Privacy Policy
Last updated 10 September 2026
CooknList is a recipe, meal-planning and nutrition app, published by Yelbuh, a sole proprietorship (“we”, “us”). This policy explains what we hold about you, why, and what you can do about it. It is written to be read rather than to be defensible, and if anything here is unclear you can ask us at hello@cooknlist.com.
The short version: we keep what you put into the app so we can show it back to you. We do not sell it, we do not advertise against it, and nothing here follows you around the internet. We do count visits, and that count cannot be traced back to you.
What we hold
Your account
Your name, email address and password. Passwords are stored only as a hash, so we cannot read yours and cannot tell you what it is. If you sign in with Google we receive your name, email address and profile picture from Google, and never your Google password.
What you save
Recipes, collections, meal plans, shopping lists and your pantry, including any photographs you upload. Where you saved a recipe from a website, we store what you kept, plus the address it came from so the original can be credited and opened.
Health-adjacent information
The food diary, weight log, water log and daily targets are, plainly, information about your body and what you eat. Setting daily targets involves telling us your height, weight, age, sex and activity level, because a calorie figure cannot be worked out without them.
We treat all of it as sensitive. It is processed for exactly one purpose: showing you your own numbers, and the projections and progress built from them. It is never sold, never shared with advertisers, never used to build a profile of you, and never shared with anyone else unless you deliberately share it yourself. Providing any of it is optional; the rest of the app works without it.
What you choose to share
Marking one of your own recipes as shared puts it in Discover, where anyone with a CooknList account can read it, save a copy, and see the name on your account beside it. Only recipes you wrote yourself can be shared: anything imported from another website stays in your own library. You can unshare a recipe at any time, though copies other people have already saved stay in their libraries.
If you share a collection, shopping list, pantry or meal plan with somebody, they can see what you shared for as long as the link lasts. That is the point of the feature, but it is worth saying out loud: sharing a list shares what is on it. Your diary, weight and targets are never included in a share.
Payments
If you subscribe, Stripe handles the payment. Card numbers are entered inside Stripe’s own form and never reach our servers, so we could not store your card if we wanted to. We keep your Stripe customer and subscription identifiers, the plan you are on, when it renews, and whether the last payment succeeded. If tax applies where you live, we hold the billing address you gave us, because a tax calculation and a receipt both need one.
Technical records
Ordinary server logs: the address of the request, roughly when it happened, and the IP address it came from. Sign-in attempts and rate limits are counted by IP so that passwords cannot be guessed at speed.
Photographs and voice recordings
When you capture a recipe from a photograph, read a nutrition label with your camera, or dictate a recipe, the image or audio is sent to Cloudflare Workers AI to be turned into text. It is used for that request and is not kept afterwards, by us or, under our agreement with them, by Cloudflare. What is kept is the recipe or the label reading that came out of it, and any photograph you deliberately attached to a recipe.
Who else is involved
We use a small number of services to run the app. Each is listed with what it actually receives:
- Cloudflare hosts the app and provides its database, file storage, live sync, AI processing and outbound email. Effectively everything you store passes through or sits with them.
- Stripe takes payments and holds your card details and billing address.
- Google only if you choose to sign in with it, and only to establish who you are.
- Open Food Facts when you scan a barcode. Only the barcode number is sent. Nothing identifies you, and nothing about your account goes with it.
- USDA FoodData Central when a food is looked up. Only the search text is sent.
- The website you import from. Saving a recipe from a URL means our servers fetch that page, so that site sees a request from us rather than from you.
We do not sell personal information, and we do not share it for advertising or any other purpose beyond the list above.
Cookies and counting visits
One cookie, which keeps you signed in. It holds nothing about you beyond the fact that it is you.
Opening a payment form loads Stripe, which sets two cookies of its own to tell a real customer from a stolen card. They arrive at that moment and not before, so a visit that never reaches a payment form never gets them.
We count visits, using Cloudflare Web Analytics. It sets no cookie, does not fingerprint your browser and cannot follow you to another site. What we see is page views, where they came from, which country and how fast the page loaded, added up, with no way to pick any one person out of it. Between that and the two above, there is nothing here that needs your permission, which is why you have not been asked to dismiss a consent banner.
Your browser also stores small preferences locally, such as your theme, which never leave your device.
How long we keep it
Your content is kept for as long as your account exists. Delete your account and it goes with it: recipes, collections, plans, lists, pantry, diary, weight and uploaded photographs are all removed, and any subscription is cancelled at the same time. Records we are required to keep for tax and accounting, principally invoices, are retained by us and by Stripe for as long as the law requires. Server logs are kept briefly and then discarded.
Your rights
You can, at any time:
- See and correct what we hold, from within the app.
- Delete your account and everything in it, from Settings. We confirm by email first, and nothing is deleted until you follow that link.
- Ask us for a copy of your data, or ask us to correct or delete something specific, by writing to hello@cooknlist.com.
If you are in the UK or the European Economic Area, the UK GDPR and GDPR give you rights of access, rectification, erasure, restriction, portability and objection, and a right to complain to your data protection authority. Our lawful basis is performing the contract for the app you asked us to provide, and, for the health-adjacent information above, your explicit consent, which you may withdraw by deleting that information or your account.
If you are in California, the CCPA gives you rights to know, delete and correct, and a right not to be discriminated against for using them. We do not sell or share personal information as those terms are defined there.
We are in Canada, so PIPEDA applies to us wherever you are. It gives you the right to see what we hold about you, to have it corrected, and to complain to the Office of the Privacy Commissioner of Canada if we get it wrong. Write to us first and we will try to put it right without you having to.
Children
CooknList is not intended for anyone under 16, and we do not knowingly collect information about them. If you believe a child has created an account, tell us and we will remove it.
Where your data is
Cloudflare and Stripe both operate globally, so your information may be processed outside the country you live in, including in the United States. Both are contractually bound to protect it under the standard safeguards that apply to those transfers.
Changes
If we change anything that matters here, we will update the date at the top and, where the change is significant, email you about it before it takes effect.
Contact
hello@cooknlist.com. We are Yelbuh, a sole proprietorship, based in Canada, and we are the data controller for the information described above.