Last updated 7 October 2026
Your recipe book, meal plan, shopping list and pantry are stored on your phone and backed up to our server, so a lost or replaced phone does not lose them. Photos you add to a recipe are backed up too. No other household can see any of it.
You do not need an account. If you choose to sign in with Apple or Google so you can get your book back on a new phone, we keep what they send us: your email address and, if they send it, your name.
The people who run PocketCook can read what is stored on our server. We read recipes only to find and fix problems in the app. If you would rather we did not read yours, write to us.
We do not sell your data, share it with advertisers or data brokers, use it to advertise to you, or track you across other apps and websites.
When you paste a link, our server reads the page or video it points to. For YouTube videos, PocketCook uses YouTube API Services to read the video’s public details. It never reads your YouTube account. Videos play in YouTube’s own player.
When the app fills in a recipe, reads a video or reads a photo of a recipe card, it sends that recipe, video link or photo to OpenAI or Google to do the reading.
When you ask a question about a recipe, the app sends your question and that recipe to Google to answer it, and we keep neither. On an iPhone or iPad with Apple Intelligence turned on, the answer is made on the device and nothing is sent.
When you turn on voice commands while cooking, the app listens through the microphone for requests like “next” and “pause”. What it hears is turned into words on your phone. The sound is never sent anywhere or kept. A question you ask aloud is sent the same way as one you type.
Using PocketCook’s video features means you also agree to the YouTube Terms of Service. Google’s handling of what it sends us is covered by the Google Privacy Policy.
If you make videos and would rather PocketCook did not read them, write to hello@pocketcook.app. We leave your whole channel out, including videos you post later.
A creator can sign in at pocketcook.app/creators with the Google account that owns their YouTube channel. PocketCook uses that permission only to find out which channel the account owns, and does not keep the permission.
A recipe site’s owner can sign in the same way, without the YouTube permission. We keep the site’s address, and when and how they proved it’s theirs.
You can also let PocketCook add a video’s PocketCook link to that video’s description on YouTube. Google asks for that permission separately, and only if you choose it. PocketCook uses it to add or remove that one line when you press the button, and does not keep the permission.
We keep the channel’s ID, name and handle, and what Google sends about the account: its ID, your name, your email address and your profile picture’s address. We use them to show you your own channel’s page and to keep everyone else out of it.
Signing in keeps you signed in on that browser, in the browser’s storage, until you sign out. It also sets one cookie, for ten minutes, used only while you sign in.
Thirty days after you last sign in, we remove your Google account from your channel. Signing in again restores it. Your channel’s ID, name and handle, and any corrections you made, stay.
You can remove PocketCook’s access at any time at myaccount.google.com/permissions. To have your channel and sign-in deleted from PocketCook, write to us and we will delete them within seven days. This changes nothing on YouTube, so a link added to a description stays until you remove it. What we have read from your public videos stays.
With PocketCook Plus you can add another phone to your household, and both phones see everything in the book. Removing a phone leaves each with its own copy.
Sharing a recipe creates a page anyone with the link can open. It shows the recipe, including any notes you wrote on it, and on iPhone your photos of the dish. It does not show your name or anything that identifies you or your household. Treat anything on a shared recipe as public, and remove a note you want to keep private before you share it.
When a recipe came from a creator’s video, we show that creator totals about their own recipes: how many households saved, cooked, rated or shopped for them, how long they typically took and how many people they typically served, and how many households follow the creator. A total appears only once at least five households are in it. Creators never see who you are, your household, your photos or anything you wrote.
When you send a list to Kroger from the app, we record which Kroger products went and which recipe they were for. That lets these totals include shopping, and lets us tell a brand how many households put its products in a cart. A brand sees totals of the same kind, and never a household.
To leave your household out of these totals, turn off Share how you use the app in Settings → Privacy, or write to us.
A recipe you share is a public link. Its creator sees how many times their recipes were shared and opened, once a recipe has been shared five times, and never who shared them.
Unless you turn off Share how you use the app in Settings → Privacy, the app sends us counts of what gets used, such as recipes saved and meals cooked, and which screens you visit, with the app version, your phone’s system version and a random installation ID that is not linked to you. It never includes anything you wrote. In the UK, the EEA and Switzerland this starts off, and nothing is sent unless you turn it on.
On iPhone, the same setting allows session recordings through Microsoft Clarity: which screens you open, and where you tap and scroll. Text and images are masked on your phone before anything is sent. The Android app does not record sessions.
If the app crashes, it sends us where in the app it failed, with the app version, your phone’s system version and the installation ID. It includes nothing you wrote.
If you allow notifications, your phone’s notification token is kept with your household so we can send them.
