BroccoliciousBack to home

Privacy

Privacy Policy

Effective July 29, 2026 · Version 1.0

This Policy explains what personal data Broccolicious handles in its current free beta, why we use it, who helps us process it, and the choices available to you.

1. Controller and contact

Z. Galili, trading as Broccolicious, based in the Netherlands, is the controller of the personal data described in this Policy.

For privacy questions, rights requests, account deletion, legal matters, or support, email support@broccolicious.app.

2. Age and guardian-managed accounts

Broccolicious is for users aged 13 and older. A user aged 13 to 15 may use the service only through an account created and controlled by their parent or legal guardian. The guardian should contact us about privacy requests for that account.

If you believe a child is using Broccolicious outside these conditions or provided personal data improperly, contact us so we can investigate and take appropriate action.

3. Personal data we handle

Account and authentication data. Your email address, Supabase user identifier, account creation date, authentication records, and basic profile information returned by Google or Apple when you choose those sign-in methods.

Waitlist data. The email address you submit, the App Store or Google Play beta you select, your waitlist status, and related timestamps. Browser and operating-system signals are used on your device to suggest a store choice. The selected store, rather than those raw signals, is saved as a waitlist field; device or browser information may also appear in normal request logs as described below.

Recipe and source data. Submitted URLs, original and canonical source links, source platform and creator details, extracted titles, descriptions, ingredients, steps, tags, language, timings, servings, warnings, confidence information, nutrition data, and the structured extraction result.

Recipe images. A source image URL and, for some social sources, a cached copy stored under an account-specific path so the recipe remains usable when the original temporary image URL expires.

Library, shopping, and activity data. Saved recipes, shopping-list items and their recipe sources, cook counts, cook-completion identifiers, and recipe-import counts.

Import problem reports. When you choose “Report problem” after a failed import, we store your account identifier and email, the submitted source URL, error type, error message, report status, and timestamps.

Device-local data. Authentication session information, a pending shared recipe URL, shopping-list display preferences, and similar settings stored on your device.

Technical and security data. IP address, request timing, request identifiers, device or browser information, service logs, and error details made available to us or our hosting providers.

Support correspondence. Your email address and the contents and metadata of messages you send to us.

4. How recipe import works

When you submit a link, our servers request publicly available content from the source website or social platform. The requested URL and relevant public recipe text or metadata may be processed by retrieval services and Google Gemini to produce a structured recipe.

We do not intentionally send your Broccolicious account email to Gemini as part of recipe extraction. Source websites may receive the server address, user agent, requested URL, and normal request information when content is retrieved.

5. Why we use personal data

We use personal data to:

  • create and secure accounts and keep you signed in;
  • retrieve, extract, translate, save, search, and display recipes;
  • provide shopping-list, cooking-history, and account features;
  • manage beta access and respond to support or privacy requests;
  • diagnose failed imports, prevent abuse, and keep the service reliable and secure;
  • understand basic operational usage through account-level counts; and
  • meet legal obligations and establish, exercise, or defend legal claims.

6. Legal bases

Where EU or UK data-protection law applies, we rely on performance of our agreement with you to provide requested account and product features; our legitimate interests in operating, securing, supporting, and improving the beta; compliance with legal obligations; and consent where the law requires it for a specific optional activity.

You may object to processing based on legitimate interests. We will assess the request against our reasons for processing and your rights.

7. Service providers and recipients

We use the following categories of recipients to operate Broccolicious:

  • Supabase for authentication, the Postgres database, and recipe-image storage. The current Broccolicious project is hosted in Supabase’s EU North region.
  • Google for Gemini recipe extraction, YouTube data retrieval, Gmail support handling, and Google sign-in when selected.
  • Apple for Apple sign-in when selected.
  • Railway for API and website hosting, networking, and operational logs.
  • Public source websites, social platforms, and retrieval services needed to fetch a submitted link, including direct website requests and intermediary text-retrieval services where a direct fetch does not provide usable content.

Providers process data under their own terms or on our instructions, depending on the service. We may also disclose information where required by law, to protect rights and security, or in connection with a lawful transfer of the service.

We do not sell personal data. The current beta has no advertising network, cross-service behavioral advertising, or third-party product-analytics SDK.

The current beta does not use a dedicated third-party crash or error-monitoring service. If we introduce one and it will receive personal data, we will update this Policy and the provider list before enabling that processing, and request consent where the law requires it.

8. International transfers

Some providers may process data outside the European Economic Area. Where required, we rely on an adequacy decision, approved contractual safeguards such as Standard Contractual Clauses, or another lawful transfer mechanism.

9. Cookies and device storage

Authentication may use cookies or similar technologies where the web service needs them. The mobile app stores session information and product preferences locally on your device. These technologies are used to provide requested features, security, and continuity.

Broccolicious does not currently use optional advertising or product-analytics cookies. If that changes, we will update this Policy and request consent where required before enabling them.

10. Retention

Account, recipe-library, shopping-list, and activity data is generally kept while your account remains active. Individual recipe records and their cached images are removed when you delete the recipe, subject to normal processing and backup cycles.

Waitlist data is kept while reasonably needed to manage beta invitations and follow-up, or until you withdraw. Import problem reports are kept while needed to diagnose recurring failures and improve reliability. Support records and technical logs are kept for as long as reasonably needed for support, security, incident response, dispute handling, or legal compliance.

When data is no longer needed, we delete or anonymize it. Limited copies may remain temporarily in backups or be retained where the law, security, fraud prevention, or a legal claim requires it.

11. Account deletion

To request deletion, email support@broccolicious.app from the address connected to your account and state that you want your Broccolicious account deleted.

We may ask for information needed to verify the request. After verification, we will delete the account and associated recipe, shopping, activity, report, and cached-image data unless we must retain limited information for a legal or security reason. Deletion is permanent.

12. Your privacy rights

Depending on where you live, you may have rights to access, correct, delete, restrict, or object to processing; receive a portable copy of data you provided; and withdraw consent without affecting processing that was lawful before withdrawal.

Send requests to support@broccolicious.app. We may need to verify your identity and will respond within the period required by applicable law. You also have the right to complain to the Dutch Data Protection Authority or the competent authority where you live or work.

13. Security

We use reasonable technical and organizational safeguards, including authenticated access, row-level database access controls, transport encryption, and account-scoped storage paths. No online service can guarantee absolute security. Use a strong, unique password and contact us if you suspect unauthorized access.

14. Changes to this Policy

We may update this Policy when the service, providers, or law changes. The effective date and version above identify the current Policy. We will provide reasonable notice of material changes.

We will review this Policy before launching payments, analytics, advertising, household sharing, dietary profiles, photo or OCR import, or a new material processor.

Broccolicious

Saved recipes, ready for real life.

TermsPrivacyContact