Privacy Policy
Last updated: July 19, 2026
Saffra ("the app", "we", "us") is an AI cooking companion built by Daniel Muskin. This policy explains what data we collect, how we use it, and the choices you have. It's written in plain English — no dark patterns.
The short version
- We collect only what the app needs to work: your identity (via Sign in with Apple), your cooking profile (equipment, allergies, preferences), your pantry, your conversation history with the chef, and recipes you import.
- We use this data solely to operate the app — personalize the chef, remember your pantry, adapt recipes for you. We do not sell it, we do not use it to train models, we do not share it with advertisers.
- Voice transcription runs on your device by default.
- You can delete your account and all associated data at any time.
What we collect
Early-access waitlist (this website)
- Email address — only the email you type into the signup form on this site, plus a timestamp and the source label
saffra-website. We use it for one thing: to send you a single message when TestFlight opens. We never sell it, we never share it with advertisers, and we never send marketing email beyond the launch notification. You can ask for removal at any time by emailing hello@saffra.app.
Account (in the app, post-launch)
- Apple or Google user ID (opaque identifier from Sign in with Apple or Sign in with Google) — to log you in.
- Email address — only if Apple or Google passes it to us, and only to contact you about your account. We never send marketing email.
Profile
- Kitchen equipment, dietary restrictions, allergies, likes, dislikes, skill level, cuisine preferences, household size, budget, time constraints, cooking style notes, preferred voice, unit system — collected during onboarding so the chef can tailor its suggestions. You can edit or clear any of these in Profile / Me.
Pantry
- Items you add manually, via barcode scan, or via receipt scan — including names, quantities, expirations, brand, and allergens.
- Receipt and cookbook photos: OCR runs on your iPhone via Apple's Vision framework. The image never leaves your device. Only the extracted text is sent to us for parsing.
Conversations
- Messages you send to the chef and the chef's replies, so the chef has memory across sessions. Older conversations are periodically summarized and the raw messages are deleted.
Recipes
- Recipes you import via URL or cookbook photo, and adapted versions created for you.
Community content (opt-in)
- Public handle & display name — only if you opt into the Community and pick a handle.
- Cook posts you explicitly share to the community, including the photo you uploaded, the caption you wrote, and which recipe the photo is for. Anyone using the app can see posts whose moderation state is
live; your private cook photos (the default) stay on your device and are never uploaded. - Likes, comments, follows, blocks, reports you create on community content.
- Moderation metadata — for every community post we keep a short record of our automated vision classifier's "food / not food" and "safe / unsafe" decisions, plus the removal reason if a post is taken down. This is used to enforce the rules, not to build a profile of you.
- Notifications — an in-app inbox of likes, comments, and follows you have received. Not sent to you via push in the current version.
Voice
- When you use voice mode, transcription runs on-device via Apple Speech.framework — audio is not sent to us.
- As a fallback (only when on-device accuracy is too low for a noisy kitchen), audio may be sent briefly to our server and forwarded to OpenAI's Whisper for transcription. We do not retain the audio; it is processed and discarded.
- Text-to-speech uses ElevenLabs. Audio is generated on our server and streamed to your device. Audio for publicly available curated recipes is cached (content-addressed) so we don't re-generate the same clip for every user.
Usage
- Per-user counters of chat messages, voice characters, and Whisper seconds, used to enforce daily limits and for aggregate cost monitoring. Not shared externally.
We do NOT collect
- Location, contacts, calendar, browsing history, financial data, health data outside your self-declared dietary/allergy profile.
- Any analytics that track you across apps or websites.
How we use it
- Operate the app — personalize recommendations, remember your pantry, stream chef responses.
- Safety — enforce rate limits and guard against abuse.
- Community safety — run an automated vision check ("is this food?" / "is this safe?") on every community photo before it's visible to others, and review user reports so we can remove rule-breaking content quickly.
- Product improvement — only via aggregate metrics (e.g., "how often does the chef call
lookup_recipe?"), never with identifiable data.
Third-party services
We share data with these service providers only to the extent needed to run the app:
- Apple — Sign in with Apple.
- Google — Sign in with Google, only if you use it. Governed by Google's privacy policy.
- Anthropic (Claude) — your chat messages and a summary of your profile and pantry are sent to Anthropic to generate and adapt the chef's replies. Governed by Anthropic's privacy policy. Neither we nor Anthropic use your content to train models.
- Voyage AI — your search queries and recipe text are sent to Voyage for embedding. Governed by Voyage's privacy policy.
- ElevenLabs — text you want spoken is sent to ElevenLabs. Governed by their privacy policy.
- OpenAI (Whisper, fallback only) — audio sent only when you explicitly use the noisy-kitchen voice fallback. Governed by OpenAI's privacy policy.
- USDA FoodData Central — ingredient names are sent to look up nutrition information. No personal data.
- Open Food Facts — barcode lookups send just the barcode number. No personal data.
- Google Firebase — for the early-access waitlist on this website only. Stores your email address until launch notification is sent.
- Fly.io, Cloudflare R2, Upstash Redis — hosting infrastructure.
None of these providers are authorized to use your data for their own purposes.
How long we keep it
- Account + profile + pantry — until you delete your account.
- Conversations — individual messages may be auto-summarized and deleted after ~20 turns; summaries persist until you delete the conversation.
- TTS audio cache — until you delete your account.
- Voice audio for Whisper fallback — not stored; discarded after transcription.
- Community posts, photos, comments, likes, follows, blocks, notifications — until you delete them individually or delete your account. When you delete your account we hard-delete the photos from object storage and remove the associated rows. Reports you've filed are retained in an anonymized form so we can keep acting on repeat abuse.
- Waitlist email — until launch notification is sent or you ask for removal, whichever is sooner.
Your choices
- Edit or delete any profile field in Profile / Me.
- Delete a pantry item, recipe, or conversation any time.
- Sign out via Profile / Me.
- Delete your account → from Profile / Me, or by emailing privacy@saffra.app. In-app deletion runs the cascade immediately (photos, posts, comments, likes, follows, blocks, notifications); email requests are processed within 30 days.
- Block another community member any time from their public profile.
- Report a post or comment — every report is reviewed, and we always respond to abusive content within 24 hours.
- Turn off premium voice in Settings to use on-device iOS voices only — no ElevenLabs request leaves your device.
Kids
The app is not directed at children under 13. We don't knowingly collect data from children.
International transfers
Our servers are in the United States. If you're in another country, your data is transferred to the US for processing. We rely on standard contractual clauses where required.
Changes
If we update this policy, we'll note the new date above and flag material changes in-app.
Contact
- Email: privacy@saffra.app
- For early-access list questions: hello@saffra.app