Privacy Policy

Last Updated: March 15, 2026

Cooky ("Cooky", "we", "our", or "us") is committed to protecting your privacy and handling personal information in a transparent and secure manner.

This Privacy Policy explains how we collect, use, disclose, store, and protect information when you use the Cooky mobile application, website, and related services (collectively, the "Service").

By accessing or using the Service, you agree to this Privacy Policy. If you do not agree, you should not use the Service.

This Privacy Policy applies to users in all countries where we make the Service available. We are an Australian business and comply with applicable privacy and data protection laws, including the Australian Privacy Act 1988 (Cth) and other applicable laws in jurisdictions where we operate.

Cooky is the data controller responsible for personal information processed through the Service.

We aim to collect only the information that is reasonably necessary to operate and improve the Service.


1. Who This Policy Applies To

This Privacy Policy applies to:

  • our mobile applications

  • our website

  • our related services, support channels, and communications

Our Service is not intended for children under 18, and we do not knowingly collect personal information from children under 18.


2. Information We Collect

We collect information to provide and improve the Service, manage accounts, enable features such as recipe imports and subscriptions, and communicate with users.

2.1 Account and Authentication Information

When you create an account or sign in, we may collect:

  • your email address

  • your password or authentication credentials

  • authentication tokens and session information

  • your name, if provided by Apple Sign In or Google Sign In

  • profile information you choose to provide

2.2 Profile, Onboarding, and Preference Information

If you complete onboarding or update your profile, we may collect information such as:

  • cooking experience

  • cooking frequency

  • dietary restrictions and food preferences

  • favorite cuisines

  • cooking goals

  • kitchen equipment

  • recipe organization preferences

  • referral source

  • gender

Some onboarding information, such as dietary preferences or dietary restrictions, may be considered sensitive personal information in certain jurisdictions. Where required by law, we collect and process this information only with your consent.

Other profile information, such as cooking preferences or gender, is optional and provided voluntarily by users. Users are able to sign up and use the Service without providing this information. This information is used to personalize recommendations and improve the user experience within the Service.

2.3 User Content and Submitted Materials

When you use the Service, we may collect and store content that you submit or create, including:

  • recipe URLs you import into the app

  • recipe content generated or saved through imports

  • cookbooks, grocery data, and saved recipes

  • photos or images you select from your photo library or capture with your camera for ingredient or recipe scanning

  • feedback, survey responses, or messages you send us

Imported recipes may originate from third party websites. We store imported content solely to provide functionality within the Service and do not claim ownership of original third party recipe content.

Imported source URLs may be retained after processing as a reference URL.

Images uploaded for scanning may be stored in our systems for up to 6 months, after which they are automatically deleted unless a longer retention period is required for legal, security, or dispute resolution purposes.

Users retain ownership of content they submit to the Service. By submitting content, you grant Cooky a limited license to store, process, and display that content solely for the purpose of operating the Service.

2.4 Subscription and Transaction Information

If you purchase a subscription through the App Store or another platform, we may receive limited subscription-related information such as:

  • subscription status

  • entitlement status

  • renewal or expiration status

  • transaction metadata made available through the platform or our subscription management provider

For iOS in-app purchases, Apple processes payment details directly. We do not receive your full payment card number or payment credentials.

2.5 Usage, Analytics, and Technical Information

When you use the Service, we may automatically collect technical and usage information such as:

  • device type and model

  • operating system and app version

  • device identifiers made available by the device or operating system

  • IP address and network information

  • app events and feature usage

  • navigation patterns and screens viewed

  • diagnostics, logs, and performance data

This information helps us operate the Service, improve reliability, understand usage, investigate issues, and develop features.

2.6 Notification Information

If you enable notifications, we may process:

  • your notification permission status

  • notification settings and preferences

  • technical information required to deliver notifications

You can disable notifications through your device settings.

2.7 Communications and Support Information

If you contact us, we may collect:

  • your email address

  • message contents

  • attachments or screenshots

  • support interaction records


3. Information We Do Not Intentionally Collect

We do not generally collect:

  • mailing addresses as a standard account field

  • phone numbers as a standard account field

  • precise GPS location

If our practices change, we will update this Privacy Policy and request appropriate permissions where required.


4. How We Use Your Information

We may use your information to:

  • create and manage your account

  • authenticate users and maintain sessions

  • provide app functionality such as recipe import, recipe organization, grocery lists, and scanning features

  • personalize your experience based on preferences and onboarding data

  • process subscriptions and entitlements

  • send service-related notifications and communications

  • provide customer support

  • maintain, monitor, and improve the Service

  • detect fraud, abuse, bugs, and security incidents

  • conduct analytics and measure product performance

  • comply with legal obligations and enforce our terms

We may also use aggregated or de-identified information for research, analytics, reporting, and product improvement.

