Privacy

Privacy Policy

Last updated: 5 September 2026

Who We Are

ClearCook provides visual recipes, wipe-clean recipe card information, a local Cooking Passport and email updates for families interested in children's cooking.

Information We Collect

We collect email addresses when you sign up for ClearCook updates, printable resources, card-release alerts, recipe-card votes or free-card draw updates. We may also record the signup source page, campaign, consent status, UTM campaign data, referrer and the number of recipes stamped in the local Cooking Passport at the time of signup.

If you submit a privacy or opt-out request, we collect the email address, request type and any message you choose to send so we can process the request.

Cooking Passport Data

The Cooking Passport is stored in your browser's local storage on your device. It is not uploaded to ClearCook when you mark a recipe as cooked. If you enter your email on a passport-related form, ClearCook only receives the email form fields described above, not the full passport contents or photos.

Referral Data

If you use a ClearCook referral link, we store the referral relationship between the two accounts and whether the referred account verified its email. We use this to show referral progress and unlock recipe cards. Referral links contain a random code and do not include either person's email address.

Analytics And Cookies

ClearCook uses Vercel Analytics and may use Plausible Analytics if configured for the site. These tools help us understand page views and site performance. We also use local storage for the Cooking Passport so the feature works without an account.

ClearCook also records privacy-minded first-party analytics so we can understand which recipes are useful. A random session identifier lasts until 30 minutes of inactivity. We also store a stable random browser visitor identifier so activity can be understood across visits. When you sign in, a separate service-role-only link can connect that pseudonymous visitor identifier to your account for first-party engagement reporting; raw analytics rows never contain an email address or account ID. We record page paths without query strings, recipe interactions, onward page paths, campaign tags and the hostname of an external referrer. We do not store IP addresses, full external referrer URLs or browser user-agent strings in this dataset. Raw events and pseudonymous attribution records are retained for no more than 13 months. Access to account-linked engagement reporting is restricted to service-role-only admin tools.

How We Use Information

We use signup information to send the email offer you requested, understand which pages and resources are useful, manage marketing preferences, process free-card draw interest and respond to privacy requests. We do not sell personal information.

Your Choices

You can ask to opt out of marketing emails, request access to information linked to your email, ask us to delete marketing signup data, or request account deletion if you later create an account.

Manage privacy preferences

Security

Personal data tables are protected with Supabase Row Level Security. Public visitors can submit email signups and privacy requests, but they cannot publicly read, update or delete those tables. Admin processing should use server-only service-role access.

Contact

For privacy questions, use the privacy preferences page and include a short message with your request.