt-in only)
Creating an account never signs you up for marketing. At signup, and later in your account settings (Email preferences), you can tick an unticked box to receive occasional tips and offers by email. If you do, we record the time and the exact wording and version you agreed to - that record is our proof of your consent. Consent comes with a thank-you: bonus recipes unlock for consenting accounts; withdrawing it simply re-locks the bonus set and returns your account to the standard free tier, nothing else changes. You can withdraw at any time in Email preferences or by emailing us, and every marketing email will include a way out. We only ever send campaigns to addresses whose consent is active at the moment of sending.
Payments
Payments are processed by Dodo Payments, acting as merchant of record - the seller of record for your purchase. Card details go directly to Dodo and never touch our servers. When you buy, we store your membership status and a Dodo customer reference so your purchase unlocks your account, and Dodo processes your payment data under its own privacy policy as an independent controller. Membership is not yet on sale.
Where data lives and international transfers
The site runs on Cloudflare's global network; server-side data (email signups, accounts, saved content) is stored in Cloudflare-hosted databases, and Cloudflare acts as our processor under its data processing addendum. Cloudflare states that it is certified under the EU-U.S. Data Privacy Framework and that its DPA incorporates the EU Standard Contractual Clauses as a fallback for restricted transfers; request metadata may be processed in its data centers in the United States and Europe. Dodo Payments states in its privacy policy that it relies on adequacy decisions and Standard Contractual Clauses for transfers outside the EEA/UK. We do not transfer your data to any other third country ourselves.
How long we keep things
- Account data and saved content: for as long as your account exists, then erased on request (see below).
- Consent records: for as long as your account exists, including the revocation record if you withdraw.
- Lead-form emails: until we have sent what you asked for and you no longer want it - deletion on request at any time.
- Aggregate search counts and anonymous feedback: kept, because they contain nothing traceable to a person.
- Technical logs and Turnstile signals: handled by Cloudflare under its own retention.
- Payment records: held by Dodo Payments under the retention obligations of a merchant of record.
Your rights
Under the GDPR you can ask what we hold about you, get a copy, correct it, restrict or object to processing, or have it erased. Email hello@onemorespoon.app from your account address and we will act on it promptly - within days in the normal case, and always within the legal one-month limit. When we erase an account we erase the account, saved content, ratings, feedback, sessions and marketing records together; encrypted backups age out within 30 days; records held by Dodo Payments as merchant of record are retained by Dodo under its legal obligations; and aggregate, non-identifying statistics are retained because they contain nothing traceable to a person. You also have the right to complain to the Cyprus Commissioner for Personal Data Protection or the data-protection authority where you live.
Lawful bases, in one place
- Operating your account, saving your content, unlocking what you bought: performance of a contract (Art. 6(1)(b) GDPR).
- Marketing email and the notify list: your consent (Art. 6(1)(a)), withdrawable at any time.
- Anti-bot checks, rate limiting, security and infrastructure logs: legitimate interests (Art. 6(1)(f)) in keeping the service safe.
- Aggregate, identifier-free statistics: legitimate interests (Art. 6(1)(f)) in understanding and improving the site without tracking anyone.
- Payment processing and tax records: contract and legal obligations, largely in Dodo Payments' hands as merchant of record.
Who we are
The data controller is Simov Studio LTD, registered in Cyprus. Contact: hello@onemorespoon.app.