JipCook 한국어

Privacy Policy

Effective 4 August 2026 · Last updated 11 August 2026

1What this is

This policy sets out what personal data JipCook handles, why, and for how long. It applies to the app and to the website. The terms of using the service are in the Terms of Service.

The information stored in JipCook — records of family meals — is personal by nature. This policy follows one principle: collect only what is needed, and delete it when it no longer is.

2What we collect

KindWhatWhen
Account The email address and account identifier we receive from Google or Apple When you sign in or link an account
Guest An anonymous identifier only — no email address When you start without an account
Profile Nickname, country When you enter or choose it
What you make Recipes (ingredients, steps, notes, tags), cooking records and the journal you write for the day, photos, hearts, the labels you give family members When you save it
Subscription Subscription status and the result of validating a store receipt. We never receive card or payment details When you start or renew Plus
Safety Reports you file (reason, note, target), the people you block, and any moderation action on your account When you report or block
Technical Access and error logs (IP address, timestamp, request) Automatically, when your app talks to the server

What we don't collect — advertising identifiers, precise location, contacts or address book, health data, call or message history.

3What we don't do

  • No advertising. There is no ad network in the app.
  • No analytics or tracking. There is no behaviour-tracking SDK in the app.
  • No advertising or tracking cookies. Staying signed in is handled by storage on your device.
  • Nothing is sold. We do not sell or share personal information — not even under California's CCPA, whose broad definition counts passing data to ad companies as a "sale".
  • JipCook does not use your records or photos to train AI models. If that ever changes we'll tell you first and ask for separate consent — and you'll be able to keep using JipCook either way. There is one exception: a reported photo is sent to Google for review, and Google may use it to improve its own models. Section 5 spells this out.

4Why we use it

The grounds for processing are performing our agreement with you (the Terms), your consent for optional items, and our legitimate interest in keeping the service safe.

5Who processes it for us

Some processing — servers, storage and the like — is entrusted to the companies below. Each handles data only as far as the job they do requires.

CompanyWhat they doWhere
Supabase Inc. Database, sign-in, server functions Data stored in the Seoul, Korea region
Cloudflare, Inc. Photo storage (R2), web hosting (Pages), visit statistics (Web Analytics — no cookies) Global network
Google LLC
(Gemini API)
First-pass risk assessment of reported photos only
(what is sent may be used to improve Google's models)
United States
Telegram FZ-LLC Private alert to the operator when a report comes in Global
Apple Inc.
Google LLC
Sign-in, app distribution, payment processing Global

Automated review of reported photos (please read)

When someone reports a photo, that single photo is sent to Google's Gemini API for a risk assessment before a person sees it. This is so a genuinely harmful photo isn't left up for hours waiting on a human.

  • We send the reported photo and the minimum needed to assess it — no account information such as email or nickname.
  • Photos that have not been reported are never sent. Your ordinary records don't travel this path.
  • A photo sent this way may be retained and reviewed by Google, and may also be used to improve Google's AI models. This is because JipCook uses Google's free API tier. Photos that were never reported are not affected.
  • The machine's assessment can only take something down from public view. Strike points are applied by a person (Terms, section 5).

The operational alert (Telegram) contains the report's reason and note plus a short-lived link to view the photo. It goes to a private channel with only operators in it.

6International transfers

Some of the companies in section 5 are outside Korea. As required by the Personal Information Protection Act, here are the details.

RecipientCountryDataWhen & howPurposeRetention
Cloudflare, Inc. USA and others Photo files Network transfer on upload Storing and serving photos Removed about 2 days after nothing references them
Google LLC USA One reported photo API call when a report is filed Risk assessment
(may be used to improve Google's models)
Per Google's API terms
Telegram FZ-LLC UAE and others Report reason and note, photo link Message sent when a report is filed Alerting the operator Until deleted from the channel
Apple Inc. / Google LLC USA and others Account identifier, subscription receipt On sign-in and payment Authentication, payment Per each company's policy

Each company's privacy contact can be found on its own privacy policy page — Cloudflare · Google · Telegram · Apple.

If you'd rather your data weren't transferred abroad, JipCook won't work for you — the service is built on these providers. Deleting your account stops the transfers.

7How long we keep it

8What stays on your device

9Your rights

If you're unhappy with how we handle your data, you can also turn to:

10How we keep it safe

Complete security cannot be guaranteed. If you find a security issue, please report it to the address below — security reports are handled first.

11Children under 14

JipCook is not directed at children under 14, and we do not knowingly collect their personal data. If we learn that an account belongs to a child under 14, we delete it. If you believe your child has an account, please write to us.

12Who to contact

Access and deletion requests, appeals against a moderation decision, and security reports all go to this address.

13Changes to this policy