Legal information
Privacy Policy
This notice explains what data Memotaste uses, why it uses it, and the choices and rights that remain under your control.
Last updated: 1 October 2026
1. Controller and contact
The controller for the Service at memotaste.com is Saverio Mazza, operator of Memotaste. For privacy requests, contact [email protected]. This notice covers the website, installable PWA and connected features.
2. Data, purposes and legal bases
| Data | Why we use it | Legal basis |
|---|---|---|
| Name, email, profile image, account ID, sessions and encrypted credentials or provider tokens | Registration, sign-in, synchronisation and security | Contract; legitimate security interests |
| Recipes, images, meal plans, preferences, notes and operation history | Provide the features you request and store your cookbook | Contract |
| URLs, text, photos, audio and transcripts submitted for import or assisted editing | Extract, translate, adapt or organise a recipe at your request | Contract |
| IP address, user agent, logs, errors and anti-abuse signals | Operation, diagnosis, limits, fraud and abuse prevention | Legitimate interests; legal obligation where applicable |
| Essential usage events, including sign-up, import previews and their aggregate outcome, imports, planning, saves and sharing; internal account identifier when available | Measure feature reliability and adoption and improve the Service | Legitimate interests |
| Short category for the first source | Understand which journeys introduce people to the Service | Consent |
| Feedback, rating, optional publication consent, contact email and attached screenshots; if you choose Telegram, Telegram identifiers and the messages, voice notes or images sent to the support chat | Reply to you, fix reported issues and, only when authorised and approved, publish the review on the website | Your request; legitimate interests; consent for publication |
| Newsletter and communication choices | Essential service messages and optional updates | Contract for essential messages; consent for optional ones |
Optional data is not required, but some features cannot work without the information needed for an account or recipe. We do not make solely automated decisions that produce legal or similarly significant effects.
Dietary and health-related information
Allergies, intolerances and dietary notes are optional and may reveal health data. We use them only to personalise the Service with your explicit consent under Article 9(2)(a) GDPR. You can withdraw consent by removing those details; this does not affect earlier lawful processing.
3. AI features and submitted content
When you ask us to import, transcribe, translate, generate or edit a recipe, the necessary URL, text, image, audio or recipe fields may be sent to contracted AI and infrastructure providers. Processing starts only after your action and is used to return the requested result, enforce limits and protect the Service. Do not submit unnecessary personal or confidential information in recipes, voice notes or feedback.
4. Sharing, Discover and public pages
Your cookbook is private by default. Creating a share link makes that recipe available to anyone with the link, but does not automatically list it in Discover or search engines. Publishing an eligible original recipe is a separate choice. Public source cards created from external URLs are attributed to the external source and do not expose who saved them.
5. Service providers and international transfers
We use providers for hosting and databases, authentication, email, object storage, error monitoring, optional analytics and AI processing. They act under contractual restrictions and receive only data needed for their task. Some may process data outside the EEA. Where required, transfers rely on adequacy decisions, EU Standard Contractual Clauses or another lawful safeguard. Contact us for the current provider list and applicable safeguards.
We use email and Telegram for operational notifications to the service operator about registrations, payments and technical errors. Registration notifications include name, email, registration time, initial language and sign-up method when available. First-touch source, campaign and entry page are included only when already collected with analytics consent. These notifications do not collect your IP address or precise location.
You can also choose to continue a support conversation in the Telegram bot. The deep link carries a short-lived opaque token and does not put your email address or other personal details in the URL. Telegram then processes the chat under its own terms and privacy policy.
Feedback may include language, web release, browser or standalone mode and the technical reference for the latest import. We do not automatically attach source links, recipe text or access tokens. This context accompanies the report delivered to the operator by email and Telegram.
To recover interrupted work, text and editing drafts are stored in this tab, separately for each account and household, and can be restored for 24 hours. They are removed after saving, discarding or reading an expired draft; closing the tab normally clears this storage. Photos not yet uploaded are not retained. Link import attempts and extracted recipes awaiting a save can be recovered on the server for one hour, then removed by periodic cleanup. Recovery serves the requested feature, not analytics.
6. Cookies, local storage and analytics
If you choose to continue from the video tool to your recipe box, we keep the extracted recipe and original link in tab storage (sessionStorage) to restore them after sign-in without repeating extraction. The draft is usable for one hour and is removed after saving, when retrieved after expiry, or when the tab is closed. It is not used for analytics.
