Privacy Policy
WifeFood is a cooking app. It knows what your family likes to eat because you told it, and it uses that for exactly one thing: answering "what do I cook today?". This page says precisely what is stored, what is only passed through, and who else ever sees it.
The short version
- We keep what the app cooks withโ your preferences, your household's tastes, what you cooked and when, your kitchen and your lists.
- Most photos and all voice notes are not stored. Fridge, pan and meal photos are held for one request and dropped. One clear exception: a linked kitchen helper may attach a receipt to an approved purchase. We remove its location metadata, keep it for 60 days, then delete it.
- We keep your searches. When you search for a cooking video we save what you typed, when, and which dish you were looking at โ so we can see which dishes cooks are asking for and go find good videos for them. It is tied to your account, and it is deleted when your account is.
- No ads, no trackers, no brokers. There is no advertising SDK, no analytics SDK and no third-party tracker anywhere in WifeFood. We have never sold or rented your data and we will not. Some links take you out of WifeFood โ a video on YouTube, a grocery app, WhatsApp โ and those places have their own rules; nothing loads from them until you tap.
- You can take it or end it. In the WifeFood app: Profile โ Delete my account, confirmed with your password, gone at once. On the website, email us and we do it for you. For a copy of your data, write to wifefood.com@gmail.com.
1. What we collect, and why
Everything here is something you typed, tapped or photographed inside WifeFood. There is no hidden collection: we do not read your contacts, your calendar, your other apps or your device's location.
Your account
Your name, email address, and your password stored only as a bcrypt hash โ we cannot read your password and neither can anyone with database access. Also: the language you read the app in, whether you are on the free or premium plan, your referral code and who referred you.
Why:to sign you in, keep your kitchen yours, and run the "give a month, get a month" referral.
An optional phone number, city and country exist on the account record. Nothing in the app asks you for them; they are only ever filled in if you give them to us yourself, for example while we are helping you with a support problem. The country is not worked out from your device โ it starts as India and only changes if someone types something else.
Your cooking preferences
Diet type (veg, non-veg, eggetarian, vegan or Jain), spice level, cuisines you love, ingredients you never want suggested, cooking skill, which meals you cook, any veg-only-days rule, your usual family size, how many days a dish should rest before repeating, your life mode, the language ingredient names appear in, and whether the juices tab is on.
Why:this is the product. Without it every suggestion would be a stranger's suggestion.
Your reminder time and timezone
The hour and minute you want the daily nudge, and your timezone.
Why:so "aaj kya banau?" arrives when you actually decide dinner, not at 3am. Set the reminder to Off and none is ever sent.
Your household
For each person you add: a name or nickname you choose, their relation to you (kid, elder, spouse, self, guest or your own words), an optional diet note in your words ("mild spice", "diabetic-friendly", "no brinjal"), an optional diet for that person (veg, non-veg, eggetarian, vegan or Jain), and for a child either an age band or a birth date.
Why:to cook one meal that works for everyone at the table โ a milder version for a child, no fried food for an elder. The per-person diet is a safety rule, not a taste: if one person at your table is pure-veg or Jain, the shared dish we suggest has to be one they can eat, so that person's diet is applied as a hard filter on everything we offer. Leave it blank and that person simply follows the household diet. See Children and baby food below.
Your cook log
For each meal you log: the dish name, which meal it was, the date, servings, your star rating, your own free-text notes, and any per-dish "cook this again after N days" rest period.
Why: this is the memory that stops WifeFood repeating a dish too soon, and it is what your streak and history are built from.
Your kitchen and lists
What you have in your pantry (item name, category, an optional quantity note), your shopping list, your saved and favourited dishes with any personal notes you added to them, your current weekly meal plan, and the dishes you passed on together with the reason you gave.
Why: to suggest dishes you can actually cook tonight, and to stop offering you things you have already said no to.
