Privacy Policy

Effective date: July 2026

Last updated: September 2026

1. Introduction

This Privacy Policy describes how DECODED.IO LIMITED ("RustleUp", "we", "us", "our") collects, uses, stores, and shares information about you when you use the RustleUp mobile applications (iOS and Android), the read-only web viewer at app.rustleup.xyz, and any related services (together, the "Service").

By creating an account and using the Service, you agree to the practices described in this Privacy Policy. If you do not agree, please do not use the Service.

We are based in the United Kingdom. The Service is operated globally, but data is processed primarily in the United States (see Section 9 on international transfers).

2. Data we collect

We collect only what we need to run the Service. The table below summarises every category, why we collect it, and where it is stored.

Account information

Item Source Why
Email address You provide it at sign-up, or it is shared by Google/Apple Sign-In To create your account, send sign-in links, and (occasionally) contact you about important Service changes
Authentication identifier Supabase Auth (our identity provider) Used internally as your account ID

You can sign in by email magic-link, Google Sign-In, or Apple Sign-In. We do not collect or store passwords ourselves — authentication is handled by Supabase Auth on our behalf.

Profile information

Item Why
Display name (optional) Shown in the app and on collections you make public
Dietary preferences (e.g., vegan, gluten-free, allergies) Used by AI features when generating recipes and suggesting filters. Never sold. Sent to our AI provider as part of those requests, so the results respect it (see Section 4); not shared beyond the processors listed in Section 4.
Avoid-ingredients list Used by AI features to exclude unwanted ingredients
Language and regional preference (e.g., en-GB, en-AU) Localises ingredient names and measurements
Measurement system (metric / imperial) Controls how quantities are displayed

User-generated content

Item Why
Saved recipes (ingredients, instructions, photos, notes) The core of the Service — your library
Recipe ratings (1–5 stars) For your reference and to surface your favourites
Personal notes on recipes Your private notes, stored only on your account
Meal plans (which recipe at which meal slot) The meal-planning feature
Shopping lists (recipe-derived plus custom items) The shopping feature
Pantry items The pantry-tracking feature
Collections (groups of recipes you create) Your organisation system; can be marked public if you choose to share
Chat conversations with the recipe AI assistant Stored on our servers so you can resume previous conversations and so we can enforce fair-use limits
Feedback you submit through the app Helps us improve the Service
Feature votes on the public roadmap Helps us prioritise development

Usage and analytics data

We use PostHog (see Section 4) to capture a defined set of product-analytics events. The complete list of events we capture, and the properties attached to each, is documented internally in our event taxonomy (ADR-038). The high-level summary:

Every event we capture is also tagged with:

What we deliberately do NOT capture as analytics properties (this is enforced in code at the point of capture):

If you have a paid subscription, the type of subscription (monthly or annual) is captured at purchase time so we can analyse conversion. Your payment card details are never captured (see Section 4).

Person-profile attributes

Tied to your account, not to individual events, we attach: email, display name, current subscription tier (free or premium), and language. These are used to enable filtered analytics (e.g., "how many premium users used the chat feature this week") without exposing individual events to PII.

Diagnostic and crash data

We use Sentry (see Section 4) to capture application crashes and unhandled errors. Sentry receives:

Sentry retains crash reports for approximately 90 days by default.

Subscription and payment data

If you subscribe to RustleUp Premium, payment is processed entirely by Apple (App Store) or Google (Play Store). We do not collect, store, or have access to your payment card or bank account details. RevenueCat (see Section 4) acts as our subscription-management layer: it receives a receipt from the store, validates it, and tells our backend whether your subscription is active. Your purchase receipt and entitlement state (premium / free, expiry date) are stored on our servers; payment instruments are not.

Device and install attribution

We use Branch.io (see Section 4) to attribute deep links and share links. Branch may collect a pseudonymous device identifier and limited install-attribution data (e.g., that you tapped a particular share link before installing) so that we can deliver the right recipe context when you first open the app. We do not use Branch for advertising attribution.

We also rely on PostHog's anonymous device identifier ($device_id) for analytics. This is generated by the PostHog SDK on first launch and is reset when you sign out.

Photos and camera

If you use the "scan a recipe from a photo" feature, the photo you select is uploaded to our backend and processed by an AI extraction service (currently routed through OpenRouter to OpenAI / Anthropic / Google models — see Section 4). The original photo is stored on our backend with your request history and is retained after extraction completes (see Section 5; the AI provider may also retain the request under its own policy — see Section 3). Extracted recipe text is then saved as part of your recipe library (see "User-generated content" above).

If you grant camera access for QR-code scanning or photo capture, photos are processed in-memory on your device unless you explicitly choose to use them in a feature that uploads to our backend.

Cookies and web storage

The mobile apps do not use cookies (cookies are a browser concept).

The web viewer at app.rustleup.xyz uses one PostHog analytics cookie (typically named _ph or similar) to maintain a session identifier across pages. No other cookies are set by us. The web viewer is read-only and does not support sign-in, so it does not store authentication tokens.

3. How we use your information

We use the information we collect to:

We do not sell your personal information, and we do not use your content to train our own models. AI model requests (recipe extraction, generation, and chat) are sent per request through OpenRouter, and our OpenRouter account is configured to exclude providers that train on submitted inputs. That is an account-level routing configuration we control — not a warranty about any individual model provider's internal practices, which OpenRouter's terms expressly disclaim. Separately, short ingredient-name text derived from recipes (names and synonyms only — never photos, chat, or personal data) is sent directly to OpenAI to compute search embeddings; under OpenAI's API terms, API content is not used to train their models by default. We do not currently have a zero-retention arrangement in place with either, so a provider may retain request data under its own policy (see Section 4).

