Zuppi is a recipe app that runs on your iPhone. It has no user accounts on our servers, no analytics, no advertising, no trackers and no third-party SDKs of any kind. Your recipes stay on your device and, if you choose, in your own iCloud account.
1. The short version
- We do not have a server that stores your recipes, your name, your email address or your account. There is nothing for us to look up, because there is nothing there.
- Everything you save lives in Zuppi’s own storage on your device. If you turn on sync, a copy also goes to your iCloud account, which we cannot read.
- Zuppi contains no analytics, no advertising identifiers, no attribution SDKs, no crash reporting SDKs and no social media SDKs. It makes no network request for the purpose of measuring you.
- We do not sell your personal information, and we do not share it for cross-context behavioural advertising. We never have and there is no mechanism in the app by which we could.
- Because Zuppi does not track you across apps or websites owned by other companies, it does not show the App Tracking Transparency prompt.
2. Who is responsible
Zuppi is published by Nathan O’Dowd, a sole trader based in Edinburgh, Scotland, United Kingdom. For the purposes of the UK GDPR and the EU GDPR, Nathan O’Dowd is the data controller for the limited processing described in this policy.
You can reach us at hello@zuppi.recipes for any question about this policy or about your data. We will provide a postal address on request. We have not appointed a Data Protection Officer, because the scale and nature of our processing does not require one under Article 37 of the UK GDPR or the EU GDPR.
3. What Zuppi keeps on your device
Zuppi stores the following in a private container on your device, shared between the app, the share extension and the widgets. None of it is transmitted to us.
- Recipes you save or create: titles, ingredients, quantities, method steps, servings, timings, notes and any photo attached to a recipe.
- Provenance for each imported recipe: the source link, the creator handle where the page published one, the raw source text a line was read from, which extraction pass produced it, a confidence score and any conflicting reading.
- Your shopping list, pantry contents, meal plan and cooking checkpoints.
- App settings and preferences, including your subscription state and whether you have completed onboarding.
This data is protected by the file protection and device encryption that iOS applies to app containers. If you use a device passcode, Face ID or Touch ID, that protection applies here too.
4. iCloud sync
If you turn sync on, Zuppi copies selected recipes into the private database of its iCloud container, inside your own Apple Account. Practically, this means:
- The data sits in your personal iCloud storage, governed by your agreement with Apple and by Apple’s Privacy Policy.
- We have no access to it. A private CloudKit database is readable only by the signed-in Apple Account that wrote it. We cannot read, export or recover it, including if you ask us to.
- Sync is selective rather than an automatic mirror of everything, and you can turn it off in Settings.
In this arrangement Apple acts as our processor for the container and as your own service provider for your iCloud account. If you have Advanced Data Protection enabled on your Apple Account, the contents are end-to-end encrypted and Apple cannot read them either.
5. Sign in with Apple
Zuppi offers Sign in with Apple purely to confirm that the device belongs to you. It is deliberately minimal:
- The app requests no scopes. It does not ask Apple for your name, and it does not ask for your email address, not even a private relay address.
- The only thing kept is the opaque user identifier Apple returns. It is stored in your device’s Keychain, marked so that it never leaves that device and never enters a backup.
- No identity token, authorisation code or credential is sent to any server of ours, because we do not operate one for this purpose.
You can revoke Zuppi’s access at any time in Settings, Apple Account, Sign in with Apple. You can also sign out inside Zuppi, which deletes the stored identifier from the Keychain.
6. Importing recipes from links
When you share or paste a link, Zuppi fetches that public page directly from your device and reads the recipe out of it. Supported sources currently include Instagram, TikTok, YouTube, Facebook, Pinterest, ChatGPT share links and general recipe websites.
What this means for your privacy:
- The request goes from your device to that platform. It does not pass through us, and we do not receive the link, the page, the recipe or any record that you imported anything.
- The platform you are importing from will see the request in the ordinary way, including your IP address, and will handle it under its own privacy policy. We have no control over and no visibility of that.
- Files downloaded during an import, such as a video used only to read its on-screen text or audio, are written to a temporary location and deleted when the import finishes, fails or is cancelled.
