Privacy Policy
Last updated: 1 June 2025 · We take your privacy seriously.
1. Who We Are
Recipiq is an AI-powered recipe discovery application. We are committed to protecting your personal information. This Privacy Policy explains what data we collect, how we use it, and your rights regarding your data, in compliance with the Information Technology Act, 2000 and the Digital Personal Data Protection Act, 2023 (DPDP Act) of India.
2. Data We Collect
2.1 Data you provide directly:
- Ingredients you enter — sent to our AI backend to generate recipes. Not stored permanently.
- Diet goals & preferences — stored in your browser's localStorage only. Never sent to our servers unless you make a search.
- Email address — collected if you sign in with Google, or provide it during payment for subscription management.
2.2 Data collected automatically:
- IP address — collected temporarily for rate limiting and fraud prevention. Not stored permanently.
- Browser/device type — used for rendering and compatibility. Not stored.
- Usage logs — Next.js server logs API request paths and status codes (no personal data in logs).
2.3 Data from third parties:
- Google OAuth — when you sign in with Google, we receive your name, email, and profile picture. We do not receive your Google password.
- Razorpay — we receive a payment confirmation with your payment ID and order ID. We do NOT receive your card number, UPI PIN, or banking credentials — those are handled exclusively by Razorpay.
3. How We Use Your Data
- To generate personalized AI recipes based on your ingredients and goals
- To manage your subscription and send payment receipts
- To authenticate you via Google Sign-In
- To enforce rate limits and prevent abuse of our AI services
- To improve the Service (aggregate, anonymous usage patterns only)
We do not sell, rent, or share your personal data with third parties for advertising.
4. Data Storage & Security
- localStorage: Your goals, saved recipes, and preferences are stored locally on your device only. We cannot access this data.
- Subscription records: Email, plan type, and payment ID are stored in an encrypted file on our server for subscription management only.
- Encryption: All data in transit is encrypted via HTTPS/TLS 1.2+.
- Security headers: We implement X-Frame-Options, X-Content-Type-Options, HSTS, and other headers to protect against common web attacks.
- API keys: All third-party API keys (Groq, Razorpay, Google) are stored as server-side environment variables and never exposed to the browser.
5. Cookies
Recipiq uses minimal cookies:
- Session cookie (next-auth.session-token): Required for Google Sign-In. Expires when you log out. This is an essential cookie — the Service cannot function without it.
- We do not use advertising cookies, tracking pixels, or third-party analytics cookies.
6. AI & Third-Party Processors
We work with the following data processors:
| Provider | Purpose | Data Shared |
|---|---|---|
| Groq (USA) | AI recipe generation | Ingredient text only |
| Google (USA) | Authentication (OAuth) | Name, email |
| Razorpay (India) | Payment processing | Email, order amount |
| Vercel (USA) | Hosting & CDN | Request logs (no PII) |
7. Your Rights (DPDP Act 2023)
Under the Digital Personal Data Protection Act, 2023, you have the right to:
- Access: Request a copy of the personal data we hold about you
- Correction: Request correction of inaccurate data
- Erasure: Request deletion of your account and associated data
- Withdraw consent: Revoke Google OAuth access at any time via your Google Account settings
- Grievance redressal: File a complaint with us or the Data Protection Board of India
To exercise any of these rights, email us at support@recipiq.app. We will respond within 30 days.
8. Children's Privacy
Recipiq is not directed at children under the age of 13. We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, contact us immediately at support@recipiq.app and we will delete it.
9. Data Retention
- Subscription records: Retained for 3 years for accounting and legal compliance
- Server logs: Automatically deleted after 30 days
- Google session tokens: Deleted when you sign out
- Your localStorage data: Controlled entirely by you — clear it via your browser settings
10. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with a new "Last updated" date. For material changes, we will notify signed-in users via email at least 14 days in advance.
11. Grievance Officer
In accordance with the Information Technology Act 2000 and rules made thereunder, you may contact our Grievance Officer for any privacy concerns: