Cero Studios

Plate & Paper Privacy Policy

Plate & Paper is designed as a private, on-device recipe library. It does not require an account, include advertising, or silently upload your cookbook.

Effective: August 25, 2026

Information Plate & Paper handles

Plate & Paper stores the recipes, notes, collections, tags, favorites, source links, meal-plan entries, shopping-list items, pantry items, cooking history, active cooking timers, and one active cooking-session draft you choose to create in the app’s private storage on your device and in its private App Group container. The active session may include the current recipe step, serving count, ingredient-prep checks, and an unfinished rating or note so cooking can resume after the app closes. Cooking history may include the serving count, rating, and note you save after cooking.

Plate & Paper does not sell personal information, track you across other companies’ apps or websites, or include third-party advertising. The production app uses RevenueCat for subscription operations. If you explicitly choose Share anonymous app usage, it also uses privacy-limited PostHog analytics to understand whether core app workflows function and where anonymous customers stop.

Recipe links and images

When you ask Plate & Paper to import a public recipe webpage, the app requests that page to look for recipe information published by the source. For supported public TikTok and YouTube links, Plate & Paper may also request the platform’s official public embed metadata. The source website or platform may receive ordinary network information, such as your IP address and request headers, under its own privacy policy. Recipe images displayed from a source URL are requested from that source or its image host.

When you choose a recipe photo or screenshot, Apple’s on-device text-recognition framework reads the image. The image and recognized text are not uploaded to a Plate & Paper-operated service in this build. Plate & Paper reports incomplete or unrecognized recipe sections for your review rather than filling them with generated content.

When you save a recipe with a selected photo, screenshot, or supported webpage image, Plate & Paper creates a size-limited normalized cover and stores it in the app’s private local storage. You can replace or remove that cover in Edit. Replacing or removing a cover deletes the previous local cover file, and deleting the recipe deletes its local cover.

Sharing and the share extension

The Plate & Paper share extension accepts a recipe link, useful text or caption, and an optional screenshot or photo only when you explicitly share them to Plate & Paper. Those related parts may be retained together as one queued capture in the app’s private App Group container so the main app can process them without discarding the fallback text or image. Image files are size-limited and remain local. After a successful save or explicit queue removal, Plate & Paper deletes the queued source image. A successfully saved recipe keeps a separate normalized local cover under the retention rules above.

Backup and restoration

When you choose Create cookbook backup or Share a household copy, Plate & Paper creates a versioned .plateandpaperbackup document on your device containing your cookbook data, kitchen data, cooking history, and normalized local covers. Backups created under the former Supperkeep name (.supperkeepbackup) and original ReciDrop working name (.recidropbackup) remain readable, so the rename does not strand an existing archive. Active cooking-session drafts, active timers, and pending share imports are temporary and are not included. Restoring a backup clears those temporary cooking states so they cannot remain attached to recipes that were replaced. The file is sent only to the destination or person you choose through Apple’s document or share interface. When you choose Restore from backup, Plate & Paper reads the document you select, checks its format and integrity, and asks for confirmation before replacing local data. Plate & Paper does not automatically upload backups or provide live cloud or household sync in this build.

Subscriptions

Purchases and subscriptions are processed by Apple. Plate & Paper receives StoreKit product and entitlement information needed to show an offer, complete or restore a purchase, and verify access. Plate & Paper does not receive your full payment-card details. Apple handles purchase information under Apple’s Privacy Policy.

Plate & Paper also sends an anonymous RevenueCat app-user identifier, App Store product identifiers, and subscription transaction information to RevenueCat so subscription delivery can be monitored and support issues can be diagnosed. RevenueCat is operational context; verified StoreKit state controls access in the app, and Apple’s App Store financial reports remain the final record of sales and proceeds. Plate & Paper disables RevenueCat’s automatic advertising-device-identifier collection and optional diagnostics.

Product analytics

Fresh installs default analytics to off. Plate & Paper does not initialize PostHog, create an analytics identifier, fetch PostHog configuration, queue an event, or send analytics unless you explicitly turn on Share anonymous app usage during onboarding or in Settings. Core features, the free allowance, and subscription access do not depend on this choice.