Zuppi reads pages that are already public. It does not sign in to those platforms on your behalf, and it does not access anything that is private to your account there.
7. Cloud assist
Reading a recipe out of a social post is the hard part, and Zuppi tries the cheapest and most private option first. There are three links in the chain, and each one exists only because the one above it can be unavailable.
7.1 On the device
The first pass runs on Apple’s on-device foundation models, together with on-device text recognition and, where relevant, on-device speech transcription. Nothing leaves your iPhone. For most imports the chain stops here.
7.2 Apple Private Cloud Compute
If the on-device result is not confident enough, or the post is longer than the on-device model can hold at once, Zuppi can send the extracted text to Apple Private Cloud Compute. This is Apple’s own infrastructure, and it is designed so that:
- Your data is used only to fulfil that one request and is not retained afterwards.
- It is not used to train any model.
- It is not accessible to Apple, and it is not accessible to us.
- The request is charged against your own daily Apple Intelligence allowance rather than to us, which is why we can offer it on the free tier.
Apple describes the guarantees and the independent verifiability of this system in its Private Cloud Compute documentation. This route requires a recent version of iOS and a device that supports Apple Intelligence.
7.3 Our extraction service
For Zuppi Plus subscribers on devices that will never receive Apple Intelligence, and only when the two routes above are unavailable, Zuppi can call an extraction service we operate on Cloudflare Workers. When that happens:
- What is sent: the text harvested from the post, which may include the caption, visible comments, text recognised in the video or image, and an audio transcript. It is sent so that a model can turn it into structured ingredients and steps.
- What is not sent: your name, your email address, your Apple Account identifier, your device identifiers, your contacts, your other recipes or your location.
- How it is authenticated: with Apple’s App Attest. Your device proves that it is a genuine, unmodified device running a genuine copy of Zuppi, using a key generated in its Secure Enclave. The key never leaves the device, and it is not an identifier we can link to you as a person. A per-install daily cap is enforced against it.
- Who processes it: Cloudflare, Inc. hosts the service and provides the first model. Where that model’s output fails validation, the text is passed to Anthropic PBC for a second attempt. Both act as our processors under contract, neither uses the content to train models, and the content is not retained after the request is answered.
- Logs: the service keeps only what is needed to run it, such as counts and error rates. It does not log recipe text.
Cloud assist never fails an import. If a quota is reached or the service is unavailable, the on-device result stands. Cloud assist is switched off entirely in the share extension.
8. Camera, photos, microphone and speech
Zuppi asks for these permissions only at the moment you use the feature that needs them, and each one is processed entirely on your device.
| Permission | Why Zuppi asks | Where it is processed |
|---|---|---|
| Camera | Scanning a cookbook page or a handwritten recipe card. | On device. Images are read by Apple’s on-device text recognition and are not uploaded. |
| Photo library | Importing a screenshot of a recipe. | On device. Zuppi receives only the images you pick. |
| Microphone | Hands-free voice control in Cook Mode, so you can move between steps without touching a screen. | On device, and only while Cook Mode is open. Audio is not recorded to a file and not uploaded. |
| Speech recognition | Transcribing a video’s audio to catch quantities the creator only says out loud, and recognising cooking commands. | On device. Zuppi explicitly requires on-device recognition and will not fall back to a server; if a device or language cannot do it on device, the feature is unavailable rather than sent away. |
You can withdraw any of these permissions at any time in iOS Settings under Zuppi. The related feature simply stops working; the rest of the app is unaffected.
9. Reminders, notifications and Live Activities
If you connect a Reminders list, Zuppi writes your shopping items, quantities and checkmarks into the single list you choose, using Apple’s EventKit framework. It does not read or change your other lists, and the contents stay within Apple’s Reminders, governed by your iCloud settings. Disconnecting the list in Zuppi stops all further writes.
Notifications and Live Activities, for example a cooking timer on the Lock Screen, are scheduled locally by the app. Zuppi does not operate a push server, so no notification content is sent to or from us.
10. Purchases and subscriptions
Zuppi Plus is sold through the App Store. Apple handles the entire transaction:
- We never see your card number, billing address or Apple Account credentials.
