How Brillat holds what's in your fridge.
This Privacy Policy explains how Brillat, operated by Codeful, collects, uses, stores, and protects your information. By using Brillat you agree to this policy. If anything is unclear, write to us at support@vibeland.app before continuing to use the app.
Effective 2026-05-18 · Last updated 2026-05-18 · App: Brillat (app.codeful.chef-ai) · Publisher: Codeful
1. What we collect
1.1 Information you give us
- Account email — to authenticate you (Sign in with Apple, Google, or email).
- Fridge & receipt photos — images you upload to populate your inventory. We extract item names and quantities from them, then discard the raw image after extraction unless you choose to keep it.
- Inventory entries — names, quantities, storage state (cold/frozen/pantry), and expiration estimates for items in your fridge. You can edit or delete any entry.
- Cooking feedback — your 👍/👎 on each recipe and any tags you tap (e.g., "Saltier ↑", "Onion ↓"). Used only to tune your taste profile.
- Meal plans — the weekly plans you build or accept.
- Subscription receipts — when you purchase Pro, Apple sends us a transaction receipt and entitlement state.
1.2 Information collected automatically
- Device identifiers — an anonymous installation ID used to sync your data to your account and prevent abuse.
- Diagnostic data — crash reports and basic performance metrics. Anonymized.
- Usage analytics — aggregate counts of features used (e.g., "recipes generated this week"). Linked to your account but not sold.
1.3 What we do not collect
- We do not collect your location.
- We do not access your contacts, camera roll beyond the photos you upload yourself, or microphone.
- We do not include advertising SDKs and do not perform cross-app tracking.
- We do not collect HealthKit data.
2. How we use your information
| Purpose | Data used |
|---|---|
| Run the app on your device | Account, inventory, meal plan |
| Extract ingredients from your photo | The receipt or fridge image you uploaded |
| Generate recipes for what you have | Inventory + your taste profile |
| Learn your palate | Your 👍/👎 ratings and taste tags |
| Verify your subscription | Apple receipt, account ID |
| Improve the app | Anonymized diagnostics + aggregate usage |
| Reply to your support requests | Email and any details you send |
We do not sell or rent your data. We do not use your photos, inventory, or cooking feedback to train any AI model.
3. AI processing — important notes
- Brillat sends your inventory list (text) and your photo (only when you ask us to scan one) to an AI service in order to (a) extract ingredient names from the image and (b) generate recipes from the resulting ingredient list.
- We send only the photo and a numeric/text summary of your inventory and taste profile. We do not send your email, name, location, or any photo you have not chosen to upload.
- Recipes are generated suggestions, not certified food-safety advice. Always use your own judgment for allergens, intolerances, and freshness — Brillat's expiration estimates are heuristic and can be wrong.
- Extracted ingredient names and generated recipes are stored in your CloudKit Private Database (visible only to you). We retain the raw image only if you opt in to "Keep originals" in Settings.
- We do not use your photo or any derived data to train any AI model, and we do not share it with advertisers or analytics networks.
- We only send these inputs to the AI provider after you have granted consent through the in-app disclosure described in §5.
4. Third-party services
We rely on a small set of carefully chosen processors:
| Service | Purpose | Where data lives |
|---|---|---|
| Apple CloudKit (Apple Inc.) | Syncs your inventory, taste profile, and meal plans across your devices in your iCloud Private Database | Apple infrastructure |
| Cloudflare Workers (Cloudflare, Inc.) | Hosts the proxy that forwards image-OCR and recipe requests to the AI provider, with rate-limiting and abuse protection | Cloudflare global edge |
| AI inference provider (Anthropic, Google, or OpenAI — disclosed in-app) | Extracts items from your photo and generates recipes from your inventory | Provider infrastructure (US). The provider does not use data sent through their paid API to train their models |
| Apple StoreKit / App Store (Apple Inc.) | Handles all payments and subscription state | Apple infrastructure |
We share only the minimum each service needs to do its job. None of them are advertising or analytics networks. We have signed Data Processing Agreements where required.
5. Your consent before we send data to an AI service
The first time you scan a receipt or fridge photo, Brillat shows a one-time disclosure screen that explains, in plain language:
- What we will send: the image you just snapped and a summary of your existing inventory and taste profile.
- Who we will send it to: the current AI inference provider (named on the disclosure screen), via our Cloudflare Worker proxy.
- Why we send it: to extract ingredient names from the image and generate recipes from the resulting ingredient list.
- What we will not do: train any AI model on your data, share it with advertisers, link it to your name or email.
You must tap Continue to grant consent. If you decline, Brillat will not send your photo or inventory to the AI provider and the photo-scan and recipe features will be unavailable — the rest of the app (manual inventory, meal planner, taste profile) remains usable.
You can withdraw consent at any time in Settings → Privacy → AI service, which deletes any raw images we are holding and stops all future calls to the AI provider. Recipes already generated remain in your library.
6. How long we keep your data
- Inventory, taste profile, meal plans, recipes — kept while your account is active. Deleted within 30 days of account deletion.
- Receipt & fridge photos — by default, deleted within 24 hours of OCR. If you opt in to "Keep originals", kept until you delete them.
- Diagnostic logs — auto-rotated, retained 90 days max.
- Subscription receipts — kept as long as required for tax and audit (typically 7 years).
7. Your rights
You can, at any time:
- See what we have about you — request an export by emailing support@vibeland.app.
- Delete your account and all associated data — through Settings → Delete Account in the app, or by emailing the same address.
- Correct inaccurate data — via the app or by writing to us.
- Object to certain uses — explain in your message which use, and we will explore alternatives.
EU/UK residents have additional rights under GDPR/UK GDPR including the right to lodge a complaint with your data-protection authority. California residents have CCPA rights to know, delete, correct, and limit the sharing of personal information; we do not sell or share personal information for advertising.
8. Children
Brillat is not directed at children under 13 (under 16 in EU). We do not knowingly collect data from children. If you believe a child has provided data, contact us and we will delete it.
9. International transfers
Our backend proxy runs on Cloudflare's global edge; the AI inference provider runs in the United States. If you use the app outside the US, your data is transferred to and processed in the US under appropriate safeguards (Standard Contractual Clauses where required for EU/UK users).
10. Security
We use industry-standard encryption in transit (TLS 1.3) and at rest. CloudKit data is stored in your private database, accessible only to your iCloud account. Access to our proxy logs is limited to authorized engineers and audited. No system is perfect — if you suspect a breach, please contact us immediately.
11. Changes to this policy
We may update this policy as the app evolves. Material changes are announced inside the app and via the email on file at least 30 days before they take effect. The "Effective date" at the top reflects the version currently in force.
12. Contact
Codeful
110, Misagangbyeonhangang-ro
Hanam-si, Gyeonggi-do 12904
Republic of Korea
Email: support@vibeland.app
For data protection inquiries: support@vibeland.app
Version 1.0 · Last updated 2026-05-18
Terms of Service →