Introduction
Wellnoria AB ("we," "us," or "our") operates Daily Simmer ("the Service"), including its web and mobile applications and assistant connections for AI-powered recipe creation and management. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service.
Last updated: August 16, 2026
This policy is a notice about our processing of personal data, not a request for consent to every activity it describes. Where processing requires your consent, we ask for it separately and you may withdraw it.
Definitions
- Account - A unique account created for you to access our Service.
- Company - Wellnoria AB, registered in Sweden, referred to as "the Company," "we," "us," or "our" in this policy.
- Personal Data - Any information that relates to an identified or identifiable individual.
- Service - Daily Simmer's web and mobile applications and related services, including assistant connections.
- Service Provider - A third-party company or individual employed by the Company to facilitate the Service, provide the Service on behalf of the Company, perform services related to the Service, or assist the Company in analyzing how the Service is used.
- Usage Data - Data collected automatically, generated by the use of the Service or from the Service infrastructure itself (for example, the duration of a page visit).
- You - The individual accessing or using the Service.
Information We Collect
Account Information
When you create an account, we collect your email address, display name, and profile image through our authentication provider, Clerk. You may sign in using Google, Apple, or email-based authentication. We store your account identifier and profile details to provide a personalized experience.
Recipe and Content Data
We collect and store the recipes you create, edit, and save within the Service. This includes recipe titles, ingredients, instructions, labels, images, and any other content you provide. We also store chat messages exchanged with the AI assistant, imported recipes from external URLs, and images you upload.
Imported URL and Social-Source Content
When you ask us to import a recipe from a public URL, we retrieve the public content needed to complete your request. Smart Import may use Bright Data for webpage retrieval and ScrapeCreators for supported social-source retrieval. We share the submitted public URL with the relevant provider and receive the public page or post content and limited technical response data.
For supported Instagram, TikTok, YouTube, and Facebook links, the retrieved public content may include the creator's display name or handle, caption or description, and media. We do not sign in to those services or access content hidden from signed-out visitors.
Retrieved social text is cached for about one hour and then deleted. We retain the resulting recipe, its image, and a limited import record containing the source and thumbnail URLs, platform, creator handle, caption length and one-way hash, and technical diagnostics until account deletion or an earlier valid removal request. We do not retain the caption text in the import record or use it to profile the creator.
If You Posted Content That Someone Imported
If public content you posted was imported, you may object to our use of your personal data or ask us to remove it by emailing support@dailysimmer.com and identifying the post. We handle requests under the rights and timeframes below. You may also report alleged infringement under our Terms of Service.
Dietary and Allergy Data
We ask for dietary preferences, structured allergies, and optional custom allergy information so we can tailor recipes and review them against the needs you provide. Some allergy or medical-diet information can reveal health information. We use it only for the recipe and personalization features you request, not for advertising, product analytics, or AI-model training. Where this information is special-category health data under the GDPR, we ask for separate explicit consent before saving or using it, in addition to the legal basis for providing the requested feature. You may withdraw that consent in Privacy settings without losing access to unrelated parts of the Service. Withdrawal clears the saved structured and custom allergy information and stops future use; it does not affect processing that was lawful before withdrawal.
Usage Data
We automatically collect certain information when you visit, use, or navigate the Service. This information does not reveal your specific identity but may include your IP address, browser type and version, device information, operating system, referring URLs, pages visited, and timestamps of your interactions.
AI Interaction Data
When you interact with the AI recipe assistant, your chat prompts and recipe content may be sent to Google Generative AI directly or through OpenRouter, depending on the model provider configured for the relevant Service environment, for recipe generation and modification. Image generation prompts are derived from your recipe data to create recipe images. These interactions are processed by third-party AI providers as described in the Third-Party Service Providers section.
Assistant Connections
You may connect Daily Simmer to a third-party AI assistant, such as ChatGPT or Claude, through our Model Context Protocol (MCP) service. When you authorize a connection, we process the connection's OAuth information, including the assistant client, approved permissions, connection status, and security timestamps. Clerk authenticates your Daily Simmer account, Cloudflare provides the MCP transport, and Convex processes the authorized recipe operation.
