Privacy Policy
Last updated: September 22, 2026
This policy describes how Recall Kitchen, LLC, an Iowa limited liability company (“Recall Kitchen,” “we,” “us”), handles personal information when you use recallkitchen.com, the app at app.recallkitchen.com, and our API and MCP. The product is built for people in the United States. Contact: [email protected].
Information we collect
- Account. Email address, name, and profile details from sign-in (Auth0) or from the MCP
signuptool. We store whether the email is verified, your roles, and when the account was created. - Watch patterns and settings. Keywords, brands, products, severity, and places you ask us to watch, and your notification preferences.
- Inventory. Product name, brand, category, and SKU or UPC you add.
- Scan photos. Package, label, or receipt photos you upload in the app or send to image-search endpoints. We store a recompressed copy. GPS and similar metadata are stripped.
- Barcode camera. The decoded UPC or EAN digits. Detection runs in your browser. Camera frames from that mode are not uploaded.
- API keys. A label, a short prefix, a hash of the secret, created and last-used times, and usage counts. The full secret is shown once and is not stored in a form we can display again.
- x402 payments. If you pay anonymously with x402, we store a deposit address so we can recognize that payer. We do not take card numbers. Payments are USDC on Base, not a card charge.
- Support and acceptance. Messages you send us, and the time and policy version when you accept the Terms and confirm you are at least 13.
- Technical data. IP address, browser and device type, pages or API methods requested, and timestamps, in server logs and operational telemetry. Cookies are described in the Cookie Policy.
How we use information
- Provide the Services: search, matching, alerts, inventory, Scan, and developer access
- Identify products in photos you submit and search indexed notices
- By default, improve barcode and product detection using uploaded Scan photos and corrections you make
- Authenticate you (Auth0), enforce quotas, and secure the Services
- Send transactional recall alerts and reply to support requests
- Record that you accepted the Terms and confirmed your age
- Settle x402 payments and prevent abuse of the free quota
- Debug outages and understand aggregate use
- Comply with law and enforce our Terms
We do not use your information for third-party advertising. We do not sell, rent, or trade personal information.
Scan photos and detection
When you upload a photo on Scan, or send an image to our API or MCP image tools, we store a recompressed copy on the account (or, for a paid anonymous image search, with that request) so the product can be identified and so you can look an upload up later. GPS and similar metadata are stripped.
By default we use those photos, and corrections you make, to improve barcode and product detection. That is a product feature, not a sale of your photos. To opt out, or to ask us to delete stored photos, email [email protected]. There is no settings toggle yet. Email is the opt-out and the deletion path.
The in-app barcode camera reads codes locally. Those frames and stills are not uploaded.
You can delete a scan in the app. Choose the photo, the saved details (product names, matches, and corrections), or both. A deleted photo is removed from your account and is no longer used to improve detection. Products already in your inventory stay until you remove them. Email [email protected] to opt out of detection improvement, or to request a partial or full deletion of your account.
How we share information
We do not sell, rent, or trade personal information. We share it in these cases:
- Processors who help us run the Services, under instructions from us:
- Auth0 — sign-in
- SendGrid — email delivery
- Cloudflare — security and content delivery
- DigitalOcean — hosting, database, and object storage for Scan photos
- Honeycomb — operational traces, when that logging is enabled
- Legal. If we believe disclosure is required by law, legal process, or to protect the rights, safety, and security of Recall Kitchen, our users, or others.
- Business transfer. If we merge, sell, or transfer the business, subject to this policy or a successor policy with notice.
- With your direction. For example, a public share page you choose to publish shows the recall notice, not your account.
Recall notices themselves are public records and retailer postings. Publishing a share link does not attach your identity to the notice.
How long we keep it
We keep account information, watch patterns, inventory, notification history, API key records, and stored Scan photos for as long as the account is open. We do not run an automatic deletion schedule. Usage counters are kept so we can enforce hourly and daily quotas.
When you email us to delete the account or specific photos, we delete them from the production database and from object storage. We do not use host backups to serve the product. Our database host may keep backups for its own backup window after a deletion. We do not promise a specific number of backup days, because that window is the host’s and can change. Server logs and telemetry age out on the logging provider’s schedule.
Revoked API keys stay in our records marked revoked so a leaked secret cannot be reused. The secret itself remains only as a hash.
Deleting a scan in the app removes that photo from production storage when you choose to delete the photo. There is no self-serve export or self-serve account deletion yet. Email [email protected] to request a copy, a correction, or deletion of the account.
Your choices and rights
- Access and correct account details by signing in, or by emailing us
- Change or delete watch patterns, inventory, and notification settings in the app
- Delete a scan’s photo, its saved details, or both from the scan page
- Request an export of your data, or a partial or full deletion of the account, by email
- Opt out of using Scan photos to improve detection by email
- Stop alert email by changing Settings or asking us to close the account
- Control cookies in your browser (see the Cookie Policy)
Children
The Services are not for children under 13. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has given us personal information, email [email protected] and we will delete it and close the account.
International users
We are based in Iowa, United States, and we operate the Services from the United States. If you use the Services from somewhere else, you understand that your information will be processed in the United States, where privacy laws may differ from yours. The product is aimed at people in the United States.
Notice at collection
We collect the categories listed above to provide the Services, secure them, and, by default, improve detection from photos you upload. We do not sell personal information, and we do not share it for cross-context behavioral advertising. We do not offer a “Do Not Sell or Share” toggle because we do not sell or share personal information that way. To ask us to delete personal information, email [email protected]. We will not discriminate against you for making a request. If a privacy law gives you additional rights and applies to us, email us and we will honor the rights that apply.
Changes
We may update this policy. We will post the new text here and change the “Last updated” date. If a change is material, we will also give notice in the app or by email. The Terms describe when we ask you to accept again.
Contact
Recall Kitchen, LLC
Iowa, United States
[email protected]
Related: Terms of Service · Cookie Policy · API Terms · Acceptable Use Policy
