Privacy Policy

Last updated: July 29, 2026

ForkThis is built to help you cook better. This policy explains what information we collect, how we use it, where it goes, and the choices you have. If you have questions, email [email protected].

1. Who We Are

The ForkThis application and related services (the "Service") are operated by Thornveil LLC ("we," "us," or "our"), the controller of the personal information described in this policy. "ForkThis" is a trade name of Thornveil LLC. The Service is operated from the United States.

2. Information We Collect

Account information. When you create an account, we collect your email address and password, or your identity from Google or Apple sign-in where available (email, and name if the provider shares it). Your email is used to authenticate you and to send essential account communications (password resets, major service changes). We do not send marketing emails without your explicit consent.

Profile and preferences. A display name, avatar, and bio if you set them; kitchen equipment; and taste-profile preferences such as dietary flags, disliked ingredients, skill level, and household size, if you choose to provide them.

App content. The data you create in ForkThis: recipes you import or write, photos and notes you attach, your pantry inventory, grocery lists and purchase history, meal plans, cook history, badges, ratings, and issue reports you submit.

Media you submit. Photos you take or upload for ingredient and receipt scanning, and the URLs, text, or media you submit for recipe import.

Usage data. Aggregate, anonymized analytics (which features are used, app performance metrics) via Plausible Analytics โ€” a cookie-free tool that does not track individuals across sites. We also keep per-account usage counts and service activity records (for example, imports and scans you run) to enforce free-tier limits and detect abuse.

Error reports. If the app crashes or encounters an error, error reports are collected via Sentry (in the app and on our servers). These include technical details about your device and the action that failed.

Server logs. Like most services, our servers and hosting providers record standard request logs, which include IP address, request time, and request metadata.

Payment information. Payments are processed by Stripe, PayPal (including Venmo), or the Apple App Store / Google Play. We never see or store your full payment card number. We retain transaction records (amounts, dates, subscription status) for accounting and legal compliance.

3. How We Use Information

We do not sell your personal information. We do not use your pantry, recipe, or grocery data for advertising profiling, and we do not share personal information for cross-context behavioral advertising.

4. Where Your Data Lives: Storage, Sync, and Backups

With an account. If you sign in, your recipes, pantry items, grocery lists, folders, meal plans, preferences, profile, subscription status, and usage counts are transmitted to and stored on servers we control or contract for: our server database hosted on Railway, and Supabase (which provides authentication and hosts shared and public recipe data and re-hosted recipe images). A copy of your content is also cached on your device to support offline use.

We can access server-stored data. Access is limited to what is needed to operate, debug, support, and secure the Service, and to comply with legal obligations.

Backups. We take automated nightly backups of our server database and retain them on a rolling window of roughly seven days (copies are kept both alongside the server and in cloud storage) before they are overwritten.

In guest mode. If you use the Service without an account, your data is stored only in your browser's local storage on your device. It is not transmitted to our servers, except when you actively use an AI-assisted feature, which necessarily transmits the content you submit. We cannot recover, transfer, or access guest data; clearing your browser data, uninstalling the app, or signing out erases it; and guest data is not merged into an account if you later sign up.

5. Sharing Features You Control

Households. If you create or join a household, your pantry items, grocery items, and grocery purchase history associated with that household become visible to other household members, and members can see the household's member list. Anyone with the household invite code can join, so share codes carefully.

Shared cookbooks. If you create or join a shared cookbook, recipes added to it become visible to other cookbook members.

Public recipe pages. If you publish a recipe to a public page, that recipe โ€” including its title, image, ingredients, instructions, and any notes or photos embedded in it โ€” becomes accessible to anyone with the link, may be indexed by search engines, and may appear as a link preview on other platforms. Recipe images may be re-hosted in a publicly accessible storage bucket. Published recipes remain public after you delete your account unless you unpublish them first or ask us to remove them.

These features are optional and require your action to enable.

6. AI Processing

When you use AI-assisted features, the relevant content is transmitted to third-party AI providers for processing:

Anthropic, PBC receives, depending on the feature: the content of recipe URLs or text you submit for import; photos and receipt images you submit for scanning; frames extracted from recipe videos you submit; ingredient names and recipe context for substitution suggestions and ingredient information; a summary of your pantry contents when you request meal suggestions; and recipe text you ask us to translate. Anthropic privacy policy.

OpenAI, L.L.C. receives the audio track extracted from recipe videos you submit, for transcription. OpenAI privacy policy.