We do not sell personal information.

We do not use personal information for third-party advertising or cross-app advertising tracking, and we do not currently request App Tracking Transparency permission.

Legal Bases for Processing

Depending on your location, we process personal information under one or more of the following legal bases:

  • to perform our contract with you and provide the Service

  • with your consent

  • to comply with legal obligations

  • for our legitimate business interests such as improving the Service, preventing fraud, and maintaining security


5. Analytics and Session Replay

We use analytics tools to understand how users interact with the Service and improve usability and performance.

Analytics may include collection of:

  • screen views

  • navigation events

  • feature usage events

  • device and technical information

We use PostHog for product analytics.

We may enable session replay in limited situations, including:

  • in staging or testing environments

  • temporarily in production to investigate bugs, crashes, or usability issues

Recordings are used solely to diagnose and improve the Service and are not used for advertising purposes.

Sensitive fields such as passwords or payment information are not recorded in session replay tools.


6. Cookies and Similar Technologies

Our website may use cookies, local storage, and similar technologies to:

  • support functionality

  • remember preferences

  • analyze usage

  • improve the Service

Our mobile app may use device storage and similar technologies to maintain sessions and preferences.

Some browsers offer a Do Not Track feature that signals websites that you do not want online activities tracked. Because there is not yet a uniform standard for interpreting these signals, we do not currently respond to Do Not Track signals.


7. App Permissions

Cooky may request certain device permissions to enable specific features:

  • Camera – used for ingredient or recipe scanning

  • Photo Library – used if you upload images for scanning

  • Notifications – used to send reminders or service updates

You can manage or revoke these permissions at any time through your device settings.


8. How We Share Information

We may share personal information with trusted third party service providers that help us operate the Service, including:

  • Supabase for authentication and backend infrastructure

  • RevenueCat for subscription management

  • PostHog for analytics and diagnostics

  • Apple and Google where you choose to use their authentication or payment services

  • cloud hosting, monitoring, and infrastructure providers

We may also disclose information:

  • where required by law or legal process

  • to law enforcement or regulators where legally required

  • to professional advisers such as lawyers or auditors

  • in connection with a merger, acquisition, restructuring, financing, or sale of assets

  • with your consent or at your direction

If Cooky is involved in a business transfer such as a merger or acquisition, your information may be transferred as part of that transaction.


9. International Data Transfers

Your information may be processed in countries outside your country of residence, including Australia and the United States.

Where we transfer personal information internationally, we take reasonable steps to ensure appropriate safeguards are in place and that information is handled in accordance with applicable laws.


10. Data Retention

We retain personal information only as long as reasonably necessary to fulfill the purposes described in this Privacy Policy.

Examples include:

  • account data retained while your account remains active

  • imported recipe URLs retained as reference data

  • uploaded scanning images stored for up to 6 months

  • analytics logs retained for debugging, security, and performance analysis

  • support communications retained for dispute resolution and operational purposes

We may retain certain data longer where required by law or necessary to protect our legal interests.


11. Security

We implement reasonable technical and organizational safeguards to protect personal information.

These safeguards may include:

  • encrypted connections

  • authentication and access controls

  • infrastructure security protections

  • monitoring and logging systems

No method of internet transmission or storage is completely secure, and we cannot guarantee absolute security.


12. Your Choices and Rights

Depending on your location, you may have rights to:

  • request access to personal information

  • request correction of inaccurate data

  • request deletion of your information

  • restrict or object to certain processing

  • withdraw consent where applicable

Some profile information may be updated directly within the app.

To exercise privacy rights, contact:

support@trycooky.com

We may need to verify your identity before processing requests.


13. Account Deletion

You may request account deletion through the app or by contacting support@trycooky.com

Upon deletion, we will remove or de-identify personal information unless retention is required for:

  • legal compliance

  • fraud prevention or security

  • dispute resolution

  • enforcement of our agreements

  • legitimate backup or operational needs

If you purchased a subscription through Apple, cancellation must be handled through your Apple account settings.


14. Third Party Links and Services

The Service may contain links to third party websites or platforms.

We are not responsible for the privacy practices of those services and encourage users to review their privacy policies before providing personal information.


15. Minors

The Service is not intended for individuals under 18 years of age.

If we discover that we have collected personal information from a child without appropriate authorization, we will take steps to delete that information.


16. Changes to This Privacy Policy

We may update this Privacy Policy periodically.

If we make material changes, we may notify users through:

  • the app

  • our website

  • email where appropriate

Continued use of the Service after an update constitutes acceptance of the revised policy.


17. Contact Us

If you have questions or privacy related requests, contact:

support@trycooky.com