4. Third-party processors

We rely on the following processors to operate the Service. Each is engaged under terms requiring them to handle your data only for the purposes we direct (the App Store and Play Store rows below act under their own terms). Where a processor routes requests on to sub-processors — see the AI row below — those terms bind our direct counterparty, not every downstream provider.

Processor Purpose Location of processing
Supabase Account authentication, primary database (your saved recipes, plans, etc.), file storage (recipe images) United States (AWS us-east-2, Ohio)
Google Cloud (Cloud Run) Hosting for our backend, which handles AI requests, recipe extraction and subscription updates. It processes your requests but does not store your data at rest. United States (us-central1, Iowa)
PowerSync Real-time data sync between your device and Supabase (holds a working copy of the data it syncs) European Economic Area (AWS eu-west-1, Ireland) for staging and production; the development environment is self-hosted on our infrastructure
PostHog Product analytics and feature flags United States (us.posthog.com)
Sentry Crash reporting and release health monitoring United States (sentry.io)
Pydantic Logfire Backend observability: request traces, performance data and error logs from our backend United States
Langfuse AI request tracing: a record of AI model requests and responses, used to debug and improve our AI features United States
RevenueCat Subscription receipt validation and entitlement management United States (revenuecat.com)
Branch.io Deep-link and share-link attribution United States
Cloudflare Content delivery, edge routing for the web viewer, share-link redirection Global edge network
OpenAI, Anthropic, Google (via OpenRouter; OpenAI also directly, for ingredient-name embeddings) AI models that power recipe extraction from URLs/photos/text, the recipe chat assistant, and AI-generated suggestions, previews and photo-based options. All AI calls go through our backend. For extraction and chat, the provider receives the recipe text, photo, or chat message needed for the request, plus a pseudonymous request identifier. When AI features generate suggestions, previews or photo-based options, the provider also receives your dietary profile — your diet types, allergies and ingredients you avoid, plus your preferred cuisines when you choose to apply your preferences — so the result respects it. No account email, payment data, or full user history is shared. For model requests our contract is with OpenRouter, which selects the model provider for each request; our account is configured to exclude providers that train on submitted inputs. Ingredient-name search embeddings are computed via OpenAI's API directly — short ingredient names and synonyms only (see Section 3). United States
fal.ai AI image generation for recipe and ingredient pictures. It receives only a text description of the dish generated from the recipe; no account, profile or dietary data. United States
GitHub (Actions — primary build pipeline, self-hosted runner) and Codemagic (standby) Build and release pipeline (does not receive runtime user data; only the application source code) Build-time only
Apple (App Store) and Google (Play Store) Payment processing and subscription billing Per Apple and Google's own privacy policies

The full list of integrations is also documented in our internal architecture decision records. We will update this Policy if we add, remove, or materially change a processor.

We do not currently use a transactional email provider, push-notification provider, or third-party moderation tool. If we add one in the future, we will update this list before the integration goes live.

5. Data retention

You can request immediate deletion of your account at any time — see Section 6.

6. Your rights

Depending on where you live, you have the following rights over your personal information.

EU / UK (GDPR / UK GDPR)

California (CCPA / CPRA)

How to exercise your rights

Email us at [email protected]. We will respond within 30 days (or longer if permitted by law for complex requests).

You can also delete your account directly from within the app: Account → Settings → Delete Account. If you cannot access the in-app flow for any reason, email us at the address above and we will process the deletion on your behalf. What happens to the recipes you added is described in Section 5.

7. Children's privacy

The Service is not directed at children under the age of 13 (or under 16 in the European Economic Area and the United Kingdom). You must self-attest that you are at least 13 (or 16 in the EU/UK) when you create an account.

If we learn that we have collected personal information from a child under the applicable age without verified parental consent, we will delete it as quickly as possible. If you believe a child has provided us with personal information, please contact us at the email address in Section 6.

8. Security

We protect your data through a combination of technical and organisational measures:

No system is perfectly secure. If you suspect your account has been compromised, contact us immediately at the address in Section 6.

9. International data transfers

We are based in the United Kingdom, but your personal data is processed mainly in the United States. That covers our database, sign-in and file storage (Supabase), backend hosting (Google Cloud), product analytics (PostHog), crash reporting (Sentry), backend and AI observability (Pydantic Logfire, Langfuse), subscription management (RevenueCat), link attribution (Branch.io), and AI processing (OpenRouter and the model providers it routes to, OpenAI for ingredient-name embeddings, and fal.ai for images). Our sync service (PowerSync) runs in the European Economic Area (Ireland), and Cloudflare serves content from its global edge network. Section 4 lists each processor and where it processes data.

For users in the United Kingdom, the European Economic Area and Switzerland, transfers to the United States are covered by each processor's data-processing agreement with us. Depending on the processor, that agreement relies on the EU-U.S. Data Privacy Framework (with its UK Extension and the Swiss-U.S. Data Privacy Framework) where the processor is certified, or otherwise on the European Commission's Standard Contractual Clauses together with the UK International Data Transfer Addendum. Transfers from the UK to the European Economic Area rely on the UK's adequacy regulations. You can ask for more information about these safeguards at [email protected].

10. Changes to this policy

We may update this Privacy Policy from time to time to reflect changes in the Service, our practices, or applicable law. Material changes will be notified to you by in-app notice and/or email before they take effect. The effective date at the top of this Policy reflects the most recent change.

Continuing to use the Service after a change takes effect means you accept the updated Policy. If you do not accept it, you can delete your account at any time.

11. Contact us

For privacy questions, data-subject requests, or any other matters covered by this Policy: