Privacy

Last updated 2026-05-26

Privacy.

Short policy because there's not much to disclose — the web library is a static reading surface, the iPhone app does its work on-device wherever possible, and we run no advertising, no cross-app tracking, and no third-party data brokers. The analytics we do collect are anonymous, EU-hosted, and exist only so we can improve the recipes the app generates.

The FujiRecipes web library is a static reading surface. We do not set tracking cookies, run third-party analytics, fingerprint devices, or maintain user profiles. The site does not require any account or sign-in to read recipes or browse hubs.

The site is hosted on Cloudflare Pages; Cloudflare logs basic request metadata (IP address, user agent, timestamp) for the standard operational purposes of running a CDN — protecting the origin, detecting abuse, and producing aggregate traffic counts. We do not link this log data to any reader identity, and we do not read it for marketing or profiling purposes.

Before the iPhone app launched, the homepage offered a waitlist. If you submitted your email address there, it was stored solely for the purpose of sending one notification email when the app became available. We will not sell, share, or use your email for any other purpose, and you can request deletion at any time by replying to the launch email or contacting us at privacy@fujirecipes.io.

A one-way hash of your email is also recorded as an anonymous identifier in our analytics so we can tell whether the same person returned to the homepage and submitted twice. The hash cannot be reversed to recover your email; deletion of the original email removes the link to the hash.

The FujiRecipes iPhone app does not require an account. We do not collect names, email addresses, contacts, browsing history, real names, or your Apple ID. We do not run advertising SDKs, cross-app tracking, identifier-linking SDKs (like Branch or AppsFlyer), or data-broker integrations. Apple's App Tracking Transparency prompt is never shown by the app because the app does not track you across other apps or websites.

Your recipe library, saved collections, and chat history live on your device in Apple's SwiftData store. They are not uploaded to our servers. If you have iCloud backup enabled for the app, that backup is governed by Apple's privacy policy, not ours.

Recipe generation and prompts. When you ask the app to generate a recipe, the text of your prompt and the camera model you've selected are sent to our Cloudflare Workers backend, which forwards the request to Anthropic's Claude API for generation. The response is returned to your device and saved locally. Anthropic processes the request under its own privacy and data retention terms (it does not train models on API traffic by default). The text of your prompt is also stored on our backend, associated with an anonymous device identifier (not your email, not your Apple ID), so we can understand which kinds of photographic situations the app is being asked for and improve the recipes the model produces. Prompts are never sold, shared with data brokers, or used for advertising. You can request deletion of your prompt history at any time by emailing privacy@fujirecipes.io with the anonymous device identifier visible in Settings → About.

Anonymous analytics events. The app records anonymous product-interaction events through PostHog (EU-hosted, GDPR-compliant) so we can see how the app is being used at the funnel level — for example: onboarding completed, recipe generated, recipe saved, paywall shown, subscription started. Each event is tagged with an anonymous device identifier and does not include your name, email, Apple ID, location, or contents of photos. PostHog operates as a data processor on our behalf; the data is hosted on Cloudflare-region EU servers and is not shared with other parties.

In-app feedback and recipe reports. If you choose to send feedback from the Profile screen, or to report a generated recipe as wrong, the text you submit — plus the anonymous device identifier, app version, camera model, and (optionally) a voice memo you attach to feedback — is stored on our backend so we can read it and improve the product. Feedback and reports are voluntary; the app never sends either without your explicit submission.

Subscription lifecycle events. Apple notifies our backend (via RevenueCat) of subscription state changes — purchase, renewal, cancellation, expiration, refund. These events include the anonymous purchase identifier and product metadata so the app knows whether your subscription is active. No payment details or personal data are included.

Photo references. If you attach a photo from your library as a reference for a recipe prompt, the photo is sent along with that single request. We do not retain the photo on our servers, and we do not access your photo library unless you explicitly pick a photo. iOS shows you the system permission dialog before this happens; you can deny it without losing access to the rest of the app.

Location for weather. If you grant the app location permission, your approximate location is used to fetch the current weather conditions and solar phase from Open-Meteo, purely to contextualize recipe suggestions for the light you're shooting in. Your location is not stored on our servers and is not linked to any identifier. You can deny location access; the app will continue to work without weather context.

Notifications. If you opt in to push notifications, your APNs device token is used solely to deliver the notifications you've enabled (for example, the weekly Friday Recipe refill). The token is not used for tracking or shared with third parties.

Crash and performance diagnostics. The app uses Apple's MetricKit framework to collect anonymous crash, hang, and CPU-exception reports from your device. These reports are surfaced to our analytics so we can fix bugs; they contain stack traces and timing information, not your content.

Subscriptions are processed by Apple through the App Store. We do not see or store your payment information. Apple shares with us an anonymous purchase receipt (via RevenueCat, our subscription analytics provider) so the app knows whether your subscription is active. RevenueCat receives the anonymous purchase identifier and basic device platform information for the sole purpose of managing your entitlements; it does not receive your name, email, or other personal data from us.

Sub-processors used in delivering the app: Anthropic (recipe generation), Cloudflare (backend hosting, database, edge network, web hosting), PostHog EU (anonymous analytics), RevenueCat (subscription state), Open-Meteo (weather context). Each is contracted to use the data only for the purpose of delivering their service to us. None are advertising or data-broker services.

We link to third-party sites (Fujifilm camera documentation, related photographic references). Those sites have their own privacy practices, which we don't control.

FujiRecipes is not directed at children under 13, and we do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us and we will delete it.

We may update this policy as the product evolves; the "Last updated" date at the top of this page reflects the current version. Material changes that affect what we process will be surfaced in the app before they take effect.

Privacy questions or deletion requests: write to privacy@fujirecipes.io.