Legal
Privacy Policy
Last updated: September 27, 2026
Suppa ("we," "us," or "our") operates the Suppa mobile application and related services (collectively, the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the Service.
By using the Service, you agree to the collection and use of information in accordance with this policy.
1. Information We Collect
1.1 Information You Provide
- Account Information. When you create an account, we collect your email address. Password credentials are handled by our authentication provider using one-way password hashing. If you sign in with Apple, we receive your name and email from Apple when you authorize it.
- Profile Information. Your display name, if you choose to provide one.
- Dietary Preferences. Allergies, dietary restrictions, disliked ingredients, excluded ingredients, favorite cuisines, skill level, spice tolerance, default servings, and maximum cook time.
- Recipes and Meal Plans. Recipes you create, import, save, or add to your meal plan, including ingredients, steps, equipment, and images. A photo you select for recipe import or upload is transmitted to our service and, when the operation succeeds, stored as part of the recipe until you remove it or delete your account. Photo-import images are also sent to Google Gemini to extract recipe details.
- Grocery Lists. Items derived from your meal plan and any custom items you add, including check-off state.
- Connected Kroger Shopping. If you connect a Kroger account, we store encrypted Kroger access and refresh tokens, the access scopes you granted, and the Kroger-family store you select. We also store grocery brand, size, or attribute preferences you ask Suppa to remember, plus records of proposed Kroger baskets: product names, UPCs, quantities, sizes, prices, image links, and whether the cart update succeeded.
- Cooking Sessions. Session progress, step completion, timer usage, and ingredient substitutions.
- Feedback and Ratings. Recipe ratings, tags, and free-text comments you submit.
- Memory and Preferences. Notes and preferences you ask the AI assistant to remember on your behalf, stored as user-controlled text.
- Assistant Conversations. Messages you exchange with the AI planning assistant, including tool-use interactions.
- Shared Plans. When you create or join a shared household plan, we store plan membership, shared meal plan items, and shared grocery lists.
1.2 Information Collected Automatically
- Device, Usage, and AI Trace Data. Device type (phone or tablet), operating system version, app version, product analytics events (PostHog), LLM analytics traces (PostHog), and crash/error diagnostics (Sentry). Product analytics events measure feature usage, activation, conversion, and reliability. LLM analytics traces help us debug and improve AI features and may include the prompts, assistant conversation context, tool-use interactions, model responses, token counts, latency, costs, and error details sent or returned during AI requests. Suppa 1.0 disables PostHog mobile session replay.
- Website Analytics. When you visit suppa.cooking, Vercel Web Analytics records page views: the page address, referring site, country, and browser, operating system, and device type. It does not use cookies or identify you across websites.
- Network Information. We detect online/offline status locally on your device to enable offline queueing. Analytics events instruct PostHog not to retain or enrich them with IP-derived location. Our hosting and database providers (Vercel and Supabase) may still process and log IP addresses in standard server access logs for security and operations.
- Approximate Location (Weather Context). When you interact with the AI assistant, we derive your approximate location from your IP address (provided by our hosting provider) to fetch local weather and seasonal context for meal suggestions (for example, "it's a cold and rainy day — lean toward warming meals"). The latitude and longitude we store are rounded to one decimal place (roughly 11 km of resolution — neighborhood- or city-level, not address-level) and cached once per day per user. We do not access your device's GPS or precise location.
- Authentication Tokens. We issue JWTs and refresh tokens to maintain your session. These are stored on your device and rotated automatically.
1.3 Information We Do NOT Collect
- We do not collect precise geolocation data (we do not access your device's GPS). See Section 1.2 for the approximate, IP-derived location we use to fetch weather context.
- We do not access your contacts or precise calendar data. We access your camera, photo library, or reminders only when you choose an import/export action that needs that permission.
- We do not use advertising identifiers or run targeted ads.
- We do not sell your personal information.
2. How We Use Your Information
We use the information we collect to:
- Provide the Service. Generate meal plans, recipes, grocery lists, and cooking guidance tailored to your preferences.
- Power AI Features. Your dietary preferences, memory notes, past feedback, and conversation history are sent to third-party AI providers to generate personalized recommendations, parse recipes, provide cooking assistance, help with connected grocery shopping, and generate supporting recipe assets. The AI planning assistant runs on models from DeepSeek, OpenAI, or Anthropic, depending on our current configuration, the onboarding chat runs on Anthropic Claude, and daily recipe-search suggestions run on Google Gemini. Other features use Google Gemini, OpenAI, and, where applicable, TypeSafe Jev and Groq. Many AI requests are routed through Vercel AI Gateway, which may serve a model through any of Vercel's inference partners, including for automatic failover. We send only the minimum context needed for each request.
- Provide Local Weather Context. Once per day per user, we send your approximate (IP-derived, rounded) coordinates to Open-Meteo to fetch a local weather forecast. The resulting summary (for example, "cool and rainy, mid-spring") is included as context for the AI assistant so its meal suggestions can reflect the season and weather. No identifying information is sent to Open-Meteo.
- Enable Collaboration. Shared plan features let household members share meal plans and grocery lists.