Your searches for a cooking video
WifeFood can point you to a video of a dish being cooked. Every one of those searches is saved, and it is attached to your account. One row per search, holding: the words you typed, exactly as you typed them; a tidied-up version of those words, so that "Dal Tadka" and "how to make dal tadka" count as one dish and not two; what kind of dish the screen said it was, if it said anything; which video we showed you, or nothing at all if we had none to give you; the recipe you had open at the time, if you were on one; which screen you searched from; the language you read the app in; and the time.
Why: so we can see which dishes cooks actually want to watch. The searches we could not answer are the most useful list we have โ they are literally the queue we work through when deciding which video to find and add next. That is the whole purpose. It is not used to advertise to you, not used to build a profile of you, and never shared.
Two limits worth knowing. Baby-food searches are never recorded โ we refuse those before anything is written down, because we do not put outside videos in front of a parent feeding an infant. And we only record the first several searches you make in a day; after that you can keep searching, we simply stop writing rows.
It is kept while your account is open and deleted with your account. See How long we keep things.
Push notification tokens
One record per device: the push token Apple or Expo issued for that device, the platform, the app version it last reported, and when it was last seen.
Why: a push token is the only way to deliver the daily reminder. The app version tells us when it is safe to retire an old build. If you never allow notifications, no token is ever created.
Partner and family links
If you share your kitchen: the read-only companion link token, the partner invite token, your link to a partner account, and any requests a partner sends you (a dish they are hoping for, or a note that they are not home for dinner on a given day).
Why:so your family can see the week's menu and the grocery list, and so a partner can ask for a dish without being able to change your kitchen.
Technical logs
Every AI call writes a usage row: which feature ran, which model, how many tokens, an estimated cost, and your account id. If a request fails, an error row records the route, the status, the error message, the stack trace and your account id.
Why: the usage rows are how we watch our own OpenAI bill and keep the daily answer free. The error rows are how a crash you hit actually gets fixed. Neither contains your photos, your voice or your recipes. These are not the only rows that carry your account id โ your video searches do too, and they are described a few cards above.
2. Photos, voice notes and what you type
These are the most personal things WifeFood touches, so their storage rule is stated for each feature rather than hidden behind one general promise.
- Photos โ a photo of your fridge, your pantry shelf, a finished dish, or a pan you want checked for doneness. The image is held in server memory for the length of that one request, screened for anything that should not be processed, sent to OpenAI to be read, and then dropped. These photos are not stored. What survives is only the text result โ the dish name that lands in your cook log, or the ingredient names that land in your kitchen.
- Receipt photos are the exception. A linked staff helper can add one only after the household approved a request to buy an item. The server checks the real image bytes, rejects anything over 4 MB, turns the image into a smaller WebP, and removes EXIF metadata including GPS before saving it. The same helper and either linked household adult can view it through an authenticated request. It is deleted after 60 days. If the helper leaves or deletes the account, access ends but the household's temporary purchase record remains until expiry; if the household owner deletes the account, the receipt is deleted immediately. Receipt photos are stored on WifeFood's DigitalOcean server and are not backed up, so they should not be treated as a permanent copy.
- Voice notesโ the recording goes straight to OpenAI's transcription model and comes back as text, which is used to answer you. The audio file is not saved, and neither is the transcript.
- Chats and typed asksโ we do not keep a transcript of your conversations with WifeFood. There is one exception, and it is worth reading: when a question is general enough to be useful to anyone (it is never a baby-food question, and never a "show me something else" retry), the words of the question and the dishes we answered with are stored so the next cook who asks the same thing gets an instant answer. We only ever reuse a stored answer for 30 days; after that it is never served again, though the row itself stays in the database. That row has no account, name or device attached to it and cannot be traced back to you โ which is also why deleting your account does not remove it, there being nothing in it that points at you. It is still your sentence, so please do not type anything private into the ask box.
- If an uploaded image is blocked by our image screening, we record that it happened โ your account id, the time, and the category it was flagged under โ so repeat abuse can be acted on. The image itself is not kept.
- Reports you file โ when you report content, we keep what you reported, the reason you chose, anything you wrote, and a link to your account, so a moderator can act on it and come back to you. Your email address is not copied into the report itself; it is read through that link, which is why deleting your account takes the address with it. Reports are never shown to the person you reported.
