How we handle your data
Personal data notice — PREP · last updated 7 October 2026
Leggi in italiano · Leer en español · Lire en français · Terms of use · Contact
PREP is a cooking app. This page explains, plainly, which data we collect when you use the app, when you subscribe to the newsletter or leave your email to hear when the app is out, when you visit the website and when you join the leaderboard, why, and what you can ask for at any time.
Who processes your data
The data controller is Francesco Palumbo, an individual, in Italy.
For any request — to know which data we hold, to correct it, to delete it — you can write to preprecipe@gmail.com. You can also download them yourself, whenever you like: in the app, Profile → Settings → Download your data. Your phone prepares the file, and you choose where to save it. If you need the controller’s postal address, ask at the same address and we will give it to you.
Which data we collect
If you subscribe to the newsletter
| Data | Why |
|---|---|
| Email address | It’s the only way to send you the newsletter |
| Consent to the newsletter | To prove it was you who asked for it |
| Consent to sponsors’ messages | Separate from the first: you can say yes to one and no to the other |
| Date and time of subscription | Proof of when you gave consent |
If you leave your email to hear when the app is out
On the website you can leave your address to receive one email, only one, when the app is out. It doesn’t subscribe you to the newsletter and it doesn’t send you anything else.
| Data | Why |
|---|---|
| Email address | It’s the only way to write to you when the app is out |
| Your consent, which you confirm with one click in the message we send you | To prove it was you who asked: until you confirm, you are not on the list |
| Date and time of the confirmation | Proof of when you gave consent |
| The page of the website you signed up from | To understand which pages are useful |
If you visit the website
We count visits with a service (Vercel Web Analytics) that uses no cookies and stores nothing on your device. The privacy, terms and contact pages are not counted.
| Data | Why |
|---|---|
| The page you open | To understand which pages are useful |
| The site you come from, for example a search | To understand how you find us |
| Country, region and city | To understand where and in which languages the site is needed |
| The type of device, the system and the browser | To check that the pages work where you open them |
We don’t recognise you from one visit to the next: the visitor is a code calculated from the request, which the service discards after twenty-four hours, and the count doesn’t record your IP address (the service’s technical log, described further down, exists all the same). There is no switch: if you don’t want to be counted, a tracking blocker in your browser stops the count.
How you use the app
| Data | Why |
|---|---|
| Which recipes you open and which cooks you start | To understand what is interesting and what isn’t |
| Whether a cook reaches the end or is abandoned | To understand where the app loses you along the way |
| How long the single steps really take | To correct the timings we state, and to build the analysis tool for restaurants |
| Searches that find nothing | To know which recipes we are missing |
| Whether you open the app by tapping an alert or a notification | To understand whether alerts are useful |
| A random number generated by your phone | To tell two sessions apart without knowing who you are |
What this means in practice: only a random number born on your phone is attached to this data. Not your email address, not your name, nothing that leads back to you. We never cross that number with the newsletter list, and subscribers don’t become recognisable in the usage data. If you uninstall and reinstall the app the number changes, and the link with the past is lost.
Of your searches we send the text only when they find nothing, and only if it contains letters and spaces: if you type an email address, a phone number or anything else in it, the text doesn’t leave and we only keep how many letters you had typed.
We don’t collect your location or your contacts. Your cooking journal, your recipes to try and the photos you take stay on your phone. They reach us only if you join the leaderboard and publish a dish or add a profile photo, or if you cook a recipe together with another profile: explained below.
If you join the leaderboard
Your profile is born when you first open the app: we ask for your first and last name, an email, a username and your year of birth to check that you are at least 16. With a public profile the leaderboard shows your first and last name; with a private profile it shows your username.