An authorized assistant may search for and read recipes that your Daily Simmer permissions allow it to access. When recipe saving is available and you authorize write access, the assistant may send us a structured recipe and optional source note to create a recipe in your account. An assistant may present an additional confirmation step according to the client you use. We do not receive the assistant's full conversation unless the assistant includes information from it in an operation you authorize. We do not use assistant connection data, recipe requests, or saved recipe content to train AI models.
You can revoke an assistant connection at any time at https://mcp.dailysimmer.com/connections. The assistant provider's own privacy policy and terms also apply to its handling of your conversations and any information you share with it.
Payment Data
Web billing is handled by Polar.sh, while mobile purchases may be handled by Apple or Google through RevenueCat. We store purchase and subscription identifiers, product and plan details, purchase time, amount and currency where the provider supplies them, and subscription status to manage paid access and consumer rights. We do not collect or store payment card details directly.
If you use the online withdrawal function, we store the purchase concerned, your name and account email, the server receipt time and reference, delivery status for the electronic acknowledgement, and the status and provider reference for refund or access-revocation processing. This record provides your receipt, carries out the request, prevents duplicate processing, and preserves evidence of when it was received.
Notification Data
If you enable mobile push notifications, we store an Expo push token, platform, and optional device label so we can send requested service notifications, such as Family invitations and referral updates. Expo forwards notifications to Apple Push Notification Service or Google Firebase Cloud Messaging. Cooking timers are scheduled locally on your device.
Analytics Data
We use PostHog's EU-hosted service to collect limited interaction data for product analytics. Web and mobile analytics use the EU ingestion endpoint. We use events such as coarse page or screen areas and feature interactions to understand reliability and how features are used. On the web, we remove page titles, URL query strings, fragments, referrers, search keywords, raw campaign parameters, click identifiers, and dynamic path details before an event is sent. We do not use PostHog session replay or automatic interaction capture, and we do not send your name, email address, recipe content, or chat content to PostHog.
Where applicable law requires prior permission for analytics storage or access, including in the EEA, United Kingdom, and Canada under our current policy, analytics remains off until you choose to enable it. If we cannot determine the applicable region, analytics also remains off. In other markets under our current policy, analytics starts automatically for our legitimate interest in understanding and improving the Service. You can disable analytics at any time through Privacy settings or the storefront's Privacy choices in every market.
To apply this rule, Cloudflare derives a two-letter country code from the incoming request's IP address and our first-party Service returns the applicable analytics setting to the web or mobile app. Daily Simmer does not add that country code to the stored analytics choice or save it to your account for this decision.
On the web, we may record one minimized first-touch attribution record when a Daily Simmer link contains standard campaign tags or when the referring website reported by your browser matches a referral source we recognize. The record contains source, medium, campaign, term, content, a coarse landing area, and landing and binding times. For a recognized referral without campaign tags, we normalize the source and medium and discard the raw referrer and full URL. After sign-in, Clerk carries the record to Convex, which links it once to your internal account ID so we can measure aggregate signups and activation. The account-bound record itself is not sent to PostHog. When PostHog analytics is active under the regional policy above, eligible usage and outcome events may contain copies of the normalized source, medium, campaign, term, content, and coarse landing area. Neither the account-bound record nor those copied attribution fields include the raw referrer or full URL, click identifiers, IP address, search terms, recipe, or chat content. The account-bound record is retained until account deletion or a verified objection to this legitimate-interest processing. In markets requiring prior permission for browser storage, we keep the candidate only in memory until analytics storage is enabled.
Cookies and Local Storage
We use cookies and local storage for the following purposes:
- Essential: Authentication tokens managed by Clerk are required for the Service to function. These cannot be disabled.
