Ingredient photos are sent only for recognition and are not written to Coook's primary database. The confirmed pantry list is stored temporarily while queued or generating, cleared after success, and retained for no more than 24 hours after failure for retry.
Effective 2026-08-25
Privacy policy 
What Coook collects, why it is used, how long it stays, and how you control it.
hello@spac0.comGenerated recipes and cooking progress are retained for 30 days by default.
We do not sell personal data or run behavioral ads. Umami records pages and key conversion events only; pantry contents, recipes, email, user ID, and payment-card data are not sent, and analytics can be turned off at any time.
You can cancel renewal and permanently delete account data from the primary database on the account page; backup copies expire through the normal retention cycle.
Who is responsible
Coook is operated by SpaceZero. SpaceZero is the controller for data whose purpose and means are determined by Coook. Contact us through in-product feedback, the email shown on these legal pages, or https://www.spac0.com.
Data we process
- Account data: email, name, avatar, verification status, and identifiers or tokens required for Google sign-in.
- Subscription data: Waffo customer and subscription identifiers, transaction status, currency, and period end. Waffo handles hosted checkout and payment processing; Coook does not receive or retain full card details.
- Recognition data: ingredient text and food photos are used to extract names, quantities, units, and estimated calories. Photos are sent with the individual request to the vision-model provider but are not written to Coook's primary database. You should correct recognition results before generation.
- Generation data: the pantry list you confirm, region, dish count, and dietary requirements are sent to the text-model provider. The request is stored temporarily while queued and running; the original request is cleared after success, while the saved recipe contains the ingredients actually used.
- Usage data: generation count and date, saved recipes, cooking steps, timer state, and completion progress.
- Communication and technical data: feedback, reply email, and hosting logs such as IP, time, browser, and requests used for security and troubleshooting.
- Analytics data: Umami records pages, referrers, browser, operating system, device type, screen size, approximate country or region, and button events such as starting a trial or checkout. Query parameters, pantry contents, and recipe content are excluded. After payment, Coook may send a revenue event containing plan, currency, and amount only, without email, user ID, order ID, or card data. Umami may transiently process IP and browser information to create an anonymous visitor identifier, but Coook does not retain full IP addresses in analytics records.
Purposes and legal bases
- Contract: provide sign-in, ingredient recognition, pantry accounting, recipe generation, subscriptions, saved recipes, and resumable cooking.
- Legitimate interests: prevent abuse, secure the service, troubleshoot, and improve reliability while balancing user rights.
- Choice and opt-out: remember language preferences and use ad-free Umami to understand aggregate visits and product usage. You can turn analytics off at any time in Cookie settings.
- Legal obligations: handle tax, payment disputes, lawful requests, and consumer rights.
Providers and international transfers
To operate Coook, we use or may use Vercel and Prisma Postgres hosting, Resend or SMTP email, Google OAuth, Waffo hosted checkout, SiliconFlow vision models, a CCTQ-compatible text-model gateway, USDA FoodData Central, Wikimedia, Openverse, and media from YouTube, Bilibili, or Vimeo. Providers may change for reliability or regional availability, but we send only data needed for the relevant function.
Providers may operate outside your country. Where required, we use contractual safeguards, adequacy decisions, or another lawful transfer mechanism. Embedded video providers may receive device and network information when you load their content.
Retention rules
- Sign-in links expire after 15 minutes; expired verification records are removed during routine cleanup.
- The confirmed pantry list is stored as a temporary request only while a task is queued or generating and is cleared immediately after success. Failed-task input is retained for no more than 24 hours to support retry after the cooldown. Generated recipes, task status, and cooking progress remain in the primary database for 30 days by default, then are deleted automatically.
- Generation and recognition quota records are retained for 90 days for limits, abuse prevention, and dispute review.
- Identity and subscription state remain until account deletion. Payment, tax, or dispute records may be retained longer where legally required.
- Security logs and backups are generally retained no longer than 30 days, except for incidents, legal holds, or technical recovery.
- Umami analytics records follow the analytics workspace configuration and are intended to be retained for no more than 12 months. Aggregated statistics that cannot be linked to an individual may be kept longer.
Your rights
- Request access, correction, export, or deletion of personal data.
- Where applicable, restrict processing, object to legitimate-interest processing, or withdraw consent.
- Delete your account directly from the account page; cancel any active paid subscription first.
- Complain to your local data protection authority. We generally respond within 30 days of a verifiable request.
Security, children, and changes
We use transport encryption, access controls, data minimization, and server-side authorization, but no internet service is perfectly secure. Coook is not directed to children below the digital-consent age in their location. Contact us to remove child data. Material policy changes will be announced prominently with a revised effective date.