Last updated: October 10, 2026
Privacy Policy
This policy explains what information Chefra LLC (“we”, “us”) collects, how we use it, and the rights you have over it.
1. Who we are
Chefra is a social recipe platform where you save, share, and organize recipes. Chefra is operated by Chefra LLC. You can reach us at privacy@getchefra.com for any privacy question, or support@getchefra.com for general support.
2. Information we collect
- Account data: email address, password (stored hashed), display name, optional avatar.
- Profile information: bio, username, links, and any other details you choose to add.
- Recipes and user content: recipes, posts, comments, cookbooks, meal plans, grocery lists, and any images you upload.
- Imported content: the links you import from and what we bring in from them — the recipe's ingredients, steps, times, servings and tags, and a copy of its main photo. We don't keep the author's introduction or story. What we read from a link is also kept for 7 days and then deleted, so importing the same link again, by you or anyone else, gives the same recipe without reading the page again.
- Usage data: pages viewed, actions taken, approximate device and browser type, IP address, and timestamps.
- Payment information: if you subscribe to premium, billing details (card number, expiration, billing address) are collected and processed by Stripe. Chefra never receives or stores your card details — only your subscription identifiers and status.
- Direct messages: the messages you send and receive in Chefra's direct-message and Kitchen conversations, including any recipes or images you attach to them. We store them so the conversation is there when you come back, and so we can act on a report of abuse.
- Crash logs, diagnostics, and performance data: when the app or website hits an error, we record the error message and stack trace, the page or screen you were on, your IP address, and approximate timing information about how the app performed. On a sample of sessions, and on sessions where an error occurs, we also record a masked replay of the session — see Sentry in §5.
- Device notification token: if you turn on push notifications, we store the token your device's push service issues to Chefra — Apple Push Notification service on iOS, Firebase Cloud Messaging on Android. It identifies your device to that service so we can deliver the alerts you opted into. It is stored against your Chefra account, it goes away when you turn push notifications off for that device or delete your account, and it is pruned automatically once the push service reports it as no longer valid.
- Launch and news sign-ups: you can leave your email address on our website to hear when a feature launches, without creating an account. We store that address, which feature you asked about, and when you signed up. If you also tick “Also send me occasional Chefra news,” we record that choice too.
3. How we use your information
- To operate, maintain, and improve Chefra.
- To personalize your feed, search, and recommendations.
- To process payments and manage your subscription.
- To secure accounts and prevent abuse, fraud, and spam.
- To send service-related messages (you can opt out of non-essential email).
- To send marketing and promotional communications — such as product updates, new features, tips, and special offers — where permitted. You can opt out of these at any time using the unsubscribe link in any marketing email, without affecting service-related messages you still need to receive.
- To respond to your requests and provide customer support.
- To comply with legal obligations.
- To email you once when the feature you signed up for is available, and — only if you ticked the news box — to send you occasional Chefra news.
4. Cookies and Analytics
Chefra uses essential cookies (authentication, security) and analytics cookies (aggregate usage patterns). We do not use advertising cookies and do not serve behavioral advertising.
One distinction is worth drawing plainly, because app-store privacy labels use the word "marketing" for both. We do send first-party marketing email — product updates, new features, tips, and offers from Chefra about Chefra — to the address on your account, and you can unsubscribe from it at any time (§3). That is a message from us to you. It is not behavioral advertising: we do not build advertising profiles, we do not track you across other companies' apps or sites, and we do not share or sell your email address for anyone else's advertising.
Because we use only essential and analytics cookies, we do not currently require an opt-in consent banner. If we add advertising cookies in the future, we will implement a compliant consent mechanism with equally prominent accept and reject options.
5. Third-party services we use
We rely on the following service providers to run Chefra. Each is bound by contract to protect your data and to use it only to provide their service to us:
- Supabase — database, authentication, and file storage for your account, recipes, and images.
- Stripe — payment processing and subscription billing.
- RevenueCat — subscription management for the iOS and Android apps. Unlike the import services below, RevenueCat does hold data about you: it receives an app user identifier tied to your Chefra account and your purchase history, and it is the system that decides whether your account has an active Premium entitlement on a mobile device.
