Privacy Policy
This Privacy Policy explains how Bo Kyung Kim, an individual operating Crésipe (“Crésipe,” “we,” “us,” or “our”), handles information when you use the Crésipe mobile app, this website, and related services (the “Services”). Crésipe is designed for food, cooking, nutrition tracking, and general wellness.
1. Information Crésipe collects
Account and profile information
- Account credentials: after the local 13+ birthday check succeeds, your email address, password, and validated date of birth are submitted to Supabase Auth to create and secure your account. The date of birth is carried as private account metadata through email confirmation and is later saved in your private wellness profile during onboarding. Crésipe does not store a readable copy of your password. Supabase manages password verification, email-confirmation codes, password-reset links, authentication records, and session tokens. The app stores your session token on your device so you can remain signed in.
- Basic profile: your display name, an internal user identifier, account-creation and onboarding timestamps, and profile settings such as units, notification preference, and a default profile colour. A legacy theme value may remain in older profile records but is ignored; the current app follows the phone’s appearance setting. Your profile is restricted to your signed-in account, and Crésipe does not currently provide public profiles or friend search.
Nutrition, food, cooking, and wellness information
- Body and profile information: date of birth, sex selection, height, current and starting weight, optional weight goal and timeframe, and the date your wellness journey starts.
- Targets and goals: calorie, protein, carbohydrate, fat, fibre, step, and sleep targets; selected food and wellness goals; and validated custom wellness goals. Custom goals are limited to general food and wellness topics.
- Dietary preferences: diet selection, preferred cuisines, spice preference, and food allergies entered for recipe filtering.
- Food and meal records: meal date and meal category, food name, serving amount, source of the log, calories, protein, carbohydrates, fat, available micronutrients, and whether a cooked meal is awaiting confirmation.
- Cooking records: pantry items and details, confirmed fridge or pantry ingredients, custom and AI-generated recipes, saved recipes, cooking sessions and elapsed time, and country or region progress in the recipe Atlas.
- Progress information: scan and AI-usage counters, streaks, badges, equipped badges, ranks, Acorn awards, and transaction identifiers used to prevent duplicate logging or rewards.
- Food searches and barcodes: search terms and scanned food barcodes. These are sent directly from the app to Open Food Facts for lookup. A search or barcode becomes part of your Crésipe meal history only if you choose to log the resulting food.
- Free-text food information: recipe requests and meal-photo correction notes that you choose to submit. Crésipe screens and rejects known medical context before using these fields for AI personalization.
Photos and camera information
If you choose a camera or photo-library feature, Crésipe processes the image you select for meal analysis, fridge or pantry scanning, or a cooked-meal record. Before upload, the app converts and compresses the selected image to JPEG. Uploaded images are stored in a private, user-scoped Supabase Storage bucket. The app stores the private storage path with the associated meal or scan record and creates a time-limited viewing link when needed. Crésipe does not upload your entire photo library.
Apple Health and Android Health Connect
With your device permission, Crésipe reads step totals and sleep sessions for the most recent seven days from Apple Health on iOS or Health Connect on Android. The current app uses those readings to show activity and sleep information while the app is running. It requests read access only, does not write to either health service, and does not upload the step or sleep records it reads to Supabase, OpenAI, or another Crésipe server. Your step and sleep goals, which you enter or adjust in Crésipe, are stored in Supabase. You can revoke health permissions in Apple Health, Health Connect, or your device settings.
Technical and support information
Supabase and other infrastructure providers may process technical information needed to deliver and protect the Services, such as IP address, request time, device or browser type, authentication and request logs, error details, and security or abuse signals. Crésipe currently schedules its two daily reminders locally on your device and does not register an Expo push token for remote marketing notifications.
If you contact us through Instagram or another support channel we publish, we receive the message, your contact details, and any information you choose to include. Do not send passwords, confirmation codes, API keys, diagnoses, medications, lab results, or other information that is not needed to answer your request.
2. Information Crésipe does not intentionally request
Crésipe does not intentionally request or use medical diagnoses, symptoms, medications, laboratory results, treatment information, pregnancy information, or medical conditions for personalization. Medical terms entered in custom goals, recipe notes, or meal-correction notes are rejected where detected. Food-allergy information is collected separately as a food-safety preference and is used to filter recipe suggestions.
The production app does not currently include an advertising SDK or a third-party product-analytics SDK. We do not sell personal information or share it for cross-context behavioural advertising. We do not use Apple Health or Health Connect information for advertising.
Crésipe is currently provided without subscriptions, paid downloads, advertising, or in-app purchases.
3. How we use information
We use information to:
- create, verify, secure, and recover accounts;
- provide food lookup, meal logging, nutrition totals, pantry, recipe, cooking, progress, badge, rank, streak, and Atlas features;
- calculate and display general-wellness nutrition targets and progress;
- personalize recipes using the food and wellness choices described below;
- analyze food photos and identify visible fridge or pantry ingredients;
- apply allergy filters, medical-scope checks, content moderation, usage limits, fraud prevention, and duplicate-action protection;
- send transactional account emails and schedule device reminders you enable;
- respond to support and privacy requests; and
- operate, troubleshoot, protect, and improve the reliability of the Services.
Where applicable law requires a legal basis, these activities are carried out as needed to provide the Services you request, with your consent for optional device permissions, for our legitimate interests in security and service operation, and to comply with legal obligations. You can withdraw optional device permission at any time, although the related feature may stop working.
4. What is sent to OpenAI
Crésipe calls the OpenAI Responses API only through server-side Edge Functions. The OpenAI API key is not included in the mobile app.
- Fridge or pantry scanning: the selected image, whether it is a fridge or pantry scan, a food-identification prompt, and a one-way hash of your Crésipe user identifier used as an OpenAI safety identifier.
