Privacy Policy
Last updated: September 4, 2026
BonsaiChef ("the app") is a cooking coach app operated by Ethan Coffin ("we", "us"). This policy explains what information the app handles and how. The short version: your food data lives on your phone, we don't sell data, and we don't show ads.
Information stored on your device
Your pantry inventory, logged meals, saved recipes, preferences, and progress are stored locally on your device. They are not uploaded to our servers as part of normal use and we cannot see them.
Information we process on our servers
- Account identifier. The app creates an anonymous account ID so features work without signup. If you later sign in (e.g., with Apple), we store the identifier and email associated with that sign-in.
- AI feature usage counts. We count how many AI recipe generations and photo scans your account uses each day to enforce daily limits. Counts reset daily.
- Photos you submit to AI features. When you scan groceries, receipts, recipe pages, nutrition-facts labels, or a finished meal on the plate, the photo is sent over an encrypted connection to our server and forwarded to our AI provider (Anthropic) to analyze it. Photos are processed to answer your request, are not stored on our servers, and are not used to build advertising profiles. Avoid including people or sensitive documents in photos.
- A shared food-lookup cache. When you type a meal description to look up its nutrition, we may keep that short sentence in a shared cache so the same lookup is faster next time. Cached entries carry no account identifier and cannot be linked to a person, are capped at 120 characters, and are deleted after 180 days. Photos are never stored in the cache or anywhere else on our servers.
- Anonymous records of how well a lookup worked. Alongside that cache we keep a short record of each nutrition lookup — the same food description, which match the app proposed, and whether you accepted, corrected or abandoned it — so we can find and fix the cases where the app matches food badly. These records carry no account identifier, cannot be linked to a person, and are deleted after 90 days. They contain no photos.
- Subscription status. If you subscribe to BonsaiChef Plus or Premium, Apple processes the payment. We receive subscription status (active/expired) from our subscription manager (RevenueCat) tied to your account ID — never your payment details.
- Messages you send us. If you write to us through the support form on bonsaichef.com, the name, email address, and message you type are forwarded to our support inbox so we can reply. They are not stored on our servers, and we use the address only to answer you.
Services we rely on
Supabase (server infrastructure and database), Anthropic (AI processing of the text and photos you submit), FatSecret (nutrition and recipe lookups — the food names you type or that appear on your receipts), Open Food Facts (barcode lookups), USDA FoodData Central (packaged-food and barcode lookups — the food names and barcodes being looked up), Resend (delivery of sign-in code emails to your address, and delivery of messages you send us through the support form on bonsaichef.com), RevenueCat (subscription management), and Apple (payments, TestFlight, App Store). Each receives only what is needed to provide its function, and none may use your data for advertising. You can revoke consent for all of this at any time by deleting your account in the app, which removes the server-side records held against your account — your account identifier, usage counts and subscription record. The two anonymous stores described above (the lookup cache and the lookup-quality records) are not covered by that deletion, because nothing in them identifies you: there is no way to tell which rows were yours. They age out on their own after 180 and 90 days.
What we don't do
- We do not sell or rent your personal information.
- We do not show third-party advertising.
- We do not access your contacts, location, or photo library beyond the photos you explicitly choose or take.
Data retention and deletion
Deleting the app removes your on-device data. To delete your server-side account data (account ID, usage counts, subscription record), use the account deletion option in the app's Preferences, or email us at the address below and we will delete it within 30 days.
Children
BonsaiChef is not directed at children under 13, and we do not knowingly collect personal information from them.
Changes
If this policy changes materially, we will update this page and note it in the app's release notes.
Contact
Questions or requests: ethancoffin16@gmail.com