Privacy
Last updated: July 2026
The short version, before the legal one. The website sets no cookies. It stores nothing on your device. It runs one anonymous page-view counter so we know if anyone's reading. The app is where your household's data lives — recipes, plans, lists, photos. That data stays in your household, on servers in Frankfurt. One exception: when you import a recipe or ask for an AI-generated recipe photo, the recipe's title and ingredients are sent to Google's Gemini API to do that work (see the subprocessor list). We never sell it, never show ads against it, never train a model on it. The rest of this page is the legally precise version of these two paragraphs.
1. What this policy is
This document tells you what personal data Staple collects from you when you use the app, why we collect it, who else gets to see it, how long we keep it, and what rights you have over it. It is written to comply with the EU General Data Protection Regulation (GDPR / DSGVO) and to be intelligible to a person who is not a lawyer.
If you only read one paragraph: Staple stores your email address, your recipes, your meal plans, your shopping lists, and any photos you upload, on servers operated by our infrastructure provider. We use this data to run the service. We do not sell it, do not show ads against it, do not use it to train AI models, and do not share it with anyone except the named technical subprocessors below. You can ask for a copy, ask for corrections, and ask for deletion at any time by writing to cook@withstaple.com.
2. Who we are (the data controller)
Staple is operated by Mischa Frank, Eckenheimer Landstr. 70, 60318 Frankfurt am Main, Germany.
For any data-protection question, the responsible contact is:
Email:
cook@withstaple.comPost: Mischa Frank, Eckenheimer Landstr. 70, 60318 Frankfurt am Main, Germany
We do not currently appoint a separate Data Protection Officer (Datenschutzbeauftragter) because we do not meet the size or processing thresholds in § 38 BDSG that would require one. If that changes, this section will be updated and a DPO contact added here.
3. What we collect, and on what legal basis
We process the following categories of personal data. Each item lists the legal basis under Art. 6 GDPR.
3.1 Account data
When you sign in for the first time, Staple creates an account tied to your email address.
- Email address. Used to send you the sign-in link, deliver important account notifications, and identify your account across devices. Basis: Art. 6(1)(b) — necessary for the performance of the contract you enter into by signing in.
- Authentication tokens. Short-lived session tokens stored on your device (and on our auth provider's servers) so you stay signed in. Basis: Art. 6(1)(b).
We do not collect your name, your phone number, your date of birth, or your address.
3.2 Profile data
After you sign in, you can optionally fill in:
- Display name (the name your household sees on the planning surface).
- Avatar image (a profile picture you upload).
- Language preference (English / German).
All of these are optional. Basis: Art. 6(1)(a) — consent (you actively choose to provide them). You can remove or change them at any time inside the app.
3.3 Household data
A "household" in Staple (in the German app: Küche) is a shared workspace for two or more people who cook and plan together. When you create or join one, the following data is associated with it:
- Household name.
- Membership list (which Staple accounts belong to the household, and each member's assigned color slot).
- Settings (timezone, first day of the week, meal slots configured for the household).
Basis: Art. 6(1)(b) — necessary to operate the multi-user features you signed up for.
3.4 Recipe, plan, and list data
The core content you create inside Staple:
- Recipes (titles, ingredients with quantities and units, method steps, source attribution, notes, cook duration, serving counts, tags, and any uploaded photos).
- Meal plans (which recipe is assigned to which day, which household member is cooking, optional swaps and substitutions).
- Shopping lists (items derived from your plans, plus anything you add manually, and margin notes on individual items).
- Cook sessions (timestamps for when you start and finish cooking a recipe; used to power features like "last cooked" and the in-progress Cook Mode surface).
Basis: Art. 6(1)(b). This data is the service. Without it, Staple cannot do what you signed in for.
3.5 Photographs
If you add photos to your recipes (a photo of the dish, the page from your grandmother's cookbook, an annotated step), those images are stored on our object-storage infrastructure (see the subprocessor list below). We do not run face recognition, content classification, EXIF-based location lookups, or any other automatic analysis on your photos.
AI-generated recipe photos. When you ask for an AI-generated recipe photo for a recipe that has none, we send the recipe's title and ingredients to Google's Gemini API, which returns an image. That image carries an invisible SynthID watermark. Google does not claim ownership of it and may generate similar content for others. Like any other photo, it is stored in your household's storage and shown only inside your household.
Basis: Art. 6(1)(b) for photos you attach to a recipe (necessary for the recipe content you saved); Art. 6(1)(a) for any photos you upload outside of a recipe context. The AI-generated photo request is also Art. 6(1)(b) — it is the action you asked us to perform.
3.6 Technical and operational data
The infrastructure that runs Staple keeps a small amount of operational data so the service can function and so we can debug it when it breaks:
- Server access logs (IP address of the request, timestamp, requested URL, HTTP status code, user-agent string). Kept by our hosting provider on a rolling basis, typically for a matter of days, for fraud prevention and abuse mitigation. Basis: Art. 6(1)(f) — legitimate interest in securing the service.
