Privacy Policy
The short version. Your recipes live on your iPhone. There is no account, no sign-up, no email address, and no password. We do not run ads, we do not sell or share your data, and no third-party analytics or advertising SDK is built into the app.
Things leave your phone only when you ask Savour to do something it cannot do on the phone alone — read a link, read a video, write a recipe, tidy a shopping list. Each of those is listed below, with what travels and what we keep.
1. Who we are
Savour is published by Autonomous Studios LLC, a Wyoming limited liability company (“we”, “us”, “Savour”).
Email us about anything in this policy: [email protected].
2. There are no accounts
Savour has no sign-in of any kind. We never ask for, and have no way to receive:
- your name, email address, phone number, or postal address
- a password or any credential
- your contacts, calendar, location, or health data
- your social media logins
We identify a device, not a person. See section 5.
3. What stays on your iPhone
All of this is stored only on your iPhone, in the app’s own private storage, and is never sent to us:
- your recipe library — titles, ingredients, steps, photos, notes, ratings, favourites, collections
- your meal plan and saved plan templates
- your grocery list, aisle categories, saved store orders, and shopping trips
- your pantry contents and expiry dates
- your household size, cooking nights, and taste likes and dislikes
- your appearance and display preferences
Delete Savour and all of it goes with the app. We keep no copy, because we never had one.
Photos. When you photograph a recipe or a cookbook page, or import a screenshot, Savour reads the text using Apple’s Vision framework, on the phone. That photo and the text read out of it never leave your iPhone. The one photo of yours that can leave is a picture of a plate of food, and only when you accept the offer to turn it into a recipe — section 4.12 says exactly what happens to it.
Your voice. When you talk to Sous Chef, or cook hands-free in Cook Mode, speech is transcribed on the device — Savour sets Apple’s on-device recognition flag — and steps are read aloud by Apple’s on-device speech synthesizer. The audio is never uploaded, and neither is the recording.
iCloud. Savour does not sync your library to iCloud or to us. If you use encrypted iPhone backups, your Savour data is included in that backup. That backup is between you and Apple and is governed by Apple’s privacy policy, not this one.
4. What leaves your iPhone, and when
Nothing here happens in the background. Every case is something you asked for by tapping something.
4.1 A recipe website you paste or share
Your iPhone fetches that page directly from the website, the way a browser would, and reads the recipe out of it on the phone. If the page declares a recipe photo, your phone downloads that image to save with the recipe.
The website sees the request, including your IP address and a user-agent string identifying Savour on iPhone. No identifier of you is attached — no device identifier, no cookie, no account. We are not involved and receive nothing.
4.2 A TikTok link
Your iPhone calls TikTok’s public oEmbed endpoint directly to read the creator’s caption, and reads the recipe out of that caption on the phone. TikTok sees the request, including your IP address. No Savour server is involved.
4.3 A social link your phone cannot read — Instagram, and reels generally
Instagram cannot be read from the phone, so the link goes to our importer, which fetches the post’s public caption and, where the platform publishes one, the reel’s transcript or subtitle track. That text comes back to your phone, and your phone reads the recipe out of it.
What we send onward: the link, to a scraping service (see section 7). What comes back: the creator’s own public caption, transcript, name, and thumbnail.
We cache this. The caption we fetched is stored against the link so that the next person importing the same reel does not make us buy the same fetch twice. That cache row records the public post — its URL, platform, caption, transcript, creator attribution, and how many times it has been served. It carries no device identifier and no reference to you, by design: it is a record of a piece of public internet content, never a record of who imported what.
4.4 Letting Savour watch a video
If the caption did not contain enough to cook from, Savour can analyse the video itself. The link and the caption text already fetched go to our service, which resolves the video’s media, has it transcribed and analysed by the AI providers in section 7, and returns the readings to your phone.
The video’s bytes are fetched, used for that one request, and discarded. We do not store the video, and we do not store the analysis.
4.5 Reading free text into a recipe
When your phone cannot structure a block of text by itself — an older iPhone has no on-device model to do it with — the text goes to our service and comes back as a structured recipe.
What we store depends on where the text came from. A creator’s published caption, a spoken transcript, or text read off the screen of a public video is public content, and the reading is cached so nobody pays to read the same reel twice. Text you pasted yourself, and text read off a photo you took, are never stored — as far as we can tell those are your own words, possibly a recipe out of a family notebook, and they are used for that one request and dropped.
