miniChef

Privacy Policy

Version 1.4 — effective 7 August 2026

This explains what personal data miniChef collects, why, and what you can do about it. The controller is Gotvach. For any privacy question or to exercise your rights: [email protected].

1. What we collect and why

DataWhyLegal basis (GDPR Art. 6)
Email address, password hashTo create and secure your accountContract, 6(1)(b)
Name, avatar (if you sign in with Google or Apple)To identify your accountContract, 6(1)(b)
Your recipes, edits, uploaded photosTo provide the ServiceContract, 6(1)(b)
Cooking preferences, skill levelTo tailor generated recipesContract, 6(1)(b)
Dietary requirements and allergiesTo exclude ingredients from recipesExplicit consent, 9(2)(a)
Shopping basket contents, last used locationTo price your basket at nearby shopsContract, 6(1)(b)
Credit balance, purchases, invoicesTo bill you and meet accounting lawContract 6(1)(b); legal obligation 6(1)(c)
Prompts you send and recipes generatedTo deliver the result and prevent abuseContract 6(1)(b); legitimate interests 6(1)(f)
Aggregate page views (Umami)To understand which features are usedLegitimate interests, 6(1)(f)
Error logs, IP addressSecurity, debugging, rate limitingLegitimate interests, 6(1)(f)

Health-related data

Allergies and dietary requirements can reveal information about your health, which GDPR treats as a special category (Art. 9). We ask for it only because excluding an allergen from a recipe is impossible without it, we process it only on your explicit consent, we use it for nothing else, and you can withdraw consent or delete it at any time from your profile — the app keeps working without it.

2. Analytics — no cookies, no tracking

We use Umami, self-hosted on our own infrastructure at analytics.gotvach.com. It is cookieless, collects no cross-site identifiers, does not fingerprint you, does not build a profile, and never leaves our servers. We do not use Google Analytics, ad networks or advertising pixels.

This is why miniChef shows no cookie banner: we set no cookies that require consent. The only browser storage we use is your login session and your preferences, which are strictly necessary to operate the Service.

3. Automated processing

Recipes are generated by large language models. This is automated processing, but it does not produce legal or similarly significant effects on you within the meaning of GDPR Art. 22 — it suggests meals. We do not use your data for automated decisions about pricing, credit or access.

4. Who else sees your data

We use these processors, each under a data processing agreement:

Transfers outside the EEA rely on the European Commission's Standard Contractual Clauses or an adequacy decision. We do not sell your personal data. Ever.

5. How long we keep it

DataRetention
Account and recipesUntil you delete your account
Deleted recipesPurged within 30 days
Closed accountsErased 60 days after closure, recoverable until then
Generation logs90 days, then aggregated
Invoices and payment records10 years (Bulgarian accounting law)
Error logs30 days
AnalyticsAggregate only, no personal data retained

When you delete your account it is closed immediately — every session ends and it cannot be signed into or used. Your data is then kept for 60 days and erased permanently after that.

That window exists for one reason: so that a deletion you did not mean, or changed your mind about, can be undone. Signing in again during those 60 days restores the account. After 60 days it is gone and we cannot recover it.

Invoices are the exception — we are legally required to keep those. They are retained in isolation and used for nothing else.

6. Your rights

Under GDPR you can:

Export and deletion are self-service, in the app: open your profile and use "Export my data" or "Delete my account".

For any other right above — correction, restriction, objection, withdrawing consent — or if self-service deletion reports that something could not be removed, email [email protected]. We respond within one month, as GDPR Art. 12(3) requires, and we will not charge you for it.

7. Security

Passwords are hashed, never stored in plain text. Traffic is encrypted in transit. Access to production data is limited to those who need it. If a breach ever puts your rights at risk we will notify the supervisory authority within 72 hours and tell you without undue delay.

8. Children

miniChef is not intended for children under 16. We do not knowingly collect their data; if you believe we have, contact [email protected] and we will delete it.

9. Changes

Material changes will be announced in the app or by email at least 14 days ahead. Every version stays available from this page.

10. Contact

Gotvach — [email protected]