Chef Happens
How it worksDownloadAbout Us
legal · privacy policy·version 1.0·effective 24 august 2026

How we handle your data.

Your kitchen, your privacy. We built Chef Happens to be useful, not nosy — here's the plain-English version of what we collect, why, who else sees it, and the controls you have. Chef Happens is available only in Australia, New Zealand and India, and this policy is written to comply with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), the New Zealand Privacy Act 2020 and its Information Privacy Principles (IPPs), and India's Digital Personal Data Protection Act 2023 (DPDP Act).

contents
  1. 01Who we are
  2. 02What we collect
  3. 03Why we collect it
  4. 04Who we share with
  5. 05Cross-border transfers
  6. 06How long we keep it
  7. 07Your rights
  8. 08Cookies & tracking
  9. 09Children
  10. 10Security
  11. 11Contact & DPO
  12. 12Changes to this policy
related
PrivacyTermsDisclaimerYour Data RightsContact us

1. Who we are

Chef Happens (ABN 51 633 975 228), a sole trader registered in Australia ("we", "us", "our"), operates the Chef Happens mobile app and chefhappens.app. Contact details are in Section 11. We are the entity responsible for personal information collected through the app and website — the APP entity in Australia, the agency handling information in New Zealand, and the Data Fiduciary under the DPDP Act in India.

2. What we collect

We collect only what is needed to run the service:

  • Account data — email, display name, region, hashed password (never stored in plain text). If you sign in with Google, we receive your email, name, and Google user ID.
  • Usage data — recipes you generate, ingredients you enter, meal plans you build, favourites you save, chat prompts sent to Pepper. This is used to power the product; we do not sell it.
  • Device data — device model, OS version, app version, IP address at request time, anonymised device ID. Used for crash reporting and abuse prevention.
  • Billing data — subscription tier, subscription source (Apple / Google / Stripe / trial), billing region, last-4 of card (Stripe only). Full card numbers are handled entirely by our payment processor (Stripe) and never touch our servers.
  • Camera-derived data — when you photograph your pantry, images are sent to our AI provider for ingredient detection and are not retained on our servers beyond the request. We do not use your photos to train models.
  • Sensitive personal information — allergens, dietary restrictions, likes and dislikes. We treat this as sensitive information and process it only with your explicit consent, which you may withdraw at any time.

We do not collect precise geolocation, contacts, calendar, browsing history outside the app, or biometric data.

3. Why we collect it

Each category above maps to a specific product purpose: account data for authentication and continuity of your library; usage data to generate recipes tailored to what you have and like; device data for stability, security and fraud prevention; billing data to charge you correctly and comply with tax law; camera-derived data to power pantry recognition; sensitive personal information to filter unsafe recipes.

The lawful bases we rely on are (a) performance of the service you have signed up for; (b) your consent for sensitive personal information, marketing communications and optional analytics — which you can withdraw any time in Settings → Privacy; (c) our legitimate interest in abuse prevention, security monitoring, and aggregate analytics, balanced against your reasonable expectations; and (d) compliance with legal obligations (for example, retention of billing records for taxation and audit purposes).

4. Who we share with (sub-processors)

We share data with a small, audited set of service providers, each bound by written data-processing agreements. We share the minimum data needed to power specific features:

  • Google Gemini — recipe generation and pantry-ingredient recognition. The prompt content you type is sent to Gemini only to generate your results, and is never used by us to train any AI model. We do not consent to your content being used to train Google's models.
  • Whisper (via DeepInfra) — transcribes short cooking videos you import and short voice clips when you dictate ingredients. Audio is processed by the Whisper model hosted on DeepInfra; requests are transient and not retained.
  • Stripe — web subscription payments in AU / NZ / IN. Card data never touches our servers.
  • Apple App Store & Google Play — in-app subscription payments on iOS / Android. Refunds, cancellations, and receipt validation flow through their billing systems.
  • RevenueCat — bridges your Apple/Google subscription status into the app so the correct plan unlocks instantly. Receives your subscription tier and an internal user ID, never your card details.
  • Resend — transactional email only (welcome, verification, password reset, billing receipts, support replies). No marketing lists without your opt-in.
  • MongoDB Atlas — encrypted database storage. Data at rest is encrypted with AES-256.
  • Google Cloud Storage — stores and serves recipe and profile images. Holds image files only; no account, billing, or contact data.
  • Cloudflare — CDN and DDoS protection. May see request metadata (IP, user-agent) but not request body content.
  • Sentry — anonymised crash reports and performance telemetry. Personal data is scrubbed before transmission.
  • Wikipedia, Unsplash, Pexels, DeepInfra, Pollinations — source regional and AI-generated recipe imagery. We send only the dish name (never account data) to retrieve photos.

AI assistants disclosure. Chef Happens features two named AI personas: Pepper (main kitchen assistant) and Fizz (cocktail/drinks sub-assistant). Both are powered by Google's Gemini family of large language models. The only data sent to the LLM is the prompt content you explicitly type (ingredients, dish names, wishes, imported recipe URLs/text) — never your email, name, DOB, country, payment details, or any other account-level information.

