Chive
⌘K
How it worksLog inSign up free

Menu

Find recipes→Sources→
Sign in

Privacy

How we handle your Chive data

Last updated September 28, 2026

Who we are

Chive is operated by Parry Technology and Media LLC, a District of Columbia limited liability company doing business as Chive. In this policy “Chive,” “we,” and “us” mean that company. This policy covers the Chive website at chive.recipes, the Chive iOS app, the Chive browser extensions, and Chive by text. Chive is operated from the United States, and your information is processed there.

The short version

You can search recipes without an account. If you make one, we store what the features need — your saved recipes, lists, plans, and anything you import — and we delete it when you delete your account. If you join a kitchen, your household shares a grocery list and meal plan; your saved recipes, private imports, and food profile stay yours alone. If you leave personalization on, Chive learns from what you do in Chive — including what you search for — to rank results and your Home feed for you; you can turn it off or clear what it has learned at any time. We keep first-party measurements of how Chive is used so we can make it simpler, stored under random identifiers rather than your name, and we keep short-lived security records so nobody can abuse the service. We do not sell your personal information, we do not share it for cross-context behavioral advertising, and we do not show you advertising inside Chive. The iOS app contains no third-party analytics or advertising software. The website does use Google Analytics and Google Ads, but only after you opt in.

What we use information for

Everything described in this policy is used for one or more of these purposes, and for nothing else:

  • To run the features you use — search, saving, lists, plans, kitchens, imports, and signing in.
  • To personalize Chive for you, when you leave personalization on: ranking results, suggestions, and your Home feed around your food profile and what you save, cook, plan, and search for.
  • To measure and improve Chive: understanding in aggregate which pages, screens, and controls people use, where they get stuck, how fast things are, and what breaks.
  • To keep Chive secure and fair: protecting accounts, preventing fraud, filtering automated traffic, and enforcing usage limits so the service stays available for everyone.
  • To communicate with you about your account: login codes, replies when you contact support, and notices about changes to Chive or these policies. We do not send marketing email.
  • To meet legal obligations and to enforce our Terms of Service.

We do not use your information for a new purpose without telling you first, and where the law or Apple’s App Store rules require it, without asking for your permission.

Account and sign-in

Signing in stores your name and verified email address. You can sign in with Apple, with Google, or with a one-time code sent to your email. Apple and Google tell us only what you approve; if you use Sign in with Apple and choose Hide My Email, we receive Apple’s relay address and never see your real one. One-time login codes are delivered by Resend on our behalf; a code expires after a few minutes and is stored only as a hash in Chive’s database. Resend also retains the delivered message and delivery logs under its standard 30-day retention. We store session records so you stay signed in. A session record includes your IP address and browser or app user agent for account security and fraud prevention. Sign-ins started by the browser extension’s account-connection flow omit both fields. Sessions expire after 30 days and are then deleted by our daily cleanup. We also count sign-up and sign-in attempts in short windows to limit abuse, as described under keeping Chive secure and fair. We count new accounts and active accounts in aggregate to understand how Chive is growing.

If you choose Google Sign-In, Google’s iOS sign-in software may process your name, email address, phone number, user and device identifiers, coarse location inferred from your IP address, usage data, and other sign-in data to provide and protect that feature. Chive receives the identity result needed to create or access your account; we do not use this information to track you across other companies’ apps or websites.

Your food profile

Our Consumer Health Data Privacy Policy describes health-related information and how to exercise your rights concerning it.

If you set up a profile, you can describe how you eat in your own words — allergies, restrictions, who you cook for, what you avoid. We store that description encrypted, and we derive a structured version of it (things like diets, disliked ingredients, and household size) to shape your results. Because this can describe allergies and dietary needs, we treat it as health-related information and handle it accordingly.

