ButlerB Privacy Policy
ButlerB is a meal-planning app. This policy explains what data we collect, why, where it goes, and your rights. Short version: we collect what the app needs to plan meals for your household, we don’t run ads or analytics trackers, we never sell your data, and you can delete your account and data at any time.
1. Data we collect
Account data — email address, name, and profile picture, provided when you sign up (directly or via Google/Apple sign-in). Authentication is handled by a dedicated authentication provider; we never see or store your password.
Profile & preferences — region, language, measurement units, favourite cuisine, avoided ingredients (taste preferences like onion or cilantro), the table’s dietary preference (omnivore/vegetarian/vegan, used to filter recipes), grocery budget, and notification preferences. Your region drives store suggestions and weather-based food-storage tips; we never collect GPS location.
Household & dietary data (sensitive) — household composition (number of adults and children), household member names, and, if you choose to add them: allergies, calorie targets, dietary goals, and health conditions relevant to diet (e.g. diabetes). This is special-category data under GDPR Article 9. We process it only with your explicit consent, given when you enter it, and solely to filter recipes and plans for your household — including sending it to our AI processing partner when you use the diet-refinement feature, which stops the moment you withdraw consent. You can remove it at any time in Settings, and withdrawing it does not affect the rest of the app. If you add household members’ details, you confirm you’re entitled to share them.
Your content — recipes you create or import (with their source links), meal plans, pantry contents, shopping lists, cooking history, and the photos you submit: recipe photos for import, fridge and pantry-shelf photos you scan to stock the pantry, grocery receipts and handwritten shopping lists you scan, and photos you attach to a cook. Photos are processed by our AI processing partner to do what you asked (read the recipe, the receipt, the shelf), and every photo attached to a cook is automatically screened by the same partner before it can be shown to anyone — see “Keeping shared content safe” below.
Social data — if you use the social features: your display name, your connections (follow requests you send and accept), photos you attach to a cook you share, and the reactions you leave. You are not discoverable by default: other people can only find you by your exact email address unless you turn on name search, and no content of yours reaches anyone until you choose an audience for it. There is no public feed and no follower count. You can block anyone (silently and in both directions) and report content or an account; we may remove reported content or suspend an account that breaks the rules.
Gatherings (sharing dietary data with a host) — when someone invites you to a gathering and you reply, you may optionally share your allergies and diet type with that host, for that one occasion, so they can cook something safe for you. This is special-category data (GDPR Art. 9) shared with another person, so: it is off unless you turn it on, it is a copy taken at the moment you share it (not a live link to your profile), it is visible only to that gathering’s host household, you can remove it at any time by turning the switch off, and it is deleted with your account. Guest entries you type in yourself (a name, and any dietary notes the guest gave you) stay under your control: you can edit or remove them at any time, they are visible only to your household, and they are deleted with the gathering.
Groups — a group is a small room you join by accepting an invitation, or by asking through a join link and being let in. Membership reveals your display name to the room’s other members, and a recipe you post there becomes readable to them for as long as the post stands — that access ends when you remove the post, leave, or the group ends, and it is never a public page. If your presence setting says so, members also see the dishes you chose to share, in the room’s feed and its weekly chart of dishes (never a ranking of people). Asking to join through a link shows your name to that room’s owner and admins only. ButlerB Kitchen, the room we run, shows a member count and never a member list; only we post there. Groups you own pass to the longest-standing admin or member if you delete your account, and your own memberships and posts are deleted with it.
Technical data — a push-notification token for your device (if you enable notifications), and internal usage/cost logs for the AI features (used for rate-limiting and budget tracking, not profiling).
Grocery store connections — if you connect a supported store account, we store the access tokens needed to send your shopping list there. We never see your store password.
We do not use advertising or analytics SDKs, we do not track you across other apps or websites, and we do not sell or share personal data for advertising.
Voice input
Added 2026-08-20, when the microphone was enabled. Rebuilt 2026-08-22 around a gate: two words you choose yourself.
One assistant, one microphone. Tap Ask BubbleBee and a bee appears, floating over whatever page you are on. While it is lit it is listening; when you switch it off it is gone, and the conversation goes with it. There is no microphone button anywhere else in the app — not on the cook screen, not in the chat. Nothing listens when the bee is out, there is no wake word running in the background, and your device's microphone indicator shows whenever listening is active.
Recording, only between two words you choose. While the bee is lit and waiting, ButlerB listens for a word you picked — it never starts on its own, and nothing is recorded during the wait. Only after hearing your word does the microphone record, and only until you say your closing word, stop speaking, or fifteen seconds pass, whichever comes first. That clip is transcribed, used once, and never uploaded to ButlerB or to anyone else.
You choose both words in Settings → ButlerB Assistant, and you can change them whenever you like. A test refuses any build where the waiting half records, or where a recording can run past its ceiling.
You can also clear the word. Then, for as long as the bee is lit, whatever is said is taken as a request. The bee is still lit only by you, only while you can see it — the screen stays awake while it is lit, locking the phone pauses it, and ten minutes of quiet pause it too — and nothing about what leaves your phone changes.
