Privacy Policy

Effective date: July 2026

Last updated: August 2026

1. Introduction

This Privacy Policy describes how DECODED.IO LIMITED ("RustleUp", "we", "us", "our") collects, uses, stores, and shares information about you when you use the RustleUp mobile applications (iOS and Android), the read-only web viewer at app.rustleup.xyz, and any related services (together, the "Service").

By creating an account and using the Service, you agree to the practices described in this Privacy Policy. If you do not agree, please do not use the Service.

We are based in the United Kingdom. The Service is operated globally, but data is processed primarily in the United States (see Section 9 on international transfers).

2. Data we collect

We collect only what we need to run the Service. The table below summarises every category, why we collect it, and where it is stored.

Account information

Item Source Why
Email address You provide it at sign-up, or it is shared by Google/Apple Sign-In To create your account, send sign-in links, and (occasionally) contact you about important Service changes
Authentication identifier Supabase Auth (our identity provider) Used internally as your account ID

You can sign in by email magic-link, Google Sign-In, or Apple Sign-In. We do not collect or store passwords ourselves — authentication is handled by Supabase Auth on our behalf.

Profile information

Item Why
Display name (optional) Shown in the app and on collections you make public
Dietary preferences (e.g., vegan, gluten-free, allergies) Used by AI features when generating recipes and suggesting filters. Never sold. Sent to our AI provider as part of those requests, so the results respect it (see Section 4); not shared beyond the processors listed in Section 4.
Avoid-ingredients list Used by AI features to exclude unwanted ingredients
Language and regional preference (e.g., en-GB, en-AU) Localises ingredient names and measurements
Measurement system (metric / imperial) Controls how quantities are displayed

User-generated content

Item Why
Saved recipes (ingredients, instructions, photos, notes) The core of the Service — your library
Recipe ratings (1–5 stars) For your reference and to surface your favourites
Personal notes on recipes Your private notes, stored only on your account
Meal plans (which recipe at which meal slot) The meal-planning feature
Shopping lists (recipe-derived plus custom items) The shopping feature
Pantry items The pantry-tracking feature
Collections (groups of recipes you create) Your organisation system; can be marked public if you choose to share
Chat conversations with the recipe AI assistant Stored on our servers so you can resume previous conversations and so we can enforce fair-use limits
Feedback you submit through the app Helps us improve the Service
Feature votes on the public roadmap Helps us prioritise development

Usage and analytics data

We use PostHog (see Section 4) to capture a defined set of product-analytics events. The complete list of events we capture, and the properties attached to each, is documented internally in our event taxonomy (ADR-038). The high-level summary:

Every event we capture is also tagged with:

What we deliberately do NOT capture as analytics properties (this is enforced in code at the point of capture):

If you have a paid subscription, the type of subscription (monthly or annual) is captured at purchase time so we can analyse conversion. Your payment card details are never captured (see Section 4).

Person-profile attributes

Tied to your account, not to individual events, we attach: email, display name, current subscription tier (free or premium), and language. These are used to enable filtered analytics (e.g., "how many premium users used the chat feature this week") without exposing individual events to PII.

Diagnostic and crash data

We use Sentry (see Section 4) to capture application crashes and unhandled errors. Sentry receives:

Sentry retains crash reports for approximately 90 days by default.

Subscription and payment data

If you subscribe to RustleUp Premium, payment is processed entirely by Apple (App Store) or Google (Play Store). We do not collect, store, or have access to your payment card or bank account details. RevenueCat (see Section 4) acts as our subscription-management layer: it receives a receipt from the store, validates it, and tells our backend whether your subscription is active. Your purchase receipt and entitlement state (premium / free, expiry date) are stored on our servers; payment instruments are not.

Device and install attribution

We use Branch.io (see Section 4) to attribute deep links and share links. Branch may collect a pseudonymous device identifier and limited install-attribution data (e.g., that you tapped a particular share link before installing) so that we can deliver the right recipe context when you first open the app. We do not use Branch for advertising attribution.

We also rely on PostHog's anonymous device identifier ($device_id) for analytics. This is generated by the PostHog SDK on first launch and is reset when you sign out.

Photos and camera

If you use the "scan a recipe from a photo" feature, the photo you select is uploaded to our backend and processed by an AI extraction service (currently routed through OpenRouter to OpenAI / Anthropic / Google models — see Section 4). The original photo is stored on our backend with your request history and is retained after extraction completes (see Section 5; the AI provider may also retain the request under its own policy — see Section 3). Extracted recipe text is then saved as part of your recipe library (see "User-generated content" above).

If you grant camera access for QR-code scanning or photo capture, photos are processed in-memory on your device unless you explicitly choose to use them in a feature that uploads to our backend.

Cookies and web storage

The mobile apps do not use cookies (cookies are a browser concept).

The web viewer at app.rustleup.xyz uses one PostHog analytics cookie (typically named _ph or similar) to maintain a session identifier across pages. No other cookies are set by us. The web viewer is read-only and does not support sign-in, so it does not store authentication tokens.

3. How we use your information

We use the information we collect to:

We do not sell your personal information, and we do not use your content to train our own models. AI model requests (recipe extraction, generation, and chat) are sent per request through OpenRouter, and our OpenRouter account is configured to exclude providers that train on submitted inputs. That is an account-level routing configuration we control — not a warranty about any individual model provider's internal practices, which OpenRouter's terms expressly disclaim. Separately, short ingredient-name text derived from recipes (names and synonyms only — never photos, chat, or personal data) is sent directly to OpenAI to compute search embeddings; under OpenAI's API terms, API content is not used to train their models by default. We do not currently have a zero-retention arrangement in place with either, so a provider may retain request data under its own policy (see Section 4).

