Privacy Policy
Last Updated: July 11, 2025
Thank you for using Chef Kong! This Privacy Policy explains how we collect, use, disclose, and protect your personal information when you use the Chef Kong meal planning app (the “App”). We are committed to safeguarding your privacy and ensuring that your personal data is protected. By using Chef Kong, you agree to the collection and use of information in accordance with this Privacy Policy.
1. Who We Are
Chef Kong is provided by an individual developer based in Germany (referred to in this policy as “we”, “us”, or “our”). For the purpose of data protection laws (such as the EU General Data Protection Regulation or “GDPR”), we are the “data controller” of your personal information collected through the App. You can find our contact details at the end of this Policy.
2. Information We Collect
We only collect data that is necessary to provide and improve the Chef Kong service. This includes:
- Account Information: When you create an account or sign in to Chef Kong, we collect information such as your name and email address. For example, if you use Sign in with Apple, Apple may provide us with your name and either your email address (or a private relay email address you’ve allowed Apple to share). We do not receive or collect your Apple ID password or any of your personal credentials from Apple.
- Profile and Health Data: You have the option to provide certain personal details to enhance your meal planning experience. This may include **basic health and diet information** such as your dietary preferences or restrictions (e.g., vegetarian, vegan, allergies), general fitness or health goals, age, weight, or other metrics you choose to input. **Sensitive Data:** If you provide health-related information, we treat it with special care and will only use it to personalize your meal plans and recommendations within the App.
- Usage Data: We collect information about how you use the App. This can include your interactions with the App’s features (for example, the recipes you view or save, meal plans you generate), log data about your sessions (such as timestamps of logins, and duration of app use), and device information. Device information may include your device model, operating system version, and unique device identifiers. We collect this data to understand usage patterns and improve our services.
- Communications: If you contact us for support or with feedback, we will collect the information you choose to give us (such as your email address, and the content of your communications). Additionally, if you opt-in to receive newsletters or marketing messages (if we offer them), we will collect your name and email for that purpose. You can unsubscribe from marketing emails at any time.
- Payment and Subscription Data: Chef Kong itself does not collect or store your payment card details. If you make a purchase or subscribe to a service within the App, the transaction is processed by the Apple App Store (or Google Play Store, etc.). We may receive limited information about these transactions from the app store – for example, confirmation that you purchased a subscription and the duration of that subscription – but we do **not** receive your credit card number or other financial details. All such sensitive payment information is handled by the platform provider (Apple/Google) according to their privacy policies.
3. How We Use Your Information
We use your personal information for the following purposes:
- To Provide the Service: We process your data to operate the Chef Kong App and provide you with its core features. For example, we use your profile and health information to generate personalized meal plans and recipe recommendations. Your email and name (if provided) help create and manage your user account (and to address you within the app, e.g., “Welcome, [Name]”).
- To Improve and Customize the App: Usage data and feedback help us understand what features are useful to you and how we can make Chef Kong better. We may analyze usage patterns to troubleshoot issues, enhance user experience, and develop new features. For instance, if many users indicate a preference for certain types of recipes, we might focus on adding more of those.
- To Communicate with You: We may use your contact information to send important **administrative or service-related communications**. This includes messages about account management (e.g., password resets, login alerts), changes to this Privacy Policy or the Terms of Service, or other critical notices. If you have explicitly opted in to receive promotional communications or a newsletter, we will use your email to send you updates such as recipe tips, new features, or special offers. You can opt out of marketing emails at any time by clicking the “unsubscribe” link in those emails or contacting us.
- Health and Safety: If you provide health-related data, we use it solely to tailor the App experience for you (for example, suggesting meals that fit your dietary needs). We will not use sensitive health information for any other purpose (such as marketing) without your explicit consent. We do not use your health data to make automated decisions beyond providing the promised service (no automated medical decisions).
