๐Ÿณ WifeFood
Last updated 1 August 2026

Privacy Policy

WifeFood is a cooking app. It knows what your family likes to eat because you told it, and it uses that for exactly one thing: answering "what do I cook today?". This page says precisely what is stored, what is only passed through, and who else ever sees it.

The short version

1. What we collect, and why

Everything here is something you typed, tapped or photographed inside WifeFood. There is no hidden collection: we do not read your contacts, your calendar, your other apps or your device's location.

Your account

Your name, email address, and your password stored only as a bcrypt hash โ€” we cannot read your password and neither can anyone with database access. Also: the language you read the app in, whether you are on the free or premium plan, your referral code and who referred you.

Why:to sign you in, keep your kitchen yours, and run the "give a month, get a month" referral.

An optional phone number and city exist on the account record. Nothing in the app asks you for them; they are only ever filled in if you give them to us yourself, for example while we are helping you with a support problem.

Your cooking preferences

Diet type (veg, non-veg, eggetarian, vegan or Jain), spice level, cuisines you love, ingredients you never want suggested, cooking skill, which meals you cook, any veg-only-days rule, your usual family size, how many days a dish should rest before repeating, your life mode, the language ingredient names appear in, and whether the juices tab is on.

Why:this is the product. Without it every suggestion would be a stranger's suggestion.

Your reminder time and timezone

The hour and minute you want the daily nudge, and your timezone.

Why:so "aaj kya banau?" arrives when you actually decide dinner, not at 3am. Set the reminder to Off and none is ever sent.

Your household

For each person you add: a name or nickname you choose, their relation to you (kid, elder, spouse, self, guest or your own words), an optional diet note in your words ("mild spice", "diabetic-friendly", "no brinjal"), and for a child either an age band or a birth date.

Why: to cook one meal that works for everyone at the table โ€” a milder version for a child, no fried food for an elder. See Children and baby food below.

Your cook log

For each meal you log: the dish name, which meal it was, the date, servings, your star rating, your own free-text notes, and any per-dish "cook this again after N days" rest period.

Why: this is the memory that stops WifeFood repeating a dish too soon, and it is what your streak and history are built from.

Your kitchen and lists

What you have in your pantry (item name, category, an optional quantity note), your shopping list, your saved and favourited dishes with any personal notes you added to them, your current weekly meal plan, and the dishes you passed on together with the reason you gave.

Why: to suggest dishes you can actually cook tonight, and to stop offering you things you have already said no to.

Push notification tokens

One record per device: the push token Apple or Expo issued for that device, the platform, the app version it last reported, and when it was last seen.

Why: a push token is the only way to deliver the daily reminder. The app version tells us when it is safe to retire an old build. If you never allow notifications, no token is ever created.

Partner and family links

If you share your kitchen: the read-only companion link token, the partner invite token, your link to a partner account, and any requests a partner sends you (a dish they are hoping for, or a note that they are not home for dinner on a given day).

Why:so your family can see the week's menu and the grocery list, and so a partner can ask for a dish without being able to change your kitchen.

Technical logs

Every AI call writes a usage row: which feature ran, which model, how many tokens, an estimated cost, and your account id. If a request fails, an error row records the route, the status, the error message, the stack trace and your account id.

Why: the usage rows are how we watch our own OpenAI bill and keep the daily answer free. The error rows are how a crash you hit actually gets fixed. Neither contains your photos, your voice or your recipes.

2. Photos, voice notes and what you type

These are the most personal things WifeFood touches, so they are handled differently from everything above: they pass through, they are not filed away.

  • Photos โ€” a photo of your fridge, your pantry shelf, a finished dish, or a pan you want checked for doneness. The image is held in server memory for the length of that one request, screened for anything that should not be processed, sent to OpenAI to be read, and then dropped. WifeFood has no photo storage. There is nowhere in the database a photo could go. What survives is only the text result โ€” the dish name that lands in your cook log, or the ingredient names that land in your kitchen.
  • Voice notesโ€” the recording goes straight to OpenAI's transcription model and comes back as text, which is used to answer you. The audio file is not saved, and neither is the transcript.
  • Chats and typed asksโ€” we do not keep a transcript of your conversations with WifeFood. There is one exception, and it is worth reading: when a question is general enough to be useful to anyone (it is never a baby-food question, and never a "show me something else" retry), the words of the question and the dishes we answered with are stored so the next cook who asks the same thing gets an instant answer. We only ever reuse a stored answer for 30 days; after that it is never served again, though the row itself stays in the database. That row has no account, name or device attached to it and cannot be traced back to you โ€” which is also why deleting your account does not remove it, there being nothing in it that points at you. It is still your sentence, so please do not type anything private into the ask box.
  • If an uploaded image is blocked by our image screening, we record that it happened โ€” your account id, the time, and the category it was flagged under โ€” so repeat abuse can be acted on. The image itself is not kept.
  • Reports you file โ€” when you report content, we keep what you reported, the reason you chose, anything you wrote, and a link to your account, so a moderator can act on it and come back to you. Your email address is not copied into the report itself; it is read through that link, which is why deleting your account takes the address with it. Reports are never shown to the person you reported.

