Privacy Policy
Last updated 30 September 2026
ChefGuru is run by Good Matter LLC. This explains what the app collects, who else touches it, and how to get rid of it. It covers the website at chefguruapp.com and the ChefGuru iOS and Android apps.
What we collect
Your account: the name and email address you sign up with, and either a password (stored only as a hash) or the name, email address and profile picture Google gives us when you sign in with Google.
Your profile, all of it optional: a bio, birthday, gender, phone number, a location you type, your language, and your dietary profile — allergies, sensitivities and spice tolerance. The dietary profile is what powers the safety badges on dishes, and it is the most sensitive thing here. It is never shown to other users.
What you make and do in the app: dishes and photos you post, captions, recipes, collections, the accounts you follow, and reports you file about a dish.
Technical data: a session cookie (or, in the app, a session token stored on the device), crash reports, and product analytics about which screens are used — including recordings of how pages are used, with every piece of text and everything you type masked out.
Camera and microphone
The camera is used for the QR scanner and for taking a photo of a dish or menu. The viewfinder runs on your device; frames leave it only in a photo you deliberately take.
Dictation uses your device’s own speech recognition — Apple’s on iOS, Google’s on Android, your browser’s on the web. That audio is handled by the platform under its own privacy policy; it never reaches ChefGuru, and we neither receive nor store a recording.
What we do not do
We do not sell your data, and we do not show ads.
We do not read your device location. The site denies itself that permission outright.
ChefGuru is not for children under 13, and we do not knowingly collect their data.
Who processes it for us
Neon hosts the database. Netlify hosts and serves the site. UploadThing stores uploaded images. Google provides sign-in with Google and the Gemini models described above. Sentry receives crash reports. PostHog receives product analytics.
Each of these acts on our instructions and under its own privacy policy. We add processors only when the app needs one, and this list is kept current with what the code actually calls.
Deleting your account
You can delete your account from inside the app at any time: Settings (the gear in the header) → Delete account. It asks for your password, or — if you signed in with Google — for a recent sign-in, and then the deletion is immediate and permanent.
You can also ask us to delete an account by writing to support@chefguruapp.com from the address the account uses. We act on that within 30 days.
Deleting removes your account, profile, dietary profile, posts and photos, collections, follows and reports.
Three things deliberately survive it. A recipe that a restaurant has adopted onto its menu stays, with your name removed from it — it belongs to the dish by then, not to the account. Moderation records of reports that were acted on are kept, because they are the record of a decision. And the @username itself is retired rather than freed, so nobody can take it and inherit the links, mentions and printed QR codes that still point at it.
Security
Traffic is served over HTTPS only. Passwords are stored hashed, never in a form anyone here can read. Access to the production database is limited to the people who operate the service.
No system is perfect. If you believe an account has been compromised, write to us at the address below and we will act on it.
Changes
If this policy changes in a way that affects what we collect or who processes it, we will update the date at the top and, for a material change, tell you in the app.
Contact
Questions, requests, or anything you think is wrong here: support@chefguruapp.com.