Privacy

How Brillat holds what's in your fridge.

This Privacy Policy explains how Brillat, operated by Codeful, collects, uses, stores, and protects your information. By using Brillat you agree to this policy. If anything is unclear, write to us at support@vibeland.app before continuing to use the app.

Effective 2026-05-18 · Last updated 2026-05-18 · App: Brillat (app.codeful.chef-ai) · Publisher: Codeful

1. What we collect

1.1 Information you give us

  • Account email — to authenticate you (Sign in with Apple, Google, or email).
  • Fridge & receipt photos — images you upload to populate your inventory. We extract item names and quantities from them, then discard the raw image after extraction unless you choose to keep it.
  • Inventory entries — names, quantities, storage state (cold/frozen/pantry), and expiration estimates for items in your fridge. You can edit or delete any entry.
  • Cooking feedback — your 👍/👎 on each recipe and any tags you tap (e.g., "Saltier ↑", "Onion ↓"). Used only to tune your taste profile.
  • Meal plans — the weekly plans you build or accept.
  • Subscription receipts — when you purchase Pro, Apple sends us a transaction receipt and entitlement state.

1.2 Information collected automatically

  • Device identifiers — an anonymous installation ID used to sync your data to your account and prevent abuse.
  • Diagnostic data — crash reports and basic performance metrics. Anonymized.
  • Usage analytics — aggregate counts of features used (e.g., "recipes generated this week"). Linked to your account but not sold.

1.3 What we do not collect

  • We do not collect your location.
  • We do not access your contacts, camera roll beyond the photos you upload yourself, or microphone.
  • We do not include advertising SDKs and do not perform cross-app tracking.
  • We do not collect HealthKit data.

2. How we use your information

PurposeData used
Run the app on your deviceAccount, inventory, meal plan
Extract ingredients from your photoThe receipt or fridge image you uploaded
Generate recipes for what you haveInventory + your taste profile
Learn your palateYour 👍/👎 ratings and taste tags
Verify your subscriptionApple receipt, account ID
Improve the appAnonymized diagnostics + aggregate usage
Reply to your support requestsEmail and any details you send

We do not sell or rent your data. We do not use your photos, inventory, or cooking feedback to train any AI model.

3. AI processing — important notes

  • Brillat sends your inventory list (text) and your photo (only when you ask us to scan one) to an AI service in order to (a) extract ingredient names from the image and (b) generate recipes from the resulting ingredient list.
  • We send only the photo and a numeric/text summary of your inventory and taste profile. We do not send your email, name, location, or any photo you have not chosen to upload.
  • Recipes are generated suggestions, not certified food-safety advice. Always use your own judgment for allergens, intolerances, and freshness — Brillat's expiration estimates are heuristic and can be wrong.
  • Extracted ingredient names and generated recipes are stored in your CloudKit Private Database (visible only to you). We retain the raw image only if you opt in to "Keep originals" in Settings.
  • We do not use your photo or any derived data to train any AI model, and we do not share it with advertisers or analytics networks.
  • We only send these inputs to the AI provider after you have granted consent through the in-app disclosure described in §5.

4. Third-party services

We rely on a small set of carefully chosen processors:

ServicePurposeWhere data lives
Apple CloudKit (Apple Inc.)Syncs your inventory, taste profile, and meal plans across your devices in your iCloud Private DatabaseApple infrastructure
Cloudflare Workers (Cloudflare, Inc.)Hosts the proxy that forwards image-OCR and recipe requests to the AI provider, with rate-limiting and abuse protectionCloudflare global edge
AI inference provider (Anthropic, Google, or OpenAI — disclosed in-app)Extracts items from your photo and generates recipes from your inventoryProvider infrastructure (US). The provider does not use data sent through their paid API to train their models
Apple StoreKit / App Store (Apple Inc.)Handles all payments and subscription stateApple infrastructure

We share only the minimum each service needs to do its job. None of them are advertising or analytics networks. We have signed Data Processing Agreements where required.

The first time you scan a receipt or fridge photo, Brillat shows a one-time disclosure screen that explains, in plain language:

  • What we will send: the image you just snapped and a summary of your existing inventory and taste profile.
  • Who we will send it to: the current AI inference provider (named on the disclosure screen), via our Cloudflare Worker proxy.
  • Why we send it: to extract ingredient names from the image and generate recipes from the resulting ingredient list.
  • What we will not do: train any AI model on your data, share it with advertisers, link it to your name or email.

You must tap Continue to grant consent. If you decline, Brillat will not send your photo or inventory to the AI provider and the photo-scan and recipe features will be unavailable — the rest of the app (manual inventory, meal planner, taste profile) remains usable.

You can withdraw consent at any time in Settings → Privacy → AI service, which deletes any raw images we are holding and stops all future calls to the AI provider. Recipes already generated remain in your library.

6. How long we keep your data

  • Inventory, taste profile, meal plans, recipes — kept while your account is active. Deleted within 30 days of account deletion.
  • Receipt & fridge photos — by default, deleted within 24 hours of OCR. If you opt in to "Keep originals", kept until you delete them.
  • Diagnostic logs — auto-rotated, retained 90 days max.
  • Subscription receipts — kept as long as required for tax and audit (typically 7 years).

7. Your rights

You can, at any time:

  • See what we have about you — request an export by emailing support@vibeland.app.
  • Delete your account and all associated data — through Settings → Delete Account in the app, or by emailing the same address.
  • Correct inaccurate data — via the app or by writing to us.
  • Object to certain uses — explain in your message which use, and we will explore alternatives.

EU/UK residents have additional rights under GDPR/UK GDPR including the right to lodge a complaint with your data-protection authority. California residents have CCPA rights to know, delete, correct, and limit the sharing of personal information; we do not sell or share personal information for advertising.

8. Children

Brillat is not directed at children under 13 (under 16 in EU). We do not knowingly collect data from children. If you believe a child has provided data, contact us and we will delete it.

9. International transfers

Our backend proxy runs on Cloudflare's global edge; the AI inference provider runs in the United States. If you use the app outside the US, your data is transferred to and processed in the US under appropriate safeguards (Standard Contractual Clauses where required for EU/UK users).

10. Security

We use industry-standard encryption in transit (TLS 1.3) and at rest. CloudKit data is stored in your private database, accessible only to your iCloud account. Access to our proxy logs is limited to authorized engineers and audited. No system is perfect — if you suspect a breach, please contact us immediately.

11. Changes to this policy

We may update this policy as the app evolves. Material changes are announced inside the app and via the email on file at least 30 days before they take effect. The "Effective date" at the top reflects the version currently in force.

12. Contact

Codeful
110, Misagangbyeonhangang-ro
Hanam-si, Gyeonggi-do 12904
Republic of Korea

Email: support@vibeland.app
For data protection inquiries: support@vibeland.app


Version 1.0 · Last updated 2026-05-18

Terms of Service →