- Cloudflare — hosting, content delivery (CDN), and security/DDoS protection.
- Google LLC (Gemini) — AI processing of recipe text and images: recipe import and parsing, nutrition estimates, title and description suggestions, content moderation, grocery-list import and aisle setup. Called directly by Chefra.
- Resend — email delivery. This covers both transactional email (sign-in confirmations, password resets, billing receipts) and the first-party marketing email described in §3 (product updates, new features, tips, and offers), which you can unsubscribe from at any time. Resend receives your email address and the content of the message we send you.
- Sentry — error monitoring and session replay. When the app or website hits an error, Sentry receives the error message and stack trace, the page or screen you were on, your IP address, browser and device type, and the account identifier of the signed-in user. Sentry also records a replay of a sample of ordinary sessions and of every session in which an error occurs. Those replays are captured with text masking and media blocking switched on, so the words you typed and the images on screen are not transmitted; what is captured is the structure of the page and the timing and position of your interactions. Sentry processes this data in the USA.
- Pexels — stock photo search. When you search for a photo, Chefra's servers send your search words to Pexels; your browser loads the search thumbnails directly from Pexels while the picker is open. The photo you choose is copied into Chefra's own storage, so people viewing your recipe or cookbook never connect to Pexels.
- Apify — fetches publicly available content from Facebook and TikTok links you paste into the importer. Chefra's servers send Apify the link you pasted and nothing else. Apify receives no account data of any kind: not your name, email address, account identifier, or device information — and because the request is made by our servers rather than by your device, Apify never sees your IP address either.
- Supadata — fetches captions and transcripts for YouTube, TikTok, and Instagram links you paste into the importer, on exactly the same basis: the link you pasted, and nothing about you.
- Firecrawl — reads public grocery-retailer websites so Chefra can sort your grocery list into the aisle order of the store you shop at. Firecrawl receives the retailer's public web address and nothing about you — not your name, email address, account identifier, or device information, and not your IP address, because the request is made by our servers.
- Instacart (Maplebear Inc.) — only when you tap Shop on Instacart on a grocery list, we send Instacart that list's title, the items still to buy (names, amounts and units) and a link back to the list in Chefra, so Instacart can build a shopping page for you. We don't send your name, email or account details. What you do on Instacart, including any order, is covered by Instacart's privacy policy, and Chefra may earn a commission on purchases.
- Apple Push Notification service (APNs) — delivery of push notifications on iOS devices when you opt in; your device's notification token is shared with this service to route the message.
- Firebase Cloud Messaging (FCM) — delivery of push notifications on Android devices when you opt in; your device's notification token is shared with this service to route the message.
- Google & Apple OAuth — when you choose "Continue with Google" or "Continue with Apple", the provider returns a verified email and a unique account identifier. We do not receive your provider password.
Prompts and content sent to AI features are processed solely to generate responses; under our agreements, these providers do not use that content to train third-party models.
We may also disclose information when required by law or in response to valid legal process, and in the event of a merger, acquisition, or sale of assets. We do not sell your personal information.
6. Sub-Processors and Third-Party Services
To operate Chefra, we share data with these sub-processors:
- Supabase — Database, authentication, file storage (USA)
- Stripe — Payment processing, subscription management (USA)
- RevenueCat — Subscription management and entitlement for the mobile apps (USA)
- Google LLC (Gemini) — AI processing of recipe text and images: recipe import and parsing, nutrition estimates, title and description suggestions, content moderation, grocery-list import and aisle setup. Called directly by Chefra.
