Privacy Policy — Pinjula

Effective date: 1 October 2026 Contact: support@pinjula.com

Türkçe metin için aşağı kaydırın. The English text is the authoritative version: if the English and the Turkish differ, the English prevails.


English

Summary

This app is local-first. Your profile, allergies, equipment, pantry, cooking history, favorites, calendar and week plans are stored on your device. The recipe catalogue ships inside the app, so choosing dishes — filtering by your allergens, diet, equipment, pantry and the repeat window — happens on your phone and sends nothing anywhere. The app has no device identifier, we don't use analytics, advertising or crash-reporting SDKs, and we don't sell your data or use it for advertising.

You can use the whole app without an account. A few things do go over the internet, and each is explained below:

Your phone's own backup system may also copy this app's data to your cloud account; that is explained too.

Who we are

Pinjula is made and published by an independent developer — "we" and "us" in this policy. We decide how the personal data described here is used, which makes us its controller under the EU and UK General Data Protection Regulation (GDPR). Write to support@pinjula.com about anything in this policy.

What's stored on your device

All of the following lives on your phone, most of it in a local database. None of it is stored on our server unless you sign in, and then only what the marked lines say, for what you choose to share. The AI features described under "What leaves your device" send the specific items listed there when you use them — a dish name you typed onto your calendar, for example — and a report you send about a recipe the app wrote carries that recipe (see "Reporting a problem with a recipe"). Apart from those and your phone's own backups (see "Device backups"), none of it leaves the phone:

You can edit or delete most of this from within the app (Settings, the pantry, the shopping list, the calendar). Uninstalling the app deletes this local database along with everything in it.

What leaves your device

Choosing dishes sends nothing. The recipe catalogue is bundled inside the app, so choosing dishes — filtering by your allergens, diet, equipment, pantry and the 7-day repeat window — happens entirely on your phone.

Dish pictures. The pictures of the dishes are too large to ship inside the app, so the app downloads each one from our server the first time it shows it, and keeps it on your phone after that. The download names the picture it wants — which is the name of the catalogue dish it shows — and nothing else: not you, not your household, not your filters.

Four optional features use AI. Each one makes a request to our backend server (a Cloudflare Worker we operate), which passes it to Google's Gemini API and returns the result. All four happen only when you actively ask for them, never in the background:

Your permission comes first. The first time you reach for one of the first three features — turning on "Mix them into one menu", opening "How to prepare this menu" or tapping "Write me a recipe" — the app asks one question that covers all three. It names each feature, says what it sends, as listed above, says that the request goes through our server to Google's Gemini, and points to this policy for what is kept and for how long. Nothing is sent until you choose "Allow". The question is never asked when the app starts or while you are setting it up. If you choose "Not now", nothing is sent and everything else keeps working: menus stay within one cuisine at a time, every dish keeps its own recipe, and a dish you typed stays on your calendar under the name you gave it; where the AI part would have been, the app says why it is missing and offers the question again. You can withdraw your permission at any time in Settings → AI features. From then on none of the three sends anything until you agree again; a recipe already written for a typed dish stays on your phone for the rest of its week. The app keeps only the date you agreed and which version of the question's words you agreed to, on your phone; if the words change in what they say, the app asks again the next time you reach for one of the three — never when it starts. Reading a receipt has its own, separate question — agreeing to one is not agreeing to the other.

None of these requests carries an identifier for you or your phone. The app has no device identifier, and the requests carry no account and no notification token. We don't keep the menus, instructions or recipes that come back — unless you report a problem with a recipe the app wrote, which sends us its text (see "Reporting a problem with a recipe").

One thing we record from any of this: the dish name. When you ask us to write a recipe for a dish our catalogue doesn't have, we count that name — so that if a few hundred people ask for the same dish, we know to add it properly. What we store is the name, how it was most recently spelled, a running count, the interface languages it was asked in, and the dates it was first and last asked for. A name is counted unless the check on your phone or on our server turns it away as not a dish name, or the answer is that it isn't food — it is counted even when the recipe could not be written. Not attached to you: no device identifier, no account, no address. For a name only one person has ever asked for, though, those two dates are when that person asked.

The recipe written for you stays on your phone for a week. The app shows it for seven days so that it doesn't change under you halfway through cooking it. After that it is no longer shown, and it is deleted the next time you open the app (or when the app next writes a recipe for you, or when you uninstall it). It is stored on our server only if you report a problem with it, and then as the report describes (see "Reporting a problem with a recipe").

What Google does with these requests. We use Gemini as a paid service. Under Google's terms for it, Google doesn't use what we send — photographs included — or what it returns to improve its products, and it processes them on our behalf under its data processing terms. Google keeps requests and responses for 55 days solely to detect and prevent misuse of its service, and during that time authorized Google staff may review them for that purpose. Google may process them in any country where it or its sub-processors have facilities.

What any request reveals. Every connection to a server shows it the IP address it came from. Cloudflare, which runs our server, keeps a record of each request it receives for up to seven days, to run and secure the service: the time, the address requested — for a dish picture, that address is the picture's name, which names the catalogue dish — the IP address it came from, the approximate location Cloudflare works out from that IP address (such as the country, region and city), and the request's technical headers, such as the name and version of the software making it. That record never contains a photograph, a dish name you typed or anything else in the body of what you send. Our own log lines never contain a photograph. For "Write me a recipe", receipts and reports they hold only counts and status or error codes. For the two menu features, a request that fails, or whose answer has to be partly thrown away, can be logged with the catalogue dishes it was about. A failed one can also be logged with the reply Google sent back, which can repeat what was sent — including a dish name you typed and the recipe written for it. We don't use any of these logs to identify or locate anybody.

A failure here never costs you a recipe. If a mixed-cuisine menu request fails, the app builds the menu on the phone instead; if the cooking plan fails, you can try again and each dish's own recipe is still there; if "Write me a recipe" fails, the dish stays on your calendar under the name you typed.

Your account and your household — optional

Signing in is a choice, and everything above keeps working if you never do. What an account is for is keeping your ratings across phones and sharing with the people you live with.

Signing in. You sign in with your Apple or Google account — there is no password of ours. Your phone talks directly to our authentication provider, Supabase, which receives: from Google, your name, your email address, the web address of your profile picture and your Google account identifier (and, for a Google Workspace account, its domain); from Apple, your email address — with "Hide My Email", a relay address — and your Apple account identifier, plus your name only if Apple passes it on. Supabase keeps these, your active sign-in sessions and a log of sign-in events, including the IP address they came from, to keep accounts secure. Apple and Google handle the sign-in itself under their own privacy policies.

What an account keeps, even without a household. The ratings and notes you give recipes, so they follow you to a new phone. When you sign in, the ratings already on the phone are copied to your account.

What syncs to our server once you create or join a household. This list is exhaustive:

What is not sent, even in a household: your shopping list, your calendar and week plans, your pantry, your suggestion and cooking history, your favorites, your equipment, your staples and the rest of your profile (household size, skill level, effort tier, residence country, default cuisine, language). They stay on your phone.

Consent for health data. Before a person's details are first stored with the household — whether or not anything is declared for them yet — the app asks you to agree explicitly, and it asks again after the app has been restarted, before the next change to their declarations. The question says what is stored — health information, and for a diet such as halal or kosher a religious belief — who can see it, why, and what saying no costs; this policy says where it is stored and for how long. We store the fact that you agreed: which text, in which language, on which date, for which member. You can withdraw that consent, and doing so deletes those declarations from the server.

Who in the household can see and change it. Everyone signed in to the household can see every member's declarations. Who may change them depends on the member. A member who signs in with their own account is the only one who records, changes, consents to and withdraws their own declarations. For a member who has no login of their own — a child, or a guest you added by name — that is the household's owner — the account that created the household, or the one ownership later passed to; another adult who joined by invitation sees those declarations but cannot edit them. The owner is also the only one who adds people to the household and who can remove a member who signs in with their own account. A person who has no account of their own can be removed by any member of the household, and removing them deletes their name and declarations from our server. Anybody can leave. A household is people who cook together and the app is built on that assumption. If that is not your situation, keep the declarations on your phone and do not join a household.

Removing a member. When someone is removed from a household, their name, age band and declarations are deleted from our server immediately. What remains there is a marker with no personal information in it, whose only job is to tell the other phones in the house that this person is no longer a member; it is erased after 30 days. Those phones keep the person, with what was declared for them, as an entry on their own list — so nobody's food is suddenly filtered less carefully without them knowing — until someone removes them there.

Deleting your account. Settings → Account & sharing → Delete account. This immediately deletes your account, your ratings and your household membership — your name and your declarations there — and marks the consents you gave as withdrawn, including those you gave for people without an account. If you owned the household, ownership passes to the member with an account who joined earliest. While other members with an account remain, the people added without an account stay in the household with what was declared for them, managed from then on by its owner, even though the consent you gave for them is now marked withdrawn; if you want them off our server, remove them from the household first. Leaving a household works the same way. If you were its last member with an account, the whole household is deleted from our server with it, including the people added without an account and their declarations. Your sign-in is then deleted from our authentication provider, normally within fifteen minutes; if that fails we keep retrying, and we keep the request on file until it succeeds rather than quietly dropping it. Deleting your account does not delete the local database on your phone — uninstalling does that — and does not remove the entries other phones in the household keep, described above. It also doesn't remove this app from the list of apps connected to your Apple or Google account; you can remove it there yourself. If you can't use the app, email support@pinjula.com from, or naming, the email address of the account you signed in with; we confirm with that address, then delete the account, within one month at the latest.

Getting a copy of your data. Settings → Account & sharing → Export my data. The file is assembled on your phone and handed to your device's share sheet. It contains your account's email address; your profile (such as your language, cuisine, residence country, household size, skill level, effort tier, weekly cooking target and when you last reset the repeat filter); the dates you allowed the AI features and receipt scanning, and which version of each question's words; the people on your household list with what was declared for them; your kitchen equipment and pantry staples; your suggestion and cooking history; your favorites; your pantry; your shopping list; your calendar and week plans, including each dish you typed onto a day, in your own words; the dishes you typed and marked as cooked; the dishes you marked as cooked from the recipe list or your Cookbook; your badges and the dated log behind them; your reminder settings; the household as your phone last synced it; and your ratings. A dish from our catalogue is named by its catalogue identifier; the recipe itself is not copied into the file. It does not contain a recipe the app wrote for a dish you typed, which the phone keeps for seven days, or your sign-in session, and it does not contain the records of the health-data consents you gave for a household, which are kept on our server: ask for them at support@pinjula.com. We do not build the file on our server or keep a copy of it. Because a household's roster can include children, the export contains the names and declarations entered for them; treat the file accordingly.

Where it is stored. Frankfurt, Germany (eu-central-1), on Supabase. We chose an EU region so that data from our European markets is stored in the EU; "Service providers and international transfers" below says who else can reach it and on what terms.

Device backups

Your phone's operating system may include this app's data in its normal device backup — Google Drive on Android, iCloud on iOS. That backup is made by your phone, into your own cloud account, under your control. We are not involved in it, we receive nothing from it, and we cannot read it. On Android 9 and later these backups are encrypted with your device's PIN, pattern or password before they leave the phone.

We leave this on rather than off, because it is what restores your pantry, your cookbook and your week plan when you change phones. If you would rather it did not happen, your device's backup settings turn it off — on Android, Settings › Google › Backup; on iOS, Settings › [your name] › iCloud.

Because the backup carries the whole local database, it carries the allergens you declared for yourself and for anyone you added as a household member. While you are signed in it also carries your sign-in session, with the email address and name your Apple or Google account shared.

The text of upcoming reminders and the pictures on your widgets are not backed up, and on Android neither is your widgets' text; they are rebuilt from your data when the app opens. On iPhone your widgets' text sits in storage the app shares with its widgets and goes into a device backup like the rest of the app's data; it names no allergen, diet or person.

Reminders and home-screen widgets

Worked out on your phone, and nothing is sent anywhere. Reminders and widgets are made from what is already on your phone: your calendar, your shopping list, what your pantry and the staples you keep hold (so a widget can say whether a planned dish's ingredients are there), the dates you entered in your pantry, the dishes you marked as cooked, and pictures — the recipe picture of a planned dish once the app has already shown it to you, and the app's own ingredient pictures. Nothing is sent to us or to anyone else to produce them, and a widget never downloads a picture. There is no push service behind them, and the app still has no device identifier or notification token.

Off until you turn them on. The app explains what it will do and asks first; on Android 13 and later your phone asks as well. There are six kinds (the day's plan, pantry items close to a date you entered, leftovers nobody has marked as eaten, ticked shopping waiting to go into your pantry, a weekly look at what you cooked, and an optional shopping day), at most three a day and never late at night. Settings → Reminders and widgets turns them all off or each kind separately, and so do your phone's notification settings. You add widgets to your home screen yourself and can remove them at any time; removing one deletes nothing.

Anyone who can see your screen can see them, so they carry no health information. A reminder can appear on your lock screen and a widget on your home screen. Neither ever names an allergy, a diet, an intolerance or the person who declared it. When a planned dish contains something your household declared, the reminder says only that the day's plan needs a look, without naming the dish, and the widget says the dish contains something declared in your household; only the app itself says what. When a planned dish may no longer fit a diet, lactose avoidance or dislike your household declared after planning it, the reminder likewise says only that the plan needs a look, and the widget keeps the dish and says it may not fit something declared in your household — again without saying what. The leftovers reminder names up to two of the dishes that still have leftovers and counts the rest. A dish that contains something anyone in your household declared, or may no longer fit it, is only counted, never named — even when that person's meals are cooked separately; a dish the app cannot check is only counted, and when it cannot read your household's declarations or the recipe catalogue, it names none. A dish name you typed onto your calendar is shown as you typed it. When the widget says which of a planned dish's ingredients are missing from your pantry, it never says so beside a dish that contains or may not fit something declared in your household.

A small copy kept on the phone. So that a widget can show something and a reminder can appear while the app is closed, the app keeps the text and the pictures they will display in its own storage on your phone. It is replaced whenever you change something. The pictures and the reminders' text are excluded from device backups, and so is the widgets' text on Android; on iPhone the widgets' text goes into a device backup with the rest of the app's data (see "Device backups"). Your reminder settings are backed up with the rest of the app's data.

A reminder does not promise a time. Your phone may delay reminders to save battery, and some manufacturers' battery managers can block them.

Scanning a receipt — the one feature that sends a photograph

Only if you switch it on, and only when you tap. On the pantry screen you can photograph a supermarket receipt, or choose a photo of one, and have the food on it added to your pantry without typing. Before the first photograph is taken the app asks you, in your own language, whether you agree to what follows; you can withdraw that agreement at any time in Settings, after which the app asks again before the next scan. It also asks again before the next scan if the words of the question change in what they say.

What leaves your device. The photograph (reduced in size on your phone first), the image type, and your interface language. Nothing else — not your pantry, your household, your account or your profile. It goes to our backend server, which passes it to Google's Gemini API to read the lines on it.

The details your phone stores inside a photo stay on your phone. Before the picture is sent, the app takes out what your phone wrote into the file — when and where it was taken, and the phone's make, model and serial number — and keeps only which way up the picture is.

What a receipt shows, said plainly. A receipt is not just a list of groceries. It can show where you shopped, when, what you paid, and everything else in the basket — medicine, baby formula, alcohol, hygiene products. The whole picture is read, because the model has to see the page to find the food on it. What comes back to your phone is only the lines it judged to be food or drink, with a quantity and unit where the receipt printed one. Prices, totals, the store, the date, card and loyalty numbers and every non-food line have no place in the answer — the server rebuilds the reply from a fixed list of three fields, so a value the model wrote anywhere else cannot travel.

