Trust
Security & privacy
This page is maintained by the FridgeCuisine team to answer common security and privacy questions about the app. It describes controls we have enabled today. It is not an independent certification or audit report.
Accounts & sign-in
- Email + password with strength enforcement, or Google sign-in.
- Password reset via time-limited email link.
- Optional "Remember me" — when unchecked, your session ends when the browser closes.
- Session tokens are stored in your browser and rotated automatically.
Data we hold
- Your account (email, sign-in method) and profile you set.
- Your saved recipes, pantry items, meal plans, and dietary preferences.
- Anonymised usage counts for rate-limiting AI generations.
- Payment metadata for purchases (charges are handled by Stripe — we never see your card number).
How data is protected
- All traffic to the app is served over HTTPS.
- Row-level security on our database restricts each user to their own rows.
- Administrative access to the backend is restricted and audited.
- Secrets and API keys are held server-side and never shipped to the browser.
Payments & payouts
- Purchases, subscriptions, and chef payouts are processed by Stripe.
- FridgeCuisine does not store card numbers, CVCs, or bank credentials.
- Chef payouts follow Stripe Connect's identity and payout rules.
Your rights & controls
- Export or delete your account and data from Account.
- Manage cookie preferences from the banner or the footer.
- Withdraw AI personalisation from Preferences.
Report a security issue
If you believe you've found a security issue, please email support@fridgecuisine.com with steps to reproduce. We'll acknowledge within 3 business days.
Shared responsibility: FridgeCuisine operates the app and its platform controls. You are responsible for the strength of your password, the security of the device you sign in from, and what you choose to share publicly (e.g. recipes you publish or sell). See our Privacy policy and Terms for the full agreement.
