Privacy Policy
In force since 18 September 2026 · version 3
The German version of this document is the legally binding one.
CobleCook is an app for collecting recipes and planning meals together in households and at events.
This Privacy Policy describes which personal data is processed when using CobleCook, what we use it for and how long it is stored.
§ 1 Controller
The controller responsible for the processing of personal data is:
Max Scheidlock
Kolonnenstr. 8
10827 Berlin
Germany
Email: support@coblecook.de
§ 2 User Account
You need a user account to use CobleCook.
Registration is only possible using an email address and password.
In particular, we process:
- your email address,
- your password exclusively as a cryptographic hash, and
- technical session information.
We need this data to provide your user account, log you in, manage your session and, where necessary, enable you to reset your password.
Legal basis: Art. 6(1)(b) GDPR.
§ 3 What Data We Process
| Data | Purpose | Legal Basis |
|---|---|---|
| Email address, password hash, where applicable display name | User account, login, password reset | Art. 6(1)(b) GDPR |
| Device and session information, login times | Maintain login, manage sessions, prevent misuse | Art. 6(1)(b) and (f) GDPR |
| Recipes, ingredients, preparation instructions, labels and personal notes | Provision of your cookbook and recipe features | Art. 6(1)(b) GDPR |
| Manually created recipes for the CobleCook recipe catalogue | Provision of the shared recipe catalogue | Art. 6(1)(b) GDPR |
| Weekly meal plans and shopping lists | Meal planning and shared use within a household | Art. 6(1)(b) GDPR |
| Personally uploaded recipe images | Display in your personal cookbook | Art. 6(1)(b) GDPR |
| Photos or screenshots that you use to import a recipe | Converting an image into a recipe draft | Art. 6(1)(b) GDPR |
| Shared Instagram or comparable links and publicly available content required for them | Creating a personal recipe draft | Art. 6(1)(b) GDPR and, for third-party data, Art. 6(1)(f) GDPR |
| Calendar absence information | Taking your availability into account in the weekly meal plan | Art. 6(1)(b) GDPR |
| Event memberships, recipes and shopping lists within an event | Joint planning of an event | Art. 6(1)(b) GDPR |
| Information about App Store purchases and subscription status | Activation and management of paid features | Art. 6(1)(b) GDPR |
| Server logs, in particular IP address, timestamp, requested path and error messages | Operation, troubleshooting and defence against attacks | Art. 6(1)(f) GDPR |
We do not process allergies or other health data for recipe planning. If you need to avoid certain foods due to an allergy, intolerance or medical condition, you are responsible for checking recipes and ingredients accordingly.
§ 4 Households
With CobleCook, you can use a household together with other people.
A household can consist of up to four people.
New participants must be approved by the person who created the household.
Within a household, participants can in particular jointly access and edit the following content:
- the shared cookbook,
- saved recipes,
- weekly meal plans,
- shopping lists, and
- personal notes, where they are created within a jointly used recipe.
If you save something within a shared household, you must therefore assume that the other participants in that household can access it.
§ 5 Events
You can create events in CobleCook and invite other people to them.
New participants in an event must be approved by the owner of the event, meaning the person who created the event and activated its invite code.
Within an event, approved participants can in particular jointly view and edit:
- the recipes saved for the event, and
- the shared shopping list.
Content within an event is made available exclusively to the participants of that event and is not published publicly.
An event is generally stored until its creator deletes it.
§ 6 Public Recipe Catalogue
CobleCook includes a general recipe catalogue that may be available to all users.
If you manually create or upload your own recipe in CobleCook, this recipe may be added to the general recipe catalogue.
In particular, the following recipe content may be used:
- title,
- ingredients,
- quantities,
- preparation steps, and
- other structured information belonging to the recipe.
The public recipe catalogue does not show which user originally submitted the recipe.
In particular, the following are not included in the public recipe catalogue:
- your email address,
- your user account,
- personal notes, and
- recipe images personally uploaded by you.
If your user account is deleted, the technical connection between your user account and a recipe that remains in the recipe catalogue is removed. The recipe may subsequently remain part of the CobleCook recipe catalogue in anonymised form.
Further information about the rights of use relating to these recipes can be found in our Terms of Use.
Imported Recipes
Recipes that you import from an external source are not added to the general recipe catalogue.
This applies in particular to recipes that are:
- imported via Instagram or comparable services, or
- imported by photographing, scanning or uploading an existing recipe.
