Your data

What we keep, for how long, and who else sees it.

Last updated 9 September 2026

How long things are kept

RecipeMirror has no automatic deletion. Nothing here expires on a timer except a shopping-list share link. What you make is kept until you remove it or delete your account, and we would rather say that plainly than write “only as long as necessary” and leave you to guess what that means.

WhatHow longNote
A recording you uploaded or madeUntil you delete itUnless you chose "delete after reading" when you brought it in, in which case our copy goes as soon as the guide exists. There is no automatic expiry.
A photograph of a recipe pageNot kept at allRead within the request and dropped. No file is written, so there is nothing to delete later.
Somebody else's video you linked toNever heldRecipeMirror reads a video where it lives. It does not download or re-host one.
Guides, corrections, cooking history, shopping listsUntil you delete your accountThese are the product. Nothing prunes them and nothing should.
A share link for a shopping list30 days, or until you turn it offThe one thing in RecipeMirror that expires on its own. A shopping list is a thing for this week.
Records of AI requests (model, timing, cost)KeptOperational data about the system rather than about you. No recipe content, no transcript.
Contact form messagesUntil answered and cleared by handNo automatic deletion. Ask and we will remove yours.

Who else processes it

These are every third party RecipeMirror sends data to. Sending a recording to a model to be read is a transfer, and it is named as one here rather than described as “processing”.

WhoWhat they doWhat they see
Google (Gemini)Reads videos, recordings and photographed pages, and answers questions about foodThe media you asked RecipeMirror to read, and the text of the prompt
SupabaseDatabase, sign-in and file storageYour email address, everything you make, and any recording we hold
VercelHosts the website and appOrdinary web logs — IP address, page, browser
RailwayRuns the APIOrdinary server logs, and anything passing through a request
PostHog (EU)Product analytics, only after you accept themNamed events. No recipe content, no email address. Nothing until you opt in
SentryTells us when a page or the API breaks, so we can fix itThe error, the page or request it happened on, and browser type. No IP address, email or recipe content
ResendDelivers sign-in links and repliesYour email address and the text of the email
Zoho MailHosts our mailboxesAnything you email us

Storage limits

A single upload is limited to 500 MB, and one account may hold up to 2 GB of stored video and photos in total. Reaching the cap refuses the next upload — it never deletes anything to make room. A product that quietly removed your oldest recipe to fit your newest would be choosing which of them mattered least, without asking. If you hit it, remove something you no longer want, or choose “delete the video after reading” on the ones you keep.

What a recipe’s creator can be told

The person whose video or page a recipe came from may be shown how it went in real kitchens: how many people cooked it, how many finished, which step people stopped at, and which amounts their recipe never gave. It is the one thing we know that their own analytics cannot tell them, and when they fix a missing amount, every future reading of that recipe improves.

It is counts, never people. No creator sees who cooked, when, what was written in a note, or anything about a particular kitchen. A channel report needs twenty cooks in total; each dish needs eight before it is broken out, and each step has its own floor on top of that — because an average taken over a handful of evenings is close enough to one of them to identify it.

What deletes itself, and what never does

Your recipes, guides, cooking history and uploaded media are never deleted automatically. Not after a year, not for being unused, not for any reason except you asking. They are why you are here.

What does expire on its own is everything RecipeMirror kept for its own purposes, each for as long as that purpose lasts: the raw AI response behind a reading, 30 days, so a reading that came out wrong can still be explained; payment webhook ids, 90 days, which is well past the point one could be replayed; the hashed network counters behind the free trial and rescue limits, 30 days, after a window that was one day long; and completed job records, 90 days, while the guide they produced is kept for good. The audit trail is kept for a year, because that is how long “who did what” stays a question anybody asks.

To remove everything, see delete your data. Anything else about your data: privacy@recipemirror.com. The full picture is in the privacy policy.