To turn your description into those structured preferences, we send up to 4,000 characters to OpenAI using a request configured not to save the response for later retrieval. This does not eliminate all provider retention: temporary prompt caching can last up to 24 hours. The editor tells you about the AI processing before you submit. OpenAI may retain API data for up to 30 days for abuse monitoring under its standard controls, does not use API data to train its models by default, and is not opted in to receive Chive inputs or outputs for model improvement. If OpenAI is unavailable, Chive uses a simpler parser on our own systems. You can turn personalization off, edit or clear the description, or delete the profile entirely from Settings in the app or Preferences on the web.

Saved recipes, lists, and plans

We store the recipes you save, the collections you put them in, the meals you mark as made, your grocery lists including any items you type yourself, and your meal plan, along with any daily calorie or protein targets you set for planning. Grocery lists also record which recipe an ingredient came from so quantities can be combined. When you open a grocery list, the installed web app may keep the most recently opened list in private browser storage for read-only offline access; signing out or deleting your account asks the browser to clear that copy. The iOS app keeps a small offline copy of your recent library and lists on the device; it is cleared when you sign out or delete your account.

Kitchens: sharing with your household

A kitchen lets a household share a grocery list and a meal plan. You can belong to one kitchen at a time. You join by entering an invite code, which expires, can be used a limited number of times, and can be revoked by the person who created it. Before you join, the invite screen shows you the kitchen’s name and the first names of its current members so you know where you are going.

What everyone in your kitchen can see:the shared grocery list and its history, including every item, quantity, and recipe added to it and whether each item is checked off; meal-plan entries you mark for the household; and, for each item, who added it and who checked it. Members also see each other’s name, profile picture, role, and when they joined. Members do notsee each other’s email addresses.

What stays private to you, even inside a kitchen: your saved recipes and collections, your private recipe imports (unless you put one on the kitchen’s shared plan or grocery list, which lets members open it), your food profile, your cooking history, and any grocery list or meal-plan entry you keep personal rather than household. You choose per list and per plan entry whether it goes to the kitchen or stays yours.

Leaving a kitchen and deleting your account. If you leave a kitchen, shared items and plan entries stay with its remaining members. Deleting your account also removes the items and plan entries you created, even if another member later edited them. Text you wrote on another member’s item is removed with that item. Your recipe contributions are removed from combined grocery quantities and carried items; other members’ independent contributions stay. Private recipes you created and their derived versions are deleted even if you shared them with a kitchen. If you own the kitchen, you must hand it to another member before leaving. When you delete your account, ownership passes to the longest-standing member. If you are the last member, the kitchen and everything in it is deleted.

Private recipe imports

Chive can build a private recipe from a photo, from text you paste or type, or from dictation. Before importing or saving recipe changes that need AI, we ask for your consent to a versioned disclosure covering the selected sources, temporary audio, extraction, nutrition checks, search indexing, and optional covers. Older disclosures do not authorize this expanded processing. What happens depends on which you use:

  • Photos. One to three images are uploaded to private storage operated by Vercel.
  • Pasted or typed text. We retain the source text you provided.
  • Dictation. The recording is sent to OpenAI to be transcribed and is discarded after the request. The transcript is then treated like pasted text.

We send the source to OpenAI to extract recipe facts and cooking directions, process the ingredients to estimate nutrition, and may send recipe facts to OpenAI to generate a clearly labeled cover image. We also send OpenAI a compact version of each kept private recipe to create an embedding, a numeric representation of its meaning used to retrieve it later. That compact version contains the recipe name, summary, ingredient names, and broad cuisine, dish, occasion, technique, and diet labels; it excludes cooking directions, the original media, publisher and author names, ratings, and nutrition.

OpenAI and Anthropic may also receive recipe and ingredient facts for nutrition verification and recipe categorization. Turning off AI recipe processing stops new requests, including queued import, cover, nutrition, and indexing work. A request already sent may finish; withdrawal does not undo earlier processing or delete saved recipes. Deletion is a separate control.

Private imports stay linked to your account and are never added to Chive’s search, feeds, or listings. Each one has its own link, which cannot be guessed. If you share that link, anyone who has it, including anyone they forward it to, can open the recipe’s name, cover, ingredients, cooking steps, nutrition, and times; signed in, they can also save it or add it to their plan or groceries. They do not see your name or your original photos or text. Only you can edit the recipe, and deleting it removes it for everyone. They remain until you delete the recipe or your account. An upload you never submit is scheduled for deletion after 24 hours. You can withdraw consent for new AI imports at any time in Settings; recipes already in your account keep working.

