Cooked.

Privacy Policy

Cooked — Last updated: June 6, 2026

This Privacy Policy explains how Noware (“we”, “us”, or “our”) collects, uses, and protects information when you use Cooked (“the Service”) at get-cooked.io. By using the Service you agree to the practices described here.

1. Information We Collect

We collect the following categories of information:

  • Account information— your email address and display name, provided when you register or sign in via a third-party provider (Google, Apple, Microsoft, or Facebook).
  • Credentials— if you sign up with email and password, we store a one-way bcrypt hash of your password. We never store your password in plain text.
  • User content— recipes, meal plans, and cookbooks (including any PDF or document files and cover images) that you create or upload to the Service.
  • Invite data— if you joined via an invite code, we record that the code was used and associate it with your email address.
  • Session data— authentication session tokens stored in secure, HTTP-only cookies to keep you signed in.
  • Local storage— a small entry in your browser’s local storage (key: cooked:now-cooking) to remember your active cooking session. This data never leaves your device.

We do not use analytics services, advertising networks, or tracking pixels. We do not collect IP addresses beyond what is incidentally captured in server logs.

2. How We Use Your Information

We use your information solely to provide and improve the Service:

  • To authenticate you and secure your account.
  • To store and display your recipes, meal plans, and cookbooks.
  • To send transactional emails (e.g. password reset) if you request them.
  • To investigate abuse or enforce our Terms of Service.

We do not sell, rent, or share your personal data with third parties for marketing purposes.

3. Third-Party Sign-In Providers

If you choose to sign in with Google, Apple, Microsoft, or Facebook, those providers may collect information about you according to their own privacy policies. We only receive your email address and display name from these providers; we do not receive your password or payment information held by them.

4. Data Retention

We retain your account and content for as long as your account is active. If you request deletion of your account, we will remove your personal data and content within 30 days, except where retention is required by law.

5. Data Security

Your data is stored in a PostgreSQL database. Access is restricted to authorised personnel and systems. Passwords are hashed using bcrypt. Session tokens are stored in secure, HTTP-only cookies. While we take reasonable precautions, no method of transmission or storage is completely secure and we cannot guarantee absolute security.

6. Your Rights

Depending on your location you may have rights regarding your personal data, including the right to access, correct, or delete the information we hold about you. To exercise any of these rights, please contact us at support@get-cooked.io.

7. Children’s Privacy

The Service is not directed at children under 13. We do not knowingly collect personal data from children under 13. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.

8. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the revised Policy on this page and updating the “Last updated” date above. Continued use of the Service after changes take effect constitutes your acceptance of the revised Policy.

9. Contact

If you have questions or concerns about this Privacy Policy, please contact us at:
Noware
support@get-cooked.io
https://get-cooked.io