- Legal Compliance and Enforcement: In certain cases, we may need to process your data to comply with a legal obligation, or to protect our rights and the rights of other users. For example, we may use or disclose information if required by law, or if necessary to enforce our Terms of Service, to prevent fraud, or to ensure safety of our users.
4. Legal Bases for Processing (for Users in the EU/EEA)
We process personal data on the following legal grounds, as allowed by the General Data Protection Regulation (GDPR) and related laws:
- Contract (Art. 6(1)(b) GDPR): Most of our data processing is to provide you with the Chef Kong service that you requested. For example, when we use your information to create meal plans or manage your account, we do so to fulfill our contract with you (the Terms of Service).
- Consent (Art. 6(1)(a) GDPR): For certain types of data and processing, we rely on your consent. In particular, any **health or dietary information** you provide is considered sensitive data – we will only process it with your explicit consent. Also, if we send you marketing emails, it’s based on your consent. You have the right to withdraw your consent at any time (for example, you can remove or update your health info in the app, or unsubscribe from marketing emails), which will stop that particular processing going forward.
- Legitimate Interests (Art. 6(1)(f) GDPR): We may process your data for our legitimate interests, such as improving the App’s functionality, securing the App, and understanding how users interact with our service. When we rely on this basis, we make sure that our legitimate interests are not overridden by your rights and interests. For instance, analyzing anonymized usage data to improve features falls under this basis.
- Legal Obligation (Art. 6(1)(c) GDPR): If we are required by law to retain or disclose certain information (for example, if a court or regulator lawfully requires it), we will do so in compliance with our legal obligations.
5. How We Share Your Information
We value your privacy. That means we do not sell your personal information to third parties for marketing or any other purposes. We only share your information in a few limited scenarios:
- Service Providers: We use trusted third-party service providers to help us operate and improve Chef Kong. For example, we use Supabase (a cloud database and hosting service) to store and manage your app data securely. Similarly, we might use analytics tools or error tracking services to understand app performance. These providers process data on our behalf **only for the purposes we specify** and in compliance with this Privacy Policy. We ensure that any service providers we use are bound by confidentiality and strong data protection obligations (including, where applicable, data processing agreements under GDPR).
- Platform Services (Apple/Google): When you use Sign in with Apple or make a purchase through the App Store, those actions are also covered by Apple’s privacy policy. For example, Apple will know that you are using Chef Kong for login or payment. This is information you provide to Apple directly, and their use of it is governed by their own policies. We do not share additional personal data with Apple beyond what is necessary for these integrations (and similarly for any other platform services the app might use).
- Legal Requirements: We may disclose your information if we are compelled to do so by law or a valid legal process (such as a subpoena or court order). We may also disclose data if necessary to investigate or remedy suspected fraud, security issues, or violations of our Terms of Service, or to protect the rights, property, and safety of our users or others. This type of disclosure will be made only in compliance with applicable laws.
- Business Transfers: As of now, Chef Kong is operated by an individual, and there are no affiliates or parent companies. If in the future we (hypothetically) form a company, merge with another organization, or transfer assets related to Chef Kong, your information may be transferred as part of that transaction. If such a change in ownership happens, we will ensure the protection of your personal data by requiring the new owner to continue to honor this Privacy Policy or provide you notice and obtain consent if required by law.
6. Data Storage and Security
Data Storage Location: Your data is stored securely on our cloud database, which is currently provided by Supabase. We strive to use server infrastructure located in jurisdictions with strong data protection standards. (If you are in the EU, we aim to store data on servers within the European Union or EEA when possible. However, depending on technical considerations, your data might be stored or backed up on servers in other countries.)
Security Measures: We take the security of your personal information seriously. We implement industry-standard technical and organizational measures to protect your data from unauthorized access, alteration, disclosure, or destruction. These measures include encryption of data in transit (the communication between the app and our servers is protected via HTTPS/TLS encryption) and at rest (our database encrypts stored data); secure authentication processes for accessing data; and regular updates and security assessments of our systems. We also limit access to personal data to only those persons and partners who need it to operate or improve the App (for example, our service providers), and they are subject to strict confidentiality obligations.