Recipes from links

If you share a recipe-page, TikTok, Instagram, YouTube, or Pinterest link with Chive, we fetch that public page to extract the recipe and store the result against your account. We do not connect to your social accounts, and we receive nothing from those services about you. The publisher or platform sees an ordinary request from Chive’s servers, never your Chive account. When you import a public recipe page, the recipe and URL import records do not identify who submitted them. Website import limits use a separate short-lived hashed counter. Recipes you explicitly import into your account remain in your library.

Recipe links you text us

If you text a recipe link to Chive’s number, we receive your phone number and the message you sent, delivered through Twilio. We store the phone number encrypted, along with the request and our reply, so the conversation works and so we can honor a stop request. Standard message and data rates from your carrier apply.

Browser extensions

With automatic cards enabled, Chive checks the address of each HTTP or HTTPS page for an existing public recipe. A match returns its card without uploading page content. On a miss, pages with Recipe markup or visible ingredient and instruction sections send a bounded recipe snapshot for extraction and nutrition calculation. Other pages are checked by address only until you manually choose to find a recipe. These features work with or without sign-in. Forms, editable fields, hidden content, comments, and navigation are excluded from the snapshot. Raw snapshots are removed after processing or within 24 hours.

Imported recipes are public in Chive. Lookup, import, polling, and retry requests do not send account tokens, cookies, a device identifier, or an anonymous browser identifier. Known URL tracking parameters and fragments are removed before transmission. Chive does not retain address checks as browsing history or store who imported a public recipe. Work limits are shared per recipe page, independent of the requester. Nothing is added to your library, groceries, or meal plan until you choose that action.

If you connect an account, the extension stores a revocable access token locally. Chive stores only its hash, browser connection type, expiry, and last-use time. The token accompanies explicit account actions, such as saving a recipe or adding groceries or a meal. You can revoke the connection from Settings and turn automatic cards off in the extension’s options. On iPhone, the Safari extension uses the Chive app’s sign-in instead: the app requests the token and keeps it on your phone, signing out of the app revokes it, and automatic cards are switched on and off in the app under Profile → Safari extension. The extension does not access your browser’s history database.

Sign-ins started to connect the extension omit IP addresses and user agents from Chive’s session records. We limit those sign-in requests using a short-lived random cookie, a hashed email address, and overall sending limits. Our hosting provider, Vercel, still processes IP addresses for network security, including protection against denial-of-service attacks. These application changes do not disable that infrastructure processing or delete older session records before their normal expiry.

Chive’s use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.

Recipe search

If you choose AI search, Chive sends the complete phrase you search for to OpenAI, which returns an embedding: a numeric representation used to compare the search with recipes. We store the normalized phrase and embedding in a shared cache so repeated searches do not require another OpenAI request. Cache entries are scheduled for deletion 30 days after they are first created and are not used after that point.

The shared cache row does not contain a Chive account ID. Search phrases can nevertheless reveal dietary, allergy, religious, or health preferences, so do not put information in a search that you do not want processed this way. OpenAI may retain API data for up to 30 days for abuse monitoring under its standard API data controls; it does not use API data to train its models by default. You can decline or withdraw AI search and continue browsing categories and saved recipes. Chive does not prefetch your typed searches before you agree. AI-search consent is separate from optional analytics.

Measurement and analytics

We want to know which parts of Chive people use, which they ignore, and where they get stuck, so we can make the product simpler. This section explains what that measurement looks like, what it will never do, and how to turn it off.

