Last updated 17 September 2026
Savory Simmer is a private recipe bank, weekly meal planner, and shopping-list tool. This policy explains exactly what it stores about you, why, who else can see it, and how to get rid of it. It is written against the actual database schema — not a template.
Savory Simmer, the Netherlands is the data controller for the purposes of the GDPR. Savory Simmer is a trading name for an independent personal project; it is not a registered company.
Contact for any privacy question or request: hello@savorysimmer.com
| Data | Why it exists |
|---|---|
| Your email address and a hashed password | So you can sign in. Handled by Supabase Auth; the operator never sees your actual password. |
| Your recipes — title, description, ingredients, steps, tags, servings, times, source URL, image URL | They are the product. You created or imported them. |
| Your meal plan — which recipe you put on which date | To show your week and build the shopping list. |
| Shopping-list checkbox state | So ticking "have it" survives a page reload. The list itself is recalculated every time and never stored. |
| A capture cache — the parsed recipe plus the raw text or captions fetched from a URL you imported | So re-importing the same link doesn't re-run (and re-charge) the AI. Private to you. |
| Account settings and a count of your recipe imports | To apply the free import allowance and Premium's fair-use limit, and to measure what each import costs us (the number of AI tokens it used, never its content). |
What Savory Simmer does not collect: no uploaded photos, no location data, no payment or card details, no advertising identifiers, no third-party tracking profile, and no contact list. Savory Simmer does not sell or share your data with anyone for marketing.
The lawful basis is performance of a contract (GDPR Art. 6(1)(b)) — you asked for an account and the data listed above is what makes the app work. There is no profiling and no automated decision-making that has any legal effect on you.
Each is a standard processor under a data processing agreement. Some operate servers outside the EU; transfers rely on the European Commission's Standard Contractual Clauses.
Savory Simmer sets no advertising or tracking cookies. The only thing kept in your browser is the session token that keeps you signed in and your light/dark theme choice — both strictly necessary, so no cookie banner is required. If privacy-friendly, aggregate analytics are added later, they will not use cookies or track you across sites, and this section will be updated before that happens.
Your data stays until you delete it. Delete a recipe and it is gone immediately. Delete your account and everything above is destroyed at the same moment — see below.
Every table enforces row-level security in the database: a query can only ever return rows belonging to the signed-in user, so one account cannot read another's recipes even if the app itself had a bug. Traffic is encrypted in transit. No system is perfect — if a breach ever affects your data, the Autoriteit Persoonsgegevens will be notified within 72 hours and you will be told directly where the law requires it.
Savory Simmer is not directed at children under 16 and does not knowingly collect their data.
If this policy changes materially, the date at the top changes and you will be told in the app before the change takes effect.