← back to reciWeLast updated: July 31, 2026

Privacy at reciWe

The short version:your collection is yours. We store what you save so we can show it back to you, we send it to AI providers only to do the things you ask for, we don't run ads or sell your data, and you can delete everything yourself, anytime.

What we collect

Your account. Sign-in is handled by Corbado, our authentication provider (passkeys, Google, or email). From that we keep your account id, email address, display name, and when you last used reciWe.

Your collection. The recipes, letters, photos, and notes you save — including text extracted from the pages, images, and videos you import. Videos from social platforms are fetched to extract the recipe and are not kept afterward; the extracted recipe and any cover image are.

Usage counters.We meter how many imports, AI calls, and photo operations your account uses each day (that's how the free tier works), and we track what your account's AI usage costs us. You can see your own numbers in the ✨ settings.

Your AI key, if you bring one. If you use the "your own AI" option, your API key is stored encrypted (AES-256-GCM), is never shown back to any client (you only ever see its last four characters), and can be removed by you at any time.

We do not collect browsing history, contacts, or location, and we run no advertising trackers and no product analytics. If we add privacy-respecting product analytics later, we'll update this page first.

Crash reports. We use Sentry to record errors so we can fix them. A crash report contains the error and the code path that produced it — not your recipes. We configure it to drop request bodies and cookies, and to mask email addresses and share links before anything is sent. It records no session replay, so it never captures your screen or your collection.

Where it lives

Your collection is stored with our cloud infrastructure providers: a vector database (Qdrant Cloud) for recipe content and search, a hosted SQLite database (Turso) for photos and account data, and Vercel for serving the site. Each account's data is isolated: every read and write is scoped to your account at the storage layer.

Payments

Payments are processed by Stripe. Your card number never reaches reciWe — checkout happens on Stripe's own hosted page, and what comes back to us is a customer reference, the amount, and whether it succeeded. We never see or store card numbers, and we cannot charge you off-session.

What we do keep is the ledger: your Stripe customer id, and a dated record of every purchase and every credit deduction, so your balance is auditable by both of us. To calculate sales tax where any applies, Stripe collects a billing address at checkout and stores it against your Stripe customer record; we do not keep a separate copy.

Stripe processes this under its own privacy policy and, as a payment processor, retains transaction records for the period its financial and anti-fraud obligations require — that retention survives deleting your reciWe account, which is a legal requirement on them and not something either of us can waive.

AI processing

reciWe's AI features send the relevant content to AI providers to do the thing you asked: importing a recipe from a photo or video sends that photo or video for extraction; asking for a substitution sends the recipe and your question; generating a cover image sends the recipe text. Depending on the feature, providers include Google (Gemini, Vertex embeddings, Cloud Vision), Anthropic, Venice.ai, and OpenAI. These providers process content to provide the service — we don't permit them to use it for advertising.

If you bring your own AI key, the text-based AI features route to your chosen provider under your key and their terms instead.

AI use here is transparent and optional where it can be — see how we think about AI.

Sharing

Nothing you save is visible to anyone else unless you share it. Share links carry a scoped token that grants access to exactly that recipe. If you connect an AI assistant via our MCP endpoint, it can read your collection only with the scoped access you approve, and you can revoke that access at any time. Emails reciWe sends (like a recipe you email to yourself) go only to your own verified address, from hello@reciwe.xyz.

Cookies

We use cookies for signing you in (session), remembering your language (recipes_lang), and share-link access. No advertising or cross-site tracking cookies.

Deleting your data

Account deletion is self-serve: in the ✨ settings, type DELETE and your recipes, photos, letters, usage records, and stored AI key are removed from our databases. We don't keep a copy of your collection after deletion. Authentication data held by Corbado is governed by their retention; contact us if you want help ensuring it's fully cleared.

Children

reciWe is not directed at children under 13, and we don't knowingly collect their data.

Changes & contact

If this policy changes in a way that matters, we'll update the date at the top and, for significant changes, tell signed-in users. Questions, concerns, or data requests: hello@reciwe.xyz.

See also the terms of service and about reciWe.