Privacy Policy
Last updated · June 21, 2026
SnapChef ("we", "us") collects only what's needed to run the app and sync your account across devices. We don't sell your data and we don't show ads — and you can permanently delete everything from inside the app at any time.
1. Information we collect
Account information
When you sign in with Apple or Google (via Firebase Authentication) we collect your email address, your display name (if provided), and a user ID plus authentication tokens for session security. If you use Sign in with Apple, we receive only what you choose to share (which may be a private relay email).
Photos and camera
SnapChef uses your camera and photo library so you can photograph ingredients. When you scan, the image is compressed on your device, location/EXIF metadata is stripped, and the image is sent to Google's Gemini API for ingredient detection. The photo is discarded after processing — we do not keep it on our servers.
Content you create (synced to your account)
So your data is available across your devices, the following is stored in Google Firestore tied to your account:
- Saved recipes and favorites
- Fridge and pantry inventory
- Cooking history and meal plans
- Dietary preferences, allergies, and onboarding answers
- Scan history, ratings, shopping lists, and streak/engagement counters
Purchases
Subscriptions are processed by the Apple App Store or Google Play — we never see your payment card details. RevenueCat manages your subscription status using a per-user identifier, purchase receipts, and device identifiers; it does not receive your name or email.
Analytics and diagnostics
We use PostHog (hosted in the EU) to understand how the app is used and to catch crashes. This includes product-interaction events (e.g. app opened, paywall viewed, purchase or trial events, recipe imports) and diagnostic/error reports, associated with your user ID and email so we can support your account. We do not use this data for advertising.
2. How we use your information
- Account data — to authenticate you and sync your content and subscription
- Photos — to identify ingredients via AI (processed in real time, then discarded)
- Ingredients & preferences — to generate personalized recipes via AI
- Purchase data — to unlock and manage premium features
- Analytics & diagnostics — to improve the product and fix problems
We do not use your data for advertising or profiling, and we never sell it.
3. Third-party services
- Google Gemini API — ingredient detection & recipe generation. When used via the API, Google states prompts and responses are not used to train its models. (Terms, Privacy)
- Google Firebase — Authentication, Firestore database, and Storage. (Privacy)
- RevenueCat — subscription management. (Privacy)
- PostHog — product analytics & error tracking, EU-hosted. (Privacy)
4. Data sharing
We will never sell, rent, or share your personal data with third parties for marketing or advertising. Data is shared only with the processors above, solely to provide the app. Your fridge photos are sent to Google for AI processing as described in Section 1.
5. Data retention
- Photos sent to Gemini — processed in real time, not stored by us
- Account & synced content — kept while your account exists; removed when you delete your account
- Purchase data — kept for the subscription duration plus any legally required period
- Analytics events — retained by PostHog per our configured retention period
6. Your rights & choices
You can delete your account and all associated data directly in the app (Settings → Delete account), which removes your Firestore content and authentication record. If you are in the EU/EEA (GDPR) or California (CCPA), you also have rights to access, correct, port, and object to or restrict processing of your data.
Legal basis (GDPR): contractual necessity (providing the service), consent (camera use, account creation), and legitimate interest (analytics, security, fraud prevention). To exercise any right, email hello@hibernyte.com — we respond within 30 days.
7. Children's privacy
SnapChef is not directed at children under 13, and we do not knowingly collect their data. If you believe a child has provided us data, contact hello@hibernyte.com.
8. Data security
All network requests use encrypted connections (HTTPS/TLS) and data is encrypted in transit. Authentication tokens are stored securely on your device. No method of transmission is 100% secure, but we apply reasonable safeguards.
9. International data transfers
Your data may be processed outside your country — Google/Firebase primarily in the United States, and PostHog in the European Union. These transfers rely on the providers' data-processing agreements and applicable safeguards.
10. Changes to this policy
We may update this policy; changes are posted here with a new date, and material changes will be surfaced in the app.
11. Contact
Questions or data requests: hello@hibernyte.com