3. Children and baby food

WifeFood is built for the adult who cooks. It is not directed at children, we do not knowingly allow anyone under 13 to create an account, and a child never uses WifeFood on their own.

The only information about a child in WifeFood is what a parent or guardian chooses to type about their own child, so that the app can suggest food that is right for that stage:

  • a name or nickname the parent picks โ€” it does not have to be a real name;
  • the relation "kid", and any diet note the parent writes;
  • either an age band (6โ€“8 months, 9โ€“12 months, 1โ€“2 years, 2โ€“5 years) or a birth date. A birth date is used for one purpose only: working out which age band the child is in today, so the band moves up on its own as the baby grows and the parent never has to remember to edit it.

That information is used to shape recipes and safety rules โ€” under one year old, for example, the app refuses to suggest honey, added salt or added sugar. It is sent to OpenAI only as cooking context in the shape of "child, 9โ€“12 months". It is never used for advertising, never used to build a profile, and never shared with anyone else. A parent can edit or delete a household member at any time in the app, and deleting the member deletes that information.

Baby-food suggestions are general guidance for healthy, full-term babies, not medical advice. Every baby-food screen carries that warning, and your paediatrician always outranks the app.

4. Who else sees your data

Three, and only three, outside services are involved.

OpenAI โ€” the AI behind the suggestions

OpenAI receives what it needs to answer you: the photos you upload, the voice audio you record, the words you type, and the cooking context for that request โ€” your diet, spice level, cuisines, avoided ingredients, family size, life mode, what is in your kitchen, what you cooked recently, and household notes such as "child, 9โ€“12 months".

OpenAI does not receive your name, your email address, your phone number or your password. Under the OpenAI API terms WifeFood uses, your content is not used to train OpenAI's models; OpenAI may hold it for a short period (currently up to 30 days) for abuse monitoring and then deletes it. OpenAI also runs the automatic screening that blocks unsafe images and unsafe submitted recipes.

Apple and Expo โ€” push notifications

To deliver a reminder we send the device's push token and the notification's title and body to Apple's Push Notification service, or to Expo's push service for devices registered through Expo. They carry the message; they do not receive your kitchen, your recipes or your household.

DigitalOcean โ€” hosting

The WifeFood server and its Postgres database run on a DigitalOcean server we operate. DigitalOcean provides the machine; nobody at DigitalOcean is given access to your data.

5. What we never do

  • We do not sell, rent or trade your data. Not to advertisers, not to data brokers, not to anyone.
  • There is no advertising network, no analytics SDK, no tracking pixel and no third-party tracker anywhere in WifeFood โ€” not on the website, not in the app.
  • We do not track your location. WifeFood never asks your device for it.
  • We do not read your contacts, photo library, calendar, messages or microphone in the background. A photo or a voice note reaches us only when you deliberately take or record one.
  • We do not use your data to build advertising profiles, and we do not share it across companies for that purpose.

6. Staying signed in

The website sets exactly one cookie, wf_session. It holds a signed session token, it is HTTP-only (JavaScript on the page cannot read it), and it lasts up to 30 days โ€” 7 days for admin sessions. The mobile app keeps the same kind of token in your phone's own secure storage instead.

That is the whole list. There are no advertising cookies, no tracking cookies and no third-party cookies. Changing your password revokes every session on every device.

7. How long we keep things

  • Your kitchen data โ€” preferences, household, cook log, pantry, lists, saved dishes โ€” is kept for as long as your account is open, because the whole point is that WifeFood remembers. It goes when the account goes.
  • Photos and voice recordings โ€” never stored. Gone at the end of the request that used them.
  • Anonymous cached questions โ€” reused for up to 30 days, then never served again. The row itself is kept; it carries no account, name or device, so there is nothing in it to tie back to a person.
  • Push tokens โ€” kept while the device is registered. A token is removed when you delete your account, when Apple tells us the token is dead (the app was deleted, the phone was wiped), and when we clear out tokens that have not checked in for a long time. To be exact: signing out does not remove the tokenโ€” set the daily reminder to Off, or turn notifications off for WifeFood in your phone's settings, if you want the reminders to stop.
  • AI usage and error logs โ€” kept while we need them for cost control and debugging. While your account is open these rows carry your account id, never your name or email. When you delete the account, that id is stripped out of every one of them โ€” see Deleting your account.
  • Content reports โ€” kept after they are dealt with, not only while they are open, so a moderator sees a repeat pattern instead of starting from zero each time. Deleting your account leaves the report standing but unlinks it from you.
  • Blocked-upload records โ€” the most recent 100 uploads refused by image screening, each holding the account id and the category it was flagged under. These keep the account id even after the account is deleted; otherwise deleting and signing up again would wipe the pattern.
  • Records of admin actions โ€” if someone on the WifeFood team acts on an account (a support fix, a suspension, a deletion), that action is written to an internal audit log that is never deleted. It records what was done, the id of the admin who did it, and the account id it was done to โ€” never your recipes, photos or notes. This exists so account changes can always be traced.

