Privacy Policy
This Privacy Policy describes how Braden Ross, doing business as Feedia ("Feedia," "we," "us," or "our"), collects, uses, and shares information about you when you use the Feedia iOS application and any related services we offer (the "Services").
If you do not agree with this policy, please do not use Feedia. If you have questions, contact us at privacy@feediaapp.com.
1. Quick Summary
- What we collect: account info (name, email, username, password, date of birth), profile content (bio, photo), the content you create (recipes, cookbooks, comments, reviews, bites, direct messages), and automatic technical data (IP address, device identifiers, app usage, approximate location derived from IP).
- What we do with it: run the app, let you connect with other users, keep accounts secure, comply with the law, improve the product. We don't sell your data. We don't show ads. We don't use it for behavioral advertising.
- Who we share it with: the service providers we need to operate the Services (AWS, PostHog, Sentry, OpenAI, Spoonacular, Neon, Apple). They process data on our behalf under data-processing agreements.
- Your controls: you can view and edit your information in the app, delete your account from Settings, or contact us to exercise any rights granted by your local privacy law.
- Age requirement: Feedia is for users 13 and older. We collect date of birth to verify this and do not knowingly create accounts for children under 13.
2. Information We Collect
2.1 Information you provide directly
When you create an account or use Feedia, you give us:
- Account information: first and last name, email address, username, password, and date of birth (used to confirm you are at least 13 years old).
- Profile information: optional profile photo and bio text.
- Content you create: recipes, cookbooks, bites, comments, reviews, posts, replies, photos you upload to those items, and direct messages you send to other users.
- Communications: any messages you send us through the in-app feedback path, email, or contact form.
- Notification preferences: your choices about which push notifications you receive and which users or conversations you have muted or blocked.
2.2 Information collected automatically
When you use Feedia, certain information is captured automatically:
- Device information: your device model, operating system and version, app version, language settings, mobile carrier, time zone, and unique device identifiers (such as the iOS Identifier for Vendor).
- Log and usage data: IP address, the dates and times of your sessions, the screens you view, the features you use, the searches you run, and similar diagnostic information collected by our servers and analytics tools.
- Approximate location: derived from your IP address. Feedia does not request access to GPS or precise device location. The location data we receive is limited to a general region (typically city or country).
- Push notification tokens: when you allow push notifications, Apple provides us a token tied to your device that we use to deliver notifications.
- Crash and error reports: when the app encounters an error, diagnostic data is sent to our error-tracking provider to help us fix the issue.
2.3 Information you grant device permissions for
Feedia requests permission to access certain device features. You can change or revoke these permissions at any time in iOS Settings.
- Microphone: used by "Cook Mode" to recognize hands-free voice commands while you cook. Audio is processed in real time and is not stored on our servers.
- Speech recognition: used in conjunction with the microphone for Cook Mode. Speech may be processed by Apple's on-device or cloud speech recognition services depending on your device.
- Push notifications: used to deliver notifications about likes, comments, follows, messages, and other activity.
- Photo library: when you choose photos to upload to a recipe, cookbook, profile, or other content, Feedia uses the iOS PhotoKit picker. This does not grant Feedia access to your entire library — only the photos you specifically select.
Feedia does not request access to your camera (photo capture), contacts, calendar, location, health data, Bluetooth, or other device features not listed above.
2.4 AI-assisted features
Feedia offers optional AI-assisted features for importing recipes. When you choose to use these features:
- Recipe URL import: the URL you paste is sent to our backend, which passes the page content to OpenAI to extract a structured recipe.
- Recipe photo scan: the photo you upload is sent to OpenAI's vision model to extract the recipe text and structure.
- Nutrition calculation: the ingredients of your recipe are sent to Spoonacular to retrieve nutrition information.
These features are opt-in. You can avoid AI processing of your content by entering recipes manually instead. We do not send your name, email, or other personal identifiers to these AI services along with recipe content.
2.5 Information we do not collect
We do not collect:
- Your phone number, mailing address, or precise GPS location.
- Payment card numbers, bank account information, or billing addresses. All purchases (including Feedia+ subscriptions) are processed by Apple through the App Store. We do not see your payment information.
- Information from data brokers, public databases, social media platforms, or other third-party data sources. We only collect information you give us directly or that is automatically generated through your use of the Services.
- Sensitive personal information such as racial or ethnic origin, religious beliefs, sexual orientation, health or medical data, biometric data, or precise geolocation.
3. How We Use Information
We use the information we collect to:
- Create and maintain your account and authenticate you when you sign in.
- Operate the Services, including delivering content, processing your recipe creations, and handling user-to-user interactions like comments, follows, and direct messages.
- Send transactional communications such as verification codes, password reset emails, security alerts, account notices, and policy updates.