3. Children and baby food
WifeFood is built for the adult who cooks. It is not directed at children, we do not knowingly allow anyone under 13 to create an account, and a child never uses WifeFood on their own.
The only information about a child in WifeFood is what a parent or guardian chooses to type about their own child, so that the app can suggest food that is right for that stage:
- a name or nickname the parent picks โ it does not have to be a real name;
- the relation "kid", and any diet note the parent writes;
- optionally, that child's diet โ veg, non-veg, eggetarian, vegan or Jain โ if the parent sets one. It is used for one thing: making sure the dish suggested for the whole family is one that child can eat. It is not required, and left blank the child simply follows the household diet.
- either an age band (6โ8 months, 9โ12 months, 1โ2 years, 2โ5 years) or a birth date. A birth date is used for one purpose only: working out which age band the child is in today, so the band moves up on its own as the baby grows and the parent never has to remember to edit it.
That information is used to shape recipes and safety rules โ under one year old, for example, the app refuses to suggest honey, added salt or added sugar. It is sent to OpenAI only as cooking context in the shape of "child, 9โ12 months". It is never used for advertising, never used to build a profile, and never shared with anyone else. A parent can edit or delete a household member at any time in the app, and deleting the member deletes that information.
Baby-food suggestions are general guidance for healthy, full-term babies, not medical advice. Every baby-food screen carries that warning, and your paediatrician always outranks the app.
4. Who else sees your data
Three outside services ever receive your data, and they are the three below. Separately, WifeFood sometimes offers you a link out to somewhere else โ a video, a grocery app, WhatsApp. Those are not services we send your data to; they are doors you choose to walk through, and the last card in this section explains exactly what happens when you do.
OpenAI โ the AI behind the suggestions
OpenAI receives what it needs to answer you: the photos you upload, the voice audio you record, the words you type, and the cooking context for that request โ your diet, spice level, cuisines, avoided ingredients, family size, life mode, what is in your kitchen, what you cooked recently, and household notes such as "child, 9โ12 months".
OpenAI does not receive your name, your email address, your phone number or your password. Under the OpenAI API terms WifeFood uses, your content is not used to train OpenAI's models; OpenAI may hold it for a short period (currently up to 30 days) for abuse monitoring and then deletes it. OpenAI also runs the automatic screening that blocks unsafe images and unsafe submitted recipes.
Apple and Expo โ push notifications
To deliver a reminder we send the device's push token and the notification's title and body to Apple's Push Notification service, or to Expo's push service for devices registered through Expo. They carry the message; they do not receive your kitchen, your recipes or your household.
DigitalOcean โ hosting
The WifeFood server and its Postgres database run on a DigitalOcean server we operate. DigitalOcean provides the machine; nobody at DigitalOcean is given access to your data.
Links that take you out of WifeFood
Three places in the app hand you a link to somewhere else. In every one of them, nothing happens until you tap, we send nothing on your behalf, and the moment you arrive you are on their service under their rules, not ours.
YouTube, for a video of a dish being cooked. WifeFood does not embed a YouTube player, does not run any Google code, and loads nothing from Google while you are in WifeFood. Tapping the link opens YouTubeโ the app on your phone, or youtube.com in your browser โ with your search or the video we picked. From that point you are on Google's service, governed by Google's privacy policy, and what you watch there is between you and Google. We do not get it back and we cannot see it. What we do keep is our own note that you searched โ see Your searches for a cooking video above.
Grocery apps, from your shopping list. The buttons beside your list open a search on Blinkit, Zepto or BigBasket for an item you are missing. The item name travels inside the link you tapped โ that is how a search link works โ and nothing else about you goes with it: no account, no email, no list. Those companies then have you as their own visitor under their own policies. We are not paid for these links today; if that ever changes, this page says so before it does.
WhatsApp, when you share. Sharing your menu, your grocery list or a family link opens WhatsApp with the message written out, ready for you to choose who to send it to. WifeFood never sends it and never sees who you sent it to.