After that optional choice, physical App Store builds use PostHog US Cloud to collect limited Product Interaction, Other Usage Data, and a random install-level Device ID for analytics. These data are not linked to your identity and are not used for tracking. Plate & Paper does not use an advertising identifier, does not track you across apps or websites, and does not request App Tracking Transparency permission. Debug, Simulator, automated-test, TestFlight, sideloaded, and unverified distribution builds do not transmit product analytics.

PostHog creates a random anonymous identifier for this installation. Plate & Paper does not identify you to PostHog, create a person profile, or attach an account, name, email address, advertising identifier, or other contact information. Events contain a fixed Plate & Paper product marker, iOS platform marker, analytics schema version, app version/build, App Store release marker, a random session identifier, and controlled information about onboarding, import method and outcome, first value, meal planning, shopping, cooking, paywall presentation, App Store checkout result, restore, and anonymous entitlement-state transitions. Counts, progress, duration, and day offsets are sent only in coarse buckets or bounded values.

The SDK also retrieves its project configuration from PostHog’s US assets endpoint using the public project token and SDK user-agent, but only after opt-in. That request does not contain the anonymous installation identifier or cookbook content, and server configuration cannot override Plate & Paper’s local disabled-feature settings or strict event allowlist.

Recipe titles, source URLs and hosts, captions, ingredients, instructions, photos, recognized text, collection names, tags, shopping-item names, pantry contents, cooking notes, raw error messages, contact information, and exported cookbook contents are not collected. Plate & Paper removes SDK-added device model, locale, network, screen, and similar context before queueing an event. It disables session replay, screen capture, autocapture, surveys, feature flags, person profiles, advertising identifiers, tracing, crash capture, diagnostic logs, and error tracking. Every event sends $geoip_disable=true so it is not enriched with IP-derived geography. PostHog’s Discard client IP data project setting is enabled so the client IP is not retained.

Apple’s aggregated Xcode privacy report also includes capability declarations from PostHog’s linked PHPLCrashReporter component for Crash Data and Other Diagnostic Data used for App Functionality, not linked to identity, and not used for tracking. Plate & Paper therefore lists those two data types in its App Store privacy answers. Plate & Paper disables runtime crash/error capture, exception recording, and SDK diagnostic logging, and its outbound event allowlist rejects exception events; it does not intentionally transmit crash or diagnostic events at runtime.

PostHog queues accepted events in protected local storage when the network is unavailable and sends them later in bounded batches. You can withdraw consent in Settings at any time. Turning Share anonymous app usage off stops future collection and removes the local queue and anonymous installation identifier. Turning it back on is a new explicit choice and creates a different random identifier.

Previously transmitted event records remain under the former random identifier until they are removed through the PostHog account’s retention or deletion procedures. After Plate & Paper removes that identifier locally, the app cannot re-associate it with this device and therefore cannot initiate or promise device-linked deletion of those records. For questions about those records, contact apps@cerostudios.net; because Plate & Paper does not know the former random identifier after withdrawal, support may be unable to locate records from device information alone.

Retention and deletion

Saved cookbook and kitchen data remain on your device until you delete the applicable item, use Delete all data, or remove the app’s data. Completing a cooking session clears its resumable draft. Delete all data clears recipes and covers, collections, meal plans, shopping and pantry items, cooking history, the active cooking-session draft, active timers and their notifications, queued share-extension captures, the local analytics queue, and the anonymous analytics installation identifier. Your analytics on/off preference remains in place so deletion does not silently opt you back in. You can create a cookbook backup, including normalized local covers and saved kitchen data, before deletion.

Remote recipe import

This build does not configure a remote recipe-import service. If a future release sends a source URL or recipe content to a Plate & Paper-operated service, this policy and the App Store privacy disclosure must be updated before that feature is enabled.

Children

Plate & Paper is a general-audience utility and is not directed to children under 13. Plate & Paper does not knowingly collect children’s personal information.

Your choices and rights

Because recipe-library data stays on your device in this build, you can access, export, correct, or delete it directly in the app. You can decline optional analytics during onboarding, grant or withdraw consent later in Settings, and delete its local identity and pending queue. For privacy questions or a rights request concerning information you sent to Plate & Paper support, contact apps@cerostudios.net.

Contact

Cero Studios
apps@cerostudios.net