Privacy
Last updated: 2026-09-05
Account
Spuno signs you in anonymously by default. No email, name, or password is required. Firebase assigns the account a random identifier so Spuno can keep its data separate from other accounts.
You may optionally link your account to Google or Apple sign-in. Linking lets you reach your data from another device, and makes recovery reliable if your phone is reset, erased, or replaced. When you link an account, the sign-in provider may give Firebase your email address, display name, provider identifier, and profile photo, depending on the provider and the choices you make there.
If you never link an account, your data is still saved on our servers, but the only thing identifying it as yours is a credential stored on your device. Erasing or resetting the device can therefore leave an unlinked account unreachable. See Your controls below for what this does and does not mean.
What data we store
The following is stored in Google Cloud Firestore under your Firebase account identifier:
- Recipes you add: name, ingredients, instructions, source, and any photos you attach (up to five per recipe, so a printed recipe spanning several pages can be captured whole).
- Weekly plans you generate or edit.
- Preferences: household size, dietary rules, and similar settings.
- Grocery list state: which items you’ve crossed off, the amount each was crossed off against, any grocery lines you’ve edited, and any items you’ve added to the list yourself.
Spuno no longer keeps a pantry. Earlier versions stored a list of ingredients you had marked as already on hand; that feature was removed, and the app no longer reads, writes or updates it. If your account still holds one from an older version, it is inert, remains protected by the same per-account security rules, and is removed when you request account deletion.
Recipe photos you upload are stored in Google Cloud Storage, under a path scoped to your account. Firebase Security Rules prevent one signed-in account from reading another account’s private Firestore or Storage data. Google, Spuno’s operator, and authorized service providers may process that data only as needed to operate, secure, support, or comply with legal obligations for the service.
Spuno also keeps a server-only cache of canonical recipe URLs and recipe fields derived from public recipe pages. Cache entries contain no Firebase account identifier or raw page content, are not readable by app clients, and expire after 60 days.
How you use the app
Spuno records how you move through the app, so we can see which parts work and which parts people give up on. In a future version, it will also let the weekly plan learn what you tend to cook. This is first-party only: the records are written to your own account’s area of the same database as your recipes, by the app itself. No analytics or advertising SDK is involved, and nothing is sent to an analytics company.
This data is pseudonymous, not anonymous. It is stored under your Firebase account identifier, which means it is linked to you, and we say so rather than calling it anonymous.
What a record contains:
- What happened and where: for example, “a recipe was shown on the Cookbook list in third position”, “a plan was saved with five nights”, “an import stopped at the parsing step”, “a grocery row was ticked”.
- Identifiers already in your account: recipe and plan identifiers, so a record can be matched back to the thing it describes.
- Numbers, yes/no answers, and times: positions, counts, and a coarse bucket for how long a recipe was open (0, 5, 15, 30, 60 or 120 seconds), never a precise duration.
What a record never contains:
- Anything you typed or that a website wrote. No recipe names, notes, search text, cravings, ingredient lines, grocery lines, web addresses, or error messages.
- Your email, name, contacts, advertising identifier, or device identifiers.
- Your location.
Where a record needs to refer to a word you used, such as a search term, a tag, or a grocery item, it stores a short one-way fingerprint of that word instead of the word itself. A fingerprint of a common word can be guessed by trying common words against it, so we do not describe these as anonymous or irreversible; they exist to keep your words out of the record, not to make the record unidentifiable.
These records are append-only: neither we nor you can edit one after it is written. They are deleted with your account like everything else, and they expire on their own after 180 days.
AI-assisted recipe import
Spuno first tries to read structured recipe data deterministically on your device or server. A complete deterministic result is not sent to an AI model. For photo imports, or when a recipe page does not provide enough structured data, a Google Cloud Function sends the photo (or, for a multi-page recipe, every page you selected, in one request) or the page’s readable text and URL to Anthropic (the maker of Claude) to extract recipe fields. Spuno does not deliberately include your Firebase account identifier, name, or email in that AI request, although a photo you choose could itself contain personal information.
Under Anthropic’s standard commercial API terms, API inputs and outputs are deleted from its backend within 30 days, except where longer retention is required for safety-policy enforcement or by law. Anthropic does not use commercial API inputs or outputs to train its generative models by default. A capped number of imports per day is enforced to control cost; imports happen only after you choose to start one.
Recipe sharing
If you explicitly share a recipe, for example to send it to a friend, Spuno creates a point-in-time snapshot at an unguessable link. Anyone with that link can view the snapshot; it is not otherwise discoverable, is never modified after creation, and carries no reference to your account. Shared snapshots do not currently expire automatically or have an in-app revoke control. Contact us with the share link if you need one removed.
Service providers and technical data
Spuno uses Google Firebase and Google Cloud for authentication, database, file storage, server functions, security attestation, and operational logs. Firebase Authentication can process account identifiers, provider contact information, IP addresses, and user-agent data. Cloud Functions can process the caller’s IP address and invocation metadata. Spuno’s own function logs record bounded timing, result category, and error category; they do not deliberately record recipe content, imported URLs, Firebase account identifiers, photos, or model output.
Optional sign-in uses Google or Apple as selected by you. When Spuno retrieves a recipe page or displays a remotely hosted recipe image, the relevant website receives normal connection information such as your IP address and user agent and applies its own privacy practices.
