Chef Fresh ("the app", "we", "us", "our") is a kitchen-inventory app that helps you track groceries, get expiry reminders, and reduce food waste. We built it to collect as little as possible: there are no ads, no third-party tracking, and we do not sell your data. This policy explains what we handle, why, the legal grounds we rely on, how long we keep it, and the rights you have.
Chef Fresh is developed and operated by Ahmet Eren, an independent developer based in the Republic of Türkiye ("we", the "data controller"). We decide how and why your personal data is processed in the app. For any privacy question or request, contact aegerapps@gmail.com (see Contact).
For users in the EU/EEA and the UK, the GDPR requires us to have a legal basis for each use of your data. Here is how each purpose maps to a basis:
| What we do | Data used | Legal basis (GDPR Art. 6) |
|---|---|---|
| Create your account and sync your kitchen across devices | Account, kitchen data | Performance of a contract — Art. 6(1)(b) |
| Recognise groceries you submit for AI scanning | Scan content (photo/voice/text) | Performance of a contract, at your request — Art. 6(1)(b) |
| Suggest recipes you can cook | Names of your fridge items, your optional note and preferences | Performance of a contract, at your request — Art. 6(1)(b) |
| Share the above with Google (Gemini API) so it can be processed | AI input as listed | Performance of a contract — Art. 6(1)(b): AI recognition is the service itself and cannot be delivered without it. The app discloses the transfer and asks you to accept it before the first transfer. |
| Unlock and restore your subscription | Subscription status, account ID | Performance of a contract — Art. 6(1)(b) |
| Prevent abuse, fraud, and free-scan circumvention; keep the service secure | Device ID, IP (transient) | Legitimate interests — Art. 6(1)(f) |
| Send expiry and recap reminders | On-device schedule; OS notification permission | Consent — Art. 6(1)(a) |
| Respond to legal requests and enforce our terms | As relevant | Legal obligation / legitimate interests — Art. 6(1)(c)/(f) |
Where we rely on legitimate interests, our interest is protecting the app and its users from abuse and keeping the service running; we have balanced this against your rights. Where we rely on consent (e.g. notifications), you can withdraw it at any time without affecting processing that already took place.
If this ever changed, we would update this policy and its effective date, notify you in the app, and — where the law requires — ask for your consent first. Any such change would apply only to data collected afterwards, never retroactively to data you gave us under this version.
Chef Fresh has no AI model of its own. Two features — scanning (recognising groceries from a photo, a voice note, or typed text) and recipe suggestions — work by sending your input to Google's Gemini API and showing you what comes back. Because that means your data leaves your device and reaches a third-party AI service, we set it out in full here.
The recipient is Google, through the Gemini API. The request travels from your device to our own server (Supabase Edge Functions) over an encrypted connection and is forwarded from there — the API key never sits on your device. We use the paid tier of the Gemini API, under which Google's own terms state that it does not use your prompts or the responses to train or improve its models, and there is no human review for model improvement. Google logs the request for a limited period solely to detect abuse of its service. Google's handling is governed by the Gemini API Additional Terms of Service and the Google Cloud Data Processing Addendum, which commit it to protections equivalent to those described in this policy.
Before anything is sent to Google, and before you can use the app, Chef Fresh shows you a screen naming Google and Gemini, listing exactly what will be transmitted, and asking you to accept. Nothing is sent unless you tap Accept and continue.
AI recognition and AI recipes are what Chef Fresh is — the app is built around them rather than offering them as an extra — so accepting is required to use it. If you do not want your input shared with Google on these terms, please do not accept: simply close the app, and nothing will have been sent. You can withdraw at any later point by deleting your account in Settings → Account and removing the app, which stops any further sharing and erases the data we hold (see Deleting your data). Because nothing you send is retained after a request completes, there is nothing left with Google to delete.
We do not store your AI input or the response: both exist only for the seconds the request takes. Recognised items are saved only after you review and confirm them, and are then ordinary fridge data.
