Privacy Policy — Pinjula
Effective date: 1 October 2026 Contact: support@pinjula.com
Türkçe metin için aşağı kaydırın. The English text is the authoritative version: if the English and the Turkish differ, the English prevails.
English
Summary
This app is local-first. Your profile, allergies, equipment, pantry, cooking history, favorites, calendar and week plans are stored on your device. The recipe catalogue ships inside the app, so choosing dishes — filtering by your allergens, diet, equipment, pantry and the repeat window — happens on your phone and sends nothing anywhere. The app has no device identifier, we don't use analytics, advertising or crash-reporting SDKs, and we don't sell your data or use it for advertising.
You can use the whole app without an account. A few things do go over the internet, and each is explained below:
- Dish pictures are downloaded from our server the first time the app shows them.
- Four optional features use AI, and each starts only when you tap it: a menu that mixes cuisines, a plan for cooking a whole menu together, a recipe for a dish you typed that our catalogue doesn't have, and reading a photo of a supermarket receipt. Each sends a request through our server to Google's Gemini, and the app asks for your permission before the first one does — one question for the first three, and a separate one for receipts.
- An optional account. If you sign in with Apple or Google, your ratings are kept with your account. If you then create or join a household, its members and what they declared — allergies included, and only after explicit consent — are stored on our database in Frankfurt, Germany.
- Reporting a problem with a recipe, when you choose to, sends your report to our server — and, for a recipe the app wrote for you, that recipe's text. Nothing that identifies you goes with it, and reports are deleted after 12 months.
Your phone's own backup system may also copy this app's data to your cloud account; that is explained too.
Who we are
Pinjula is made and published by an independent developer — "we" and "us" in this policy. We decide how the personal data described here is used, which makes us its controller under the EU and UK General Data Protection Regulation (GDPR). Write to support@pinjula.com about anything in this policy.
What's stored on your device
All of the following lives on your phone, most of it in a local database. None of it is stored on our server unless you sign in, and then only what the marked lines say, for what you choose to share. The AI features described under "What leaves your device" send the specific items listed there when you use them — a dish name you typed onto your calendar, for example — and a report you send about a recipe the app wrote carries that recipe (see "Reporting a problem with a recipe"). Apart from those and your phone's own backups (see "Device backups"), none of it leaves the phone:
- Your profile: household size, diet, skill level, default effort tier, residence country, default cuisine, locale
- Declared allergens and their severity, intolerances, kitchen equipment, pantry staples — your own allergens and intolerances, and the diet in your profile, are also stored on our server if you share yourself with a household
- Household members you add: the name you type for them, their age band, their portion size, whether they eat from a separate plate, and their own allergens, diets, intolerances and disliked ingredients — also stored on our server for each person you choose to share with a household
- Pantry contents
- Suggestion and cooking history, favorited recipes, and the ratings and notes you write — ratings and their notes are also kept with your account while you are signed in
- Shopping list items
- Your calendar and the week plans you've generated
- Each dish you typed onto your calendar and marked as cooked: its name as you typed it, the day, and when you marked it. This record stays on your phone when you clear the calendar, until you undo the mark or uninstall the app
- Each catalogue dish you marked as cooked from the recipe list or your Cookbook: the dish, when you marked it, and your answers about leftovers and whether it counted for everyone. It stays on your phone until you uninstall the app
- When you marked a dish's leftovers as eaten, on the dish's own cooking record
- Your weekly cooking target, the badges you've earned with the day each was earned (for a dish badge, which catalogue dish), and a short log of the actions badges count — sharing a recipe, a menu or a photo, using an AI feature, stocking your pantry from the shopping list, finishing a list, cooking with something within two days of its use-by date. The log keeps the day, never the time, and never what you shared, typed or scanned
- A recipe the app wrote for a dish you typed, shown for seven days (see "What leaves your device")
- Your reminder settings: whether reminders are on, which kinds, at what times, and your quiet hours
- If you agreed to them: the date you allowed the AI features, and the date you allowed receipt scanning, each with which version of the question's words you agreed to
- While you are signed in: your sign-in session — the tokens that keep you signed in, with the email address and name your Apple or Google account shared — which the sign-in library keeps in the app's settings storage until you sign out or delete your account
You can edit or delete most of this from within the app (Settings, the pantry, the shopping list, the calendar). Uninstalling the app deletes this local database along with everything in it.
What leaves your device
Choosing dishes sends nothing. The recipe catalogue is bundled inside the app, so choosing dishes — filtering by your allergens, diet, equipment, pantry and the 7-day repeat window — happens entirely on your phone.
Dish pictures. The pictures of the dishes are too large to ship inside the app, so the app downloads each one from our server the first time it shows it, and keeps it on your phone after that. The download names the picture it wants — which is the name of the catalogue dish it shows — and nothing else: not you, not your household, not your filters.
Four optional features use AI. Each one makes a request to our backend server (a Cloudflare Worker we operate), which passes it to Google's Gemini API and returns the result. All four happen only when you actively ask for them, never in the background:
- A menu that mixes cuisines. Your phone picks the candidate dishes first and sends only what our catalogue already says about them — their identifiers, names, course and hands-on time — along with the interface language, the cuisines you chose, how many menus you want, the courses you asked for and your time limit. Your allergens, your pantry and your household are not sent: the filtering already happened on the phone.
- "How to prepare this menu" — a step-by-step plan for cooking a menu you have already chosen, all of it together. This sends the dishes in that menu — their names, courses, ingredient names and steps — and your interface language. If the menu includes a dish you typed onto your calendar, that means the name as you typed it and the ingredients and steps of the recipe the app wrote for it.
- "Write me a recipe" for a dish you typed onto a day that we don't have in our catalogue. This sends the dish name you typed, your interface language and how many people you're cooking for. Nothing else: not your allergens, not your pantry, not your household. Without an account, this and the cooking plan above are the only places in the app where text you typed yourself goes to Google, so treat that box the way you would any other box whose contents get sent. (The note you add to a report about a recipe also leaves the device, with or without an account; with an account, so do the notes you write on ratings, and with a household the names you type for it and its members — but all of those go to our database, never to Google.) Two things narrow it further: the app checks the name on your phone first, and if it doesn't look like a dish name the button isn't offered at all — so that text is never sent anywhere. And if we do send it and the answer is that it isn't food, we don't count it.
- Reading a receipt — the one feature that sends a photograph. It has its own section below.
Your permission comes first. The first time you reach for one of the first three features — turning on "Mix them into one menu", opening "How to prepare this menu" or tapping "Write me a recipe" — the app asks one question that covers all three. It names each feature, says what it sends, as listed above, says that the request goes through our server to Google's Gemini, and points to this policy for what is kept and for how long. Nothing is sent until you choose "Allow". The question is never asked when the app starts or while you are setting it up. If you choose "Not now", nothing is sent and everything else keeps working: menus stay within one cuisine at a time, every dish keeps its own recipe, and a dish you typed stays on your calendar under the name you gave it; where the AI part would have been, the app says why it is missing and offers the question again. You can withdraw your permission at any time in Settings → AI features. From then on none of the three sends anything until you agree again; a recipe already written for a typed dish stays on your phone for the rest of its week. The app keeps only the date you agreed and which version of the question's words you agreed to, on your phone; if the words change in what they say, the app asks again the next time you reach for one of the three — never when it starts. Reading a receipt has its own, separate question — agreeing to one is not agreeing to the other.
None of these requests carries an identifier for you or your phone. The app has no device identifier, and the requests carry no account and no notification token. We don't keep the menus, instructions or recipes that come back — unless you report a problem with a recipe the app wrote, which sends us its text (see "Reporting a problem with a recipe").
One thing we record from any of this: the dish name. When you ask us to write a recipe for a dish our catalogue doesn't have, we count that name — so that if a few hundred people ask for the same dish, we know to add it properly. What we store is the name, how it was most recently spelled, a running count, the interface languages it was asked in, and the dates it was first and last asked for. A name is counted unless the check on your phone or on our server turns it away as not a dish name, or the answer is that it isn't food — it is counted even when the recipe could not be written. Not attached to you: no device identifier, no account, no address. For a name only one person has ever asked for, though, those two dates are when that person asked.
The recipe written for you stays on your phone for a week. The app shows it for seven days so that it doesn't change under you halfway through cooking it. After that it is no longer shown, and it is deleted the next time you open the app (or when the app next writes a recipe for you, or when you uninstall it). It is stored on our server only if you report a problem with it, and then as the report describes (see "Reporting a problem with a recipe").
What Google does with these requests. We use Gemini as a paid service. Under Google's terms for it, Google doesn't use what we send — photographs included — or what it returns to improve its products, and it processes them on our behalf under its data processing terms. Google keeps requests and responses for 55 days solely to detect and prevent misuse of its service, and during that time authorized Google staff may review them for that purpose. Google may process them in any country where it or its sub-processors have facilities.
What any request reveals. Every connection to a server shows it the IP address it came from. Cloudflare, which runs our server, keeps a record of each request it receives for up to seven days, to run and secure the service: the time, the address requested — for a dish picture, that address is the picture's name, which names the catalogue dish — the IP address it came from, the approximate location Cloudflare works out from that IP address (such as the country, region and city), and the request's technical headers, such as the name and version of the software making it. That record never contains a photograph, a dish name you typed or anything else in the body of what you send. Our own log lines never contain a photograph. For "Write me a recipe", receipts and reports they hold only counts and status or error codes. For the two menu features, a request that fails, or whose answer has to be partly thrown away, can be logged with the catalogue dishes it was about. A failed one can also be logged with the reply Google sent back, which can repeat what was sent — including a dish name you typed and the recipe written for it. We don't use any of these logs to identify or locate anybody.
A failure here never costs you a recipe. If a mixed-cuisine menu request fails, the app builds the menu on the phone instead; if the cooking plan fails, you can try again and each dish's own recipe is still there; if "Write me a recipe" fails, the dish stays on your calendar under the name you typed.
Your account and your household — optional
Signing in is a choice, and everything above keeps working if you never do. What an account is for is keeping your ratings across phones and sharing with the people you live with.
Signing in. You sign in with your Apple or Google account — there is no password of ours. Your phone talks directly to our authentication provider, Supabase, which receives: from Google, your name, your email address, the web address of your profile picture and your Google account identifier (and, for a Google Workspace account, its domain); from Apple, your email address — with "Hide My Email", a relay address — and your Apple account identifier, plus your name only if Apple passes it on. Supabase keeps these, your active sign-in sessions and a log of sign-in events, including the IP address they came from, to keep accounts secure. Apple and Google handle the sign-in itself under their own privacy policies.
What an account keeps, even without a household. The ratings and notes you give recipes, so they follow you to a new phone. When you sign in, the ratings already on the phone are copied to your account.
What syncs to our server once you create or join a household. This list is exhaustive:
- The household's name
- For each person shared with the household: the name you type, their age band, their portion size, whether they eat from a separate plate, whether they have their own account, and who owns the household
- The allergens, diets, intolerances and disliked ingredients recorded for each of them — this is health information, and a diet such as halal or kosher can also reveal a religious belief; both are special categories of personal data under the GDPR, which is why we ask for consent separately before it is stored (see below)
- The record that consent was given: which text, in which language, on which date, for which member — and nothing about the declaration itself
- Invitation codes, stored only as a one-way hash, never the code itself
What is not sent, even in a household: your shopping list, your calendar and week plans, your pantry, your suggestion and cooking history, your favorites, your equipment, your staples and the rest of your profile (household size, skill level, effort tier, residence country, default cuisine, language). They stay on your phone.
Consent for health data. Before a person's details are first stored with the household — whether or not anything is declared for them yet — the app asks you to agree explicitly, and it asks again after the app has been restarted, before the next change to their declarations. The question says what is stored — health information, and for a diet such as halal or kosher a religious belief — who can see it, why, and what saying no costs; this policy says where it is stored and for how long. We store the fact that you agreed: which text, in which language, on which date, for which member. You can withdraw that consent, and doing so deletes those declarations from the server.
