Privacy Policy
Effective date: June 12, 2026. This notice explains how Punkin handles personal data when you use the website, mobile app, browser extensions, and related services.
Who We Are
Punkin is a recipe capture, meal planning, and shopping list service. For this policy, “Punkin,” “we,” “us,” and “our” refer to the operator of Punkin at punkin.top. You can contact us about privacy at privacy@punkin.top.
Information We Collect
We collect information you provide or create in the service:account information, such as your name, email address, avatar, authentication identifiers, and household membership;
recipe, meal plan, shopping list, nutrition goal, household invite, and feedback content you enter or generate;
recipe-page content captured by the browser extension when you choose to save a recipe, including the page URL, page title, recipe HTML, JSON-LD recipe data, and candidate image URLs;
usage and technical information, such as request metadata, device or browser type, logs, error reports, security events, and approximate timestamps.
We do not intentionally collect payment card data, government ID numbers, health records, or other sensitive personal data. Nutrition targets and meal preferences can reveal information about your lifestyle, so only add information you are comfortable storing in the service.
How We Use Information
We use personal data to:provide accounts, authentication, and household access;
save, normalize, search, edit, rate, and display recipes;
generate meal plans, shopping lists, nutrition estimates, and related recommendations;
send service communications, household invitations, security notices, and support responses;
detect, prevent, and investigate misuse, fraud, security incidents, and technical failures;
improve reliability, debugging, product quality, and user experience.
Legal Bases for EU and UK Users
Where EU or UK data protection law applies, we rely on these legal bases:Contract: to create and operate your account and provide the core service features you request.
Legitimate interests: to secure the service, prevent abuse, debug errors, improve features, and respond to support or feedback, balanced against your rights and expectations.
Consent: where we ask for optional permissions or optional processing, such as browser extension access initiated by you.
Legal obligation: where we must keep records or respond to lawful requests.
Browser Extension
The browser extension only captures a page when you choose to save a recipe. It sends recipe-page data to Punkin so the service can extract and normalize the recipe into your library. The extension stores a short-lived authentication token in browser extension storage. It does not store your primary sign-in credentials.
Cookies and Local Storage
Punkin and its authentication providers use cookies, browser storage, and similar technologies that are necessary to sign you in, keep you signed in, protect accounts, remember app state, and operate the service. The browser extension also uses extension storage for short-lived authentication state and related extension settings. We do not use third-party advertising cookies.
AI and Recipe Processing
Punkin may use automated processing and AI providers to parse recipe pages, estimate nutrition, normalize ingredients, derive tags, and assist with meal planning. Inputs can include recipe content, URLs, ingredients, instructions, and related context needed to perform those tasks. Do not submit private or sensitive information inside recipe or feedback fields unless you want it processed for the service.
Sharing and Processors
We share personal data only as needed to run the service, comply with law, or protect users and the service. This can include:authentication providers, such as Clerk, for sign-in and account identity;
hosting, database, logging, analytics, and infrastructure providers;
AI and recipe-processing providers used to parse and enrich recipe content;
email providers used for invitations, notifications, and support;
other members of your household workspace, who can see shared household recipes, meal plans, shopping lists, and related activity.
We do not sell personal data. We also do not use recipe, meal plan, or shopping list content for third-party advertising.
International Transfers
Punkin and its service providers may process data in countries other than where you live, including the United States. Where required, we rely on appropriate safeguards such as contractual protections, standard contractual clauses, adequacy decisions, or other lawful transfer mechanisms.
Retention
We keep personal data for as long as needed to provide the service, maintain your account, comply with legal obligations, resolve disputes, and protect the service. Account content such as recipes, meal plans, shopping lists, household records, and feedback is kept until deleted, replaced, archived, or no longer needed. Security, diagnostic, and operational logs are kept for a limited period appropriate to their purpose.
Your Choices and Rights
Depending on where you live, including if you are in the EU or UK, you may have rights to access, correct, delete, restrict, object to processing of, or receive a portable copy of your personal data. Where processing is based on consent, you may withdraw consent at any time without affecting processing that already happened.
To make a request, contact privacy@punkin.top. We may need to verify your identity before acting on a request. You can also contact your local data protection authority if you have concerns about how we handle your information.
Security
We use technical and organizational measures designed to protect personal data, including encrypted transport, authenticated API access, access controls, and operational monitoring. No online service can guarantee absolute security, so please use a strong account password and protect access to your email and devices.
Children
Punkin is not intended for children under 13, and we do not knowingly collect personal data from children under 13. If you believe a child has provided personal data, contact us so we can take appropriate action.
Changes
We may update this policy from time to time. If changes are material, we will provide reasonable notice, such as through the website, app, email, or store listing. The effective date at the top shows when this policy was last updated.