These recipes remain in your personal area or in a shared household selected by you.
§ 7 AI Features and Recipe Scanner
CobleCook uses artificial intelligence for certain clearly defined features.
These include in particular:
- importing a recipe from a photo or screenshot,
- creating a recipe draft from a shared Instagram or comparable post, and
- generating recipes.
For these features, requests are forwarded via Cloudflare to OpenAI.
We do not transmit your email address, user ID, account ID or any other direct identifier of your CobleCook user account.
The AI request is technically made independently of your user account. In particular, we do not attach a user identifier to the request for analytics, advertising or tracking purposes.
Recipe from a Photo or Screenshot
If you import a recipe using the scanner feature:
- You take a photo, for example of a cookbook page, or select a screenshot.
- The image is transferred to our server.
- To extract the recipe, the image is transmitted via Cloudflare to OpenAI.
- A recipe draft is created from it.
- You can then review and save this draft.
The scan is used exclusively to capture the recipe for you.
Import via a Shared Link
If, for example, you share an Instagram post with CobleCook via the share menu:
- The URL of the post is transmitted to our server.
- Our server retrieves the publicly available information from the post.
- Where necessary, the public caption is processed in particular.
- The relevant text is transmitted via Cloudflare to OpenAI and converted into a recipe draft.
- A publicly available cover image required for the recipe may be stored within your personal recipe.
When the public page is retrieved, Meta or the operator of the external platform only learns that our servers accessed the relevant URL. We do not transmit any CobleCook account data to Meta.
We use third-party data from such publicly available posts exclusively to provide you with the requested import feature. We do not add this data to the public CobleCook recipe catalogue.
AI-Generated Recipes
If you use a feature for generating a recipe, we send the request required for creation via Cloudflare to OpenAI.
No CobleCook account data or direct user identifiers are transmitted.
AI-generated content may contain errors. Additional information on the required review of such recipes can be found in our Terms of Use.
Your Own Recipe Images
Images that you personally upload as an image for an existing recipe are not analysed by an AI service.
They are only stored and technically processed to the extent required for display, for example by resizing or compression.
§ 8 Calendar
CobleCook can access your calendar in order to take into account days or meals during weekly planning when you are not available. The assessment of whether a calendar entry means that you are unavailable for a meal takes place directly on your device.
Calendar access only takes place after you have expressly granted permission in iOS.
You decide which calendars the app may access.
What Remains on Your Device
The following information is not transmitted to our servers:
- event titles,
- exact times,
- locations,
- participants,
- event notes, and
- the calendars selected by you.
The assessment of whether a calendar entry means that you are unavailable for a meal takes place on your device.
What Is Transmitted to CobleCook
Only information about which days or relevant meals you are unavailable for is transmitted to our servers.
Other participants in your household can see this information in the shared weekly meal plan.
However, they cannot see why you are unavailable.
CobleCook does not create appointments in your calendar, modify appointments or delete appointments.
The analysis covers the current week and the following three weeks. Outdated or past absence information is removed during subsequent calendar synchronisation and deleted no later than the end of the relevant planning period.
If you disable calendar access in the iOS settings, no new calendar information will be processed.
§ 9 App Store, Subscriptions and Purchases
Paid CobleCook features are currently offered via the Apple App Store.
These include in particular:
- the CobleCook subscription, and
- paid activation of an invite code for an event.
The actual payment processing is carried out by Apple.
CobleCook does not receive your credit card details, bank account details or other complete payment information.
We only receive or process the technical information required to recognise a purchase or subscription and activate the relevant feature. This may in particular include:
- the purchased product,
- the status of a subscription,
- purchase and expiry dates, and
- technical transaction identifiers.
Apple processes data in connection with the App Store and payment processing under its own responsibility and in accordance with Apple's privacy policies.
§ 10 What Does Not Take Place
A secure and data-minimising app experience is important to us.
CobleCook does not use your data for behavioural advertising or the sale of user data.
In particular, the following currently does not take place:
- no advertising tracking,
- no Facebook Pixel,
- no Google Analytics within the app,
- no advertising identifiers,
- no sale of your personal data,
- no disclosure of your data to third parties for their own advertising purposes, and
- no creation of user profiles for advertising purposes.
AI features are used exclusively for the purposes described in § 7.