- Improve the Service. Aggregated usage patterns and diagnostic data help us fix bugs, understand activation/conversion, measure reliability, and prioritize features.
- Communicate with You. Send password reset emails and essential service notifications. We do not send marketing emails without your opt-in consent.
- Maintain Security. Rate limiting, account lockout, and SSRF prevention protect your account and our infrastructure.
3. Third-Party Services
For AI request routing, provider details, and your choices, see How AI uses your data.
We use the following third-party services that may process your data:
| Service | Purpose | Data Shared | |---------|---------|-------------| | Supabase | Database hosting (PostgreSQL) | All stored user data (encrypted at rest) | | Vercel | Application hosting, AI request routing (Vercel AI Gateway), and website analytics (Vercel Web Analytics) | Server requests, IP addresses in access logs, the content of AI requests routed through the AI Gateway, and website page views (page address, referrer, country, and browser, operating system, and device type) | | Vercel AI Gateway inference partners | Hosting the AI models that Gateway-routed requests use; the Gateway selects the partner serving a request and may fail over between partners. Vercel lists its current partners | The content of the AI request routed to that partner (the same categories listed for the model developer) | | DeepSeek | Model provider that Suppa may use for the AI planning assistant and onboarding chat, served through Vercel AI Gateway | Preferences, household context, conversation messages, memory notes, and assistant tool context (such as meal plans, grocery lists, recipe search results, and Kroger product results) | | OpenAI | Recipe adaptation, recipe image generation, semantic embeddings, and a model provider that Suppa may use for the AI planning assistant | Preferences, household context, conversation messages, memory notes, and assistant tool context (such as meal plans, grocery lists, recipe search results, and Kroger product results); recipes and adaptation requests; recipe and image prompts; and text used for search/recommendation embeddings | | Google (Gemini) | Recipe import, recipe suitability checks, daily recipe-search suggestions, backup Kroger search-term preparation, and wording memory notes saved from chat | Recipe import content (including photos), recipes being checked, preferences (including allergies, dietary restrictions, and dislikes), memory notes, recent meal-plan titles, relevant conversation context, and grocery ingredient requests | | Anthropic (Claude) | Onboarding chat; alternative model provider that Suppa may use for the AI planning assistant | Preferences (including allergies, dietary restrictions, and dislikes), onboarding conversation messages, memory notes, and recent meal-plan titles; if used for the planning assistant, conversation messages and assistant tool context | | TypeSafe (Jev) | Connected grocery product matching and purchase quantities, checking grocery list items against your pantry staples, and assistant recipe suitability checks and memory-saving decisions | Grocery ingredient requests and amounts; household food preferences, allergies, and dietary restrictions (for a shared plan, this can include members' display names and food restrictions); saved grocery brand, size, and attribute preferences; Kroger product details; grocery item names with your pantry staples list; and, for assistant checks, recipes, memory notes, and chat messages | | Groq | Kroger search-term preparation, through Vercel AI Gateway | Grocery ingredient requests and recipe wording, earlier search terms and returned product names, and household food preferences, allergies, and dietary restrictions (for a shared plan, this can include members' display names) | | PostHog | Product and LLM analytics | App/device metadata, interaction events, AI request metadata, prompts, assistant conversation context, tool-use interactions, model responses, token counts, latency, costs, and error details | | Sentry | Error tracking | Crash/error reports, performance and device metadata, technical breadcrumbs, and the signed-in account ID, email address, and display name | | Brave Search | Recipe web search | Search queries (e.g., "Thai curry recipe") | | Open-Meteo | Local weather forecast for assistant context | Approximate coordinates (rounded to ~11 km) and timezone — no account identifier | | Instacart | Create a shopping page when you choose the Instacart shopping option | Unchecked grocery item names, quantities and units, the list title, and a Suppa return link (including the shared-plan identifier for shared lists) | | Kroger | Connected shopping at Kroger-family stores when you connect a Kroger account (Suppa Plus) | Kroger authorization codes and tokens, the ZIP code you give to find nearby stores, your selected store ID, grocery product search terms, and the product UPCs and quantities in a basket you confirm | | RevenueCat | Subscription management | Purchase status, product IDs, transaction identifiers | | Email Provider | Password reset emails | Email address | | Apple Sign-In | Authentication | Email, name (as authorized by you) |
Each third-party service is governed by its own privacy policy. We encourage you to review them.
Using the Instacart shopping option is optional. To create a shopping link, Suppa shares the list information described above with Instacart. When you open the shopping page, Instacart handles its own account, shopping, and checkout experience under the Instacart Privacy Policy.
Connecting a Kroger account is optional. It is available to Suppa Plus subscribers and works with Kroger and Kroger-family stores such as Ralphs, Fred Meyer, and QFC. You sign in on Kroger's own authorization page, so Suppa never sees your Kroger password. Suppa asks only for permission to search Kroger's product catalog and to add items to your Kroger cart. It does not ask for access to your Kroger profile, loyalty account, or purchase history. Kroger gives Suppa access and refresh tokens. Suppa encrypts them (AES-256-GCM) before storing them and uses them only for requests you make through Suppa.