What is kept, and where. Our server keeps nothing: the photograph is not stored and not written to a log, and we do not record which items were read. Google keeps the request — the photograph with it — for 55 days solely to detect misuse of its service, as described under "What leaves your device"; we send it no identifier for you. On your phone, the app deletes the photo picker's copies of the picture as soon as it has read them, before anything is sent — the reduced one it sends and, on Android, the full-size copy the picker makes of a photo chosen from your gallery. The photo in your gallery is never touched. Apart from Google's 55-day misuse log of the request and its reply — which covers every line Google read, not only the food lines the app is sent — the list that comes back is stored only on your phone, and there only once you have confirmed it.

Nothing reaches your pantry without you. The lines come back as a list you review; you untick what you did not buy, and only what you confirm is added. An item we could match to our ingredient list is added under that ingredient; one we could not is added by the name we read and marked as such — never silently mapped onto a neighbour.

If reading fails, the app says so and nothing is added.

Reporting a problem with a recipe

Only when you send one. At the foot of every recipe — ours, and the ones the app writes for a dish you typed — "Report a problem with this recipe" lets you tell us what is wrong. You pick a reason (an ingredient, a step, an allergen or diet concern, the translation, a cultural inaccuracy, the picture, something offensive, or something else) and can add a note of up to 500 characters. Nothing is sent until you tap "Send report". A report that could not be sent stays on the screen for you to send again or close; it is not kept, and it is not sent later on its own.

What is sent. For a recipe from our catalogue: which recipe it is (its catalogue identifier), the reason, your note and the app's language — not the recipe itself, which we already have. For a recipe the app wrote for a dish you typed, its text goes with the report: the title, the ingredients and the steps, because that recipe exists only on your phone and a report without it would be about nothing we can see; the report screen says so before you send. Never your account, your household, your allergies or your profile. A report goes to our server and is stored in our database in Frankfurt; it never goes to Google, so asking for it does not need your permission for the AI features.

What is kept, and for how long. The report — the reason, your note, the language, the day it was sent (not the time of day), and either the recipe's catalogue identifier or the written recipe's text — is kept for 12 months and then deleted. We store no account, no device identifier, no IP address and nothing else about who sent it, and we send nothing back to your phone that could find it again. Our own log lines about a report hold only status codes, never your note or the recipe. Like every request, it passes through Cloudflare's request record described under "What leaves your device", which keeps the IP address it came from for up to seven days and never the body of what you send.

Please keep personal details out of the note. A report carries nothing that links it to you, so we cannot reply to it, and a name or an email address written into the note would be kept for the 12 months like the rest of it. If you want an answer, or want to tell us something a report cannot carry, write to support@pinjula.com. If you want a report you sent deleted before its 12 months are up, write to us with enough to find it — the recipe, the day and the words of your note — and we will delete it.

What we do with reports. We read them to correct the catalogue and the way the app writes recipes. A report is not a promise that a recipe will be changed, and nothing you report changes what the app shows anyone by itself.

Sharing a recipe

If you use the share button, the app hands a plain-text version of the recipe — or of a whole menu — to your device's normal share sheet — that's entirely your choice of where it goes (messaging apps, notes, etc.) and isn't something we're involved in or see. For its badges, the app notes on your phone that a share happened, and on which day — never what you shared or with whom.

Sharing with your own photo. You can also attach a photo of a dish you cooked, either taken then and there or chosen from your photos. The app asks your device for that one picture, passes it to the share sheet you choose, and does nothing else with it: it is never uploaded and we never receive it. We do not read, browse or index your photo library — the picker your device shows is the operating system's own, and the app only ever sees the single file you hand it. The photo picker leaves a temporary file in the app's cache, never backed up, which your phone clears when it needs space. If you back out without choosing, nothing happens at all.

Camera and photo permissions. On iOS the app asks for access to the camera or to your photos at the moment you tap — for a dish photo to share or for a receipt to read, never on first launch — and declining leaves everything else working. On Android the app asks for no camera or photo permission at all: your phone's own camera app takes the picture and the system photo picker chooses it.

Ratings

Without an account, ratings you give are stored only on your device.

With an account they are kept with it, so they follow you to a new phone. Only your own phones receive them — not the other people in your household. Today they are used for nothing else: we don't aggregate them across users, we don't show them as "popular with others", and we don't build a profile of you from them. You can change a rating at any time. There is no button to remove one yet; deleting your account deletes them from our server, and uninstalling the app deletes them from your phone.

Service providers and international transfers

We use three service providers. Each processes the data on our behalf and on our instructions, under the data processing terms that come with its service, which bind it to protect the data and to use it only to provide that service to us — the same protection this policy describes.

So some personal data is processed outside the EU and the UK, mainly in the United States. Cloudflare and Google are certified under the EU–US Data Privacy Framework, which the European Commission has found to give adequate protection, and whose extensions the UK and Switzerland recognise; and all three providers' data processing terms include the European Commission's Standard Contractual Clauses, with their UK equivalent, for transfers the Framework does not cover. You can ask us for a copy of these safeguards at support@pinjula.com.

When you sign in with Apple or Google, that company is not our service provider: it handles your sign-in under its own privacy policy and sends us only what "Signing in" lists.

We don't use any analytics, advertising or crash-reporting SDKs in this app, and we don't sell your data or give it to anybody else.

Withdrawing a consent stops what it covered from then on; it doesn't make unlawful what was done before.

How long we keep things

Your rights

Wherever you live, you can ask us for a copy of your data, ask us to correct or delete it, and withdraw any consent at any time. If the GDPR or the UK GDPR applies to you, you also have the rights to restrict or object to our use of your data and to data portability, and you can complain to the data protection authority where you live or work — in the UK, the Information Commissioner's Office.

Your right to object. Where we rely on our legitimate interest — request logs, sign-in logs, finishing an account deletion, the details of people added without an account of their own, and reports about a recipe — you can object at any time, on grounds relating to your particular situation, by writing to support@pinjula.com. A report can be found only from what you tell us about it (see "Reporting a problem with a recipe").

Most of this you can do in the app yourself: Settings → Account & sharing has Export my data and Delete account, and withdrawing your own health-data consent is on the same screen; for someone you added, "Stop sharing with the household" deletes them and what was declared for them from our server; the receipt-scanning consent and the consent for the AI features are each withdrawn in Settings. For anything else, or if you can't use the app, email support@pinjula.com; we reply within one month.

Not medical or nutritional advice

Where the app shows nutrition figures, they are estimates calculated from published food-composition databases (USDA FoodData Central; for mutton, the Australian Food Composition Database by Food Standards Australia New Zealand) applied to a recipe's ingredients — not a verified analysis of the food you actually cook, and never medical or dietary advice. Allergen filtering is a best-effort safety aid, not a guarantee — always check the full ingredient list yourself before cooking, especially if you have a food allergy. The app is not a medical device and does not diagnose, treat, cure or prevent any medical condition; for medical advice, diagnosis or treatment, consult a healthcare professional.

Children

This app isn't directed at children and we don't knowingly let a child create an account.

An adult can, however, add a child to a household — that is what the age bands and portion sizes are for. In a shared household the child's entry reaches our server: the name you typed for them, their age band, their portion size and whether they eat from a separate plate, and any allergies, diets, intolerances and dislikes you record. We ask the adult for explicit consent before storing it, we hold nothing else about that child (no email address, no sign-in, no device identifier, no date of birth), and removing the child from the household deletes the name and the declarations from our server at once.

Changes to this policy

If this policy changes, we'll update the effective date above, add a line to the changelog at the end, and, for material changes, note it in the app's release notes.

Contact

Questions about this policy: support@pinjula.com


Türkçe

Özet

Bu uygulama yerel öncelikli çalışır. Profilin, alerjilerin, mutfak ekipmanın, dolabın, pişirme geçmişin, favorilerin, takvimin ve haftalık planların cihazında saklanır. Tarif kataloğu uygulamanın içinde geldiği için yemek seçimi — alerjenlerine, diyetine, ekipmanına, dolabına ve tekrar penceresine göre süzme — telefonunda yapılır ve hiçbir yere hiçbir şey göndermez. Uygulamanın cihaz kimliği yoktur; analiz, reklam ya da çökme raporlama SDK'sı kullanmayız; verilerini satmaz, reklam için kullanmayız.