We do not send your account credentials to AI providers, and pantry or preference data is sent only as part of a request you initiate (for example, a meal-suggestion request that references your pantry).

Once a URL has been successfully imported, the extracted recipe is cached on our servers. Subsequent imports of the same URL by any user return the cached result without additional AI processing. Cached extractions are not tied to your account and may be retained after you delete your account.

When you submit a social media or website URL for import, we may use third-party content retrieval services to fetch the publicly posted content at that URL; the URL you submit is transmitted to those services.

7. Other Third-Party Services

Legal disclosures. We may disclose information if required by law, court order, or government request, or if we believe in good faith that disclosure is necessary to protect the rights, property, or safety of Thornveil LLC, our users, or the public.

8. Voice, Camera, Notifications, and Device Features

Voice control and read-aloud. Cook Mode's voice commands use your browser's built-in speech recognition (the Web Speech API). Your voice audio is processed by your browser โ€” depending on the browser, that may involve the browser vendor's own speech service โ€” and only the recognized text is used, on your device, to match commands. ForkThis never receives or stores your voice audio. Read-aloud uses your device's built-in text-to-speech and happens entirely on your device.

Camera and photos. Photos you take or choose for ingredient or receipt scanning are sent to our server and then to Anthropic for analysis (Section 6). The barcode scanner processes the camera feed on your device and sends only the decoded barcode number to Open Food Facts.

Notifications. Expiration alerts and cooking timers are generated on your device if you allow notifications. If you enable push notifications, we store a push subscription for your device, and notification contents may include the names of pantry items (for example, an item that is expiring soon).

Location. We do not collect your location.

9. Cookies and Local Storage

The Service uses your browser's local storage โ€” not cookies โ€” to cache your data on your device, store preferences, and keep you signed in (your authentication session token is stored locally). These uses are strictly necessary for the Service to function.

We do not use advertising cookies, third-party tracking pixels, or cross-site tracking. Our analytics provider does not use cookies.

10. Data Retention

11. Your Rights: Export and Deletion

You can act on your own data directly in the app, whenever you want:

You may also request access, correction, deletion, or a portable copy of your personal information by emailing [email protected]. We will respond to verifiable requests within 30 days or as required by applicable law.

12. US State Privacy Rights

Depending on your state of residence, you may have statutory rights to access, correct, delete, or obtain a copy of your personal information, and to opt out of targeted advertising, sales of personal information, or certain profiling. We honor access, correction, deletion, and portability requests for all users regardless of location through the mechanisms in Section 11. We do not sell personal information, do not share it for cross-context behavioral advertising, and do not engage in profiling that produces legal or similarly significant effects โ€” so there is nothing to opt out of.

California residents (CCPA/CPRA): you have the right to know the categories and specific pieces of personal information we collect (described in Section 2), to delete and correct personal information, to non-discrimination for exercising your rights, and to use an authorized agent to submit requests.

13. International Users

The Service is operated from the United States. If you access it from outside the US, your information will be transmitted to, processed, and stored in the United States, where data-protection laws may differ from those in your country, and may be processed by the US-based providers listed in this policy. EU/UK users may exercise the rights described in Sections 11โ€“12 using the same mechanisms.

14. Children

ForkThis is not directed at children under 13, and we do not knowingly collect personal information from children under 13. If we become aware that we have collected personal information from a child under 13 without parental consent, we will delete it. If you believe this has happened, contact [email protected].

15. Security

We use reasonable technical and organizational measures to protect your information, including HTTPS encryption in transit, row-level access controls restricting each account's data to that account, token-based authentication with server-side verification, and access controls on server-side data. No security system is impenetrable, and we cannot guarantee absolute security; please keep your own credentials and devices secure.

Breach notification. If we become aware of a security incident affecting your personal information, we will notify you and any required regulators as and when required by applicable law.

16. Changes to This Policy

We will notify you of material changes to this policy via email or an in-app notice before the changes take effect. The "Last updated" date at the top reflects the current version.

17. Contact

Questions, concerns, or privacy requests? Contact:

Thornveil LLC
Email: [email protected]
Website: forkthis.app
Mailing address: [INSERT THORNVEIL LLC MAILING ADDRESS]

ForkThis is a trade name of Thornveil LLC. ยฉ 2026 Thornveil LLC.


โ† Back to ForkThis ยท Terms of Service ยท Support