- Your entitlement is verified on your device against the signed transaction Apple provides. We do not maintain a subscriber database.
- Apple provides us with aggregated, anonymised sales and financial reports. These do not identify individual customers.
Losing Plus never deletes your data and never blocks export of your own recipes.
11. Crash reports and diagnostics
Zuppi does not embed a crash reporting or analytics SDK. If you have chosen to share analytics with app developers in iOS Settings, Apple may provide us with crash logs and aggregate performance metrics through App Store Connect. That sharing is a setting between you and Apple, it can be turned off there at any time, and what we receive is aggregated and not identified to you.
12. What Zuppi never does
- No advertising, no ad networks and no advertising identifier (IDFA) is requested.
- No selling of personal information, and no sharing for cross-context behavioural advertising, as those terms are defined in California law.
- No profiling and no automated decision-making that produces legal or similarly significant effects.
- No tracking across other companies’ apps or websites, and no data brokers.
- No fingerprinting. The App Attest key described above is a hardware attestation, not an identifier we can resolve to a person.
- No sale or transfer of data in the ordinary course. If the app were ever sold or transferred, there is no user database to transfer with it.
13. Legal bases for processing
For people in the United Kingdom, the European Economic Area and Switzerland, the limited processing we carry out relies on the following legal bases under Article 6 of the UK GDPR and the EU GDPR.
| Activity | Legal basis |
|---|---|
| Storing your recipes and settings on your device | Performance of a contract. This is the app doing the thing you installed it to do. |
| Syncing to your own iCloud | Consent, given by turning sync on, and withdrawable by turning it off. |
| Sign in with Apple | Consent, given by choosing to sign in. |
| Sending post text to our extraction service | Performance of a contract, to deliver the Plus feature you subscribed for. |
| App Attest and per-install rate limits | Legitimate interests, namely preventing abuse of a service we pay for per request. Assessed as low impact because no personal identity is involved. |
| Camera, photos, microphone, speech, Reminders | Consent, given through the iOS permission prompt and withdrawable in iOS Settings. |
14. How long data is kept, and how to delete it
- On your device: your data is kept until you delete it or delete the app. Deleting the app removes its container, including everything listed in section 3.
- In your iCloud: data remains in your Apple Account until you delete it. You can remove it in Settings, Apple Account, iCloud, Manage Account Storage, then Zuppi. Deleting the app alone does not automatically remove iCloud data.
- In our extraction service: request content is not retained after the response is returned. Operational counters are kept for no more than 30 days.
- Purchase records: Apple retains transaction records under its own policy. We keep the aggregate financial reports Apple provides for as long as tax law requires, currently six years in the United Kingdom.
Because we hold no account for you, there is no account for us to delete. If you want confirmation of that in writing, ask us and we will send it.
15. International transfers
Your recipes do not leave your device and your iCloud unless you use the Plus extraction service. Where a transfer does occur, it is covered as follows:
- Apple (iCloud, Private Cloud Compute, App Store) operates globally and relies on Standard Contractual Clauses, the UK International Data Transfer Addendum, and the EU-US and UK-US Data Privacy Frameworks where applicable.
- Cloudflare, Inc. processes requests at the edge location nearest your device and relies on Standard Contractual Clauses and the UK Addendum.
- Anthropic PBC, used only on the fallback path described in section 7.3, relies on Standard Contractual Clauses and the UK Addendum.
16. Your rights
Depending on where you live you have some or all of the following rights: to be told what is processed, to access it, to correct it, to delete it, to restrict or object to processing, to data portability, and to withdraw consent at any time without affecting processing already carried out.
Two honest points about exercising them here:
- For most of these rights you do not need us. Your data is in your hands already: you can read, correct, export and delete it inside the app, and export is never locked behind a subscription.
- If you write to us asking for a copy of your data, we will tell you truthfully that we hold none, because we do not. We cannot reach into your device or your iCloud, by design.
Write to hello@zuppi.recipes and we will respond within one month. We will never charge for a request or make you create an account to submit one.
