Privacy Policy
Last updated : 30 June 2026
This policy explains what data Keepeat (“we”) collects when you use the Keepeat iOS app and the keepeat.fr website, why we collect it, and your rights. We follow the principle of data minimisation: we only collect what is strictly necessary to run the service.
Data we collect
Identity and account data
- Email address: used to identify you and send the one-time sign-in code. We do not use passwords.
- Sign in with Apple: if you use “Sign in with Apple”, we receive your Apple email address (or a private relay alias if you choose to hide it) and your first and last name if you share them.
- Display name: the username visible in the app.
- Bio / description: optional, freely entered in your profile.
- Preferred language: saved to personalise the interface (fr/en).
Content you create
- Recipes: name, description, source, ingredients, steps, tips, difficulty, prep/cook time, servings, nutrition facts, and associated images or videos.
- Meal plans: recipes scheduled by date and meal moment.
- Tags: created by you to organise your recipes.
- Favourites: recipes you mark as favourite.
- View history: each time you open a recipe, a row is recorded (date and time). This history is used to improve suggestions.
- Import jobs: metadata of recipes imported from an external URL (including Instagram), including the source URL.
Technical and diagnostic data
- Diagnostic reports: when the app errors, crashes or slows down, technical reports are sent to our monitoring tool (device type, app version, incident trace). These reports do not include your IP address (option disabled).
- Performance data and execution profiles: for 100% of sessions, app performance data is collected (load times, execution traces, app logs). No personal browsing data is included.
- Authentication tokens: your access and refresh tokens are stored securely in the iOS Keychain on your device.
Website data (keepeat.fr)
- Language preference: saved in your browser’s
localStorage(keyke-lang). No cookies are placed on the website.
We do not collect precise location data, advertising identifiers (IDFA), or payment data. We never sell your data.
Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Providing the service (recipe management, planning, sync) | Performance of the contract |
| Securing access (sending OTP code by email) | Performance of the contract + legitimate interest |
| Improving and maintaining the app (diagnostics, performance) | Legitimate interest |
| AI enrichment of imported recipes | Legitimate interest |
Passwordless sign-in
Keepeat offers two secure, passwordless sign-in methods:
- One-time code (OTP): a temporary code is sent to your email at each sign-in.
- Sign in with Apple: authentication delegated to Apple, which can provide a relay email alias to protect your real address.
These mechanisms avoid storing passwords and reduce the risks linked to password theft.
AI enrichment
When you import a recipe from an external URL, the recipe text (ingredients, steps) may be sent to an AI service for automatic enrichment (ingredient structuring, nutrition calculation, suggestions).
- Provider: OpenAI (United States) — GPT-4.1-nano / GPT-4o-mini models.
- Data sent: raw recipe text only (no personal identifier).
- Purpose: improving recipe data quality; your content is not used to train OpenAI models, in accordance with OpenAI’s API usage policy.
- International transfer: see the “International transfers” section below.
Import from Instagram
When you import a recipe from an Instagram link, the URL is sent to Instagram / Meta via their oEmbed API to retrieve public post metadata (title, description). No Instagram account data is collected.
Retention
Your data is kept for as long as your account is active. You can delete your account at any time from the app (OTP confirmation required); your recipes and all associated data are deleted within a reasonable period, subject to legal retention obligations.
Processors and data recipients
We use the following providers, who act on our behalf and are bound by contractual confidentiality and security obligations.
| Provider | Purpose | Region |
|---|---|---|
| OVH SAS | Server hosting (VPS), database (PostgreSQL), image and video storage (S3 Object Storage) | EU — France |
| Cloudflare, Inc. | Ingress tunnel / application firewall (processes incoming IP addresses) | Global / EU |
| Zoho ZeptoMail | Sending transactional emails (OTP codes for sign-in and account deletion) | EU (.eu endpoint) |
| Sentry (Functional Software, Inc.) | App error and performance monitoring | EU — Germany (ingest.de.sentry.io) |
| OpenAI, LLC | AI enrichment of imported recipes (text only) | United States |
| Meta Platforms (Instagram oEmbed) | Recipe import from Instagram links (public metadata only) | United States |
| Apple Inc. | ”Sign in with Apple” authentication | Global |
Internal infrastructure tools (Beszel, Portainer) are used solely for infrastructure monitoring and management, and do not process user data.
International transfers
The providers OpenAI (United States) and Meta/Instagram (United States) involve transfers of data outside the European Economic Area (EEA). These transfers are governed by Standard Contractual Clauses (SCCs) adopted by the European Commission, which ensure an adequate level of protection.
Cloudflare operates a global network with EU points of presence; European data is processed preferentially within the EU in accordance with their data localisation policy.
Your rights
Under the GDPR (EU Regulation 2016/679), you have the following rights:
- Access: obtain a copy of your personal data.
- Rectification: correct inaccurate data.
- Erasure: request deletion of your data (right to be forgotten).
- Restriction: restrict processing in certain situations.
- Objection: object to processing based on legitimate interest.
- Portability: receive your data in a structured format.
To exercise these rights, email us at [email protected]. You may also lodge a complaint with your local data protection authority. In France: the CNIL (cnil.fr).
Minors
The service is intended for persons aged 16 or over. We do not knowingly collect personal data from persons under 16. If you believe a child under 16 has created an account, please contact us at [email protected] so we can delete the relevant data.
Data breach notification
In the event of a personal data breach likely to result in a risk to your rights and freedoms, we are committed to notifying the CNIL within 72 hours in accordance with Article 33 of the GDPR, and to informing you as soon as possible if the breach is likely to result in a high risk to your rights.
Security
We implement reasonable technical and organisational measures to protect your data: encrypted communications (HTTPS/TLS), authentication tokens stored in iOS Keychain, database access restricted to the server’s local network, passwordless authentication.
Changes
This policy may change to reflect updates to the service or regulations. Any significant change will be flagged in the app or on this page, with the date above updated.
Contact
For any question about your personal data: [email protected]