Who in the household can see and change it. Everyone signed in to the household can see every member's declarations. Who may change them depends on the member. A member who signs in with their own account is the only one who records, changes, consents to and withdraws their own declarations. For a member who has no login of their own — a child, or a guest you added by name — that is the household's owner — the account that created the household, or the one ownership later passed to; another adult who joined by invitation sees those declarations but cannot edit them. The owner is also the only one who adds people to the household and who can remove a member who signs in with their own account. A person who has no account of their own can be removed by any member of the household, and removing them deletes their name and declarations from our server. Anybody can leave. A household is people who cook together and the app is built on that assumption. If that is not your situation, keep the declarations on your phone and do not join a household.
Removing a member. When someone is removed from a household, their name, age band and declarations are deleted from our server immediately. What remains there is a marker with no personal information in it, whose only job is to tell the other phones in the house that this person is no longer a member; it is erased after 30 days. Those phones keep the person, with what was declared for them, as an entry on their own list — so nobody's food is suddenly filtered less carefully without them knowing — until someone removes them there.
Deleting your account. Settings → Account & sharing → Delete account. This immediately deletes your account, your ratings and your household membership — your name and your declarations there — and marks the consents you gave as withdrawn, including those you gave for people without an account. If you owned the household, ownership passes to the member with an account who joined earliest. While other members with an account remain, the people added without an account stay in the household with what was declared for them, managed from then on by its owner, even though the consent you gave for them is now marked withdrawn; if you want them off our server, remove them from the household first. Leaving a household works the same way. If you were its last member with an account, the whole household is deleted from our server with it, including the people added without an account and their declarations. Your sign-in is then deleted from our authentication provider, normally within fifteen minutes; if that fails we keep retrying, and we keep the request on file until it succeeds rather than quietly dropping it. Deleting your account does not delete the local database on your phone — uninstalling does that — and does not remove the entries other phones in the household keep, described above. It also doesn't remove this app from the list of apps connected to your Apple or Google account; you can remove it there yourself. If you can't use the app, email support@pinjula.com from, or naming, the email address of the account you signed in with; we confirm with that address, then delete the account, within one month at the latest.
Getting a copy of your data. Settings → Account & sharing → Export my data. The file is assembled on your phone and handed to your device's share sheet. It contains your account's email address; your profile (such as your language, cuisine, residence country, household size, skill level, effort tier, weekly cooking target and when you last reset the repeat filter); the dates you allowed the AI features and receipt scanning, and which version of each question's words; the people on your household list with what was declared for them; your kitchen equipment and pantry staples; your suggestion and cooking history; your favorites; your pantry; your shopping list; your calendar and week plans, including each dish you typed onto a day, in your own words; the dishes you typed and marked as cooked; the dishes you marked as cooked from the recipe list or your Cookbook; your badges and the dated log behind them; your reminder settings; the household as your phone last synced it; and your ratings. A dish from our catalogue is named by its catalogue identifier; the recipe itself is not copied into the file. It does not contain a recipe the app wrote for a dish you typed, which the phone keeps for seven days, or your sign-in session, and it does not contain the records of the health-data consents you gave for a household, which are kept on our server: ask for them at support@pinjula.com. We do not build the file on our server or keep a copy of it. Because a household's roster can include children, the export contains the names and declarations entered for them; treat the file accordingly.
Where it is stored. Frankfurt, Germany (eu-central-1), on Supabase. We chose an EU region so that data from our European markets is stored in the EU; "Service providers and international transfers" below says who else can reach it and on what terms.
Device backups
Your phone's operating system may include this app's data in its normal device backup — Google Drive on Android, iCloud on iOS. That backup is made by your phone, into your own cloud account, under your control. We are not involved in it, we receive nothing from it, and we cannot read it. On Android 9 and later these backups are encrypted with your device's PIN, pattern or password before they leave the phone.
We leave this on rather than off, because it is what restores your pantry, your cookbook and your week plan when you change phones. If you would rather it did not happen, your device's backup settings turn it off — on Android, Settings › Google › Backup; on iOS, Settings › [your name] › iCloud.
Because the backup carries the whole local database, it carries the allergens you declared for yourself and for anyone you added as a household member. While you are signed in it also carries your sign-in session, with the email address and name your Apple or Google account shared.
The text of upcoming reminders and the pictures on your widgets are not backed up, and on Android neither is your widgets' text; they are rebuilt from your data when the app opens. On iPhone your widgets' text sits in storage the app shares with its widgets and goes into a device backup like the rest of the app's data; it names no allergen, diet or person.
Reminders and home-screen widgets
Worked out on your phone, and nothing is sent anywhere. Reminders and widgets are made from what is already on your phone: your calendar, your shopping list, what your pantry and the staples you keep hold (so a widget can say whether a planned dish's ingredients are there), the dates you entered in your pantry, the dishes you marked as cooked, and pictures — the recipe picture of a planned dish once the app has already shown it to you, and the app's own ingredient pictures. Nothing is sent to us or to anyone else to produce them, and a widget never downloads a picture. There is no push service behind them, and the app still has no device identifier or notification token.
Off until you turn them on. The app explains what it will do and asks first; on Android 13 and later your phone asks as well. There are six kinds (the day's plan, pantry items close to a date you entered, leftovers nobody has marked as eaten, ticked shopping waiting to go into your pantry, a weekly look at what you cooked, and an optional shopping day), at most three a day and never late at night. Settings → Reminders and widgets turns them all off or each kind separately, and so do your phone's notification settings. You add widgets to your home screen yourself and can remove them at any time; removing one deletes nothing.
Anyone who can see your screen can see them, so they carry no health information. A reminder can appear on your lock screen and a widget on your home screen. Neither ever names an allergy, a diet, an intolerance or the person who declared it. When a planned dish contains something your household declared, the reminder says only that the day's plan needs a look, without naming the dish, and the widget says the dish contains something declared in your household; only the app itself says what. When a planned dish may no longer fit a diet, lactose avoidance or dislike your household declared after planning it, the reminder likewise says only that the plan needs a look, and the widget keeps the dish and says it may not fit something declared in your household — again without saying what. The leftovers reminder names up to two of the dishes that still have leftovers and counts the rest. A dish that contains something anyone in your household declared, or may no longer fit it, is only counted, never named — even when that person's meals are cooked separately; a dish the app cannot check is only counted, and when it cannot read your household's declarations or the recipe catalogue, it names none. A dish name you typed onto your calendar is shown as you typed it. When the widget says which of a planned dish's ingredients are missing from your pantry, it never says so beside a dish that contains or may not fit something declared in your household.
A small copy kept on the phone. So that a widget can show something and a reminder can appear while the app is closed, the app keeps the text and the pictures they will display in its own storage on your phone. It is replaced whenever you change something. The pictures and the reminders' text are excluded from device backups, and so is the widgets' text on Android; on iPhone the widgets' text goes into a device backup with the rest of the app's data (see "Device backups"). Your reminder settings are backed up with the rest of the app's data.
A reminder does not promise a time. Your phone may delay reminders to save battery, and some manufacturers' battery managers can block them.
Scanning a receipt — the one feature that sends a photograph
Only if you switch it on, and only when you tap. On the pantry screen you can photograph a supermarket receipt, or choose a photo of one, and have the food on it added to your pantry without typing. Before the first photograph is taken the app asks you, in your own language, whether you agree to what follows; you can withdraw that agreement at any time in Settings, after which the app asks again before the next scan. It also asks again before the next scan if the words of the question change in what they say.
What leaves your device. The photograph (reduced in size on your phone first), the image type, and your interface language. Nothing else — not your pantry, your household, your account or your profile. It goes to our backend server, which passes it to Google's Gemini API to read the lines on it.
The details your phone stores inside a photo stay on your phone. Before the picture is sent, the app takes out what your phone wrote into the file — when and where it was taken, and the phone's make, model and serial number — and keeps only which way up the picture is.
What a receipt shows, said plainly. A receipt is not just a list of groceries. It can show where you shopped, when, what you paid, and everything else in the basket — medicine, baby formula, alcohol, hygiene products. The whole picture is read, because the model has to see the page to find the food on it. What comes back to your phone is only the lines it judged to be food or drink, with a quantity and unit where the receipt printed one. Prices, totals, the store, the date, card and loyalty numbers and every non-food line have no place in the answer — the server rebuilds the reply from a fixed list of three fields, so a value the model wrote anywhere else cannot travel.
What is kept, and where. Our server keeps nothing: the photograph is not stored and not written to a log, and we do not record which items were read. Google keeps the request — the photograph with it — for 55 days solely to detect misuse of its service, as described under "What leaves your device"; we send it no identifier for you. On your phone, the app deletes the photo picker's copies of the picture as soon as it has read them, before anything is sent — the reduced one it sends and, on Android, the full-size copy the picker makes of a photo chosen from your gallery. The photo in your gallery is never touched. Apart from Google's 55-day misuse log of the request and its reply — which covers every line Google read, not only the food lines the app is sent — the list that comes back is stored only on your phone, and there only once you have confirmed it.
Nothing reaches your pantry without you. The lines come back as a list you review; you untick what you did not buy, and only what you confirm is added. An item we could match to our ingredient list is added under that ingredient; one we could not is added by the name we read and marked as such — never silently mapped onto a neighbour.
If reading fails, the app says so and nothing is added.
Reporting a problem with a recipe
Only when you send one. At the foot of every recipe — ours, and the ones the app writes for a dish you typed — "Report a problem with this recipe" lets you tell us what is wrong. You pick a reason (an ingredient, a step, an allergen or diet concern, the translation, a cultural inaccuracy, the picture, something offensive, or something else) and can add a note of up to 500 characters. Nothing is sent until you tap "Send report". A report that could not be sent stays on the screen for you to send again or close; it is not kept, and it is not sent later on its own.
What is sent. For a recipe from our catalogue: which recipe it is (its catalogue identifier), the reason, your note and the app's language — not the recipe itself, which we already have. For a recipe the app wrote for a dish you typed, its text goes with the report: the title, the ingredients and the steps, because that recipe exists only on your phone and a report without it would be about nothing we can see; the report screen says so before you send. Never your account, your household, your allergies or your profile. A report goes to our server and is stored in our database in Frankfurt; it never goes to Google, so asking for it does not need your permission for the AI features.
What is kept, and for how long. The report — the reason, your note, the language, the day it was sent (not the time of day), and either the recipe's catalogue identifier or the written recipe's text — is kept for 12 months and then deleted. We store no account, no device identifier, no IP address and nothing else about who sent it, and we send nothing back to your phone that could find it again. Our own log lines about a report hold only status codes, never your note or the recipe. Like every request, it passes through Cloudflare's request record described under "What leaves your device", which keeps the IP address it came from for up to seven days and never the body of what you send.
Please keep personal details out of the note. A report carries nothing that links it to you, so we cannot reply to it, and a name or an email address written into the note would be kept for the 12 months like the rest of it. If you want an answer, or want to tell us something a report cannot carry, write to support@pinjula.com. If you want a report you sent deleted before its 12 months are up, write to us with enough to find it — the recipe, the day and the words of your note — and we will delete it.
What we do with reports. We read them to correct the catalogue and the way the app writes recipes. A report is not a promise that a recipe will be changed, and nothing you report changes what the app shows anyone by itself.
Sharing a recipe
If you use the share button, the app hands a plain-text version of the recipe — or of a whole menu — to your device's normal share sheet — that's entirely your choice of where it goes (messaging apps, notes, etc.) and isn't something we're involved in or see. For its badges, the app notes on your phone that a share happened, and on which day — never what you shared or with whom.
Sharing with your own photo. You can also attach a photo of a dish you cooked, either taken then and there or chosen from your photos. The app asks your device for that one picture, passes it to the share sheet you choose, and does nothing else with it: it is never uploaded and we never receive it. We do not read, browse or index your photo library — the picker your device shows is the operating system's own, and the app only ever sees the single file you hand it. The photo picker leaves a temporary file in the app's cache, never backed up, which your phone clears when it needs space. If you back out without choosing, nothing happens at all.
Camera and photo permissions. On iOS the app asks for access to the camera or to your photos at the moment you tap — for a dish photo to share or for a receipt to read, never on first launch — and declining leaves everything else working. On Android the app asks for no camera or photo permission at all: your phone's own camera app takes the picture and the system photo picker chooses it.
Ratings
Without an account, ratings you give are stored only on your device.
