Chef Happens
How it worksDownloadAbout Us
legal · privacy policy·version 1.0·effective 24 august 2026

How we handle your data.

Your kitchen, your privacy. We built Chef Happens to be useful, not nosy — here's the plain-English version of what we collect, why, who else sees it, and the controls you have. Chef Happens is available only in Australia, New Zealand and India, and this policy is written to comply with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), the New Zealand Privacy Act 2020 and its Information Privacy Principles (IPPs), and India's Digital Personal Data Protection Act 2023 (DPDP Act).

contents
  1. 01Who we are
  2. 02What we collect
  3. 03Why we collect it
  4. 04Who we share with
  5. 05Cross-border transfers
  6. 06How long we keep it
  7. 07Your rights
  8. 08Cookies & tracking
  9. 09Children
  10. 10Security
  11. 11Contact & DPO
  12. 12Changes to this policy
related
PrivacyTermsDisclaimerYour Data RightsContact us

1. Who we are

Chef Happens (ABN 51 633 975 228), a sole trader registered in Australia ("we", "us", "our"), operates the Chef Happens mobile app and chefhappens.app. Contact details are in Section 11. We are the entity responsible for personal information collected through the app and website — the APP entity in Australia, the agency handling information in New Zealand, and the Data Fiduciary under the DPDP Act in India.

2. What we collect

We collect only what is needed to run the service:

  • Account data — email, display name, region, hashed password (never stored in plain text). If you sign in with Google, we receive your email, name, and Google user ID.
  • Usage data — recipes you generate, ingredients you enter, meal plans you build, favourites you save, chat prompts sent to Pepper. This is used to power the product; we do not sell it.
  • Device data — device model, OS version, app version, IP address at request time, anonymised device ID. Used for crash reporting and abuse prevention.
  • Billing data — subscription tier, subscription source (Apple / Google / Stripe / trial), billing region, last-4 of card (Stripe only). Full card numbers are handled entirely by our payment processor (Stripe) and never touch our servers.
  • Camera-derived data — when you photograph your pantry, images are sent to our AI provider for ingredient detection and are not retained on our servers beyond the request. We do not use your photos to train models.
  • Sensitive personal information — allergens, dietary restrictions, likes, dislikes. Treated as sensitive under APP 3.3, IPP 4, and DPDP §2(t), and processed only with your explicit consent, which you may withdraw at any time.

We do not collect precise geolocation, contacts, calendar, browsing history outside the app, or biometric data.

3. Why we collect it

Each category above maps to a specific product purpose: account data for authentication and continuity of your library; usage data to generate recipes tailored to what you have and like; device data for stability, security and fraud prevention; billing data to charge you correctly and comply with tax law; camera-derived data to power pantry recognition; sensitive personal information to filter unsafe recipes.

The lawful bases we rely on are (a) performance of the service you have signed up for; (b) your consent for sensitive personal information, marketing communications and optional analytics — which you can withdraw any time in Settings → Privacy; (c) our legitimate interest in abuse prevention, security monitoring, and aggregate analytics, balanced against your reasonable expectations; and (d) compliance with legal obligations (for example, retention of billing records for taxation and audit purposes).

4. Who we share with (sub-processors)

We share data with a small, audited set of service providers, each bound by written data-processing agreements. We share the minimum data needed to power specific features:

  • Google Gemini — recipe generation and pantry-ingredient recognition. Prompts you type are sent to Gemini; your prompts are not used to train Google's models under the Gemini enterprise API terms.
  • Whisper (via DeepInfra) — transcribes social-media videos (Instagram / TikTok / YouTube) and short voice clips when you dictate ingredients. Audio is processed by the Whisper model hosted on DeepInfra; requests are transient and not retained.
  • Stripe — web subscription payments in AU / NZ / IN. Card data never touches our servers.
  • Apple App Store & Google Play — in-app subscription payments on iOS / Android. Refunds, cancellations, and receipt validation flow through their billing systems.
  • RevenueCat — bridges your Apple/Google subscription status into the app so the correct plan unlocks instantly. Receives your subscription tier and an internal user ID, never your card details.
  • Resend — transactional email only (welcome, verification, password reset, billing receipts, support replies). No marketing lists without your opt-in.
  • MongoDB Atlas — encrypted database storage. Data at rest is encrypted with AES-256.
  • Google Cloud Storage — stores and serves recipe and profile images. Holds image files only; no account, billing, or contact data.
  • Cloudflare — CDN and DDoS protection. May see request metadata (IP, user-agent) but not request body content.
  • Sentry — anonymised crash reports and performance telemetry. Personal data is scrubbed before transmission.
  • Wikipedia, Unsplash, Pexels, DeepInfra, Pollinations — source authentic regional and AI-generated recipe imagery. We send only the dish name (never account data) to retrieve photos.

