Last updated: September 21, 2026
CardAppetit (“the app,” “we,” “us”) is a mobile app that lets you photograph physical recipe cards and digitizes them using AI so you can browse, search, and organize your recipes. This policy explains what information the app collects, how it’s used, and your choices.
Information We Collect
Account information
When you sign in with Google, we receive your name, email address, and a unique account identifier from Google, via Firebase Authentication. We use this solely to identify your account and associate your recipes with you.
Photos you take
When you scan a recipe card, the app captures a photo of it (front and, optionally, back) using your device’s camera. These photos are uploaded to our backend, compressed, and:
Sent to Anthropic’s Claude AI service to extract the recipe’s name, ingredients, instructions, and other details from the image.
Stored (the compressed images) in our cloud storage, so the photo remains attached to your saved recipe for you to view later.
Recipe and shopping list data
The recipe details extracted from your scans (name, ingredients, instructions, servings, prep time, an AI-suggested cuisine tag, and whether you’ve marked a recipe as a favorite), along with any shopping list items you add, are stored in our database and linked to your account.
Usage information
We track your scan balance — a one-time allowance from your free trial, plus any scan packs you purchase — so the app can show how many scans you have left and enforce that balance.
Purchase history
If you buy a scan pack, purchases are handled entirely by Google Play Billing — we never see or store your payment card details. Google provides us a purchase token and the product purchased, which we use to verify the purchase and credit your account with the scans you paid for.
Notification token
When you sign in, the app registers a device token with Firebase Cloud Messaging and stores it with your account, so we can send notifications about the app to your device. You can turn notifications off at any time in your device’s settings.
Crash and error reports
If the app crashes or encounters an unexpected error, we automatically collect diagnostic information — such as device model, OS version, and a stack trace describing the error — via Firebase Crashlytics (on your device) and Sentry (on our backend server). This is used solely to identify and fix bugs, and is not linked to your recipe content.
We do not use any advertising or analytics tracking SDKs in this app, and we do not collect location data.
How We Use Your Information
To provide the app’s core functionality: extracting, storing, and displaying your recipes and shopping list.
To authenticate you and keep your data private to your account.
To enforce your scan balance.
To identify and fix bugs and crashes.
We do not sell your information, and we do not use your recipe photos or data for any purpose beyond providing the app’s features to you.
Third Parties We Share Data With
We use the following third-party services to operate the app. Each processes data on our behalf, under their own privacy and security practices:
Google Firebase — authentication (Google Sign-In), push notifications (Firebase Cloud Messaging), and, via Firebase Crashlytics, crash/diagnostic reporting from the app on your device. See Firebase’s Privacy and Security page.
Anthropic — processes recipe card photos to extract structured recipe data. See Anthropic’s Privacy Policy.
Supabase — hosts our database and image storage.
Google Cloud Platform — hosts our backend server.
Sentry — receives error reports from our backend server when something goes wrong, to help us diagnose and fix bugs. See Sentry’s Privacy Policy.
Google Play Billing — processes scan pack purchases. We receive a purchase token and product ID to verify and credit your purchase; Google handles your payment details directly. See Google’s Privacy Policy.
Data Retention and Deletion
Your recipes and shopping list items are retained until you delete them. You can delete individual recipes and shopping list items directly in the app at any time.
To request deletion of your entire account and all associated data, email us at cardappetit@larwal.dev. We will delete your account data within a reasonable time of receiving your request.
Data Security
Data is encrypted in transit (HTTPS) between the app and our servers. Access to stored data is restricted to what’s necessary to operate the app.
Children’s Privacy
CardAppetit is not directed at children under 13, and we do not knowingly collect information from children under 13.
Changes to This Policy
If this policy changes, we’ll update the “Last updated” date above. If changes are material, we’ll make reasonable efforts to notify users through the app.
Contact
Questions about this policy or your data can be sent to cardappetit@larwal.dev.
Keep the recipes worth remembering.
Built for Android