With an account they are kept with it, so they follow you to a new phone. Only your own phones receive them — not the other people in your household. Today they are used for nothing else: we don't aggregate them across users, we don't show them as "popular with others", and we don't build a profile of you from them. You can change a rating at any time. There is no button to remove one yet; deleting your account deletes them from our server, and uninstalling the app deletes them from your phone.
Service providers and international transfers
We use three service providers. Each processes the data on our behalf and on our instructions, under the data processing terms that come with its service, which bind it to protect the data and to use it only to provide that service to us — the same protection this policy describes.
- Cloudflare, Inc. runs our backend server and stores the dish pictures. Cloudflare is a US company, and our server runs on its global network, in whichever of its data centres receives your request. Its request logs (see "What leaves your device") are kept in our Cloudflare account.
- Supabase, Inc. runs our database — accounts, households, ratings, the dish-name counts and recipe reports — and our sign-in service. The database is in Frankfurt, Germany; Supabase is a US company, and its terms allow it and its sub-processors to process the data from other countries — to operate and support the service, for example.
- Google (the Gemini API) processes the four AI requests. Google may process them in any country where it or its sub-processors have facilities.
So some personal data is processed outside the EU and the UK, mainly in the United States. Cloudflare and Google are certified under the EU–US Data Privacy Framework, which the European Commission has found to give adequate protection, and whose extensions the UK and Switzerland recognise; and all three providers' data processing terms include the European Commission's Standard Contractual Clauses, with their UK equivalent, for transfers the Framework does not cover. You can ask us for a copy of these safeguards at support@pinjula.com.
When you sign in with Apple or Google, that company is not our service provider: it handles your sign-in under its own privacy policy and sends us only what "Signing in" lists.
We don't use any analytics, advertising or crash-reporting SDKs in this app, and we don't sell your data or give it to anybody else.
The legal basis for each use (EU, EEA and UK)
- Providing the app and what you ask of it — dish pictures, your account, your household: necessary to provide the service you asked for (GDPR Article 6(1)(b)).
- The mixed-cuisine menu, the cooking plan and "Write me a recipe": your consent (Article 6(1)(a)), asked in the app before the first request and withdrawable in Settings.
- Allergies, diets, intolerances and disliked ingredients stored with a household: your explicit consent (Article 9(2)(a)), asked in the app for each person and withdrawable at any time.
- People you add who have no account of their own: their name, age band, portion size and separate-plate choice rest on our legitimate interest, and theirs, in the household's meals being planned for them too (Article 6(1)(f)). Their allergies, diets, intolerances and dislikes rest on the explicit consent you give for them — as the person responsible for a child, and for another adult only with their agreement, which the app asks you to get first.
- Receipt photos: your consent (Article 6(1)(a)), and your explicit consent (Article 9(2)(a)) wherever a receipt shows something about your health; withdrawable in Settings.
- Reports about a recipe: our legitimate interest, and that of everyone who cooks from the app, in recipes that are correct (Article 6(1)(f)). You decide to send each one, and it carries nothing that identifies you.
- Request logs, sign-in logs and finishing account deletions: our legitimate interest in running a service that is secure and does what it promises (Article 6(1)(f)).
- Keeping a record that consent was given: our legal obligation to be able to show it (Articles 6(1)(c) and 7(1)).
Withdrawing a consent stops what it covered from then on; it doesn't make unlawful what was done before.
How long we keep things
- On your phone: until you delete it or uninstall the app. A recipe the app wrote for a dish you typed: shown for seven days, then deleted the next time the app writes one, or when you uninstall. The text and pictures prepared for reminders and widgets: replaced whenever your data changes. The date you allowed the AI features or receipt scanning: until you withdraw it in Settings.
- Your account and your ratings: until you delete your account. Your sign-in at Supabase is then deleted too, normally within fifteen minutes (see "Deleting your account").
- A household's members and their declarations: until the member is removed, the consent is withdrawn or the household ends. A removed member leaves a marker with no personal information for 30 days. A member with an account who leaves or deletes their account while others with an account remain leaves the people without an account, and what was declared for them, with the household. When the last member with an account leaves or deletes their account, the household and everything in it is deleted.
- Consent records: kept, because we must be able to show that consent was asked. When the account or the member a record is about is deleted, its link to that person is removed, and what remains — a text version, a language and dates — names nobody.
- Dish names counted for "Write me a recipe": kept as counts, with the dates each name was first and last asked for, never linked to an account or a device.
- Reports about a recipe: 12 months from the day they were sent, then deleted — never linked to an account or a device.
- Logs: Cloudflare's request logs, up to seven days; Google's logs of the AI requests, 55 days; Supabase's logs of sign-in events, under Supabase's log retention for our project.
Your rights
Wherever you live, you can ask us for a copy of your data, ask us to correct or delete it, and withdraw any consent at any time. If the GDPR or the UK GDPR applies to you, you also have the rights to restrict or object to our use of your data and to data portability, and you can complain to the data protection authority where you live or work — in the UK, the Information Commissioner's Office.
Your right to object. Where we rely on our legitimate interest — request logs, sign-in logs, finishing an account deletion, the details of people added without an account of their own, and reports about a recipe — you can object at any time, on grounds relating to your particular situation, by writing to support@pinjula.com. A report can be found only from what you tell us about it (see "Reporting a problem with a recipe").
Most of this you can do in the app yourself: Settings → Account & sharing has Export my data and Delete account, and withdrawing your own health-data consent is on the same screen; for someone you added, "Stop sharing with the household" deletes them and what was declared for them from our server; the receipt-scanning consent and the consent for the AI features are each withdrawn in Settings. For anything else, or if you can't use the app, email support@pinjula.com; we reply within one month.
Not medical or nutritional advice
Where the app shows nutrition figures, they are estimates calculated from published food-composition databases (USDA FoodData Central; for mutton, the Australian Food Composition Database by Food Standards Australia New Zealand) applied to a recipe's ingredients — not a verified analysis of the food you actually cook, and never medical or dietary advice. Allergen filtering is a best-effort safety aid, not a guarantee — always check the full ingredient list yourself before cooking, especially if you have a food allergy. The app is not a medical device and does not diagnose, treat, cure or prevent any medical condition; for medical advice, diagnosis or treatment, consult a healthcare professional.
Children
This app isn't directed at children and we don't knowingly let a child create an account.
An adult can, however, add a child to a household — that is what the age bands and portion sizes are for. In a shared household the child's entry reaches our server: the name you typed for them, their age band, their portion size and whether they eat from a separate plate, and any allergies, diets, intolerances and dislikes you record. We ask the adult for explicit consent before storing it, we hold nothing else about that child (no email address, no sign-in, no device identifier, no date of birth), and removing the child from the household deletes the name and the declarations from our server at once.
Changes to this policy
If this policy changes, we'll update the effective date above, add a line to the changelog at the end, and, for material changes, note it in the app's release notes.
Contact
Questions about this policy: support@pinjula.com
Türkçe
Özet
Bu uygulama yerel öncelikli çalışır. Profilin, alerjilerin, mutfak ekipmanın, dolabın, pişirme geçmişin, favorilerin, takvimin ve haftalık planların cihazında saklanır. Tarif kataloğu uygulamanın içinde geldiği için yemek seçimi — alerjenlerine, diyetine, ekipmanına, dolabına ve tekrar penceresine göre süzme — telefonunda yapılır ve hiçbir yere hiçbir şey göndermez. Uygulamanın cihaz kimliği yoktur; analiz, reklam ya da çökme raporlama SDK'sı kullanmayız; verilerini satmaz, reklam için kullanmayız.
Uygulamanın tamamını hesap açmadan kullanabilirsin. Yine de bazı şeyler internetten geçer ve her biri aşağıda anlatılıyor:
- Yemek görselleri, uygulama onları ilk gösterdiğinde sunucumuzdan indirilir.
- İsteğe bağlı dört özellik yapay zekâ kullanır ve her biri yalnızca sen dokunduğunda başlar: mutfakları karıştıran bir menü, bir menünün tamamını birlikte pişirme planı, kataloğumuzda olmayan ve senin yazdığın bir yemek için tarif, ve bir market fişi fotoğrafının okunması. Her biri sunucumuz üzerinden Google'ın Gemini'sine bir istek gönderir ve uygulama, bunlardan ilki bir şey göndermeden önce senden izin ister — ilk üçü için tek bir soru, fişler için ayrı bir soru.
- İsteğe bağlı bir hesap. Apple ya da Google ile giriş yaparsan puanların hesabında tutulur. Ardından bir hane kurar ya da bir haneye katılırsan, hanenin üyeleri ve onlar için beyan edilenler — alerjiler dahil, yalnızca açık rızadan sonra — Frankfurt'taki (Almanya) veritabanımızda saklanır.
- Bir tarifte sorun bildirmek, sen istediğinde, raporunu sunucumuza gönderir — uygulamanın senin için yazdığı bir tarifte o tarifin metnini de. Seni tanımlayan hiçbir şey onunla gitmez ve raporlar 12 ay sonra silinir.
Telefonunun kendi yedekleme sistemi de bu uygulamanın verisini senin bulut hesabına kopyalayabilir; o da anlatılıyor.
Biz kimiz
Pinjula, bağımsız bir geliştirici tarafından yapılır ve yayımlanır — bu politikadaki "biz" odur. Burada anlatılan kişisel verilerin nasıl kullanılacağına biz karar veririz; bu da AB ve Birleşik Krallık Genel Veri Koruma Tüzüğü (GDPR) açısından bizi veri sorumlusu yapar. Bu politikadaki herhangi bir konu için support@pinjula.com adresine yaz.
Cihazında saklananlar
Aşağıdakilerin hepsi telefonunda, çoğu yerel bir veritabanında tutulur. Giriş yapmadıkça hiçbiri sunucumuzda saklanmaz; giriş yaptığında da yalnızca işaretli satırların söylediği, paylaşmayı seçtiklerin için saklanır. "Cihazından ne çıkıyor" altında anlatılan yapay zekâ özellikleri, onları kullandığında orada sayılan belirli şeyleri gönderir — örneğin takvimine yazdığın bir yemek adını. Uygulamanın yazdığı bir tarif hakkında gönderdiğin bir rapor da o tarifi taşır ("Bir tarifte sorun bildirmek"e bak). Bunlar ve telefonunun kendi yedekleri ("Cihaz yedekleri"ne bak) dışında hiçbiri telefondan çıkmaz:
- Profilin: hane büyüklüğü, diyet, beceri seviyesi, varsayılan efor seviyesi, ikamet ülken, varsayılan mutfak, dil
- Belirttiğin alerjenler ve şiddet dereceleri, intoleranslar, mutfak ekipmanların, temel malzemelerin — kendini bir haneyle paylaşırsan kendi alerjenlerin ve intoleransların, profilindeki diyetle birlikte, ayrıca sunucumuzda saklanır
- Eklediğin hane üyeleri: onlar için yazdığın ad, yaş aralığı, porsiyon büyüklüğü, ayrı tabaktan yiyip yemediği ve kendi alerjenleri, diyetleri, intoleransları ve sevmedikleri malzemeler — bir haneyle paylaşmayı seçtiğin her kişi için ayrıca sunucumuzda saklanır
- Dolap içeriğin
- Öneri ve pişirme geçmişin, favori tariflerin ve yazdığın puanlar ile notlar — giriş yapmışken puanlar ve notları ayrıca hesabında tutulur
- Alışveriş listesi öğeleri
- Takvimin ve oluşturduğun haftalık planlar
- Takvimine kendin yazıp pişirildi diye işaretlediğin her yemek: yazdığın hâliyle adı, günü ve ne zaman işaretlediğin. Bu kayıt takvimi temizlediğinde de telefonunda kalır; işareti geri alana ya da uygulamayı kaldırana kadar
- Tarif listesinden ya da Yemek defterinden pişirildi diye işaretlediğin her katalog yemeği: yemek, ne zaman işaretlediğin ve artan porsiyon ile herkes için sayılıp sayılmadığı hakkındaki cevapların. Uygulamayı kaldırana kadar telefonunda kalır
- Bir yemeğin artanını ne zaman "yendi" diye işaretlediğin, o yemeğin kendi pişirme kaydında
- Haftalık pişirme hedefin, kazandığın rozetler ve her birinin kazanıldığı gün (yemek rozetinde hangi katalog yemeği olduğu) ve rozetlerin saydığı işlerin kısa bir kaydı — bir tarif, bir menü ya da bir fotoğraf paylaşmak, bir yapay zekâ özelliğini kullanmak, alışveriş listesinden dolabı doldurmak, bir listeyi bitirmek, son kullanma tarihine iki gün kalmış bir malzemeyle pişirmek. Kayıt günü tutar; saati, paylaştığını, yazdığını ya da taradığını asla tutmaz
- Yazdığın bir yemek için uygulamanın yazdığı tarif, yedi gün boyunca gösterilir ("Cihazından ne çıkıyor"a bak)
- Hatırlatıcı ayarların: açık olup olmadıkları, hangi türlerin açık olduğu, saatleri ve sessiz saatlerin
- İzin verdiysen: yapay zekâ özelliklerine izin verdiğin tarih ve fiş taramaya izin verdiğin tarih; her biri, sorunun hangi sürümüne izin verdiğinle birlikte
- Giriş yapmışken: oturumun — seni girişli tutan anahtarlar, Apple ya da Google hesabının paylaştığı e-posta adresi ve adla birlikte; giriş kütüphanesi bunları sen çıkış yapana ya da hesabını silene kadar uygulamanın ayar deposunda tutar
Bunların çoğunu uygulama içinden (Ayarlar, dolap, alışveriş listesi, takvim) düzenleyebilir ya da silebilirsin. Uygulamayı kaldırmak bu yerel veritabanını içindeki her şeyle birlikte siler.