- Preferences: We store your theme preference (
simmer-theme) and promotional banner dismissal states in local storage to remember your settings across sessions. Your language selection is stored in local storage and in a first-partysimmer-languagecookie, so the page renders in your language from the start instead of switching after it loads. This cookie is a functional preference, not tracking or advertising, is not shared with any analytics or advertising provider, and lasts up to 1 year or until you clear your browser data. If your browser holds an earlierreceptia-languagelocal storage value from before this cookie existed, we read it once to carry your existing language choice forward. - Offline and feature state: We store account-scoped recipe data, unsent chat and recipe-creation drafts, active cooking state, checkout handoff state, and similar feature state in browser or app storage so the Service can recover your work and support offline use. Session-only interface state expires with the browser tab. A pending checkout expires after 24 hours. Other feature state remains until the feature clears it, you sign out where applicable, you delete the account through the app, or you remove the browser/app data.
- Analytics: PostHog may use web cookies, browser local storage, or mobile app storage to collect usage analytics. In markets requiring prior permission, these technologies remain dormant until you enable analytics. In other markets under our current policy, they start automatically. You can change your choice at any time in Privacy settings on web and mobile or through Privacy choices in the public website footer.
- Signup attribution: The web app may store one bounded first-touch record from standard campaign tags or a recognized website referral under
daily-simmer-signup-attribution-v1. It expires after 30 days and is not overwritten by later visits. In markets requiring prior permission for storage, it remains in memory until that permission is granted. - Advertising: We do not use any advertising cookies or tracking technologies.
How We Use Your Information
We use the information we collect for the following purposes:
- Provide and operate the Service, including account management, recipe storage, and content delivery
- AI recipe generation and modification, where your chat messages and recipe content are sent to Google Generative AI directly or through OpenRouter to generate and refine recipes
- Dietary and allergy personalization, using the preferences you choose to provide for recipe generation and review
- Image generation, where recipe data is used to create prompts for generating recipe images
- Process purchases, subscriptions, billing, refunds, and online withdrawal requests through the applicable payment or app-store provider
- Internal product and campaign measurement, such as feature usage, general interaction patterns, and aggregate signups and activation from attributed links and referrals. We do not send recipe or chat content to PostHog or analyze individual recipe content for product analytics
- Send account and user-requested emails via Resend, including security, billing, collaboration, and other messages needed for the Service or requested by you
- Send getting-started emails when enabled, consisting of one welcome email and up to two behavior-aware recipe-start emails during the first four days. Eligibility uses account age, whether you saved a recipe, and a bounded set of product actions; this category does not include promotions, newsletters, or ongoing re-engagement
- Send enabled service notifications through Expo and the device push services
- Security, rate limiting, and abuse prevention to protect the Service and its users
Legal Bases and Electronic-Marketing Rules
We use the following GDPR legal bases and, for electronic mail, the separate marketing rules identified below:
- Performance of a contract: We process account details, recipes, chat content, user-requested AI and assistant operations, subscription status, and transactional messages when this is objectively necessary to provide the Service or take steps you request before entering into a contract.
- Consent: We use consent for analytics where prior permission is required and for other processing presented to you as optional. We use explicit consent under GDPR Article 9(2)(a) when allergy or medical-diet information you provide reveals health information. You may withdraw consent at any time. Withdrawal does not affect processing that was lawful before withdrawal.
- Legitimate interests: Outside markets where prior permission is required, we process limited product-usage events to understand reliability and feature use and improve the Service. We also process a minimized, account-bound signup-attribution record to understand which Daily Simmer links and recognized web referrals result in account creation and activation. We process limited technical and diagnostic data to secure the Service, prevent fraud and abuse, enforce rate limits, investigate failures, maintain reliability, and establish or defend legal claims. Under GDPR Article 6(1)(f), we also process public creator information needed when you direct Smart Import to retrieve a specific social page. We limit this to public content from the page you name, do not use it for profiling, advertising, or model training, minimize retention, and provide the objection and removal process described above. Our interests are improving and protecting Daily Simmer, operating a dependable service, and protecting our legal rights. We limit analytics through EU hosting, a restricted event set, no advertising or sale, no session replay or automatic interaction capture, exclusion of names, email addresses, recipes, and chats, and an opt-out available in every market. You have the right to object to processing based on legitimate interests.
