Privacy
Last updated 2026-07-29
Rypzy is a personal food library: you save recipes and food spots, and find them back. This page explains exactly what we store, why, where it lives, and how you get rid of it. Plain language, no lawyer-speak.
What we store
Your account: email address, your name, and either a password (stored only as a hash — we never see the password itself) or the fact that you signed in with Google.
What you save: recipes and food spots, plus the details you add — ingredients, steps, cuisine, city, your own tags, collections, notes and scores, and whether you cooked or visited something.
Photos you upload, and thumbnails we mirror from a source page so a saved link has an image.
Your profile: handle, bio, and whether it is private or public. Private is the default.
Who you follow and who follows you, and invitations you send.
Where it lives
The database runs on Neon in Frankfurt (eu-central-1). Photos live in Cloudflare R2. The app itself runs on Cloudflare Workers, deliberately pinned to the same European region as the database.
Nothing is stored outside the EU by design. Where a third party is involved, it is named in the next section.
Who else is involved
Cloudflare — hosting, photo storage and sending the emails below.
Neon — the database.
PostHog (European servers) — product analytics: which pages get used and which errors happen. Requests go through our own domain, so no third-party analytics domain is contacted from your browser. When you are signed in, your user id, name and email are attached so we can support your account.
Google — the Places API, used to look up a restaurant when you attach one to a saved place. Google sees that search term. If you sign in with Google, Google also confirms your identity to us.
When you save a link, we fetch that page once to read its title, image and recipe data. That website sees a request from us, not from you.
Cookies
A session cookie, so you stay signed in. Without it there is no account.
A language cookie, remembering whether you chose English or Dutch.
Analytics cookies from PostHog, as described above.
No advertising cookies, and nothing is sold or shared with advertisers.
Email we send you
Only about your account: confirming your address, and resetting your password. These are service messages and have no unsubscribe link — you cannot opt out of your own password reset.
If you joined the waitlist, that is separate: it is marketing, you asked for it, and you can unsubscribe from it at any time.
Sharing is something you do, not us
Your library is private by default. An item becomes visible to others only when you put it on your profile, or when you create a share link for it.
A share link works for anyone who has it, so treat it as public. You can revoke it at any time, and the link stops working immediately.
Sharing one item never opens the rest of your library.
Deleting your account
You can delete your account from your profile settings. It is then scheduled for deletion with a 14-day grace period, so a mistake or an angry evening is recoverable — sign back in within those 14 days and the deletion is cancelled.
After 14 days a daily job permanently removes your account, everything in your library, and your photos. That is not a flag in the database; the rows and the files are gone.
Your rights
Under the GDPR you can ask what we hold about you, have it corrected, have it deleted, or receive a copy. Most of it you can already see and edit in the app itself, and deletion is a button.
You also have the right to complain to the Autoriteit Persoonsgegevens, the Dutch data protection authority.
Changes
If this page changes in a way that matters, the date at the top changes with it, and we tell you in the app or by email.