Privacy Policy

Last updated: July 30, 2026 · Version 2026-07-30

The short version.

This summary is for orientation only. The full policy below is what applies.

This Privacy Policy explains how Stove Pals collects, uses, shares, and protects personal information when you use stovepals.com and the Stove Pals app (the “Service”). It also explains the choices and rights you have.

Contents

  1. Who is responsible for your data
  2. Information we collect
  3. Where we get it
  4. How we use it
  5. Our legal bases (EEA/UK)
  6. AI processing
  7. How we share information
  8. Cookies and tracking
  9. International transfers
  10. Your rights and choices
  11. Do not sell or share my information
  12. How long we keep data
  13. Deleting your account
  14. Security
  15. Children’s privacy
  16. Information you make public
  17. Automated decision-making
  18. Changes to this policy
  19. Contact us

1. Who is responsible for your data

The data controller for your personal information is [ADD BEFORE LAUNCH: full legal name of the operating entity or individual], located in Minnesota, United States, operating as “Stove Pals” (“we,” “us,” “our”).

Contact: jrhq.net@gmail.com
Postal address: [ADD BEFORE LAUNCH: postal address]

We are a small operation and do not have a designated Data Protection Officer. Privacy enquiries go to the email address above and are handled directly by the operator.

2. Information we collect

2.1 Account information

2.2 Content you create

2.3 Diet and nutrition information

If you use the nutrition features, we collect the nutrition goals you set, the meals you log, calorie and nutrient figures, and any dietary preferences, restrictions, or allergy-related tags you record. In a family with tracking enabled, we also record which member ate which planned meal.

Depending on what you enter, this information can reveal something about your health — for example a medically restricted diet or an allergy. Under EU and UK law that is a special category of personal data. These features are entirely optional, and we process this information only on the basis of your explicit consent, given by choosing to use them. You can stop at any time and delete what you have recorded.

2.4 Uploads and AI inputs

Photos may contain more than the food you intended to capture — a kitchen, a document, a screen, or other people. Please avoid uploading anything you would not want sent to a third-party AI provider.

2.5 Usage, device, and technical information

2.6 Information about guests and invitees

If you invite someone to a family or an event, you give us their email address so we can send that invitation. If someone signs up to an event as a guest without creating an account, we collect the name they enter, optionally what they are bringing, and optionally an email address if they ask for a reminder. We use this only to run the event and to send the reminder they asked for.

We do not collect precise geolocation, we do not access your contacts, camera roll, or microphone beyond the single photo you choose to upload, and we do not buy personal information from data brokers.

3. Where we get it

Almost everything comes directly from you. We also receive: technical and usage data automatically from your browser; authentication data from Google Firebase when you sign in; recipe content from a third-party website when you ask us to import from a link; and information about you from another user when they invite you to a family or an event, or when you appear as a guest on an event they created.

4. How we use it

We do not use your content to train AI models, and we do not use your recipes, plans, photos, or nutrition data to build advertising profiles about you.

5. Our legal bases (EEA/UK)

If you are in the European Economic Area or the United Kingdom, we rely on the following legal bases under the GDPR and UK GDPR:

Purpose Legal basis
Creating your account and providing the Service Performance of a contract (Art. 6(1)(b))
AI processing of content you submit Performance of a contract (Art. 6(1)(b))
Transactional email and invitations Performance of a contract (Art. 6(1)(b))
Security, abuse prevention, and rate limiting Legitimate interests (Art. 6(1)(f)) — keeping the Service safe and available
Product improvement from aggregated usage Legitimate interests (Art. 6(1)(f)) — improving a service you use
Analytics and advertising cookies Consent (Art. 6(1)(a)), withdrawable at any time
Optional lifecycle/marketing email Consent, or legitimate interests where permitted; always withdrawable
Diet, nutrition, and allergy information Explicit consent (Art. 9(2)(a)) where it constitutes health data
Meeting legal obligations and defending claims Legal obligation (Art. 6(1)(c)); legitimate interests (Art. 6(1)(f))

Where we rely on legitimate interests, we have considered the impact on you and concluded that our interests do not override your rights. You may object — see Section 10.

6. AI processing

When you use an AI feature, the content you provide for that feature — a photo, a PDF, a pasted link and the page content behind it, or a text description — is transmitted to Google’s Gemini API for processing, and the generated result is returned to you and saved to your account.

We send only what is needed for the task. We do not send your account email, your family membership, your nutrition history, or your other recipes along with it unless that information is what you asked the feature to work on.

Google processes this content as our service provider under the Google APIs Terms of Service and its data processing terms. Neither we nor Google use your content to train generative AI models under the paid API terms we operate under.

AI providers may retain submitted content for a short period for abuse monitoring and service operation before deleting it, in line with their own published policies.

Please do not submit sensitive content to AI features. Avoid uploading images containing identity documents, medical records, financial statements, screens showing private data, or photographs of other people, particularly children. Once content is sent for processing we cannot recall it.

Separately, and importantly: AI output is frequently inaccurate. For what that means for your safety, see our Disclaimers and Terms of Service.

7. How we share information

We do not sell your personal information for money, and we have not done so in the preceding twelve months. We share information only as described here.

7.1 Service providers

Provider What it does What it receives
Google Firebase Authentication, database, file storage Account credentials, all content you save, uploaded files
Google Gemini API AI recipe and nutrition processing Only the photo, PDF, link content, or text you submit to an AI feature
Railway Application hosting Request data, IP address, server logs
Google Analytics Usage measurement Pseudonymous usage events, device and browser data, truncated IP — only with your consent
Meta (Facebook) Pixel Advertising measurement and audiences Page views, signup completion events, cookie identifiers, IP address — only with your consent
Google Gmail API Sending our email Recipient email address and message content
Google Docs API Logging product feedback you submit The feedback text and the email address you provide
Google Fonts, Cloudflare CDN Serving fonts and icon assets IP address and browser data, as part of loading the asset

These providers are permitted to use the information only to perform services for us. If we add or change a provider in a way that materially affects your privacy, we will update this policy.

7.2 People you choose

Members of a family group you create or join can see the content shared into that group. Guests of an event you create can see the event and other guests’ names and dishes. Anyone can see a recipe you publish to the Discover feed, along with your display name and profile photo.

7.3 Legal and safety

We may disclose information where we reasonably believe it is required by law, subpoena, or other legal process, or where necessary to investigate suspected fraud or abuse, to enforce our Terms, or to protect the rights, property, or safety of our users, the public, or us. Where the law allows it, we will try to notify you of a legal demand for your data.

7.4 Business transfers

If Stove Pals is involved in a merger, acquisition, financing, or sale of assets, your information may be transferred as part of that transaction. We will notify you before your information becomes subject to a materially different privacy policy, and the acquirer will be bound by commitments at least as protective.

7.5 Aggregated and de-identified data

We may create and use aggregated or de-identified information — for example, how many users publish a recipe in a week. We will maintain it in de-identified form and will not attempt to re-identify it.

8. Cookies and tracking

We use a small number of cookies and similar technologies (including browser local storage). Strictly necessary ones keep you signed in, hold your session, and remember your cookie choice. Optional ones power analytics and advertising measurement, and load only after you accept them.

Our Cookie Policy lists each one, what it does, and how long it lasts. You can change your choice at any time from the Cookie settings link in any page footer.

We honour the Global Privacy Control (GPC) signal. If your browser sends GPC, we treat it as a valid opt-out of advertising and analytics cookies and of the “sharing” described in Section 11, and we do not load those trackers.

9. International transfers

We operate from the United States, and our providers process data in the United States and other countries. If you are in the European Economic Area, the United Kingdom, or Switzerland, your information will be transferred outside your country to a jurisdiction that may not offer the same level of legal protection.

Where required, we rely on the European Commission’s Standard Contractual Clauses (and the UK Addendum / International Data Transfer Agreement) as incorporated into our providers’ data processing terms, together with the providers’ supplementary technical measures such as encryption in transit and at rest. You may request more information about these safeguards at the contact address below.

10. Your rights and choices

10.1 Everyone

10.2 EEA, UK, and Switzerland

You have the right to access your data; to rectification; to erasure; to restrict processing; to data portability; to object to processing based on legitimate interests, including profiling; and to withdraw consent at any time without affecting processing already carried out. You also have the right to lodge a complaint with your local supervisory authority — in the UK, the Information Commissioner’s Office — although we would appreciate the chance to resolve the matter first.

10.3 California

Under the CCPA as amended by the CPRA, California residents have the right to know what personal information we collect, use, disclose, and share; to access it and receive a copy; to correct inaccurate information; to delete it; to opt out of its sale or sharing; to limit the use of sensitive personal information; and not to be discriminated against for exercising these rights.

In the preceding twelve months we collected the categories of personal information described in Section 2: identifiers, customer records, internet and network activity, commercial information, visual information (photos you upload), inferences generated by AI features, and — if you use nutrition features — information that may constitute sensitive personal information relating to health. We disclosed those categories to the service providers listed in Section 7 for the business purposes described in Section 4.

We do not sell personal information, and we do not knowingly sell or share the personal information of anyone under 16. However, our use of the Meta Pixel constitutes “sharing” for cross-context behavioural advertising under California law. See Section 11 to opt out.

We use sensitive personal information only to provide the features you asked for, and never to infer characteristics about you, so the “limit the use of my sensitive personal information” right does not change how we operate. You may still submit a request.

You may use an authorised agent to make a request; we will ask for proof of authorisation and may ask you to verify your identity directly.

Shine the Light. California Civil Code § 1798.83 permits residents to request details of personal information shared with third parties for their direct marketing purposes. We do not share personal information for that purpose.

10.4 Other U.S. states

If you are a resident of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Minnesota, Maryland, Rhode Island, Tennessee, Indiana, Kentucky, or another state with a comprehensive privacy law in force, you have broadly similar rights: to confirm whether we process your data, to access and obtain a copy of it, to correct it, to delete it, and to opt out of targeted advertising and of any sale of your data. Several of these states also give you the right to appeal a decision we make on your request; if we decline a request, our response will explain how to appeal, and if the appeal is denied you may contact your state attorney general.

Minnesota residents additionally have the right to obtain a list of the specific third parties to which we have disclosed personal data, and rights concerning profiling. Section 7 above lists every recipient; you may also request a personalised list.

10.5 How to make a request

Email jrhq.net@gmail.com with the subject line “Privacy Request” and tell us what you want. We will verify your identity, usually by confirming control of the email address on the account, and will not ask for more information than we need.

We respond within 45 days (extendable by a further 45 days where permitted, with notice), and within one month for GDPR requests (extendable by two further months for complex requests, with notice). Requests are free unless they are manifestly unfounded or excessive.

11. Do not sell or share my information

We do not sell personal information. We do share limited information with Meta through the Meta Pixel for cross-context behavioural advertising, and with Google Analytics for measurement, as those terms are defined under California and other state privacy laws.

You can stop this in any of three ways:

  1. Open Cookie settings from any page footer and reject analytics and advertising cookies. This is the direct opt-out mechanism, and it takes effect immediately on this browser.
  2. Enable Global Privacy Control in your browser or extension. We detect and honour it automatically.
  3. Email jrhq.net@gmail.com and ask us to record an account-level opt-out.

Because these opt-outs are stored in your browser, you will need to repeat the first option on each browser and device you use, and after clearing your cookies.

We will not discriminate against you for opting out. The Service works the same either way.

12. How long we keep data

Data Retention
Account and content you create Until you delete it, or until your account is deleted
Uploaded photos and PDFs Until you delete the item they belong to, or your account
Content sent to the AI provider Not retained by us beyond the resulting recipe; the provider may hold it briefly for abuse monitoring under its own policy
Recipes published to Discover Until you unpublish; copies saved by other users remain in their libraries
Guest event signups For the life of the event, then deleted with the event
Server and security logs Typically up to 30 days, as retained by our hosting provider
Analytics data Up to 14 months in Google Analytics; Meta’s own retention applies to Pixel data
Email delivery records As retained in the sending mailbox, typically up to 12 months
Records of privacy requests Up to 24 months, as required to demonstrate compliance
Backups Deleted content may persist in routine backups for a limited period before being overwritten

We may retain information longer where necessary to comply with a legal obligation, resolve disputes, or enforce our agreements.

13. Deleting your account

You can request deletion of your account and associated data from the Account page, or by emailing jrhq.net@gmail.com.

Deletion requests are currently processed manually. We will confirm receipt promptly and complete the deletion within 30 days, and always within the time limits required by applicable law. Once deleted, your data cannot be recovered.

Some things do not disappear when your account does:

If you are the last administrator of a family group, tell us what you would like to happen to it when you request deletion.

14. Security

We take security seriously and use measures appropriate to the size of our operation, including: encryption in transit (HTTPS/TLS) across the whole site; encryption at rest at our infrastructure providers; authentication and password hashing handled by Google Firebase; server-side authorisation checks and database security rules so users can only reach their own data; a strict Content Security Policy; rate limiting on sensitive and expensive endpoints; input validation and output escaping; and signed, verified links for actions such as unsubscribing.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. Please use a strong, unique password and tell us immediately if you suspect unauthorised access.

If a breach affecting your personal information occurs, we will notify you and the relevant regulators where the law requires it, and without undue delay.

Reporting a vulnerability. If you believe you have found a security issue, please email jrhq.net@gmail.com before disclosing it publicly. We will not pursue legal action against researchers who act in good faith, avoid privacy violations and service disruption, and give us a reasonable chance to fix the issue.

15. Children’s privacy

The Service is not directed to children under 13, and we do not knowingly collect personal information from them. In the EEA and UK, the minimum age is 16, or the lower age of digital consent set by your country where applicable.

If you are a parent or guardian and believe a child under the applicable age has provided us personal information — including by being added to a family group — contact us at jrhq.net@gmail.com and we will delete the account and its data promptly.

We do not knowingly sell or share the personal information of anyone under 16.

16. Information you make public

Anything you publish to the Discover feed — the recipe, its photo, your display name, and your profile photo — is public. Event pages shared by link are visible to anyone holding the link. Please think before you publish: information you make public can be copied, saved, indexed, or shared by others in ways we cannot control or undo.

17. Automated decision-making

We do not make decisions producing legal or similarly significant effects about you by automated means. Our AI features generate content for you to review; they do not evaluate, score, or profile you.

18. Changes to this policy

We may update this Privacy Policy. When we do, we will revise the “Last updated” date and version above. If a change materially affects how we handle your personal information, we will give you advance notice by email or a prominent in-app notice, and where the law requires it we will ask for your consent.

We keep prior versions on request, so you can see what changed and when.

19. Contact us

Questions, requests, or complaints about this policy or your data:

Email: jrhq.net@gmail.com
Post: [ADD BEFORE LAUNCH: postal address]

We aim to answer every privacy enquiry within a few days, and in all cases within the deadlines set out in Section 10.5.

Terms of Service Cookie Policy Disclaimers