Privacy Policy
Last updated: August 12, 2026
Clemi ("we", "our", or "the app") is a recipe companion that helps you save, organize, and share recipes and grocery lists. This Privacy Policy explains what data we collect, how we use it, and your rights.
1. Data We Collect
Account
You can use Clemi without giving us any personal information. By default your account is anonymous: it is identified by a randomly generated ID, with no name or email attached.
If you choose to sign in with Apple or Google — to back up your recipes and use them on another device — that provider shares the following with us, and we store it:
- Your email address. If you use Apple's "Hide My Email", we only ever receive the private relay address, never your real one.
- Your name, as set on your Apple or Google account.
- Your profile picture (Google only, stored as a link). Apple does not share one.
- A provider account identifier and the sign-in tokens needed to keep you signed in.
We never receive or store a password — sign-in is handled entirely by Apple or Google. Signing in upgrades the anonymous account you already have, so the recipes you saved before stay with you.
Content You Create
Recipes, collections, grocery lists, meal plans, and profile preferences (display name, measurement system, dietary preferences) you add to the app are stored on our servers to sync across your devices.
Photos you upload (e.g. cookbook scans) and messages you send to the AI recipe assistant are also stored.
Automatically Collected
- Usage analytics — screen views and feature interactions, linked to your account ID. Your name and email are never sent to our analytics provider, and session replay is disabled.
- Crash reports — error logs, device type, OS and app version, linked to your account ID so we can trace a specific report. Your name and email are not included.
- Sessions and server logs — when you sign in we record the IP address and device identifier (user agent) of that session. Our server logs keep the requested endpoint, account ID, app version and platform for security and debugging.
- Push tokens — stored if you enable notifications.
- Purchase data — subscription status and transaction confirmations via a third-party service. We never see your payment details.
Data We Do Not Collect
Passwords, payment details, precise location, contacts, browsing history, or advertising identifiers. We do not sell your data or use it for advertising.
2. How We Use Your Data
- Provide the service — store and sync your content across devices.
- Sign-in — identify you, keep you signed in, restore your recipes on a new device, and protect your account. We use your email to recognise you when you sign back in, not to market to you.
- AI features — process recipes, images, and video URLs through AI services for extraction, substitutions, and image generation.
- Sharing — enable real-time sync with your Home members.
- Improve the app — use analytics and crash reports to fix bugs and prioritize improvements.
- Purchases — manage subscriptions and credit balances.
3. Third-Party Services
We use third-party services to provide functionality. Each receives only the minimum data needed. We do not sell or share your data for advertising.
- Apple and Google — identity providers, only if you choose to sign in. They tell us who you are; we send them nothing about how you use Clemi.
- AI provider — recipe content and images for extraction and generation.
- Payment processor — your account ID and purchase receipts. Your email and name are not sent.
- Analytics — usage data tied to your account ID, with no name, email, or session replay.
- Error tracking — crash reports and performance data tied to your account ID, with no name or email.
- Cloud infrastructure — database and file storage, encrypted at rest and in transit.
4. Data Sharing
We do not sell, rent, or trade your data. It is only shared when:
- Home sharing — members of your Home can see shared grocery lists, recipes, and your display name. They cannot see your email address. Joining requires an explicit action (sharing a temporary code).
- Third-party processing — as described in Section 3.
- Legal requirements — if required by law.
5. Security
All data is encrypted at rest and in transit. We store no passwords, so there is none to leak. Authentication tokens are stored in your device's secure storage (iOS Keychain / Android Keystore), and the sign-in tokens we hold from Apple and Google are kept in our database encrypted at rest. Access controls ensure you can only access your own data and shared resources you've been invited to.
6. Data Retention and Deletion
Your data is retained as long as your account exists. You can delete individual items at any time. Deleting your account permanently removes all associated data (recipes, grocery lists, collections, profile, and credits) along with your sign-in details: the email, name, and profile picture we received from Apple or Google, your active sessions, and the stored provider tokens. This is irreversible.
Two things account deletion does not cover. If you used Clemi anonymously and then signed in to a different Clemi account that already existed, the earlier anonymous account is left in place rather than merged or deleted — email us and we will remove it. And records held by our analytics, error tracking, and payment providers follow their own retention periods.
You can also revoke Clemi's access from your Apple ID or Google account settings. That stops future sign-ins but does not delete your Clemi data — use account deletion in the app for that.
7. Your Rights
You can access, modify, and delete your data at any time through the app, and sign out or delete your account from Settings. You can revoke sharing by leaving a Home. For anything you cannot do in the app — including a copy of the account details we hold — email us and we will handle it. If you are in the EEA or UK, you also have the right to data portability and to lodge a complaint with your local data protection authority.
8. Children's Privacy
Clemi is not directed at children under 13. We do not knowingly collect data from children. Contact us if you believe a child has provided data.
9. Changes to This Policy
We may update this policy from time to time. The "Last updated" date at the top reflects the most recent revision.
10. Language
This policy is published in several languages. If a translation differs from the English version, the English version applies.
11. Contact Us
Questions? Reach us at [email protected]