Privacy Policy
Last updated: 19 August 2026
1. Introduction
This policy explains how information is handled when you use Plately.
2. Your cookbook and iCloud
Your recipes, meal plans and shopping lists are stored on your device. If you enable iCloud sync, Apple stores this data in your private iCloud account so it is available on your devices. We do not have access to the contents of your private iCloud database. Your use of iCloud is governed by Apple's Privacy Policy.
3. Firebase services
Plately uses the following Google Firebase services to operate and protect its server features:
- Firebase Core configures the connection to Firebase.
- Cloud Functions for Firebase receives requests for features that require server-side processing.
- Firebase Anonymous Authentication automatically assigns an anonymous user identifier. You are not asked to create an account or provide a name, email address or password.
- Firebase App Check uses app or device attestation where supported to help determine whether requests come from a genuine copy of Plately.
- Cloud Firestore stores request-count records used to apply per-minute abuse limits to requests that cannot be verified by App Check. The counters are indexed by a pseudonymous Firebase identifier, a one-way hash derived from the network address, or a global request scope, and include timestamps. These counters do not contain your recipes or other cookbook data.
- Cloud Firestore stores recipe snapshots, including a compressed image, only when you explicitly create a sharing link.
Firebase and its infrastructure may also process network addresses, device or app attestation information, request metadata and diagnostic information to deliver and secure these services. Learn more in Firebase Privacy and Security and the Google Privacy Policy.
4. Recipe sharing
When you choose to share a recipe, Plately uploads an independent snapshot of that recipe and its image to Firebase and creates a random, unlisted link. Anyone who has the link can view the snapshot without signing in, so you should share it only with people you trust. The link stops working 30 days after it is created, and the stored snapshot and image are then removed by automated cleanup. Later edits to or deletion of the recipe in your private cookbook do not change the shared snapshot.
5. AI features and OpenAI
When you choose to use an AI-assisted feature, the information needed to fulfil that request is sent through our Firebase function to the OpenAI API. Depending on the feature, this can include recipe text, text imported from a webpage or PDF, ingredients, preferences, or a prompt you provide. This information is used to generate the result you requested and is not added to your Firebase rate-limit record.
OpenAI states that data submitted through its API is not used to train its models by default unless the API account owner opts in. OpenAI may retain prompts, responses and related metadata for safety, abuse prevention and service operation in accordance with its API data controls and data-use policy.
6. How information is used
Server-side information is used only to return requested app features, authenticate requests, prevent excessive automated use, maintain security and diagnose service failures. We do not sell personal information or use it for advertising.
7. In-app purchases
Purchases are processed by Apple. We receive purchase-entitlement information needed to unlock paid features, but we do not receive your payment-card or billing details.
8. Retention and your choices
You can edit or delete locally stored cookbook data in Plately and manage iCloud data through your Apple ID and iCloud settings. Anonymous authentication and rate-limit information is retained only as needed to operate, secure and protect the service, subject to the retention practices of Firebase and Google. OpenAI retains API data according to the policies linked above.
9. Security
We use Firebase Authentication, App Check and server-side rate limiting as complementary safeguards. No system can guarantee absolute security, but these measures reduce unauthorized and automated use without requiring you to register an account.
10. Updates
This policy may change as Plately, its services or legal requirements evolve. The date at the top will be updated when changes are published.
11. Contact
Questions or privacy requests can be sent to info@mchrzastek.com.