Despite our best efforts, please note that no system can be 100% secure. The internet is not completely risk-free, so we cannot guarantee absolute security of information. It is important that you also take precautions: use unique and strong passwords for your accounts, and keep your device secure. If we ever experience a data breach that affects your personal data, we will notify you and the appropriate authorities as required by law.
7. Data Retention
We keep your personal information only for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law. This means:
- Active Account: As long as you have an active Chef Kong account, we will retain the information associated with your account. This allows us to provide you with the service (e.g., maintain your meal history, preferences, etc.).
- Account Deletion: If you choose to delete your Chef Kong account or request deletion of your data, we will delete or anonymize your personal information, except for information we are legally required to keep (for example, certain transaction records or logs that must be retained for legal compliance, fraud prevention or security purposes). We will carry out deletion/anonymization promptly after your request, and in any case within the timeframe required by applicable law.
- Inactive Accounts: If you stop using the App without formally deleting your account, we may eventually purge personal data from inactive accounts after a prolonged period of time. Before we do so, we may try to reach out to the email on file to notify you, so you have a chance to keep the account active if you wish.
- Usage Data: In some cases, we may retain aggregated or de-identified usage data (data that no longer identifies you personally) for analytics purposes, even after personal data is deleted. This data helps us understand usage trends and improve our services, but it cannot be traced back to an individual once anonymized.
8. Your Rights
If you are in the European Union, United Kingdom, or certain other jurisdictions, you have specific rights regarding your personal data. We are committed to upholding these rights. They include:
- Right to Access: You have the right to request a copy of the personal data we hold about you, and to obtain information about how we process it. We will provide this information, subject to some exceptions (for example, we might not be able to provide certain data if it involves another individual’s personal information or if it’s legally privileged).
- Right to Rectification: If any of your information is inaccurate or incomplete, you have the right to ask us to correct or update it. You can also correct most basic account information through the App settings/profile section.
- Right to Erasure: You have the right to request deletion of your personal data (“right to be forgotten”). This is not absolute, but we will honor it to the extent required by law. For example, if you withdraw consent or if your data is no longer needed for the purposes we collected it, you can request that we erase it. Note that we might retain certain minimal information if necessary (e.g., to prove that we’ve complied with your request or as required for legal obligations).
- Right to Restrict Processing: You can ask us to limit the processing of your data in certain circumstances – for instance, if you contest the accuracy of your data, we may restrict processing during the period we are verifying the accuracy.
- Right to Data Portability: You have the right to obtain your personal data that you provided to us, in a structured, commonly used, and machine-readable format, and to transfer it to another service provider where technically feasible. (This typically applies to data processed based on your consent or a contract, and which is processed by automated means.) If you need an export of your data, please contact us and we will assist you.
- Right to Object: In certain situations, you have the right to object to the processing of your data. For example, if we are processing your data based on legitimate interests, you can object if you have grounds related to your particular situation. You also have an unconditional right to object to your personal data being used for direct marketing purposes. If you opt-out of marketing, we will cease using your data for that purpose.
- Right to Withdraw Consent: If we are processing any of your personal data based on your consent (for instance, health information or receiving promotional emails), you have the right to withdraw your consent at any time. This will not affect the lawfulness of processing before the withdrawal. For example, you can simply stop providing certain optional data, or adjust your settings to revoke consent for data collection (where applicable), and we will honor that choice.
- Right not to be Subject to Automated Decisions: Chef Kong does not make any legally significant decisions about you purely by algorithms without human involvement. However, if that ever changes, you would have rights to certain protections, such as the ability to obtain human intervention or to contest decisions.
