Privacy Policy
Last updated 16 September 2026
Salsa: AI Recipe Guide is operated by Ashton McHardy. For privacy questions, access or correction requests, or help deleting data, contact ashton.mchardy@gmail.com.
Information we use
- Account and sign-in: Firebase Authentication processes your account identifier and email, and the name and profile information your chosen Apple or Google sign-in provides. Apple may provide a private relay address. Email sign-in and password recovery are handled by Firebase. A pseudonymous account may be created before your profile is linked, to associate setup and purchases securely. Salsa does not request Google mail, contacts or files.
- Your recipes: recipe links, selected recipe text or photos, organised ingredients and instructions, cover photos, categories, notes and ratings. Recipes and cooking progress are stored on your iPhone. With recipe sync enabled, recipes and chosen covers are also backed up to your private Firebase account. Finished queued imports are stored in your account for delivery even when automatic backup is off.
- Cooking assistance: your question, relevant recipe and current step, and recent conversation context are processed to provide an answer. Do not include information that is unnecessary for cooking, such as passwords or payment details.
- Subscriptions and security: Apple purchase identifiers, signed transaction information, subscription status, an account-association token, import allowance records and technical request information are used to verify access, prevent abuse and run the service. Apple handles checkout; Salsa does not receive your payment card details. Network providers may process IP addresses and technical connection logs.
- Optional diagnostics: if you enable Help improve Salsa, Firebase Crashlytics processes crash reports and technical app/device and installation information. Salsa records basic import, cooking and sync counts. We do not deliberately attach recipe text, photos, notes, questions, email addresses or Salsa account IDs to crash reports. This option is off by default.
- Optional Apple Ads and subscription measurement: in versions offering this choice, and only when you allow it, Salsa sends RevenueCat a pseudonymous account identifier, verified Apple purchase/subscription information and an Apple AdServices attribution token. This helps us connect Apple Ads campaigns, ad groups and keywords to trials, subscriptions, renewals and refunds. Attribution is not available for every installation. This is separate from optional diagnostics and from AI processing. Salsa does not deliberately include recipes, photos, questions, private notes, email addresses or names in RevenueCat reporting. Server/network providers may process technical connection information.
- Support: we receive the email address, message and any attachments you choose to send us. Send only information needed to investigate your request.
OpenAI processing
The paywall explains what is shared with OpenAI before you accept. With that permission, Salsa sends selected recipe text and recipe photos through its server to OpenAI to organise and check imports, and sends recipe context and your cooking questions to answer them. Recipe text may also be used to create a labelled fallback cover illustration. AI can make mistakes; verification is not a guarantee of recipe accuracy or food safety.
Your passwords, sign-in tokens, private recipe notes and privately saved cover photos are not deliberately included in these AI requests. A photo you explicitly select for a recipe import is different: it is sent for reading and verification. Original import photos and private notes are not placed in a shared image catalogue. Cooking-step image generation and voice narration are currently disabled. Previously generated, non-private illustrations may remain available for reuse.
Salsa requests that AI responses not be stored as retrievable response history where the API supports this. This is not a promise of zero retention. OpenAI's API data is not used for model training by default; abuse monitoring may retain content for up to 30 days, with legal and safety exceptions. See OpenAI's API data controls.
Service providers and sharing
We use Google Firebase/Google Cloud for authentication, hosting, private recipe storage, processing and optional crash reporting; OpenAI for the AI functions described above; and Apple for purchases and platform services. Google or Apple also processes sign-in if you choose that provider. These services may process data outside your country, including in the United States. We use service-provider terms and access controls to protect information and limit its use to providing the service, security and legal obligations. See Firebase privacy and security and Apple's privacy information.
Google sign-in may use your IP address to estimate a general location for fraud prevention. Its included SDK also declares account/contact information (including phone-number information), user and device identifiers, usage information and other technical data for sign-in functionality and service analytics. Salsa does not ask for your phone number or precise location, read your contacts, or request access to Google mail or files. These provider disclosures are included in our App Store privacy information; they are separate from Salsa's optional crash-reporting switch. See Google sign-in's data disclosure guidance.
