Noshbook
Cooked & Shared

Privacy Policy

Noshbook is a place to keep the food and drink you cook, find and want to remember, and to share some of it with other people. This policy explains what we store when you use the app or this website, why we store it, who else touches it, and how you get rid of it.

Noshbook is run by Chris Christou, who is the data controller for the purposes of the UK and EU General Data Protection Regulation. The registered address is Galateias 1, 4521 Limassol, Cyprus, and you can reach us any time at info@noshbook.app.

The short version

What we collect

Account details

Your email address, and a password if you sign up with one. If you sign in with Google or Apple instead, we receive your email address and basic profile details from them, never your password. We also store the account identifier that Firebase Authentication assigns you, which is what links your content to you.

Your profile

A display name, and anything else you choose to add: a short bio, a free-text location (a place name you type, such as “Nicosia” — we never read your device’s location), a profile photo, a cover photo, and the food interests you pick for taste matching.

What you create

Recipes, recommendations and finds, photos you upload or take, notes, comments, ratings and likes, shopping lists, meal plans, events, and the groups (pods) you take part in.

Messages

Direct messages and group messages you send inside Noshbook are stored so they can be delivered and shown to the people in the conversation. They are not end-to-end encrypted: they are encrypted in transit and at rest, but we are technically able to access them, and we will do so only where it is necessary to investigate a report of abuse or where the law requires it.

Technical and diagnostic data

If the app crashes or runs slowly we receive a crash report and performance trace through Sentry, containing the device model, operating system version, app version, and the state of the app at the time. We have configured Sentry not to attach personal identifiers or IP addresses to these reports.

Notification token

If you turn on notifications we store the push token your device issues, so we can send you the alerts you have asked for. It is a device identifier, not a personal one, and removing the app invalidates it.

What we do not collect

Noshbook does not collect your device location, your contacts, your calendar, your browsing history, your health or fitness data, your financial or payment information, or your advertising identifier. The app contains no advertising SDK and no third-party analytics or tracking SDK. Nothing you do in Noshbook is used to profile you for advertising, here or anywhere else.

Why we use it

What is public and what is not

This distinction matters more than anything else in this policy, so it is worth being precise. Public means visible to anyone using Noshbook.

Public:your profile (name, photo, cover, bio, location and interests), anything you deliberately publish or share — recipes, recommendations, finds — and comments and ratings you leave on other people’s content. Whether your Liked and Poached lists appear on your profile is your choice, in Settings.

Private: your personal board, saved items, items kept for later, shopping lists, meal plans, direct messages, and pod conversations. Pod and shared-list content is visible to the people you shared it with, and to nobody else.

Content you make public can be seen, saved and screenshotted by other people. If you later unpublish or delete it we remove it from Noshbook, but we cannot retrieve copies other people already made.

Who else handles your data

We do not sell your data and we do not share it for anyone else’s marketing. A small number of companies process it on our behalf, under contract, and only to provide the service:

Google and Anthropic operate servers outside Cyprus, including in the United States. Where data leaves the European Economic Area it is transferred under the European Commission’s Standard Contractual Clauses or an equivalent safeguard.

We may also disclose data where the law genuinely requires it, or to protect someone’s safety.

Using Noshbook without an account

You can import a recipe from a link, or generate one with AI, without signing up. In that case we create an anonymous session so the feature works, and what you make stays on your device rather than in an account. If you later sign up, you can keep what you made. If you never do, it is not linked to any identity.

How long we keep it

We keep your content for as long as your account exists. Delete an individual item and it goes straight away. Delete your account and we remove your profile, your board, your saved items, your uploaded photos and the content you published, then close the account.

Two things outlive that, deliberately: messages you sent to other people remain in those people’s conversations, in the same way a sent email does; and abuse reports are kept so a blocked or banned account cannot be cleared by deleting and re-registering. Crash reports expire on Sentry’s own retention schedule, typically within 90 days.

Deleting your account

In the app, open your profile, then the settings icon, then Delete account. It is immediate and it cannot be undone.

If you have already removed the app, or you cannot sign in, follow the steps on our account deletion page— email us from the address on the account and we will delete it for you. We will confirm within 30 days.

Your rights

Under the GDPR you can ask us for a copy of what we hold about you, correct it, delete it, receive it in a portable format, restrict how we use it, or object to processing we base on legitimate interest. Most of these you can do yourself in the app; for the rest, email us and we will respond within one month.

If you think we have handled your data badly, please tell us first — but you are entitled to complain to the Office of the Commissioner for Personal Data Protection in Cyprus, or to the supervisory authority where you live.

Children

Noshbook is an 18+ service. It is not intended for children or for under-18s, it is not directed at them, and it features alcoholic drinks alongside food. We do not knowingly collect data from anyone under 18. If you believe an under-18 has created an account, email us and we will remove it.

Security

Everything travels over encrypted connections and is stored encrypted at rest. Access to your account is controlled by rules enforced on the server, not just in the app, so one person’s private content is not readable by another. We also use Firebase App Check, which verifies that requests come from a genuine copy of the app rather than a script. No service can promise perfect security, but we take this seriously and fix what we find.

Changes

If we change this policy we will update the date at the top, and for anything significant we will tell you in the app before it takes effect.