Privacy Policy

Effective August 9, 2026 · Applies to the Pipori iOS app

The short version: we collect the minimum needed to turn your links into recipes. Your library syncs through your own iCloud, we never sell your data, there are no ads, and you can delete everything in one tap.

Pipori is operated by Bukovitz Ltda, a Brazilian company ("we", "us"). This policy explains how we handle your data when you use Pipori.

1. What we collect

Content you share. Links, videos, or photos you send to Pipori, and the recipe pages generated from them, plus edits, notes, plans, and shopping lists you create.

Account basics. If you sign in with Apple, we receive an anonymized identifier and, if you allow it, your email (which can be Apple's private relay address). No password is ever stored with us.

Diagnostics. Crash reports and aggregate, non-identifying usage metrics (e.g. "how many recipes were dropped today"), used only to keep the app fast and reliable. You can opt out in Settings → Privacy.

2. What we don't collect

No advertising identifiers, no location tracking, no contact list access, no cross-app tracking, and no payment details (Apple processes all purchases). We do not sell or rent personal data to anyone, and we never train advertising profiles on your cooking habits.

3. How your data is used

We process the content you share solely to (a) generate your recipe pages, ingredients, steps, and nutrition estimates; (b) sync your library across your devices; and (c) operate features you use, like the meal planner and shopping list.

Recipe extraction runs on our servers; the source link and extracted text are processed transiently and are not retained beyond what is needed to build and cache your recipe page.

4. Where your data lives

Your recipe library is stored in your private iCloud database (CloudKit), under your Apple ID — we cannot read it. A minimal server-side record (account identifier, subscription status, diagnostic events) is stored on our infrastructure in the United States, encrypted in transit and at rest.

5. Sharing

We share data only with service providers who help us run the Service (cloud hosting, crash reporting), bound by contracts limiting use to our instructions; with Apple, to process purchases and sync; and where required by law. That's the whole list.

6. Retention and deletion

Your library persists until you delete it. Settings → Account → Delete Account removes your server-side record immediately and permanently; your iCloud data is deleted from your private database at the same time. Diagnostics are retained for at most 18 months.

You can also export your full library (Markdown or JSON) at any time from Settings → Export.

7. Your rights

Depending on where you live (GDPR, UK GDPR, CCPA/CPRA, and similar laws), you may have rights to access, correct, export, delete, or restrict processing of your personal data, and to lodge a complaint with your supervisory authority. Most of these are self-serve in the app; for anything else, email privacy@pipori.app and we will respond within 30 days. We do not discriminate against you for exercising your rights.

8. Children

The Service is not directed to children under 13 (or the applicable age of digital consent), and we do not knowingly collect their data. If you believe a child has provided us personal data, contact us and we will delete it.

9. Changes to this policy

If we make material changes, we will notify you in the app before they take effect and update the date at the top of this page. Prior versions are available on request.

10. Contact

Bukovitz Ltda · privacy@pipori.app