Your recipes are personal

Privacy Policy

Buttermade is built for family recipes and the memories around them. This policy explains what the app handles, why it is needed, and the choices available to you.

Effective date: July 20, 2026

1. Scope and operator

This policy applies to the Buttermade iOS app, its family beta, and this website. Buttermade is an independent app project created and operated by Benjamin and Melissa Fallon in the United States. In this policy, “Buttermade,” “we,” and “us” refer to that project.

Questions about this policy can be sent to feedback@buttr.studio.

2. Information we handle

Account and profile information

If you sign in, Buttermade uses Sign in with Apple. We may receive your name, an email address or Apple private relay address, and an Apple account identifier. We create a Buttermade user ID and store the profile information needed to identify you inside cookbooks.

Recipes and family content

The app handles content you choose to create, scan, import, save, or share. This can include recipe text, source information, cookbook content, recipe-card images, dish photos, notes, variations, cooked-history entries, and optional cooked-event photos. This material can contain personal or family information, so only submit content you are comfortable processing and sharing with the cookbook members you select.

Personal settings and activity

We handle information needed for favorites, hidden recipes, grocery state, notification preferences, cookbook memberships, invitations, and other app settings. Some of this information is stored only on your device, while signed-in and shared features use our backend service.

Device, usage, and diagnostic information

We collect limited technical information such as app version and build, operating-system version, device model, environment, installation ID, user ID when signed in, event timestamps, cookbook/recipe/capture identifiers, feature-use events, durations, result states, network state, and stable error classes. Push notifications require a device push token.

Product analytics and error diagnostics are designed not to include recipe titles or text, ingredients, instructions, notes, transcripts, image bytes, image links or storage paths, email addresses, names, Apple identifiers, or push tokens. Session replay is disabled.

Camera, photos, microphone, and speech

Buttermade asks for camera or photo-library access only when you choose a photo-based feature. Optional hands-free Cook Mode asks for microphone and speech-recognition permission when you turn it on. Buttermade uses the resulting transcript during the active session and does not retain it as product analytics. Apple may process speech recognition under its own privacy terms.

Feedback

If you choose Send Feedback, the app opens your email client with a draft. The draft includes a random feedback ID, app version and build, UTC time, generic device model, and operating-system version. You decide whether to send it and what to write. The message body you write is not copied into our analytics or backend database.

3. How we use information

We use information to:

  • create and secure accounts and cookbook memberships;
  • store, synchronize, display, and share cookbook content;
  • parse recipe photos or links and provide optional generated imagery;
  • deliver household notifications you choose to enable;
  • operate personal features such as favorites, hidden recipes, and groceries;
  • measure reliability and improve the beta without reading recipe content in analytics;
  • diagnose errors, prevent abuse, enforce limits, and secure the service; and
  • respond to feedback, privacy questions, and support requests.

We do not sell personal information. Buttermade has no third-party advertising and does not use your information to track you across other companies’ apps or websites.

4. Guest mode and shared cookbooks

Guest mode

Recipes and drafts you keep in guest mode remain on that device unless you later sign in and move them into your account. A guest-initiated photo parse still sends the prepared recipe image to our backend and AI processor so the app can return a draft. Guest requests use temporary service identifiers and limited technical telemetry for reliability and abuse prevention.

Shared cookbooks

Content you add to a shared cookbook is visible to that cookbook’s members according to their access. Personal overlays are kept separate where the product describes them as private. Do not add content to a shared cookbook if you do not want its members to see it.

5. Who receives information

We share information only as needed to operate Buttermade:

  • Other cookbook members receive content you add to shared cookbooks and the profile attribution needed for the family experience.
  • Apple supports Sign in with Apple, push notifications, camera/photo permissions, and speech recognition.
  • Supabase provides authentication, database, private file storage, realtime synchronization, server functions, and push-registration storage.
  • OpenAI processes the recipe images, recipe text, links, or prompts needed when you choose an AI-assisted parsing or image feature. Buttermade keeps provider credentials on the server rather than in the app.
  • PostHog processes the limited usage and error metadata described above. Our PostHog project is hosted in the United States, identified profiles use a Buttermade user ID, and session replay is disabled.
  • Email providers process a support or feedback message only if you choose to send one.

We may also disclose information when required by law, to protect people or the service, or as part of a business transition where the recipient is required to honor this policy.

6. Retention and deletion

We retain account and shared-cookbook information while it is needed to provide the service, maintain the family cookbook, meet security and legal obligations, resolve disputes, and honor deletion choices. Device-only guest content remains until you remove it, delete the app’s data, or move it into an account.

During the family beta, our policy is to retain detailed recipe parse/save telemetry for up to 180 days, product analytics and error diagnostics for approximately 90 days where vendor controls permit, and de-identified or aggregate operational metrics for longer periods. Feedback emails are retained as needed to resolve the report and maintain a reasonable support record.

Internal-beta deletion status: Buttermade’s in-app account-deletion flow is currently disabled while its shared-content and two-account behavior completes testing. During this beta, contact feedback@buttr.studio to request account or data deletion. An in-app deletion path is required before a public App Store release.

When account deletion is completed, Buttermade removes the account identity, profile, Apple token custody, push registrations, account preferences, analytics identity, and the member’s source recipes, versions, memories, notes, and photos. A complete copy or version that another member independently chose to keep may remain as that member’s separate object, without the deleted account identity attached. Minimal deletion receipts and encrypted backup copies may remain temporarily for security, recovery, and proof of completion, then expire under their applicable rotation.

7. Your choices

  • Use guest mode for device-local use where available.
  • Choose whether to sign in and which cookbook to join.
  • Review and edit parsed recipe drafts before saving them.
  • Control camera, photo, microphone, speech, and notification permissions in iOS Settings.
  • Turn supported notification categories on or off in the app.
  • Choose whether to send feedback and what the message says.
  • Contact us to request access, correction, export, or deletion of account-related information.

Some requests may require us to verify your identity and may be limited where information belongs to another cookbook member or must be retained for security or legal reasons.

8. Security and children

We use technical and organizational safeguards appropriate to a private family-cookbook beta, including encrypted network connections, private storage paths, account authentication, and server-side access rules. No service can guarantee absolute security, so please use care with especially sensitive material.

Buttermade is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided personal information, contact us.

9. Changes and contact

We may update this policy as the beta, providers, or app features change. We will update the effective date and provide additional notice in the app when a change materially affects how personal information is handled.

Privacy questions and requests: feedback@buttr.studio. General beta help is available on the support page.