Privacy Policy
Last updated: 24 August 2026
This Privacy Policy explains how Pipiro (“Pipiro”, “the app”, “we”, “us”) collects, uses, and protects your personal data when you use the Pipiro mobile application and related services.
We respect your privacy and are committed to protecting your personal data in accordance with the EU General Data Protection Regulation (GDPR) and applicable Lithuanian law.
1. Who is responsible for your data (Data Controller)
Pipiro is operated by an individual sole developer:
- Controller: Andrius Čepukas
- Country: Lithuania (European Union)
- Contact: via our contact form
If you have any questions about this policy or how your data is handled, please get in touch via our contact form.
2. What data we collect
We only collect data that we need to provide the app’s features.
2.1 Account data
- Email address - used to sign you in and to send you one-time sign-in codes.
- Authentication identifiers - if you sign in with Google or Apple, we receive a unique account identifier from that provider (and, where you allow it, your name).
- Display name (optional) - if you choose to set one.
- Profile photo (optional) - if you sign in with Google or Apple and your account has a profile picture, we receive and store its image URL to show your avatar. You can also upload your own profile photo or remove it at any time.
2.2 Content you create
- Recipes you create, import, fork, or edit - including titles, descriptions, ingredients, steps, notes, tags, cooking times, and version history.
- Recipe photos you upload or take with your camera.
- Cook history, collections, shopping lists, and your weekly meal plan that you create to organise your recipes.
2.3 Recipe import data
When you import a recipe from a social or web link, we process:
- the URL you provide;
- the public content of that page (text and images) that we fetch in order to extract the recipe;
- the extracted recipe data returned to you.
The fetched content is sent to our AI provider solely to extract structured recipe information (see Section 4).
2.4 Technical data
- Standard technical information needed to operate a mobile app and cloud backend, such as your IP address, device type, and app version, processed by our infrastructure providers for security, abuse prevention, and reliability.
- Local settings stored only on your device (e.g. preferences), which are not transmitted to us.
2.5 One-time codes
When you sign in by email, we store a hashed (irreversible) version of your one-time code temporarily (it expires within 10 minutes) to verify your login.
2.6 Usage analytics
To understand how the app is used - which features are used and which are not - and to guide improvements, we collect aggregated, privacy-preserving usage statistics: counts of actions such as recipes created, imported, or cooked, and whether key features are used. We also count new sign-ups, and to measure retention we record once per day that your account was active.
This analytics is first-party: it is generated by our own backend from the actions you take in the app and stored only in our own infrastructure (see Section 5). We do not use Google Analytics or any third-party analytics SDK, we do not use advertising or cross-app tracking identifiers, and we never include the content of your recipes, collections, or notes in these statistics - only counts and whether a feature was used. Because the statistics are aggregated and contain no tracking identifiers, they do not require a consent banner; we rely on our legitimate interest in operating and improving the app (Art. 6(1)(f)). The account activity used for retention is deleted when you delete your account.
Apple Search Ads attribution (iOS only). We advertise Pipiro on the App Store, and to know whether those ads bring people who actually use the app, we ask Apple - once, when you first sign in after installing - whether your download came from one of our Apple Search Ads campaigns. This uses Apple’s AdServices framework in its standard mode: Apple answers from its own records, no tracking permission is requested, no advertising identifier is used, and nothing follows you across other apps or websites. Apple’s answer is a yes/no plus campaign-level identifiers (which campaign, ad group and keyword, and the storefront country) - never anything about your device or you. We record it alongside your account’s usage statistics above, so we can compare how people who came from ads and people who found the app themselves use it. It is deleted with your account.
When you import a recipe from a web link and the import fails, we temporarily store the link (URL) you tried to import together with the reason it failed, so we can reproduce the problem and fix our importer (different sites present recipes differently). These records are not linked to your account, are accessible only to us, are never used for advertising or shared with third parties, and are automatically deleted within 30 days. We rely on our legitimate interest in keeping the import feature working (Art. 6(1)(f)).
Basic error and diagnostic logs generated by our backend are covered under technical data (Section 2.4). We do not use third-party advertising SDKs, and we do not sell your personal data.
2.7 Subscription data
If you purchase a paid subscription (monthly or yearly), we process:
- your subscription status and plan (e.g. active or expired, monthly or yearly), so the app can unlock paid features;
- purchase and subscription identifiers provided by Apple or Google (such as a transaction identifier), together with an app-specific user identifier, used to link your purchase to your account and verify your entitlement.
Payment itself is handled entirely by the Apple App Store or Google Play. We never receive or store your card number or other payment details. We use RevenueCat to validate purchases and manage subscription status (see Section 5).
2.8 Nutrition estimation
When you ask Pipiro to estimate a recipe’s nutrition, we process that recipe’s ingredient lines (and its name and description) to calculate approximate calories and macronutrients. The ingredient text is sent to our AI provider solely to match each ingredient to reference nutrition values and estimate portion weights (see Section 4). We do not derive or store any information about your own health, diet, or body from this - the estimate describes the recipe, not you.
2.9 Households (shared recipe libraries)
Pipiro lets you share one recipe library with the people you cook with (a “household”). This is entirely optional - you are in a household only if you create an invitation or accept one, and a household holds at most five people.
- What becomes visible to the others. When you join a household, the recipes you already had - along with their versions, cook history, and photos - move into the shared library, together with your shopping lists and your weekly meal plan. Every member can read, edit, and delete them, and can see who cooked or changed what. Your collections stay private to you, even inside a shared household.
- Your profile within the household. The other members see your display name, username, and profile photo, so that recipes, edits, cooks, and ratings can be attributed to a person rather than to an anonymous account.