What we record. Chive keeps first-party records of how it is used: which pages and screens are opened, which buttons and controls are tapped, searches and how many results they return, which recipes are opened and which publisher links are followed, how features such as imports progress and whether they succeed, and errors and response times. Each record carries the surface it came from, a timestamp, and technical details such as app version, a coarse browser and device category (for example, Safari on iPhone), how you arrived on the website, and server processing time. Today this consists mainly of search and recipe-click measurement plus visits to our home page; we expect to add screen-level and control-level events over time, and this policy covers them.

Usage identifiers.Optional usage events use a random per-install identifier in the app or an analytics cookie on the website, along with search-session identifiers. These are pseudonymous, not anonymous: app requests can carry the identifier alongside a signed-in session. We do not use Apple’s advertising identifier or fingerprint devices. These identifiers are never linked to advertising networks.

Search text. Usage records from the iOS app never contain the text of your search. On the website, if you allow analytics, we also store the search text and the structured criteria we parsed from it so we can improve relevance. The separate semantic-search cache described above stores normalized search phrases from both the app and the website for up to 30 days after you opt in to AI search, independently of your analytics setting.

What we never do with it.We do not use usage records to show you advertising, we do not sell them, and we do not combine them with data from other companies’ apps, websites, or offline sources. This is not “tracking” as Apple defines it, and the app does not ask for App Tracking Transparency permission because there is nothing to consent to. The iOS app contains no third-party analytics or advertising software. If we ever add an analytics provider or software development kit to the app, we will update this policy and the app’s App Store privacy label before it ships. We may use a service provider to store or analyze these records on our behalf; any such provider will be listed in the processors table below before it receives anything, and will be bound by contract to use the records only for our purposes.

On the website only. If you opt in through the cookie banner, we use Google Analytics for site analytics and Google Ads to measure conversions from our own advertising, which includes storing Google click identifiers such as gclid, gbraid, and wbraid. None of this runs in the iOS app. If you do not opt in, neither is loaded.

Your controls.Optional usage statistics are off until you choose to share them. In the app, use “Share usage statistics” under Profile → Account & privacy. Turning it off removes the install identifier and stops optional usage events. On the website, the cookie banner controls optional page and search-funnel measurement, Google Analytics, and Google Ads. Usage and consent records are scheduled for deletion after 180 days. Essential authentication, abuse-prevention, error, and service-operation records remain separate; their purposes and retention are described in this policy. Aggregate statistics that cannot be tied back to you may be kept longer.

Personalized results

Personalization is on by default when you create an account. While it is on, Chive may learn from what you do in Chive and use it to rank your search results, shape your Home feed, and choose suggestions for you. The signals it can draw on are: what you save and unsave, mark as made, like or pass on, open, and follow to the publisher; your grocery lists and meal plan, including any daily targets you set; your food profile; and what you search for — both the ingredients, cuisines, dishes, proteins, and diet terms we parse out of your searches and the search phrases themselves. We turn this activity into weighted preferences, looking back about 180 days for those preferences and about 30 days for recipes you recently made. Not every signal is in use at all times, and which ones are active changes as we tune Chive, but they all live under the same controls below. Search-based learning is stored with your learned activity, separately from the usage measurements described above, and none of it is used for advertising or shared with anyone.

To keep Home fresh we also remember what it has shown you for 14 days and each day’s lineup for 30 days.

You can turn personalization off at any time, which stops Chive from using what it has learned; clear what has been learned while keeping your saved recipes and grocery lists; or delete your account. Learned activity and preference weights are scheduled for deletion after 180 days even if you do not clear them yourself.

Keeping Chive secure and fair

Chive is free, and every search and import costs real money to run, so we protect it from automated abuse and keep it fair for everyone. To do that:

  • Session records keep your IP address and user agent for ordinary website and mobile sign-ins for up to 30 days. Sign-ins started to connect a browser extension omit both.
  • Usage limits. We count requests over short windows — a minute, an hour, or a day — per account, per app install, or, when you are signed out, per network address and browser type. Extension recipe imports use a shared limit per recipe page with no requester identity. Extension sign-in uses a short-lived random cookie and hashed email, and explicit account actions use the account. This covers things like login-code requests, searches, imports, dictation, and other API calls. The counters are keyed by a one-way hash made with a secret, so the table never holds a readable address or account ID, and rows are deleted after two days. Some features also have daily caps per account, such as the number of imports you can start. When you reach a limit, Chive asks you to try again later.
  • Automated traffic.We tell bots and headless browsers apart from real visitors so that they do not distort our measurements or consume the service, and app requests must carry the app’s own signature.
  • Investigations. If we investigate a specific abuse incident, security event, or legal claim, we may keep the records connected to it for as long as that matter requires, and we may suspend or close accounts as described in the Terms.