- Send push notifications about activity related to your account (likes, comments, follows, mentions, messages), based on your notification settings.
- Provide customer support and respond to your questions, requests, and feedback.
- Monitor and improve the Services, including identifying usage trends, fixing bugs, and measuring feature performance.
- Detect, prevent, and respond to fraud, abuse, security incidents, and violations of our Terms of Service.
- Comply with legal obligations and respond to lawful requests from government authorities.
We do not use your information to deliver targeted advertising, to engage in cross-context behavioral advertising, to make automated decisions that produce legal or similarly significant effects, or to send marketing or promotional messages from us or any third party.
4. How We Share Information
4.1 With other users
Feedia is a social product. When you create public content or interact with other users, certain information is visible to them, including:
- Your username, display name, profile photo, and bio.
- The recipes, cookbooks, bites, comments, reviews, and other public content you post.
- Your likes, follows, reposts, and other public engagement signals.
Direct messages are visible only to the participants in that conversation. Your email address, password, date of birth, and other account credentials are never visible to other users.
4.2 With service providers
We share information with third-party service providers who process data on our behalf to operate the Services. Each provider is bound by a data processing agreement and may only use the data for the purposes we direct.
- Amazon Web Services (AWS) — cloud infrastructure, including authentication (Cognito), file storage (S3), content delivery (CloudFront), serverless compute (Lambda, API Gateway), transactional email (SES), and push-notification routing (SNS).
- PostHog — product analytics, feature flag delivery, and remote configuration.
- Sentry — application error monitoring and crash reporting.
- OpenAI — recipe URL parsing and recipe photo scanning, when you use those AI-assisted features.
- Spoonacular — nutrition data lookup, when you use the nutrition feature.
- Neon — managed PostgreSQL database hosting.
- Apple Inc. — push notification delivery (APNs) and in-app purchase processing for Feedia+ subscriptions.
- Formspree — processing of privacy contact form submissions made through feediaapp.com/contact-privacy.
4.3 For legal reasons
We may disclose information if we have a good-faith belief that doing so is necessary to:
- Comply with applicable law, a court order, or other legal process.
- Enforce our Terms of Service or other agreements.
- Protect the rights, property, or safety of Feedia, our users, or the public.
- Investigate suspected fraud, abuse, or violations of our policies.
4.4 In connection with a business transfer
If Feedia is sold, merged, or otherwise transferred to another company, your information may be transferred as part of that transaction. We will notify you (for example, by email or in-app notice) before your information becomes subject to a different privacy policy.
4.5 What we do not do
We do not sell your personal information. We do not share your personal information with third parties for their own direct marketing purposes. We do not participate in cross-context behavioral advertising. We do not share your information with business partners, affiliates, or marketing partners.
5. How Long We Keep Information
We keep your personal information for as long as your account is active. When you delete your account:
- 14-day grace period: your account is marked for deletion but can be restored within 14 days if you change your mind. During this period, your profile is hidden from other users.
- After 14 days: your account and most associated personal information are permanently deleted from our active systems.
- Anonymized tombstones: certain content that other users have already engaged with — specifically comments, reviews, and direct messages — may be retained in anonymized form to preserve conversation context. The original author's identity is removed and the content is attributed to "Deleted User." This anonymized content cannot be linked back to you.
- Legal holds: we may retain certain information longer if required by law, to comply with an ongoing legal proceeding, or to investigate a potential violation of our Terms.
Automatic analytics data collected by our service providers (such as PostHog) may be retained according to those providers' default retention windows.
6. How We Protect Information
We take security seriously and use industry-standard measures to protect your information, including:
- Encryption of data in transit using HTTPS / TLS for all communication between the Feedia app and our servers.
- Encryption of data at rest in our database and file storage.
- Password hashing and authentication managed by AWS Cognito, with a strong password policy and rate-limited login attempts.
- Role-based access controls so that only the systems that need specific data can access it.
- Rate limiting and abuse-prevention controls on our APIs.
- Continuous error and crash monitoring to detect anomalies.
No security system is perfectly safe, and we cannot guarantee the absolute security of your information. Please use a strong, unique password for your Feedia account and let us know promptly at privacy@feediaapp.com if you suspect any unauthorized access.
7. Your Privacy Rights
7.1 Rights available to everyone
Regardless of where you live, you can:
- View your information: most of your data is visible directly in the Feedia app (your profile, content, conversations, etc.).
- Edit your information: update your name, username, bio, profile photo, notification preferences, and other account settings from within the app.
- Delete your account: go to Settings → Delete Account in the app.
- Contact us: email privacy@feediaapp.com with any privacy-related question or request.
