Privacy Policy
Ruchy · Effective 30 September 2026 · Operated by Raj Bharath, India.
This policy explains what personal data Ruchy ("we", "us") collects, why, who we share it with, and the rights you have under India's Digital Personal Data Protection Act, 2023 (DPDP). By using the app you agree to this policy.
1. Who we are
Ruchy is a recipe app that lets you save recipes from links, photos, and text, organise them, and cook them. The data controller ("Data Fiduciary" under DPDP) is Raj Bharath, contactable at hello@ruchy.app.
2. You do not create an account with personal details
Ruchy does not require your name, email, or phone number to work. On first launch the app creates an anonymous device identity (a random ID) so your recipes can back up to the cloud and sync across your own devices. We do not know who you are from this ID.
The one exception is the waitlist on this website. If you choose to enter your email on ruchy.app, we store: that email; whether you signed up under the founding-member offer; which link or post brought you (for example utm_source); a personal invite code we create for you; and, if you arrived through someone else's invite link, their code. This is kept in our Supabase database. We use it to send you launch news and the occasional recipe, to show you your place in line, to credit whoever invited you, and to see which posts brought people in. You can unsubscribe from any email, or ask us at hello@ruchy.app to delete your entry, at any time. It is never sold, never used for advertising, and is not connected to your in-app device identity. Your IP address is not stored alongside the email — it is held in memory only for a moment, to stop one machine submitting the form hundreds of times. The app itself still needs no email to work.
3. What we collect and why
| Data | Why | Where it lives |
|---|---|---|
| Email address, invite code, and the code of whoever invited you (website waitlist only — optional, never in the app) | Launch news and the occasional recipe (unsubscribe anytime); your place in line and invite link; crediting referrals; which posts worked | Our cloud (Supabase) |
| Anonymous device ID | Sync and back up your own data | Device + our cloud (Supabase) |
| Display name (optional, if you enter one) | To greet you in the app | Device + cloud |
| Diet & allergy preferences (e.g. vegetarian, nut allergy) | To suggest recipes you can safely eat and flag imports that clash | Device + cloud, and sent to our AI provider (see §4) |
| Recipes you save; meal plans; grocery & pantry lists; your food/nutrition log | The core features of the app | Device + cloud |
| Links, text, and photos you import to create a recipe | To read them into a structured recipe | Sent to our AI provider (see §4); the resulting recipe is stored |
| The web address a recipe came from | To credit the original creator and let you reopen the source (see Terms §4) | Device + cloud, saved with the recipe |
| Photos you take of your own cooked dishes | To illustrate your saved recipe | Device only — these are not uploaded |
| Anonymous usage events: that the app was installed or opened, and that a recipe import started or succeeded, a recipe was cooked, or a recipe card was shared — tagged with a random ID that the analytics software creates on your device, the app version and the device type. Never a recipe’s content, your text, photos, name, email or location | To learn which features work and fix the ones that don’t | PostHog (see §7), in the United States |
| Reports you send about a recipe or an AI answer (only when you tap Report): the text you reported, the reason you pick, an optional note, the recipe’s source link, your anonymous device ID and app version | To review and fix or remove offensive, unsafe or wrong AI content, and to stop the report button being abused | Our API server’s logs — never sent to an AI provider |
Sensitive data. Diet and allergy information can reveal health details. We collect it only to make recipe suggestions safe for you, we ask for it optionally, and you can clear it at any time in Settings.
4. AI processing and cross-border transfer
To turn a link, photo, or text into a recipe — and to filter recipe searches by your diet — the relevant content is sent to providers that process it on servers outside India (in the United States). Google (Gemini) reads recipes from links, photos and text. For Discover, Serper runs the web search and Google (Gemini) selects and formats the results; Anthropic (Claude) is used for that search only on an alternative configuration, and is not used when Serper is enabled.
What the search provider receives. When you use Discover, your search words are sent to Serper together with your country and language — and, if you have set a diet, that diet is added to the search text (for example a search becomes “vegan <your words> recipe”). Diet can reveal health information, and some values can imply religious practice, so we are naming this explicitly rather than describing it as ordinary search. Your name, device ID and allergy list are never sent to the search provider. If you would rather not send this, leave the diet setting unset or avoid Discover; every other part of the app works without it.
Before any content is sent for AI processing for the first time, the app shows you a consent screen describing exactly what is shared, and you must agree. We do not send your name or device ID to the AI provider with this content.
5. What we do NOT do
- We do not show advertising.
- We do not track you across other apps or websites, and we do not sell your data.
- We do not use advertising SDKs. We use one analytics tool, PostHog, only for the anonymous usage events in §3: it builds no profile of you, does no location lookup and records no screens or taps beyond those events.
- We do not put any personal data on the recipe cards you share — a shared card shows only the recipe, the original creator's handle, the Ruchy mark, and a short link. It carries your own photo or a Ruchy illustration, never a photograph from the source site.
- We do not handle your card details. Ruchy is a paid subscription with a free trial, and payment is taken by the App Store or Google Play, never by us — we are told only whether your subscription is active.
6. How long we keep it
We keep your data until you delete it. Deleting a recipe removes it (a short recovery window applies via the in-app bin). Deleting your account (see §8) removes your synced data from our cloud. Reports you send (§3) live in our API server’s logs, which our host deletes on a rolling schedule.
7. Who we share with (processors)
- Google — AI recipe extraction from links, photos and text, and selection of Discover results (see §4).
Serper — runs the Discover web search; receives your search words, country, language and, when set, your diet (see §4).
Anthropic — an alternative provider for the Discover search only; not used while Serper is enabled (see §4). - Railway — hosts our API server, which passes what you import to the AI providers above; its logs hold the reports you send (§3).
- Supabase — cloud database that stores your synced data and the website waitlist.
- PostHog — anonymous product analytics (the usage events in §3), on servers in the United States.
- Vercel — hosts ruchy.app and runs the waitlist sign-up, passing your email to Supabase; it may keep short-lived request logs.
- Apple / Google — the app stores that distribute the app.
These providers process data on our behalf under their own security terms. We do not share your data with anyone for their own marketing.
8. Your rights under DPDP, and deleting your data
You have the right to access, correct, and erase your personal data, to withdraw consent, and to grievance redressal.
- Delete everything: in the app go to You → Account & data → Delete account & data. This wipes your data from this device and from our cloud, and signs out the anonymous identity.
- Without the app installed: email hello@ruchy.app from any address and we will delete your synced data — see our Support page.
- Export: You → Account & data → Export my recipes downloads a copy.
- Correct / withdraw consent: edit or clear your details in Settings, or email us.
9. Grievance Officer (required by DPDP)
If you have a complaint about how your data is handled, contact our Grievance Officer:
- Name: Raj Bharath
- Email: hello@ruchy.app
- We will acknowledge and respond within the timelines required by law.
10. Children
Ruchy is intended for users aged 18 and over. Under DPDP, processing a child's data requires verifiable parental consent; we do not knowingly collect data from children. If you believe a child has used the app, contact us and we will delete the data.
11. Security
We protect data in transit with HTTPS and restrict who can read your cloud data to your own account. No system is perfectly secure, but we design to keep your data private by default.
12. Changes
We may update this policy; we will change the effective date above and, for material changes, notify you in the app.