Chef Auvra

Privacy Policy

Last updated: August 22, 2026

1. Information We Collect

  • Account information — your name, email address, and password (stored as a salted hash, never in plain text) when you register directly. If you sign in with Google or Apple instead, we receive your name, email, and a profile identifier from that provider.
  • Profile & preference data — dietary flags and allergy information you enter (e.g. vegetarian, gluten-free, nut allergy), household/serving-size preferences, and your subscription tier.
  • Pantry, recipe, and meal-plan data — ingredients you track, recipes you create, save, or publish, meal plans and grocery lists you generate, and photos you upload of recipes or receipts.
  • Phone number — only if you enable SMS-based two-factor authentication.
  • Payment information — we do not store your card details. Payments are processed directly by Stripe; we retain only a Stripe-issued customer and subscription reference.
  • Content you submit — comments, ratings, recipe photos, and reports you file against other users' content.
  • Technical data — IP address, device/browser type, and log data collected automatically, including for security purposes such as detecting repeated failed login attempts.

2. How We Use Your Information

  • To provide the core service — storing your pantry and recipes, and generating AI recipes, meal plans, grocery lists, and receipt scans on your request.
  • To process payments and manage your subscription through Stripe.
  • To send transactional email (verification, password reset, security alerts, billing notices) through our email provider, Postmark.
  • To send SMS verification codes, if you opt into phone-based two-factor authentication, through Twilio.
  • To moderate user-submitted content (recipes, comments, photos) for compliance with our Acceptable Use policy.
  • To maintain account security, including two-factor authentication, encrypted storage of sensitive fields, and an internal audit log of account changes.
  • To communicate with you about your account, respond to support requests, and comply with applicable law.

3. Third-Party Services

We share the minimum data necessary with the following service providers to operate Chef Auvra. Each processes data only as needed to provide their service to us, under their own privacy and security terms:

  • OpenAI — processes recipe requests, pantry text, and related prompts to generate recipes, meal plans, and grocery lists.
  • Google Cloud Vision — processes photos you submit for receipt/label scanning and recipe-card transcription.
  • Stability AI — generates AI cover photos for recipes published on PRO/FAMILY tiers.
  • Stripe — processes subscription payments and stores your payment method on our behalf; we never receive or store your full card number.
  • Twilio — delivers SMS verification codes if you enable phone-based two-factor authentication.
  • Postmark — delivers transactional email.
  • Cloudflare R2 — stores photos you upload.
  • Hosting/infrastructure providers (Vercel, Railway, Upstash) — host the application, background job processing, and caching; they do not use your data for their own purposes.

We do not sell your personal information to third parties.

4. Data Retention & Deletion

We retain your account data for as long as your account is active. If you delete your account, we permanently delete or anonymize your personal information (including your email, name, pantry data, and phone number) within 30 days, except where we're required to retain certain records (e.g. billing records) for legal or tax purposes. Published recipes and public comments may be retained in de-identified form so that other users' saved content and recipe history remain intact. You can request deletion at any time from Settings → Account, or by emailing support@chefauvra.com.

5. Your Rights

Depending on where you live, you may have the right to:

  • Access the personal information we hold about you.
  • Correct inaccurate information.
  • Request deletion of your account and associated data.
  • Export your data in a portable format.
  • Object to or restrict certain processing, or withdraw consent where processing is based on consent.

Residents of the EU/UK (GDPR) and California (CCPA/CPRA) have specific statutory rights under those laws; we honor equivalent rights for all users regardless of location. To exercise any of these rights, email support@chefauvra.com — we'll respond within the timeframe required by applicable law (generally 30 days).

6. Security

We take reasonable technical and organizational measures to protect your information, including encrypting sensitive fields (such as two-factor authentication secrets) at rest, hashing passwords with a strong, salted algorithm, offering two-factor authentication (authenticator app or SMS), rate-limiting repeated failed login/verification attempts, and maintaining an internal audit log of administrative actions on accounts. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.

7. Children's Privacy

Chef Auvra is not directed to, and we do not knowingly collect personal information from, children under 13 (or the equivalent minimum age in your jurisdiction). If we learn we've collected information from a child under this age, we will delete it.

8. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we'll notify you by email or an in-app notice before they take effect. The "Last updated" date at the top of this page reflects the most recent revision.

9. Contact

Questions about this policy or your data? Email us at support@chefauvra.com.