Privacy Policy
We handle your personal data with care. This policy explains what we collect, why, and what you can do about it.
Who we are
Gaston is a meal planning and kitchen management app developed and operated by Jonas Egeskov, Denmark ("we", "us", "Gaston").
If you have questions about this policy or want to exercise your rights, you can contact us at: jonasegeskov29@gmail.com
What we collect
Information you give us
| Data | When | Purpose |
|---|---|---|
| Email address | Sign-up / login | Authentication via magic link |
| Household size | Onboarding | Tailoring meal plans |
| Dietary preferences and allergies | Onboarding | Filtering recipes and AI suggestions |
| Favourite cuisines | Onboarding | Personalisation |
| Weekly food budget | Onboarding (optional) | Meal plan tailoring |
Information we collect automatically
| Data | When | Purpose |
|---|---|---|
| Pantry contents (groceries, quantities, expiry dates) | App use | Core functionality |
| Meal plans and recipes you save | App use | Core functionality |
| Shopping lists | App use | Core functionality |
| Receipt images | Scanner feature | Updating pantry via AI |
| AI chat messages | Cook Mode | AI processing — deleted after session |
| AI feature usage | Ongoing | Quota and subscription management |
What we do NOT collect
- Payment details (handled by Apple App Store / RevenueCat)
- Location data
- Contacts
- Camera access beyond what you explicitly scan
- Advertising IDs or third-party tracking
What we use your data for
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Delivery of core features (pantry, recipes, meal plan, shopping list) | Contract (Art. 6(1)(b)) |
| AI features (meal plan, cooking assistant, receipt scanning, recipe import) | Consent (Art. 6(1)(a)) |
| Subscription management and access control | Contract (Art. 6(1)(b)) |
| Error handling and app stability (Sentry) | Legitimate interest (Art. 6(1)(f)) |
| Security and fraud prevention | Legitimate interest (Art. 6(1)(f)) |
Use of artificial intelligence (AI)
Which AI features does Gaston use?
- AI meal planner — Generates personal weekly plans based on your preferences, pantry and household profile
- AI cooking assistant — Answers questions and gives real-time advice while cooking (Cook Mode)
- AI recipe importer — Analyses images, links and videos (YouTube, Instagram, TikTok) and converts them into recipes
- AI receipt scanner — Uses image analysis to read receipts and update your pantry
- Weekly Wrapped — Summarises your cooking week with an AI-generated commentary
What is sent to AI services?
When you use AI features, relevant data is sent to our AI providers: your groceries and pantry contents, your preferences, your household size, receipt images (only when scanning), links and images you submit yourself, and messages you send to the cooking assistant.
Who are our AI providers?
| Service | Purpose | Processing location |
|---|---|---|
| Anthropic (Claude) | Meal plan, cooking assistant, recipe import | USA (EU Standard Contractual Clauses) |
| Google (Gemini) | Receipt scanning, image analysis | EU |
Consent and opt-out
The first time you use an AI feature, Gaston asks for your active consent. You can withdraw your consent at any time under Settings → Privacy → AI Consent.
If you withdraw consent, AI features will be disabled. Your saved recipes and meal plans remain available, and all manual features continue to work.
AI-generated content
Recipes and meal plans generated by AI are marked with an AI icon in the app. AI can make mistakes — always verify allergens and nutritional information, especially if you have special dietary requirements.
Sharing of data
We share your data with the following categories of recipients:
| Recipient | Purpose | Location |
|---|---|---|
| Supabase (database provider) | Storage of all app data | EU (Frankfurt) |
| Anthropic | AI processing (only with consent) | USA (EU Standard Contractual Clauses) |
| Google Cloud | AI image analysis (only with consent) | EU |
| Sentry | Error reporting and app stability | USA (EU Standard Contractual Clauses) |
| Apple / RevenueCat | Subscription management | USA (EU Standard Contractual Clauses) |
We only disclose personal data to authorities if we are legally required to do so.
Cookies and tracking
Gaston is a native mobile app and does not use cookies. The Gaston app collects no advertising IDs and uses no third-party advertising networks.
Our website (chefgastonapp.dk) may use analytics cookies. The website's cookie policy is presented in the banner on the site.
Retention and deletion
| Data type | Retention period |
|---|---|
| Account and user data | As long as the account is active |
| AI chat messages | Deleted after session ends (not sent to storage) |
| Receipt images | Deleted immediately after AI processing |
| Error reports (Sentry) | 90 days |
| Subscription history | 7 years (statutory bookkeeping requirement) |
When you delete your account, all the above data is deleted within 30 days, except for data we are legally required to retain.
Your rights
As a data subject under GDPR, you have the following rights:
- Right of access — You can request a copy of the data we hold about you
- Right to rectification — You can request correction of inaccurate data
- Right to erasure — You can request deletion via Delete my account in Settings, or by contacting us
- Right to data portability — You can request your data in a machine-readable format
- Right to restriction — You can request restriction of processing in certain cases
- Right to object — You can object to processing based on legitimate interest
- Right to withdraw consent — For AI features, you can withdraw your consent at any time
To exercise your rights: contact us at jonasegeskov29@gmail.com. We respond within 30 days.
If you have complaints about how we process your personal data, you can file a complaint with the Danish Data Protection Agency (datatilsynet.dk).
Data security
- All data transmission is encrypted via TLS/HTTPS
- Databases are encrypted at rest
- Access to user data is restricted via row-level security (RLS) — users can only access their own data
- API keys and secrets are never stored in the app code
- Error reports are anonymised before being sent to Sentry
Minors
Gaston is not directed at users under 13. If we become aware that we have collected data from a child under 13 without parental consent, we will delete the data immediately.
Changes to this policy
Material changes to this privacy policy will be announced via an in-app notification. The current version is always available at chefgastonapp.dk/privacy.
Contact
Privacy Policy for Gaston
Who we are: Gaston is a meal planning app by Jonas Egeskov, Denmark. Contact: jonasegeskov29@gmail.com
What we collect: Email address, household profile (size, diet, allergies, cuisines), and in-app activity (pantry contents, meal plans, shopping lists). Receipt images and AI chat messages are processed transiently and not permanently stored. We do not collect payment details, location, or advertising IDs.
How we use it: Core features run on a contractual basis (GDPR Art. 6(1)(b)). AI features require your explicit consent (Art. 6(1)(a)), which you can withdraw at any time in Settings → Privacy → AI Consent.
AI processors: When you use AI features, relevant pantry and preference data (never your name or email) is sent to Anthropic (Claude, USA) and Google Cloud (Gemini, EU) under EU Standard Contractual Clauses.
Your rights: You have the right to access, rectify, erase, port, and restrict your data. Use "Delete my account" in Settings or email us. Complaints: datatilsynet.dk
Retention: Account data is retained while the account is active and deleted within 30 days of account deletion, except where legally required.