5. What we never do
- We do not sell, rent or trade your data. Not to advertisers, not to data brokers, not to anyone.
- There is no advertising network, no analytics SDK, no tracking pixel and no third-party tracker anywhere in WifeFood โ not on the website, not in the app. No embedded video player, no social buttons, no outside fonts, no outside scripts. While you are on a WifeFood screen, your device is talking to us and to nobody else.
- We do not hand anyone a way to follow you. When you tap a link out to YouTube, a grocery app or WhatsApp, we do not attach an identifier, a referral tag or anything about you to it โ and we get nothing back about what you did there. What that other company then does is theirs, which is why we name them in Who else sees your data rather than leaving you to find out.
- We do not track your location. WifeFood never asks your device for it.
- We do not read your contacts, photo library, calendar, messages or microphone in the background. A photo or a voice note reaches us only when you deliberately take or record one.
- We do not use your data to build advertising profiles, and we do not share it across companies for that purpose.
7. How long we keep things
- Your kitchen data โ preferences, household, cook log, pantry, lists, saved dishes โ is kept for as long as your account is open, because the whole point is that WifeFood remembers. It goes when the account goes.
- Fridge, pan and meal photos, and voice recordings โ not stored. Gone at the end of the request that used them. Approved-purchase receipt photos are stripped of metadata and deleted after 60 days (or immediately when the household owner deletes the account).
- Your video searches โ kept for as long as your account is open, and deleted with it. We do not want a permanent record of what you looked up, so we are adding an automatic clear-out that removes search rows older than 90 days; until that is switched on they stay for the life of the account, and this page will say so plainly when it changes. Deleting your account removes them either way, immediately, and does not wait for any clear-out.
- Anonymous cached questions โ reused for up to 30 days, then never served again. The row itself is kept; it carries no account, name or device, so there is nothing in it to tie back to a person.
- Push tokens โ kept while the device is registered. A token is removed when you delete your account, when Apple tells us the token is dead (the app was deleted, the phone was wiped), and when we clear out tokens that have not checked in for a long time. To be exact: signing out does not remove the tokenโ set the daily reminder to Off, or turn notifications off for WifeFood in your phone's settings, if you want the reminders to stop.
- AI usage and error logs โ kept while we need them for cost control and debugging. While your account is open these rows carry your account id, never your name or email. When you delete the account, that id is stripped out of every one of them โ see Deleting your account.
- Content reports โ kept after they are dealt with, not only while they are open, so a moderator sees a repeat pattern instead of starting from zero each time. Deleting your account leaves the report standing but unlinks it from you.
- Blocked-upload records โ the most recent 100 uploads refused by image screening, each holding the account id and the category it was flagged under. These keep the account id even after the account is deleted; otherwise deleting and signing up again would wipe the pattern.
- Records of admin actions โ if someone on the WifeFood team acts on an account (a support fix, a suspension, a deletion), that action is written to an internal audit log that is never deleted. It records what was done, the id of the admin who did it, and the account id it was done to โ never your recipes, photos or notes. This exists so account changes can always be traced.
8. Getting a copy of your data
Tap Download my data โ in Profile in the app, in Settings on the website โ and you get a plain, readable report: your account details, your preferences, your dishes, your full cook log, your pantry and every dish you passed on. It is free for everyone, on any plan: a copy of your own data is not something we charge for.
That file is not everything we hold. It is the part of your kitchen you are most likely to want back, and it leaves out your household members, your meal plan, your shopping list, your partner and companion links, your push tokens and your video searches. If you want a copy of all of it, email wifefood.com@gmail.com from the address on your account and say so โ we will put the rest together by hand and send it, free, within 30 days.
9. Deleting your account
In the WifeFood app, you do it yourself: Profile โ Delete my account. You type your account password to confirm โ a tap alone must never be able to do this โ and the account is deleted immediately. No waiting period, no email to click, no reason to give, and nobody to ask. It cannot be undone, so the password screen is the last point at which you can change your mind.