§ 11 Where Your Data Is Stored and Which Service Providers We Use
CobleCook's core data is stored on servers operated by Hetzner Online GmbH in Germany.
We currently use the following service providers in particular:
| Service Provider | Purpose | Location |
|---|---|---|
| Hetzner Online GmbH | Server, database and file storage | Germany |
| Infomaniak Network SA | Sending system emails, e.g. confirmation and password reset emails | Switzerland |
| Cloudflare, Inc. | Technical forwarding of AI requests | USA |
| OpenAI | Processing of the AI requests described in § 7 | USA |
Where these companies process personal data on our behalf, this takes place on the basis of appropriate data processing agreements.
An adequacy decision by the European Commission applies to Switzerland.
For transfers to the USA, we use the mechanisms provided for under the GDPR for international data transfers. Where the respective recipient is certified under the EU-US Data Privacy Framework, the transfer may be based on the corresponding adequacy decision. Otherwise, in particular, the European Commission's Standard Contractual Clauses may be used.
§ 12 Retention Periods and Deletion
We store personal data only for as long as it is required for the respective purpose or where statutory retention obligations apply.
In particular, the following rules currently apply:
Account
Your account and personal content are generally stored for as long as your account exists.
If you do not use CobleCook for more than one year, we may delete your inactive account and the associated personal data.
We generally notify you 30 days in advance using the email address stored in your account.
Using the app again resets this period.
After Account Deletion
After deletion of your account, your personal account data is deleted or anonymised unless statutory retention obligations prevent this.
Content within a jointly used household or event may remain where it is still required by other participants.
A recipe that has already become part of the general CobleCook recipe catalogue may remain there in anonymised form. The connection to your user account is removed.
Deleted Recipes
If you delete a personal or imported recipe, we also delete the images and imported content stored in connection with that recipe.
This applies in particular to:
- scanned recipe images,
- saved screenshots, and
- cover images from imported links.
Households
A household without members is permanently deleted after 30 days.
This allows accidentally abandoned households to be restored within this period.
Events
An event is generally stored until it is deleted by the owner.
After deletion, the personal event data and jointly stored content associated with the event are deleted unless statutory retention obligations prevent this.
Calendar Data
Calendar absence information is only required for the relevant planning period. Past or outdated entries are removed as part of calendar synchronisation and deleted no later than the end of the relevant planning period.
Login Data and Security Information
- Confirmation and reset links are deleted no later than upon expiry.
- Counters for failed login attempts are generally deleted 24 hours after the last failed attempt.
- Technical deletion markers required for synchronising different devices may be stored for up to 90 days.
Email Logs
Delivery information relating to our system emails, in particular recipient address, email type and time of sending, may be stored for up to twelve months as proof of delivery.
We do not use tracking pixels and do not record whether you have opened an email.
Server Logs
Technical server logs are stored in a limited ring buffer and are overwritten with new entries after a few days during ongoing operation.
Passwords and authentication tokens are not stored in server logs.
Backups
Backup copies are stored for no longer than 14 days.
Deletion takes effect immediately in the live system. Existing backups may still contain data until the respective backup is automatically deleted.
§ 13 Your Rights
Under the GDPR, you have in particular the right to:
- access the personal data stored about you (Art. 15 GDPR),
- rectification of inaccurate data (Art. 16 GDPR),
- erasure of personal data (Art. 17 GDPR),
- restriction of processing (Art. 18 GDPR),
- data portability (Art. 20 GDPR),
- withdrawal of consent with effect for the future (Art. 7(3) GDPR), and
- object to processing based on Art. 6(1)(f) GDPR (Art. 21 GDPR).
An informal message to support@coblecook.de is sufficient.
You also have the right to lodge a complaint with a data protection supervisory authority.
The authority responsible for us is in particular:
Berlin Commissioner for Data Protection and Freedom of Information
Alt-Moabit 59–61
10555 Berlin
Germany
You may also contact the data protection supervisory authority responsible for your habitual place of residence.
§ 14 Security
The connection between the CobleCook app and our servers is encrypted using TLS.
Passwords are not stored in plain text, but exclusively as cryptographic hashes.
Administrative access to our servers is technically restricted and protected against unauthorised access.
§ 15 Changes to this Privacy Policy
If the processing of personal data or the features of CobleCook change materially, we will update this Privacy Policy accordingly.
The date shown above indicates the current version of this Privacy Policy.
In the event of material changes, we will inform you within the app or by another appropriate means.