Last updated: May 17, 2026. This policy describes how Herb (cookwithherb.com) handles personal information today. It is meant to be clear and accurate, not legal advice. I may update it as the site or the law changes.
Who is responsible
Herb is operated at cookwithherb.com. For privacy questions or requests, contact herb@cookwithherb.com.
Quick summary
- Recipe generation needs the ingredients and options you type; that goes to AI providers.
- Product analytics are opt-in. No optional analytics until you accept.
- Sign-in uses a third-party authentication service. Saved recipes may be stored when you persist them.
- Herb does not sell your personal information or share it for cross-site behavioral ads.
- You can turn analytics off anytime via Cookie settings or Privacy settings.
Information I collect
What I collect depends on how you use the site:
- Recipe inputs and outputs: ingredients, cuisine, dietary preferences, time limits, and generated recipe text (and related metadata) when you generate or save recipes.
- Account information (if you sign in): email and profile details from the authentication provider, plus preferences stored on your account (such as analytics consent).
- Usage analytics (only if you opt in): pages visited, features you use, actions you take (such as button clicks), and session replays. Replays are recordings of how you use this site in your browser (for example, which pages you open and where you click), stored by the analytics provider so I can spot confusing flows and fix them.
- Technical data: IP address, browser type, and request logs for security and operations. When analytics are allowed, server-side product events use an event-based identifier, not your IP address.
- Communications: if you email me, I keep what you send so I can respond.
How and why I use it
| Purpose | Examples | Legal basis (GDPR) |
|---|---|---|
| Provide the service | Generate recipes, save recipes, sign you in | Contract / legitimate interests |
| Optional product analytics | Understand which features are used; session replays of site usage | Your consent |
| Security and abuse prevention | Rate limits, protecting APIs | Legitimate interests |
| Support | Reply to your email | Legitimate interests / contract |
Where GDPR applies, you may withdraw consent for analytics at any time without affecting core recipe features.
Cookies and local storage
- Strictly necessary: session cookies from the authentication provider so you can sign in and stay signed in.
- Optional analytics (opt-in only): when you accept analytics, first-party and analytics-provider cookies may be set. When you accept or reject, your choice is also stored on this device (browser local storage).
- Functional (this device): session storage for your current recipe batch so a refresh does not wipe in-progress work. That is separate from analytics.
Manage analytics anytime via Cookie settings in the footer, Privacy settings when signed in, or the cookie banner when shown.
Analytics (optional)
Product analytics do not run unless you turn them on. If you accept analytics in the banner, sign-up checkbox, or Privacy settings, a third-party analytics service may record which features are used (for example, pages visited and actions you take) and may create session replays of your visit on this site. Autocapture is off: I log specific product events, not every click on the page. You can turn analytics off anytime; when off, optional analytics are not initialized in your browser and optional server-side analytics events are not sent.
Recipe generation and images
When you ask for recipes, the ingredients and options you provide (such as cuisine, dietary preferences, and time limits) are sent to third-party AI services to generate recipe text and images. Saved recipes and images may be stored with hosting and database providers when you save or generate them. Turning off analytics does not stop recipe generation. It only controls optional usage analytics.
Third parties who process data
Herb uses service providers that process personal information on our behalf, including:
- Authentication and account services (when you sign in)
- Cloud hosting, networking, and security logging
- Databases and file storage (saved recipes and images)
- AI services for recipe and image generation
- Product analytics (only if you opt in)
A list of current subprocessors is available on request: herb@cookwithherb.com.
Where data is stored
Infrastructure providers are primarily based in the United States. If you access Herb from outside the US, your information may be processed there. I rely on each provider's contractual safeguards (such as standard contractual clauses where applicable) for international transfers.
How long I keep information
- Account data: while your account is active and for a reasonable period after deletion, unless law requires longer retention.
- Saved recipes: until you delete them or delete your account (account deletion is available in your account settings).
- Analytics (if enabled):per the analytics provider's retention settings.
- Server logs: typically on the order of weeks, per hosting defaults.
Backups may retain deleted data for a limited period before rotation.
Your choices and rights
Depending on where you live, you may have the right to:
- Access a copy of your personal information
- Correct inaccurate information
- Delete your information
- Withdraw consent (for analytics)
- Object to or restrict certain processing
- Data portability, where applicable
To exercise these rights, email herb@cookwithherb.com. I will respond within the timeframes required by applicable law (generally within 30 days for GDPR requests and 45 days for California requests). EU/UK users may also complain to their local data protection authority.
Analytics controls: use the cookie banner, Privacy settings, or footer Cookie settings (same opt-out as rejecting analytics).
California residents
California law gives you the right to know what personal information is collected, to request deletion or correction, and to opt out of the sale or sharing of personal information for cross-context behavioral advertising. Herb does not sell your personal information. I do not share it with third parties for cross-context behavioral advertising. Optional product analytics are opt-in; you can opt out anytime using Cookie settings (reject non-essential) or Privacy settings. I will not discriminate against you for exercising these rights.
Children's privacy
Herb is not directed at children under 13, and I do not knowingly collect personal information from children under 13. If you believe a child has provided personal information, email herb@cookwithherb.com and I will delete it.
Security
The site uses HTTPS, access controls on production systems, and standard hosting security practices.
Changes to this policy
I may update this policy when practices or legal requirements change. The date at the top shows the latest revision. Material changes to analytics practices may require a new consent choice (I version consent separately from this page).
Contact
Privacy questions or requests: herb@cookwithherb.com