AI output is a suggestion, not a fact. Item names, quantities, estimated expiry dates and recipes should be checked before you rely on them — especially for allergies and food safety.
The app relies on a small set of processors that handle data only on our instructions and only to provide their function:
| Provider | Purpose | Typical processing location |
|---|---|---|
| Supabase | Accounts and cloud database (sync) | Cloud data centres (may be outside your country) |
| Google (Gemini API) | AI scanning and recipe generation (see section 5) | Google Cloud infrastructure |
| RevenueCat | Subscription management | United States |
| Apple / Google | Sign-in and payment processing | Per their own policies |
Each provider has its own privacy policy governing its infrastructure. Each is bound by a data-processing agreement requiring it to protect your data to a standard equivalent to the one described in this policy, to process it only on our instructions and only for the purpose listed above, and to keep it confidential. We do not authorise any of them to use your data for their own advertising, and none of them is permitted to use it to train AI models.
Because we use the providers above, your data may be processed in countries outside your own, including the United States, which may not offer the same level of data protection as your home country. Where the GDPR applies, such transfers are protected by appropriate safeguards — typically the European Commission's Standard Contractual Clauses or an equivalent mechanism offered by the provider. You can request more detail using the contact below.
If you share a kitchen, its members see the shared inventory and the display name you chose — that's the point of the feature. Any member can edit the shared items. Leaving a kitchen keeps a private local copy of the items on your own device. Only invite people you trust.
The app asks for these device permissions only when you use the related feature, and you can revoke any of them in your device settings. Separately from these, the app asks you to accept the sharing of AI input with Google before you can use it at all — see section 5.
Subject to the laws that apply to you (including the GDPR/UK GDPR), you have the right to:
You can exercise most of these directly in the app (see Deleting your data) or by emailing us. We will respond within the timeframe required by applicable law (generally one month under the GDPR) and will not charge you or discriminate against you for exercising a right.
If you are a California resident, you have rights under the CCPA/CPRA. In the past 12 months we have collected the following categories of personal information, and we have not sold or "shared" (for cross-context behavioural advertising) any personal information:
| Category | Examples in Chef Fresh |
|---|---|
| Identifiers | Name, email, account ID, device ID, IP address (transient) |
| Commercial information | Subscription status |
| Audio/visual information | Scan photo or voice recording (used once, not stored) |
| Internet/network activity | Minimal, abuse-prevention only |
We do not knowingly collect sensitive personal information for the purpose of inferring characteristics, and we do not use it beyond providing the service. California residents may exercise the rights to know, delete, and correct, and to be free from discrimination for exercising them. Because we do not sell or share personal information, no "Do Not Sell or Share My Personal Information" action is required, but you may still contact us with any request at the address below.
You are in control:
For any other privacy request, contact us at the address below and we'll help as required by the laws that apply to you.
All traffic between the app and our servers is encrypted in transit (TLS), and cloud data is protected with row-level security so each account can only reach its own kitchen's data. No method of transmission or storage is 100% secure, but we take reasonable measures to protect your information and keep our data footprint small.
Chef Fresh is a general-audience app and is not directed to children. We do not knowingly collect personal data from children under 13 (or the minimum age of digital consent in your country, which can be up to 16 in parts of the EU). If you believe a child has provided us personal data, contact us and we will delete it.
AI scanning suggests item names, quantities, and estimated expiry dates to save you typing, and recipe suggestions propose dishes; you can always review and edit both (see section 5). It does not make any decision that produces legal or similarly significant effects about you, so it is not "automated decision-making" in the sense of GDPR Article 22.
If this policy changes, we'll update this page and its effective date above; material changes will also be communicated in the app. Continued use after an update means you acknowledge the revised policy.
Questions or requests: aegerapps@gmail.com
Data controller: Ahmet Eren, Fatih, İstanbul, Republic of Türkiye.