Cihazından ne çıkıyor
Yemek seçmek hiçbir şey göndermez. Tarif kataloğu uygulamanın içinde geldiği için yemek seçimi — alerjenlerine, diyetine, ekipmanına, dolabına ve 7 günlük tekrar penceresine göre süzme — tamamen telefonunda yapılır.
Yemek görselleri. Yemeklerin görselleri uygulamanın içine sığmayacak kadar büyük; bu yüzden uygulama her birini ilk gösterdiğinde sunucumuzdan indirir ve sonra telefonunda tutar. İndirme isteği yalnızca istenen görselin adını taşır — bu da gösterdiği katalog yemeğinin adıdır: seni, haneni ya da süzgeçlerini değil.
İsteğe bağlı dört özellik yapay zekâ kullanır. Her biri işlettiğimiz arka uç sunucusuna (bir Cloudflare Worker) istek gönderir; sunucu bunu Google'ın Gemini API'sine iletir ve sonucu döndürür. Dördü de yalnızca sen istediğinde çalışır, arka planda asla:
- Mutfakları karıştıran menü. Aday yemekleri önce telefonun seçer ve yalnızca kataloğumuzun onlar hakkında zaten söylediklerini gönderir — katalog kısaltmaları, adları, kursları ve aktif iş süreleri — yanında arayüz dili, seçtiğin mutfaklar, kaç menü istediğin, istediğin kurslar ve süre sınırın. Alerjenlerin, dolabın ve hanen gönderilmez: süzme zaten telefonda yapıldı.
- "Menünün hazırlanışı" — zaten seçmiş olduğun bir menünün hepsini birlikte pişirmek için adım adım plan. Bu, o menüdeki yemekleri — adlarını, yemek türlerini, malzeme adlarını ve adımlarını — ve arayüz dilini gönderir. Menüde takvimine kendin yazdığın bir yemek varsa bu, onun yazdığın hâliyle adı ve uygulamanın onun için yazdığı tarifin malzemeleri ile adımları demektir.
- "Bana bir tarif yaz" — takvimine yazdığın ve kataloğumuzda olmayan bir yemek için. Bu, yazdığın yemek adını, arayüz dilini ve kaç kişilik pişirdiğini gönderir. Başka hiçbir şeyi: alerjenlerini değil, dolabını değil, haneni değil. Hesabın yoksa uygulamada kendi yazdığın metnin Google'a gittiği yerler yalnızca burası ve yukarıdaki pişirme planıdır; o kutuya, içindekiler gönderilecek herhangi bir kutu gibi davran. (Bir tarif hakkındaki rapora eklediğin not da, hesabın olsun olmasın, cihazdan çıkar; hesabın varsa puanlara yazdığın notlar da, bir hanen varsa hane ve üyeleri için yazdığın adlar da — ama bunların hepsi veritabanımıza gider, Google'a asla.) İki şey bunu daha da daraltıyor: uygulama adı önce telefonunda kontrol ediyor, bir yemek adına benzemiyorsa düğmeyi hiç sunmuyor — yani o metin hiçbir yere gitmiyor. Gönderdiğimiz hâlde cevap bunun yiyecek olmadığıysa onu saymıyoruz.
- Bir fişin okunması — fotoğraf gönderen tek özellik. Aşağıda kendi bölümü var.
Önce senin iznin. İlk üç özellikten birine ilk kez uzandığında — "Tek menüde karıştır"ı açtığında, "Menünün hazırlanışı"nı açtığında ya da "Bana bir tarif yaz"a dokunduğunda — uygulama üçünü birden kapsayan tek bir soru sorar. Soru her özelliği adıyla anar, yukarıda sayıldığı gibi ne gönderdiğini söyler, isteğin sunucumuz üzerinden Google'ın Gemini'sine gittiğini söyler ve neyin ne kadar süre saklandığı için bu politikayı gösterir. Sen "İzin ver"i seçene kadar hiçbir şey gönderilmez. Bu soru uygulama açılırken ya da kurulum sırasında hiç sorulmaz. "Şimdi değil"i seçersen hiçbir şey gönderilmez ve geri kalan her şey çalışmaya devam eder: menüler her seferinde tek bir mutfaktan kurulur, her yemeğin kendi tarifi yerinde durur ve yazdığın bir yemek takviminde verdiğin adla kalır; yapay zekâ kısmının olacağı yerde uygulama neden eksik olduğunu söyler ve soruyu yeniden sunar. İznini istediğin zaman Ayarlar → Yapay zekâ özellikleri'nden geri çekebilirsin. O andan sonra sen yeniden izin verene kadar üçünden hiçbiri bir şey göndermez; yazdığın bir yemek için zaten yazılmış bir tarif, haftasının geri kalanı boyunca telefonunda kalır. Uygulama yalnızca izin verdiğin tarihi ve sorunun hangi sürümüne izin verdiğini, telefonunda tutar; sorunun söyledikleri değişirse uygulama, üçünden birine bir sonraki uzandığında yeniden sorar — açılırken asla. Bir fişin okunmasının kendine ait ayrı bir sorusu vardır — birine izin vermek ötekine izin vermek değildir.
Bu isteklerin hiçbiri seni ya da telefonunu tanımlayan bir kimlik taşımaz. Uygulamanın cihaz kimliği yoktur ve istekler ne bir hesap ne de bir bildirim anahtarı taşır. Dönen menüleri, talimatları ya da tarifleri saklamıyoruz — uygulamanın yazdığı bir tarifte sorun bildirmediğin sürece; rapor o tarifin metnini bize gönderir ("Bir tarifte sorun bildirmek"e bak).
Bütün bunlardan kaydettiğimiz tek şey: yemeğin adı. Kataloğumuzda olmayan bir yemek için tarif yazmamızı istediğinde o adı sayıyoruz — böylece birkaç yüz kişi aynı yemeği isterse onu düzgün biçimde eklememiz gerektiğini öğreniyoruz. Sakladığımız şey ad, en son nasıl yazıldığı, bir sayaç, hangi arayüz dillerinde istendiği ve ilk ve son istendiği tarihler. Ad, telefonundaki ya da sunucumuzdaki kontrol onu yemek adı değil diye geri çevirmedikçe ve cevap bunun bir yiyecek olmadığını söylemedikçe sayılır — tarif yazılamadığında bile. Seninle ilişkilendirilmiyor: cihaz kimliği yok, hesap yok, adres yok. Yine de yalnızca bir kişinin istediği bir ad için o iki tarih, o kişinin ne zaman istediğidir.
Sana yazılan tarif bir hafta telefonunda kalır. Uygulama onu, pişirmenin ortasında altında değişmesin diye yedi gün gösterir. Sonra artık gösterilmez ve uygulamayı bir sonraki açışında silinir (ya da uygulama sana bir sonraki tarifi yazdığında, ya da uygulamayı kaldırdığında). Sunucumuzda yalnızca onda bir sorun bildirirsen, raporla birlikte ve orada anlatıldığı şekilde saklanır ("Bir tarifte sorun bildirmek"e bak).
Google bu isteklerle ne yapar. Gemini'yi ücretli bir hizmet olarak kullanıyoruz. Google'ın bu hizmete ait şartlarına göre Google, gönderdiğimizi — fotoğraflar dahil — ya da döndürdüğünü ürünlerini geliştirmek için kullanmaz ve bunları kendi veri işleme şartları altında bizim adımıza işler. Google istekleri ve yanıtları yalnızca hizmetinin kötüye kullanılmasını tespit etmek ve önlemek için 55 gün tutar; bu süre içinde yetkili Google çalışanları onları yalnızca bu amaçla inceleyebilir. Google bunları kendisinin ya da alt işleyenlerinin tesisi bulunan herhangi bir ülkede işleyebilir.
Her isteğin gösterdiği. Bir sunucuya yapılan her bağlantı ona geldiği IP adresini gösterir. Sunucumuzu çalıştıran Cloudflare, aldığı her isteğin kaydını hizmeti çalıştırmak ve güvende tutmak için en fazla yedi gün tutar: zamanını, istenen adresi — bir yemek görselinde bu adres görselin adıdır, yani katalog yemeğini adlandırır —, geldiği IP adresini, Cloudflare'in o IP adresinden çıkardığı yaklaşık konumu (ülke, bölge ve şehir gibi) ve isteğin teknik başlıklarını, örneğin isteği yapan yazılımın adını ve sürümünü. Bu kayıt hiçbir zaman bir fotoğraf, senin yazdığın bir yemek adı ya da gönderdiğinin gövdesindeki başka bir şeyi içermez. Bizim kendi kayıt satırlarımız hiçbir zaman bir fotoğraf içermez. "Bana bir tarif yaz", fişler ve raporlarda yalnızca sayılar ile durum ya da hata kodları taşırlar. İki menü özelliğinde başarısız olan ya da cevabının bir kısmı atılan bir istek, ilgili olduğu katalog yemekleriyle kaydedilebilir. Başarısız olan bir istek ayrıca Google'ın geri gönderdiği yanıtla birlikte kaydedilebilir; bu yanıt gönderileni tekrarlayabilir — senin yazdığın bir yemek adı ve onun için yazılan tarif dahil. Bu kayıtların hiçbirini kimseyi tanımlamak ya da konumunu bulmak için kullanmayız.
Buradaki bir hata sana asla bir tarife mal olmaz. Mutfakları karıştıran bir menü isteği başarısız olursa uygulama menüyü telefonda kurar; pişirme planı başarısız olursa yeniden deneyebilirsin ve her yemeğin kendi tarifi yerinde durur; "Bana bir tarif yaz" başarısız olursa yemek takviminde yazdığın adla kalır.
Hesabın ve hanen — isteğe bağlı
Giriş yapmak bir tercih; hiç yapmasan da yukarıdakilerin hepsi çalışmaya devam eder. Hesabın işi, puanlarını telefonlar arasında korumak ve birlikte yaşadığın kişilerle paylaşmaktır.
Giriş yapmak. Apple ya da Google hesabınla giriş yaparsın; bize ait bir parola yoktur. Telefonun doğrudan kimlik doğrulama sağlayıcımız Supabase ile konuşur; Supabase şunları alır: Google'dan adını, e-posta adresini, profil fotoğrafının web adresini ve Google hesap tanımlayıcını (bir Google Workspace hesabında ayrıca alan adını); Apple'dan e-posta adresini — "E-postamı Gizle" seçeneğinde bir aktarma adresini — ve Apple hesap tanımlayıcını, adını ise yalnızca Apple iletirse. Supabase bunları, etkin oturumlarını ve geldikleri IP adresi dahil giriş olaylarının kaydını hesapları güvende tutmak için saklar. Girişin kendisini Apple ve Google kendi gizlilik politikaları altında yürütür.
Hane olmasa bile hesabın tuttukları. Tariflere verdiğin puanlar ve notlar; böylece yeni telefonuna seninle gelirler. Giriş yaptığında telefonda zaten bulunan puanlar hesabına kopyalanır.
Bir hane kurduğunda ya da bir haneye katıldığında sunucumuza eşitlenenler. Bu liste eksiksizdir:
- Hanenin adı
- Haneyle paylaşılan her kişi için: yazdığın ad, yaş aralığı, porsiyon büyüklüğü, ayrı tabaktan yiyip yemediği, kendi hesabı olup olmadığı ve haneye kimin sahip olduğu
- Her biri için kaydedilen alerjenler, diyetler, intoleranslar ve sevmediği malzemeler — bu bir sağlık verisidir; helal ya da koşer gibi bir diyet ayrıca dini bir inancı da gösterebilir; ikisi de GDPR'da özel nitelikli kişisel veridir, bu yüzden saklanmadan önce ayrıca rızanı isteriz (aşağıya bak)
- Rıza verildiğinin kaydı: hangi metin, hangi dilde, hangi tarihte, hangi üye için — beyanın kendisine dair hiçbir şey değil
- Davet kodları; yalnızca tek yönlü bir özet (hash) olarak, kodun kendisi asla
Hanede bile gönderilmeyenler: alışveriş listen, takvimin ve haftalık planların, dolabın, öneri ve pişirme geçmişin, favorilerin, ekipmanların, temel malzemelerin ve profilinin geri kalanı (hane büyüklüğü, beceri seviyesi, efor seviyesi, ikamet ülken, varsayılan mutfak, dil). Bunlar telefonunda kalır.
Sağlık verisi için rıza. Bir kişinin bilgileri haneyle ilk kez saklanmadan önce — onun için henüz bir şey beyan edilmiş olsun ya da olmasın — uygulama senden açıkça onay ister; uygulama yeniden başlatıldıktan sonra da, beyanlarındaki bir sonraki değişiklikten önce yeniden sorar. Soru neyin saklandığını (sağlık bilgisi; helal ya da koşer gibi bir diyette dini bir inanç), kimin görebileceğini, neden saklandığını ve hayır demenin neye mal olduğunu söyler; nerede ve ne kadar süre saklandığını bu politika söyler. Onay verdiğin kaydedilir: hangi metin, hangi dilde, hangi tarihte, hangi üye için. Bu rızayı geri çekebilirsin; geri çektiğinde o beyanlar sunucudan silinir.
Hanede bunu kim görebilir ve değiştirebilir. Haneye giriş yapmış herkes her üyenin beyanlarını görebilir. Kimin değiştirebileceği üyeye göre değişir. Kendi hesabıyla giriş yapan bir üyenin beyanlarını yalnızca kendisi kaydeder, değiştirir, onlar için rıza verir ve geri çeker. Kendi girişi olmayan bir üye için — bir çocuk ya da adıyla eklediğin bir misafir — bunu hanenin sahibi yapar — haneyi kuran hesap ya da sahipliğin sonradan geçtiği hesap; davetle katılan başka bir yetişkin o beyanları görür ama düzenleyemez. Haneye kişi eklemek ve kendi hesabıyla giriş yapan bir üyeyi çıkarmak da yalnızca sahibin elindedir. Kendi hesabı olmayan bir kişiyi ise hanenin herhangi bir üyesi çıkarabilir; onu çıkarmak adını ve beyanlarını sunucumuzdan siler. Ayrılmak herkesin elindedir. Hane, birlikte yemek pişiren insanlardır ve uygulama bu varsayım üzerine kuruludur. Durumun bu değilse beyanları telefonunda tut ve bir haneye katılma.
Bir üyeyi çıkarmak. Bir kişi haneden çıkarıldığında adı, yaş aralığı ve beyanları sunucumuzdan anında silinir. Orada kişisel hiçbir bilgi taşımayan bir işaret kalır; tek işi evdeki diğer telefonlara bu kişinin artık üye olmadığını söylemektir ve 30 gün sonra silinir. O telefonlar kişiyi, onun için beyan edilenlerle birlikte kendi listelerinde bir kayıt olarak tutar — kimsenin yemeği, haberi olmadan birden daha gevşek süzülmesin diye — ta ki biri onu orada kaldırana kadar.
Hesabını silmek. Ayarlar → Hesap ve paylaşım → Hesabı sil. Bu işlem hesabını, puanlarını ve hane üyeliğini — oradaki adını ve beyanlarını — anında siler ve verdiğin rızaları, hesabı olmayan kişiler için verdiklerin dahil, geri çekilmiş olarak işaretler. Hanenin sahibi sensen sahiplik, hesabı olan ve haneye en önce katılmış üyeye geçer. Hesabı olan başka üyeler kaldıkça, hesapsız eklenen kişiler onlar için beyan edilenlerle birlikte hanede kalır; onlar için verdiğin rıza artık geri çekilmiş görünse de bundan sonra onları hanenin sahibi yönetir. Sunucumuzdan kalkmalarını istiyorsan önce onları haneden çıkar. Haneden ayrılmak da aynı şekilde işler. Hanenin hesabı olan son üyesi sensen hane de onunla birlikte sunucumuzdan tamamen silinir, hesapsız eklenen kişiler ve beyanları dahil. Girişin ardından kimlik doğrulama sağlayıcımızdan da silinir, normalde on beş dakika içinde; bu başarısız olursa denemeye devam ederiz ve başarılı olana kadar talebi kayıtlı tutarız, sessizce düşürmeyiz. Hesabını silmek telefonundaki yerel veritabanını silmez — onu uygulamayı kaldırmak siler — ve hanedeki diğer telefonların tuttuğu, yukarıda anlatılan kayıtları da kaldırmaz. Bu uygulamayı Apple ya da Google hesabına bağlı uygulamalar listesinden de çıkarmaz; orada kendin kaldırabilirsin. Uygulamayı kullanamıyorsan giriş yaptığın hesabın e-posta adresinden, ya da o adresi yazarak, support@pinjula.com adresine e-posta gönder; o adresle doğrularız, sonra hesabı en geç bir ay içinde sileriz.
Verinin bir kopyasını almak. Ayarlar → Hesap ve paylaşım → Verilerimi dışa aktar. Dosya telefonunda oluşturulur ve cihazının paylaşım sayfasına verilir. İçinde hesabının e-posta adresi; profilin (dilin, mutfağın, ikamet ülken, hane büyüklüğü, beceri ve efor seviyen, haftalık pişirme hedefin ve tekrar filtresini en son ne zaman sıfırladığın gibi); yapay zekâ özelliklerine ve fiş taramaya izin verdiğin tarihler ve her sorunun hangi sürümüne izin verdiğin; hane listendeki kişiler ve onlar için beyan edilenler; mutfak ekipmanların ve temel malzemelerin; öneri ve pişirme geçmişin; favorilerin; dolabın; alışveriş listen; takvimin ve haftalık planların — bir güne yazdığın her yemek, kendi sözlerinle, dâhil; kendin yazıp pişirildi diye işaretlediğin yemekler; tarif listesinden ya da Yemek defterinden pişirildi diye işaretlediğin yemekler; rozetlerin ve onların dayandığı tarihli kayıt; hatırlatıcı ayarların; hanenin telefonunun son eşitlediği hâli ve puanların vardır. Katalogdaki bir yemek katalog tanımlayıcısıyla belirtilir; tarifin kendisi dosyaya kopyalanmaz. Yazdığın bir yemek için uygulamanın yazdığı ve telefonun yedi gün tuttuğu tarif ile oturumun içinde yoktur; bir hane için verdiğin sağlık verisi rızalarının kayıtları da yoktur, onlar sunucumuzda tutulur: support@pinjula.com adresinden iste. Dosyayı sunucumuzda oluşturmuyoruz ve bir kopyasını tutmuyoruz. Bir hanenin listesinde çocuklar da olabileceği için dosya onlar için girilen adları ve beyanları içerir; dosyaya buna göre davran.
Nerede saklanıyor. Frankfurt, Almanya (eu-central-1), Supabase üzerinde. Avrupa pazarlarımızdaki veri AB içinde saklansın diye AB bölgesini seçtik; ona başka kimin, hangi şartlarla ulaşabildiğini aşağıdaki "Hizmet sağlayıcılar ve yurt dışına aktarım" bölümü söylüyor.
Cihaz yedekleri
Telefonunun işletim sistemi, bu uygulamanın verisini olağan cihaz yedeğine dahil edebilir — Android'de Google Drive, iOS'ta iCloud. Bu yedeği telefonun alır, senin kendi bulut hesabına, senin denetiminde. Biz bu işin içinde değiliz, ondan hiçbir şey almıyoruz ve okuyamıyoruz. Android 9 ve sonrasında bu yedekler telefondan çıkmadan önce cihazının PIN'i, deseni ya da parolasıyla şifrelenir.
Bunu kapatmak yerine açık bırakıyoruz, çünkü telefon değiştirdiğinde dolabını, yemek defterini ve haftalık planını geri getiren şey bu. Olmasını istemiyorsan cihazının yedekleme ayarlarından kapatabilirsin — Android'de Ayarlar › Google › Yedekleme, iOS'ta Ayarlar › [adın] › iCloud.
Yedek yerel veritabanının tamamını taşıdığı için, kendin ve hane üyesi olarak eklediğin kişiler için belirttiğin alerjenleri de taşır. Giriş yapmışken, Apple ya da Google hesabının paylaştığı e-posta adresi ve adla birlikte oturumunu da taşır.
Yaklaşan hatırlatıcıların metni ve widget'larının resimleri yedeklenmez, Android'de widget'larının metni de yedeklenmez; uygulama açıldığında verilerinden yeniden oluşturulurlar. iPhone'da widget'larının metni, uygulamanın widget'larıyla paylaştığı depoda durur ve uygulamanın diğer verileri gibi cihaz yedeğine girer; hiçbir alerjeni, diyeti ya da kişiyi anmaz.
Hatırlatıcılar ve ana ekran widget'ları
Hepsi telefonunda hesaplanır, hiçbir yere gönderilmez. Hatırlatıcılar ve widget'lar telefonunda zaten olan bilgilerden oluşur: takvimin, alışveriş listen, dolabında ve elinde hep bulunan temel malzemelerde olanlar (bir widget planlanmış bir yemeğin malzemelerinin evde olup olmadığını söyleyebilsin diye), dolabına girdiğin tarihler, pişirdim diye işaretlediğin yemekler ve resimler — planlanmış bir yemeğin tarif resmi, uygulama onu sana daha önce gösterdiyse, ve uygulamanın kendi malzeme resimleri. Bunları oluşturmak için bize ya da başka birine hiçbir şey gönderilmez, bir widget hiçbir resmi indirmez; arkalarında anlık bildirim (push) servisi yoktur ve uygulamanın hâlâ bir cihaz kimliği ya da bildirim anahtarı yoktur.
Sen açana kadar kapalıdır. Uygulama önce ne yapacağını anlatır ve sorar; Android 13 ve sonrasında telefonun da ayrıca izin ister. Altı türü vardır (günün planı, dolabına girdiğin tarihi yaklaşan ürünler, kimsenin "yendi" demediği artanlar, dolaba girmeyi bekleyen işaretli alışveriş, haftada bir pişirdiklerine bakış ve isteğe bağlı alışveriş günü); günde en fazla üç tane gelir, gece geç saatte hiç gelmez. Ayarlar → Hatırlatıcılar ve widget'lar'dan hepsini ya da her birini ayrı ayrı kapatabilirsin; telefonunun bildirim ayarları da kapatır. Widget'ları ana ekranına sen eklersin ve istediğin zaman kaldırırsın; kaldırmak hiçbir şeyi silmez.