| Data | Why |
|---|---|
| Email address, encrypted (AES-256), with a fingerprint used only to find it again | It’s the way back in if you change phones: nobody at our end reads it in the clear in day-to-day work |
| Username | It’s your public name on the leaderboard and on your profile |
| First and last name | They appear on the leaderboard if your profile is public, after a review; with a private profile your username appears |
| Year of birth | Used only to compute your age at sign-up: it is not stored |
| The dish photos you publish, and the minutes of that cook | They are your showcase and they make the cook count on the leaderboard; photos are re-encoded without hidden data (location, phone model, time) |
| Your profile photo, if you add one, or the character you pick instead | It shows on your profile, in the ranking and next to your name or username wherever they appear (postcards, comments, likes, followers, suggestions, invitations to cook together): anyone using the app can see it, even if your profile is private. The photo is cropped to a square and re-encoded without hidden data (location, phone model, time); the character is a PREP drawing, not a picture of you |
| Who you follow and who follows you, and whether your profile is private | That is your network: the counts are public, the lists are yours; with a private profile only people you approve see your postcards |
| The selfie of who cooked, if you choose to take it at the end of a cook | It sits on the postcard next to the dish, re-encoded like the photo; the check and the review look at the whole postcard, selfie included |
| The likes you give to other people’s postcards, and when you gave them | They are counted, we remember yours and we let the person who posted know: anyone who can see the postcard can also see who liked it, and the person who posted it gets a notification |
| The comments you write under postcards (up to 300 characters) | They appear under the postcard with your kitchen name if it is public and your profile isn’t private, otherwise with your username or your three-number sign, and with your profile photo or your character; whoever can see the postcard can see them |
| The reports you make about a comment | We remember that you reported it, once, so the same person isn’t counted twice; the person who wrote it sees that the comment is under review, but not who reported it |
| The count of cooks for each week | That is the leaderboard |
| A fingerprint of your phone’s secret | Recognises your device without a login every time |
| Your iPhone’s notification token (a code Apple gives PREP on that phone, used only to deliver notifications), with the app’s language, the two switches “Who follows you” and “Likes and comments”, and the day it was last updated | It tells you, even with the app closed, when someone follows you or asks to follow you, accepts your follow request, or likes or comments on one of your postcards. We keep it only if you have allowed notifications and at least one of the two switches is on |
Before appearing in public, photos go through an automatic check (the Google Cloud Vision service, which answers two questions: is there food, and is there anything that must not go public) and, when in doubt, a human review. A profile photo is only asked the second question: the check doesn’t recognise who you are and doesn’t compare your face with anyone else’s. While it is under review only you, and whoever reviews it, can see it, and others see your previous photo or character; if it doesn’t pass, nobody sees it. If one of your profile photos is stopped or removed, a person always looks at the next ones before they appear. Your username, your profile photo and, if you made it public, your name are visible to anyone using the app. Legal basis: the performance of the service you request by joining the leaderboard and adding a profile photo (art. 6(1)(b) GDPR) and, for the public name, your consent.
Comments appear right away. An automatic filter (words in the app’s four languages, email addresses, links and phone numbers) can hold one back for review; the first report by another person does the same. Under review only you can see it, with a note; then we look at it and let it through or block it, and a blocked comment is seen only by you, with a note, and you can delete it. You can delete your comments whenever you want, with a long press, and whoever published the postcard can delete any comment under it. Legal basis: the performance of the service you request by writing or liking (art. 6(1)(b)); for the filter, the reports and the review, our legitimate interest in keeping PREP a respectful place (art. 6(1)(f)).
Notifications are delivered by Apple. They say what the Notifications screen says: the username of whoever made the move and, for a comment, the start of the text (at most 80 characters). A comment held back by the filter reaches you only if it passes review. You turn them off in Profile → Settings → What we tell you, or in your iPhone’s settings. So that your phone doesn’t go off twice for the same move (someone who unfollows you and follows you again, or removes a like and gives it again), for one day we remember the notifications already sent: who did what, to whom and when. Legal basis: the performance of the service you request by allowing notifications and leaving the switch on (art. 6(1)(b)).
If you cook together with another profile
When you invite someone to cook with you, the two phones have to agree on what is already done: to manage that, they talk through our server. Only that one cooking goes through it, and only for as long as it lasts.
| Data | Why |
|---|---|
| The recipe, how many people, how many at the stove, and your kitchen’s heat | It is the plan: without it, the two phones would show different times for the same dish |
| Every move of the cooking with its moment: what you start, what you close, when you step away and why | It is how the two screens stay in step, and how everything is put back if one phone loses the network |
| The usernames of the two profiles and who did what | Each of you sees your own work and the other’s, and the cooking can count on the leaderboard for both |
| The gap between your phone’s clock and ours | Two different clocks would give two different timers |
What does not go through the server: the photos, your journal and the names you type by hand — the name you give a cook without a profile stays on your phone. Legal basis: performing the service you ask for by inviting someone (art. 6(1)(b)).
The AI Chef
When you type what’s in your pantry, that text is sent to a language model (Anthropic, United States) to recognise which ingredients of our catalogue you named: the dishes are then worked out by your phone. Legal basis: performing the service you ask for by typing in that field (art. 6(1)(b)).
We do not store it: the pantry ends up in no database of ours and in none of our technical logs. What whoever runs the model does with it is decided by their terms, not ours. That is why the rule stays one: don’t type personal data in it, neither yours nor anyone else’s. The dish doesn’t need it.
On which basis
For the newsletter: your consent, given by ticking the box when subscribing (art. 6(1)(a) of Regulation (EU) 2016/679). Boxes are never pre-ticked: if you don’t touch them, there is no consent. Consent to sponsors’ messages is separate, and refusing it takes nothing away from the newsletter.
For the waiting list: your consent, given by ticking the box and confirming in the message we send you (art. 6(1)(a)). The box is never pre-ticked. You can withdraw it whenever you want, by writing to us.
For usage data: our legitimate interest (art. 6(1)(f)) in making the app work and understanding where to improve it. We don’t use it to profile you or to show you tailored advertising. If you don’t want it, you switch it off yourself: in the app, under Profile → Settings → Usage data. From that moment the app stops collecting it and discards what hasn’t been sent yet, without you having to write to anyone. It has a price, and we say so first: switching it off also takes you out of the public leaderboard, because that count rests on those same sends. The profile, the postcards and the diary stay.
