Privacy at weReci
The short version: your collection is yours. We store what you save so we can show it back to you, we send it to AI providers only to do the things you ask for, we don't run ads or sell your data, we count which features get used so we know what to build next, and you can delete everything yourself, anytime.
What we collect
Your account. Sign-in is handled by Corbado, our authentication provider (passkeys, Google, or email). From that we keep your account id, email address, display name, and when you last used weReci.
Your collection. The recipes, letters, photos, and notes you save — including text extracted from the pages, images, and videos you import. Videos from social platforms are fetched to extract the recipe and are not kept afterward; the extracted recipe and any cover image are.
Usage counters.We meter how many imports, AI calls, and photo operations your account uses each day (that's how the free tier works), and we track what your account's AI usage costs us. You can see your own numbers in the ✨ settings.
Your AI key, if you bring one. If you use the "your own AI" option, your API key is stored encrypted (AES-256-GCM), is never shown back to any client (you only ever see its last four characters), and can be removed by you at any time.
Which features get used. We use Vercel Web Analytics to count page views and a short list of product events — a recipe imported, an AI action run, cook mode opened. These carry no identifier at all: they are counts, no profile is built, and nothing from inside a recipe of yours is ever part of an event. We read them for one reason — to learn which parts of weReci people actually value, so we can build more of those and less of the rest.
How many people arrive. Separately, we count how many people reach weReci and how many go on to make an account. Page views cannot answer that — one person reloading looks exactly like five people arriving — so a first-party cookie gives your browser a random id, and we record which steps of the introduction that id reached: the landing page, the tour, a cookbook tried without an account, an account created. The id is a random number with nothing personal in it; we keep the steps, not the pages you read; and if you create an account we note the id alongside it, which is how a visit gets connected to the account it became. It stays on this site — never shared, never sold, and meaningless anywhere else.
Comparing two versions of the introduction. Much of what a new visitor first sees — the guest tour, and the themed groupings our AI assembles to introduce it — is generated rather than hand-written, and we have no way to tell which version actually helps without putting two of them side by side. So we may show different visitors different versions and count which one leads to more accounts. While such a comparison is running, the same id described above also records which version you were shown, so it stays the same on every visit instead of changing under you, and the account you create is counted toward that version. Nothing new is collected to do this — it is the arrival count above, split in two.
We do not collect browsing history, contacts, or location, and we run no advertising trackers.
Crash reports. We use Sentry to record errors so we can fix them. A crash report contains the error and the code path that produced it — not your recipes. We configure it to drop request bodies and cookies, and to mask email addresses and share links before anything is sent. It records no session replay, so it never captures your screen or your collection.
Where it lives
Your collection is stored with our cloud infrastructure providers: a vector database (Qdrant Cloud) for recipe content and search, a hosted SQLite database (Turso) for photos and account data, and Vercel for serving the site. Each account's data is isolated: every read and write is scoped to your account at the storage layer.
Payments
Payments are processed by Stripe. Your card number never reaches weReci — checkout happens on Stripe's own hosted page, and what comes back to us is a customer reference, the amount, and whether it succeeded. We never see or store card numbers, and we cannot charge you off-session.
What we do keep is the ledger: your Stripe customer id, and a dated record of every purchase and every credit deduction, so your balance is auditable by both of us. To calculate sales tax where any applies, Stripe collects a billing address at checkout and stores it against your Stripe customer record; we do not keep a separate copy.
Stripe processes this under its own privacy policy and, as a payment processor, retains transaction records for the period its financial and anti-fraud obligations require — that retention survives deleting your weReci account, which is a legal requirement on them and not something either of us can waive.
AI processing
weReci's AI features send the relevant content to AI providers to do the thing you asked: importing a recipe from a photo or video sends that photo or video for extraction; asking for a substitution sends the recipe and your question; generating a cover image sends the recipe text.
Text features. Chat, scaling, substitutions, step reformulation, the themed groupings on your shelf, and translating your content for display all run on open-weight models hosted by Venice.ai, whose stated policy is that prompts and responses are not stored on its servers.
Photos, videos, search, and covers. Importing a recipe from a photo or video, reading text out of images (Cloud Vision), the embeddings that power search, and generating cover images are processed by Google (Gemini, Vertex). If Google's image service is unavailable, cover generation can fall back to OpenAI.
These providers process content to provide the service — we don't permit them to use it for advertising.
If you bring your own AI key, the text-based AI features route to your chosen provider under your key and their terms instead.
AI use here is transparent and optional where it can be — see how we think about AI.
Sharing
Nothing you save is visible to anyone else unless you share it. Share links carry a scoped token that grants access to exactly that recipe. If you connect an AI assistant via our MCP endpoint, it can read your collection only with the scoped access you approve, and you can revoke that access at any time. Emails weReci sends (like a recipe you email to yourself) go only to your own verified address, from hello@reciwe.xyz.
A shopping list sent to a phone. The list travels inside the link itself — we keep no copy of it, and the link stops working after two weeks. If you then tap “Sync with another phone” on that page, we store which lines are crossed off, filed under a one-way hash of the link, so a second phone holding the same link shows the same ticks. That record is numbers only: no item names, no amounts, not the list's title, and nothing connecting it to your account. It is off unless you turn it on, it expires when the link does, and turning it back off stops any further sharing — though ticks already shared stay until the link expires.
A shopping list shared with the person you share a cookbook with. This is the one thing here we do hold: two accounts cannot share a list we cannot see. If you turn it on for a list, we store its lines, who put each one there, and who crossed it off — for two weeks. It is off unless you turn it on, the two of you turn it on separately, and leaving is your own act: the list stays for whoever is still on it, and once the last person leaves it is deleted outright. Your own list, on your own device, is untouched either way. Handing that list to a grocer still ends where it always did — on their site, under your account.
Recipes an assistant added for you. If you ask an assistant — in the app's chat, or a connected one like Claude — to put recipes on your list while the app isn't open, we hold those entries until your app next opens and collects them, at which point our copy is deleted. They are only ever added when you ask, only to your own list, readable only by your own account, and anything never collected expires on its own after two weeks. If you share a list with your cookbook partner, an assistant add lands there instead, under the shared list's own rules above.
Notifications about a shared list. If you turn them on, we keep the address your browser gives us for reaching that one device, and nothing else — no keys, and nothing that would let anyone read anything of yours. What we send to it is empty: your device is nudged, and then asks us directly what to show. So the notification service in between — Google's, Apple's or Mozilla's — never learns what is on your list. Turning them off, or clearing this site's data, drops the address.
Cookies
We use cookies for signing you in (session), remembering your language (recipes_lang), share-link access, and counting visitors: one (reciwe_anon) holds the random id described under “What we collect”, for a year, so someone who comes back next week is counted as one person rather than two. No advertising or cross-site tracking cookies.
Deleting your data
Account deletion is self-serve: in the ✨ settings, type DELETE and your recipes, photos, letters, usage records, and stored AI key are removed from our databases. We don't keep a copy of your collection after deletion. Authentication data held by Corbado is governed by their retention; contact us if you want help ensuring it's fully cleared.
Children
weReci is not directed at children under 13, and we don't knowingly collect their data.
Changes & contact
If this policy changes in a way that matters, we'll update the date at the top and, for significant changes, tell signed-in users. Questions, concerns, or data requests: hello@reciwe.xyz.
See also the terms of service, about weReci, and connect Claude.
© 2026 Reciwe LLC. All rights reserved. weReci™ is a trademark of Reciwe LLC.