- Electronic-marketing consent: We send the finite getting-started series only after you explicitly enable it while signed in. Both optional email categories are off by default, and signup does not depend on either choice. You may withdraw at any time through the no-login link in every message, by replying, or in Preferences. A saved in-product or link withdrawal stops the category and queued messages at the sending chokepoint. Newsletters and promotions require a separate choice and are not currently sent. Under GDPR Article 21, your objection to direct marketing is absolute.
- Legitimate interests for related records: We use a minimized behavior evaluation to choose or suppress the next getting-started message and retain the versioned notice record and one-way email suppression digest to demonstrate and honor your choice. These supporting records are separate from the electronic-mail sending rule above. Our interests are helping a new account reach the recipe service it requested, preventing unwanted messages, and demonstrating compliance; safeguards include a four-day limit, no promotions, data minimization, no open/click tracking, and the objection controls above.
- Legal obligations: We may process information when Swedish or EU law requires it, including accounting, tax, and responding to legally binding requests.
Where one activity has several purposes, we assess each purpose separately and apply the basis appropriate to that purpose.
Third-Party Service Providers
We share data with the following third-party providers to operate the Service:
| Provider | Purpose | Data Shared |
|---|---|---|
| Clerk | Authentication | Email, name, profile image |
| Convex | Backend/database | Application data, including minimized account-linked signup-attribution records |
| Google Generative AI | AI chat, image generation, and recipe extraction from an imported page; the YouTube Data API supplies a public video's title, description, and thumbnail for a YouTube import | Chat messages, recipe content, image prompts, retrieved page or post text, and the public video identifier for a YouTube import |
| OpenRouter | AI model routing, including recipe extraction when the Google model is not configured for that environment | Chat messages, recipe content, retrieved page or post text |
| Polar.sh | Web billing, refunds, and subscription access changes | Email, purchase and subscription identifiers, product, amount, currency, subscription status, and withdrawal receipt reference |
| RevenueCat | Mobile purchase and entitlement management | App account identifier, store transaction and product details, entitlement status |
| Apple App Store and Google Play | Mobile payment, refund, and subscription processing | Store account and transaction information handled under the store's own terms; Daily Simmer sends or receives transaction status through RevenueCat or the applicable store process |
| PostHog | Product analytics | Limited usage and outcome events, normalized acquisition source, medium, campaign, term, content, and coarse landing area when available, an internal account identifier, and plan type when analytics is active under the applicable regional policy; web and mobile event ingestion is configured for PostHog's EU service |
| Resend | Transactional email, including withdrawal acknowledgements and recipe activation onboarding | Recipient email, rendered message subject/body, and delivery metadata. A saved-recipe activation email may include the recipe title, description, and servings in that rendered content; Daily Simmer does not send Resend a separate structured recipe record or API payload |
| Cloudflare | Hosting, CDN, R2 storage | All served content, uploaded images |
| Sentry | Error monitoring and service reliability | Error reports and technical diagnostics that may include an account or device identifier; default web PII, mobile account email, and mobile screenshots are excluded, and MCP reports also exclude recipe bodies and OAuth tokens |
| Bright Data Ltd | Public webpage retrieval for Smart Import | Submitted public URL, returned public page content, and limited technical request data |
| ScrapeCreators (Web Scraping Guy LLC) | Public social-source retrieval for Smart Import | Submitted public post URL, returned public post content, and limited technical request data |
| Expo, Apple Push Notification Service, and Google Firebase Cloud Messaging | Mobile push delivery | Push token, platform, notification content, and delivery status |
| Connected AI assistants | User-authorized recipe search, reading, and (when enabled) saving through MCP | The recipe operation requested by you, plus the structured recipe and optional source note for an authorized save |
We use providers only for the purposes described above. Some providers may act as independent controllers for limited processing they determine themselves, such as payment compliance or an assistant provider's handling of your conversation under its own service terms.