Essential cookies and local storage keep sessions secure, remember language and consent choices, support offline use and prevent abuse. They are necessary to provide the Service.
Separately from Clarity, we record essential server-side counters for product features, including import-preview attempts and aggregate outcomes, imports, planning, sharing and the journey towards a subscription. They use no cookie or persistent browser identifier. If you are signed in, an event may be associated with your internal account identifier; an anonymous visit to a shared link remains anonymous.
If you accept optional analytics, we keep a first-party cookie for up to 30 days containing a short category for the first source (for example direct, search, campaign, Android app or shared recipe). We do not store the full URL, search terms or advertising identifiers. At registration, that category is associated with the account so we can understand which journeys bring real users. With the same consent, a second cookie lasts up to 30 days and stores a predefined identifier of the first supported public page (homepage, product guide or selected public recipe). We record anonymous views of these pages and attach the identifier to the signup event to measure subsequent imports and returns. Private recipe links and query strings are excluded; a third cookie stores a short campaign label, if available, for up to 30 days. Withdrawal removes all attribution cookies.
Microsoft Clarity records interactions only after you accept, on public pages and inside the production app. Analytics cookies connect pages within a visit, including for signed-in visitors. The segments we add contain only categories: signed-in status, Free or Pro plan, and whether the account is less than seven days old. After consent, an opaque account identifier lets us find associated recordings and investigate usability problems, including across devices. We do not send names or email addresses with this identifier. Recognized test and administrator browsers are excluded; a local flag keeps the exclusion after logout. Before your choice and after refusal these tools do not load. Anyone who accepted before this change must choose again before account-linked recordings are enabled.
We do not use profile names or email addresses to identify sessions. Clarity may receive visited page and clicked link URLs; content masking does not cover those addresses. Recipe box navigation and personal recipe titles, photos, ingredients and steps are visible in recordings. Form fields, notes, personal tips, preferences, account and household member names, meal plan details and shopping lists remain masked. Anyone who accepted analytics before this change must choose again before replays with these visible contents are enabled. You can refuse or change your mind at any time without losing any feature; withdrawal does not affect earlier lawful processing.
7. Retention, export and deletion
To diagnose sign-in and imports, we also record outcome codes, duration, app version and launch mode (Play Store, installed app or browser). A random reference links the stages of one operation without identifying the browser across sessions. Detailed import-stage history, linked to the signed-in account, is deleted after 90 days and contains no shared links, recipe text, passwords or email addresses.
Essential service measurement also includes anonymous counters of consent choices, sign-in button use, authentication method and outcome. We do not record passwords, email addresses, raw error messages or full URLs in these counters. For signed-in visits we keep at most one activity row per account per UTC day to measure return visits. These operational events and daily activity rows are retained for up to 400 days and use no persistent browser identifier. Self-hosted Umami analytics loads only after you accept optional analytics. It is separate from these service counters and from Clarity.
Account and cookbook data are kept while your account is active. Shorter operational periods apply to logs, temporary uploads and processing artefacts; legal, security or dispute records may be kept for the period required by law. You can delete individual recipes or permanently delete the account from Profile. Backup copies are removed on normal rotation unless law requires longer retention.
A support conversation you voluntarily open on Telegram also remains in your Telegram chat and in the bot's private operator topic under Telegram's settings and retention rules. You can delete the chat from Telegram or ask us to remove the operator topic.
8. Your GDPR rights
Depending on the circumstances, you may request access, correction, deletion, restriction, objection and portability, and withdraw consent at any time. You may also complain to your local supervisory authority; in Italy this is the Garante per la protezione dei dati personali. Send requests to [email protected]. We may need to verify your identity and normally respond within one month.
9. Security and children
We use access controls, encryption in transit, managed infrastructure, monitoring and limited provider access. No online system is perfectly secure, so use a unique password and report suspicious activity. The Service is not intended for children under 14, and we do not knowingly collect their data. A parent or guardian can contact us to request removal.
10. Changes, contact and complaints
We update this notice when the Service, providers or law changes. We will give reasonable notice of material changes where practical. For questions or complaints, email [email protected]. You retain the right to contact your data protection authority at any time.