Legal
Privacy Policy
Last updated: 12 August 2026. This page explains exactly what My Royal Chef stores, who processes it, and why — in plain language.
About this policy
My Royal Chef is a pantry-aware cooking assistant and recipe service provided by Aporia Systems. This policy covers the website (myroyalchef.com) and the Android app. If you have questions about this policy or about your data, use the contact form and we will respond as soon as we can.
Data we store
What we collect.
Account information
If you create an account, we store your username, email address, and a secure hash of your password (never the password itself). If you sign in with Google, we receive your name and email from Google to create or match your account. Your account may also record your plan status (Free or Premium) and how it was granted.
Chef chat & saved recipes
Chat messages (and an optional image, max one per message) are sent to our server and processed by the configured AI provider (via OpenRouter) when a server-generated answer is needed. Many routine requests on the website, including mechanical operations such as recipe resizing, unit and temperature conversions, known substitutions and curated fixes, can instead be interpreted and answered entirely on your device by our C++/WebAssembly engine, without sending that request to our server. When a question needs fresh facts, our server may also perform a web search on your behalf and include the results in the answer. If you are logged in, your conversations and saved recipes are stored on our server so you can return to them across sessions; the Android app also keeps a local copy of your chat. Guest chats are kept in browser or app storage apart from requests that are sent to obtain a server-generated answer. On the website, voice dictation is handled by browser or operating-system speech recognition; we do not receive the audio.
Pantry & recipe tools
Your pantry list and saved ingredients are stored on your device only. When you ask Fridge Rescue or Cook Tonight to generate recipes, the ingredient names (and any quantities or expiry dates you have entered) are included in the AI request sent to our server and the AI provider, because that is what the recipe generator needs to work. Your pantry is never uploaded or stored separately on our server.
Messages you send us
If you use the contact form or sign up for the cookbook, we store the name, email, and message you provided so we can respond.
Subscription & payments
Premium is sold through Gumroad on the website. Gumroad processes your payment — we never see your card details. We receive only your purchase email and sale status, which we use solely to attach Premium to your account. The Android app on Google Play is currently a consumption-only build: it recognizes your existing Premium entitlement after login but does not sell subscriptions itself.
AI content reports
When you report an AI-generated answer or recipe from the app, we store the report category, the feature it came from, a short content identifier (for example a recipe title) or a SHA-256 hash of the content, an optional note you write, and — only if you are signed in — an internal user id. Reports do not contain your password, images, advertising identifiers or full chat history, and they are used only to review and improve AI output. If you later delete your account, the reporter link on your reports is anonymized (your user id is removed) while the moderation record itself may remain.
Security logs
We keep minimal technical records (login attempts, rate-limit counters) purely to protect accounts from abuse. These are not used for marketing or profiling.
Our promises
What we never do.
No selling of your data
We do not sell, rent, or trade your personal data to anyone. Advertising in the Android app is served by Google (see below); we do not receive your personal data from those ads beyond standard aggregate reporting.
Only necessary cookies
A session cookie keeps you logged in, and a security token protects forms against forgery. Both are strictly necessary. There are no marketing cookies.
Advertising
Ads in the Android app.
Google Mobile Ads (AdMob)
The Android app includes Google's Mobile Ads SDK so free users can watch a rewarded ad to earn one extra chef message (max 3 per day). Google may process device and advertising identifiers (for example the advertising ID), ad interactions, and diagnostics, measurement and fraud-prevention data to serve and measure ads, in line with Google's policies — that processing is done by Google under its own terms, and we receive only a small completion claim from the app, not Google's ad data. We do not intentionally collect or store the device advertising ID in our own backend. When an eligible signed-in user completes a rewarded ad, the Android app sends a reward-completion claim to our server so the bonus message can be granted: we process and store limited reward records (a generated reward identifier, the reward type, the date, and a subject key linked to the signed-in account). These records are used only to grant the bonus, enforce the quota and daily limits, prevent duplicate claims and prevent abuse. Because they are linked to a signed-in account, they are not anonymous. Guests cannot currently claim rewarded-ad bonus messages.
The app uses Google's User Messaging Platform to determine where consent or privacy messages are required and to show Google-managed consent or privacy messages to the users who need them. Where Google requires a privacy-options entry point, the Android app's Settings shows a "Privacy choices" option to review or change those choices.
Android app
How the app handles data.
On-device storage and server processing
The Android app runs its recipe tools and the fallback chat engine on your device. Chat messages (and any image you attach) are sent to myroyalchef.com and processed by the culinary LLM to answer you — the same as the website. The app also contacts our server to sign you in, check your plan and quota, and download the latest recipe data. Your chat transcript, saved recipes, pantry and cached results are stored on your device in the app's private storage; guests' data never leaves the device except for the chat requests you send. Google sign-in on Android uses Google's native, system-level account picker — the app never sees your Google password. Your session is stored securely on the device and is cleared when you log out, delete your account, or clear the app's data.
Voice input
The chat mic button uses Android speech recognition to convert your voice into text in the input box. Speech recognition may be handled by the device's configured recognition service or provider (for example Google's speech services), rather than entirely on the device — audio may therefore be processed by that service according to its own policies. We do not receive or store your audio. The mic only listens while you activate it, and only with the RECORD_AUDIO permission you grant.
Processors
Third parties.
- OpenRouter — processes chat prompts (and any attached image) to generate AI answers. Prompts are sent from our server; we do not send your account credentials.
- Google (Sign-In, Mobile Ads, speech services) — authentication, advertising, and device-level speech recognition as described above.
- Gumroad — website payments only; never used inside the Android app.
- Web search — when a question needs fresh facts, our server queries a public search engine on your behalf and the results are included in the answer context.
Security
How we protect data.
Data is transmitted over HTTPS where applicable, and we apply reasonable technical and organizational measures to protect the data we hold. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
Your control
Access, deletion & retention.
Deleting your account
You can delete your account at any time — in the Android app under Settings → Account → Delete account, or signed in on the delete account page. Deletion is permanent: in one transaction we remove your account, saved recipes, chats, usage records and any pending premium grant linked to your account's email, and your app session is cleared. Purchase receipts are anonymized (personal identifiers removed) and kept for tax and accounting compliance; rate-limit and security counters are kept without personal content; and any AI content reports you submitted keep their moderation record with your user id removed. See the delete account page for the full detail. If you prefer, you can also ask us through the contact form, and we process deletion requests within 30 days.
Retention
Account data is kept while your account is active. Chat answers are cached server-side for a limited period so identical repeat questions do not have to be reprocessed; this cache is not keyed to you personally. Rate-limit counters are pruned automatically (typically within 24 hours) and technical logs are kept for a limited period; none of these are used for profiling.