Privacy Policy
Last updated: 10 September 2026
CookFast helps you turn cooking videos into recipes you can actually cook from. This policy explains what personal data we collect, why, and what your rights are. We have tried to keep it short and honest.
Who we are
CookFast is a personal project operated from the Netherlands (the "developer", "we"). For anything in this policy, contact support@cookfast.fit. We are the data controller for the personal data described below under the EU General Data Protection Regulation (GDPR).
What we collect
- Account data. When you sign in with Google we receive your name, email address and profile picture. We do not see your Google password.
- Your content. The YouTube links you paste, the recipes extracted from them, your edits, tags, cook log and food preferences.
- Suggestion history. The five weeknight preferences you set (diet, goal, weeknight time, cuisines, foods to avoid), which video we suggest you each day, and which suggestions you skip (and why, if you tell us). Used only to pick better suggestions for you.
- Technical logs. Standard server logs (IP address, browser or app version, timestamps) kept briefly for security and debugging.
We do not run ads, do not use third-party analytics or tracking SDKs, do not process payments and do not sell personal data. Full stop.
How we use your data, and on what legal basis
- Providing the service (your account, recipe library, suggestions, community features): performance of a contract, Article 6(1)(b) GDPR.
- Security, abuse prevention and debugging (server logs, rate limiting): legitimate interest, Article 6(1)(f) GDPR.
- Anything new that needs consent will ask for it first.
How YouTube links are processed
When you paste a YouTube link, our server fetches information about that video to build a structured recipe (title, ingredients, steps). We store the extracted recipe and the video's channel name and link so the creator is credited. We do not store or serve the video itself. YouTube is a separate service with its own terms and privacy policy.
The community pool
Recipes can appear in the public community section. Community recipes are always anonymous: they never show your name, email or any account detail. Only the recipe itself and the original video creator's credit are public.
Who we share data with
Only the processors needed to run the service: our hosting provider (Render, with servers in the EU and US) and Google (sign-in). Where data leaves the EEA, it is protected by the EU-US Data Privacy Framework or Standard Contractual Clauses. Nobody gets your data for advertising.
How long we keep it
For as long as your account exists. Server logs are kept for a short rolling window. When your account is deleted, your account data, personal recipe library and suggestion history are deleted immediately and irreversibly; there is no archived copy and no hidden deactivated account. Anonymous community-pool recipes (which contain no personal data) may remain.
Deleted data can survive for a short while in routine encrypted database backups. Those backups are not queried or used for anything except disaster recovery, and if one ever has to be restored, the deletion is applied again to the restored data.
Deleting your account and data
You can delete your account yourself, at any time, from inside CookFast. On the web, open Preferences and use Delete account. In the mobile app, open Profile and use Delete account. You will be asked to type the word DELETE to confirm.
Deletion happens straight away and cannot be undone. It removes your account, your name and email address, your recipe library and tags, your preference answers, and the record of what you cooked or skipped. Recipes of yours already in the anonymous community pool stay there with the link to you removed, as described in the terms of service; those copies contain no personal data.
If you would rather not do it yourself, or you cannot sign in, email support@cookfast.fit from the address you signed in with and we will delete your account and associated personal data within 30 days.
Your rights
Under the GDPR you can ask for access to, correction of, deletion of, or a portable copy of your personal data, restrict or object to processing, and withdraw consent. Contact support@cookfast.fit. You can also lodge a complaint with the Dutch supervisory authority, the Autoriteit Persoonsgegevens.
Children
CookFast is not directed at children and is intended for users aged 16 and over.
Changes
If this policy changes materially, we will update this page and the date above. Continued use after a change means the new version applies.