Uygulamanın tamamını hesap açmadan kullanabilirsin. Yine de bazı şeyler internetten geçer ve her biri aşağıda anlatılıyor:

Telefonunun kendi yedekleme sistemi de bu uygulamanın verisini senin bulut hesabına kopyalayabilir; o da anlatılıyor.

Biz kimiz

Pinjula, bağımsız bir geliştirici tarafından yapılır ve yayımlanır — bu politikadaki "biz" odur. Burada anlatılan kişisel verilerin nasıl kullanılacağına biz karar veririz; bu da AB ve Birleşik Krallık Genel Veri Koruma Tüzüğü (GDPR) açısından bizi veri sorumlusu yapar. Bu politikadaki herhangi bir konu için support@pinjula.com adresine yaz.

Cihazında saklananlar

Aşağıdakilerin hepsi telefonunda, çoğu yerel bir veritabanında tutulur. Giriş yapmadıkça hiçbiri sunucumuzda saklanmaz; giriş yaptığında da yalnızca işaretli satırların söylediği, paylaşmayı seçtiklerin için saklanır. "Cihazından ne çıkıyor" altında anlatılan yapay zekâ özellikleri, onları kullandığında orada sayılan belirli şeyleri gönderir — örneğin takvimine yazdığın bir yemek adını. Uygulamanın yazdığı bir tarif hakkında gönderdiğin bir rapor da o tarifi taşır ("Bir tarifte sorun bildirmek"e bak). Bunlar ve telefonunun kendi yedekleri ("Cihaz yedekleri"ne bak) dışında hiçbiri telefondan çıkmaz:

Bunların çoğunu uygulama içinden (Ayarlar, dolap, alışveriş listesi, takvim) düzenleyebilir ya da silebilirsin. Uygulamayı kaldırmak bu yerel veritabanını içindeki her şeyle birlikte siler.

Cihazından ne çıkıyor

Yemek seçmek hiçbir şey göndermez. Tarif kataloğu uygulamanın içinde geldiği için yemek seçimi — alerjenlerine, diyetine, ekipmanına, dolabına ve 7 günlük tekrar penceresine göre süzme — tamamen telefonunda yapılır.

Yemek görselleri. Yemeklerin görselleri uygulamanın içine sığmayacak kadar büyük; bu yüzden uygulama her birini ilk gösterdiğinde sunucumuzdan indirir ve sonra telefonunda tutar. İndirme isteği yalnızca istenen görselin adını taşır — bu da gösterdiği katalog yemeğinin adıdır: seni, haneni ya da süzgeçlerini değil.

İsteğe bağlı dört özellik yapay zekâ kullanır. Her biri işlettiğimiz arka uç sunucusuna (bir Cloudflare Worker) istek gönderir; sunucu bunu Google'ın Gemini API'sine iletir ve sonucu döndürür. Dördü de yalnızca sen istediğinde çalışır, arka planda asla:

Önce senin iznin. İlk üç özellikten birine ilk kez uzandığında — "Tek menüde karıştır"ı açtığında, "Menünün hazırlanışı"nı açtığında ya da "Bana bir tarif yaz"a dokunduğunda — uygulama üçünü birden kapsayan tek bir soru sorar. Soru her özelliği adıyla anar, yukarıda sayıldığı gibi ne gönderdiğini söyler, isteğin sunucumuz üzerinden Google'ın Gemini'sine gittiğini söyler ve neyin ne kadar süre saklandığı için bu politikayı gösterir. Sen "İzin ver"i seçene kadar hiçbir şey gönderilmez. Bu soru uygulama açılırken ya da kurulum sırasında hiç sorulmaz. "Şimdi değil"i seçersen hiçbir şey gönderilmez ve geri kalan her şey çalışmaya devam eder: menüler her seferinde tek bir mutfaktan kurulur, her yemeğin kendi tarifi yerinde durur ve yazdığın bir yemek takviminde verdiğin adla kalır; yapay zekâ kısmının olacağı yerde uygulama neden eksik olduğunu söyler ve soruyu yeniden sunar. İznini istediğin zaman Ayarlar → Yapay zekâ özellikleri'nden geri çekebilirsin. O andan sonra sen yeniden izin verene kadar üçünden hiçbiri bir şey göndermez; yazdığın bir yemek için zaten yazılmış bir tarif, haftasının geri kalanı boyunca telefonunda kalır. Uygulama yalnızca izin verdiğin tarihi ve sorunun hangi sürümüne izin verdiğini, telefonunda tutar; sorunun söyledikleri değişirse uygulama, üçünden birine bir sonraki uzandığında yeniden sorar — açılırken asla. Bir fişin okunmasının kendine ait ayrı bir sorusu vardır — birine izin vermek ötekine izin vermek değildir.

Bu isteklerin hiçbiri seni ya da telefonunu tanımlayan bir kimlik taşımaz. Uygulamanın cihaz kimliği yoktur ve istekler ne bir hesap ne de bir bildirim anahtarı taşır. Dönen menüleri, talimatları ya da tarifleri saklamıyoruz — uygulamanın yazdığı bir tarifte sorun bildirmediğin sürece; rapor o tarifin metnini bize gönderir ("Bir tarifte sorun bildirmek"e bak).

Bütün bunlardan kaydettiğimiz tek şey: yemeğin adı. Kataloğumuzda olmayan bir yemek için tarif yazmamızı istediğinde o adı sayıyoruz — böylece birkaç yüz kişi aynı yemeği isterse onu düzgün biçimde eklememiz gerektiğini öğreniyoruz. Sakladığımız şey ad, en son nasıl yazıldığı, bir sayaç, hangi arayüz dillerinde istendiği ve ilk ve son istendiği tarihler. Ad, telefonundaki ya da sunucumuzdaki kontrol onu yemek adı değil diye geri çevirmedikçe ve cevap bunun bir yiyecek olmadığını söylemedikçe sayılır — tarif yazılamadığında bile. Seninle ilişkilendirilmiyor: cihaz kimliği yok, hesap yok, adres yok. Yine de yalnızca bir kişinin istediği bir ad için o iki tarih, o kişinin ne zaman istediğidir.

Sana yazılan tarif bir hafta telefonunda kalır. Uygulama onu, pişirmenin ortasında altında değişmesin diye yedi gün gösterir. Sonra artık gösterilmez ve uygulamayı bir sonraki açışında silinir (ya da uygulama sana bir sonraki tarifi yazdığında, ya da uygulamayı kaldırdığında). Sunucumuzda yalnızca onda bir sorun bildirirsen, raporla birlikte ve orada anlatıldığı şekilde saklanır ("Bir tarifte sorun bildirmek"e bak).

Google bu isteklerle ne yapar. Gemini'yi ücretli bir hizmet olarak kullanıyoruz. Google'ın bu hizmete ait şartlarına göre Google, gönderdiğimizi — fotoğraflar dahil — ya da döndürdüğünü ürünlerini geliştirmek için kullanmaz ve bunları kendi veri işleme şartları altında bizim adımıza işler. Google istekleri ve yanıtları yalnızca hizmetinin kötüye kullanılmasını tespit etmek ve önlemek için 55 gün tutar; bu süre içinde yetkili Google çalışanları onları yalnızca bu amaçla inceleyebilir. Google bunları kendisinin ya da alt işleyenlerinin tesisi bulunan herhangi bir ülkede işleyebilir.