On the website there is no such button yet. We are being straight about that rather than pointing you at a screen that does not exist: if you use WifeFood in a browser, email wifefood.com@gmail.com from the address you signed up with, and we delete the account within 7 days and confirm by email. The same applies if you are locked out of the app. The button is coming to the website, and this page will change the day it does.
Deleting the account removes, permanently and together: your profile and password, your preferences and life mode, every household member you added (including any child age band, birth date or per-person diet), your entire cook log with its notes and ratings, your saved dishes and personal notes, your pantry, your shopping list, your meal plan, every dish you passed on and every dish you planned anyway, the record of suggestions we made you, every video search you ever made, every push token, your companion and partner invite links, your link to any partner account, every partner request sent to or from you, and every receipt photo owned by your household. None of it is recoverable afterwards.
A few things outlive the account, and you should know exactly which:
- Recipes you published into the shared WifeFood library stay in the library, unlinked from you โ your account is no longer named as their author. If you want them taken down as well, email wifefood.com@gmail.com before you delete: once the account is gone nothing connects those recipes to you, so we can no longer tell which ones were yours.
- The internal AI-usage and error rows stay, because our cost and crash figures are built from them โ but your account id is stripped out of each one as part of the deletion, so they are no longer attached to a person.
- If someone on the WifeFood team ever acted on your account, the admin audit row for that action is never deleted and keeps the account id it acted on. It holds none of your content, and it is what makes an account change traceable afterwards.
- A content report you filed stays in the moderation queue, because the content you reported still has to be reviewed โ but it is unlinked from you: your account id is removed from it, and your email was never stored on it in the first place.
- A record that an upload of yours was blocked by image screening does keep the account id, so a repeat pattern survives someone deleting and signing up again. The image itself was never stored.
- Anonymous cached asks are untouched, because there is nothing in them pointing at you to remove โ see Photos, voice notes and what you type.
11. Keeping it safe
- Passwords are stored only as bcrypt hashes. Nobody โ including us โ can read your password.
- All traffic between the app, the website and the server is encrypted with HTTPS.
- Session tokens are signed and revocable; changing your password signs out every other device.
- Access to the server and database is limited to the people who run WifeFood.
No system is perfect. If we ever discover a breach that affects your data, we will tell affected cooks by email and say plainly what happened.
12. Where your data is handled
The WifeFood server and database run on DigitalOcean infrastructure. OpenAI processes requests on its own infrastructure, primarily in the United States. So if you are cooking in India, the words you type and the photos you take are read on servers outside India before the answer comes back to you.
13. Your choices
- Change or clear any preference, at any time, in Profile โ Settings on the website.
- Remove a household member, and the information about them goes with the row.
- Set the daily reminder to Offin the WifeFood app, or turn off notifications for WifeFood in your phone's settings. Reminders only ever go to a phone, so if you use WifeFood in a browser there is nothing being sent to switch off โ and the website has no reminder screen for that reason.
- Delete individual cook-log entries and dishes you passed on.
- Turn off the companion link, or remove a partner, and the access ends immediately.
- Simply not use the camera or the microphone โ every other part of WifeFood works without them.
- Simply not search for a video. Nothing is written down about a search you did not make, and every other part of WifeFood works without it.
- Delete the whole account yourself in the app, from Profile โ Delete my account โ password, then gone. From the website, email wifefood.com@gmail.com and we do it for you.
- Ask for a copy of your data at wifefood.com@gmail.com.
14. Changes to this policy
If what we collect or who we share it with changes, this page changes in the same release and the "last updated" date at the top moves. For a change that meaningfully affects you, we will also tell you in the app or by email rather than quietly editing the page.
15. Contact
Questions about anything here, or a request about your own data, goes to one place: wifefood.com@gmail.com. A person reads it. See also our Terms of Use and the Support page.
WifeFood is operated by Jodi Studio, the data controller for everything described on this page.
Jodi Studio148, 2nd Main Rd, 2 Block, Annapoorneshwari Nagar
Nagarbhavi, Bengaluru, Karnataka 560091, India