Ekranını görebilen herkes görebilir, bu yüzden sağlık bilgisi taşımazlar. Bir hatırlatıcı kilit ekranında, bir widget ana ekranında görünebilir. Hiçbiri bir alerjiyi, diyeti, intoleransı ya da onu beyan eden kişiyi anmaz. Planlanmış bir yemek hanende beyan edilmiş bir şey içeriyorsa hatırlatıcı yalnızca günün planına bakmak gerektiğini söyler, yemeğin adını bile söylemez; widget da yemeğin hanende beyan edilen bir şey içerdiğini söyler; neyin olduğunu yalnızca uygulamanın içi söyler. Planlanmış bir yemek, planlandıktan sonra hanende beyan edilen bir diyete, laktozdan kaçınmaya ya da sevilmeyen bir şeye artık uymayabilecekse de hatırlatıcı yalnızca plana bakmak gerektiğini söyler; widget yemeği gösterir ve hanende beyan edilen bir şeye uymayabileceğini söyler — yine neyin olduğunu söylemeden. Artan yemek hatırlatıcısı artanı olan yemeklerden en fazla ikisinin adını verir, gerisini sayar. Hanende herhangi birinin beyan ettiği bir şeyi içeren ya da ona artık uymayabilecek bir yemek — o kişinin yemeği ayrı pişirilse bile — yalnızca sayılır, adı hiç yazılmaz; uygulamanın kontrol edemediği bir yemek yalnızca sayılır; hanenin beyanlarını ya da tarif kataloğunu okuyamadığında hiçbir yemeğin adını vermez. Takvimine kendin yazdığın bir yemek adı yazdığın gibi gösterilir. Widget planlanmış bir yemeğin hangi malzemelerinin dolabında olmadığını söylediğinde, bunu hanende beyan edilen bir şeyi içeren ya da ona uymayabilecek bir yemeğin yanında hiçbir zaman söylemez.
Telefonda tutulan küçük bir kopya. Uygulama kapalıyken widget'ın bir şey gösterebilmesi ve hatırlatıcının çıkabilmesi için uygulama, göstereceği metni ve resimleri telefonun kendi uygulama deposunda tutar. Bir şeyi her değiştirdiğinde yenilenir. Resimler ve hatırlatıcıların metni cihaz yedeklerine dahil edilmez, Android'de widget'ların metni de; iPhone'da widget'ların metni uygulamanın diğer verileriyle birlikte cihaz yedeğine girer ("Cihaz yedekleri"ne bak). Hatırlatıcı ayarların uygulamanın diğer verileriyle birlikte yedeklenir.
Bir hatırlatıcı saat vaat etmez. Telefonun pil tasarrufu için hatırlatıcıları geciktirebilir; bazı üreticilerin pil yöneticileri tamamen engelleyebilir.
Fiş tarama — fotoğraf gönderen tek özellik
Yalnızca sen açarsan ve yalnızca dokunduğunda. Dolap ekranında bir market fişinin fotoğrafını çekip ya da bir fotoğrafını seçip üzerindeki yiyecekleri yazmadan dolabına ekletebilirsin. İlk fotoğraf çekilmeden önce uygulama, aşağıdakileri kabul edip etmediğini kendi dilinde sorar; bu onayı istediğin zaman Ayarlar'dan geri çekebilirsin, o zaman uygulama bir sonraki taramadan önce yeniden sorar. Sorunun söyledikleri değişirse de bir sonraki taramadan önce yeniden sorar.
Cihazından ne çıkıyor. Fotoğraf (önce telefonunda küçültülür), görselin türü ve arayüz dilin. Başka hiçbir şey — dolabın, hanen, hesabın ya da profilin değil. Sunucumuza gider; sunucu da satırları okuması için Google'ın Gemini API'sine iletir.
Telefonunun fotoğrafın içine yazdığı bilgiler telefonunda kalır. Resim gönderilmeden önce uygulama, telefonunun dosyaya yazdıklarını — ne zaman ve nerede çekildiğini, telefonun markasını, modelini ve seri numarasını — çıkarır; yalnızca resmin hangi yönde durduğunu bırakır.
Bir fiş ne gösterir, açıkça. Fiş yalnızca bir alışveriş listesi değildir. Nerede alışveriş yaptığını, ne zaman, ne ödediğini ve sepetteki diğer her şeyi — ilaç, bebek maması, alkol, hijyen ürünleri — gösterebilir. Resmin tamamı okunur, çünkü model üzerindeki yiyeceği bulmak için sayfayı görmek zorundadır. Telefonuna dönen şey yalnızca yiyecek ya da içecek olduğuna karar verdiği satırlardır; fişte basılıysa miktar ve birimle. Fiyatlar, toplamlar, mağaza, tarih, kart ve müşteri numaraları ve yiyecek olmayan her satır cevapta yer bulmaz — sunucu yanıtı üç alanlık sabit bir listeden yeniden kurar; modelin başka bir yere yazdığı bir değer yolculuk edemez.
Ne, nerede saklanır. Sunucumuz hiçbir şey saklamaz: fotoğraf saklanmaz, bir kayda yazılmaz ve hangi ürünlerin okunduğunu kaydetmeyiz. Google isteği — fotoğrafla birlikte — yalnızca hizmetinin kötüye kullanılmasını tespit etmek için 55 gün tutar ("Cihazından ne çıkıyor"da anlatıldığı gibi); ona seni tanımlayan hiçbir şey göndermeyiz. Telefonunda uygulama, fotoğraf seçicinin resimden aldığı kopyaları okur okumaz, bir şey gönderilmeden önce siler — gönderdiği küçültülmüş kopyayı ve Android'de, galeriden seçilen bir fotoğraf için seçicinin aldığı tam boy kopyayı. Galerindeki fotoğrafa hiç dokunulmaz. Google'ın isteği ve yanıtını tuttuğu 55 günlük kötüye kullanım kaydı dışında — ki bu kayıt, uygulamaya gönderilen yiyecek satırlarını değil, Google'ın okuduğu her satırı kapsar — dönen liste yalnızca telefonunda saklanır, orada da ancak sen onayladıktan sonra.
Sen olmadan dolabına hiçbir şey girmez. Satırlar incelemen için bir liste olarak gelir; almadıklarının işaretini kaldırırsın ve yalnızca onayladıkların eklenir. Malzeme listemizle eşleştirebildiğimiz bir ürün o malzeme olarak eklenir; eşleştiremediğimiz, okuduğumuz adla eklenir ve öyle işaretlenir — asla sessizce bir komşusuna eşlenmez.
Okuma başarısız olursa uygulama bunu söyler ve hiçbir şey eklenmez.
Bir tarifte sorun bildirmek
Yalnızca sen gönderdiğinde. Her tarifin sonunda — bizimkilerin ve uygulamanın yazdığın bir yemek için yazdıklarının — "Bu tarifte bir sorun bildir" ile neyin yanlış olduğunu bize söyleyebilirsin. Bir neden seçersin (bir malzeme, bir adım, alerjen ya da diyetle ilgili bir kaygı, çeviri, kültürel bir yanlışlık, görsel, rahatsız edici bir şey ya da başka bir şey) ve en fazla 500 karakterlik bir not ekleyebilirsin. "Raporu gönder"e dokunana kadar hiçbir şey gönderilmez. Gönderilemeyen bir rapor, yeniden göndermen ya da kapatman için ekranda kalır; saklanmaz ve sonradan kendiliğinden gönderilmez.
Ne gönderilir. Kataloğumuzdaki bir tarif için: bunun hangi tarif olduğu (katalog tanımlayıcısı), seçtiğin neden, notun ve uygulamanın dili — tarifin kendisi değil, o zaten bizde. Yazdığın bir yemek için uygulamanın yazdığı bir tarifte ise metni raporla birlikte gider: adı, malzemeleri ve adımları; çünkü o tarif yalnızca telefonunda var ve onsuz bir rapor, göremediğimiz bir şey hakkında olurdu. Rapor ekranı bunu sen göndermeden önce söyler. Hesabın, hanen, alerjilerin ya da profilin asla gitmez. Rapor sunucumuza gider ve Frankfurt'taki veritabanımızda saklanır; Google'a hiçbir zaman gitmez, bu yüzden yapay zekâ özellikleri için verdiğin izni gerektirmez.
Ne, ne kadar saklanır. Rapor — seçtiğin neden, notun, dil, gönderildiği gün (günün saati değil) ve tarifin katalog tanımlayıcısı ya da yazılan tarifin metni — 12 ay saklanır, sonra silinir. Hesap, cihaz kimliği, IP adresi ya da gönderen hakkında başka hiçbir şey saklamayız ve telefonuna onu yeniden bulmaya yarayacak hiçbir şey geri göndermeyiz. Bir rapor hakkındaki kendi kayıt satırlarımız yalnızca durum kodlarını tutar, notunu ya da tarifi asla. Her istek gibi o da "Cihazından ne çıkıyor"da anlatılan Cloudflare istek kaydından geçer; bu kayıt geldiği IP adresini en fazla yedi gün tutar, gönderdiğinin gövdesini ise hiçbir zaman.
Lütfen nota kişisel bilgi yazma. Bir rapor seni ona bağlayan hiçbir şey taşımaz; bu yüzden ona cevap veremeyiz, nota yazılan bir ad ya da e-posta adresi de raporun geri kalanı gibi 12 ay tutulur. Cevap istiyorsan ya da bir raporun taşıyamayacağı bir şey söylemek istiyorsan support@pinjula.com adresine yaz. Gönderdiğin bir raporun 12 ayı dolmadan silinmesini istiyorsan onu bulmamıza yetecek kadarını — tarifi, günü ve notunun sözlerini — yazarak bize ulaş; sileriz.
Raporlarla ne yaparız. Kataloğu ve uygulamanın tarif yazma biçimini düzeltmek için okuruz. Bir rapor, bir tarifin değiştirileceği sözü değildir ve bildirdiğin hiçbir şey uygulamanın kimseye gösterdiğini kendiliğinden değiştirmez.
Tarif paylaşma
Paylaş düğmesini kullandığında, uygulama tarifin — ya da bütün bir menünün — düz metin hâlini cihazının normal paylaşım menüsüne verir — nereye gideceği tamamen senin seçimindir (mesajlaşma uygulamaları, notlar vb.) ve biz buna dahil değiliz, göremeyiz. Uygulama, rozetleri için telefonunda bir paylaşım yapıldığını ve hangi gün yapıldığını not eder — neyi ya da kiminle paylaştığını asla.
Kendi fotoğrafınla paylaşma. Pişirdiğin bir yemeğin fotoğrafını da ekleyebilirsin — o anda çekebilir ya da fotoğraflarından seçebilirsin. Uygulama cihazından yalnızca o tek fotoğrafı ister, seçtiğin paylaşım uygulamasına verir ve başka hiçbir şey yapmaz: hiçbir yere yüklenmez ve bize ulaşmaz. Fotoğraf galerini okumuyor, taramıyor veya listelemiyoruz — gördüğün seçici işletim sisteminin kendi seçicisidir ve uygulama yalnızca senin verdiğin tek dosyayı görür. Fotoğraf seçici uygulamanın önbelleğinde, hiç yedeklenmeyen ve telefonun yer gerektiğinde temizlediği geçici bir dosya bırakır. Seçmeden vazgeçersen hiçbir şey olmaz.
Kamera ve fotoğraf izinleri. iOS'ta uygulama kameraya ya da fotoğraflarına erişimi sen dokunduğun anda ister — paylaşılacak bir yemek fotoğrafı ya da okunacak bir fiş için, asla ilk açılışta — ve vermezsen geri kalan her şey çalışmaya devam eder. Android'de uygulama hiçbir kamera ya da fotoğraf izni istemez: fotoğrafı telefonunun kendi kamera uygulaması çeker, sistemin fotoğraf seçicisi seçer.
Puanlar
Hesabın yoksa verdiğin puanlar yalnızca cihazında saklanır.
Hesabın varsa hesabında tutulur, böylece yeni telefonuna seninle gelir. Onları yalnızca senin telefonların alır — hanendeki diğer kişiler değil. Bugün başka hiçbir şey için kullanılmazlar: kullanıcılar arasında toplulaştırmıyoruz, "diğerleri arasında popüler" diye göstermiyoruz ve buradan senin hakkında bir profil çıkarmıyoruz. Bir puanı istediğin zaman değiştirebilirsin. Puanı kaldıracak bir düğme henüz yok; hesabını silmek onları sunucumuzdan, uygulamayı kaldırmak da telefonundan siler.