- Google LLC — Android push notifications via Firebase Cloud Messaging (USA)
- Apple Inc. — iOS push notification delivery (APNs) (USA)
- Firecrawl — Reading public grocery-retailer websites for aisle and department names, to order your grocery list (USA)
- Instacart — Building a shopping page from a grocery list you choose to send; receives that list's title, its items still to buy and a link back to the list (USA)
- Apify — Fetching public content from Facebook and TikTok URLs you import (USA)
- Supadata — Fetching captions and transcripts from video URLs you import (USA)
- Cloudflare — Content delivery, DDoS protection, bot/abuse prevention (Turnstile) (USA)
- Resend — Transactional and first-party marketing email delivery; receives your email address and message content (USA)
- Sentry — Error monitoring, crash and performance diagnostics, and masked session replay; receives error payloads, IP address, page or screen path, device and browser type, and account identifier (USA)
- Pexels — Stock photo search; receives your search words and, while the picker is open, your browser's request for result thumbnails (USA)
If you use AI-assisted features (recipe import, parsing, nutrition estimation, or moderation), your input — such as recipe text, URLs, images, or grocery items — is sent to the AI model provider (Google) for processing. Google processes this data solely to return the requested result and does not use it to train its models under our agreement.
7. How Long We Keep Your Data
- Account and profile data: Life of account. Deletion is immediate — when you delete your account, the account record and the data linked to it are removed from our database at that moment, not queued for later processing. There is no waiting period for that removal. Some data outlives it and is listed below.
- Recipe and content data: Life of account. Deleted content is removed promptly but may persist in backups up to 30 days.
- Consent records: At least three years, or one year after account termination.
- Billing records: Seven years for tax and legal compliance. Full card numbers are never stored — Stripe handles payment data.
- Usage/analytics data: Up to 24 months for individual-level data.
- Device notification tokens: Life of the notification opt-in. Removed when your account is deleted, and pruned automatically once the push service reports the token as no longer valid.
- Launch and news sign-ups: a launch sign-up is kept until we send the launch email for that feature, then deleted within 30 days. A news sign-up is kept until you unsubscribe, using the link in any news email, or ask us to remove it at the privacy address in §16.
- DMCA and legal records: Duration of related legal matter plus applicable statutes of limitations.
- Moderation records and refused-upload evidence: Kept indefinitely until a person reviews and deletes it. When an image you upload is refused by our automated moderation, a copy of that image is stored in a private evidence bucket that only Chefra staff can read, together with a log of the refusal — the category, the model's confidence, and a hash of the image. There is no automatic expiry: these records are kept indefinitely until a person reviews and deletes them. We keep them so a refusal can be reviewed, appealed, and defended, and so the same image cannot simply be uploaded again. Images refused as suspected child sexual abuse material are stored separately and reported to the National Center for Missing and Exploited Children (NCMEC), and those records are kept as long as the law requires.
What "immediate" does and does not cover. Deleting your account removes your account record and the database rows linked to it straight away. Four things outlive that, and we would rather say so than imply a clean sweep. Uploaded images may persist in our storage system after the database rows referencing them are gone, until they are cleared; they are no longer linked to you or reachable from anywhere in Chefra, but the file objects themselves are not deleted by the same operation. Copies of deleted data can remain in encrypted backups for up to 30 days on the normal rotation. Our payment and email providers — Stripe and Resend — keep their own records under their own retention schedules, which we do not control; the retention periods listed above for billing and consent records reflect that. And if an upload of yours was refused by automated moderation, the retained copy of that image and the log of the refusal are not removed when you delete your account — they are kept indefinitely until a person reviews and deletes them, as described above.
8. Your Privacy Rights
Depending on where you live, you may have the right to access, delete, correct, or port your personal data, and to opt out of sale or sharing of your data and automated profiling.
Chefra does not sell your personal data or share it for cross-context behavioral advertising. If this changes, we will update this policy and provide opt-out mechanisms first.
California residents (CCPA/CPRA) and residents of other states with comprehensive privacy laws (Colorado, Connecticut, Virginia, Texas, and others) have these rights under applicable state law.
To submit a request: email privacy@getchefra.com with "Privacy Request" in the subject line. We will verify your identity and respond within 45 days.
Exercising your privacy rights will never result in denial of service or different pricing.
9. Global Privacy Control (GPC)
Chefra honors the Global Privacy Control (GPC) signal. If your browser sends a GPC signal, we treat it as a request to opt out of sale and sharing of your personal data. Because Chefra does not currently sell or share data for advertising, this has no additional practical effect at this time, but it is acknowledged.
10. Children's Privacy
Chefra is for users 13 and older (16 or older for EEA users). We do not knowingly collect personal information from children under 13. If we learn we have done so, we will delete it promptly. To report an underage account: privacy@getchefra.com.