AI assistants disclosure. Chef Happens features two named AI personas: Pepper (main kitchen assistant) and Fizz (cocktail/drinks sub-assistant). Both are powered by Google's Gemini family of large language models. The only data sent to the LLM is the prompt content you explicitly type (ingredients, dish names, wishes, imported recipe URLs/text) — never your email, name, DOB, country, payment details, or any other account-level information.

We do not sell personal data. We do not share personal data for third-party advertising. We do not use your data to train external AI models.

5. Cross-border transfers

Chef Happens is operated from Australia. Some AI-provider processing occurs in the United States on the transient request-response cycle only. For Australian users, cross-border disclosure complies with APP 8. For New Zealand users, it complies with IPP 12. For Indian users, transfers comply with DPDP Act 2023 §16 — the United States is not on the notified restricted-transfer list at the time of writing, and if that changes we will update this policy and notify you.

6. How long we keep it

  • Account data — until you delete your account (or 3 years of inactivity, whichever is sooner).
  • Generated recipes and favourites — for the lifetime of your account.
  • Chat prompts with Pepper — 90 days rolling, then aggregated and anonymised.
  • Billing records — 7 years (Australian Taxation Office requirement).
  • Server logs — 30 days.
  • Deleted account grace period — 30 days, after which all data is unrecoverable.

7. Your rights

Under the Australian Privacy Principles, New Zealand IPPs, and the DPDP Act, you have the following rights. All are exercisable at no cost and will not affect the service you receive:

  • Access — request a copy of the data we hold about you (APP 12 / IPP 6 / DPDP §11).
  • Correction — correct data that is inaccurate, out of date, incomplete, irrelevant or misleading (APP 13 / IPP 7 / DPDP §12).
  • Erasure / Deletion — request that we delete your account and associated data (DPDP §12; also honoured under APP 11.2 and IPP 9 where retention is no longer necessary).
  • Data portability — receive your saved data in a machine-readable format (DPDP §11).
  • Withdraw consent — for anything based on consent (sensitive data, marketing, optional analytics) at any time.
  • Nominate a representative — you may nominate another person to exercise your rights in the event of incapacity or death (DPDP §14).
  • Complaint — lodge a complaint with a regulator without going through us first (see Section 11).

See Data Rights for step-by-step instructions on how to exercise each right in-app or by email.

8. Cookies & tracking

The Chef Happens marketing site uses only strictly-necessary cookies (session, CSRF, region detection). We do not use advertising cookies, cross-site trackers, or analytics that identify individual users. If we introduce optional analytics later, we will ask for your consent first.

9. Children

Chef Happens is intended for users 13 years and older. In India, the DPDP Act 2023 treats anyone under 18 as a child — we require verifiable parental or guardian consent before processing a minor's personal data, do not run targeted advertising or behavioural monitoring on minors, and apply additional safeguards to their account. If you believe a child under 13 (or a minor without parental consent in India) has created an account, contact us and we will remove the account immediately.

10. Security

We use HTTPS everywhere, AES-256 encryption at rest, bcrypt password hashing, rate-limiting on all authentication endpoints, and least-privilege access controls. Employees only access user data with a documented reason. We conduct security reviews before every major release. In the event of a personal-data breach that is likely to result in serious harm, we will notify affected users and the relevant regulator without undue delay, as required by APP 11 and the Notifiable Data Breaches scheme in Australia, section 118 of the New Zealand Privacy Act 2020, and DPDP §8(6).

11. Contact & regulators

Privacy questions, data-rights requests, and grievance-officer contact under DPDP §8(10) can all be reached at [email protected]. Please use a clear subject line to help us route your query:

  • Privacy Enquiry — APP for Australian privacy queries
  • Privacy Enquiry — NZ for New Zealand privacy queries
  • Grievance — DPDP for Indian Data Principal requests (acknowledged within 24 hours, resolved within 15 days)
  • Data Rights Request for access / export / correction / deletion under Section 7

You may lodge a complaint directly with:

  • Australia — Office of the Australian Information Commissioner (oaic.gov.au)
  • New Zealand — Office of the Privacy Commissioner (privacy.org.nz)
  • India — Data Protection Board of India, once operational under DPDP Act 2023

Postal / registered business address: Chef Happens (ABN 51 633 975 228), Level 1, 63-73 Ann Street, Surry Hills, NSW 2010, Australia.

12. Changes to this policy

We will notify you of material changes via email and an in-app banner at least 30 days before they take effect. The full version history is available on request.

PRODUCT
DownloadSupport
LEGAL
PrivacyTermsDisclaimerYour Data Rights
CONTACT
[email protected]
MADE WITH LOVE

© 2026 Chef Happens · All rights reserved

Chef Happens · ABN 51 633 975 228
Level 1, 63–73 Ann Street, Surry Hills NSW 2010, Australia