Legal information
Privacy Policy
This notice explains what data Memotaste uses, why it uses it, and the choices and rights that remain under your control.
Last updated: 18 August 2026
1. Controller and contact
The controller for the Service at memotaste.com is Saverio Mazza, operator of Memotaste. For privacy requests, contact [email protected]. This notice covers the website, installable PWA and connected features.
2. Data, purposes and legal bases
| Data | Why we use it | Legal basis |
|---|---|---|
| Name, email, profile image, account ID, sessions and encrypted credentials or provider tokens | Registration, sign-in, synchronisation and security | Contract; legitimate security interests |
| Recipes, images, meal plans, preferences, notes and operation history | Provide the features you request and store your cookbook | Contract |
| URLs, text, photos, audio and transcripts submitted for import or assisted editing | Extract, translate, adapt or organise a recipe at your request | Contract |
| IP address, user agent, logs, errors and anti-abuse signals | Operation, diagnosis, limits, fraud and abuse prevention | Legitimate interests; legal obligation where applicable |
| Feedback, contact email and attached screenshots | Reply to you and fix reported issues | Your request; legitimate interests |
| Newsletter and communication choices | Essential service messages and optional updates | Contract for essential messages; consent for optional ones |
Optional data is not required, but some features cannot work without the information needed for an account or recipe. We do not make solely automated decisions that produce legal or similarly significant effects.
Dietary and health-related information
Allergies, intolerances and dietary notes are optional and may reveal health data. We use them only to personalise the Service with your explicit consent under Article 9(2)(a) GDPR. You can withdraw consent by removing those details; this does not affect earlier lawful processing.
3. AI features and submitted content
When you ask us to import, transcribe, translate, generate or edit a recipe, the necessary URL, text, image, audio or recipe fields may be sent to contracted AI and infrastructure providers. Processing starts only after your action and is used to return the requested result, enforce limits and protect the Service. Do not submit unnecessary personal or confidential information in recipes, voice notes or feedback.
4. Sharing, Discover and public pages
Your cookbook is private by default. Creating a share link makes that recipe available to anyone with the link, but does not automatically list it in Discover or search engines. Publishing an eligible original recipe is a separate choice. Public source cards created from external URLs are attributed to the external source and do not expose who saved them.
5. Service providers and international transfers
We use providers for hosting and databases, authentication, email, object storage, error monitoring, optional analytics and AI processing. They act under contractual restrictions and receive only data needed for their task. Some may process data outside the EEA. Where required, transfers rely on adequacy decisions, EU Standard Contractual Clauses or another lawful safeguard. Contact us for the current provider list and applicable safeguards.
6. Cookies, local storage and analytics
Essential cookies and local storage keep sessions secure, remember language and consent choices, support offline use and prevent abuse. They are necessary to provide the Service. Optional product analytics start only after consent. You can change that choice from the Privacy settings in the app; withdrawal does not affect earlier lawful processing.
7. Retention, export and deletion
Account and cookbook data are kept while your account is active. Shorter operational periods apply to logs, temporary uploads and processing artefacts; legal, security or dispute records may be kept for the period required by law. You can delete individual recipes or permanently delete the account from Profile. Backup copies are removed on normal rotation unless law requires longer retention.
8. Your GDPR rights
Depending on the circumstances, you may request access, correction, deletion, restriction, objection and portability, and withdraw consent at any time. You may also complain to your local supervisory authority; in Italy this is the Garante per la protezione dei dati personali. Send requests to [email protected]. We may need to verify your identity and normally respond within one month.
9. Security and children
We use access controls, encryption in transit, managed infrastructure, monitoring and limited provider access. No online system is perfectly secure, so use a unique password and report suspicious activity. The Service is not intended for children under 14, and we do not knowingly collect their data. A parent or guardian can contact us to request removal.
10. Changes, contact and complaints
We update this notice when the Service, providers or law changes. We will give reasonable notice of material changes where practical. For questions or complaints, email [email protected]. You retain the right to contact your data protection authority at any time.