- Meal-photo nutrition: the selected meal image, an optional food or portion correction note, a nutrition-estimation prompt, and the hashed safety identifier.
- Recipe generation: confirmed or requested ingredients, pantry item names, cuisines, spice preference, food allergies, validated general-wellness goals, calorie target, an optional food-related recipe note, and the hashed safety identifier.
The current implementation does not send your email address, display name, password, raw date of birth, sex selection, height, weight, weight goal, or Apple Health or Health Connect records to OpenAI.
Requests use strict structured output, input/output moderation, and store: false, so Crésipe does not ask OpenAI to retain the response as Responses API application state. Under OpenAI’s standard API data controls, API data is not used to train OpenAI models unless the API customer opts in. OpenAI may retain prompts, responses, images, and related metadata in abuse-monitoring logs for up to 30 days, unless different approved retention controls apply or longer retention is required for legal or safety reasons. Images may also be screened for child-safety abuse detection under OpenAI’s policies.
5. Service providers and other recipients
We disclose information only as needed to provide, secure, support, or legally operate the Services:
- Supabase: authentication, database hosting, private image storage, and Edge Functions. The production project is hosted in Supabase’s United States West region.
- OpenAI: the AI and moderation processing described in Section 4.
- Resend: SMTP delivery of email-confirmation codes, password-reset messages, and related delivery metadata. Resend receives the recipient email address and transactional message content.
- Open Food Facts: public food and barcode lookups. Because these requests are made directly from the app, Open Food Facts receives the search term or barcode, the Crésipe app User-Agent, and ordinary network information such as IP address. It does not receive your Crésipe email or user identifier from the lookup code.
- Apple and Google: app distribution and the device-controlled Apple Health or Health Connect permissions you choose to grant. The Crésipe implementation does not send your Crésipe food logs to Apple Health or Health Connect.
- Cloudflare and Google Fonts: domain and website infrastructure. The website loads font files from Google Fonts, so a website visitor’s browser makes requests that can include IP address, browser information, referring page, and request time. Cloudflare may process similar network information when serving or protecting the domain or website.
- Meta/Instagram: only when you choose to contact the @cresipe_app Instagram account.
We may also disclose information when required by law; to protect users, the public, our rights, or the Services; with your direction or consent; or as part of a merger, financing, reorganization, or transfer of the service, subject to applicable legal requirements.
6. Storage and retention
- Account and app records: Supabase stores account, profile, wellness, preference, meal, pantry, recipe, progress, quota, and related operational records while your account remains active or as otherwise needed to provide and secure the Services.
- Photos: successful meal and scan uploads may remain in private storage while your account is active. Removing an individual meal or scan record may not immediately remove every associated image. Failed or abandoned uploads are removed in several failure and cancellation paths, but an interrupted cleanup may leave an upload until account deletion or later maintenance.
- OpenAI: the API retention described in Section 4 applies.
- Email, support, website, and security records: providers may retain delivery, support, request, backup, and security records according to their own retention schedules and as required by law. The repository does not establish one fixed period for every provider record.
In-app account deletion first attempts to remove all images stored under your user folder and then deletes your Supabase Auth user. Database relationships are configured to delete the user-owned profile, wellness, preference, meal, pantry, private recipe, progress, and quota records tied to that account. If image cleanup fails, the account-deletion function reports an error instead of intentionally leaving an inaccessible image behind.
Deletion removes information from active Crésipe systems, but limited copies may remain temporarily in provider backups, abuse-prevention records, security logs, or records retained to meet legal obligations. We cannot promise immediate deletion from every provider backup or log.
7. Your choices and privacy rights
- Edit your display name, wellness data and goals, food preferences, pantry, recipes, and meal information in the app where controls are available.
- Turn Crésipe reminders off in the app or device settings.
- Revoke camera, photo-library, Apple Health, or Health Connect access in device settings.
- Delete your account in Profile → Privacy & Terms → Delete my account, or use our web deletion-request page if you cannot access the app.
- Email support@cresipe.app to request access, correction, deletion, or a portable copy of information associated with your account.
Depending on where you live, you may also have rights to object to or restrict certain processing, withdraw consent, or complain to a privacy regulator. We may need to verify your identity and account ownership before acting on a request. Some rights are subject to legal exceptions.
8. Teen users and children
Crésipe is intended for people aged 13 and older. The current Create Account screen validates the complete date of birth on the device before calling Supabase Auth. A future date, invalid date, or age under 13 is rejected, and the normal signup flow does not send that person’s email, password, or birthday to Supabase. A legacy fallback remains for unfinished accounts created by older app versions before the pre-signup check existed.
If you are under the age of majority where you live, use Crésipe only with permission from a parent or legal guardian. A parent or guardian who believes a child under 13 created or retained an account should contact us so it can be investigated and deleted.
9. Security and international processing
Crésipe uses measures including encrypted network connections, password handling through Supabase Auth, persisted device sessions, user-scoped database rules, private image storage, expiring signed image links, server-held secret keys, authenticated Edge Functions, input limits, and usage quotas. No online service or storage system is completely secure, and we cannot guarantee that a security incident will never occur.
Crésipe and its providers may process information outside your province, state, or country, including in the United States. Privacy laws in those locations may differ, and information may be available to courts, law enforcement, or regulators under applicable law.
10. Changes to this policy
We may update this Privacy Policy as the Services or legal requirements change. We will update the date above and provide additional notice or request consent when required by law. Material additions such as analytics, advertising, remote push notifications, social sharing, new payment methods, or new uses of health information require this policy to be reviewed again before release.
11. Contact
Crésipe Privacy Officer
Ontario, Canada
Email: support@cresipe.app
Mailing contact information for the person responsible for Crésipe’s privacy practices is available upon request at support@cresipe.app.