Privacy
How IvanEats handles your information.
This policy explains what information IvanEats uses, why we use it, which services help us provide Kitchen, and the choices and rights available to you.
Privacy contact: IvanEats, contact@ivaneats.com. We do not sell personal data or use advertising trackers. Optional product analytics only runs after you choose to allow it.
Information we use
Account and authentication information
When you create or use an account, we process information needed to identify and authenticate you. This includes your email address, sign-in method, and a display name where one is available. If you choose Google sign-in, Google may provide basic profile information such as your name, email address and profile picture as part of the sign-in flow.
Membership, billing and payment information
If you start a Kitchen membership, Stripe processes the checkout and payment. Stripe may process information such as your name or email, billing address, payment method details, transaction information, applicable tax information and fraud-prevention signals. IvanEats does not receive or store your full card number.
IvanEats stores the billing identifiers and subscription state needed to provide Kitchen access and prevent duplicate subscriptions. These records can include your Stripe customer, subscription and price identifiers, selected currency, subscription status, renewal/cancellation state, current billing-period end, subscription start/end timestamps and short-lived Checkout-session state.
Withdrawal and billing-support records
If you exercise the online right-of-withdrawal function, IvanEats records the subscription reference, Stripe customer reference, the account connected to the request where available, the email used for acknowledgement, when the request was received, refund status and the technical reference for the acknowledgement. This creates a durable record of the request and lets IvanEats demonstrate when it was received and how it was handled.
Kitchen preferences
Paid Kitchen membership can remember your default serving preference, measurement system, diet category and ingredients you choose to exclude. For members, these preferences are stored with your account and a local browser copy may be used so the interface can apply them consistently. When paid access is inactive, saved membership defaults are not applied by Kitchen.
Made-For-You recipes
When you ask Kitchen to create Made-For-You recipes, Kitchen uses information about the IvanEats recipe you cooked, the leftovers you confirm, any extra or excluded ingredients, serving information, cooking preferences and a short list of recently used IvanEats recipes to help avoid repeating similar meals. For signed-in users, the Made-For-You recipes Kitchen creates are stored in your History so you can return to them later. Recipes you choose to save are also kept in your Saved collection.
Public recipe links and meal photos
When you open Share for a Made-For-You recipe, Kitchen prepares a public link so it is ready when you press Share. The shared page can include the recipe title, summary, servings, cooking time, ingredients, method, notes and the IvanEats recipe it followed. It does not show your name, email address, preferences, other History entries or other Kitchen recipes.
Anyone with the link can open and reshare the recipe. Shared pages are not meant to appear in public searches, but we cannot promise that a link or copy will never be found, saved or reshared. Only share a recipe or photo you are comfortable making public.
If you add a meal photo, your browser places it inside the branded share card. IvanEats stores the finished card, not a separate copy of the original photo. You can remove the public link from Share, which removes the IvanEats page and stored card. Deleting your account also removes your remaining public links and cards.
Technical information about Made For You
To keep Made For You reliable, we also keep limited technical records about each attempt to create recipes. These records can include when the request was made, the IvanEats recipe it came from, how many leftovers, extra ingredients and exclusions were included, how long different parts of the process took, which AI model was used, how much AI processing was used, whether our checks passed, fixed or rejected a result, whether the request succeeded and whether the generation used the free or paid entitlement. These records are linked to your account and help us apply Kitchen usage limits, find technical problems, monitor speed and reliability, and understand the cost of running Made For You.
The technical records do not contain the names of your leftovers or exclusions, your exact diet preference, prompts, model responses or the text of the Made-For-You recipes themselves. The recipes themselves may still be stored in History as described above.
Hosting and technical request information
Vercel hosts the IvanEats website and application functions. When you open a page or use an IvanEats API, Vercel processes the request information needed to deliver and protect the service. This can include IP or network information, the requested route or domain, timestamps, response status, request identifiers, function details, and error or security metadata. Application requests can also pass through Vercel functions when they are sent to the other services described in this policy.
IvanEats uses these technical records to serve the website, investigate errors, protect accounts and payment flows, and maintain availability. We do not use Vercel request logs for advertising.
Feedback you choose to send
When you use the thumbs-up or thumbs-down feedback on a Made-For-You recipe, we store whether your feedback was positive or negative, any structured reason you select after negative feedback, and when it was sent. Your recipe feedback is not linked to the recipe you were viewing. We do not attach recipe content, ingredients, leftovers, or your Kitchen preferences to that feedback.
The Contact page also lets signed-in users send broader feedback. We store the broad topic you choose, the message you write and when it was sent, associated with your signed-in account. We do not automatically attach your Kitchen ingredients, recipe History or preferences to the message. Because this is a free-text field, the message can contain information you choose to write yourself; please do not include sensitive personal information that is not needed for your feedback.
Product analytics
Analytics is optional. After you consent, we may record limited usage data such as pages viewed, feature activity, which public IvanEats or shared recipe pages are viewed, whether a visitor opens the original recipe or Kitchen, counts, whether a Made-For-You request succeeded and how long it took. For signed-in users, analytics can be associated with your account. If you submit feedback, analytics may record whether it was positive or negative and how many negative reasons you selected, or the broad Contact-feedback topic.