- Invitations. An invitation stores the name of the person who created it and a random invite code, so that whoever opens the link can see who invited them. Anyone holding a valid invitation link or code can join, so share it only with people you trust; a pending invitation can be revoked in the app.
- Matching an invitation after you install the app. If you open an invitation link before Pipiro is installed, our backend briefly stores an irreversible hash of your IP address together with your platform (iOS or Android) and the invitation concerned. This serves one purpose only: so that when you first open the app we can offer you the invitation you came for, instead of it being lost during installation. These records are deleted automatically within one hour, are not linked to your account, and are never used for advertising, profiling, or tracking you across apps or websites. We rely on our legitimate interest in making invitations work (Art. 6(1)(f)).
3. Device permissions
The app may ask for the following permissions. You can decline or revoke them in your device settings; some features will not work without them.
- Camera - to take photos of your recipes.
- Photo library - to attach existing photos to recipes.
- Motion / sensors - used locally to enable hands-free interactions while cooking. This sensor data stays on your device and is not collected by us.
4. How we use your data and the legal basis
| Purpose | Data used | Legal basis (GDPR) |
|---|---|---|
| Create and secure your account, sign you in | Email, auth identifiers, one-time codes | Performance of a contract (Art. 6(1)(b)) |
| Store and sync your recipes and content | Content you create | Performance of a contract (Art. 6(1)(b)) |
| Send sign-in / transactional emails | Performance of a contract (Art. 6(1)(b)) | |
| Import recipes from links you provide | URL, page content, AI extraction | Performance of a contract (Art. 6(1)(b)) |
| Estimate a recipe’s nutrition on request | Ingredient lines, recipe name and description, AI matching | Performance of a contract (Art. 6(1)(b)) |
| Provide paid features and verify your subscription | Subscription status, purchase identifiers | Performance of a contract (Art. 6(1)(b)) |
| Share a recipe library with your household | Content you create, display name and profile photo | Performance of a contract (Art. 6(1)(b)) |
| Deliver an invitation that survives app installation | Hashed IP address, platform | Legitimate interests (Art. 6(1)(f)) |
| Understand usage and improve the app | Aggregated usage statistics; account active-day for retention | Legitimate interests (Art. 6(1)(f)) |
| Measure whether our App Store ads bring engaged users (iOS) | Apple Search Ads attribution: yes/no and campaign identifiers | Legitimate interests (Art. 6(1)(f)) |
| Keep the service secure and prevent abuse | Technical data | Legitimate interests (Art. 6(1)(f)) |
| Comply with legal obligations | As required | Legal obligation (Art. 6(1)(c)) |
5. Service providers (sub-processors)
We use trusted third-party providers to run Pipiro. They process data only on our behalf and under appropriate data-protection terms:
- Google Firebase / Google Cloud - authentication, database, file storage,
serverless functions, and hosting of our own first-party usage statistics. Our
backend is hosted in the European Union (region
europe-west1, Belgium). - Anthropic - provides the AI models used to extract structured recipe data from the content you import and to estimate a recipe’s nutrition. Imported page content and, for nutrition estimates, recipe ingredient lines are sent to Anthropic for these purposes. Anthropic does not use this data to train its models under our business terms.
- RevenueCat - validates app-store purchases and manages subscription status. RevenueCat receives an app-specific user identifier and purchase information from Apple or Google; it does not receive your name, email address, or payment details.
- Postmark - sends transactional emails (such as your one-time sign-in codes).
- Google / Apple Sign-In - if you choose these sign-in methods, the respective provider processes your authentication.
Some providers may process data outside the European Economic Area. Where this happens, transfers are protected by appropriate safeguards such as the European Commission’s Standard Contractual Clauses.
6. How long we keep your data
- Account and content data - kept for as long as your account exists.
- Subscription data - kept for as long as your account exists; records of transactions may be retained longer where required for accounting or other legal obligations.
- One-time sign-in codes - deleted automatically within 10 minutes.
- Household invitations - an invitation stops working 7 days after it is created, or as soon as it is used or revoked. The record of it (who created it and when) stays with the household account until that account is deleted.
- Invitation-matching records (Section 2.9) - deleted within one hour.
- When you delete your account, we permanently delete your account, recipes, versions, cook history, and associated files (see Section 8).
- If you leave a household, the recipes you created leave with you; the shared shopping lists and weekly meal plan stay with the household, and your star ratings are removed from the cooks that stay behind.
- If you delete your account while in a household, the recipes you created are deleted for everyone in that household - including members who have been cooking from them - while the shared shopping lists and meal plan remain with the household.
7. How we protect your data
- Data is transmitted over encrypted connections (HTTPS/TLS).
- Access to backend data is restricted; the app’s database is deny-by-default and access is scoped to your own account and, if you have joined one, to the household you share it with.
- One-time codes are stored only as irreversible hashes.
No system is perfectly secure, but we take reasonable technical and organisational measures to protect your data.
8. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you;
- rectify inaccurate data;
- erase your data (“right to be forgotten”);
- restrict or object to certain processing;
- data portability - receive your data in a portable format;
- withdraw consent where processing is based on consent.
You can delete your account and all associated data directly in the app at any time. To exercise any other right, get in touch via our contact form.
You also have the right to lodge a complaint with your data protection authority. In Lithuania this is the State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija, https://vdai.lrv.lt).
9. Children
Pipiro is not directed to children under the age of 16. We do not knowingly collect personal data from children under 16. If you believe a child has provided us with personal data, please contact us and we will delete it.
10. Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last updated” date and, where appropriate, notify you in the app. Your continued use of Pipiro after changes take effect means you accept the updated policy.
11. Contact
Questions or requests regarding your privacy: get in touch via our contact form.