4.6 Writing a recipe from a request
When you ask Savour to write a recipe, your request goes to our service, together with the allergies and diet tags you saved in Profile, as plain words — so the recipe comes back already avoiding them. It is used for that request and is not stored.
This is the one place your saved allergy and dietary settings leave the phone. If you never ask Savour to write a recipe, they never leave.
4.7 Sous Chef
Sous Chef answers most things on the phone. When it cannot place what you asked, your message and the conversation so far go to our service for a reply. Sous Chef never sends your pantry, your library, your plan, or your list — the server has no access to your kitchen and cannot write anything to it. Used for that turn, not stored.
Cook Mode’s coach line uses the same channel. When you start cooking a recipe, its title, ingredient names, and steps go to our service once, for a single sentence about what most often goes wrong with that dish. The sentence is kept on the recipe so it is not asked for again; the request itself is not stored.
4.8 The plated-dish picture
When you ask for a picture of the plated dish, the recipe’s title and ingredient names go to our service to generate it. The generated image comes back and is saved on your phone. Used for that request, not stored.
4.9 Planning a week with AI
The titles of recipes already in your library go to our service as candidates so a week can be composed from them. Ingredients, notes, and photos do not travel. Used for that request, not stored.
4.10 Tidying a shopping list
When you tap a Shop button, each ingredient line goes to our service to be reduced to the item a shop actually sells — “3/4 cup shredded mozzarella (freshly shredded melts better)” becomes “shredded mozzarella”.
We cache this, against a one-way hash of the line, so the same line is never paid for twice across everyone using Savour. What is stored is the hash and the shortened product name. The row carries no device identifier and nothing linking it to you.
The shortened name can only ever be words your own line already contained — the service is not allowed to rename, translate, or substitute anything, and your phone checks that before using the answer.
4.11 Buying a subscription
When you subscribe, Apple gives the app a signed receipt, which goes to our service so it can confirm the purchase and unlock the app on that device. Apple also notifies our service directly about renewals, cancellations, and refunds.
We store, against the device identifier: the App Store transaction id, which product was bought, whether it is active, and when it expires. We never receive your name, your email, your Apple Account, or your payment details. Apple handles payment; we never see a card.
4.12 A photo of a plate of food
When you snap a photo and Savour finds no recipe text in it, it offers to treat the picture as a dish and write a recipe for it. Nothing happens until you accept. If you do, the photo goes to our service and on to the AI provider in section 7, for two questions in turn: what dish is this, and then a recipe for it. What comes back is Savour’s best guess at a restaurant-style version you can make at home — it is marked as Savour’s, not as any creator’s. The photo is used for that one request and is not stored anywhere.
4.13 Checking a cover picture
A recipe imported from a social video arrives with the video’s cover frame. Before Savour uses that frame as the recipe’s picture, it may send the frame to our service with one question: does this show the finished dish? The answer is yes or no, and a no means Savour shows its placeholder instead. This is the creator’s public frame, never a photo you took, and it is not stored.
4.14 Popular dishes
The “Popular with other cooks” row in your library asks our service for the most-reused public links in the recipe cache. The request carries the device identifier and nothing else — none of your recipes, and nothing about which tiles you look at. Tapping a tile runs an ordinary link import, and section 4.3 applies to it.
4.15 What is never sent, in any case
Your recipe library. Your photos. Your pantry, plan, or grocery list. Your ratings, notes, or collections. Your household size or taste preferences. Your name, email, contacts, location, or health data. Your voice.
5. The device identifier
To meter usage without accounts, Savour generates a random UUID the first time it needs one and stores it in your device’s Keychain. It travels on every request to our own services, with an Apple App Attest assertion proving the request came from a genuine, unmodified copy of Savour.
- It is randomly generated. It is not derived from your Apple Account, your email, your phone number, the advertising identifier, or any hardware serial number.
- It is not synced to iCloud and does not follow you to another device.
- It identifies a device, not a person. We hold nothing that could link it to you.
- It is used for rate limiting, abuse prevention, cost control, and knowing which device a subscription belongs to. Never for advertising, and never for tracking.
- It is never attached to requests to third-party websites (sections 4.1 and 4.2).
Because it lives in the Keychain, it survives deleting and reinstalling the app on the same device. Erasing the device removes it.
6. Analytics, ads, and tracking
- No advertising, and no ad network code of any kind.