- Error logs. When the app crashes or returns an error, the server records the error message and a stack trace. These logs may incidentally contain your user ID (a random UUID) and the URL you were on when the error happened. They do not contain your recipes, your email, or your content. Basis: Art. 6(1)(f).
- Realtime presence. When you are inside the app, our realtime infrastructure tracks which household members are currently online, so household-mate features (the live shopping list, the active cook in the household masthead) can render. This presence data is not persisted to long-term storage. Basis: Art. 6(1)(b).
3.7 Cookies
Staple sets only strictly necessary cookies: the encrypted session cookies that keep you signed in (set by our authentication provider) and a small number of functional values stored in your browser's local storage (e.g. onboarding state). The marketing pages of withstaple.com set no cookies at all. We do not set advertising, tracking, or third-party analytics cookies. Because these cookies are strictly necessary to provide the service you requested, no consent banner is required for them under § 25(2) TDDDG.
3.8 Website visits (the marketing pages)
The marketing pages of withstaple.com are intentionally lean:
- No cookies at all. The site sets no cookies and stores nothing in your browser beyond strictly necessary values (§ 25(2) TDDDG) — which is why there is no consent banner.
- Self-hosted fonts. The typefaces are downloaded once at build time and served from the same domain as the page. Your browser never makes a runtime request to a third-party font CDN.
- No forms. No contact form, no newsletter signup, no waitlist field.
- Simple Analytics counts page views on the site exactly as it does in the app (see the subprocessor table below) — cookieless, no IP storage, no personal identifiers.
- If you email us at
cook@withstaple.com, we process the message and the address you sent it from in order to answer you, and we keep the thread for as long as the correspondence requires. Basis: Art. 6(1)(f) — legitimate interest in responding; Art. 6(1)(b) where your message relates to your account.
3.9 What we don't collect
To be explicit, because the omissions matter:
- No third-party advertising. No pixels from Meta, Google Ads, TikTok, X, or LinkedIn. No tracking SDKs. The app is not monetized through advertising.
- No data brokers. We do not buy, sell, or rent data from or to any third party.
- No AI training. Your recipes, photos, and household data are not used to train any machine-learning model — neither ours nor any third party's. When you import a recipe or generate a recipe photo, the recipe's title and ingredients are processed by Google's Gemini API for that request only. On the paid API tier we use, Google does not use this content to train its models.
- No biometric data. We use only the device-level biometric unlock features your operating system provides (Face ID, fingerprint). Staple itself never sees the biometric.
- No precise location. The app does not request GPS access. We do not log your geolocation.
4. Who has access (subprocessors)
To run Staple, we use a small number of technical service providers ("subprocessors" in the language of Art. 28 GDPR). Each one is contractually bound to use your data only on our instructions, and any transfer outside the EU/EEA is covered by appropriate safeguards (Standard Contractual Clauses or an adequacy decision) — see the next section.
| Subprocessor | Role | Data it sees | Region |
|---|---|---|---|
| Supabase (supabase.com) | Database, authentication, file storage, realtime sync | All app data (email, profile, recipes, plans, lists, photos, sessions) | EU region (Frankfurt) for stored data; control plane in the United States |
| Vercel (vercel.com) | Web hosting and edge runtime for the app | Server access logs, error logs, encrypted session cookies in transit | EU edge nodes for European traffic; control plane in the United States |
| Sendkit (sendkit.dev) | Transactional email delivery (sign-in links and codes, account notifications), connected as the SMTP provider of Supabase Auth | Your email address and the text of the transactional email | Brazil |
| Simple Analytics (simpleanalytics.com) | Privacy-friendly page-view analytics on the site and in the app | Page views, referrer, aggregate engagement. No cookies, no IP storage, no personal identifiers | EU (Netherlands) |
| Google (cloud.google.com) | Gemini API — recipe import extraction and AI-generated recipe photos | Recipe title, ingredients, and for imports the source text/photos you submitted | Processing may occur wherever Google operates; EU–US Data Privacy Framework participant |
When we add a new subprocessor, this list is updated. If a future subprocessor materially changes the categories of data they see or the region they operate from, we will notify existing users by email before the change takes effect.
We do not transfer your data to any other third party. Specifically, we have no commercial, marketing, advertising, or analytics partners beyond the privacy-friendly page-view counter named above.
5. International data transfers
Some of our subprocessors operate from outside the EU/EEA:
- Supabase and Vercel run their control planes in the United States. Transfers are covered by the EU–U.S. Data Privacy Framework where the provider participates, and otherwise by Standard Contractual Clauses (Art. 46(2)(c) GDPR).
- Sendkit (transactional email) operates from Brazil, for which no EU adequacy decision exists. The transfer of your email address and the transactional email text is covered by Standard Contractual Clauses (Art. 46(2)(c) GDPR). Only the minimum data needed to deliver the email is transferred.
- Google (Gemini API) may process requests on servers outside the EU/EEA. Google participates in the EU–US Data Privacy Framework, and any transfer not covered by that framework is covered by Standard Contractual Clauses (Art. 46(2)(c) GDPR). Only the minimum recipe text needed for the request is transferred.
