Back to CookeryBook

Privacy

Privacy Policy

This policy explains what CookeryBook and Pinch collect, why it is needed, and the choices available to people who use the site.

Last updated July 9, 2026

Information collected

CookeryBook operates Pinch. When you sign in with Google, Pinch receives the account identifier, name, email address, profile image, and session information needed to authenticate you. Pinch stores recipes, notes, tags, images, videos, sharing records, and other cookbook content that you choose to add.

Feedback submissions can include your message, an optional contact email, the current page, browser user agent, and account information when you are signed in. Please do not submit passwords or sensitive credentials.

Analytics and cookies

Pinch uses essential authentication cookies and an HTTP-only cookie that remembers your analytics preference for up to 180 days. These cookies support requested account features and preserve your choice. You can change the analytics preference at any time through Cookie settings in the footer.

Optional analytics remains off unless you allow it. After permission, Pinch creates a first-party visitor cookie named rb_visitor_id. The visitor cookie is HTTP-only, uses SameSite=Lax, and expires after no more than 90 days.

First-party analytics records page paths, referring pages, browser user agents, visit counts, timestamps, and limited product events such as a successful import, tool result copy, recipe save, or accepted invitation. Product events do not include recipe text, search text, email addresses, or IP addresses. Pinch does not store IP addresses in its application analytics tables, although hosting and security providers may process network information in their infrastructure logs.

With permission, Pinch also uses Vercel Web Analytics to understand aggregate page usage. Advertising cookies are not currently used. The consent controls will be replaced or expanded with an appropriate consent platform before advertising technology is introduced.

How information is used

  • Provide authentication and private recipe collections.
  • Import, format, scale, store, and share recipes at your direction.
  • Operate security controls, rate limits, and abuse prevention.
  • Diagnose failures and understand which public tools are useful.
  • Respond to feedback, account requests, and privacy requests.

Service providers

Pinch relies on service providers to operate the application, including Google for authentication, Vercel for hosting, analytics, and file storage, Turso for application data, Upstash for rate limiting, and Resend for recipe invitation email when configured. The optional navigation assistant may use Hugging Face to process a navigation question. These providers process information under their own terms and privacy commitments.

Sharing and visibility

Recipe collections are private to the signed-in account. When you share a recipe, Pinch stores the recipient email and creates a difficult-to-guess invitation link. A recipient must use the intended Google account before the recipe is added to that account.

Pinch does not sell personal information. Private recipe and invite pages are excluded from search indexing.

Retention and choices

Account and recipe information is retained while needed to provide the service. Raw first-party visitor and funnel analytics records use a 90-day retention window and older records are removed during automated maintenance. Aggregated statistics, feedback, security logs, and backups may be retained longer for operational, security, and legal purposes.

Choosing Essential only stops future analytics, clears the visitor identifier, and schedules deletion of the raw first-party records associated with that browser and, when signed in, that account. Vercel analytics is also disabled for future page activity. You can also clear cookies through browser settings.

To request access, correction, export, or deletion, use the secure form on the contact page and provide an email that can be used to verify the request. Some records may be retained when required for security, fraud prevention, or legal obligations.

Security and changes

Pinch uses access controls, secure cookies, restrictive browser headers, rate limiting, and account-level data checks. No internet service can guarantee absolute security, so report a suspected issue through the contact page without including exploit details in a public forum.

This policy may change as the product or its providers change. The date at the top will be updated when material revisions are published.