GhostChef privacy policy
Last updated: 23 September 2026
This policy explains which personal data GhostChef processes, why, on what legal basis, for how long and with whom we share it. It applies to the GhostChef Android app and to this website. The app is in Dutch; button names are quoted as they appear in the app.
In short
- We only process what is needed to run the app, keep it safe and offer it for free with ads.
- Your data is stored with Supabase in Ireland (EU).
- We only send something to OpenAI (US) after you agree to it for that type of action.
- Published recipes, your name, your rank, your likes and who you follow are public. Your lists, pantry and saved recipes are private.
- We do not sell any data and we do not use your photos or videos for advertising.
- You can only log in with Google or GitHub.
- A video never becomes a recipe photo. We delete videos automatically after processing.
Please note: an AI reads our email. Every email sent to app.ghostchef@outlook.com, including reports made in the app, is read and sorted by an AI assistant: Grok by xAI (US). Only include what is needed. Decisions are always made by a person. More information
1. Who is responsible
The controller is [NAAM], [ADRES], Belgium, trading as GhostChef (enterprise number [KBO-NUMMER]). Contact: app.ghostchef@outlook.com. GhostChef has no data protection officer; this is not required for a service of this size.
2. What we process and why
2.1 Account and login
- Data: your email address, whether you log in with Google or GitHub, and an account ID. Google or GitHub also send your name, your username there and a link to your profile picture. Supabase stores these with your login data. GhostChef does not show or use them. Each login session also records the time, your IP address and your device or browser type.
- Why: to give you an account and a secure login.
- Legal basis: performance of the contract (Art. 6(1)(b) GDPR). For session and security data: our legitimate interest in securing accounts (Art. 6(1)(f) GDPR).
- Retention: until you delete your account. Session data until you log out or the session expires.
- You can only log in with a Google or GitHub account. You can browse recipes without an account.
2.2 Profile, XP, leaderboard and cooking streak
- Data: username and display name (chosen once), chef rank, XP and what you earned points for, badges, position on the monthly leaderboard and your cooking streak (the days you finished cook mode).
- Why: to run the profile, levels, boosts and leaderboard.
- Legal basis: performance of the contract.
- Retention: until you delete your account.
2.3 Recipes, photos and cook mode
- Data: recipes (title, description, ingredients, steps), recipe photos and cook photos. Photos are taken live with the camera. You can post at most 2 cook photos per recipe.
- Why: to create, show, share and cook recipes.
- Legal basis: performance of the contract.
- Retention: until you delete the content, we remove it or you delete your account.
2.4 Private features
- Data: shopping lists, pantry, saved recipes and drafts.
- Legal basis: performance of the contract.
- Retention: until you delete them or your account. Nobody else can see them.
2.5 Video to recipe
- Data: the cooking video you pick from your gallery (it may show or record your face, voice and surroundings), still frames from that video, a transcript of what is said, a digital fingerprint of the file (SHA-256) and the processing status.
- Why: to turn your video into a recipe, recognise duplicate videos and apply the limit of 5 videos per month.
- Legal basis: your consent to send the video to OpenAI (Art. 6(1)(a) GDPR), which we ask for in the app before your first video. The rest falls under performance of the contract.
- Retention: we automatically delete the video and frames as soon as processing is finished, also when it fails. Files that do not belong to a running job, for example because the app was closed during the upload, are deleted automatically after about one hour. The fingerprint is kept as long as the recipe exists. OpenAI keeps what it received for at most 30 days (see section 3).
- Your video and the frames from it are never used as a recipe photo and are never public. If you want a recipe photo, you take it yourself, live with the camera.
- If other people are recognisable in your video, ask for their permission first.
2.6 Fridge scan
- Data: one live photo of your fridge or pantry, and the products recognised in it.
- Why: to suggest what you can add to your pantry.
- Legal basis: your consent to send the photo to OpenAI.
- Retention: we do not keep the photo. The recognised products and what you add to your pantry are kept until you delete them or your account.
2.7 Automatic checks
- Data: recipe text, username and display name, and recipe and cook photos. We check these automatically with OpenAI and with our own list of banned words. We keep the outcome: approved or rejected, with the reason.
- Why: to stop hate, sexual content, violence and other prohibited or illegal content, and to check that a photo really belongs to the recipe.
- Legal basis: your consent to send that content to OpenAI. We keep the outcome based on our legitimate interest in a safe app and our obligations under the Digital Services Act.