What we don’t do
Spuno does not run analytics or advertising SDKs, sell personal data, use personal data for targeted advertising, or build user profiles for marketing. It shares data with the service providers described above only to provide and secure features you request.
The usage records described in How you use the app are first-party: they are written by the app into your own account’s area of our database, using the same Google Cloud services that already store your recipes. They are used to improve the app and, in a future version, to personalise your weekly plan. They are not used for advertising, not sold, not shared with an analytics company, and not used to build a marketing profile.
App Check
Spuno uses Apple’s App Attest (via Firebase App Check) to confirm that requests to our backend come from a genuine copy of the app, rather than a script. This is a technical anti-abuse measure, not advertising or marketing. App Check processes an App Attest attestation and short-lived security tokens to establish app and device integrity.
Retention and deletion
- Private recipes, plans, preferences, grocery state, and uploaded recipe photos remain until you delete them through an available in-app control or request account deletion. Any pantry record left over from an earlier version of the app is retained on the same terms and removed on account deletion, even though nothing in the app reads it.
- Deleting a recipe removes its Firestore record. Every app-uploaded photo attached to that recipe is then deleted from Storage by a server cleanup process. Images hosted by recipe websites are controlled by those websites rather than Spuno.
- Usage records (see How you use the app) expire automatically 180 days after they are written, and are deleted immediately when you delete your account.
- Server-only recipe-cache entries expire after 60 days. Anthropic’s API retention is described in AI-assisted recipe import above.
- Public recipe-share snapshots do not currently expire automatically. Contact us with the link to request removal.
- Firebase and other processors may retain limited security, operational, or backup data for a period after deletion under their applicable terms or where required by law.
Your controls
- Deleting your account deletes your usage records along with everything else. There is no separate opt-out control for them today; if you want them removed before then, contact us.
- Delete individual recipes and manage grocery items from within the app. Deleting a recipe also schedules deletion of its app-uploaded photos. Individual photos can be removed from a recipe by editing it.
- New week on the grocery list clears every checkmark and nothing else. Your added items, edited amounts and meal plan are untouched.
- Deleting the app does not delete your data. Your recipes and plans remain stored on our servers. On iPhone, the credential identifying your account is normally retained by iOS even after the app is deleted, so reinstalling usually signs you back into the same account with your data intact.
- Erasing or resetting your device can leave an unlinked anonymous account unreachable. Note what this does and does not mean: you would lose access to the data, but the data itself remains stored on our servers until deletion is requested. Linking Google or Apple avoids this.
Deleting your account
- You can delete your account and all of its data from inside the app. Open the account sheet and choose Delete account and data (or Erase everything and start fresh if you have not linked a Google or Apple account). You will be shown exactly what will be destroyed and asked to confirm; the deletion cannot be undone.
- This applies to guest accounts too. An anonymous session holds real recipes, plans and photos, so it gets the same control. No sign-in is required to erase your data.
- If your account is linked to Google or Apple, you will be asked to sign in with that provider one more time first. This confirms the person holding the phone owns the account being destroyed. Cancelling that prompt, or signing in with a different account, deletes nothing.
- Signing in with Apple: the same prompt is used to revoke Spuno’s access to your Apple ID, so Spuno stops appearing in your Apple ID’s list of apps using Sign in with Apple. If that revocation cannot be completed, the deletion is cancelled rather than partially performed. Nothing is deleted and you can try again.
- What deletion removes: your recipes, your weekly plan, your grocery list and its saved edits, your saved preferences, every photo you uploaded, any public recipe-share snapshots created from your account, any inert records left by earlier versions of the app, and the account itself. Deletion runs in an order that leaves nothing stranded if it is interrupted: if a step fails, nothing further is deleted and running it again completes the job.
- What deletion does not remove: server-only recipe-cache entries, which hold derived recipe fields keyed by web address, contain no account identifier, are shared across all users, and expire on their own after 60 days. They are not attributable to you.
- After deletion, the app signs you out and starts a new, empty guest session on this device.
Requesting deletion instead. If you cannot use the in-app control, because you no longer have the app installed, you have lost access to the account, or the in-app route fails, email support@spuno.app and we will delete the account and its data for you. See Delete your account for the full walkthrough. Please include enough information to identify the account (the email address you signed in with, or the approximate date and device). Because public recipe-share snapshots intentionally contain no account identifier, include any share links you also want removed.
This website
Everything above describes the Spuno app. This website is separate and much simpler: it sets no cookies, runs no analytics, and embeds no third-party tracking.
If you submit your email address to join the beta, we store that address, the page you submitted it from, and the time, in a Supabase Postgres database, so we can send you an invite. To stop the form being abused we also store a one-way hash of your IP address for a short period; the address itself is never written down. Ask us at support@spuno.app to remove your email from that list at any time.
Changes
Spuno is built by PCF Digital LLC, based in Marietta, GA. This policy may be updated as Spuno’s features change, and the date at the top of this page always reflects the latest version. It mirrors the app’s own privacy policy, last revised 18 August 2026, which is also published at pcfdigital.com/spuno/privacy.html. This policy will be reviewed by counsel before public launch. Questions or requests, including access or deletion, go to support@spuno.app.