Privacy Policy

Cool Meat for Party

Effective date: 2026-09-21

This policy explains how this application handles information and how to contact us about privacy.

Information we process

Cool Meat for Party stores the recipes and their version history, ingredients, cooking instructions, marinades, spice rubs, sauces, tags, party plans, guest and portion counts, shopping lists, kitchen tools, cooking-session notes, timers, temperature measurements and selected photos that you choose to add. Records are stored on your iPhone in SwiftData; photos are stored in the app’s local application-support directory. PDF exports are saved in the app’s Documents directory. Language, temperature-unit, synchronization and pending-deletion preferences are stored locally. An automatically generated random installation secret is stored in this iPhone’s Keychain. When synchronization is enabled, the app sends your records, timestamps and photos to its backend. The backend stores an installation identifier and one-way credential hashes, structured records and recipe snapshots in SQLite on a Railway persistent volume, and photos in a private Railway S3-compatible bucket. There are no user accounts, contact lists, location access, advertising identifiers or analytics SDKs. The hosting infrastructure still receives requests and connection metadata, which may include IP addresses and request times when you use the app’s online features or visit this website.

How we use information

The app uses this information to maintain your personal cooking notebook, preserve and restore recipe versions, calculate ingredient quantities, build shopping lists, run cooking timers and keep photos and measurements with your meals. Your installation secret authorizes access to only that installation’s server records. Synchronization retains a server copy and retries pending local changes when the app is active with connectivity; it is not an account-based recovery or cross-device sign-in service. Notifications provide local timer alerts. Photos are resized and re-encoded as JPEG on the iPhone before storage and upload; original photo-library files are not modified. PDFs are created only when you request an export. Application error logs contain a generated request identifier and error type, rather than your recipe content or credentials.

Service providers and sharing

Railway provides the application hosting, persistent volume and private object-storage infrastructure used for synchronization and this public website. The backend uses the AWS S3 client library to communicate with the configured Railway-compatible storage endpoint; it does not send your data to a separately configured advertising, analytics or messaging service. Railway and the infrastructure used to deliver its service process the requests and technical metadata needed to operate that hosting. We do not sell your cooking content or use it for targeted advertising. If you export a PDF through the iOS share sheet, the destination you select receives that file and handles it under its own practices. Timer notifications are handled locally by iOS, with no app-operated push notification server. This public privacy page requires no login and sets no application cookies.

Data retention

Local records remain until you delete them or remove the app’s local data. The installation secret can remain in the system Keychain independently of app files; it is cleared by successful in-app deletion of all data. Server records remain until deletion is requested. The server maintains up to fifty accepted recipe-envelope snapshots in addition to the version history carried inside your recipe. Deleting a document clears its server payload and recipe snapshots, while retaining a minimal identifier-and-timestamp tombstone to prevent an older offline copy from restoring it. Photos can remain on the server until Delete all my data removes the installation’s photo collection. Exported PDFs remain in the local Exports directory until all-data deletion or app removal; copies shared to another destination have that destination’s retention rules. No application backup schedule or fixed infrastructure-log retention period has been configured or verified. We do not promise a specific retention period for Railway infrastructure logs or any provider-managed backups.

Deleting your information

Use Settings, Delete all my data to remove the local notebook, local photos and app-managed PDF exports and request removal of the installation’s server records and private photo objects. The app retains a pending-deletion marker and the credential needed to retry if the server cannot be reached; new record saves are paused while deletion is pending. Keep the installation and reconnect so the request can finish. The backend records erasure intent, blocks ordinary data access and deletes the installation’s object-storage prefix before removing its database records and revoking its token. The app clears its Keychain secret after confirmation. Uninstalling alone does not send a server deletion request, and loss of the secret can prevent us from locating or authorizing access to your private records. Deletion does not retract files already shared with other apps, your own device backups or infrastructure backups outside the app’s direct control. Any provider-retained residual copies are subject to the provider’s practices; an exact backup-removal timetable is not known.

Permissions and your choices

Camera access is requested when you choose to take a cooking photo. You can instead use the system photo picker, which shares only the images you select without giving the app general access to your photo library. Notification permission is requested when scheduling a cooking timer; denying it leaves the in-app timer available but prevents background alerts. You can revoke camera or notification permission in iPhone Settings at any time. Previously saved content is not removed merely by withdrawing a permission; use deletion controls for that. The app does not request microphone, location, contacts or tracking permission. Synchronization can be switched off in app Settings without preventing local cooking-notebook use.

Your privacy rights

For privacy questions or requests concerning access, correction or deletion, contact eu.fallowmere@icloud.com. This address is a public privacy contact, not an account identifier or an in-app email delivery feature. You can inspect and correct your records in the app, export recipes or plans as PDF and use the all-data deletion control. Depending on your location, applicable law may provide additional rights, including objection, restriction or a complaint to a data-protection authority. We may need enough information to verify that a request concerns your installation, and cannot promise recovery or identify private records after its secret has been lost. Do not send your installation secret in an ordinary email.

Security

The deployed API uses HTTPS. A random secret is generated on the device and stored with a this-device-only Keychain accessibility setting; no shared server credential is embedded in the app. Server authentication resolves installation ownership before private record or photo operations, and only one-way credential hashes are stored in the database. Photos are served through an authenticated API proxy rather than a public bucket URL. Server storage credentials remain in Railway configuration. Input sizes, installation storage quotas, rate limits and serialized private operations reduce accidental abuse and inconsistent deletion. Local photo files use iOS file protection. These measures do not make any system risk-free, and we do not claim unverified encryption-at-rest settings, compliance certifications or guaranteed availability.

Children’s privacy

Cool Meat for Party is intended for adults and other people who can safely plan and carry out home cooking, rather than as a service directed to young children. It has no age-profile or identity-collection flow. Do not enter a child’s identifying or sensitive information in recipes, notes or photos. If you believe such information has been included improperly, use the in-app deletion controls or contact eu.fallowmere@icloud.com so we can discuss a verified request.

Changes to this policy

We may update this policy when the application’s processing or hosting changes. The current policy and its effective date are published at this page and linked from app Settings. Review it when deciding whether to use synchronization or other online functions. Material changes will be reflected in the published policy and, where needed, in an app update. The privacy contact remains eu.fallowmere@icloud.com.