Privacy

PrepSheet can cost recipes without an account. Recipes and pack prices stay in this browser unless you choose to sign in and save a cloud copy.

Optional account

If you request a sign-in link, PrepSheet stores your email address, sign-in timestamps, a salted IP hash used for abuse control, and the recipe book you save. The link is stored as a hash, expires after 20 minutes and works once. A sign-in session lasts up to 90 days. A short user-agent string is stored with the sign-in link and session; expired link records are swept on later link requests, and expired sessions are removed when used or when a new session is created. PrepSheet records account activity such as link requests and sends, throttling, sign-ins, recipe-book syncs, sign-outs and failed links for service metrics and abuse prevention. These events include a timestamp and, where available, the account ID and salted email and IP hashes. Unlinked sign-in activity becomes eligible for removal after 30 days and is pruned in batches of up to 500 as later account activity is recorded.

Deletion and retention

Use Delete account or the public account deletion page to remove the account, cloud recipe book, sessions, unused sign-in links, scan balance, invoice review data and account-linked scan history. Payment reconciliation rows for scan packs remain detached from the account; they contain pack, amount, payment status and Stripe identifiers, but not your email, invoice image or extracted invoice text. Account-linked activity events are deleted; one deletion count event remains without your account ID, email hash or IP hash. Unlinked sign-in activity older than 30 days is pruned in bounded batches as later account activity is recorded. Local browser data is left on your device and can be cleared there. Hosting and email providers may retain their own operational records under their policies.

App measurement and service providers

App screens do not use the website page-view counter or Pinterest Tag. Resend receives your email address and sign-in message to deliver the link; its service may also process delivery metadata for its own operations, security and service improvement under its privacy policy. The SMTP connection is encrypted, and the service runs on a Fasthosts VPS. Caddy HTTP access logging is disabled on the service. The VPS stores application and proxy output through Docker's json-file log driver; no log rotation limit is configured, so the service operator manages cleanup. Fasthosts may process infrastructure data under its own policies.

Payments

This app version does not offer subscriptions or in-app purchases. Recipe costing, scaling and exports are available without payment. The website's separate sales and payment providers are not part of this app flow.

Who is responsible

The controller for the data described here is Michael Price Robinson, trading as PrepSheet, a sole trader based in the UK. Postal address: Lytchett House, 13 Freeland Park, Wareham Road, Poole, Dorset, BH16 6FA, United Kingdom. Email: pacman@getprepsheet.com, which is the fastest way to reach us about your data. The same details are under Who we are on the terms page.

Contact

For a privacy request, email pacman@getprepsheet.com. You can also complain to the UK Information Commissioner's Office at ico.org.uk.