4. Third-party processors

We rely on the following processors to operate the Service. Each is engaged under terms requiring them to handle your data only for the purposes we direct (the App Store and Play Store rows below act under their own terms). Where a processor routes requests on to sub-processors — see the AI row below — those terms bind our direct counterparty, not every downstream provider.

Processor Purpose Location of processing
Supabase Account authentication, primary database (your saved recipes, plans, etc.), file storage (recipe images) AWS US-East-1 (United States)
PowerSync Real-time data sync between your device and Supabase Cloud (staging and production); the development environment is self-hosted on our infrastructure
PostHog Product analytics and feature flags United States (us.posthog.com)
Sentry Crash reporting and release health monitoring United States (sentry.io)
RevenueCat Subscription receipt validation and entitlement management United States (revenuecat.com)
Branch.io Deep-link and share-link attribution United States
Cloudflare Content delivery, edge routing for the web viewer, share-link redirection Global edge network
OpenAI, Anthropic, Google (via OpenRouter; OpenAI also directly, for ingredient-name embeddings) AI models that power recipe extraction from URLs/photos/text, the recipe chat assistant, and AI-generated suggestions, previews and photo-based options. All AI calls go through our backend. For extraction and chat, the provider receives the recipe text, photo, or chat message needed for the request, plus a pseudonymous request identifier. When AI features generate suggestions, previews or photo-based options, the provider also receives your dietary profile — your diet types, allergies and ingredients you avoid, plus your preferred cuisines when you choose to apply your preferences — so the result respects it. No account email, payment data, or full user history is shared. For model requests our contract is with OpenRouter, which selects the model provider for each request; our account is configured to exclude providers that train on submitted inputs. Ingredient-name search embeddings are computed via OpenAI's API directly — short ingredient names and synonyms only (see Section 3). United States
GitHub (Actions — primary build pipeline, self-hosted runner) and Codemagic (standby) Build and release pipeline (does not receive runtime user data; only the application source code) Build-time only
Apple (App Store) and Google (Play Store) Payment processing and subscription billing Per Apple and Google's own privacy policies

The full list of integrations is also documented in our internal architecture decision records. We will update this Policy if we add, remove, or materially change a processor.

We do not currently use a transactional email provider, push-notification provider, or third-party moderation tool. If we add one in the future, we will update this list before the integration goes live.

5. Data retention

You can request immediate deletion of your account at any time — see Section 6.

6. Your rights

Depending on where you live, you have the following rights over your personal information.

EU / UK (GDPR / UK GDPR)

California (CCPA / CPRA)

How to exercise your rights

Email us at [email protected]. We will respond within 30 days (or longer if permitted by law for complex requests).

You can also delete your account directly from within the app: Account → Settings → Delete Account. If you cannot access the in-app flow for any reason, email us at the address above and we will process the deletion on your behalf.

7. Children's privacy

The Service is not directed at children under the age of 13 (or under 16 in the European Economic Area and the United Kingdom). You must self-attest that you are at least 13 (or 16 in the EU/UK) when you create an account.

If we learn that we have collected personal information from a child under the applicable age without verified parental consent, we will delete it as quickly as possible. If you believe a child has provided us with personal information, please contact us at the email address in Section 6.

8. Security

We protect your data through a combination of technical and organisational measures:

No system is perfectly secure. If you suspect your account has been compromised, contact us immediately at the address in Section 6.

9. International data transfers

We are based in the United Kingdom. Most of our processors (Supabase, PostHog, Sentry, RevenueCat, Branch.io, OpenRouter, the AI providers) operate in the United States. By using the Service, you acknowledge that your data may be transferred to and processed in countries other than your own, including the United States.

For users in the European Economic Area, the United Kingdom, and Switzerland, we rely on the European Commission's Standard Contractual Clauses (and the UK addendum where applicable) as the legal mechanism for these transfers. Our processors are bound by these clauses through their own data-processing agreements with us.

10. Changes to this policy

We may update this Privacy Policy from time to time to reflect changes in the Service, our practices, or applicable law. Material changes will be notified to you by in-app notice and/or email before they take effect. The effective date at the top of this Policy reflects the most recent change.

Continuing to use the Service after a change takes effect means you accept the updated Policy. If you do not accept it, you can delete your account at any time.

11. Contact us

For privacy questions, data-subject requests, or any other matters covered by this Policy:

Notes for review

This draft was prepared by the engineering team based on the codebase's actual data practices as of the launch date. It has not been reviewed by a qualified privacy lawyer. Before publishing, we strongly recommend:

  1. Legal review of the GDPR / UK GDPR / CCPA rights sections, the data-retention table, and the international-transfer mechanism (SCCs).
  2. Re-confirmation of the legal entity (DECODED.IO LIMITED), contact email ([email protected]), postal address (39 Ludgate Hill, London EC4M 7JN, UK), and effective date (July 2026) once final business decisions are made.
  3. Confirmation that the processor list in Section 4 matches the production deployment.
  4. If the Service is marketed to or used by EU/UK residents in significant numbers and the operator is not established in the EU/UK, appointing an Article 27 representative.
  5. Re-review when material features change (e.g., adding push notifications, web sign-in, new AI providers, new payment paths, or community features such as comments).