BroccoliciousBack to home

Privacy

Privacy Policy

Effective August 20, 2026 · Version 1.3

This Policy explains what personal data Broccolicious handles in its current free beta, why we use it, who helps us process it, and the choices available to you.

1. Controller and contact

Z. Galili, trading as Broccolicious, based in the Netherlands, is the controller of the personal data described in this Policy.

For privacy questions, rights requests, account deletion, legal matters, or support, email support@broccolicious.app.

2. Age and guardian-managed accounts

Broccolicious is for users aged 13 and older. A user aged 13 to 15 may use the service only through an account created and controlled by their parent or legal guardian. The guardian should contact us about privacy requests for that account.

If you believe a child is using Broccolicious outside these conditions or provided personal data improperly, contact us so we can investigate and take appropriate action.

3. Personal data we handle

Account and authentication data. Your email address, Supabase user identifier, account creation date, authentication records, and basic profile information returned by Google or Apple when you choose those sign-in methods.

Legal acceptance evidence. Your account identifier, the Terms and Privacy Policy versions presented to you, the signup surface and platform, authentication provider, affirmative-checkbox method, and acceptance timestamp. For initial signup, the account creation time is also recorded as the acceptance time.

Waitlist data. The email address you submit, the App Store or Google Play beta you select, your waitlist status, and related timestamps. Browser and operating-system signals are used on your device to suggest a store choice. The selected store, rather than those raw signals, is saved as a waitlist field; device or browser information may also appear in normal request logs as described below.

Recipe and source data. Submitted URLs, original and canonical source links, source platform and creator details, extracted titles, descriptions, ingredients, steps, tags, language, timings, servings, warnings, confidence information, nutrition data, and the structured extraction result.

Recipe images. A source image URL and, for some social sources, a cached copy stored under an account-specific path so the recipe remains usable when the original temporary image URL expires. When you import from a photo and choose Save, the normalized JPEG source photo is stored privately with that recipe.

Library, shopping, and activity data. Saved recipes, shopping-list items and their recipe sources, cook counts, cook-completion identifiers, and recipe-import counts.

Food preferences and profile data. Your selected eating pattern, dietary restrictions, EU-listed allergens, other allergy words or phrases you enter, household size, cooking skill, main goal, how you heard about Broccolicious, onboarding completion timestamps, and whether you successfully imported a first recipe. Food preferences can reveal health-related or religious information. You choose whether to provide optional profile details and can edit these fields in the app.

Import problem reports. When you choose “Report problem” after a failed import, we store your account identifier and email, the submitted source URL, error type, error message, report status, and timestamps.

Device-local data. Authentication session information, a pending shared recipe URL, shopping-list display preferences, and similar settings stored on your device.

Technical and security data. IP address, request timing, request identifiers, device or browser information, service logs, and error details made available to us or our hosting providers.

Support correspondence. Your email address and the contents and metadata of messages you send to us.

4. How recipe import works

When you submit a link, our servers request publicly available content from the source website or social platform. The requested URL and relevant public recipe text or metadata may be processed by retrieval services and Google Gemini to produce a structured recipe.

When you choose a recipe photo, the app corrects orientation, removes metadata, resizes it, and sends the normalized JPEG to Google Gemini so it can transcribe and structure the recipe. The result may include uncertainty and AI-inference warnings for you to review. A canceled or failed scan is not intentionally retained by our server. If you confirm Save, the app uploads the normalized photo again and Supabase stores it privately with the saved recipe so you can view the source later.

We do not intentionally send your Broccolicious account email to Gemini as part of recipe extraction. Source websites may receive the server address, user agent, requested URL, and normal request information when content is retrieved.

5. Why we use personal data

We use personal data to:

  • create and secure accounts and keep you signed in;
  • record which legal documents you accepted when your account was created;
  • retrieve, extract, translate, save, search, and display recipes;
  • provide shopping-list, cooking-history, and account features;
  • remember your food preferences, hide redundant matching diet labels, and show basic possible-allergen warnings;
  • manage beta access and respond to support or privacy requests;
  • diagnose failed imports, prevent abuse, and keep the service reliable and secure;
  • understand basic operational usage through account-level counts; and
  • meet legal obligations and establish, exercise, or defend legal claims.

6. Legal bases

Where EU or UK data-protection law applies, we rely on performance of our agreement with you to provide requested account and product features; our legitimate interests in operating, securing, supporting, and improving the beta; compliance with legal obligations; and consent where the law requires it for a specific optional activity.

You may object to processing based on legitimate interests. We will assess the request against our reasons for processing and your rights.

Where food preferences reveal health information, religious beliefs, or other special-category data, we rely on your explicit choice to provide and use that information for the requested profile and warning features. You may change or remove those preferences in the app and may withdraw that consent by removing the data, without affecting earlier lawful processing.

