Version 1.4 — effective 7 August 2026
This explains what personal data miniChef collects, why, and what you can do about it. The controller is Gotvach. For any privacy question or to exercise your rights: [email protected].
| Data | Why | Legal basis (GDPR Art. 6) |
|---|---|---|
| Email address, password hash | To create and secure your account | Contract, 6(1)(b) |
| Name, avatar (if you sign in with Google or Apple) | To identify your account | Contract, 6(1)(b) |
| Your recipes, edits, uploaded photos | To provide the Service | Contract, 6(1)(b) |
| Cooking preferences, skill level | To tailor generated recipes | Contract, 6(1)(b) |
| Dietary requirements and allergies | To exclude ingredients from recipes | Explicit consent, 9(2)(a) |
| Shopping basket contents, last used location | To price your basket at nearby shops | Contract, 6(1)(b) |
| Credit balance, purchases, invoices | To bill you and meet accounting law | Contract 6(1)(b); legal obligation 6(1)(c) |
| Prompts you send and recipes generated | To deliver the result and prevent abuse | Contract 6(1)(b); legitimate interests 6(1)(f) |
| Aggregate page views (Umami) | To understand which features are used | Legitimate interests, 6(1)(f) |
| Error logs, IP address | Security, debugging, rate limiting | Legitimate interests, 6(1)(f) |
Allergies and dietary requirements can reveal information about your health, which GDPR treats as a special category (Art. 9). We ask for it only because excluding an allergen from a recipe is impossible without it, we process it only on your explicit consent, we use it for nothing else, and you can withdraw consent or delete it at any time from your profile — the app keeps working without it.
We use Umami, self-hosted on our own infrastructure at analytics.gotvach.com. It is cookieless, collects no cross-site identifiers, does not fingerprint you, does not build a profile, and never leaves our servers. We do not use Google Analytics, ad networks or advertising pixels.
This is why miniChef shows no cookie banner: we set no cookies that require consent. The only browser storage we use is your login session and your preferences, which are strictly necessary to operate the Service.
Recipes are generated by large language models. This is automated processing, but it does not produce legal or similarly significant effects on you within the meaning of GDPR Art. 22 — it suggests meals. We do not use your data for automated decisions about pricing, credit or access.
We use these processors, each under a data processing agreement:
Transfers outside the EEA rely on the European Commission's Standard Contractual Clauses or an adequacy decision. We do not sell your personal data. Ever.
| Data | Retention |
|---|---|
| Account and recipes | Until you delete your account |
| Deleted recipes | Purged within 30 days |
| Closed accounts | Erased 60 days after closure, recoverable until then |
| Generation logs | 90 days, then aggregated |
| Invoices and payment records | 10 years (Bulgarian accounting law) |
| Error logs | 30 days |
| Analytics | Aggregate only, no personal data retained |
When you delete your account it is closed immediately — every session ends and it cannot be signed into or used. Your data is then kept for 60 days and erased permanently after that.
That window exists for one reason: so that a deletion you did not mean, or changed your mind about, can be undone. Signing in again during those 60 days restores the account. After 60 days it is gone and we cannot recover it.
Invoices are the exception — we are legally required to keep those. They are retained in isolation and used for nothing else.
Under GDPR you can:
Export and deletion are self-service, in the app: open your profile and use "Export my data" or "Delete my account".
For any other right above — correction, restriction, objection, withdrawing consent — or if self-service deletion reports that something could not be removed, email [email protected]. We respond within one month, as GDPR Art. 12(3) requires, and we will not charge you for it.
Passwords are hashed, never stored in plain text. Traffic is encrypted in transit. Access to production data is limited to those who need it. If a breach ever puts your rights at risk we will notify the supervisory authority within 72 hours and tell you without undue delay.
miniChef is not intended for children under 16. We do not knowingly collect their data; if you believe we have, contact [email protected] and we will delete it.
Material changes will be announced in the app or by email at least 14 days ahead. Every version stays available from this page.
Gotvach — [email protected]