We use these signals only for security, fraud prevention, and fair use of the service — never to build a profile of you and never for advertising. Security and fraud-prevention use of this kind is not tracking under Apple’s rules.

Companies that process data for us

We use these providers to run Chive. Each receives only what its job requires, none is permitted to use your information for its own purposes, and each is required to protect it at least as well as this policy describes.

ProviderWhat it handles
VercelWebsite and app hosting, and private storage for imported photos
NeonThe database holding your account and content
RailwayBackground recipe-import and nutrition workers, including private source content when you import a recipe
Apple, GoogleSign-in, when you choose one of them
ResendSending one-time login codes
OpenAIStructuring food profiles, creating search and recipe embeddings, reading imported recipes, transcribing dictation, generating covers, and proposing or adjudicating additional nutrition review
AnthropicCategorizing recipes and performing independent nutrition verification, including private imports
TwilioDelivering and receiving recipe text messages
Google Analytics, Google AdsWebsite measurement only, and only if you opt in

For a recipe that needs additional nutrition review, the worker may send structured recipe, ingredient, and nutrition facts directly to OpenAI for proposal or adjudication and directly to Anthropic for independent verification. This can include a private recipe you imported, but does not include your Chive account ID. Under their standard API terms, OpenAI may retain API data for up to 30 days for abuse monitoring, while Anthropic says it deletes API inputs and outputs within 30 days. Either provider may keep limited data longer when required by law, needed to enforce its usage policies, or governed by different contract controls.

If we add a provider — for example to store or analyze usage measurements on our behalf — we will add it to this table before it receives any data. We do not share your information with anyone else except to comply with the law, to protect Chive or its users, or as part of a sale or reorganization of the business, in which case this policy would continue to apply to it.

How long we keep things, and deletion

Account content stays until you remove it or delete your account. Deleting your account removes the account, profile, saved recipes, cooking history, grocery lists, meal plans, private imports, learned preferences, Home history, and extension connections. This includes private recipes created from typed or pasted text, camera or photo imports, and audio dictation, along with source text, transcripts, components, derived versions, and your recipe variations. Original public web and social recipes remain in the catalog without your account associations. Your authored Kitchen content is removed as described above. Private uploaded photos and generated covers are queued for a storage sweep after a 20-minute grace period to catch uploads already in progress; failed sweeps are retried. Signing out or completing account deletion also clears personal drafts, recent searches, cached content, temporary media, and pending actions from the iOS device. Signing back in restores server data, not discarded drafts or pending actions. If you signed in with Apple we ask Apple to revoke the token as part of the same flow. Unsubmitted photo uploads are deleted after 24 hours. Normalized search phrases and their embeddings are scheduled for deletion 30 days after first being cached. OpenAI may retain API data for up to 30 days for abuse monitoring under its standard controls; Anthropic says it deletes API inputs and outputs within 30 days under its standard controls, subject to its stated legal, safety, and contractual exceptions. Expired sessions, including their IP address and user agent, and expired one-time-code records are deleted by the daily retention job. Hashed usage-limit counters are deleted after two days. Learned activity and preference weights, first-party usage and page-visit records, consent events, install identifiers in those records, and server timing diagnostics are scheduled for deletion after 180 days; Home feed history after 14 days. Some records with an independent purpose are kept longer, such as message logs needed to honor a stop request or records connected to an open abuse or legal matter. Our service providers may retain limited logs or backup copies for their stated security, continuity, and deletion periods. We may retain de-identified, aggregated statistics that cannot be tied back to you.

