Privacy Notice
Last updated: May 2026
1. Who we are
The data controller for Cook Today is Jóna Oszkár, a sole individual based in Hungary. You can contact us through the support email shown in the app.
2. Data we collect
- Account data: email, optional display name and language preference.
- Cooking preferences: allergens, ingredient exclusions and inclusions, saved and cooked recipes.
- Usage data: number of recipes generated per day (for free-tier limits) and basic technical logs.
- Anonymous quota cookie: a random identifier stored in an httpOnly cookie to enforce daily limits for signed-out users. Not used for tracking or advertising.
3. Why we use it
- To provide and personalise recipe suggestions (contract performance).
- To enforce free-tier quotas and prevent abuse (legitimate interest).
- To process payments and subscriptions (contract performance).
- To respond to support requests (legitimate interest).
4. Who we share it with
- Paddle.com — Merchant of Record for all sales; handles payments, billing, tax compliance, invoicing, and refund processing.
- Hosting & database providers — for running the app and storing your data securely.
- AI providers — your recipe-generation requests (excluding identifying account data) are processed by AI model providers to produce recipes.
- Authorities — only where required by law.
5. International transfers
Some service providers may process data outside the EEA. Where that happens, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses or adequacy decisions.
6. Retention
We keep account and content data for as long as your account is active, plus a limited period afterwards for legal and accounting obligations. You can delete your account at any time, after which we delete or anonymise your data.
7. Your rights (GDPR)
You have the right to access, rectify, erase, restrict, and port your personal data, to object to processing, to withdraw consent, and to lodge a complaint with your supervisory authority. We respond to requests within one month.
8. Security
We use appropriate technical and organisational measures (encryption in transit, access controls, role-based permissions) to protect your data.
9. Cookies & local storage
We use only strictly necessary cookies and browser storage. We do not use analytics, advertising, or third-party tracking cookies. Because these are essential to running the app, no opt-in consent is required under EU ePrivacy rules — but here is exactly what we store, so you know:
| Name | Type | Purpose | Lifetime |
|---|---|---|---|
| sb-*-auth-token | localStorage | Keeps you signed in | Until sign-out |
| ct_anon | httpOnly cookie | Anonymous daily quota for signed-out users | 1 year |
| sidebar_state | cookie | Remembers sidebar open/closed | 7 days |
| i18nextLng | localStorage | Your language preference | Persistent |
| cookie-notice-ack-v1 | localStorage | Remembers you dismissed the cookie notice | Persistent |
| Recipe cache | localStorage | Faster recipe loading | Persistent |
You can clear any of these at any time via your browser settings. Removing essential storage will sign you out and reset your preferences.