8. Getting a copy of your data

Tap Download my data in Profile and you get a plain, readable report โ€” your account details, preferences, your dishes, your full cook log, your kitchen and every dish you passed on. It is free for everyone, on any plan: a copy of your own data is not something we charge for.

You can also email support@wifefood.com from the address on your account and we will send you the same report, free, within 30 days.

9. Deleting your account

You do it yourself, in the app: Profile โ†’ Delete my account. You type your account password to confirm โ€” a tap alone must never be able to do this โ€” and the account is deleted immediately. No waiting period, no email to click, no reason to give, and nobody to ask. It cannot be undone, so the password screen is the last point at which you can change your mind.

If you are locked out and cannot reach that button, email support@wifefood.com from the address you signed up with and we will delete the account for you within 7 days and confirm by email. That is the fallback, not the main route.

Deleting the account removes, permanently and together: your profile and password, your preferences and life mode, every household member you added (including any child age band or birth date), your entire cook log with its notes and ratings, your saved dishes and personal notes, your pantry, your shopping list, your meal plan, every dish you passed on, every push token, your companion and partner invite links, your link to any partner account, and every partner request sent to or from you. None of it is recoverable afterwards.

A few things outlive the account, and you should know exactly which:

  • Recipes you published into the shared WifeFood library stay in the library, unlinked from you โ€” your account is no longer named as their author. If you want them taken down as well, email support@wifefood.com before you delete: once the account is gone nothing connects those recipes to you, so we can no longer tell which ones were yours.
  • The internal AI-usage and error rows stay, because our cost and crash figures are built from them โ€” but your account id is stripped out of each one as part of the deletion, so they are no longer attached to a person.
  • If someone on the WifeFood team ever acted on your account, the admin audit row for that action is never deleted and keeps the account id it acted on. It holds none of your content, and it is what makes an account change traceable afterwards.
  • A content report you filed stays in the moderation queue, because the content you reported still has to be reviewed โ€” but it is unlinked from you: your account id is removed from it, and your email was never stored on it in the first place.
  • A record that an upload of yours was blocked by image screening does keep the account id, so a repeat pattern survives someone deleting and signing up again. The image itself was never stored.
  • Anonymous cached asks are untouched, because there is nothing in them pointing at you to remove โ€” see Photos, voice notes and what you type.

10. Links you share with your family

WifeFood can create a read-only companion link so your family can see this week's menu and the grocery list without an account. That link is public by design โ€” it is meant to be pasted into a family group chat, and anyone who has it can open it. Treat it the way you would treat anything you post in that group. You can turn it off in the app at any time, and the old link stops working immediately.

A partner invite is different and deliberately separate: redeeming it creates a lasting link to your kitchen. Removing a partner rotates the invite, so a removed partner cannot walk back in with the old code.

11. Keeping it safe

  • Passwords are stored only as bcrypt hashes. Nobody โ€” including us โ€” can read your password.
  • All traffic between the app, the website and the server is encrypted with HTTPS.
  • Session tokens are signed and revocable; changing your password signs out every other device.
  • Access to the server and database is limited to the people who run WifeFood.

No system is perfect. If we ever discover a breach that affects your data, we will tell affected cooks by email and say plainly what happened.

12. Where your data is handled

The WifeFood server and database run on DigitalOcean infrastructure. OpenAI processes requests on its own infrastructure, primarily in the United States. So if you are cooking in India, the words you type and the photos you take are read on servers outside India before the answer comes back to you.

13. Your choices

  • Change or clear any preference, at any time, in Profile.
  • Remove a household member, and the information about them goes with the row.
  • Set the daily reminder to Off in Profile โ€” or turn off notifications for WifeFood in your phone's settings.
  • Delete individual cook-log entries and dishes you passed on.
  • Turn off the companion link, or remove a partner, and the access ends immediately.
  • Simply not use the camera or the microphone โ€” every other part of WifeFood works without them.
  • Delete the whole account yourself, from Profile โ†’ Delete my account โ€” password, then gone.
  • Ask for a copy of your data at support@wifefood.com.

14. Changes to this policy

If what we collect or who we share it with changes, this page changes in the same release and the "last updated" date at the top moves. For a change that meaningfully affects you, we will also tell you in the app or by email rather than quietly editing the page.

15. Contact

Questions about anything here, or a request about your own data, goes to one place: support@wifefood.com. A person reads it. See also our Terms of Use and the Support page.