- Retention: as long as the content exists.
- How this works and how to ask for a human review is explained in section 7.
2.8 Likes, follows, blocks and reports
- Data: who likes which recipe, who follows whom, who blocks whom, and reports: who reports, what is reported, the reason and the time.
- Why: social features, handling reports and preventing abuse. You can report the same recipe or account only once, and at most 7 times per week.
- Legal basis: for likes, follows and blocks, performance of the contract. For reports, our legitimate interest and our legal obligation to handle notices (Art. 16 Digital Services Act).
- We send each report made in the app to our mailbox by email through Resend. That email contains your username, display name, account ID and your account’s email address, what you reported and the reason. We use your email address to tell you what we did with your report, as Article 16 of the Digital Services Act requires. Grok also reads these emails (see section 2.10).
- We do not tell the reported person who reported them, unless strictly necessary, for example when a rights holder files a copyright notice in their own name.
- Retention: likes, follows and blocks until you undo them or delete your account. Reports stay in the database as long as the reporter’s account exists. We delete report emails at the latest 12 months after the report is handled.
2.9 Copyright notices
- Data about the notifier: your name and email address, on whose behalf you act (if not yourself), which work is yours, which recipe or account it concerns, your explanation and your statement that you report in good faith.
- Data about the uploader: the reported content, username and account ID, our decision and any counter-notice with explanation.
- Why: to assess the notice, hide or remove the content if needed, tell the uploader why, handle a counter-notice and prevent abuse of notices.
- Legal basis: our legal obligation to handle notices and explain our decisions (Art. 16 and 17 Digital Services Act; Art. 6(1)(c) GDPR), and our legitimate interest in acting against infringements and defending ourselves in a dispute (Art. 6(1)(f) GDPR).
- Sharing: so the uploader can respond, we may give them your name (or the rights holder’s name) and a description of the work. We do not share your email address unless you agree. We may share a counter-notice with the notifier in the same way.
- If you report in the app, the notice reaches our mailbox through Resend, as in section 2.8. If you report by email, it arrives directly in our mailbox. In both cases Grok reads it (see section 2.10).
- Retention: up to 12 months after the notice is handled. If there is a dispute or court case, until it has ended.
2.10 Emailing us: Grok reads along
- Data: your email address, your message and any attachments.
- Why: to handle your question, report or request.
- Legal basis: our legitimate interest in replying and keeping our mailbox manageable, and our legal obligation for privacy requests and reports.
- An AI reads your email. An AI assistant, Grok by xAI (US), reads, summarises and sorts every email that arrives in our mailbox, including attachments. This also applies to reports made in the app, because they arrive by email. Grok decides nothing: reports, accounts and requests are always reviewed by a person, and replies come from a person.
- The mailbox itself runs on Microsoft’s Outlook.com. Microsoft only stores the emails as the mailbox provider. Your email may therefore reach Microsoft and xAI, including in the US.
- Only include what is needed. Do not send a copy of your ID card, your national ID number, health data or other people’s data.
- Retention: until your request is handled and then at most 12 months.
2.11 Ads through Google AdMob
- Data: your device’s advertising ID, your IP address, device and app information, which ads you see and tap, your approximate location (derived from your IP address) and your consent choice.
- Where you see ads: shortly after adding to your shopping list, when starting cook mode, after an approved cook photo, and as a banner while a video recipe is being made.
- Legal basis: your consent (Art. 6(1)(a) GDPR and the ePrivacy rules), given through Google’s consent screen on first launch. If you say no, Google only shows limited, non-personalised ads.
- Google Ireland Limited is itself responsible for what Google does with this data. See policies.google.com/technologies/ads.
- Change: in the app via Account → Advertentievoorkeuren. You reset or delete your advertising ID in the Android settings.
- Retention: according to Google’s periods.
2.12 Security and troubleshooting
- Data: technical logs of our database and server functions: account ID, time, IP address and error messages.
- Legal basis: our legitimate interest in keeping the app secure and working.
- Retention: a few days, according to Supabase’s log retention.
2.13 This website
- Data: your IP address, browser, the page requested and the time, logged by our hosting provider [HOSTING].
- Legal basis: our legitimate interest in showing and securing the website.
- The website sets no cookies and uses no analytics or advertising services.
- Retention: short, according to the hosting provider’s period.
