Privacy Policy
Effective date: 15 July 2026
Overview
Gratin is a personal recipe manager available as a desktop app (macOS & Windows), mobile app (iOS & Android), and Chrome extension. It is built, from the ground up, to keep your recipes private and in your hands. This policy explains, in plain language, what little data Gratin handles and the commitments we make to you.
Our promise to you
We make money from an optional sync subscription, never from your data. We do not, and will not:
- sell, rent, or trade your personal information;
- show you ads, or work with advertising or data-broker networks;
- build a profile of you or of what you cook;
- track you across other apps or websites; or
- share your data with anyone, beyond the minimal infrastructure needed to run a feature you have asked for.
Wherever a line in this policy could be read two ways, read it as the one that favours you. That is the intent behind all of it.
Local-first architecture
Gratin is a local-first application. All of your content, recipes, collections, grocery lists, and meal plans, lives on your device. The app asks for nothing in order to use it: no account, no email, no password, no sign-up. Used this way, Gratin collects no personal information about you at all.
Sync
By default, Gratin syncs your data across devices using the freeEvolu relay. The relay stores an end-to-end encrypted copy of your data, so your devices stay in sync and you can recover everything on a new device. It cannot read your recipes or any other content: the data is encrypted on your device with a key only you hold, so the relay only ever holds scrambled data that neither we nor the relay operator can read. Because Gratin is local-first, your own devices remain the source of truth.
If you take optional paid sync, we host that relay for you on Cloudflare's global edge network. Because the edge is spread across many locations worldwide, we make no claim about where any particular encrypted blob physically rests, and it does not matter: everything is end-to-end encrypted, so no location holds anything readable. You can instead point Gratin at a relay you run yourself, or any other Evolu-compatible relay, at any time.
You can disable sync entirely at any time. Your data remains fully functional on your device without any relay connection.
Paid sync and payments
Paid sync is the one part of Gratin that involves a little more. Payment is handled by our payment provider; we do not see or store your card details. To run your plan, our systems keep only the minimum needed: an identifier for your encrypted data and how much storage it is using. That is never linked to the content of your recipes, which stays end-to-end encrypted and unreadable to us. If you cancel, your hosted copy is removed after a 60-day grace period, and your own devices keep everything.
Chrome extension
The Gratin Recipe Clipper Chrome extension reads the content of web pages you visit to detect structured recipe data (such as JSON-LD and Microdata). This processing happens entirely within your browser. No page content is sent to our servers.
When you choose to save a recipe, the extension temporarily stores the recipe data in local browser storage to transfer it to the Gratin app. This temporary data is automatically deleted after use.
The extension also fetches recipe images from their original hosts to convert them to a portable format. No browsing history or page content is collected, stored, or transmitted beyond what is needed to clip the specific recipe you choose to save.
Desktop & mobile apps
The desktop and mobile apps may periodically check for available updates by contacting our update server. These requests include your current app version and platform. No personal data is sent during update checks.
As with any online connection, reaching our update or sync servers reveals your device's network address to that server, as it must for the response to come back. We use it only to deliver what you asked for, never to track or profile you.
Analytics & tracking
Gratin uses no third-party analytics, no advertising trackers, and no tracking cookies. We do not measure what you do inside the app or build any picture of you from it. We would rather not know.
Data security
All communication with a relay or our servers uses encrypted connections (HTTPS and WSS). Anything that passes through a relay is end-to-end encrypted and cannot be read by the relay operator, including us. Your encryption key comes from a recovery phrase that only you hold. Keep it safe: it is the one thing we cannot recover for you, precisely because we never have it.
Your rights and control
Because your data lives on your device, you hold the controls, not us:
- Access and export: your recipes are yours to read and export at any time, as open JSON-LD or a full SQLite copy of your database.
- Delete: remove any data, or all of it, from within the app. There is no account for us to hold and nothing you need to request from us.
- Relays: switch relays, self-host, or turn sync off whenever you like.
Where data-protection laws such as the GDPR or CCPA give you rights over personal data, we honour them in full, and Gratin's design already puts most of them in your hands by default. If you are ever unable to exercise a right yourself, contact us and we will help.
Changes to this policy
We may update this policy from time to time. If we ever make a change that would reduce your privacy or widen what we handle, we will say so clearly and give you notice, not bury it. The current version always lives here, with its effective date.
Contact
If you have any questions about this policy, or want help exercising any right above, contact us at[email protected].