Who is responsible
This policy applies to the Cookta mobile application and cookta.app. The data controller is Adam Vajda, the individual developer and operator of Cookta, established in Hungary. Contact the controller at vajdaad4m@gmail.com. Cookta has not appointed a data protection officer.
Data Cookta collects
You can browse recipes and use active cooking guidance as a guest without creating an account. In guest mode, Cookta does not send account identity, bookmarks, cooking history, allergy choices, diet, or experience preferences to Cookta’s servers. If you choose to sign in, Cookta collects only the information needed to provide the account features you request:
- Account information: your name, email address, Cookta user ID, and sign-in provider information supplied by Google or Apple.
- Cooking preferences: dietary preference, experience level, preferred measurement system, and—only with your explicit consent—optional allergy exclusions. Allergy exclusions are treated as health-related information and used only for recipe filtering and warnings.
- Saved content: identifiers for recipes you save.
- Cooking history: the recipe identifier and the date and time a cook was completed.
- Optional product analytics: if you opt in, a random installation identifier, operating system, broad device type, and allowlisted events for onboarding completion, opening a recipe, starting, completing, or abandoning a cook, using a timer, and requesting account deletion. Events may include a recipe ID, step ID, screen source, or cooking phase where needed to understand the feature.
- Optional privacy-minimized app diagnostics: if you opt in, a random installation and short-lived session identifier, exception class, code stack or native crash trace, app version and build, release environment, operating-system version, and device type or model. These reports help Cookta identify and repair crashes and serious app errors.
- Consent records: the policy version, decision, decision time, and where the choice was made. These records are linked to your account so Cookta can apply your choices and demonstrate them.
- Aggregate website analytics: page path, referrer, approximate location, device type, operating system, and browser information for visits to cookta.app. Cookta removes every query string and URL fragment before an analytics event is sent. Vercel Web Analytics aggregates this information without third-party cookies and does not associate page views with a Cookta account or retain the raw IP address in Cookta’s reports.
- Optional deletion feedback: a selected reason or free-form comment sent as part of the authenticated deletion request, then stored separately without your user ID or email. Do not include names, contact details, or other identifying information in the comment.
Mobile analytics and diagnostics are off by default. The PostHog client does not initialize before you choose to enable them. They do not include your name, email address, Cookta account ID, advertising identifier, search text, cooking preferences, allergy selections, or deletion feedback. JavaScript diagnostic reports replace raw error messages with the exception class and remove local file paths, source-code context, variable values, and all properties outside a strict technical allowlist. Cookta does not collect console logs, diagnostic breadcrumbs, recipe activity, allergy choices, screen contents, touches, or recordings with a crash report. Native reports can include a platform-generated crash reason and technical stack trace.
Cookta does not use analytics or diagnostics for advertising, cross-app tracking, session replay, or precise-location profiling.
Beyond the allergy exclusions you choose to save, Cookta does not collect medical records, diagnoses, symptoms, fitness data, advertising identifiers, precise location, payment details, contacts, photos, or microphone recordings. Cookta does not sell personal data or use it for third-party advertising.
Information kept on your device
An active cooking session, checklist progress, serving and measurement choices, running timer state, and completion of required doneness checks are stored locally so a cook can resume after navigation or an app restart. This applies in guest mode as well as when signed in, with separate local storage namespaces so guest activity cannot be assigned to an account. Guest completions are not added to cooking history. Cookta does not receive the condition of your food or any measured temperature. Timer notifications are scheduled by your device. Signed-in users may also opt in to dinner invitations; Cookta stores that choice on the device and schedules only two local reminders. No remote push token or inactivity history is sent to Cookta. Guest state is removed by clearing Cookta’s app data or uninstalling the app; account-local state is also removed when you delete that account.
Purposes and legal bases
- Providing Cookta (GDPR Article 6(1)(b), contract): providing guest browsing and local active cooking, and—if you choose to sign in—account creation, authentication, synchronization, preferences, saved recipes, and history.
- Allergy protection (Articles 6(1)(a) and 9(2)(a), explicit consent): storing and using the allergy exclusions you select to filter and warn about recipes. This is optional and Cookta remains usable without it.
- Mobile analytics and diagnostics (Article 6(1)(a), consent): measuring allowlisted feature use and diagnosing errors only if you opt in. You can refuse or withdraw without losing Cookta features.
- Security and service integrity (Article 6(1)(f), legitimate interests): preventing abuse, securing accounts, maintaining availability, and investigating technical incidents, balanced against user rights and limited to necessary technical data.