Her isteğin gösterdiği. Bir sunucuya yapılan her bağlantı ona geldiği IP adresini gösterir. Sunucumuzu çalıştıran Cloudflare, aldığı her isteğin kaydını hizmeti çalıştırmak ve güvende tutmak için en fazla yedi gün tutar: zamanını, istenen adresi — bir yemek görselinde bu adres görselin adıdır, yani katalog yemeğini adlandırır —, geldiği IP adresini, Cloudflare'in o IP adresinden çıkardığı yaklaşık konumu (ülke, bölge ve şehir gibi) ve isteğin teknik başlıklarını, örneğin isteği yapan yazılımın adını ve sürümünü. Bu kayıt hiçbir zaman bir fotoğraf, senin yazdığın bir yemek adı ya da gönderdiğinin gövdesindeki başka bir şeyi içermez. Bizim kendi kayıt satırlarımız hiçbir zaman bir fotoğraf içermez. "Bana bir tarif yaz", fişler ve raporlarda yalnızca sayılar ile durum ya da hata kodları taşırlar. İki menü özelliğinde başarısız olan ya da cevabının bir kısmı atılan bir istek, ilgili olduğu katalog yemekleriyle kaydedilebilir. Başarısız olan bir istek ayrıca Google'ın geri gönderdiği yanıtla birlikte kaydedilebilir; bu yanıt gönderileni tekrarlayabilir — senin yazdığın bir yemek adı ve onun için yazılan tarif dahil. Bu kayıtların hiçbirini kimseyi tanımlamak ya da konumunu bulmak için kullanmayız.

Buradaki bir hata sana asla bir tarife mal olmaz. Mutfakları karıştıran bir menü isteği başarısız olursa uygulama menüyü telefonda kurar; pişirme planı başarısız olursa yeniden deneyebilirsin ve her yemeğin kendi tarifi yerinde durur; "Bana bir tarif yaz" başarısız olursa yemek takviminde yazdığın adla kalır.

Hesabın ve hanen — isteğe bağlı

Giriş yapmak bir tercih; hiç yapmasan da yukarıdakilerin hepsi çalışmaya devam eder. Hesabın işi, puanlarını telefonlar arasında korumak ve birlikte yaşadığın kişilerle paylaşmaktır.

Giriş yapmak. Apple ya da Google hesabınla giriş yaparsın; bize ait bir parola yoktur. Telefonun doğrudan kimlik doğrulama sağlayıcımız Supabase ile konuşur; Supabase şunları alır: Google'dan adını, e-posta adresini, profil fotoğrafının web adresini ve Google hesap tanımlayıcını (bir Google Workspace hesabında ayrıca alan adını); Apple'dan e-posta adresini — "E-postamı Gizle" seçeneğinde bir aktarma adresini — ve Apple hesap tanımlayıcını, adını ise yalnızca Apple iletirse. Supabase bunları, etkin oturumlarını ve geldikleri IP adresi dahil giriş olaylarının kaydını hesapları güvende tutmak için saklar. Girişin kendisini Apple ve Google kendi gizlilik politikaları altında yürütür.

Hane olmasa bile hesabın tuttukları. Tariflere verdiğin puanlar ve notlar; böylece yeni telefonuna seninle gelirler. Giriş yaptığında telefonda zaten bulunan puanlar hesabına kopyalanır.

Bir hane kurduğunda ya da bir haneye katıldığında sunucumuza eşitlenenler. Bu liste eksiksizdir:

Hanede bile gönderilmeyenler: alışveriş listen, takvimin ve haftalık planların, dolabın, öneri ve pişirme geçmişin, favorilerin, ekipmanların, temel malzemelerin ve profilinin geri kalanı (hane büyüklüğü, beceri seviyesi, efor seviyesi, ikamet ülken, varsayılan mutfak, dil). Bunlar telefonunda kalır.

Sağlık verisi için rıza. Bir kişinin bilgileri haneyle ilk kez saklanmadan önce — onun için henüz bir şey beyan edilmiş olsun ya da olmasın — uygulama senden açıkça onay ister; uygulama yeniden başlatıldıktan sonra da, beyanlarındaki bir sonraki değişiklikten önce yeniden sorar. Soru neyin saklandığını (sağlık bilgisi; helal ya da koşer gibi bir diyette dini bir inanç), kimin görebileceğini, neden saklandığını ve hayır demenin neye mal olduğunu söyler; nerede ve ne kadar süre saklandığını bu politika söyler. Onay verdiğin kaydedilir: hangi metin, hangi dilde, hangi tarihte, hangi üye için. Bu rızayı geri çekebilirsin; geri çektiğinde o beyanlar sunucudan silinir.

Hanede bunu kim görebilir ve değiştirebilir. Haneye giriş yapmış herkes her üyenin beyanlarını görebilir. Kimin değiştirebileceği üyeye göre değişir. Kendi hesabıyla giriş yapan bir üyenin beyanlarını yalnızca kendisi kaydeder, değiştirir, onlar için rıza verir ve geri çeker. Kendi girişi olmayan bir üye için — bir çocuk ya da adıyla eklediğin bir misafir — bunu hanenin sahibi yapar — haneyi kuran hesap ya da sahipliğin sonradan geçtiği hesap; davetle katılan başka bir yetişkin o beyanları görür ama düzenleyemez. Haneye kişi eklemek ve kendi hesabıyla giriş yapan bir üyeyi çıkarmak da yalnızca sahibin elindedir. Kendi hesabı olmayan bir kişiyi ise hanenin herhangi bir üyesi çıkarabilir; onu çıkarmak adını ve beyanlarını sunucumuzdan siler. Ayrılmak herkesin elindedir. Hane, birlikte yemek pişiren insanlardır ve uygulama bu varsayım üzerine kuruludur. Durumun bu değilse beyanları telefonunda tut ve bir haneye katılma.

Bir üyeyi çıkarmak. Bir kişi haneden çıkarıldığında adı, yaş aralığı ve beyanları sunucumuzdan anında silinir. Orada kişisel hiçbir bilgi taşımayan bir işaret kalır; tek işi evdeki diğer telefonlara bu kişinin artık üye olmadığını söylemektir ve 30 gün sonra silinir. O telefonlar kişiyi, onun için beyan edilenlerle birlikte kendi listelerinde bir kayıt olarak tutar — kimsenin yemeği, haberi olmadan birden daha gevşek süzülmesin diye — ta ki biri onu orada kaldırana kadar.

Hesabını silmek. Ayarlar → Hesap ve paylaşım → Hesabı sil. Bu işlem hesabını, puanlarını ve hane üyeliğini — oradaki adını ve beyanlarını — anında siler ve verdiğin rızaları, hesabı olmayan kişiler için verdiklerin dahil, geri çekilmiş olarak işaretler. Hanenin sahibi sensen sahiplik, hesabı olan ve haneye en önce katılmış üyeye geçer. Hesabı olan başka üyeler kaldıkça, hesapsız eklenen kişiler onlar için beyan edilenlerle birlikte hanede kalır; onlar için verdiğin rıza artık geri çekilmiş görünse de bundan sonra onları hanenin sahibi yönetir. Sunucumuzdan kalkmalarını istiyorsan önce onları haneden çıkar. Haneden ayrılmak da aynı şekilde işler. Hanenin hesabı olan son üyesi sensen hane de onunla birlikte sunucumuzdan tamamen silinir, hesapsız eklenen kişiler ve beyanları dahil. Girişin ardından kimlik doğrulama sağlayıcımızdan da silinir, normalde on beş dakika içinde; bu başarısız olursa denemeye devam ederiz ve başarılı olana kadar talebi kayıtlı tutarız, sessizce düşürmeyiz. Hesabını silmek telefonundaki yerel veritabanını silmez — onu uygulamayı kaldırmak siler — ve hanedeki diğer telefonların tuttuğu, yukarıda anlatılan kayıtları da kaldırmaz. Bu uygulamayı Apple ya da Google hesabına bağlı uygulamalar listesinden de çıkarmaz; orada kendin kaldırabilirsin. Uygulamayı kullanamıyorsan giriş yaptığın hesabın e-posta adresinden, ya da o adresi yazarak, support@pinjula.com adresine e-posta gönder; o adresle doğrularız, sonra hesabı en geç bir ay içinde sileriz.