3. Who receives your data
| Recipient | What for | Where | Safeguard |
|---|---|---|---|
| Supabase, Inc. | Database, login, file storage and server functions | Data centre in Ireland (EU). Support staff and subprocessors may be outside the EU. | Data processing agreement with standard contractual clauses |
| OpenAI Ireland Ltd., with OpenAI, L.L.C. | Video to recipe, fridge scan and automatic checks | US | Data processing agreement with standard contractual clauses. OpenAI does not use the data to train its models and keeps it for at most 30 days to detect abuse. |
| Resend, Inc. | Sending reports made in the app by email to our mailbox | US | Data processing agreement with standard contractual clauses |
| Microsoft (Outlook.com) | Only the mailbox that holds our emails | EU and US | Microsoft’s terms and the EU–US Data Privacy Framework |
| xAI (Grok) | AI assistant that reads and sorts every email in our mailbox, including reports made in the app | US | xAI’s terms |
| Google Ireland Limited and Google LLC | Ads (AdMob). Login with Google, if you choose it. | EU and US | Google is itself responsible. EU–US Data Privacy Framework and standard contractual clauses. |
| GitHub, Inc. | Login with GitHub, if you choose it | US | GitHub is itself responsible. EU–US Data Privacy Framework. |
| [HOSTING] | Hosting this website | [LAND] | Data processing agreement |
If you install the app through Google Play, Google processes data for that under its own privacy policy. We only give data to authorities when the law requires it. We do not sell any data.
4. Transfers outside the EEA
Some recipients are based in the United States. For companies that have joined the EU–US Data Privacy Framework, an adequacy decision of the European Commission applies. For the others we use the European Commission’s standard contractual clauses. You can ask us for a copy of these safeguards.
5. Storage on your device
The app stores a few things on your phone:
- Your login session, so you stay logged in. This is strictly necessary.
- Which types of actions you gave AI consent for, so we do not ask every time. Withdraw via Account → AI-toestemming intrekken.
- Small display settings, such as whether you have already seen a level-up screen.
- Google’s advertising software reads and stores your advertising ID and similar data, only as you chose in Google’s consent screen.
The app only asks for access to your camera and gallery when you take a photo or pick a video. You manage that access in the Android settings. On recipe and cooking screens the app blocks screenshots; no data is collected for this. The app uses no other tracking or analytics software.
6. What is public
Visible to everyone, including people without an account: published recipes and their photos, approved cook photos, your username and display name, chef rank, XP and what you earned points for, badges, cooking streak, leaderboard position, which recipes you like, who you follow and who follows you. Your email address is never public.
Private: shopping lists, pantry, saved recipes, drafts, videos, fridge photos, and your reports and blocks.
7. Automated decisions
A name, recipe text or photo can be rejected automatically, for example for hate, sexual content, violence, text in the image, a photo that does not match the recipe or an image from the internet. Such a rejection only concerns that name, text or photo, not your whole account. If you think the check got it wrong, email us and a person will review it. We never close accounts automatically.
8. Age
The minimum age depends on your country and is between 13 and 16 (see the terms of use). When you log in, you declare that you are old enough. We do not ask for or store your date of birth. If we find out someone is too young, we delete the account.
9. Your rights
- Access and copy (Art. 15 and 20 GDPR): see My data.
- Rectification (Art. 16): you cannot change your username yourself. If something is wrong, email us.
- Erasure (Art. 17): see Delete account.
- Restriction (Art. 18) and objection (Art. 21): you can object to processing based on our legitimate interest.
- Withdrawing consent (Art. 7): AI via Account → AI-toestemming intrekken, ads via Account → Advertentievoorkeuren. Processing that already took place remains lawful.
Email your request to app.ghostchef@outlook.com, preferably from your account’s email address so we know it is you. Grok reads that email (see section 2.10). We reply within one month. For complex requests this can be extended by two months; we will let you know if so.
If you disagree with how we handle your data, you can file a complaint with the Belgian Data Protection Authority (dataprotectionauthority.be) or with the authority in your own country.
10. Security
All connections are encrypted. In the database, each user can only access their own private data. Secret keys are kept only on the server, not in the app. If a data breach poses a risk to you, we report it to the Data Protection Authority within 72 hours and, if the risk is high, to you as well.
11. Changes
If we change this policy on an important point, we will announce it in advance in the app or on this website. The date at the top shows the latest version.