If you send feedback, we receive what you typed, the app version, your phone’s system version and your email address if you leave one, which we use only to reply. A note sent from a recipe, a cooking step or the shopping list also includes that recipe or list. Nothing is sent until you press send.
If you connect a Kroger account, we keep the access Kroger grants, not your password, so the app can add to your Kroger cart when you ask. What you send to Kroger is covered by Kroger’s privacy policy. A Walmart order opens in Walmart’s own website.
Subscriptions are handled by Apple on iPhone and by Google Play on Android. We never see your payment details.
If you redeem a creator’s code in PocketCook, the app tells us which code began your subscription, so we can credit the creator. We keep the code with Apple’s ID for that purchase, and nothing else about you, for a year.
Our website counts visits to shared recipes, creator pages and creators’ gift pages. It uses your IP address to count visits and estimate your country, and does not store the address. A shared recipe page remembers your place in it, in your browser’s storage. The website’s fonts are loaded from Google.
Under UK and EU data protection law, our legal bases are:
Contract, for storing, backing up and syncing your recipe book, for the reading features you use, and for purchases.
Consent, for usage data and session recordings. You can withdraw it at any time in Settings → Privacy. That stops future reporting; to delete what was already sent, ask us.
Legitimate interests, for crash reports, for reading stored recipes to fix problems, for counting website visits and for the totals shown to creators. You can object by writing to us, or by turning off Share how you use the app.
Depending on where you live, you can ask for a copy of your data, or ask us to correct it, delete it, or limit or stop how we use it. You can also complain to your data protection authority. Write to us to use any of these.
PocketCook is for adults and is not directed at children. We do not knowingly collect data from anyone under the age of digital consent where they live, which is between 13 and 16. If you think a child has sent us something, send us the installation ID from Settings → Privacy and we will delete it.
Usage data and website visit counts are deleted after six months, crash reports after a year, and feedback after two years. A notification token is deleted 90 days after your phone was last seen. Your recipe book’s backup and a Kroger connection are kept until you delete your account.
Supabase hosts our server and database, and Deno hosts our website. OpenAI and Google do the reading described above, and Google also provides YouTube API Services, sign-in with Google and the website’s fonts. Microsoft handles session recordings on iPhone. Apple and Google handle purchases and sign-in. Some of them process data outside the UK and the EEA, under the standard contractual clauses in their terms.
Everything sent between your phone or browser and PocketCook is encrypted in transit, over HTTPS. Supabase, which hosts our server and database, encrypts everything it stores with AES-256. The keys that can read or change everything in our database, and the secret behind Google sign-in, stay on our servers. The app and the pages our website sends to your browser never carry them.
If you sign in as a creator, your studio opens only for the Google account that YouTube confirms owns the channel. Only our server can record which channel is yours, and it first checks with Google that the permission came from you and was given to PocketCook.
Each time you sign in, our server uses Google’s permission only to ask YouTube which channel is yours, then discards it. If you let PocketCook add links, your open page also holds that permission for up to an hour, to add or remove the line when you ask. It is gone when you close or reload the page. Google’s access tokens are never saved in our database or on our servers, and we never ask Google for a refresh token.
From your Google account we keep its ID, your name, your email address and your profile picture’s address. From YouTube we keep your channel’s ID, name and handle. Your permission is not used to read your comments, subscriptions or watch history, and we change nothing on YouTube except the one line you ask us to add or remove.
We use this information only to sign you in, to run your creator studio, to show your channel’s name on recipes you correct, and to add or remove the link you ask for. PocketCook’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. The people who run PocketCook look at it only when you ask us to, such as to delete it, when we need to investigate a problem or misuse, or when the law requires it.
We keep it until you ask us to delete it. Thirty days after your last sign-in, or as soon as you sign out, we unlink your Google account from your channel. Signing in again links it back.
To delete it, choose Delete my data under Account in the creator studio, or write to hello@pocketcook.app. We delete your channel’s details, the recipes you corrected and your sign-in within seven days. If you also use that Google account for a recipe book in the app, we keep the account for the book until you delete it in the app. You can remove PocketCook’s access to your Google account at any time at myaccount.google.com/permissions. Deleting your data here changes nothing on YouTube, so a link added to a description stays until you remove it.
Deleting the app removes what is on your phone. Delete account in Settings removes your account and its backup, including your photos, straight away.
To delete what the app sent us, such as feedback, usage data and crash reports, send us the installation ID from Settings → Privacy, under This phone’s id. We will delete it within a month. You can ask for a copy the same way.
PocketCook does not track you across other websites, so there is nothing for a Do Not Track signal to turn off.
If we change this policy, we will update this page and the date at the top.
PocketCook is made by PocketCook LLC, an Illinois limited liability company, which is the data controller for everything on this page.
Write to hello@pocketcook.app about anything on this page. We answer within a month.