Your data
Privacy policy
Andrea keeps as little about you as it can while still learning your taste. This page says exactly what that is, where it goes, and how to take it back.
Last updated 2026-08-26
The short version
Who is responsible for your data
Andrea is published by an individual based in Sweden, who is the data controller: Alexander Anders Linden, Furusundsgatan 3, 115 37 Stockholm, Sweden. The same details are on the legal and contact page. For any privacy question you can write to support.andrea@gmail.com, and you will get an answer within 5 business days.
One other developer works on Andrea and can access the live database in order to keep the service running and to investigate faults. Nobody else can, and neither of us reads your journal for any other purpose.
Before you have an account
Onboarding runs before you sign in, and it shows photographs of dishes. To find those photographs the app sends the name of a dish to our own image service, which passes it to Pexels. That request carries no account, no identifier and nothing you have typed, but like any web request it reaches our server with your IP address attached, and our provider logs it briefly. This is the only thing that leaves your phone before you sign in.
What we collect, and why
Everything below is collected because a specific feature needs it. There is no category collected speculatively or kept in case it becomes useful later.
| What | Why | Collected when |
|---|---|---|
| Your sign in identifier | To identify your account and let you sign back in on another device. Andrea uses Sign in with Apple, so what we receive is whatever Apple returns, which is usually a private relay address rather than your real one. We never see your Apple password. | When you create your account |
| Chef name | To address you in the app. | You type it during onboarding |
| Cooking records: which recipe, its title, when you cooked it, whether you skipped a step or used a timer, and any change you made mid cook | To build your journal and to work out your taste. This is the core of the product. | Each time you finish a cook |
| Ratings, written notes, review answers, and the full recipe you cooked | A generated recipe exists for one session, so the recipe is stored with your note. Without it your journal would be a list of titles and the taste profile could not be recalculated. | When you review or save a cook |
| Your shopping list and meal plan | So that they are still there when you get to the shop. | When you add to either |
| A daily count of recipes generated | To enforce the fair use limit on AI generation. It is a count, not a log of what you asked for. | Each generation |
| The ingredients and preferences you type when generating a recipe | Sent to Anthropic to produce the recipe. We do not store them in the database, but they can appear briefly in our server logs. See how long it is kept. | Each generation |
| A photograph of a receipt or a shelf, if you use the scan | Sent to Anthropic to read the ingredient names out of it. The photograph is not stored by us and is gone once the reply comes back. Only the ingredient names reach the app, and you confirm every one of them. Scanning is optional, and typing stays the primary way in. | Only if you take a scan |
| The name of a dish, to find a photograph of it | Sent to Pexels to search, then shown to a model to pick which of the results is actually the dish. The answer is cached under the dish name, so it is shared by everyone who cooks the same thing and is attached to nobody. | Whenever a recipe needs a picture |
| Your subscription status | To know whether your subscription is active. Apple takes the payment and RevenueCat records the result against an identifier for your account. | If you subscribe |
What stays on your phone
These are not sent to us, not synced between your devices, and not visible to anyone but you. Which also means they are not in your export, and not recoverable if you lose the phone.
- Photographs of your own dishes. They are saved on your device, and to your photo library if you ask for that, and they never leave it.
- Your allergies and dietary rules. An allergy is health information, and the safest way to handle health information is not to hold it. Andrea enforces your rules in code on the device, so they never reach our servers and we process no special category data under Article 9 of the GDPR at all.
- Anything you have started but not saved.
What we deliberately do not collect
- No location data of any kind.
- No contacts, calendars, or address book access.
- No advertising identifiers, and no tracking across other apps or websites. Andrea shows no advertising and never asks for permission to track, because it does not.
- No analytics or behavioural profiling SDKs are embedded in the app or on this website.
- No push notification tokens. Andrea schedules its reminders on the device itself, so there is no token, no push server, and no device identifier held by us.
- No card or payment details. Apple takes the payment and never gives us the card.
Why we are allowed to do this
Under the GDPR every use of your data needs a lawful basis. These are ours.
| What we do | Lawful basis |
|---|---|
| Running your account, generating recipes, keeping your journal in sync, and providing the subscription you bought | Performance of a contract, Article 6(1)(b). Without this there is no service to give you. |
| Enforcing the daily generation limit, defending against abuse, and keeping short server logs | Legitimate interests, Article 6(1)(f), in keeping a small service running and affordable. You can object to this at any time. |
| Using the camera to read a receipt or a shelf | Consent, Article 6(1)(a), given at the iOS permission prompt. You can withdraw it in the iOS Settings app and the app keeps working without it. |
| Keeping the records a sale requires | Legal obligation, Article 6(1)(c). |
Third parties we share data with
These are processors acting on our instructions, under a data processing agreement signed with each of them. None are permitted to use your data for their own purposes, and none are advertising networks.
| Provider | What it receives | Purpose | Where |
|---|---|---|---|
| Supabase | Your account and everything in the table above | Database, authentication and sync hosting | European Union, eu-west-1 in Ireland |
| Anthropic | The ingredients, preferences and taste summary used for one generation, and the photograph if you use the scan | Generating the recipe and reading the scan. Requests are not used to train their models. | United States |
| Pexels | A keyword such as the dish name. No personal data. | Finding a photograph of the dish | United States |
| Apple | Whatever you authorise at the Sign in with Apple prompt, and the payment | Sign in, and taking the payment for a subscription | Per Apple’s own policy |
| RevenueCat | An identifier for your account and the state of your subscription. No card details, because we never have any. | Knowing whether your subscription is active | United States |
We do not sell your data, and we do not share it for anyone else’s marketing.