Hizmet sağlayıcılar ve yurt dışına aktarım
Üç hizmet sağlayıcı kullanıyoruz. Her biri veriyi bizim adımıza ve talimatımızla, hizmetiyle birlikte gelen veri işleme şartları altında işler; bu şartlar onu veriyi korumaya ve yalnızca bize o hizmeti vermek için kullanmaya bağlar — bu politikanın anlattığı korumanın aynısı.
- Cloudflare, Inc. arka uç sunucumuzu çalıştırır ve yemek görsellerini saklar. Cloudflare bir ABD şirketidir ve sunucumuz onun küresel ağında, isteğini hangi veri merkezi alırsa orada çalışır. İstek kayıtları ("Cihazından ne çıkıyor"a bak) Cloudflare hesabımızda tutulur.
- Supabase, Inc. veritabanımızı — hesaplar, haneler, puanlar, yemek adı sayıları ve tarif raporları — ve giriş hizmetimizi çalıştırır. Veritabanı Frankfurt'ta (Almanya); Supabase bir ABD şirketidir ve şartları, kendisinin ve alt işleyenlerinin veriyi başka ülkelerden — örneğin hizmeti işletmek ve desteklemek için — işlemesine izin verir.
- Google (Gemini API) dört yapay zekâ isteğini işler. Google bunları kendisinin ya da alt işleyenlerinin tesisi bulunan herhangi bir ülkede işleyebilir.
Yani bazı kişisel veriler AB ve Birleşik Krallık dışında, çoğunlukla Amerika Birleşik Devletleri'nde işlenir. Cloudflare ve Google, Avrupa Komisyonu'nun yeterli koruma sağladığına karar verdiği ve uzantılarını Birleşik Krallık ile İsviçre'nin de tanıdığı AB–ABD Veri Gizliliği Çerçevesi'ne sertifikalıdır; üç sağlayıcının da veri işleme şartları, Çerçeve'nin kapsamadığı aktarımlar için Avrupa Komisyonu'nun Standart Sözleşme Maddelerini ve bunların Birleşik Krallık karşılığını içerir. Bu güvencelerin bir kopyasını support@pinjula.com adresinden isteyebilirsin.
Apple ya da Google ile giriş yaptığında o şirket bizim hizmet sağlayıcımız değildir: girişini kendi gizlilik politikası altında yürütür ve bize yalnızca "Giriş yapmak"ta sayılanları gönderir.
Bu uygulamada hiçbir analiz, reklam ya da çökme raporlama SDK'sı kullanmıyoruz; verilerini satmıyor, başka hiç kimseye vermiyoruz.
Her kullanımın hukuki dayanağı (AB, AEA ve Birleşik Krallık)
- Uygulamayı ve ondan istediklerini sağlamak — yemek görselleri, hesabın, hanen: istediğin hizmeti sağlamak için gereklidir (GDPR md. 6(1)(b)).
- Mutfakları karıştıran menü, pişirme planı ve "Bana bir tarif yaz": rızan (md. 6(1)(a)); uygulamada ilk istekten önce sorulur ve Ayarlar'dan geri çekilebilir.
- Bir hanede saklanan alerjiler, diyetler, intoleranslar ve sevilmeyen malzemeler: açık rızan (md. 9(2)(a)); uygulamada her kişi için ayrı sorulur ve istediğin zaman geri çekilebilir.
- Kendi hesabı olmayan, eklediğin kişiler: adları, yaş aralıkları, porsiyon büyüklükleri ve ayrı tabak tercihleri, hanenin yemeklerinin onlar için de planlanmasındaki bizim ve onların meşru menfaatine dayanır (md. 6(1)(f)). Alerjileri, diyetleri, intoleransları ve sevmedikleri ise onlar adına verdiğin açık rızaya dayanır — bir çocuk için ondan sorumlu kişi olarak, başka bir yetişkin için ise yalnızca onun onayıyla; uygulama önce ona sormanı ister.
- Fiş fotoğrafları: rızan (md. 6(1)(a)), ve bir fiş sağlığınla ilgili bir şey gösterdiği ölçüde açık rızan (md. 9(2)(a)); Ayarlar'dan geri çekilebilir.
- Bir tarif hakkındaki raporlar: bizim ve uygulamadan yemek pişiren herkesin, tariflerin doğru olmasındaki meşru menfaati (md. 6(1)(f)). Her birini göndermeye sen karar verirsin ve hiçbiri seni tanımlayan bir şey taşımaz.
- İstek kayıtları, giriş kayıtları ve hesap silmeleri tamamlamak: güvenli ve verdiği sözü tutan bir hizmet işletmekteki meşru menfaatimiz (md. 6(1)(f)).
- Rıza verildiğinin kaydını tutmak: bunu gösterebilme yönündeki yasal yükümlülüğümüz (md. 6(1)(c) ve 7(1)).
Bir rızayı geri çekmek, kapsadığı işlemeyi o andan itibaren durdurur; öncesinde yapılanı hukuka aykırı hâle getirmez.
Neyi ne kadar saklıyoruz
- Telefonunda: sen silene ya da uygulamayı kaldırana kadar. Yazdığın bir yemek için uygulamanın yazdığı tarif: yedi gün gösterilir, sonra uygulama bir sonrakini yazdığında ya da uygulamayı kaldırdığında silinir. Hatırlatıcılar ve widget'lar için hazırlanan metin ve resimler: verin her değiştiğinde yenilenir. Yapay zekâ özelliklerine ya da fiş taramaya izin verdiğin tarih: Ayarlar'dan geri çekene kadar.
- Hesabın ve puanların: hesabını silene kadar. Supabase'deki girişin de ardından silinir, normalde on beş dakika içinde ("Hesabını silmek"e bak).
- Bir hanenin üyeleri ve beyanları: üye çıkarılana, rıza geri çekilene ya da hane sona erene kadar. Çıkarılan bir üye, kişisel bilgi taşımayan bir işareti 30 gün bırakır. Hesabı olan bir üye, hesabı olan başkaları kalırken ayrılır ya da hesabını silerse hesapsız kişiler ve onlar için beyan edilenler hanede kalır. Hesabı olan son üye ayrıldığında ya da hesabını sildiğinde hane ve içindeki her şey silinir.
- Rıza kayıtları: tutulur, çünkü rızanın sorulduğunu gösterebilmemiz gerekir. Bir kaydın ilgili olduğu hesap ya da üye silindiğinde o kişiyle bağı kaldırılır; geriye kalan — bir metin sürümü, bir dil ve tarihler — kimseyi adlandırmaz.
- "Bana bir tarif yaz" için sayılan yemek adları: her adın ilk ve son istendiği tarihlerle birlikte sayı olarak tutulur, hiçbir hesapla ya da cihazla ilişkilendirilmez.
- Bir tarif hakkındaki raporlar: gönderildikleri günden itibaren 12 ay, sonra silinir — hiçbir hesapla ya da cihazla ilişkilendirilmez.
- Kayıtlar: Cloudflare'in istek kayıtları en fazla yedi gün; Google'ın yapay zekâ isteklerine ait kayıtları 55 gün; Supabase'in giriş olayları kayıtları, Supabase'in projemiz için uyguladığı kayıt saklama süresince.
Hakların
Nerede yaşarsan yaşa, verinin bir kopyasını isteyebilir, düzeltilmesini ya da silinmesini isteyebilir ve herhangi bir rızanı istediğin zaman geri çekebilirsin. GDPR ya da Birleşik Krallık GDPR'ı sana uygulanıyorsa verinin kullanımını kısıtlama ve itiraz etme ile veri taşınabilirliği hakların da vardır; yaşadığın ya da çalıştığın yerdeki veri koruma otoritesine — Birleşik Krallık'ta Information Commissioner's Office'e — şikâyette bulunabilirsin.
İtiraz hakkın. Meşru menfaatimize dayandığımız yerlerde — istek kayıtları, giriş kayıtları, bir hesap silmeyi tamamlamak, kendi hesabı olmadan eklenen kişilerin bilgileri ve bir tarif hakkındaki raporlar — kendi özel durumunla ilgili gerekçelerle istediğin zaman support@pinjula.com adresine yazarak itiraz edebilirsin. Bir rapor ancak onun hakkında bize söylediklerinden bulunabilir ("Bir tarifte sorun bildirmek"e bak).
Bunların çoğunu uygulamada kendin yapabilirsin: Ayarlar → Hesap ve paylaşım'da Verilerimi dışa aktar ve Hesabı sil var, kendi sağlık verisi rızanı geri çekmek de aynı ekranda; eklediğin biri için "Hanede paylaşmayı bırak" onu ve onun için beyan edilenleri sunucumuzdan siler; fiş tarama rızası da yapay zekâ özellikleri için verdiğin rıza da Ayarlar'dan ayrı ayrı geri çekilir. Başka her şey için ya da uygulamayı kullanamıyorsan support@pinjula.com adresine yaz; bir ay içinde cevap veririz.
Tıbbi veya beslenme tavsiyesi değildir
Uygulama besin değeri gösterdiğinde, bunlar yayımlanmış gıda bileşim veritabanlarından (USDA FoodData Central; koyun eti için Food Standards Australia New Zealand'ın Avustralya Gıda Kompozisyon Veri Tabanı) tarifin malzemelerine uygulanarak hesaplanmış tahminlerdir — gerçekten pişirdiğin yemeğin doğrulanmış bir analizi değildir ve hiçbir zaman tıbbi ya da diyet tavsiyesi olarak değerlendirilmemelidir. Alerjen filtreleme en iyi çabayla yapılan bir güvenlik yardımcısıdır, bir garanti değildir — özellikle bir gıda alerjin varsa, pişirmeden önce malzeme listesinin tamamını mutlaka kendin kontrol et. Uygulama tıbbi bir cihaz değildir; hiçbir hastalığı teşhis etmez, tedavi etmez, iyileştirmez ya da önlemez. Tıbbi tavsiye, teşhis veya tedavi için bir sağlık uzmanına danış.
Çocuklar
Bu uygulama çocuklara yönelik değildir ve bir çocuğun hesap açmasına bilerek izin vermeyiz.
Bununla birlikte bir yetişkin haneye çocuk ekleyebilir — yaş aralıkları ve porsiyon büyüklükleri bunun içindir. Paylaşılan bir hanede çocuğun kaydı sunucumuza ulaşır: onun için yazdığın ad, yaş aralığı, porsiyon büyüklüğü, ayrı tabaktan yiyip yemediği ve kaydettiğin alerjiler, diyetler, intoleranslar ve sevmedikleri. Saklamadan önce yetişkinden açık rıza isteriz, o çocuk hakkında başka hiçbir şey tutmayız (e-posta yok, giriş yok, cihaz kimliği yok, doğum tarihi yok) ve çocuk haneden çıkarıldığında ad ve beyanlar sunucumuzdan anında silinir.
Bu politikadaki değişiklikler
Bu politika değişirse, yukarıdaki yürürlük tarihini güncelleriz, sondaki değişiklik geçmişine bir satır ekleriz ve önemli değişiklikler için uygulamanın sürüm notlarında belirtiriz.
İletişim
Bu politikayla ilgili sorular için: support@pinjula.com
Changelog · Değişiklik geçmişi
- 2026-10-01 — Our contact address is now support@pinjula.com, on our own domain; nothing else changed. · İletişim adresimiz artık kendi alan adımızdaki support@pinjula.com; başka bir şey değişmedi.
- 2026-09-30 — Device backups, corrected: on iPhone your widgets' text goes into a device backup with the rest of the app's data; this policy had said it did not. It names no allergen, diet or person. On Android it is still not backed up, and the widgets' pictures and the reminders' text are backed up on neither. Nothing new leaves the phone. · Cihaz yedekleri, düzeltme: iPhone'da widget'larının metni uygulamanın diğer verileriyle birlikte cihaz yedeğine girer; bu politika girmediğini söylüyordu. Hiçbir alerjeni, diyeti ya da kişiyi anmaz. Android'de hâlâ yedeklenmez; widget'ların resimleri ve hatırlatıcıların metni ikisinde de yedeklenmez. Telefondan yeni bir şey çıkmaz.
