Privacy Policy

Last updated: 3 March 2026  ·  Effective: 3 March 2026

This Privacy Policy explains how SteakChef ("we", "us", "our") collects, uses, shares, and protects your personal data when you use steakchef.app (the "Service"). It applies to all users in the United Kingdom and European Economic Area and is written to comply with the UK GDPR, the Data Protection Act 2018, and the EU GDPR (Regulation 2016/679).

1. Data Controller

The data controller responsible for your personal data is SteakChef, operated by Zulfikar Gani. You can contact us at [email protected].

We are not currently required to appoint a Data Protection Officer (DPO), but all data protection enquiries should be directed to the address above and will be handled promptly.

2. Data We Collect

We collect the following categories of personal data:

CategoryExamplesSource
Account dataName, email address, hashed password, profile photo URLYou, directly
Authentication dataGoogle OAuth ID, session tokens, email verification tokensYou / Google
Subscription & billing dataStripe customer ID, subscription status, payment intent IDsStripe
Cooking preferencesPreferred cuts, doneness levels, cooking methodsYou, directly
AI-generated recipesSteak recipes generated using your inputsAI processing of your inputs
Usage dataPages visited, features used, timestamps, IP addressAutomatically
CommunicationsSupport emails, feedback submitted through the ServiceYou, directly
Marketing preferencesEmail opt-in/out status, unsubscribe tokenYou / system

We do not collect special-category data (health, biometric, political, religious data) and do not collect payment card numbers — all card processing is handled directly by Stripe.

3. How We Use Your Data

We process your personal data only where we have a valid lawful basis under UK/EU GDPR:

PurposeData UsedLawful Basis
Create and manage your accountName, email, password hashContract (Article 6(1)(b))
Authenticate you and maintain sessionsSession tokens, OAuth IDsContract (Article 6(1)(b))
Process subscription payments via StripeEmail, Stripe IDs, subscription statusContract (Article 6(1)(b))
Generate AI-powered steak recipesCooking preferences, inputs you provideContract (Article 6(1)(b))
Send transactional emails (verification, password reset)Email addressContract (Article 6(1)(b))
Send marketing & onboarding emails (welcome, tips)Email address, nameConsent (Article 6(1)(a)) — you may withdraw at any time
Improve the Service and conduct analyticsUsage data, aggregated recipe dataLegitimate interests (Article 6(1)(f))
Comply with legal obligationsAny data required by lawLegal obligation (Article 6(1)(c))
Prevent fraud and ensure securityIP address, session dataLegitimate interests (Article 6(1)(f))

Where we rely on legitimate interests, we have balanced those interests against your rights and concluded that our interests do not override your fundamental rights and freedoms. You may object to such processing at any time (see Section 7).

4. AI-Generated Content

SteakChef uses an AI language model to generate personalised steak recipes based on the inputs you provide (cut, doneness, cooking method, and optional preferences). Your inputs and the resulting recipes are processed on our servers. We may use aggregated, anonymised recipe data to improve our AI prompts and Service quality, but we do not use your personal data to train external AI models.

AI-generated recipes are provided for informational and culinary guidance purposes only. They do not constitute professional dietary, nutritional, or medical advice. You should exercise your own judgement when following any recipe, particularly regarding food safety temperatures and allergens.

Automated decision-making that produces legal or similarly significant effects is not used on this Service.

5. Sharing Your Data

We do not sell your personal data. We share data only with the following categories of recipients:

RecipientPurposeSafeguards
Stripe, Inc.Payment processing and subscription managementStripe Privacy Policy; Standard Contractual Clauses (US transfer)
Google LLCOAuth authentication (if you choose Google sign-in)Google Privacy Policy; Standard Contractual Clauses
Manus AI (hosting & infrastructure)Cloud hosting, database, email delivery, AI inferenceData Processing Agreement; EU/UK SCCs where applicable
Law enforcement / regulatorsWhere required by applicable law or court orderLegal obligation only; minimum necessary data

6. Retention Periods

We retain your personal data only for as long as necessary for the purposes described in this policy:

Data TypeRetention Period
Active account dataFor the duration of your account
Deleted account dataPurged within 30 days of deletion request
Billing records (Stripe IDs, transaction references)7 years (UK tax/accounting obligations)
Email communication logs2 years
Server access logs (IP, timestamps)90 days
Unverified accounts (no verification within 30 days)Deleted after 30 days

7. Your Rights

Under UK GDPR and EU GDPR, you have the following rights. To exercise any of them, contact us at [email protected] or use the controls in your Account Settings.

RightWhat it means
Access (Article 15)Request a copy of all personal data we hold about you.
Rectification (Article 16)Ask us to correct inaccurate or incomplete data.
Erasure / 'Right to be forgotten' (Article 17)Request deletion of your account and personal data, subject to legal retention obligations.
Restriction (Article 18)Ask us to pause processing while a dispute is resolved.
Data portability (Article 20)Receive your data in a structured, machine-readable format (JSON).
Object (Article 21)Object to processing based on legitimate interests or for direct marketing.
Withdraw consent (Article 7(3))Withdraw marketing consent at any time via the unsubscribe link in any email or in Account Settings.
Automated decision-making (Article 22)We do not use solely automated decision-making that produces legal effects.

We will respond to all requests within 30 days. We may need to verify your identity before processing a request. There is no charge for exercising your rights.

8. Cookies & Tracking

We use cookies and similar technologies on the Service. For full details of the cookies we use, their purposes, and how to manage your preferences, please read our Cookie Policy.

Under the UK Privacy and Electronic Communications Regulations (PECR) and the EU ePrivacy Directive, we obtain your consent before setting any non-essential cookies. You can manage or withdraw your cookie consent at any time via the cookie banner or your browser settings.

9. Security

We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. These include TLS encryption in transit, hashed password storage (bcrypt), JWT-signed session tokens with short expiry, and access controls limiting data access to authorised personnel only.

No method of transmission over the internet is 100% secure. If you become aware of any security vulnerability or breach, please contact us immediately at [email protected].

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Information Commissioner's Office (ICO) within 72 hours and inform affected individuals without undue delay.

10. Children

The Service is not directed at children under the age of 13. We do not knowingly collect personal data from children under 13. If you believe a child under 13 has provided us with personal data, please contact us and we will delete it promptly.

Users between 13 and 16 in the EEA require parental or guardian consent for data processing based on consent under Article 8 GDPR.

11. International Transfers

Your data may be processed outside the UK and EEA by our service providers (including Stripe and Manus AI infrastructure). Where such transfers occur, we ensure appropriate safeguards are in place, including:

  • Standard Contractual Clauses (SCCs) approved by the European Commission and the UK ICO
  • Adequacy decisions where applicable
  • Binding Corporate Rules where relevant

You may request a copy of the relevant transfer safeguards by contacting us.

12. Policy Changes

We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email (if you have an account) and by updating the "Last updated" date at the top of this page. Continued use of the Service after the effective date constitutes acceptance of the updated policy.

13. Contact & Complaints

For any questions, requests, or concerns about this Privacy Policy or our data practices, please contact us:

SteakChef — Data Privacy

Email: [email protected]

Website: steakchef.app

If you are not satisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK supervisory authority for data protection:

Information Commissioner's Office

Website: ico.org.uk

Helpline: 0303 123 1113

If you are based in the EEA, you may also contact your local data protection authority. A list of EU supervisory authorities is available at edpb.europa.eu.