7. Service providers and recipients

We use the following named providers and recipients to operate Broccolicious:

  • Supabase for authentication, the Postgres database, public recipe-image storage, and private photographed-recipe source storage. The current Broccolicious project is hosted in Supabase’s EU North region.
  • Vercel for hosting the public website, content delivery, networking, security controls, and website request logs.
  • Railway for API hosting, networking, health checks, and operational request logs.
  • Google for Gemini recipe extraction and translation, YouTube Data and oEmbed retrieval, Google Custom Search fallback, Google sign-in when selected, Gmail support handling, Google Play distribution or beta access, and Search Console for public-site indexing and aggregate search performance.
  • Apple for Apple sign-in when selected and App Store or TestFlight distribution.
  • Meta for public Instagram and Facebook content or oEmbed retrieval when those sources are submitted.
  • TikTok for public TikTok content and oEmbed retrieval when a TikTok source is submitted.
  • Jina AI as a text-extraction fallback when a submitted public recipe page cannot be read directly.
  • LinkinProfile to discover publicly linked recipe pages associated with a submitted creator profile when needed.
  • SerpApi, Brave Search, and DuckDuckGo as conditional search fallbacks. When used, they receive search terms derived from public creator names, source titles, or recipe titles; we do not intentionally include your Broccolicious account email in those queries.
  • Cloudflare for domain and email-routing infrastructure used to receive messages sent to our support address.
  • Expo and EAS for building and distributing mobile application binaries. The Broccolicious app does not intentionally send account or recipe content to Expo as part of normal product use.
  • Public recipe websites and social platforms receive normal request information when our servers retrieve a URL you submitted. Their own terms and privacy notices apply to their services.

Providers process data under their own terms or on our instructions, depending on the service. We may also disclose information where required by law, to protect rights and security, or in connection with a lawful transfer of the service.

We do not sell personal data. The current beta has no advertising network, cross-service behavioral advertising, or third-party product-analytics SDK.

The current beta does not use a dedicated third-party crash or error-monitoring service. If we introduce one and it will receive personal data, we will update this Policy and the provider list before enabling that processing, and request consent where the law requires it.

8. International transfers

Some providers may process data outside the European Economic Area. Where required, we rely on an adequacy decision, approved contractual safeguards such as Standard Contractual Clauses, or another lawful transfer mechanism.

9. Cookies and device storage

Authentication may use cookies or similar technologies where the web service needs them. The mobile app stores session information and product preferences locally on your device. These technologies are used to provide requested features, security, and continuity.

Broccolicious does not currently use optional advertising or product-analytics cookies. If that changes, we will update this Policy and request consent where required before enabling them.

10. Retention

Account, recipe-library, shopping-list, and activity data is generally kept while your account remains active. Individual recipe records, cached images, and privately retained source photos are removed when you delete the recipe, subject to normal processing and backup cycles.

Waitlist data is kept while reasonably needed to manage beta invitations and follow-up, or until you withdraw. Import problem reports are kept while needed to diagnose recurring failures and improve reliability. Support records and technical logs are kept for as long as reasonably needed for support, security, incident response, dispute handling, or legal compliance.

Legal acceptance evidence is kept while the account is active. After account deletion, we may retain the limited account identifier, legal-document versions, acceptance method and timestamp, and related audit fields only for as long as reasonably necessary to meet a legal obligation or establish, exercise, or defend legal claims. It is not used for product personalization or marketing.

When data is no longer needed, we delete or anonymize it. Limited copies may remain temporarily in backups or be retained where the law, security, fraud prevention, or a legal claim requires it.

11. Account deletion

To request deletion, email support@broccolicious.app from the address connected to your account and state that you want your Broccolicious account deleted.

We may ask for information needed to verify the request. After verification, we will delete the account and associated profile, food-preference, recipe, shopping, activity, report, cached-image, and private recipe-source-photo data unless we must retain limited legal-acceptance, transaction, fraud-prevention, or security evidence for a legal reason. Any retained legal-acceptance evidence is restricted as described in the retention section. Deletion of the remaining account data is permanent.

12. Your privacy rights

Depending on where you live, you may have rights to access, correct, delete, restrict, or object to processing; receive a portable copy of data you provided; and withdraw consent without affecting processing that was lawful before withdrawal.

Send requests to support@broccolicious.app. We may need to verify your identity and will respond within the period required by applicable law. You also have the right to complain to the Dutch Data Protection Authority or the competent authority where you live or work.

13. Security

We use reasonable technical and organizational safeguards, including authenticated access, row-level database access controls, transport encryption, and account-scoped storage paths. No online service can guarantee absolute security. Use a strong, unique password and contact us if you suspect unauthorized access.

14. Changes to this Policy

We may update this Policy when the service, providers, or law changes. The effective date and version above identify the current Policy. We will provide reasonable notice of material changes.

We will review this Policy before launching payments, analytics, advertising, household sharing, or a new material processor.

Broccolicious

Saved recipes, ready for real life.

TermsPrivacyContact