Verinin bir kopyasını almak. Ayarlar → Hesap ve paylaşım → Verilerimi dışa aktar. Dosya telefonunda oluşturulur ve cihazının paylaşım sayfasına verilir. İçinde hesabının e-posta adresi; profilin (dilin, mutfağın, ikamet ülken, hane büyüklüğü, beceri ve efor seviyen, haftalık pişirme hedefin ve tekrar filtresini en son ne zaman sıfırladığın gibi); yapay zekâ özelliklerine ve fiş taramaya izin verdiğin tarihler ve her sorunun hangi sürümüne izin verdiğin; hane listendeki kişiler ve onlar için beyan edilenler; mutfak ekipmanların ve temel malzemelerin; öneri ve pişirme geçmişin; favorilerin; dolabın; alışveriş listen; takvimin ve haftalık planların — bir güne yazdığın her yemek, kendi sözlerinle, dâhil; kendin yazıp pişirildi diye işaretlediğin yemekler; tarif listesinden ya da Yemek defterinden pişirildi diye işaretlediğin yemekler; rozetlerin ve onların dayandığı tarihli kayıt; hatırlatıcı ayarların; hanenin telefonunun son eşitlediği hâli ve puanların vardır. Katalogdaki bir yemek katalog tanımlayıcısıyla belirtilir; tarifin kendisi dosyaya kopyalanmaz. Yazdığın bir yemek için uygulamanın yazdığı ve telefonun yedi gün tuttuğu tarif ile oturumun içinde yoktur; bir hane için verdiğin sağlık verisi rızalarının kayıtları da yoktur, onlar sunucumuzda tutulur: support@pinjula.com adresinden iste. Dosyayı sunucumuzda oluşturmuyoruz ve bir kopyasını tutmuyoruz. Bir hanenin listesinde çocuklar da olabileceği için dosya onlar için girilen adları ve beyanları içerir; dosyaya buna göre davran.

Nerede saklanıyor. Frankfurt, Almanya (eu-central-1), Supabase üzerinde. Avrupa pazarlarımızdaki veri AB içinde saklansın diye AB bölgesini seçtik; ona başka kimin, hangi şartlarla ulaşabildiğini aşağıdaki "Hizmet sağlayıcılar ve yurt dışına aktarım" bölümü söylüyor.

Cihaz yedekleri

Telefonunun işletim sistemi, bu uygulamanın verisini olağan cihaz yedeğine dahil edebilir — Android'de Google Drive, iOS'ta iCloud. Bu yedeği telefonun alır, senin kendi bulut hesabına, senin denetiminde. Biz bu işin içinde değiliz, ondan hiçbir şey almıyoruz ve okuyamıyoruz. Android 9 ve sonrasında bu yedekler telefondan çıkmadan önce cihazının PIN'i, deseni ya da parolasıyla şifrelenir.

Bunu kapatmak yerine açık bırakıyoruz, çünkü telefon değiştirdiğinde dolabını, yemek defterini ve haftalık planını geri getiren şey bu. Olmasını istemiyorsan cihazının yedekleme ayarlarından kapatabilirsin — Android'de Ayarlar › Google › Yedekleme, iOS'ta Ayarlar › [adın] › iCloud.

Yedek yerel veritabanının tamamını taşıdığı için, kendin ve hane üyesi olarak eklediğin kişiler için belirttiğin alerjenleri de taşır. Giriş yapmışken, Apple ya da Google hesabının paylaştığı e-posta adresi ve adla birlikte oturumunu da taşır.

Yaklaşan hatırlatıcıların metni ve widget'larının resimleri yedeklenmez, Android'de widget'larının metni de yedeklenmez; uygulama açıldığında verilerinden yeniden oluşturulurlar. iPhone'da widget'larının metni, uygulamanın widget'larıyla paylaştığı depoda durur ve uygulamanın diğer verileri gibi cihaz yedeğine girer; hiçbir alerjeni, diyeti ya da kişiyi anmaz.

Hatırlatıcılar ve ana ekran widget'ları

Hepsi telefonunda hesaplanır, hiçbir yere gönderilmez. Hatırlatıcılar ve widget'lar telefonunda zaten olan bilgilerden oluşur: takvimin, alışveriş listen, dolabında ve elinde hep bulunan temel malzemelerde olanlar (bir widget planlanmış bir yemeğin malzemelerinin evde olup olmadığını söyleyebilsin diye), dolabına girdiğin tarihler, pişirdim diye işaretlediğin yemekler ve resimler — planlanmış bir yemeğin tarif resmi, uygulama onu sana daha önce gösterdiyse, ve uygulamanın kendi malzeme resimleri. Bunları oluşturmak için bize ya da başka birine hiçbir şey gönderilmez, bir widget hiçbir resmi indirmez; arkalarında anlık bildirim (push) servisi yoktur ve uygulamanın hâlâ bir cihaz kimliği ya da bildirim anahtarı yoktur.

Sen açana kadar kapalıdır. Uygulama önce ne yapacağını anlatır ve sorar; Android 13 ve sonrasında telefonun da ayrıca izin ister. Altı türü vardır (günün planı, dolabına girdiğin tarihi yaklaşan ürünler, kimsenin "yendi" demediği artanlar, dolaba girmeyi bekleyen işaretli alışveriş, haftada bir pişirdiklerine bakış ve isteğe bağlı alışveriş günü); günde en fazla üç tane gelir, gece geç saatte hiç gelmez. Ayarlar → Hatırlatıcılar ve widget'lar'dan hepsini ya da her birini ayrı ayrı kapatabilirsin; telefonunun bildirim ayarları da kapatır. Widget'ları ana ekranına sen eklersin ve istediğin zaman kaldırırsın; kaldırmak hiçbir şeyi silmez.

Ekranını görebilen herkes görebilir, bu yüzden sağlık bilgisi taşımazlar. Bir hatırlatıcı kilit ekranında, bir widget ana ekranında görünebilir. Hiçbiri bir alerjiyi, diyeti, intoleransı ya da onu beyan eden kişiyi anmaz. Planlanmış bir yemek hanende beyan edilmiş bir şey içeriyorsa hatırlatıcı yalnızca günün planına bakmak gerektiğini söyler, yemeğin adını bile söylemez; widget da yemeğin hanende beyan edilen bir şey içerdiğini söyler; neyin olduğunu yalnızca uygulamanın içi söyler. Planlanmış bir yemek, planlandıktan sonra hanende beyan edilen bir diyete, laktozdan kaçınmaya ya da sevilmeyen bir şeye artık uymayabilecekse de hatırlatıcı yalnızca plana bakmak gerektiğini söyler; widget yemeği gösterir ve hanende beyan edilen bir şeye uymayabileceğini söyler — yine neyin olduğunu söylemeden. Artan yemek hatırlatıcısı artanı olan yemeklerden en fazla ikisinin adını verir, gerisini sayar. Hanende herhangi birinin beyan ettiği bir şeyi içeren ya da ona artık uymayabilecek bir yemek — o kişinin yemeği ayrı pişirilse bile — yalnızca sayılır, adı hiç yazılmaz; uygulamanın kontrol edemediği bir yemek yalnızca sayılır; hanenin beyanlarını ya da tarif kataloğunu okuyamadığında hiçbir yemeğin adını vermez. Takvimine kendin yazdığın bir yemek adı yazdığın gibi gösterilir. Widget planlanmış bir yemeğin hangi malzemelerinin dolabında olmadığını söylediğinde, bunu hanende beyan edilen bir şeyi içeren ya da ona uymayabilecek bir yemeğin yanında hiçbir zaman söylemez.

Telefonda tutulan küçük bir kopya. Uygulama kapalıyken widget'ın bir şey gösterebilmesi ve hatırlatıcının çıkabilmesi için uygulama, göstereceği metni ve resimleri telefonun kendi uygulama deposunda tutar. Bir şeyi her değiştirdiğinde yenilenir. Resimler ve hatırlatıcıların metni cihaz yedeklerine dahil edilmez, Android'de widget'ların metni de; iPhone'da widget'ların metni uygulamanın diğer verileriyle birlikte cihaz yedeğine girer ("Cihaz yedekleri"ne bak). Hatırlatıcı ayarların uygulamanın diğer verileriyle birlikte yedeklenir.