17. Region specific information
United Kingdom, European Economic Area and Switzerland
You may lodge a complaint with your supervisory authority. In the UK this is the Information Commissioner’s Office (ico.org.uk). In the EEA it is the authority for your country of residence. In Switzerland it is the Federal Data Protection and Information Commissioner. We would appreciate the chance to put things right first, but you are not required to come to us before going to them.
California
Under the California Consumer Privacy Act as amended by the CPRA: in the preceding twelve months we have not collected any category of personal information listed in the statute from consumers through the app, we have not sold personal information, and we have not shared personal information for cross-context behavioural advertising. We do not use or disclose sensitive personal information for purposes that would trigger the right to limit. You have the rights to know, delete, correct and to non-discrimination, and we do not offer financial incentives for data. Because we hold no personal information about you, a verifiable consumer request will be answered by telling you so.
Other United States jurisdictions
Residents of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Indiana, Kentucky and Rhode Island have comparable rights of access, correction, deletion, portability and opt-out under their respective privacy statutes. We do not sell personal data, do not process it for targeted advertising, and do not carry out profiling with legal or similarly significant effects, so the opt-out rights those laws create have nothing to attach to here. Requests go to the same address.
Canada
We handle personal information in line with PIPEDA and the applicable provincial statutes, including Quebec’s Law 25. You may complain to the Office of the Privacy Commissioner of Canada or to your provincial commissioner.
Brazil
Under the Lei Geral de Proteção de Dados you have rights of confirmation, access, correction, anonymisation, portability, deletion, information about sharing, and revocation of consent. The controller is Nathan O’Dowd, contactable at hello@zuppi.recipes. You may complain to the ANPD.
Australia and New Zealand
We handle personal information in accordance with the Australian Privacy Principles under the Privacy Act 1988 and, in New Zealand, the Privacy Act 2020. Complaints may go to the Office of the Australian Information Commissioner or the New Zealand Privacy Commissioner.
Japan
We handle personal information in accordance with the Act on the Protection of Personal Information. We do not provide personal data to third parties in a manner requiring your prior consent under the APPI, other than the processors named in this policy.
South Korea
Under the Personal Information Protection Act you have rights of access, correction, deletion and suspension of processing. We do not collect resident registration numbers and do not transfer personal information overseas for marketing. Disputes may be taken to the Personal Information Dispute Mediation Committee.
India
Under the Digital Personal Data Protection Act 2023 you may access, correct and erase your personal data and nominate another person to exercise your rights. Grievances may be sent to hello@zuppi.recipes and, if unresolved, to the Data Protection Board of India.
South Africa
Under the Protection of Personal Information Act you may object to processing and complain to the Information Regulator.
Türkiye
Under KVKK Law No. 6698 you have rights of access, correction, deletion and objection, and may apply to the Turkish Personal Data Protection Authority.
Mainland China
Where Zuppi is offered on the mainland China App Store, we process personal information in accordance with the Personal Information Protection Law. Data that leaves your device on the routes described in section 7 is processed outside mainland China. Where a cross-border transfer requires separate consent under PIPL Article 39, the app requests it before that route is used and the feature is otherwise disabled.
18. Children
Zuppi is a general audience app intended for people aged 13 and over. It is not directed at children under 13 and we do not knowingly collect personal information from them. Where the digital age of consent in your country is higher than 13, which it is in several EU member states, a person under that age should use Zuppi only with the consent of a parent or guardian. Because Zuppi has no accounts, no messaging, no user-to-user features and no advertising, there is no mechanism by which a child’s personal information could reach us. If you believe a child has provided personal information to us, write to hello@zuppi.recipes and we will act on it.
19. Changes to this policy
If we change this policy we will update the date at the top of this page. If a change is material, for example a new category of data leaving your device, we will say so in the app before the change takes effect, and where the law requires consent we will ask for it rather than assume it. We will not apply a materially different practice to data already collected without telling you.
20. Contact
Nathan O’Dowd, Edinburgh, Scotland, United Kingdom.
Email: hello@zuppi.recipes. A postal address is available on request.
This policy is written in English. Where it is translated, the English version governs in the event of a conflict.