Privacy
What RecipeMirror holds, and what it refuses to.
Last updated 21 September 2026
Who is responsible
Rivoryn Ltd (CRO 815118) operates RecipeMirror and is the data controller for personal information collected through this website and the web app. We are based in Ireland and comply with the GDPR and the Irish Data Protection Acts 2018 — the same arrangement as DrySpell. For anything about your data, write to privacy@recipemirror.com. Product questions go through the contact form. A registered office will be added here when it is published, rather than invented on this page.
What is held
The sources you bring in, the guides built from them, what you have said you have in your kitchen, your cooking history and any corrections you make. Your display name and email, if you have signed in. Messages you send through a form, so somebody can reply.
What is not held
RecipeMirror does not store the videos it reads from public links. It reads them where they live and links back. It does not build an advertising profile and does not sell lists. RecipeMirror does not train any model on your cooking — but to read a source it sends it to Google’s Gemini, and on our current plan Google may use submitted data to improve their products.
Recordings of other people
A recording of a family member is consented for private analysis only. RecipeMirror does not publish it and does not show it to other users, and the share control does not appear at all on a guide built from one. Reading it means sending it to Google’s Gemini, which on our current plan may use submitted data to improve their products — so please do not upload a recording of someone else until you are comfortable with that.
What stays on your device
Your theme, your mise-en-place ticks, your kitchen equipment list, demo mode, and your cookie choice. Those describe a device and a room rather than an account, and a cook using the app at someone else’s house should not have their own pans follow them there. See the cookie policy for the exact keys.
Why we hold it (legal bases)
- Contract / steps you asked for. Creating a guide, scaling a recipe, naming foods in a photo, signing in, exporting or deleting your account.
- Consent. Analytics events (only after you accept), a family recording (the in-app gate), and the native-app waitlist (one email when there is something to install).
- Legitimate interests. Reading a contact message so we can reply, keeping the service secure, and diagnosing a failure you reported. You can object; we will stop unless we have a compelling reason to continue.
Who else sees anything
Processors act on our instructions. They are not given a kitchen or a dish unless that is the job you asked us to do.
- Hosting. The website is served from our host (Vercel when deployed). They see ordinary web logs.
- Accounts and dishes. Supabase, when you sign in — guides, cooks and profile data for your account.
- Email. Resend delivers a contact-form or waitlist message to us. The inboxes themselves are privacy@recipemirror.com and hello@recipemirror.com, hosted on Zoho Mail. No auto-reply. Zoho and Resend see the address and the text so they can hold or deliver it.
- Analytics. PostHog on EU hosting, and only if you allowed analytics. Named actions and a path. Never a recipe, transcript, email or message body.
- Counting visits. We keep a number for each day, page and source word — for example “20 September, /features, youtube” — so we know how many people came and which link brought them. No cookie, no identifier, no account, no IP address, no query string and no referring page: nothing in it points at a person, including you, which is why it does not wait for consent. The source is whatever a link was tagged with (?utm_source=youtube) or the platform you followed a link from.
- Reading a source. An AI provider, through our own API, when you ask us to analyse something. What is sent is the source and the prompt — not your name or email. The provider in use is named in the product where a source is analysed.
YouTube
RecipeMirror uses YouTube API Services. RecipeMirror never signs you in to YouTube, never asks for access to your YouTube account, and holds no YouTube token, watch history, subscription or any other information about you held by YouTube. Everything below is public information about videos and channels.
What YouTube data we access and store
- Searching on the Cook page. The video id, title, channel name, thumbnail, length and publication date of each result.
- A video you bring in. Its link and id, title, channel name and thumbnail, kept with the guide made for you. The description the creator wrote is read while your guide is being built and is not kept; what stays from it is the ingredients and steps, if they wrote the recipe there.
- Examples on signed-out pages. The same public fields for a small set of videos shown to visitors who have not signed in.
- A creator verifying a channel. The channel’s public name and description, to confirm the code they placed there.