Bir hatırlatıcı saat vaat etmez. Telefonun pil tasarrufu için hatırlatıcıları geciktirebilir; bazı üreticilerin pil yöneticileri tamamen engelleyebilir.

Fiş tarama — fotoğraf gönderen tek özellik

Yalnızca sen açarsan ve yalnızca dokunduğunda. Dolap ekranında bir market fişinin fotoğrafını çekip ya da bir fotoğrafını seçip üzerindeki yiyecekleri yazmadan dolabına ekletebilirsin. İlk fotoğraf çekilmeden önce uygulama, aşağıdakileri kabul edip etmediğini kendi dilinde sorar; bu onayı istediğin zaman Ayarlar'dan geri çekebilirsin, o zaman uygulama bir sonraki taramadan önce yeniden sorar. Sorunun söyledikleri değişirse de bir sonraki taramadan önce yeniden sorar.

Cihazından ne çıkıyor. Fotoğraf (önce telefonunda küçültülür), görselin türü ve arayüz dilin. Başka hiçbir şey — dolabın, hanen, hesabın ya da profilin değil. Sunucumuza gider; sunucu da satırları okuması için Google'ın Gemini API'sine iletir.

Telefonunun fotoğrafın içine yazdığı bilgiler telefonunda kalır. Resim gönderilmeden önce uygulama, telefonunun dosyaya yazdıklarını — ne zaman ve nerede çekildiğini, telefonun markasını, modelini ve seri numarasını — çıkarır; yalnızca resmin hangi yönde durduğunu bırakır.

Bir fiş ne gösterir, açıkça. Fiş yalnızca bir alışveriş listesi değildir. Nerede alışveriş yaptığını, ne zaman, ne ödediğini ve sepetteki diğer her şeyi — ilaç, bebek maması, alkol, hijyen ürünleri — gösterebilir. Resmin tamamı okunur, çünkü model üzerindeki yiyeceği bulmak için sayfayı görmek zorundadır. Telefonuna dönen şey yalnızca yiyecek ya da içecek olduğuna karar verdiği satırlardır; fişte basılıysa miktar ve birimle. Fiyatlar, toplamlar, mağaza, tarih, kart ve müşteri numaraları ve yiyecek olmayan her satır cevapta yer bulmaz — sunucu yanıtı üç alanlık sabit bir listeden yeniden kurar; modelin başka bir yere yazdığı bir değer yolculuk edemez.

Ne, nerede saklanır. Sunucumuz hiçbir şey saklamaz: fotoğraf saklanmaz, bir kayda yazılmaz ve hangi ürünlerin okunduğunu kaydetmeyiz. Google isteği — fotoğrafla birlikte — yalnızca hizmetinin kötüye kullanılmasını tespit etmek için 55 gün tutar ("Cihazından ne çıkıyor"da anlatıldığı gibi); ona seni tanımlayan hiçbir şey göndermeyiz. Telefonunda uygulama, fotoğraf seçicinin resimden aldığı kopyaları okur okumaz, bir şey gönderilmeden önce siler — gönderdiği küçültülmüş kopyayı ve Android'de, galeriden seçilen bir fotoğraf için seçicinin aldığı tam boy kopyayı. Galerindeki fotoğrafa hiç dokunulmaz. Google'ın isteği ve yanıtını tuttuğu 55 günlük kötüye kullanım kaydı dışında — ki bu kayıt, uygulamaya gönderilen yiyecek satırlarını değil, Google'ın okuduğu her satırı kapsar — dönen liste yalnızca telefonunda saklanır, orada da ancak sen onayladıktan sonra.

Sen olmadan dolabına hiçbir şey girmez. Satırlar incelemen için bir liste olarak gelir; almadıklarının işaretini kaldırırsın ve yalnızca onayladıkların eklenir. Malzeme listemizle eşleştirebildiğimiz bir ürün o malzeme olarak eklenir; eşleştiremediğimiz, okuduğumuz adla eklenir ve öyle işaretlenir — asla sessizce bir komşusuna eşlenmez.

Okuma başarısız olursa uygulama bunu söyler ve hiçbir şey eklenmez.

Bir tarifte sorun bildirmek

Yalnızca sen gönderdiğinde. Her tarifin sonunda — bizimkilerin ve uygulamanın yazdığın bir yemek için yazdıklarının — "Bu tarifte bir sorun bildir" ile neyin yanlış olduğunu bize söyleyebilirsin. Bir neden seçersin (bir malzeme, bir adım, alerjen ya da diyetle ilgili bir kaygı, çeviri, kültürel bir yanlışlık, görsel, rahatsız edici bir şey ya da başka bir şey) ve en fazla 500 karakterlik bir not ekleyebilirsin. "Raporu gönder"e dokunana kadar hiçbir şey gönderilmez. Gönderilemeyen bir rapor, yeniden göndermen ya da kapatman için ekranda kalır; saklanmaz ve sonradan kendiliğinden gönderilmez.

Ne gönderilir. Kataloğumuzdaki bir tarif için: bunun hangi tarif olduğu (katalog tanımlayıcısı), seçtiğin neden, notun ve uygulamanın dili — tarifin kendisi değil, o zaten bizde. Yazdığın bir yemek için uygulamanın yazdığı bir tarifte ise metni raporla birlikte gider: adı, malzemeleri ve adımları; çünkü o tarif yalnızca telefonunda var ve onsuz bir rapor, göremediğimiz bir şey hakkında olurdu. Rapor ekranı bunu sen göndermeden önce söyler. Hesabın, hanen, alerjilerin ya da profilin asla gitmez. Rapor sunucumuza gider ve Frankfurt'taki veritabanımızda saklanır; Google'a hiçbir zaman gitmez, bu yüzden yapay zekâ özellikleri için verdiğin izni gerektirmez.

Ne, ne kadar saklanır. Rapor — seçtiğin neden, notun, dil, gönderildiği gün (günün saati değil) ve tarifin katalog tanımlayıcısı ya da yazılan tarifin metni — 12 ay saklanır, sonra silinir. Hesap, cihaz kimliği, IP adresi ya da gönderen hakkında başka hiçbir şey saklamayız ve telefonuna onu yeniden bulmaya yarayacak hiçbir şey geri göndermeyiz. Bir rapor hakkındaki kendi kayıt satırlarımız yalnızca durum kodlarını tutar, notunu ya da tarifi asla. Her istek gibi o da "Cihazından ne çıkıyor"da anlatılan Cloudflare istek kaydından geçer; bu kayıt geldiği IP adresini en fazla yedi gün tutar, gönderdiğinin gövdesini ise hiçbir zaman.

Lütfen nota kişisel bilgi yazma. Bir rapor seni ona bağlayan hiçbir şey taşımaz; bu yüzden ona cevap veremeyiz, nota yazılan bir ad ya da e-posta adresi de raporun geri kalanı gibi 12 ay tutulur. Cevap istiyorsan ya da bir raporun taşıyamayacağı bir şey söylemek istiyorsan support@pinjula.com adresine yaz. Gönderdiğin bir raporun 12 ayı dolmadan silinmesini istiyorsan onu bulmamıza yetecek kadarını — tarifi, günü ve notunun sözlerini — yazarak bize ulaş; sileriz.

Raporlarla ne yaparız. Kataloğu ve uygulamanın tarif yazma biçimini düzeltmek için okuruz. Bir rapor, bir tarifin değiştirileceği sözü değildir ve bildirdiğin hiçbir şey uygulamanın kimseye gösterdiğini kendiliğinden değiştirmez.

Tarif paylaşma

Paylaş düğmesini kullandığında, uygulama tarifin — ya da bütün bir menünün — düz metin hâlini cihazının normal paylaşım menüsüne verir — nereye gideceği tamamen senin seçimindir (mesajlaşma uygulamaları, notlar vb.) ve biz buna dahil değiliz, göremeyiz. Uygulama, rozetleri için telefonunda bir paylaşım yapıldığını ve hangi gün yapıldığını not eder — neyi ya da kiminle paylaştığını asla.