- 2026-09-30 — Widgets: the plan widget can show a planned dish's recipe picture — only once the app has already shown it to you, never downloaded for the widget — and say which of its ingredients your pantry and staples do not hold, never beside a dish that needs a look; the shopping and pantry widgets show the app's own ingredient pictures. The pictures are kept on the phone and are not backed up. Nothing new leaves the phone. · Widget'lar: plan widget'ı planlanmış bir yemeğin tarif resmini — yalnızca uygulama onu sana daha önce gösterdiyse, widget için hiç indirmeden — gösterebilir ve malzemelerinden hangilerinin dolabında ve temel malzemelerinde olmadığını söyleyebilir; bakılması gereken bir yemeğin yanında bunu söylemez. Alışveriş ve dolap widget'ları uygulamanın kendi malzeme resimlerini gösterir. Resimler telefonda tutulur ve yedeklenmez. Telefondan yeni bir şey çıkmaz.
- 2026-09-30 — The leftovers reminder now names up to two of the dishes that still have leftovers and counts the rest, where it only counted them. A dish that contains something anyone in your household declared, or may no longer fit it, is still only counted and never named, even when that person's meals are cooked separately; a dish the app cannot check is only counted, and when the app cannot read your household's declarations or the recipe catalogue, no dish is named. Nothing new leaves the phone. · Artan yemek hatırlatıcısı artık, yalnızca saymak yerine, artanı olan yemeklerden en fazla ikisinin adını verir ve gerisini sayar. Hanende herhangi birinin beyan ettiği bir şeyi içeren ya da ona artık uymayabilecek bir yemek, o kişinin yemeği ayrı pişirilse bile, yine yalnızca sayılır, adı yazılmaz; uygulamanın kontrol edemediği bir yemek yalnızca sayılır; hanenin beyanlarını ya da tarif kataloğunu okuyamadığında hiçbir yemeğin adı verilmez. Telefondan yeni bir şey çıkmaz.
- 2026-09-30 — A recipe written for a typed dish that has passed its week is now deleted when you next open the app, not only when the app next writes one. · Yazılan bir yemek için üretilen ve haftası dolan tarif artık uygulamayı bir sonraki açışında da silinir, yalnız bir sonraki tarif yazıldığında değil.
- 2026-09-30 — A sixth reminder: leftovers nobody has marked as eaten, at most once a day, with its own switch; it counts them and never names a dish. The phone keeps when leftovers were marked eaten, and the data export includes it. Nothing new leaves the phone. · Altıncı bir hatırlatıcı: kimsenin "yendi" demediği artanlar, günde en fazla bir kez, kendi anahtarıyla; sayar, hiçbir yemeğin adını vermez. Telefon artanın ne zaman "yendi" diye işaretlendiğini tutar ve dışa aktarılan dosyada da vardır. Telefondan yeni bir şey çıkmaz.
- 2026-09-30 — "What's stored on your device" now lists each catalogue dish you mark as cooked from the recipe list or your Cookbook, which stays on the phone until you uninstall the app; the data export includes them. · "Cihazında saklananlar" artık tarif listesinden ya da Yemek defterinden pişirildi diye işaretlediğin her katalog yemeğini sayıyor; uygulamayı kaldırana kadar telefonda kalır ve dışa aktarılan dosyada da var.
- 2026-09-30 — Reminders and widgets: a planned dish that may no longer fit a diet, lactose avoidance or dislike declared later is flagged the same discreet way as an allergen — the reminder names no dish, the widget says only that it may not fit something declared; nothing new leaves the phone. · Hatırlatıcılar ve widget'lar: sonradan beyan edilen bir diyete, laktozdan kaçınmaya ya da sevilmeyen bir şeye artık uymayabilecek planlanmış yemek, alerjen gibi aynı ölçülü biçimde işaretlenir; telefondan yeni bir şey çıkmaz.
- 2026-09-29 — A receipt photo now leaves your phone without the details your phone stored inside it: the app takes out when and where it was taken and the phone's make, model and serial number before it is sent, and keeps only which way up it is. The app also deletes the photo picker's copies of a receipt photo as soon as it has read them, instead of leaving them in its cache. The two permissions kept on your phone — for the AI features and for receipts — now record which version of the question's words you agreed to, and the app asks again, the next time you reach for the feature, when those words change; the data export includes the version. The permission questions for the AI features, receipts and health information are shorter: each keeps what is sent, to whom, what saying no costs and how to withdraw, and points to this policy for where things are stored and for how long. The health question now says that a diet such as halal or kosher can show a religious belief, and the receipt question no longer says the photo is "gone" — it says Google keeps requests for a limited time to detect misuse. Because the words changed, each question is asked again the next time you reach for its feature. · Bir fiş fotoğrafı artık telefonunun içine yazdığı bilgiler olmadan telefonundan çıkıyor: uygulama, ne zaman ve nerede çekildiğini ve telefonun markasını, modelini ve seri numarasını gönderilmeden önce çıkarıyor; yalnızca resmin hangi yönde durduğunu bırakıyor. Uygulama ayrıca fotoğraf seçicinin bir fiş fotoğrafından aldığı kopyaları, önbelleğinde bırakmak yerine okur okumaz siliyor. Telefonunda tutulan iki izin — yapay zekâ özellikleri ve fişler için — artık sorunun hangi sürümüne izin verdiğini de kaydediyor; o sorunun söyledikleri değişince uygulama, özelliğe bir sonraki uzandığında yeniden soruyor; dışa aktarılan dosyada sürüm de var. Yapay zekâ özellikleri, fişler ve sağlık bilgisi için izin soruları kısaldı: her biri neyin, kime gönderildiğini, hayır demenin neye mal olduğunu ve iznin nasıl geri çekildiğini söylemeye devam ediyor; neyin nerede ve ne kadar süre saklandığı için bu politikayı gösteriyor. Sağlık sorusu artık helal ya da koşer gibi bir diyetin dini bir inancı gösterebileceğini söylüyor; fiş sorusu fotoğrafın "gittiğini" söylemiyor, Google'ın kötüye kullanımı tespit etmek için istekleri bir süre sakladığını söylüyor. Sözler değiştiği için her soru, özelliğine bir sonraki uzandığında yeniden soruluyor.
- 2026-09-28 — Nutrition figures name their second source: mutton's come from the Australian Food Composition Database (Food Standards Australia New Zealand), because the U.S. database has no raw mutton. Nothing about your data changed. · Besin değerleri ikinci kaynaklarını da anıyor: koyun etininkiler Avustralya Gıda Kompozisyon Veri Tabanı'ndan (Food Standards Australia New Zealand), çünkü ABD veritabanında çiğ koyun eti yok. Verilerinizle ilgili hiçbir şey değişmedi.
- 2026-09-27 — "What's stored on your device" now lists your weekly cooking target, the badges you've earned and the short, dated log of the actions they count, and each dish you typed onto your calendar and marked as cooked, which stays on the phone when the calendar is cleared; sharing can send a whole menu, and a share leaves only a dated note on the phone; the data export now includes the dates you allowed the AI features and receipt scanning and, since the same day, what the phone itself holds — equipment and staples, history, favorites, pantry, shopping list, calendar and week plans, the dishes you typed and marked as cooked, badges and their log, reminder settings and your weekly cooking target; and on a phone set up before 13 September 2026 the app deletes the copies of your allergens, diet and lactose answer that your profile kept after they moved onto each person — they were no longer used, and each person's own answers are unchanged. · "Cihazında saklananlar" artık haftalık pişirme hedefini, kazandığın rozetleri ve saydıkları işlerin kısa, tarihli kaydını, ve takvimine kendin yazıp pişirildi diye işaretlediğin, takvim temizlendiğinde de telefonda kalan her yemeği sayıyor; paylaşım artık bütün bir menüyü gönderebiliyor ve bir paylaşım telefonda yalnızca tarihli bir not bırakıyor; verilerini dışa aktarma artık yapay zekâ özelliklerine ve fiş taramaya izin verdiğin tarihleri ve, aynı günden beri, telefonun kendi tuttuklarını da içeriyor — ekipman ve temel malzemeler, geçmiş, favoriler, dolap, alışveriş listesi, takvim ve haftalık planlar, kendin yazıp pişirildi diye işaretlediğin yemekler, rozetler ve kayıtları, hatırlatıcı ayarları ve haftalık pişirme hedefin; ve 13 Eylül 2026'dan önce kurulmuş bir telefonda uygulama, alerjenlerin, diyetin ve laktoz cevabın her kişiye taşındıktan sonra profilinde kalan kopyalarını siliyor — artık kullanılmıyorlardı, her kişinin kendi cevapları değişmedi.
- 2026-09-15 (reports) — New section, "Reporting a problem with a recipe": a report sends a catalogue recipe's identifier, or the text of a recipe the app wrote for a dish you typed, with a reason, an optional note and the app's language; it carries nothing that identifies you, is stamped with the day it was sent and not the time, never goes to Google, and is deleted after 12 months. The summary, "What leaves your device", the legal bases, how long we keep things and your right to object say so too. · Yeni bölüm, "Bir tarifte sorun bildirmek": bir rapor, katalogdaki bir tarifin tanımlayıcısını ya da yazdığın bir yemek için uygulamanın yazdığı tarifin metnini; bir neden, isteğe bağlı bir not ve uygulamanın diliyle birlikte gönderir; seni tanımlayan hiçbir şey taşımaz, saatiyle değil yalnızca gönderildiği günle kaydedilir, Google'a gitmez ve 12 ay sonra silinir. Özet, "Cihazından ne çıkıyor", hukuki dayanaklar, saklama süreleri ve itiraz hakkın da bunu söylüyor.
- 2026-09-15 (later) — The app now asks your permission before the first request of the mixed-cuisine menu, the cooking plan or "Write me a recipe", in one question for all three, never at launch or during setup; declining costs only the AI part; the permission is withdrawn in Settings → AI features; the legal basis for these three is now your consent; the cooking plan is listed as sending each dish's course, which it always did, and what our log can keep from a menu request is described more exactly. · Uygulama artık mutfakları karıştıran menü, pişirme planı ya da "Bana bir tarif yaz"ın ilk isteğinden önce, üçü için tek bir soruyla, asla açılışta ya da kurulum sırasında olmadan iznini istiyor; hayır demek yalnızca yapay zekâ kısmına mal oluyor; izin Ayarlar → Yapay zekâ özellikleri'nden geri çekiliyor; bu üçünün hukuki dayanağı artık rızan; pişirme planının her yemeğin türünü de gönderdiği — bunu hep gönderiyordu — artık yazıyor ve bir menü isteğinden kayıtlarımızda ne kalabileceği daha tam anlatılıyor.
- 2026-09-15 — Brought up to what the app does today: four AI features (not three) and what Google does with them; dish pictures; the sign-in data and Supabase; the shopping list and calendar are not shared; the recipe written for a typed dish is kept on the phone for a week; service providers and international transfers; legal bases, retention and rights; web account deletion by email; nutrition figures come from USDA FoodData Central only; the details stored inside a receipt photo, and what Cloudflare's request record holds; a typed dish in the cooking plan; any member can remove a person without an account; what happens to those people's declarations when an account holder leaves; halal and kosher diets as religious-belief data; what the export contains; the sign-in session on the phone; the right to object. · Uygulamanın bugün yaptığına getirildi: dört yapay zekâ özelliği (üç değil) ve Google'ın onlarla ne yaptığı; yemek görselleri; giriş verileri ve Supabase; alışveriş listesi ve takvim paylaşılmıyor; yazılan yemek için üretilen tarif telefonda bir hafta tutuluyor; hizmet sağlayıcılar ve yurt dışına aktarım; hukuki dayanaklar, saklama süreleri ve haklar; e-postayla hesap silme; besin değerleri yalnızca USDA FoodData Central'dan; bir fiş fotoğrafının içinde saklanan bilgiler ve Cloudflare'in istek kaydının tuttukları; pişirme planında yazılan yemek; hesapsız bir kişiyi herhangi bir üyenin çıkarabilmesi; hesap sahibi ayrıldığında o kişilerin beyanlarına ne olduğu; dini inanç verisi olarak helal ve koşer diyetleri; dışa aktarılan dosyanın içeriği; telefondaki oturum; itiraz hakkı.