We do not sell personal data. We do not share personal data for third-party advertising. We do not use your data to train external AI models.

5. Cross-border transfers

Chef Happens is operated from Australia. Some AI-provider processing occurs in the United States on the transient request-response cycle only. For Australian users, cross-border disclosure complies with APP 8. For New Zealand users, it complies with IPP 12. For Indian users, transfers comply with DPDP Act 2023 §16 — the United States is not on the notified restricted-transfer list at the time of writing, and if that changes we will update this policy and notify you.

6. How long we keep it

We keep personal information only for as long as it is needed for the purposes described in this policy, or as required by law, and then delete or anonymise it:

  • Account data, saved recipes, favourites and meal plans — kept while your account is active, so your library is there when you come back.
  • Anonymous recipe activity not linked to an account — deleted after 90 days.
  • Diagnostic and abuse-prevention data (such as crash reports, rate-limit records and aggregate analytics) — kept only as long as needed for those purposes, then deleted or anonymised.
  • Records we are legally required to keep (for example, information needed for tax and financial reporting) — retained for the period required by law; most of these are held by our payment providers rather than on our servers.
  • Account deletion — when you delete your account we permanently remove your personal data from our systems straight away. We keep only a one-way hashed marker that helps prevent trial abuse and cannot be used to identify you. If you have an active store subscription with time still left on it, that subscription is held by Apple or Google and can be restored — cancel it in your App Store or Play Store settings to stop it renewing.

7. Your rights

Under the Australian Privacy Principles, New Zealand IPPs, and the DPDP Act, you have the following rights. All are exercisable at no cost and will not affect the service you receive:

  • Access — request a copy of the data we hold about you (APP 12 / IPP 6 / DPDP §11).
  • Correction — correct data that is inaccurate, out of date, incomplete, irrelevant or misleading (APP 13 / IPP 7 / DPDP §12).
  • Erasure / Deletion — request that we delete your account and associated data (DPDP §12; also honoured under APP 11.2 and IPP 9 where retention is no longer necessary).
  • Data portability — receive your saved data in a machine-readable format (DPDP §11).
  • Withdraw consent — for anything based on consent (sensitive data, marketing, optional analytics) at any time.
  • Nominate a representative — you may nominate another person to exercise your rights in the event of incapacity or death (DPDP §14).
  • Complaint — lodge a complaint with a regulator without going through us first (see Section 11).

See Data Rights for step-by-step instructions on how to exercise each right in-app or by email.

8. Cookies & tracking

The Chef Happens marketing site uses only strictly-necessary cookies (session, CSRF, region detection). We do not use advertising cookies, cross-site trackers, or analytics that identify individual users. If we introduce optional analytics later, we will ask for your consent first.

9. Children

Chef Happens is intended for users aged 13 and older, and is not directed at children under 13. We do not knowingly collect personal information from anyone under 13. In India, the DPDP Act 2023 treats anyone under 18 as a child; we ask that a parent or guardian consent to and supervise a minor's use of the app, we do not run targeted advertising or behavioural monitoring on minors, and we do not knowingly process a minor's personal data without appropriate consent. If you believe a child under 13 — or a minor in India without parental or guardian consent — has created an account, please contact us and we will remove it promptly.

10. Security

We use HTTPS everywhere, AES-256 encryption at rest, bcrypt password hashing, rate-limiting on all authentication endpoints, and least-privilege access controls. We only access user data with a documented reason. We conduct security reviews before every major release. In the event of a personal-data breach that is likely to result in serious harm, we will notify affected users and the relevant regulator without undue delay, as required by APP 11 and the Notifiable Data Breaches scheme in Australia, section 118 of the New Zealand Privacy Act 2020, and DPDP §8(6).

11. Contact & regulators

Privacy questions, data-rights requests, and grievance-officer contact under DPDP §8(10) can all be reached at [email protected]. Please use a clear subject line to help us route your query:

  • Privacy Enquiry — APP for Australian privacy queries
  • Privacy Enquiry — NZ for New Zealand privacy queries
  • Grievance — DPDP for Indian Data Principal requests (handled as promptly as we can, within the timeframes required by the DPDP Act)
  • Data Rights Request for access / export / correction / deletion under Section 7

You may lodge a complaint directly with:

  • Australia — Office of the Australian Information Commissioner (oaic.gov.au)
  • New Zealand — Office of the Privacy Commissioner (privacy.org.nz)
  • India — Data Protection Board of India, once operational under DPDP Act 2023

Postal / registered business address: Chef Happens (ABN 51 633 975 228), Level 1, 63-73 Ann Street, Surry Hills, NSW 2010, Australia.

12. Changes to this policy

We will notify you of material changes via email and an in-app banner at least 30 days before they take effect. The full version history is available on request.

PRODUCT
DownloadSupport
LEGAL
PrivacyTermsDisclaimerYour Data Rights
CONTACT
[email protected]
MADE WITH LOVE

© 2026 Chef Happens · All rights reserved

Chef Happens · ABN 51 633 975 228
Level 1, 63–73 Ann Street, Surry Hills NSW 2010, Australia