RypzyBack to rypzy.com

Privacy

Last updated 2026-08-26

Rypzy is a personal food library: you save recipes and food spots, and find them back. This page explains exactly what we store, why, where it lives, and how you get rid of it. Plain language, no lawyer-speak.

What this covers

This page covers all of Rypzy: the website on rypzy.com, the web app on app.rypzy.com, and the Rypzy app for iPhone and Android. All three talk to the same server and the same database, so everything below applies everywhere.

The app on your phone asks for nothing on the side. It does not read your location, it has no advertising identifier, it does not touch your contacts or your calendar, and it only opens your camera roll when you pick a photo yourself. What it does with a photo is exactly what the web app does.

What we store

Your account: email address, your name, and either a password (stored only as a hash — we never see the password itself) or the fact that you signed in with Google.

What you save: recipes and food spots, plus the details you add — ingredients, steps, cuisine, city, your own tags, collections, notes and scores, and whether you cooked or visited something.

Photos you upload, and thumbnails we mirror from a source page so a saved link has an image.

Your profile: handle, bio, and whether it is private or public. Private is the default.

Who you follow and who follows you, and invitations you send.

If you report something or block someone: what you reported, the reason, and anything you typed to explain it.

Technical, for security: with every sign-in we store the IP address and the browser or app you used, and we count requests per account and per IP address so nobody can hammer the service.

Where it lives

The database runs on Neon in Frankfurt (eu-central-1). Photos live in Cloudflare R2. The app itself runs on Cloudflare Workers, deliberately pinned to the same European region as the database.

Nothing is stored outside the EU by design. Where a third party is involved, it is named in the next section.

Who else is involved

Cloudflare — hosting, photo storage and sending the emails below.

Neon — the database.

PostHog (European servers) — product analytics: which pages get used and which errors happen. Requests go through our own domain, so no third-party analytics domain is contacted from your browser. When you are signed in, your user id, name and email are attached so we can support your account. The address of the page you are on travels with it, and in your library that address contains whatever you typed in the search box.

Google — the Places API, used to look up a restaurant when you attach one to a saved place. Google sees that search term. If you sign in with Google, Google also confirms your identity to us.

Google, once more, for photos of restaurants: those stay on Google’s servers because their terms do not let us copy them, so your browser fetches such a photo straight from Google. Photos from Instagram or TikTok we do copy to our own storage, so there your browser contacts nobody.

CARTO — the map background on the map page. Your browser fetches the map tiles from them, so they see your IP address and which part of the map you are looking at. No key, no account, and they get nothing else from us.

When you save a link, we fetch that page once to read its title, image and recipe data. That website sees a request from us, not from you.

OpenRouter — when you save a link whose page does not spell out the recipe itself (a reel, a post with the recipe in the caption), the text of that page or caption is sent to OpenRouter, which routes it on to a language model that reads the recipe out of it. That text leaves the EU. Nothing about your account travels with it: no name, no email address, no user id, and nothing else you saved.

Google, a third time, for a recipe you photograph: the photo itself is sent to Google’s Gemini, and the photo is the entire request — no sentence about you is attached to it. That happens on Google’s own servers, outside the EU, and only when you take that photo yourself.

Cookies

A session cookie, so you stay signed in. Without it there is no account.

A language cookie, remembering whether you chose English or Dutch.

Analytics cookies from PostHog, as described above.

No advertising cookies, and nothing is sold or shared with advertisers.

Email we send you

Only about your account: confirming your address, and resetting your password. These are service messages and have no unsubscribe link — you cannot opt out of your own password reset.

If you joined the waitlist, that is separate: it is marketing, you asked for it, and you can unsubscribe from it at any time.

Sharing is something you do, not us

Your library is private by default. An item becomes visible to others only when you put it on your profile, or when you create a share link for it.

A share link works for anyone who has it, so treat it as public. You can revoke it at any time, and the link stops working immediately.

Sharing one item never opens the rest of your library.

Deleting your account

You can delete your account yourself, in the app, from your profile settings. It is then scheduled for deletion with a grace period of exactly 14 days, so a mistake or an angry evening is recoverable.

Can you no longer sign in? On rypzy.com there is a page for exactly that, “Delete your account”, with the address you can email us at. We then put in the same request for you, with the same 14 days.

The moment you ask, you are gone for everyone else: your profile can no longer be opened, your experiences disappear from your friends’ activity, and nobody can follow you. During those 14 days a bar sits on every page in the app with the date and a button to keep the account after all. One tap and the deletion is off — that is the only way to cancel it, so signing in on its own changes nothing.

After 14 days a daily job permanently removes your account, everything in your library, and your photos — the rows in the database and the files in storage, not a flag on a row. We keep no copy of our own. Our database provider holds recovery points for a short period, as any database does; those expire on their own and we do not use them to bring an account back.

Your rights

Under the GDPR you can ask what we hold about you, have it corrected, have it deleted, receive a copy, or object to how we use it. Most of it you can already see and edit in the app itself, and deletion is a button.

You have the right to a copy of your own data — everything you put into Rypzy, in a file you can read and take elsewhere: your account details, your saved items with their notes and tags, your collections, your experiences with their scores, and your photos. There is a button for it on your profile page, which hands you the file on the spot. You can also ask us, and then you get it free of charge within a month.

That file also names the people you are connected to, because a relationship cannot be exported without saying who is on the other end: the handle of everyone you follow and everyone who follows you — including handles of accounts that are private — whether a follow request is still waiting, and, for an item someone shared with you, their name. It is nothing you cannot already see in the app, but it does become something you are carrying around: treat the file as personal and do not forward it.

Your photos are in it as links, not as copies. Such a link asks us for permission again every single time it is opened, so passing the file on does not pass on your photos. One exception, and it is not a new one: a photo on an item you currently have a share link for stays openable, exactly as that share link already made it. The share links themselves are deliberately left out of the file — those are keys, and a key does not belong in an export.

For anything else, email contact@rypzy.com. You also have the right to complain to the Autoriteit Persoonsgegevens, the Dutch data protection authority.

Changes

If this page changes in a way that matters, the date at the top changes with it, and we tell you in the app or by email.