Privacy policy

Your baking data stays yours.

What Oven & Butter stores

Recipes, folders, pantry stock, shopping lists, bake plans, history, notes, preferences, and locally selected photos are stored on your device. You can export, restore, or delete this local data from the app.

Accounts and purchases

Most baking tools work without an account. Sign in with Apple on iOS, or Google sign-in on Android, is normally required for AI services and AI-credit purchases. Invited review/test users may instead use a separately provisioned username and password. Those credentials are sent securely to our backend; the password is checked against a salted password hash and is not saved by the app. Review/test sessions and data are separate from personal Apple and Google accounts. When you sign in, Oven & Butter receives an Apple-provided account identifier and, when Apple makes it available, your email or relay email. On Android, a Google sign-in token is sent securely to our backend for verification. It may contain basic profile or email claims; our account records persist only the Google-provided account identifier, not your Google name or email. Purchase transactions are processed by Apple on iOS and Google Play on Android. Oven & Butter verifies transactions and keeps a server-side credit ledger so valid credits can be recovered without being granted twice.

AI imports and assistance

When you choose an AI feature and allow AI sharing, the recipe text, link, selected photo or scanned page, question, or relevant baking context you submit is sent securely to Oven & Butter's backend and OpenAI, its AI processing provider, to produce the requested result. Context can include current and previous-bake notes, planning details, and the dietary or allergy preferences you have selected. You can turn off AI sharing in Settings; offline baking tools remain available. Oven & Butter does not send your private recipes or photos unless you actively use a feature that requires them. Avoid including personal information that is not needed for your baking request.

We request that OpenAI does not store Responses API results for later retrieval. This does not eliminate provider safety retention: OpenAI may retain API inputs and outputs in abuse-monitoring logs for up to 30 days, with longer retention in circumstances described in its data controls. Deleting your Oven & Butter account or turning off AI sharing does not automatically delete provider safety logs.

For Create with AI, we temporarily keep the generated draft and its review information on our server for a 24-hour recovery window so an interrupted request can be recovered without another credit charge. We also use the completed recipe’s title, ingredients and method to request an AI cover illustration from OpenAI. The image is cached for the same recovery window to avoid generating it repeatedly. After that window, server drafts and image bytes are cleared by scheduled cleanup. Minimal account-linked request identifiers, status, input fingerprints and credit records remain while your account is active to prevent duplicate charges. Available draft and cover records are included in account export, and account deletion removes these server records. The app also keeps your pending request, returned draft and illustration locally so you can resume reviewing them; saved recipes and their cover images remain on your device and are included in local backups.

Reporting AI content

When you choose to report AI content, we send the selected output, any image preview shown in the report, your selected reason and optional explanation, and your account identifier to the Oven & Butter backend for safety review. Reporting is optional and does not use an AI credit. Reports are not sent to OpenAI. We keep reports for up to 90 days or until you delete your account, whichever happens first.

Camera, photos, microphone, and speech

Oven & Butter requests these permissions only when you choose a related feature, such as importing from a photo or using hands-free baking controls. Apple’s speech recognition service on iOS, or the selected Android speech recognition service, may process microphone audio on its servers, depending on device, service and language support. Questions transcribed for AI assistance are sent only with AI-sharing permission. Spoken narration uses installed voices; Android offers installed offline voices. You can change permission access in your device’s Settings.

Analytics, advertising, and tracking

Oven & Butter does not show third-party advertising and does not track you across apps or websites. The iOS privacy manifest declares no tracking domains.

Usage events are recorded locally to help you review app activity. If you enable optional usage sharing in Settings, the app sends daily event counts and its version/build to our backend to help improve the app. This upload does not include recipe text, questions, photos, or individual event details. Requests use your signed-in session; the aggregate statistics table does not store an account identifier. Usage sharing is off by default and can be turned off in Settings.

Android photo text recognition uses Google ML Kit on the device. ML Kit may send SDK telemetry to Google, including per-installation identifiers, device and app information, usage, diagnostics and performance data. This is separate from our optional product-count sharing. See Google’s ML Kit data disclosure.

Retention and deletion

Local data remains on your device until you delete it or the app. Account and credit-ledger records are retained while your account is active for account security and purchase recovery. You can delete your server account inside Oven & Butter after confirming with Apple or Google (or re-entering the separate review/test credentials for an invited test account), or request deletion through support without reinstalling the app. Account deletion removes the server account, any stored email, credit ledger, account-linked purchase records, and recoverable AI drafts and covers. On iOS it also revokes the app’s Sign in with Apple authorization. The Android backend does not retain a reusable Google authorization token. We retain redeemed Apple transaction identifiers or hashed Google Play purchase tokens without the account identifier to prevent previously used purchases from being redeemed again. Deleting your server account does not delete recipes, photos or baking data stored locally; those can be managed separately in Settings.

Contact

Questions or privacy requests can be sent to hello@bakebook.app.