Who does the transcribing depends on a choice you make. On the same settings screen you can download a speech model — including KB-Whisper, the National Library of Sweden's — which runs entirely on your phone. With a model downloaded, no audio leaves your device at any point. With none, your device's own speech service (Apple Speech on iOS, Google's speech recognizer on Android) does the transcribing, and depending on your device's settings that service may process what you said between your two words on Apple's or Google's servers under their terms. That happens on the platform side, before anything reaches us. Either way, what reaches ButlerB is the resulting text, never audio.
Voice sessions leave only what a command did. A sentence spoken between your two words is acted on where you are: a step turned, a timer started, an item added to a list, a note saved with the cook. Everything said outside the gate is not merely ignored — it was never recorded, never transcribed, and is discarded on your device before anything else could happen to it. The microphone permission can be declined or revoked at any time in your phone's settings; every feature works fully with typed input.
2. Why we process it (lawful bases)
| Purpose | Data | Basis (GDPR) |
|---|---|---|
| Provide the service (accounts, sync, plans, lists) | account, content, technical | Contract (Art. 6(1)(b)) |
| Filter recipes/plans for allergies, diets, conditions | household & dietary data | Explicit consent (Art. 9(2)(a)) |
| AI features (recipe import, photo/receipt/list scans, adaptation, suggestions) | the text and photos you submit; dietary/health context only under its own consent row above | Contract |
| Automated screening of every photo attached to a cook, before it can be shown to anyone | the photo (sent to our AI processor); only the pass/flag decision is stored, never a copy | Legitimate interests (Art. 6(1)(f)) — a safe service for everyone |
| Social features (connections, shared cooks, gatherings) | display name, connections, shared photos | Contract — and each share is your choice |
| Sharing your allergies/diet with a gathering host | your dietary data, copied to that gathering | Explicit consent (Art. 9(2)(a)) — per gathering, revocable |
| Keeping shared content safe (reports, moderation, blocking) | reported content, reporter and subject account ids | Legitimate interests (Art. 6(1)(f)) — a safe service for everyone |
| Notifications (meal reminders, shopping alerts) | push token | Consent — opt-in, revocable in system settings |
| Abuse prevention, rate limiting, error monitoring | technical | Legitimate interest (Art. 6(1)(f)) |
3. Who processes it for us
We use a small set of service providers (processors), bound by data-processing agreements. By category:
| Category of recipient | What they receive |
|---|---|
| Authentication provider | email, name, sign-in metadata |
| Cloud database & hosting providers | app data at rest and in transit |
| AI processing partner | the text and photos you submit to AI features — recipe imports, fridge/pantry-shelf scans, receipt and shopping-list scans, photos attached to cooks (including the automatic safety screening of each one) — and, with your explicit consent, dietary/health context for the diet features. Not used to train their models. |
| Push-notification delivery service | push token, notification content |
| Page-rendering service (recipe import) | only the recipe URL you asked to import — no account data |
| Error & crash monitoring service | technical error reports (stack trace, app version, device model/OS, request path) — never your content, household or dietary data |
Recipe imports and app features also query public content, nutrition, weather and store-price data services with content identifiers only (a video ID, an ingredient name, your region) — never your identity.
A full, current list of our processors is available on request at admin@butlerb.com.
Some providers process data in the United States. Where data leaves the EU/EEA, transfers rely on the EU–US Data Privacy Framework and/or Standard Contractual Clauses.
4. Retention
Your data is kept while your account exists. When you delete your account, your personal data — including all household and dietary data, content, push tokens, and store connections — is deleted from our systems without undue delay. Aggregated, non-identifying records (e.g. anonymous usage counts) may be retained. Backups roll off on the hosting providers’ standard cycles. One thing survives only if you ask: when deleting your account you can choose to leave to ButlerB Kitchen the public recipes you marked as your own writing, and those recipes then remain published under our account with your name removed. Recipes you marked as adapted from, or taken from, someone else are not included and are deleted with everything else (see the Terms, “Your content”).
5. Your rights
Under GDPR you can: access your data, correct it, delete it, export it (portability), restrict or object to processing, and withdraw consent for dietary/health data at any time (delete it in Settings, or ask us — withdrawal also stops the diet features from sending it to our AI partner). We provide a complete machine-readable (JSON) export of everything we hold about you; it states what was redacted or withheld and why, and names the data our providers hold on our behalf. Contact admin@butlerb.com — we respond within one month, usually much faster. You may also complain to your supervisory authority; in Sweden that is IMY (imy.se).
You can delete your account (and all data) directly in the app: Settings → Account → Delete account.
6. Children
ButlerB is not directed at children and requires you to be 16 or older to create an account. Household features let an adult account holder note family members’ dietary needs (including children’s); that information is provided by and controlled by the account holder. The automatic photo screening declines any shared cook photo in which a child is the main subject.
7. Security
Data is encrypted in transit (TLS) and at rest by our hosting providers. ButlerB is operated by one person: production database access is limited to the controller, is used for schema migrations and content moderation, and is not used to browse user data — routine investigation uses a read-only credential, and the rules that keep one household’s data from reaching another are enforced by an automated test suite that runs on every change. Sign-in is protected against breached passwords and new-device checks via our authentication provider.
8. Changes
We’ll post updates here and update the effective date. For material changes (especially anything touching dietary/health data), we’ll notify you in the app before they take effect.
9. Contact
Vijay Uba — admin@butlerb.com