11. International Data Transfers
Chefra is based in the United States. If you use Chefra from outside the US, your data will be transferred to and processed in the United States. For EEA and UK users, we rely on the EU-US Data Privacy Framework (where applicable) and Standard Contractual Clauses for international data transfers.
12. EEA and UK Users
If you are in the EEA or UK, we process your data on these legal bases: contract (to provide the service), consent (marketing, optional features), legitimate interests (security, fraud prevention, analytics), and legal obligation.
EEA users must be at least 16 years old to create an account.
You have the right to lodge a complaint with your local data protection authority.
Data controller: Chefra LLC, PO Box 76, Haven, Kansas 67543, USA. Email: privacy@getchefra.com.
EU/EEA and UK Data Protection Representative. Chefra LLC has appointed Data Protection Representative Limited (trading as DataRep) as its Data Protection Representative under Article 27 of the EU GDPR and the UK GDPR. EEA and UK data subjects may contact DataRep regarding the processing of their personal data:
- Email: datarequest@datarep.com (quote "Chefra LLC" in the subject line)
- Online form: www.datarep.com/data-request
- EU/EEA post: DataRep, The Cube, Monahan Road, Cork, T12 H1XY, Republic of Ireland
- UK post: DataRep, 107-111 Fleet Street, London, EC4A 2AB, United Kingdom
When writing by post, please address your letter to "DataRep" (not "Chefra LLC") so it reaches us. For questions about the Chefra product or your account, contact us directly at privacy@getchefra.com.
13. Data Security
We implement reasonable security measures including encrypted storage, encrypted transmission (TLS), access controls, and database row-level security. In the event of a breach affecting your personal data, we will notify you as required by applicable law, including K.S.A. 50-7a01 (Kansas).
13a. Mobile app permissions
The Chefra iOS and Android apps may ask for the following device permissions. Each permission is requested only when the related feature is used, and you can revoke it at any time in your device settings:
- Camera — to take a photo of a dish or scan a printed recipe. Photos are uploaded only when you tap "save" or "post".
- Photo library — to attach an existing image to a recipe, post, or profile.
- Notifications — to deliver the alerts you opt into (replies, mentions, DMs, follows). You can change notification topics in Settings → Notifications.
Photo location metadata. Photos taken on a phone can carry EXIF metadata that includes the GPS coordinates where the photo was taken. Chefra removes that metadata from photos before they are stored: every image is stripped of its EXIF, XMP, and IPTC metadata on the way into our storage, whether you upload it in the app, share it to Chefra from another app, or import it from a link. We do not keep, use, or share the location a photo was taken in.
Chefra does not request location, microphone, contacts, calendar, health, motion, or Bluetooth access, and the app does not track you across other companies' apps or websites (no IDFA / Advertising ID collection, no AppTrackingTransparency prompt).
13b. Manage, export, or delete your data
You can take these actions yourself, without contacting us:
- Export a copy of your data — Settings → Privacy & Security → "Download my data" produces a JSON file with your recipes, posts, comments, grocery items, and profile.
- Delete your account — Settings → Privacy & Security → "Delete account" permanently removes your account and personal data (subject to the retention schedule in §7).
- Report content or a user — use the "Report" option on a post, comment, recipe, profile, or direct message, or email support@getchefra.com.
- Block a user — use the "···" menu on their post, comment, or direct message and choose Block, or open that person's profile and choose Block there. Manage everyone you have blocked in Settings → Blocked.
- Manage notifications — Settings → Notifications.
If you need help, email privacy@getchefra.com.
14. DMCA designated agent
Chefra has designated the following agent to receive notices of claimed copyright infringement under the Digital Millennium Copyright Act:
- Designated Agent: Eli Kramer
- Organization: Chefra LLC
- Email: dmca@getchefra.com
- U.S. Copyright Office Registration: DMCA-1073800
15. Changes to this policy
We may update this policy. When we make material changes, we will notify you in the app or by email and update the "Last updated" date at the top of this page.
16. Contact
Privacy questions or requests? Email privacy@getchefra.com.