Heirloom Cookbook — Privacy Policy

Last updated 20 July 2026

Heirloom Cookbook (“Heirloom”, “the app”) is a recipe-keeping app for families. It is made by an individual developer in Australia. This policy explains exactly what the app collects, why, where it is stored, and how to get rid of it.

Heirloom does not sell your data, does not show advertising, and contains no third-party advertising, tracking or analytics SDKs.

Who is responsible

The developer of Heirloom Cookbook is the data controller. Contact: chefheirloom@gmail.com.

What Heirloom collects

WhatWhyRequired?
Account details — your email address, a display name, and (if your sign-in provider supplies one) a profile picture. To create your account, sign you in, and show who wrote a recipe or belongs to a cookbook. Required
Sign-in identifiers — if you use Sign in with Apple or Google, we receive an identifier from them, plus your email address and (on first authorisation only) your name. To authenticate you without Heirloom handling a password. Required if you choose those sign-in methods
Your recipes and photos — recipe text, ingredients, steps, notes and tips you write, photos you attach, and photos of original recipe cards you import. This is the content of the app. It is stored so you and the people you share a cookbook with can read it. Required to use the app’s purpose
Cookbook membership — which cookbooks you own or belong to, your role in them, and invitations you send or accept. To control who can see which recipes. Required
Onboarding answers — what you want from the app. Your goals (e.g. “Preserve our recipes”) and what gets in the way of cooking (e.g. “Lack of time”). To tailor defaults and to understand what people actually want the app to do. Optional — every question can be skipped
Onboarding answers — demographics. An age range (e.g. “35–44”) and the number of people in your household (e.g. “4”). To understand who is using the app in aggregate, and to inform sensible defaults such as recipe serving sizes. Heirloom does not ask for your date of birth, gender, race, ethnicity, religion, health, sexuality, political views, income or any other sensitive category. Optional — can be skipped, and either field can be left blank
Onboarding answers — how you found us. A single choice such as “Someone invited me”, “App Store” or “Social media”. To know which channels bring people to the app, so effort goes where it is useful. This is a self-reported answer only — Heirloom does not use advertising attribution SDKs, referrer tracking, install fingerprinting or any third-party measurement service. Optional — can be skipped

On the optional questions. The demographic and “how did you hear about us” questions appear once, during onboarding, each on a screen with a visible Skip control. Skipping them stores nothing and does not limit any feature of the app. If you answered them and want that removed, see “Deleting your data” below.

What Heirloom does not collect

Where your data is stored

Heirloom uses Supabase as its hosting provider for the database, authentication and file storage. Data is stored in Supabase’s Sydney, Australia region (ap-southeast-2). Supabase acts as a processor on the developer’s behalf and does not use your content for its own purposes.

Access is enforced at the database level by row-level security: a recipe is readable only by its owner and by members of a cookbook it has been shared into. Photos are stored in per-user folders and served through short-lived signed links.

The only other parties involved are Apple and Google, and only if you choose their sign-in buttons. Their handling of that sign-in is covered by Apple’s and Google’s own privacy policies.

Beta testing via TestFlight

While Heirloom is distributed through TestFlight, Apple provides the developer with aggregate tester and crash information, and TestFlight itself collects data under Apple’s terms. Feedback you submit through TestFlight — including any screenshot — is sent to Apple and shared with the developer. See Apple’s TestFlight privacy notice.

How long it is kept

Your account and content are kept until you delete them. Deleted content is removed from the live database immediately; encrypted infrastructure backups may retain it for up to 30 days before rolling off.

Deleting your data

Heirloom has in-app account deletion: Profile → Delete account. Because deleting an account can affect cookbooks other people rely on, the screen shows what will be removed and asks you to choose who inherits any cookbook you own, and whether recipes you shared stay with the group. Deletion removes your profile, your onboarding answers (including the demographic and acquisition-source answers), your recipes and photos according to those choices, and your sign-in record.

You can also email chefheirloom@gmail.com to request access to, correction of, or deletion of your data.

Children

Heirloom is not directed at children and is not intended for use by anyone under 13. The app does not knowingly collect data from children under 13. If you believe a child has provided data, email the address above and it will be deleted.

Your rights

Under the Australian Privacy Principles (Privacy Act 1988 (Cth)), and under the GDPR if you are in the UK or EEA, you may request access to your personal information, ask for it to be corrected, ask for it to be deleted, or complain about how it has been handled. Requests go to the address above and will be answered within 30 days. If you are in Australia and are unhappy with the response, you may complain to the Office of the Australian Information Commissioner.

Changes to this policy

If this policy changes materially, the date at the top will be updated and the change noted in the app’s release notes. Past versions are visible in the app’s public source repository.

Contact

chefheirloom@gmail.com