7.2 Rights for U.S. residents
Depending on the U.S. state where you live, you may have additional rights under laws such as the California Consumer Privacy Act / California Privacy Rights Act (CCPA / CPRA), Virginia Consumer Data Protection Act, Colorado Privacy Act, Connecticut Data Privacy Act, Utah Consumer Privacy Act, and similar laws in Texas, Oregon, Tennessee, Montana, Iowa, Indiana, Delaware, New Jersey, New Hampshire, Minnesota, Maryland, Kentucky, Rhode Island, and others.
These rights may include:
- Right to know / access: request a copy of the personal information we hold about you.
- Right to correct: ask us to correct inaccurate personal information.
- Right to delete: request deletion of your personal information.
- Right to opt out of sale or sharing: we do not sell or share your personal information, so this right is satisfied by default for all users.
- Right to opt out of targeted advertising: we do not engage in targeted advertising, so this right is satisfied by default.
- Right to opt out of profiling: we do not use your information for profiling that produces legal or similarly significant effects.
- Right to limit use of sensitive personal information: we do not collect sensitive personal information as defined by these laws.
- Right to non-discrimination: we will not deny you services, charge you different prices, or provide a different quality of service if you exercise any of these rights.
- Right to appeal: if we deny your privacy request, you can appeal by replying to our decision email or contacting privacy@feediaapp.com with "Privacy Appeal" in the subject line.
To exercise any of these rights, email privacy@feediaapp.com or use the contact form at feediaapp.com/contact-privacy. We will verify your identity and respond within the timeframe required by applicable law (typically 45 days, extendable to 90 days in limited circumstances).
7.3 Notice of financial incentives
We do not offer financial incentives in exchange for the collection, sale, or sharing of personal information.
7.4 Rights for residents of the European Economic Area, United Kingdom, and Switzerland
If you are located in the EEA, UK, or Switzerland, you have additional rights under the General Data Protection Regulation (GDPR) and equivalent national laws.
The legal bases on which we process your personal information are:
- Performance of a contract — processing necessary to provide the Services you have signed up for.
- Legitimate interests — running and improving the Services, keeping them secure, and preventing abuse, where these interests are not outweighed by your privacy rights.
- Consent — for optional features such as push notifications, microphone access, and AI-assisted recipe import.
- Legal obligation — complying with applicable laws and responding to lawful requests.
You have the right to:
- Access, correct, or delete your personal information.
- Restrict or object to the processing of your personal information.
- Receive a copy of your personal information in a portable format (data portability).
- Withdraw consent at any time where we rely on consent.
- Lodge a complaint with your local data protection authority.
To exercise these rights, contact privacy@feediaapp.com.
8. International Data Transfers
Feedia is operated from the United States. If you access the Services from outside the United States, your information will be transferred to, stored in, and processed in the United States. By using the Services, you understand that your information may be transferred to a country that does not have the same data protection laws as your home country. Where required by law, we rely on appropriate safeguards (such as the European Commission's Standard Contractual Clauses) for international transfers.
9. Children's Privacy
Feedia is intended for users who are at least 13 years old. We collect a date of birth at signup specifically to verify this minimum age. We do not knowingly collect personal information from children under 13.
If we learn that we have collected personal information from a child under 13, we will promptly delete the account and any associated information. If you believe a child under 13 has provided us personal information, please contact us at privacy@feediaapp.com and we will take appropriate action.
10. Cookies and Similar Technologies
The Feedia website (feediaapp.com) does not currently use cookies or web beacons to track visitors.
The Feedia iOS app uses software development kits (SDKs) provided by PostHog and Sentry that perform functions analogous to cookies on the web, such as assigning a stable device identifier to track app usage, sessions, and crashes. You can limit this tracking by enabling "Limit Ad Tracking" or denying tracking permissions in iOS Settings.
11. Do Not Track Signals
Some browsers and operating systems offer a "Do Not Track" (DNT) signal. There is currently no industry-standard interpretation of the DNT signal. The Feedia website does not respond differently to DNT signals at this time.
12. Third-Party Links and Services
The Services may include links to third-party websites or contain content that links to external sites. We are not responsible for the privacy practices of those third parties. We encourage you to read their privacy policies before sharing information with them.
13. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page. For material changes, we will provide additional notice such as an in-app message or an email to your registered address before the changes take effect. Your continued use of the Services after a change to this policy means you accept the updated policy.
14. Contact Us
Braden Ross, doing business as Feedia
Email: privacy@feediaapp.com
Contact form: feediaapp.com/contact-privacy
Mailing address: 13535 Lyndhurst Street, Apt 9109, Austin, TX 78717
We will respond to privacy-related inquiries as required by applicable law. For requests under the CCPA / CPRA and similar state laws, we will verify your identity before processing the request and respond within 45 days (extendable to 90 days where permitted). For requests under GDPR, we will respond within 30 days (extendable to 60 days where permitted).