Instagram, TikTok, YouTube, and Facebook are sources rather than service providers. Their terms and privacy policies govern their handling of requests to public pages.
Data Sharing
We share your personal data only in the following circumstances:
- With Service Providers: We share data with the third-party providers listed above solely for the purpose of operating and improving the Service.
- Business Transfers: If the Company is involved in a merger, acquisition, or asset sale, your personal data may be transferred. We will provide notice before your data is transferred and becomes subject to a different privacy policy.
- Legal Requirements: We may disclose your personal data if required to do so by law or in response to valid requests by public authorities (for example, a court or government agency).
We do not sell your personal data to third parties. We do not use your content to train AI models. Your recipes, chat messages, and other content remain yours.
Data Retention
We retain your personal data for as long as your account is active and as needed to provide you with the Service. When you delete your account through the Service, Daily Simmer first removes account data, recipes, chat history, push tokens, assistant records, import records, and associated content from the primary application database, then schedules related AI-thread cleanup and deletion of the Clerk account. After successful deletion, the mobile app removes its user-scoped offline database, and the web app removes its account-scoped offline database and feature state. Device-wide language, theme, and analytics choices may remain because they are not account records.
Purchase contracts and online withdrawal receipts remain available with your active account so you can review the request and we can prevent duplicate fulfillment. If you delete your account, purchase records with no withdrawal request are deleted from our primary application database. An accepted withdrawal receipt and its linked purchase record are detached from the deleted account and retained until eight years after we received the withdrawal, then automatically deleted. This bounded period allows us to deliver and complete the request, preserve accounting evidence for the required period, and establish or defend legal claims. Payment, email, or app-store providers may retain their own transaction or delivery records for periods they determine under their legal obligations and service terms.
Text retrieved from a social-source page is held in a short-lived retrieval cache for about one hour, is not read after it expires, and is deleted automatically by a scheduled job. The import record that remains keeps the minimized fields described in Imported URL and Social-Source Content above, not the caption text, until account deletion or until we honour a creator's objection.
For assistant connections, pending authorization transactions expire after 10 minutes and active connection credentials expire after 30 days unless renewed. Records used to prevent duplicate recipe saves expire after 30 days, and recipe-write security audit records expire after 90 days.
Our current PostHog project setting retains analytics events for up to 84 months unless we delete them earlier, and PostHog is configured to discard client IP addresses before event storage. Sentry event retention follows the active Sentry project setting. Resend documents a standard 30-day retention period for transactional email data. Push tokens remain until sign-out or unregister, invalid-token cleanup, or account deletion. Expo says notification contents remain only in delivery queues and push receipts are cleared after 24 hours.
If you object to getting-started emails, we retain a one-way digest of your normalized email address and the category, time, and source of the objection after account deletion. This narrow suppression record prevents a recreated account from silently restarting the series. We retain it while we offer that email category, unless you later make an explicit signed-in choice to turn the category back on.
The browser or device copy of an eligible signup-attribution candidate expires after 30 days. Where local storage permission is required, we keep that candidate in memory until you make a storage choice. If it is linked to your account, the minimized attribution record remains until account deletion or a verified objection to this legitimate-interest processing.
Deleting the Daily Simmer account does not cancel an Apple or Google subscription, delete a conversation held by a connected assistant provider, or instantly remove records that another provider must keep as an independent controller. Residual processor copies may remain temporarily in routine backups or deletion queues. A verified erasure request may therefore require us to run provider-specific deletion processes for analytics, monitoring, billing synchronization, email, or remote retrieval records.
International Data Transfers
Some of the service providers identified above process personal data outside the European Economic Area, including in the United States. A provider may also route data or appoint subprocessors in countries described in its current service terms. The destination depends on the provider and the features you use.