Exercising Your Rights: You can exercise these rights by contacting us via email (see the “Contact Us” section below). For security, we may need to verify your identity before fulfilling certain requests (for example, by asking you to confirm details associated with your account). We will respond to your requests within the timeframe required by law (generally within 30 days for GDPR, with possible extensions in certain cases), and we will let you know if we need additional information from you.
Complaints: If you believe your data has been handled improperly or your rights have not been respected, you have the right to lodge a complaint with your local data protection supervisory authority. If you’re in Germany, for example, you can contact the data protection authority (DPA) in your state (Bundesland) or the lead DPA for our company’s location. A list of DPAs in Germany and their contact information is available online. If you’re in another country, you can reach out to the regulator in your jurisdiction. Of course, we would appreciate the chance to address your concerns directly first, so we encourage you to contact us with any issues and we will do our best to resolve them.
9. International Data Transfers
Chef Kong is available to users around the world. The data we collect from you will typically be stored in your home region (for example, users in Europe will have their data stored in Europe whenever possible). However, it’s possible that your information may be transferred to and processed in countries other than your own, including the United States or other countries that may not have the same level of data protection as your home country.
Regardless of where your data is processed, we take measures to protect it in accordance with this Privacy Policy and applicable law. If we transfer personal data from the European Economic Area (EEA) or UK to a country that the European Commission (or relevant authority) has not deemed to have “adequate” data protection, we rely on appropriate safeguards, such as Standard Contractual Clauses (SCCs) or your consent, to ensure your rights and protections travel with your data. For example, our contract with Supabase and any other service providers will include commitments to uphold EU privacy standards for data of EU users. You can contact us if you’d like more information about cross-border data transfer safeguards in place.
10. Cookies and Tracking Technologies
In-App Data Storage: The Chef Kong mobile app may use local storage or similar technologies on your device to remember your preferences and settings (for example, to keep you logged in or save certain user settings). This is analogous to how websites use cookies, but in a mobile app context. We do not use third-party advertising cookies or tracking beacons in the mobile app.
Analytics: We may use built-in analytics or third-party analytics services that collect **anonymous** information about how users interact with the App. This information can include screens viewed, buttons clicked, and other usage statistics. These analytics help us improve the design and content of Chef Kong. Any third-party analytics providers will be listed in this policy or in the App’s settings if used. For example, if we use an analytics service that uses device identifiers or similar technology, we will update this section to inform you. You typically have the option to opt-out of analytics tracking in the App settings or by not consenting if prompted.
If we ever expand to a web-based service, we will update our policy to detail any cookie usage on the website (such as for analytics or necessary site functionality). At present, Chef Kong’s primary platform is a mobile application.
11. Children’s Privacy
As noted in our Terms, Chef Kong is not directed to children and we do not knowingly collect personal data from anyone under the age of 16. If you are under 16, please do not use the App or submit any personal information. In the event we learn that we have inadvertently collected information from a child under 16, we will take prompt steps to delete that information from our records (unless we are legally obligated to retain it). If you are a parent or guardian and you believe your child (under 16) has provided us with personal information without your consent, please contact us immediately so that we can take appropriate action.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. When we update the policy, we will revise the “Last Updated” date at the top. If changes are significant, we may also provide a more prominent notice (such as an in-app alert or an email notification). We encourage you to review this Privacy Policy periodically to stay informed about how we are protecting your information.
Your continued use of Chef Kong after any changes to this Privacy Policy will signify your acceptance of the updated terms, as long as we have notified you of the changes in a reasonable manner. If you do not agree with any updates to the policy, you should discontinue use of the App.
13. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or your personal data, please reach out to us. We are here to help and will respond as promptly as we can.
Contact Email: [Your Contact Email]
When contacting us about a privacy issue, please include sufficient detail so that we can effectively understand and address your concerns. For example, the email associated with your Chef Kong account and the specific issue you’re reaching out about will help us assist you better.
Thank you for trusting Chef Kong with your meal planning needs. Your privacy and satisfaction are extremely important to us.