When your data leaves the EU
Your account and your journal are stored in Ireland and stay there. But recipe generation, the scan and dish photographs are handled by providers in the United States, so the data listed against them in the table above is transferred there each time you use those features.
Those transfers are covered by the European Commission’s Standard Contractual Clauses, which form part of the data processing agreement we have signed with each provider. Ask us at support.andrea@gmail.com if you want a copy of the relevant clauses.
How long it is kept
| What | How long |
|---|---|
| Your account and everything in it | Until you delete it. The taste profile is calculated from your whole history and gets better the longer it runs, so nothing is aged out behind your back. |
| Server logs, which can contain the ingredients you typed and your IP address | One day. That is our hosting plan’s retention, and we do not extend it. |
| The photograph from a scan | Not stored. It is passed through to be read and is gone once the reply comes back. |
| The cached answer to which photograph shows a given dish | Indefinitely, because it is keyed on the name of a dish and contains nothing about you. |
| Database backups | We hold no restorable backups. That is a real cost to you if something breaks, and the honest upside is that when your data is deleted there is no copy of it sitting in a backup for weeks afterwards. |
Deleting your account
Deletion is available inside the app and does not require contacting us. There is a 30 day grace period: sign back in during that window and nothing is lost. After it passes, your account and everything in it are removed permanently and cannot be recovered, and because we keep no restorable backups, removed means removed.
Step by step instructions are on the delete your account page.
Your rights, and how to exercise them
If you are in the EU, the UK, or another region with comparable law, you have the right to access your data, correct it, export it, delete it, restrict or object to processing, and complain to your data protection authority.
Getting a copy
Open Settings, then Your data, then Privacy, and choose Export my data. You get a JSON file immediately, with no request to approve, containing your profile, your cooking records, your notes and ratings, your saved recipes, your shopping list and your meal plan. It does not contain the things listed under what stays on your phone, because we do not have them. If you think something we hold is missing from it, tell us at support.andrea@gmail.com and we will send it to you within one month.
Correcting something
Your chef name, your notes and your ratings are all editable in the app. For anything else, write to support.andrea@gmail.com.
Objecting, or asking us to stop
You can stop the processing described here by deleting your account, which removes it entirely. Camera access can be revoked at any time in the iOS Settings app, and the app continues to work without it.
Complaining
If you think we have handled your data badly, please tell us first at support.andrea@gmail.com. You also have the right to complain directly to your national data protection authority. Ours is Integritetsskyddsmyndigheten (IMY) in Sweden.
How your data is protected
- Everything between the app and our servers travels over TLS. There is no unencrypted path.
- Your session token is held in the iOS Keychain, not in ordinary app storage.
- The database enforces row level security, so a signed in account can read its own rows and nobody else’s.
- Access to the live database is limited to the controller and one other developer, each with their own credentials.
- We hold no card details, so there is nothing of that kind to lose.
If something goes wrong
If personal data is exposed by a breach, we will report it to Integritetsskyddsmyndigheten (IMY) within 72 hours of becoming aware of it, as Article 33 requires. Where the breach is likely to put you at high risk, we will tell you directly and say plainly what happened, what was exposed, and what to do about it.
Children
Andrea is for people aged 13 and over. It is not directed at younger children and we do not knowingly collect data from them. If you believe a child has created an account, write to support.andrea@gmail.com and we will remove it.
If you are in California
The categories we collect are identifiers, commercial information limited to whether you have an active subscription, and the content you create in the app. The purposes and the sources are described above.
We have not sold or shared personal information in the preceding twelve months, and we do not engage in cross context behavioural advertising, so there is nothing for a “Do Not Sell or Share” link to switch off. We do not use or disclose sensitive personal information beyond what is needed to provide the app.
You have the right to know, to delete, and to correct, and not to be discriminated against for exercising any of them. Deleting your account exercises the right to delete in full, and the export gives you the right to know. Write to support.andrea@gmail.com if you would rather ask us directly.
Cookies on this website
This website sets no cookies. It runs no analytics, no tracking pixels, and no third party scripts, which is why you were not asked to accept anything when you arrived. Our hosting provider processes standard server request logs, including IP address, to deliver the site and defend against abuse.
Changes to this policy
If the substance of this policy changes we will update the date at the top and, where the change is significant, tell you inside the app before it takes effect.