For counting visits: our legitimate interest (art. 6(1)(f)) in understanding which pages of the site are useful and improving them. We don’t use it to profile you or to show you tailored advertising. The right to object, below, applies to this as well.
Who else sees it
- Brevo (Sendinblue SAS, France) — keeps the list and sends the messages.
- Vercel (Vercel Inc., United States) — hosts the program that receives your subscription and passes it to Brevo, and counts visits to the website, without cookies.
- Supabase (Supabase Pte. Ltd., Singapore) — the database where usage and leaderboard data end up.
- Cloudflare R2 (Cloudflare Inc., United States) — stores, in Europe, the dish photos and profile photos you upload, and the backup copies of the database.
- Google Cloud Vision (Google Ireland Ltd.) — the automatic check on photos before publication.
- Anthropic (Anthropic PBC, United States) — the model that answers the AI Chef.
- Apple (Apple Inc., United States) — delivers notifications to your iPhone: it receives the token and the text of each notification.
Vercel, Cloudflare and Anthropic are US companies and Supabase is a Singapore company: even when data is stored on servers in Europe, whoever runs the service may access it to make it work, and the transfer relies on the standard contractual clauses approved by the European Commission. Apple is also a US company: its own privacy policy states that transfers of data collected in Europe are governed by the same clauses. We prefer to say it this way rather than write that data “stays in Europe” and stop there.
Nobody else. In particular: we don’t sell or hand over your address to advertisers or anyone else. When a company buys space in the newsletter, the message goes from us to you: the advertiser doesn’t receive your address and doesn’t know who you are.
For how long
The email address: as long as you stay subscribed. When you unsubscribe it is removed from the list. We keep proof of consent for the time needed to show we acted correctly, and no longer.
The waiting-list address: until our launch email, then we delete it, unless in the meantime you have also subscribed to the newsletter. If the app is not out within twelve months of your signing up, we delete it anyway. We keep proof of consent, the confirmation with date and time, for the time needed to show it, and no longer.
Website visits: the counts stay viewable for as long as the service plan allows (today one month); the provider may keep them a little longer. Since they aren’t linked to your name or email, we don’t know whose they are.
The leaderboard: each week’s counts stay twelve weeks and are then deleted. The postcards you publish stay on your profile until you withdraw them from the post or delete your account: a postcard you withdraw disappears right away, the week’s count stays. A postcard blocked by moderation, which nobody sees, is deleted after twelve weeks. An account that doesn’t join the leaderboard for twelve months is deleted with everything it contains, postcards included. And you can delete it yourself whenever you want, from the profile in the app: email, username, name and photos disappear.
Your profile photo: until you change it. When you add a new one and it passes the check, or you pick a character, the previous one disappears straight away, and its file is deleted with it. A photo stopped by the check or removed by moderation is seen by nobody: we keep it as evidence for thirteen weeks, then it is deleted. A photo nobody has decided on yet is deleted after thirteen weeks, a half-uploaded one after a day. If you delete your account, it goes with it.
Likes and comments: until you remove them, and in any case as long as the postcard lasts: they go with it when it is withdrawn, and with the account if you delete it. Reports go with the comment they were about.
The notification token: as long as you need notifications. We delete it when you turn off both switches or withdraw permission for notifications (the next time you open the app), when you sign out of PREP (if you sign out without a connection, your phone stops receiving them right away, and we delete the token as soon as Apple tells us it is no longer valid), when you sign in with your profile on another phone, when you delete your account and when Apple tells us it is no longer valid, for example because you have uninstalled the app. We don’t keep the notifications: they go out, and that’s it. If your phone is off or offline, Apple holds a notification for at most twenty-four hours to deliver it. For one day we remember the notifications already sent, then they are deleted.
Cooking together: its record is only needed while you are cooking. It is deleted within twenty-four hours of the end of the cooking, and within twelve hours of the last move if the cooking is abandoned halfway; an invitation nobody accepts disappears within twenty-four hours. We keep no summary of it.
Usage data: at most twenty-four months, then it is deleted. It serves to read the trend over time, not to reconstruct what you did: not being linked to your name or your email, we don’t know whose it is.
The backup copies of the database, one a week, are kept for eight weeks and then delete themselves: what you delete disappears from the app right away, and from the copies within eight weeks.
How you unsubscribe
There is an unsubscribe link at the bottom of every message. One click, no explanations and no need to write to us. Or send us an email and we do it.
Your rights
You can ask us at any time to:
- know which of your data we hold;
- correct it if it is wrong;
- delete it;
- restrict or object to the processing;
- receive it in a readable format to take it elsewhere;
- withdraw consent, without this making unlawful what was done before.
We answer within a month. If the request is complicated the law gives us two more months: in that case we tell you within the first month, and why. If you think something is wrong, you can turn to the Italian data protection authority, the Garante per la protezione dei dati personali.
If this page changes
The date at the top says when it was last updated. If we change something substantial about how we use your address, we will tell you by email before doing it.