← Ember Recipes

Privacy Policy

Effective: 8 August 2026

This privacy policy explains what information we collect, how we use it, and your rights relating to it. It applies to all users of the websites, mobile applications and desktop applications provided by M Augustsson Holding AB, including the Ember Recipes app.

If you have any questions, please email support@ma-dev.se.

  • Name: M Augustsson Holding AB
  • Registered address: Markviksvägen 22a, 16559 Hässelby
  • Org number: 556942-8039
  • Publication director: Mats Augustsson
  • Email: support@ma-dev.se

M Augustsson Holding AB is the data controller for the processing described in this policy.

For privacy-related questions, requests concerning your personal data, or the exercise of your rights under data protection laws, please contact us at support@ma-dev.se. We have not appointed a Data Protection Officer, as we are not legally required to do so.

2. What information is collected?

2.1 Information that you give us

We collect and process information that you voluntarily give us. This includes:

  • Email address and display name at registration. If you register with a password, it is stored only as a salted hash. If you sign in with Apple instead, we receive from Apple a pseudonymous identifier for your account, and an email address if you allow it. That address may be a Private Relay alias (@privaterelay.appleid.com) which forwards mail to you without revealing your real address to us. If you choose to share no address at all, your account carries a placeholder that is not a working address and is never used to contact you. Such an account has no password until you choose to add one. We also store a token issued by Apple, used for one purpose only: to revoke your Apple sign-in if you delete your account.
  • Public @handle, short bio, avatar (preset colour/emoji, generated design, or an uploaded photo) — optional profile information.
  • Recipes — titles, ingredients, instructions, notes and photos, when you create or import them.
  • Subscription records — which product you purchased, Apple's transaction identifier, the current status and the renewal date. We never receive or store your payment details; Apple is the merchant of record.
  • Meal plans, shopping lists, pantry contents and wine cellar entries, as you use those features.
  • Restaurant visits — the restaurant's name, city and address, the date, your rating and review text, photos, and the names of people you record as having been present.
  • Comments, ratings and likes on recipes — optional social features.
  • Friend and follow relationships, and family membership — social and household features.
  • Messages you send to the AI meal planner.
  • Feedback you submit — optional.

Where you provide information about other individuals, you are responsible for ensuring that you have an appropriate basis for doing so and that sharing such information does not violate their rights.

2.2 Technical data

We automatically collect technical data when you use our services (websites, mobile apps, desktop apps). This includes the visited URL, your IP address, web browser name and version, operating system name and version, referrer address, device type, device country, device language, app version, date, time, error messages and anomalies. The collection of this data is necessary for the operation of the Service.

Technical data is collected for legitimate interests including:

  • To ensure the operation of our services
  • To prevent fraud
  • To implement security measures
  • To ensure server uptime
  • To detect errors and diagnose issues
  • To monitor performance and increase reliability
  • To display information specific to your language or country (such as prices in local currency)
  • To respond to legal requests

2.3 Usage data

We automatically collect usage data when you use our services (websites, mobile apps, desktop apps). This includes how you interact with our services and which features you use. The collection of this data is necessary for the operation of the Service.

Usage data is collected for legitimate interests including:

  • To detect and improve or remove unused product features
  • To understand errors

2.4 What your device provides

  • A biometric device key (a random token, generated by us and stored behind your device's Face ID / Touch ID) for optional biometric sign-in. We never receive or store your fingerprint or face data — those never leave your device.
  • Platform type (iOS / Windows), for aggregate usage statistics.
  • A record of each AI feature call — which feature, whether it succeeded, and the date — for enforcing daily usage limits and understanding cost.

We do not collect location data from your device, and we do not access your contacts, advertising identifiers or browsing history, and we do not use tracking or advertising cookies. There is no advertising in the app.

3. Photographs of other people

Restaurant visits and recipe photos may contain images of identifiable people other than you. If you upload a photograph of someone else, you are responsible for having their agreement to do so.

We process those images only to display them to you and to whoever you have shared that content with (your family, friends, or publicly, according to the visibility you chose).

4. How do we protect your privacy?

Your privacy matters to us.

  • We do not sell or share your information with third-party data brokers.
  • We do not sell or share your information with third-party advertising networks.
  • We do not display ads in our mobile or desktop applications.
  • We do not use advertising or tracking cookies. Essential technical cookies may be used to enable login, security, and operation of the service.

We use cloud-based servers with industry-standard TLS and HTTPS encryption to protect your information when it is transferred across the internet. We use pseudonymised or anonymised information as much as possible.

5. Why we process your information and the legal basis for doing so

We process personal data only when we have a valid legal basis under applicable data protection laws.

