Chef Arnold · Atanas Hristov
Privacy policy
Updated 8 September 2026
Your cooking data
Your name, food preferences, fridge, weekly plan, cooking history, meal log, reminders and optional weight entries stay on this device. There is no cloud sync of this cooking profile. The home-screen widget uses a shared local store. Your phone’s backup settings may include app data.
Subscriptions
Chef Arnold requires an active Apple subscription or eligible introductory trial. Apple processes payment. RevenueCat receives a random app user identifier, purchase and entitlement details, and connection metadata to validate access. We do not send your name, weight, recipes or food preferences to RevenueCat. Verified subscription access can be cached for a limited time offline, never beyond verified access expiry.
Photo scans
Photos are uploaded only after you review them and tap Send photo. Our Cloudflare service checks your subscription with RevenueCat, then sends the compressed image to OpenAI to suggest ingredients. No name, weight, cooking history or dietary profile accompanies it. A photo may contain personal information you choose to include. Review every result before adding foods; scanning cannot verify allergens, freshness or safety. Swaps and weekly planning run on your device.
Retention and deletion
The Chef Arnold photo service does not store photos or model drafts. It stores a random service identity, a hash of the device credential, its expiry, request identifiers/status and image hashes, and pseudonymous daily usage counters. These authenticate requests and prevent duplicate photo attempts. Service connections expire 90 days after creation or renewal; request metadata is removed after 48 hours. Hourly cleanup normally removes expired connections within one hour and request metadata within 49 hours. Daily counters stop applying at midnight UTC and are normally removed by the next hourly cleanup. A cleanup failure can delay removal. Delete service profile in Subscription & data to revoke the credential and erase its session/request records immediately after a successful response; daily counters remain until cleanup. Temporary photo copies may remain in the device’s OS-managed cache until removed.
Cloudflare’s processing
Cloudflare hosts the photo service and its database. It processes the image in transit and network information, including IP addresses, to deliver and protect requests. The application does not write photos, credentials or provider responses to logs. Infrastructure security records and database backups may have separate retention; deleting a service profile does not erase those independently retained records. See https://www.cloudflare.com/privacypolicy/ and contact the publisher for a data request.
OpenAI’s processing
We disable saved responses for photo scans. OpenAI may retain API content in abuse-monitoring logs for up to 30 days, or longer for legal or safety reasons. Images flagged by safety checks may be retained for review. Temporary prompt caches may also apply. We do not assume a zero-retention agreement. OpenAI does not use API data for training unless the account opts in to sharing. See https://developers.openai.com/api/docs/guides/your-data for its policy. Deleting a Chef Arnold service profile does not erase OpenAI’s independently retained records.
Your choices
Subscription & data is accessible even without a paid subscription. Erase local cooking data clears your profile, fridge, weekly plan, history, reminders, active timer, widget, recipe cache and optional measurement consent. It keeps the separate service credential so you can restore your purchase. Delete service profile separately to revoke it. Neither action cancels your Apple subscription or deletes Apple/RevenueCat purchase records or device backups. Use Manage or cancel in the App Store to stop renewal.
Optional advertising measurement
It is off by default. In builds that offer it, you must choose to enable it in the app’s Privacy settings and allow Apple’s tracking permission before the Meta SDK starts. Meta can receive basic interaction counts, advertising/device identifiers and network metadata to measure ads. Recipe identities, ingredients, weight, your name and food preferences are excluded from our event payloads. Withdrawing permission stops future events; it does not delete records Meta previously received.
Links and submissions
Opening an original recipe, licence or help page shares connection information with that website. A configured recipe service can receive your IP address when loading its public recipe count. Recipe submissions are unavailable unless a submission service has been enabled. Sharing a submission, when offered, sends only recipe content after your explicit action.
Contact and data requests
Chef Arnold is published by Atanas Hristov. Email atanas910@gmail.com for privacy questions or a data request. Do not email photos, passwords or service credentials unless a safe and necessary follow-up process has been agreed.