Privacy Policy
Last updated 4 September 2026
The short version. SoopaFood stores the recipes you save and the account you save them under. The browser extension only reads a page when you click its button — it never runs in the background. Recipe text is sent to a few outside services that help extract and index it. We don't sell your data, don't show ads, and don't track your browsing. You can have everything deleted from the web app, the iOS app, or by emailing us.
SoopaFood is a free recipe app: you save recipes from around the web, organise them, plan meals, and build shopping lists. This policy explains exactly what that involves for your data. It covers the website at soopafood.com, the app at app.soopafood.com, the SoopaFood iOS app, and the SoopaFood browser extension for Chrome and Firefox.
What we collect
Your account
When you create an account we store your email address. If you sign in with Google, we receive your email address and basic profile information from Google as part of that sign-in. If you sign in with Apple, we receive your email address — or, if you choose Apple's "Hide My Email", the private relay address Apple creates for you — and your name the first time you sign in. If you sign in with Facebook, we receive your name, email address, and profile picture from Facebook. If you sign in with a password, we never store the password itself — only a scrambled version of it (hashed with scrypt, using a random salt unique to you). It cannot be turned back into your password, so we cannot read it and neither can anyone who obtained our database.
Recipes and the things you make from them
We store the recipes you save, along with anything you build on top of them: your collections, meal plans, shopping lists, any edits you make to a recipe, photos you add to a recipe, and any reports you send us about a recipe that came through inaccurately. Cooking instructions that you save are stored encrypted and are readable only under your account.
If you export your recipes, the export file is kept for up to 7 days so you can download it, then deleted.
The browser extension
This is the part worth being precise about, because it is the part that touches pages you visit.
The extension does nothing until you click its toolbar button. There is no script running in the background on pages you browse. It has no ability to read a page you haven't asked it to read, and it does not collect your browsing history.
When you do click the button, the extension reads the page you are currently looking at — its full HTML and any structured recipe data in it. What it then sends to SoopaFood depends on the page:
- On a page with recipe data: the page's full HTML and its address are sent to SoopaFood so the recipe can be extracted and saved to your collection.
- On a supported social post (Instagram, TikTok, YouTube): only the post's address and the name of the platform are sent. The page content itself is not transmitted.
Reading and sending are separate steps, and we describe them separately because the distinction is real: the extension reads the page in your browser on every click, and only some of what it reads ever leaves your computer.
Technical information
Our servers record your IP address to enforce rate limits and prevent abuse. We use cookies for one purpose: keeping you signed in. Our own logs also record a small number of product events — for example that Cook mode was opened, and whether a request came from the web app, the iOS app, or the extension — plus error reports from the app, so we can tell when something is broken. These stay on our servers. We do not use third-party analytics, advertising, or tracking cookies, and there are no third-party trackers on our site, in the iOS app, or in the extension.
Who else processes your data
Extracting a recipe from a web page is done by machine-learning services we don't run ourselves, so recipe content is sent to them. These are the only outside companies that receive your data, and what each one gets:
| Service | What it receives | Why |
|---|---|---|
| OpenAI | The text of the recipe page you imported, the ingredient lines in it, and the searches you type | To identify the ingredients, quantities, and steps in a recipe, and to understand what a search is asking for |
| DeepSeek | The same as OpenAI, but only as a standby if OpenAI is unavailable | Backup for the same extraction work |
| Google (Gemini) | Recipe titles and ingredient names | To build the search index that makes recipes findable |
| Google (YouTube), TikTok, ScrapeCreators | The address of a YouTube, TikTok, or Instagram post you import — each service only the posts from its own platform (ScrapeCreators handles Instagram) | To fetch the post's public description so the recipe in it can be extracted |
| Google (Sign-In) | Your sign-in request — only if you choose Google sign-in | To verify who you are |
| Apple (Sign in with Apple) | Your sign-in request — only if you choose Sign in with Apple | To verify who you are |
| Facebook (Facebook Login) | Your sign-in request — only if you choose to continue with Facebook | To verify who you are |
| Resend | Your email address and the emails we send you (verification, password reset) | To deliver those emails |
| Amazon Web Services | Everything, as our hosting provider (United States) | To run the servers and store the database |
| Cloudflare | Traffic between you and our servers | To route and protect that traffic |
None of these companies receive your data for their own marketing, and we do not sell or rent your information to anyone.
How long we keep it
We keep your recipes and account data for as long as your account exists. We don't put an expiry date on saved recipes — they're yours to keep. If you delete your account, we delete them.
Records of import activity — the addresses you imported and when — are kept for up to 90 days and then deleted automatically. Recipe export files are deleted after 7 days.
Deleting your data
You can delete your account and everything associated with it — your saved recipes, collections, meal plans, shopping lists, photos, and saved instructions — from the web app (account menu → Settings → Delete Account), the iOS app (account menu → Delete Account), or by emailing privacy@soopafood.com from the address on your account, in which case we will delete it within 30 days and confirm when it's done. If you signed in with Apple or Facebook, deleting your account from the app also asks Apple or Facebook to revoke SoopaFood's access. Step-by-step instructions are on our delete your account page.
What we don't do
- We do not sell or rent your personal information.
- We do not show ads, and we do not share your data with advertisers.
- We do not collect your browsing history or track which sites you visit.
- We do not use third-party analytics or tracking tools on our site, in the iOS app, or in the extension.
Children
SoopaFood is not intended for children under 13, and we do not knowingly collect personal information from them. If you believe a child under 13 has given us their information, email privacy@soopafood.com and we will delete it.
Changes to this policy
If we change this policy we will update the date at the top of this page. If a change materially affects what we collect or who receives it, we will say so on the site rather than change it quietly.
Contact
Questions about privacy, or requests to delete your data: privacy@soopafood.com.
