Your data, clearly explained
Privacy policy
Last updated: 19 August 2026
In short: most of your pantry, shopping-list, recipe, reminder and food-profile data stays on your device. If you choose an AI photo or receipt scan, the selected images are sent securely to our backend and Google Gemini so the scan can be performed. Account authentication is provided by Supabase, purchases are handled by the relevant app store and RevenueCat, and website waitlist details are stored in our own application database.
1. Who we are
Now We're Cooking ("NWC", "we", "us" or "our") is a food-management and recipe app. The data controller is Dan Donovan, of 8 Victoria Road, Workington, CA14 2QT, United Kingdom. You can contact us about privacy at dan@nowwerecooking.com.
2. Where this policy applies
This policy applies to the Now We're Cooking mobile app, our website and waitlist, and the backend services used by the app. It does not govern third-party websites or services you choose to visit.
3. Information we process
| Information | How it is used | Where it is handled |
|---|---|---|
| Account email, authentication identifiers and optional sign-in-provider details | Create and secure your account, sign you in, confirm email addresses and reset passwords. | Supabase and the selected authentication provider. |
| Pantry items, quantities, dates, prices, shopping lists, favourites, hidden recipes and cached content | Provide the app's inventory, recipe-matching and shopping features. | Stored locally on your device unless a future sync feature is introduced with a separate notice. |
| Food profile, household size, dietary preferences, avoided foods and allergy selections | Personalise quantities and filter recipe suggestions. | Stored locally on your device. These details are not sent to RevenueCat. Allergy information can be sensitive; providing it is optional. |
| Photos of fridges, cupboards, freezers and receipts that you deliberately select | Identify visible food, receipt lines and related purchase information using automated image analysis. | Sent to our backend and Google Gemini for processing. We do not intentionally store uploaded scan images in our application database. |
| Barcodes, product names and product lookup queries | Find product, ingredient, image and nutrition information. | Our backend and/or Open Food Facts. |
| Purchase and subscription information, store account status, app user identifier and country | Offer, verify, restore and manage Premium access and prevent duplicate purchases. | Apple App Store or Google Play and RevenueCat. We do not receive full payment-card details. |
| Waitlist email address and consent record, including when and which consent wording you accepted | Manage the waitlist and send early-access news and occasional product updates. | Our application database and infrastructure provider. You can unsubscribe using any marketing email. |
| Technical information such as IP address, request time, device/app information and error details | Deliver and secure network services, diagnose failures, prevent abuse and maintain reliability. | Our hosting providers and service processors may process this information in operational logs. |
| Notification permission and reminder schedule | Create expiry reminders you request. | Notifications are scheduled locally on your device. |
4. Our reasons for using information
Under UK data-protection law, we rely on the following lawful bases:
- Contract: to provide accounts, app functionality and Premium access you request.
- Consent: for optional marketing messages and where you deliberately choose to upload a scan or provide optional food-profile information. You may withdraw consent at any time, although this does not make earlier processing unlawful.
- Legitimate interests: to secure, maintain, troubleshoot and improve the service, prevent fraud and understand operational performance, where those interests are not overridden by your rights.
- Legal obligation: where records must be retained or disclosed to comply with tax, accounting, consumer-protection or other law.
We do not use food-profile or allergy information to make decisions that have legal or similarly significant effects. Recipe filters and AI scan results are suggestions only.
5. Third parties
We use service providers only where needed to run the service. These currently include Supabase (authentication), RevenueCat (subscription management), Apple and Google (app distribution and payments), Google Gemini (image analysis), Open Food Facts (product data), and infrastructure providers that host our API and databases. Each provider processes information under its own terms and privacy commitments.
We do not sell personal information and we do not use it for cross-service behavioural advertising.
6. International transfers
Some providers may process information outside the United Kingdom. Where UK personal data is transferred internationally, we use providers and transfer mechanisms intended to comply with UK data-protection law, such as UK adequacy regulations, the UK International Data Transfer Agreement or UK Addendum, as appropriate. Contact us to request more information about applicable safeguards.
7. How long information is kept
- Local app data remains on your device until you delete it, clear the app's data or uninstall the app.
- Scan images are processed for the requested analysis and are not intentionally retained in our application database; temporary copies and processor logs may exist only for operational, security or legal periods.
- Account information is retained while the account is active and for a reasonable period afterwards where necessary for security, disputes and legal compliance.
- Subscription and transaction records are retained as required by the stores, RevenueCat and applicable financial or consumer law.
- Waitlist information is retained until you unsubscribe, ask us to erase it, or the waitlist purpose ends, subject to a minimal suppression record needed to honour opt-outs.
- Operational logs are retained for the shortest practical period consistent with security, troubleshooting and legal obligations.
8. Your choices and rights
Depending on the circumstances, UK data-protection law gives you rights to access, correct or erase personal data; restrict or object to processing; receive portable data; and withdraw consent. You also have the right to object to direct marketing at any time.
You can delete local pantry and profile information through the app or by clearing/uninstalling it. You can disable notifications in device settings, unsubscribe from marketing using the link in any message, and manage subscriptions in the Apple App Store or Google Play. For account deletion or any privacy request, contact dan@nowwerecooking.com. We may need to verify your identity.
9. Children
The service is not directed to children under 13. Anyone under 18 should use purchases only with permission from a parent or legal guardian. If you believe a child has provided personal data improperly, contact us so we can investigate and remove it where appropriate.
10. Security
We use reasonable technical and organisational safeguards, including encrypted network connections and access controls. No online service can guarantee absolute security. Keep your account credentials private and contact us if you suspect unauthorised access.
11. Changes and complaints
We may update this policy when the service or law changes. We will revise the date above and provide additional notice where a material change requires it.
Please contact us first if you have a concern. You may also complain to the UK Information Commissioner's Office at ico.org.uk/make-a-complaint or by telephone on 0303 123 1113.
12. Contact
Dan Donovan
8 Victoria Road, Workington, CA14 2QT, United Kingdom
dan@nowwerecooking.com