BestChef Privacy Policy
Effective date: 6 September 2026
This policy explains what data BestChef ("we", "us", operated by Trey Shuldberg, an individual developer based in the United States) processes, why, and what rights you have. The short version: your private kitchen stays on your device, the social layer lives on our servers, we run no ads and no third-party analytics, and you can delete everything from inside the app.
1. Data that stays on your device
The private kitchen (saved recipes, grocery lists, pantry inventory, receipt and expiration scans you confirm, drafts, and app settings) is stored in a local database on your device. It is not uploaded unless a feature explicitly says so (for example, submitting a recipe to a public competition).
2. Data we process on our servers
When you use BestChef's social features we process:
- Account data. An anonymous account identifier created at first launch; your chef handle and display name; an email address only if you choose to link one; your accepted terms version; and your confirmed age-gate answer (the threshold shown and your yes/no, not a birth date).
- Content you publish. Recipe submissions, photos and videos, comments, votes, vote-proof photos, follows, likes, and reports you file.
- Integrity and safety data. Content fingerprints (hashes) of vote-proof photos used to prevent duplicate-proof fraud (kept even after a vote is deleted, tied to your profile until account deletion); durable rate-limit ledgers (which action happened when, retained up to 35 days); moderation queues and decisions about your content; and block relationships you create.
- Media metadata. Upload status, moderation status, and storage location of media you upload. Vote-proof photos are private by default and only become publicly visible when a proof is approved.
3. What we do NOT collect
No advertising identifiers, no third-party analytics SDKs, no location tracking, no contact-list access, no cross-app tracking, no sale of personal data. Server logs necessary to run and secure the service are kept short-term.
4. Why we process it (legal bases)
- Operating the service you asked for (contract): account, content, media hosting, leaderboards.
- Keeping the competition and community safe (legitimate interest, and legal obligation where applicable): proof-hash dedup, rate limits, moderation, blocks, age gating.
- Compliance with law (legal obligation): responding to valid legal requests, child-safety reporting where required.
5. Who else sees your data (processors)
We host data with Supabase (database, storage, edge functions). Media and content-safety classification providers process uploads to screen for prohibited content. These providers act under contract as processors; we do not let them use your data for their own purposes. A current list is available from support@bestchef.app.
6. International transfers
Our servers are hosted in the United States (Oregon, via Supabase on AWS us-west-2; the website runs on Fly.io in San Jose). Where data crosses borders from the EU/UK, we rely on the providers' EU-approved safeguards (standard contractual clauses).
7. Retention
- Content and account data: until you delete it or your account.
- Vote-proof hash ledger: until account deletion (it exists to stop proof reuse; deleting a single vote does not clear its hash).
- Rate-limit ledgers: pruned after 35 days.
- Moderation decisions: retained while your account exists, so appeals and repeat-violation handling work.
- Backups: deleted content can persist in encrypted backups briefly before aging out.
8. Your rights
Depending on where you live (GDPR, UK GDPR, CCPA, and similar), you can access, correct, export, restrict, object to processing of, or delete your data, and you will not be discriminated against for exercising these rights. Most of them are built into the app:
- Delete: Settings → Delete account (see the Data Deletion policy).
- Export (portability): Settings → Full account export produces a machine-readable JSON copy of your server-side account data (profile, submissions, votes, comments, follows, reports you filed, media metadata, creator status, appeals, and notifications). Each list is capped at 5,000 most-recent rows; a capped list reports its full count, and you can email support@bestchef.app for a complete copy of any truncated list. Settings → Export device data gives you the copy of the data stored locally on your device.
- Correct: edit your profile and content in-app.
- Anything else: email support@bestchef.app. We respond within 30 days. You may also complain to your local data-protection authority.
9. Children
BestChef enforces per-country minimum ages at onboarding (16 in Germany, Ireland, the Netherlands, Hungary, Lithuania, Luxembourg, Slovakia, Croatia, Poland, Romania; 15 in France, Czechia, Greece; 14 in Italy, Spain, Austria, Bulgaria, Cyprus; 13 elsewhere). We do not knowingly process data of children below these thresholds; if we learn we have, we delete it.
10. Changes
We will announce material changes in-app at least 14 days before they take effect, with the effective date above always current.
11. Contact
Questions, privacy requests and legal notices: trey@receeps.com. Support inside the app: Settings, Support. Postal address available on request by email. (Operator: Trey Shuldberg, individual developer, United States.) support@bestchef.app