- Consent evidence (Articles 6(1)(c) and 6(1)(f)): keeping a minimal, versioned record so choices can be applied and Cookta can demonstrate compliance.
- Cookie-free website measurement (Article 6(1)(f), legitimate interests): understanding aggregate visits to the public website using daily rotating visitor hashes.
- Optional deletion feedback (Article 6(1)(a), consent): improving Cookta from a reason or comment you choose to submit. It is stored without an account identifier.
Services that process data
Cookta uses Supabase for authentication and database hosting, Google and Apple for sign-in, Vercel to host cookta.app and provide aggregate website analytics, and—only after mobile opt-in—PostHog’s EU service for minimized mobile analytics and diagnostics. Vercel Web Analytics is configured for page views only; Cookta removes query strings and URL fragments before transmission, does not use third-party cookies, and does not identify visitors across websites. PostHog is configured not to create person profiles, enrich events with geolocation, record sessions, capture screens or touches, collect console logs, or collect advertising identifiers. Like other internet services, these providers may process limited network and security information, such as an IP address and request logs, under their own service terms and privacy commitments. They act as processors or independent controllers only where described in their own sign-in notices. Cookta does not sell personal data.
Retention and deletion
- Account, preferences, saved recipes, history and consent records: until you delete the account. Account deletion removes live account-linked rows. Residual encrypted service-provider backups expire under the provider’s restricted backup schedule and are not restored except for disaster recovery.
- Guest active cook and device-only settings: until app removal or clearing the app’s device data. They are not merged into a later account.
- Signed-in active cook and device-only settings: until account deletion, app removal, or clearing the app’s device data.
- Opt-in mobile analytics and diagnostics: no more than 12 months, after which reports are deleted or irreversibly aggregated. Withdrawing stops new collection and removes the queued events and installation identifier from that device; already received reports are not account-linked.
- Account-disassociated deletion feedback: 12 months. The database automatically deletes expired entries.
- Aggregate website analytics: Cookta keeps no separate visitor-level copy. Vercel rotates the temporary visitor hash after 24 hours and makes only aggregate reports available within the active plan’s reporting window.
- Privacy and support correspondence: up to 24 months after the request is closed, or longer only when needed to establish, exercise or defend a legal claim.
- Security logs: normally up to 90 days, unless a longer period is necessary for an active security incident or legal obligation.
You can permanently delete the account from Settings → Delete account or through our web deletion page.
Your choices and rights
Guest mobile telemetry is off and no allergy preferences can be stored. After signing in, you can change privacy-minimized mobile telemetry in Settings → Privacy choices. You can withdraw allergy consent there at any time; Cookta immediately stops using the choices on that device and queues their removal from your account. If the device is offline, account removal completes when it reconnects. Withdrawal does not affect processing that was lawful before withdrawal.
Under the GDPR, you may request access, correction, erasure, restriction, portability, or object to processing based on legitimate interests. You may also withdraw consent at any time. Use the support page or email the controller. Cookta responds without undue delay and normally within one month, subject to permitted identity verification and legal exceptions.
Cookta does not make decisions that produce legal or similarly significant effects. Recipe ranking and filtering only change what is shown in the app.
You may lodge a complaint with the supervisory authority where you live or work. In Hungary, this is the National Authority for Data Protection and Freedom of Information (NAIH), 1055 Budapest, Falk Miksa utca 9–11. You also have the right to seek a judicial remedy.
Security and international processing
Cookta uses encrypted HTTPS connections, provider-managed authentication, row-level database access controls, append-only consent records, restricted server credentials, and data minimization. No system is perfectly secure. Where a provider processes personal data outside the EEA, Cookta relies on an adequacy decision or appropriate safeguards such as the European Commission’s Standard Contractual Clauses, as applicable.
Children and age eligibility
Cookta is intended only for people aged 18 or older. Before either guest access or sign-in becomes available, the entry flow requires a person to confirm that they meet this minimum age. Account-scoped Terms acceptance repeats the requirement. Cookta does not ask for or store a date of birth.
Cookta does not knowingly offer guest access or accounts to anyone under 18. If you believe someone under 18 has created an account or provided personal data, contact the controller so the account and associated data can be investigated and deleted.
Policy changes and contact
This notice is version 2026-08-27. Material changes receive a new version and Cookta asks signed-in users to acknowledge the updated notice before account processing continues. For privacy questions, contact the controller or visit Cookta support.