- No third-party analytics or crash-reporting SDK. No Firebase, Google Analytics, Amplitude, Mixpanel, Segment, Sentry, or anything like them is built into Savour.
- No tracking, as Apple defines it. Savour never touches the advertising identifier and shows no App Tracking Transparency prompt, because it has nothing to ask for.
- No data brokers. We do not sell, rent, or share personal information with anyone, including for cross-context behavioural advertising under US state privacy laws.
Savour does contain a small first-party measurement client we wrote ourselves, which could report anonymous screen names and counts — how many people finish setup, for example. It ships switched off: no key is configured, so it queues nothing, sends nothing, and writes nothing to disk. If we ever switch it on, it would send event names and counts only — never a recipe, a link, an allergy, or anything you typed — and we will update this policy and this section before we do.
7. Who else is involved
We use a small number of companies to run the parts of Savour that do not run on your phone. Each receives only what its job needs.
| Company | What it does | What it receives |
|---|---|---|
| Supabase | Hosts our service and database | Everything in section 4 passes through it; it stores what section 8 lists |
| Apify | Fetches public social posts and their media | The public link you asked us to read |
| Google (Gemini) | AI: reading videos and pictures, structuring text | The caption, transcript, or video we fetched; the text you asked us to read; a dish photo you chose to send (4.12); a cover frame being checked (4.13) |
| Anthropic (Claude) | AI: structuring text, writing recipes, Sous Chef replies, shortening shopping lines | The text for that request |
| Deepgram | Speech-to-text, used only when a platform publishes no captions of its own | The audio of the public video being analysed |
| Apple | Payments, subscription receipts, and App Attest | Your purchase; we never see your payment details |
None of them receives your device identifier, and none of them is given anything to build a profile with. If we change this list we will update this page.
8. What we store, and for how long
| What | Where | How long |
|---|---|---|
| Your recipes, plan, groceries, pantry, profile, photos | Your iPhone only | Until you delete them or delete the app |
| The device identifier and its App Attest key | Your Keychain, and our database once you use a service | Until you ask us to delete it |
| Usage rows — which function ran, which AI model, whether it succeeded, token counts, cost, timestamp | Our database, against the device identifier | Until you ask us to delete it |
| Subscription record — transaction id, product, status, expiry | Our database, against the device identifier | Until you ask us to delete it |
| Cached public captions and transcripts (4.3), and readings of them (4.5) | Our database, against the link | Indefinitely. No device identifier, nothing linking it to you |
| Cached shopping-line results (4.10) | Our database, against a hash of the line | Indefinitely. No device identifier, nothing linking it to you |
| Links, video bytes, pasted text, photographed text, a dish photo you chose to send, cover frames being checked, Sous Chef messages, recipe titles sent for planning or plating | Not stored | Used for that one request, then dropped |
We do not currently run an automatic deletion schedule, so we are not going to claim one. The honest answer is: we keep the rows above until you ask us to delete them, and we will delete them when you do.
To delete everything associated with your device: email [email protected]. Because we hold no identity data, we may ask you to send the device identifier so we can find the rows — we have no other way to locate them, and we will never ask you for identifying information to prove they are yours. If you would rather not send it, deleting the app and erasing the device removes the identifier from your end and leaves us with rows nobody can ever match to a person.
9. Your rights
Depending on where you live you may have rights to access, correct, delete, or port your personal data, or to object to its processing — under the EU and UK GDPR, the California CCPA/CPRA, or similar laws.
Most of these are self-executing here, because the data is on your device and under your control. For the server-side rows in section 8, email [email protected] and we will action any valid request.
We do not sell personal information and have not done so. We do not share personal information for cross-context behavioural advertising. There is nothing to opt out of.
For users in the EEA and UK: our legal basis for the device identifier and usage rows is our legitimate interest in running the service securely and controlling its cost; for subscription records it is performance of our contract with you. The processing is minimal and pseudonymous.
10. Children
Savour is a general-audience cooking app and is not directed to children under 13. We do not knowingly collect personal information from children. Because we operate no accounts and collect no personal information from anyone, we hold no children’s data. If you believe a child has somehow provided us personal information, contact [email protected].
11. Changes
If we change this policy we will update the effective date and post the new version at autonomousstudios.ai/savour/privacy. Changes that affect what leaves your device will be surfaced in the app.
12. Contact
Autonomous Studios LLC
Wyoming, United States
[email protected]