Kendi fotoğrafınla paylaşma. Pişirdiğin bir yemeğin fotoğrafını da ekleyebilirsin — o anda çekebilir ya da fotoğraflarından seçebilirsin. Uygulama cihazından yalnızca o tek fotoğrafı ister, seçtiğin paylaşım uygulamasına verir ve başka hiçbir şey yapmaz: hiçbir yere yüklenmez ve bize ulaşmaz. Fotoğraf galerini okumuyor, taramıyor veya listelemiyoruz — gördüğün seçici işletim sisteminin kendi seçicisidir ve uygulama yalnızca senin verdiğin tek dosyayı görür. Fotoğraf seçici uygulamanın önbelleğinde, hiç yedeklenmeyen ve telefonun yer gerektiğinde temizlediği geçici bir dosya bırakır. Seçmeden vazgeçersen hiçbir şey olmaz.

Kamera ve fotoğraf izinleri. iOS'ta uygulama kameraya ya da fotoğraflarına erişimi sen dokunduğun anda ister — paylaşılacak bir yemek fotoğrafı ya da okunacak bir fiş için, asla ilk açılışta — ve vermezsen geri kalan her şey çalışmaya devam eder. Android'de uygulama hiçbir kamera ya da fotoğraf izni istemez: fotoğrafı telefonunun kendi kamera uygulaması çeker, sistemin fotoğraf seçicisi seçer.

Puanlar

Hesabın yoksa verdiğin puanlar yalnızca cihazında saklanır.

Hesabın varsa hesabında tutulur, böylece yeni telefonuna seninle gelir. Onları yalnızca senin telefonların alır — hanendeki diğer kişiler değil. Bugün başka hiçbir şey için kullanılmazlar: kullanıcılar arasında toplulaştırmıyoruz, "diğerleri arasında popüler" diye göstermiyoruz ve buradan senin hakkında bir profil çıkarmıyoruz. Bir puanı istediğin zaman değiştirebilirsin. Puanı kaldıracak bir düğme henüz yok; hesabını silmek onları sunucumuzdan, uygulamayı kaldırmak da telefonundan siler.

Hizmet sağlayıcılar ve yurt dışına aktarım

Üç hizmet sağlayıcı kullanıyoruz. Her biri veriyi bizim adımıza ve talimatımızla, hizmetiyle birlikte gelen veri işleme şartları altında işler; bu şartlar onu veriyi korumaya ve yalnızca bize o hizmeti vermek için kullanmaya bağlar — bu politikanın anlattığı korumanın aynısı.

Yani bazı kişisel veriler AB ve Birleşik Krallık dışında, çoğunlukla Amerika Birleşik Devletleri'nde işlenir. Cloudflare ve Google, Avrupa Komisyonu'nun yeterli koruma sağladığına karar verdiği ve uzantılarını Birleşik Krallık ile İsviçre'nin de tanıdığı AB–ABD Veri Gizliliği Çerçevesi'ne sertifikalıdır; üç sağlayıcının da veri işleme şartları, Çerçeve'nin kapsamadığı aktarımlar için Avrupa Komisyonu'nun Standart Sözleşme Maddelerini ve bunların Birleşik Krallık karşılığını içerir. Bu güvencelerin bir kopyasını support@pinjula.com adresinden isteyebilirsin.

Apple ya da Google ile giriş yaptığında o şirket bizim hizmet sağlayıcımız değildir: girişini kendi gizlilik politikası altında yürütür ve bize yalnızca "Giriş yapmak"ta sayılanları gönderir.

Bu uygulamada hiçbir analiz, reklam ya da çökme raporlama SDK'sı kullanmıyoruz; verilerini satmıyor, başka hiç kimseye vermiyoruz.

Her kullanımın hukuki dayanağı (AB, AEA ve Birleşik Krallık)

Bir rızayı geri çekmek, kapsadığı işlemeyi o andan itibaren durdurur; öncesinde yapılanı hukuka aykırı hâle getirmez.

Neyi ne kadar saklıyoruz

Hakların

Nerede yaşarsan yaşa, verinin bir kopyasını isteyebilir, düzeltilmesini ya da silinmesini isteyebilir ve herhangi bir rızanı istediğin zaman geri çekebilirsin. GDPR ya da Birleşik Krallık GDPR'ı sana uygulanıyorsa verinin kullanımını kısıtlama ve itiraz etme ile veri taşınabilirliği hakların da vardır; yaşadığın ya da çalıştığın yerdeki veri koruma otoritesine — Birleşik Krallık'ta Information Commissioner's Office'e — şikâyette bulunabilirsin.

İtiraz hakkın. Meşru menfaatimize dayandığımız yerlerde — istek kayıtları, giriş kayıtları, bir hesap silmeyi tamamlamak, kendi hesabı olmadan eklenen kişilerin bilgileri ve bir tarif hakkındaki raporlar — kendi özel durumunla ilgili gerekçelerle istediğin zaman support@pinjula.com adresine yazarak itiraz edebilirsin. Bir rapor ancak onun hakkında bize söylediklerinden bulunabilir ("Bir tarifte sorun bildirmek"e bak).

Bunların çoğunu uygulamada kendin yapabilirsin: Ayarlar → Hesap ve paylaşım'da Verilerimi dışa aktar ve Hesabı sil var, kendi sağlık verisi rızanı geri çekmek de aynı ekranda; eklediğin biri için "Hanede paylaşmayı bırak" onu ve onun için beyan edilenleri sunucumuzdan siler; fiş tarama rızası da yapay zekâ özellikleri için verdiğin rıza da Ayarlar'dan ayrı ayrı geri çekilir. Başka her şey için ya da uygulamayı kullanamıyorsan support@pinjula.com adresine yaz; bir ay içinde cevap veririz.

Tıbbi veya beslenme tavsiyesi değildir

Uygulama besin değeri gösterdiğinde, bunlar yayımlanmış gıda bileşim veritabanlarından (USDA FoodData Central; koyun eti için Food Standards Australia New Zealand'ın Avustralya Gıda Kompozisyon Veri Tabanı) tarifin malzemelerine uygulanarak hesaplanmış tahminlerdir — gerçekten pişirdiğin yemeğin doğrulanmış bir analizi değildir ve hiçbir zaman tıbbi ya da diyet tavsiyesi olarak değerlendirilmemelidir. Alerjen filtreleme en iyi çabayla yapılan bir güvenlik yardımcısıdır, bir garanti değildir — özellikle bir gıda alerjin varsa, pişirmeden önce malzeme listesinin tamamını mutlaka kendin kontrol et. Uygulama tıbbi bir cihaz değildir; hiçbir hastalığı teşhis etmez, tedavi etmez, iyileştirmez ya da önlemez. Tıbbi tavsiye, teşhis veya tedavi için bir sağlık uzmanına danış.

Çocuklar

Bu uygulama çocuklara yönelik değildir ve bir çocuğun hesap açmasına bilerek izin vermeyiz.

Bununla birlikte bir yetişkin haneye çocuk ekleyebilir — yaş aralıkları ve porsiyon büyüklükleri bunun içindir. Paylaşılan bir hanede çocuğun kaydı sunucumuza ulaşır: onun için yazdığın ad, yaş aralığı, porsiyon büyüklüğü, ayrı tabaktan yiyip yemediği ve kaydettiğin alerjiler, diyetler, intoleranslar ve sevmedikleri. Saklamadan önce yetişkinden açık rıza isteriz, o çocuk hakkında başka hiçbir şey tutmayız (e-posta yok, giriş yok, cihaz kimliği yok, doğum tarihi yok) ve çocuk haneden çıkarıldığında ad ve beyanlar sunucumuzdan anında silinir.

Bu politikadaki değişiklikler

Bu politika değişirse, yukarıdaki yürürlük tarihini güncelleriz, sondaki değişiklik geçmişine bir satır ekleriz ve önemli değişiklikler için uygulamanın sürüm notlarında belirtiriz.

İletişim

Bu politikayla ilgili sorular için: support@pinjula.com


Changelog · Değişiklik geçmişi