- Technical safeguards apply across all transfers: encryption in transit (TLS 1.3) and at rest, scoped access tokens, and Row-Level Security on the database layer so that no subprocessor employee has standing access to your recipes or plans.
The bulk of your data — recipes, plans, lists, photos — lives in Supabase's EU region (Frankfurt) and does not leave the EU/EEA under normal operation.
6. How long we keep it
| Data | Retention |
|---|---|
| Account email and profile | For as long as you have an account, plus 30 days after deletion (for spam/abuse appeals) |
| Recipes, plans, lists, photos | For as long as your household exists, plus 30 days after household deletion |
| Authentication tokens | Until they expire or you sign out (typically 1 hour to 7 days for refresh tokens) |
| Server access logs | Up to 14 days, then automatically rotated |
| Error logs | Up to 30 days |
| Email delivery logs (sender-side) | Up to 30 days |
| Gemini API prompts/responses | Up to 55 days in Google's abuse-monitoring logs; not used for model training |
When you delete your account, your personal data is removed from the live database within 7 days and from rolling backups within 30 days. Anonymous aggregate counts (e.g. "the database has N households") may persist indefinitely; these contain no identifier of you.
7. Your rights
Under the GDPR you have the following rights with respect to your personal data. We comply with valid requests free of charge and within one month (extendable to three months for complex requests, per Art. 12(3)).
- Art. 15 — Right of access. You can ask us to confirm whether we hold data about you, and to send you a copy of it.
- Art. 16 — Right to rectification. You can ask us to correct inaccurate or incomplete data. Most fields are also editable directly in the app.
- Art. 17 — Right to erasure ("right to be forgotten"). You can ask us to delete your account and the personal data associated with it — either inside the app (Settings → Delete account) or by email. Note that recipes you contributed to a shared household belong to the household; deleting your account removes your authorship link but leaves the recipes for the other household members. If you want the household and its contents fully erased, ask for that explicitly.
- Art. 18 — Right to restriction of processing. You can ask us to stop processing your data (other than storage) under certain conditions.
- Art. 20 — Right to data portability. You can ask us to export your data in a machine-readable format. We currently provide a JSON export of your recipes, plans, and lists on request; an in-app export button is on the roadmap.
- Art. 21 — Right to object. You can object to processing based on legitimate interest (Art. 6(1)(f)). For us, that means the server access logs and error logs — if you object, we will excise your identifiers from those logs going forward (we cannot rewrite historical logs without compromising their integrity).
- Art. 7(3) — Right to withdraw consent. For data we process on the basis of your consent (profile fields, optional photos), you can withdraw consent at any time. Withdrawal does not affect processing that already happened lawfully.
- Art. 77 — Right to lodge a complaint with a supervisory authority. The authority competent for us is Der Hessische Beauftragte für Datenschutz und Informationsfreiheit, Postfach 3163, 65021 Wiesbaden (Gustav-Stresemann-Ring 1, 65189 Wiesbaden). You can also complain to the authority of your own habitual residence.
To exercise any of these rights, email cook@withstaple.com and describe what you want. We may ask you to confirm the request from the email address tied to your Staple account, so we can be sure we are not handing your data to someone impersonating you.
8. Security
We take reasonable technical and organizational measures to protect your data, including:
- Encryption in transit. All traffic between your device and Staple is TLS 1.3.
- Encryption at rest. Database and storage are encrypted at rest by our infrastructure provider.
- Row-Level Security. Postgres Row-Level Security policies enforce, at the database level, that one household's data is never readable by another household. RLS is applied to every household-scoped table.
- No password to leak. Staple uses passwordless authentication (magic link + 6-digit code). There is no password database to breach, and you do not have a password to reuse from another compromised service.
- Scoped access tokens. Administrative access to the database is limited, logged, and used only for incident response and migrations.
- Backups. Encrypted backups are kept for up to 30 days by our infrastructure provider.
No system is perfectly secure. If we become aware of a personal-data breach that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours per Art. 33 GDPR, and notify you directly if the risk is high (Art. 34).
9. Children
Staple is not directed at children. In Germany, the age of digital consent under Art. 8 GDPR is 16, and our Terms of Service require account holders to be at least 16 years old. If we become aware that an under-16 has created an account without verifiable parental consent, we will close that account.
Children under 16 are very welcome to help cook, plan, and write in a household their parents created — they just cannot be the named account holder.
10. Changes to this policy
We may update this policy from time to time, for example when we add a new subprocessor, change the retention period of a data category, or in response to a change in the law.
- Material changes — the kind that affect what you agree to, what we collect, who sees it, or how long we keep it — will be announced by email to your registered account address at least 30 days before they take effect. You will have the option to delete your account before the change, if you do not wish to accept it.
- Non-material changes — typo fixes, clarifications, new examples — are made silently and reflected in the "Last updated" date at the top.
A version history of material changes is maintained at the bottom of this page.
Version history
- July 2026. Initial published version.
- August 2026. Added Google Gemini API as subprocessor (recipe import, AI-generated recipe photos).