We do not send the specific feedback reasons you selected, Contact message text, recipe context, your name, email address, ingredient text, generated recipe content or exact diet preference as feedback or public-sharing analytics.
Transactional email
We use your email address to send account-related messages such as email confirmation, password reset and password-change notifications. After the first successful payment for a Kitchen subscription, IvanEats also sends an essential membership confirmation that can include the amount and currency paid, your renewal date, the membership allowance and a link to Account. Stripe separately provides the official payment receipt or paid invoice. We may also send essential billing or consumer-rights communication where needed, including a durable acknowledgement when you use the online withdrawal function. Delivery providers may keep technical delivery events needed to send, secure and troubleshoot those messages.
Why we use this information
Accounts, preferences, recipe history, saved recipes, creating Made-For-You recipes and applying usage limits.
Performance of our agreement with you.
Create and remove the public recipe link and branded card when you choose to share.
Performance of our agreement with you and the sharing action you request.
Checkout, recurring billing, subscription access, cancellation, payment recovery, invoices and related customer support.
Performance of our agreement with you; legal obligations where billing or tax records must be kept.
Receiving withdrawal requests, ending subscriptions, processing refunds, issuing acknowledgements and retaining evidence where necessary.
Legal obligations and establishment, exercise or defence of legal claims where applicable.
Authentication, abuse prevention, duplicate-checkout prevention, keeping Made For You and public sharing reliable and responsive, controlling operating costs, hosting the service, and technical troubleshooting.
Legitimate interests in operating a secure, reliable and sustainable service.
Understanding feedback you choose to send, identifying recurring product problems and improving IvanEats and Kitchen.
Legitimate interests in receiving voluntary feedback and improving the service.
Understanding which pages, sharing journeys and features are useful and where Kitchen can improve.
Consent.
Account confirmation, password recovery, account-security email, Kitchen membership confirmation and essential billing or withdrawal acknowledgements.
Contract, legal obligation where applicable, and legitimate interests for account-security notifications.
Services that process data for IvanEats
Provides authentication, database and private file-storage services for account information, preferences, recipe history, saved content, public recipe links and branded share-card images, feedback, Made-For-You usage, membership state, withdrawal records and the technical performance records described above.
Provides website and API hosting, request routing, application functions, deployment infrastructure and operational logging. Vercel processes the technical request, network, response, function, error and security information needed to deliver and protect IvanEats.
Provides Kitchen subscription checkout, payment processing, recurring billing, tax-related checkout functionality, invoices, payment-retry tooling, billing management and refunds. Stripe receives the payment and billing information needed to provide those services.
Processes the information Kitchen sends to create Made-For-You recipes. IvanEats sends these API requests with response storage disabled. OpenAI states that API inputs and outputs are not used to train its models by default, while customer content may be retained in abuse-monitoring logs for up to 30 days under its default API controls.
Provides optional product analytics. IvanEats uses the EU PostHog endpoint and does not load PostHog until analytics consent has been granted. Feedback message text, generated recipe content and the specific negative reasons you select are not sent to PostHog.
Sends transactional account email, the essential Kitchen membership confirmation after a successful initial subscription payment, and withdrawal acknowledgements. Brevo processes the recipient email address, message content and technical delivery information needed for those communications. These messages are service and billing communications, not optional marketing email.
Used only when you choose Sign in with Google. Google shares the basic account information needed for the sign-in flow with your permission.
Some service providers may process information outside the EEA. Where required, transfers are handled using the safeguards provided by the relevant provider agreements and applicable data-protection law.
How long we keep information
Account information, Kitchen preferences, Made-For-You usage, feedback and the technical performance records described above are generally kept while your account exists. Recipe history and saved recipes remain associated with your account until they are removed or the account is deleted. Account deletion is designed to remove the ordinary IvanEats application data tied to that account.
A shared recipe and its branded card remain available until you remove the public link or delete your account. Removing the link removes the IvanEats page and stored card. Copies already saved or reshared elsewhere may remain available.
Billing, payment, tax, refund and withdrawal records can need a different retention period because IvanEats may be required to retain financial records or evidence of a consumer-rights request after the application account has been deleted. Where a withdrawal record no longer needs an account link, it is designed to survive account deletion without keeping the deleted Supabase user as an active account.
Hosting, analytics, security, technical and email-delivery records may be retained for different periods depending on their purpose, provider settings and applicable legal obligations. We use these records for product understanding, security, delivery, billing and troubleshooting rather than for advertising.
Your choices and rights
Depending on the circumstances, data-protection law may give you rights to access, correct, delete, restrict or receive a copy of personal information, and to object to certain processing. You can withdraw analytics consent at any time through Privacy settings.
You can remove a public recipe link from Share for the relevant History or Saved recipe. You can delete your IvanEats account from Account settings; this also removes your remaining public recipe links. Financial or legal records that IvanEats is required or entitled to retain are handled separately from ordinary account deletion. For another privacy request, email contact@ivaneats.com. If you believe your personal data has been handled incorrectly, you can also make a complaint to the Swedish Authority for Privacy Protection (IMY).
Changes to this policy
We may update this policy when IvanEats changes how the service works or adds providers and features. Material changes that affect consent may cause the site to ask for a new privacy choice.