PurposeLegal basis
Creating and managing your account, storing and displaying your content, and providing the features of the servicePerformance of a contract
Sharing content with family members, friends, and other users according to your settingsPerformance of a contract
Processing recipe imports, meal planning, shopping lists, pantry management, restaurant records, and other core application featuresPerformance of a contract
Providing AI-powered features described in Section 6Performance of a contract
Processing subscription purchases and managing paymentsPerformance of a contract
Sending account-related communications such as verification emails, password reset emails, security alerts, and service notificationsPerformance of a contract and legitimate interests
Protecting accounts, preventing abuse, detecting fraud, enforcing usage limits, and maintaining platform securityLegitimate interests
Monitoring performance, diagnosing technical issues, ensuring reliability, and improving the serviceLegitimate interests
Producing aggregate and non-identifying usage statistics to understand how the service is used and to improve existing featuresLegitimate interests
Complying with legal obligations, regulatory requirements, court orders, and lawful requests from public authoritiesLegal obligation

Where we rely on our legitimate interests, we carefully consider and balance our interests against your rights and freedoms before processing your personal data.

We do not use your personal data for advertising purposes, do not sell personal data, and do not use personal data to build advertising profiles.

6. Who has access to your information?

We use various third-party service providers to manage our technical infrastructure and support the functionality of the app.

AI-generated recommendations are intended to assist users and are not used to make legally significant automated decisions.

AI and search providers

  • Anthropic — AI processing (USA): photo scanning (OCR); import functionality from web and social platforms (TikTok, Instagram); classification of recipes, ingredients and instructions; planning features and per-recipe chat features; shopping list features; wine information lookup; restaurant lookup.
  • Fal.ai — AI processing (USA): recipe image generation.
  • SerpAPI — search functionality (USA): restaurant lookup, recipe lookup.
  • Pexels — photo search functionality (Germany): stock photo search.
  • Pixabay — photo search functionality (Germany): stock photo search.

We do not send your email address, name, @handle or account identifier to any of these providers. The content itself may of course contain personal data if you put it there.

Anthropic's commercial terms state API inputs are not used to train their models.

Infrastructure and other providers

  • Resend — email delivery (USA; sending infrastructure in Ireland): sending in-app emails, password resets, account verification.
  • Fly.io — application hosting provider (USA). Application hosting and database storage are hosted in Sweden.
  • Tigris — backup (USA): encrypted off-site database replica (disaster recovery).
  • Apple — payment processing for subscriptions (Ireland / USA). Apple is the merchant of record and we never see your payment details; billing information is handled by Apple under their specific privacy terms.
  • TikTok / Instagram (USA) — when you import a recipe from a link, our server fetches that post's public caption. Those platforms receive the request and the post URL, not your identity or account.

We have implemented measures to protect your information, including by using Data Protection Addendums, when necessary. Where personal data is transferred outside the EEA, we rely on adequacy decisions, Standard Contractual Clauses (SCCs), or other lawful transfer mechanisms.

We may also share your information with law enforcement authorities when requested.

7. How long we keep it

Your content is kept for as long as your account exists. Logs and technical information may be retained in accordance with the table below.

Data typeRetention
AccountUntil deletion
RecipesUntil deletion
AI feature usage log (which feature was used, date, and success status)3 months
Support messages3 years
Technical logs3 months

When you delete your account — which you can do yourself, in the app, under Account — the deletion is immediate and irreversible. Your profile, recipes, photos, recipe collections, meal plans, shopping lists, pantry, wine cellar and wine wishlist, restaurant visits, saved special days, events you host, comments, ratings, planner conversations, friendships, follows and subscription records are erased from our live database, and your uploaded files are deleted from storage.

Content you shared with a family that still has other members is kept, with your name removed, so those people do not lose material they rely on. This is described in the app before you confirm. Two things survive deletion for a short, bounded period, for disaster recovery reasons:

  1. Our database is continuously replicated off-site (Tigris). The replica reflects the deletion within minutes, but a short window exists where deleted data is still present in it.
  2. We take daily snapshots of the storage volume and keep them for five days. A snapshot taken before your deletion still contains your data until it ages out.

We do not access these backups to retrieve deleted accounts, and they are overwritten on a schedule. Within five days of your deletion, all copies are gone.

Aggregate usage records (which AI feature was used, on which date, whether it succeeded) are kept with the link to your account removed, so they no longer identify you.

8. Your rights

You may request access to your data, correction, erasure, restriction, objection, and portability. In practice:

  • Access and portability — a machine-readable export of your data is available on request to support@ma-dev.se.
  • Erasure — delete your account in the app, under Account. See §7.
  • Everything else — contact us at support@ma-dev.se.

We normally respond within one month of verifying your identity.

You may complain to the Swedish authority, Integritetsskyddsmyndigheten (IMY) — www.imy.se.

9. Do we sell your personal information?

We have never and will never sell your personal information.

In the event of a change of ownership or other business transition, such as an acquisition, merger or partial sale of our business activities, your information may be transferred following applicable privacy laws.

10. Do we collect children's information?

Our services are not intended for children. We do not knowingly collect personal data from children and will delete such information if we become aware of it.

11. Security

Passwords are stored only as salted hashes. Traffic is encrypted in transit (HTTPS, enforced). Database backups are encrypted.

12. Changes

We will post changes here and update the date above. Material changes will be notified in the app.

13. How can you make a complaint?

You can contact us by email at support@ma-dev.se. We will do our best to help you.

If the problem has not been resolved satisfactorily and it concerns personal data, you have the option of contacting your data protection authority. If you reside in Sweden, you may contact Integritetsskyddsmyndigheten (IMY). If you reside in another jurisdiction, you may contact your local supervisory authority.