To find nearby stores, Suppa sends Kroger the ZIP code you give. To build a basket, Suppa sends Kroger grocery search terms and your selected store ID. Kroger returns product details such as descriptions, sizes, prices, availability, ingredient and allergen information, and image links, and your device loads product images directly from Kroger. Kroger shopping runs through the AI assistant. Your grocery items, related messages, Kroger product results, and food preferences are therefore processed by the AI providers described above, including TypeSafe (Jev) for product matching and purchase quantities and Groq, with Google Gemini as a backup, for turning ingredients into store search terms. Suppa adds items to your Kroger cart only after you confirm a proposed basket, and it sends only product UPCs and quantities for store pickup. Suppa cannot read or remove items already in your Kroger cart. You review your cart and check out with Kroger, under the Kroger Privacy Policy. The app does not yet have a disconnect option. To remove your Kroger connection and stored tokens without deleting your account, email privacy@suppa.cooking.
Before Suppa first transfers your information to an AI provider, the app asks for versioned, explicit consent describing the providers, data categories, purposes, and consequences of declining. You may decline and continue using manual planning, grocery, and cooking tools. You may withdraw or restore consent at any time under Settings → AI Data Sharing; after withdrawal, Suppa blocks new AI transfers and the affected AI features remain unavailable until you consent again.
4. Data Retention
- Account Data. Retained while your account is active. When you delete your account, access is disabled and sessions are revoked immediately. Sign in with Apple authorization is revoked when applicable. The account and associated data are permanently purged by an automated cleanup process within 30 days.
- Cooking Sessions. Stale sessions (inactive for an extended period) are cleaned up automatically via scheduled maintenance.
- Conversations. Assistant conversation history is retained until you delete a conversation or your account.
- Authentication Tokens. Mobile session tokens are stored in the iOS Keychain, rotate automatically, and are invalidated when the account is deleted.
- Kroger Connection Data. If you connect Kroger, your encrypted tokens, selected store, saved grocery shopping preferences, and Kroger basket records are kept until you ask us to remove them or delete your account. Kroger access tokens are short-lived and are refreshed as needed. A Kroger basket shown in an assistant conversation is also part of that conversation's history.
- Rate Limiting Records. Expire automatically after their time window closes.
- Product and AI Analytics. PostHog product events and consented LLM traces may be retained for up to seven years under the current project configuration unless they are deleted or anonymized earlier. We periodically review this window and may shorten it as operational needs mature.
5. Data Export and Deletion
- Export. You can request a copy of your personal data by emailing privacy@suppa.cooking. We may need to verify your identity before providing your data. Authenticated API access is also available via the
/api/profile/exportendpoint. - Deletion. You can delete your account through the app. Access is disabled immediately and permanent purge completes within 30 days. The purge removes your profile, preferences, recipes, meal plans, grocery lists, cooking sessions, feedback, memory, and conversation history. Deletion cascades to all related data.
- Kroger Connection. The purge also deletes your Kroger connection, including its encrypted tokens and selected store, along with your saved grocery shopping preferences and Kroger basket records. It does not remove items already added to your Kroger cart or information Kroger holds under its own privacy policy.
- Shared Plans. If you are the owner of a shared plan, deleting your account will delete the shared plan and its associated data for all members. Members should be notified before you delete your account.
- Subscriptions. Deleting your Suppa account does not automatically cancel a subscription billed by Apple. Cancel it separately in Apple ID subscription settings to prevent renewal.
6. Data Security
We implement reasonable technical and organizational measures to protect your data:
- Password credentials are managed by Supabase Auth using one-way hashing.
- Authentication uses short-lived access tokens and rotating refresh tokens; mobile session material is stored in the iOS Keychain.
- API routes enforce authentication checks before processing requests.
- Rate limiting and account lockout protect against brute-force attacks.
- SSRF prevention guards against server-side request forgery on URL imports.
- Input sanitization prevents XSS and injection attacks.
- Database connections use encrypted channels (TLS).
No method of electronic transmission or storage is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.
7. Children's Privacy
The Service is not directed to children under 13. We do not knowingly collect personal information from children under 13. If we learn that we have collected data from a child under 13, we will delete it promptly. If you believe a child has provided us with personal information, please contact us.
8. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access the personal data we hold about you.
- Correct inaccurate or incomplete data.
- Delete your personal data (see Section 5).
- Export your data in a portable format (see Section 5).
- Object to or restrict certain processing of your data.
- Withdraw consent where processing is based on consent.
To exercise these rights, contact us at the address below.
8.1 California Residents (CCPA)
If you are a California resident, you have the right to know what personal information we collect, request deletion, and opt out of any sale of personal information. We do not sell personal information.
8.2 European Residents (GDPR)
If you are in the EEA/UK, our legal bases for processing are: (a) performance of our contract with you (providing the Service), (b) legitimate interests (security, improvement), and (c) your consent (where applicable). You may lodge a complaint with your local data protection authority.
9. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the new policy in the app and updating the "Last updated" date. Your continued use of the Service after changes constitutes acceptance.
10. Contact Us
If you have questions about this Privacy Policy, please contact us at:
Email: privacy@suppa.cooking