Where GDPR transfer restrictions apply, we use an applicable European Commission adequacy decision or another appropriate safeguard, such as the European Commission's Standard Contractual Clauses, with supplementary measures where required. Providers that act as independent controllers describe their international-transfer safeguards in their own privacy terms.
Contact support@dailysimmer.com to ask which destination country and safeguard apply to a particular provider or use of your information, and to obtain a copy of the relevant safeguard, subject to lawful redactions.
Security
We implement appropriate technical and organizational security measures to protect your personal data, including:
- Encryption of data in transit (TLS/SSL) and at rest
- HTTP Strict Transport Security (HSTS) enforcement
- Security headers including X-Frame-Options: DENY, X-Content-Type-Options: nosniff, and strict Referrer-Policy
- Rate limiting to prevent abuse
- JWT-based authentication through Clerk with secure token handling
While we strive to protect your personal data, no method of transmission over the Internet or electronic storage is completely secure. We cannot guarantee absolute security.
Children's Privacy
The Service is not available to anyone under the age of 16. We do not knowingly collect personal data from children under 16. If we become aware that we have collected personal data from a child under 16, we will take steps to remove that information from our servers. If you believe we have collected data from a minor, please contact us immediately.
Your Rights (GDPR)
If you are located in the European Economic Area, you have the following rights under the General Data Protection Regulation:
- Right of Access: You have the right to request copies of your personal data.
- Right to Rectification: You have the right to request that we correct any information you believe is inaccurate or complete information you believe is incomplete.
- Right to Erasure: You have the right to request that we erase your personal data under certain conditions.
- Right to Restrict Processing: You have the right to request that we restrict the processing of your personal data under certain conditions.
- Right to Object to Processing: You have the right to object to our processing of your personal data under certain conditions.
- Right to Data Portability: You have the right to request that we transfer the data we have collected to another organization, or directly to you, under certain conditions.
You can download your recipes, embedded recipe images, and selected collection structure at any time from Data export in Settings. The native archive is designed for restoring that content to Daily Simmer; it does not include account credentials, billing records, chat history, analytics events, or the identities of other collection members.
To exercise a right for other applicable personal data, please contact us at support@dailysimmer.com. We will respond to your request within 30 days. Account erasure requests will be processed within 30 days of verification.
You also have the right to lodge a complaint with the Swedish Authority for Privacy Protection (IMY) or another competent supervisory authority in the EEA.
California Privacy Rights (CCPA)
If you are a California resident, you have the following rights under the California Consumer Privacy Act:
- Right to Know: You have the right to request that we disclose what personal information we collect, use, and share about you.
- Right to Delete: You have the right to request deletion of the personal information we have collected from you, subject to certain exceptions.
- Right to Opt-Out of Sale: We do not sell personal information. However, you have the right to direct us not to sell your personal information if we ever change this practice.
- Right to Non-Discrimination: We will not discriminate against you for exercising any of your privacy rights.
To exercise your rights, contact us at support@dailysimmer.com.
Links to Other Websites
The Service may contain links to other websites or allow you to import recipes from supported external URLs, including selected social-source pages as described in Imported URL and Social-Source Content above. We are not responsible for the privacy practices of third-party websites. Basic Import uses a native request and deterministic parsing. If you choose Smart Import, we may send the submitted URL and the retrieved page data to the retrieval or AI providers needed for that outcome; those providers may process request metadata and page content under their own terms and privacy policies. Do not include secrets or personal data in a URL that you do not want processed by those providers. We encourage you to review the privacy policies of any third-party sites and providers involved.
Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page, updating the "Last updated" date, and where appropriate, notifying you via email or an in-app notification.
We encourage you to review this Privacy Policy periodically for any changes. Changes are effective when they are posted on this page.
Contact Us
If you have any questions about this Privacy Policy, you can contact us:
- Email: support@dailysimmer.com
- Mail: Wellnoria AB, Kardemummagränd 28, 135 36 Tyreso, Sweden