You can delete your account yourself, without contacting us, from Profile → Account & privacy in the iOS app or Preferences on the web.

Kitchen safety reports and blocks

When you report shared content, we keep your report, your account ID, the kitchen ID, and the reported member ID when supplied so support can investigate. Reports are not shown to other members. Resolved reports are deleted after 180 days; unresolved reports remain until reviewed. Account deletion removes account identifiers from the report, but report text may remain until that retention period ends.

A block records the two account IDs and prevents the accounts from sharing a kitchen. Owners remove the blocked member; other members leave immediately. Blocks remain until removed or an account is deleted. Contact support@chive.recipes for help with a report or block.

Your choices

  • Turn “Share usage statistics” off in the iOS app under Profile → Account & privacy.
  • Change cookie and advertising consent from the website footer.
  • Turn personalization off, or clear what has been learned.
  • Edit or clear your food profile, or delete it entirely.
  • Withdraw consent for new AI recipe imports.
  • Delete an individual private recipe.
  • Turn a browser extension’s automatic cards off, or revoke its connection. For Safari on iPhone, use Profile → Safari extension in the Chive app, or sign out of the app.
  • Reply STOP to any Chive text message.
  • Delete your account and everything in it.

Your California privacy rights

If you live in California, the CCPA as amended by the CPRA gives you the rights below. We honor them for everyone, not only California residents.

What we collect. In the last twelve months we have collected identifiers (name, email address, phone number if you text us, and account and install identifiers), commercial information (recipes saved, lists, plans), internet activity (searches, page and screen views, and interactions within Chive, and IP address in session and security records), health-related information you choose to give us in your food profile, and user content you import. We collect it from you directly and from your use of Chive. We use it for the purposes listed at the top of this policy: to provide, personalize, improve, and secure the service, and to measure our own advertising on the website.

We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We have not done so in the preceding twelve months, and we do not knowingly sell or share the personal information of anyone under 16. Because we do not sell or share, there is nothing for a Global Privacy Control browser signal to opt you out of; your cookie choices in the website footer control website analytics and advertising measurement.

Sensitive information. The food profile can contain health-related details. We use it only to provide the service you asked for — personalizing recipes — and not to infer characteristics about you. That use falls within the CCPA exemption, so no limitation right applies, but you can delete the profile at any time.

Your rights. You may request to know what we collect and why, to receive a portable copy, to correct inaccurate information, and to delete your information. You may also opt out of the website analytics and advertising described above at any time. We will not discriminate against you for exercising any of these rights.

How to exercise them. Most are immediate and self-service: delete your account, clear your profile, or change consent from within Chive. For anything else, email support@chive.recipes. Because Chive operates exclusively online and deals with you directly, email is our designated method for these requests. We verify a request by confirming control of the account’s email address, and we respond within 45 days. An authorized agent may act for you with written permission we can verify.

Children

Chive is not for children under 13, and you must be at least 13 to create an account. We do not knowingly collect personal information from a child under 13. If you believe a child has given us information, email us and we will delete it.

Security

Traffic is encrypted in transit, your profile description is encrypted at rest, phone numbers are encrypted, login codes and extension tokens are stored only as hashes, and usage-limit counters are keyed by one-way hashes. No service can promise perfect security, but we design to keep the sensitive parts unreadable even to us wherever we reasonably can.

Changes to this policy

We will update this page when what we do changes, and we will move the date at the top. If a change materially affects how we handle information you have already given us, or uses it for a new purpose, we will give notice in the product before it takes effect.

Contact us

Email support@chive.recipes. Our Terms of Service cover the rest of the relationship, and /bot explains how we index recipes published on other sites.

Back to Chive
Chive

Find food that fits your life.

Recipe nutrition is shown as published or estimated from ingredients. Chive provides general information, not medical advice. For medical conditions, follow your doctor or registered dietitian.

© 2026 Chive, a service of Parry Technology and Media LLC·Sources·For creators·Privacy·Consumer Health Data Privacy·Terms·Support·Text a recipe··For site owners