How we use it, and who else sees it
It is used to show you search results, to label a guide with the video it came from and link back to it on YouTube, and to read the recipe a creator published in their description. It is not used for advertising, not sold, not given to data brokers, and not used to train any model of our own.
Inside RecipeMirror, data stored with a guide is visible to you and to anyone you share that guide with. Our own staff reach it only to fix a fault you have reported. Outside RecipeMirror it reaches two processors, and no one else: Supabase, on EU hosting, which runs the database it is stored in; and Google, whose Gemini model reads the video description when you ask us to build a guide from a video — on our current plan Google may use data submitted to Gemini to improve their products. Search results held on our server are not linked to your account.
How long we keep it, and how it is refreshed
The YouTube API Services Developer Policies allow this data to be stored for up to 30 days, after which it must be refreshed or deleted, and RecipeMirror stays inside that. Search results are deleted after seven days. Example videos are re-fetched from YouTube every 20 days and removed at 29 if a re-fetch has not succeeded. The video data stored with your guide — its title, channel, thumbnail, and any recipe read from the description — is re-checked against YouTube every 25 days. If YouTube still returns the same thing, the stored copy is refreshed. If the creator has edited the recipe in their description, our copy is replaced with the one they have now. If the video has been made private or taken down, our copy of YouTube’s data about it is deleted: the title, the channel, the thumbnail and the copied recipe all go. Your guide itself stays either way — it is yours, and a creator taking a video down is not a reason to take your dinner away. Deleting a guide, or your account, deletes the YouTube data held with it at the same time — write to privacy@recipemirror.com and we will confirm.
By using these features you agree to be bound by the YouTube Terms of Service. Google’s handling of that data is described in the Google Privacy Policy, and you can review or remove any app’s access to your Google account at Google’s security settings. Questions about what RecipeMirror holds go to privacy@recipemirror.com.
Checking a video before you publish it
A creator can send us a cut from their own machine, or an unlisted link, to find out which amounts and steps a viewer would have to guess. An unpublished video is the most sensitive thing anyone sends us, so: the file is stored only for as long as it takes to read it and is deleted as soon as the reading finishes. We do not publish it, do not show it to another user, and no share control appears on it. Reading it means sending it to Google’s Gemini, which on our current plan may use submitted data to improve their products.
What we keep after the file is gone is the reading itself — the ingredients, the steps, and the gaps found in them — stored with your account. That is what the creator page counts, so it can tell you what keeps coming up across your videos rather than only what happened in one. A check is readable only by the account that asked for it; anyone else asking for it is refused, including with a correct link. Nothing from a check is shown to another creator, published, added to any public figure, or used to train a model of ours. Delete the video from your library, or your account, and the check goes with it.
How long
Account data until you delete the account. Contact messages until we have replied and no longer need the thread. Waitlist addresses until you ask us to remove them or we send the one email and close the list. Analytics events according to PostHog’s retention on our project, and they stop when you withdraw consent. Device storage until you clear the site data.
Your rights
You can ask to access, correct, delete or export what we hold; restrict or object to processing; and withdraw consent (analytics, waitlist, a recording) without affecting anything that happened before you withdrew. Kitchen Profile already has an export and a delete that genuinely deletes rather than hiding. For anything else, email privacy@recipemirror.com. You can also complain to the Data Protection Commission in Ireland (dataprotection.ie), or your local supervisory authority if you live elsewhere in the EEA.
Children
The product is not directed at children under 13. If you believe we have collected data from a child, email privacy@recipemirror.com and we will delete it.
Cookies
Analytics do not run until you opt in. Details, including how to change your mind, are on the cookie policy.
Honestly stated: these pages describe what the software actually does. They have not been reviewed by a lawyer and are not a substitute for one. They will be replaced with reviewed versions before RecipeMirror takes money or launches as a paid product. Product questions go to contact or hello@recipemirror.com. Anything about your data goes to privacy@recipemirror.com.