RevenueCat provides the optional subscription and Apple Ads measurement described above. We send this information through Salsa's server; the app does not include a RevenueCat purchase-observer SDK. RevenueCat may process data in the United States and other locations under its service-provider terms. See RevenueCat's privacy information. Salsa does not sell personal information, request your advertising identifier (IDFA), or use this measurement to track your activity across other companies' apps and websites. Optional crash reporting is separate from ad measurement. We may disclose information when legally required or to address fraud, abuse or a security incident.
If you create a recipe invitation, anyone with its link can see the sender name you enter and the recipe preview. A registered subscriber can save a separate copy. The invitation excludes private notes, star ratings and privately uploaded cover photos. Disabling a link or deleting your account does not remove copies another person already saved.
Retention and deletion
- Saved recipes and profile information remain until you remove them or delete the account. Turning off Recipe sync stops future automatic backup; it does not delete existing cloud copies.
- Temporary import sources are normally removed after completion or cancellation. Interrupted cleanup is retried. A scheduled cleanup checks for sources older than 24 hours every 30 minutes; service failures can delay removal. Ready import-status records are scheduled for cleanup after seven days.
- Unconfirmed uploads stay privately on the iPhone for retry until confirmed or cancelled. Unimported Safari links expire after seven days and are cleaned when the local inbox is accessed.
- Recipe invitation links expire after 90 days; expired server records are cleaned regularly. You can revoke an invitation sooner from its sharing screen.
- Optional local diagnostic queues expire after seven days; server duplicate-prevention receipts expire after eight days. Daily usage aggregates do not retain account identifiers. Firebase states that Crashlytics starts removing crash reports and associated identifiers after 90 days; provider backup and deletion schedules also apply.
- Queued measurement data is kept privately until delivered, cancelled or deleted with your account; failures are retried. We remove raw attribution tokens and signed reporting payloads from completed delivery records. Completed purchase/notification delivery records expire after 30 days; an attribution-delivery marker is retained until account deletion to avoid overwriting your original acquisition.
- Deleting your account removes its active Firebase account, recipes, private uploaded files, saved permissions, invitations and queued measurement data. If reporting has started, Salsa also requests deletion of the RevenueCat customer record and checks completion. Failures are retried. A deletion marker blocks old sign-in tokens while cleanup is outstanding and is scheduled to expire one day after cleanup completes; completed deletion-job records expire after seven days. Provider backups, security logs and records subject to legal obligations may take longer to expire. Deletion is not an immediate purge of all provider systems.
Your choices and rights
In Settings you can export recipes, control Recipe sync and Help improve Salsa, manage AI permission, and delete your account under Account & more. Turning off AI processing stops future authorised requests and cancels queued processing when the server receives the change; an already-running request may finish. Saved recipes and cooking steps remain available. iOS controls camera, selected-photo, notification, alarm and Live Activity permissions separately.
Where offered, Apple Ads & subscription measurement is optional and can be changed under Settings → Privacy. Declining does not restrict paid features. Turning it off stops new reporting once Salsa reconnects and the server receives your choice; an already-running request may finish. It does not automatically erase previously reported data. Delete your Salsa account or contact us for a data-deletion request. Older app versions without this measurement choice do not enable it.
You may contact us to request access, correction or deletion, or exercise other privacy rights available where you live. We may need to verify that the account is yours. You can also raise a concern with your local privacy regulator. Parents or guardians should contact us if a child has supplied personal information without appropriate permission.
Deleting Salsa or your Salsa account does not cancel an Apple subscription. Use Manage subscription in Salsa or your Apple account's subscription settings.
Changes
We will update this page when practices change. Material changes affecting permission will be explained before the new processing begins.