Home/Legal/Privacy Policy

Privacy Policy

Service provider: Quarter Kitchen LLC
Last updated: August 4, 2026

1. What We Never Do

Before anything else, here is what Quarter will never do with your data:

  • We will never sell your personal information to anyone, for any reason.
  • We will never share your data with advertisers, data brokers, or any third party for marketing purposes.
  • We will never use tracking pixels, retargeting cookies, or behavioral profiling for advertising.
  • We will never serve ads on Quarter. There are no ads and there will never be ads.
  • We will never send you marketing emails, newsletters, or promotional digests.
  • We will never use third-party analytics cookies.
  • We will never monetize your data in any way. Our revenue comes exclusively from subscriptions.

These are binding commitments, not aspirations. They are incorporated into our Terms of Service.

2. Information We Collect

2.1 Account Information. When you create an account, we collect:

  • Email address (for authentication and essential transactional communications)
  • Date of birth (for age verification — 13+ account creation, 21+ alcohol content access)
  • Display name / username (for community attribution)
  • Password (stored only in hashed form — we cannot see your password)

2.2 Content You Create. Recipes, photographs, comments, ratings, cook feedback, meal plans, shopping lists, pantry data, and tag suggestions.

2.3 Interaction Data. We log how you use the app (page views, saves, cooks, searches) to improve the Service. This data is stored in Quarter's own database, never shared externally, segmented by account type for internal analytics, and purged after 13 months (aggregated into anonymous summaries first). Guest events use a session ID only — no PII.

2.4 Payment Information. Processed by Stripe. Quarter stores only your Stripe customer ID and subscription metadata. We never see or store your card number.

2.5 Technical Data (Automatic).

  • Error monitoring (Sentry): error traces, browser/OS type, page URL. No PII, no recipe data, no behavioral data.
  • Performance data (Vercel Analytics): anonymous aggregate page views and web vitals. No cookies, no personal data, no IP logging.

3. How We Use Your Information

We use your information solely to operate, maintain, and improve the Service:

  • Account operation, authentication, and age restriction enforcement.
  • Displaying your recipes, photos, comments, and profile to the community.
  • Personalizing your recipe feed via the preference algorithm (runs on every load, uses your interaction data, never announces itself).
  • Computing recipe nutrition, allergen warnings, and dietary compatibility automatically.
  • Processing subscription payments (via Stripe).
  • Sending essential transactional emails only: inactivity warnings, enforcement notices, admin thank-yous (via Resend). No marketing emails.
  • Detecting and fixing software errors (via Sentry).
  • Measuring aggregate site performance (via Vercel Analytics).
  • Validating uploaded photographs depict food (via Google Cloud Vision, behind a feature flag).
  • Enforcing our Terms of Service and Community Guidelines.
  • Computing internal analytics for the admin dashboard (never shared externally).

4. Data Processors

Quarter shares your data only with the following service providers, solely for the purposes described:

4.1 Supabase — database and authentication. Stores all user data. US servers (Oregon). Primary data processor.

4.2 Stripe — payment processing. Receives payment details directly. Quarter stores only Stripe customer ID.

4.3 Resend — transactional email delivery only. Receives email address for delivery. No marketing emails.

4.4 Vercel — web hosting. Anonymous aggregate analytics only. No cookies, no PII.

4.5 Google Cloud Vision — photo validation (food check + plagiarism). Images processed and not retained per Google API terms. Behind feature flag.

4.6 Sentry — error monitoring. Technical data only. No PII.

Quarter does not share your data with any other third parties. No ad networks, data brokers, retargeting services, or third-party analytics that identify individuals.

5. Cookies

Quarter uses only essential cookies:

  • Authentication session cookie (Supabase) — required to stay logged in.
  • Service worker cache — enables offline recipe access during cooking mode.

Quarter does not use analytics, tracking, third-party, or advertising cookies of any kind.

For EU users, we display a minimal informational notice: "Quarter uses only essential cookies for login. No tracking cookies." with a single "Got it" button.

6. Data Retention

6.1 Active accounts: data retained while account is active.

6.2 Interaction events: 13-month retention, then aggregated and purged.

6.3 Inactive subscriptions: monthly cancelled at 4 months inactivity (3-month warning). Annual runs full course; skips renewal if inactive 4+ months.

6.4 Inactive accounts: automatically deleted after 2 years of total inactivity. All PII erased. Published recipes anonymized to "[Deleted]." Drafts deleted.

6.5 Rejected photos: 12-month retention in non-public archive, then purged.

6.6 Notifications: 90-day retention or max 50 per user.

7. Your Rights

7.1 Access — request a copy of your personal data.

7.2 Rectification — update or correct your data via account settings.

7.3 Erasure — delete your account at any time. All PII erased within 30 days. Published recipes anonymized (community content).

7.4 Data Portability — request an export in a standard, machine-readable format within 30 days.

7.5 Object — object to non-essential processing. Use "not interested" to permanently exclude content from your feed.

7.6 Restrict Processing — request restriction while a dispute is resolved.

Contact: t.gardnertree@gmail.com. Response within 30 days.

8. GDPR (EU Users)

8.1 Lawful Basis: Contract (account/content/payment processing) + Legitimate Interest (preference algorithm, error monitoring, analytics). No consent basis for core features.

8.2 Data Transfers: US servers (Supabase, Oregon). Standard Contractual Clauses (SCCs) and provider GDPR compliance mechanisms.

8.3 DPO: Not currently required at Quarter's scale. Privacy inquiries to t.gardnertree@gmail.com.

8.4 Data Processing Agreements (DPAs) are maintained with all third-party processors listed in Section 4. A DPA is a contract between Quarter and each service provider that governs how your personal data is handled, ensuring compliance with GDPR and applicable data protection laws.

9. CCPA (California)

9.1 Categories Collected: identifiers (email, display name, DOB), internet activity (page views, interactions), commercial info (subscription status, Stripe ID).

9.2 Purpose: solely to provide the Service.

9.3 Sale: Quarter does not sell personal information. No cross-context behavioral advertising.

9.4 "Do Not Sell or Share" notice: provided as required, though Quarter does not sell or share data.

9.5 Rights: see Section 7. No discrimination for exercising CCPA rights.

10. COPPA

Quarter is not directed at children under 13. We do not knowingly collect personal information from children under 13. Date-of-birth gate prevents account creation for users under 13. If we learn such data was collected, we will delete it promptly. Contact: t.gardnertree@gmail.com.

11. Security

Passwords hashed. Row-Level Security on every database table. Payments handled by Stripe (PCI Level 1). Rate limiting and bot defense (honeypot, Cloudflare Turnstile, brute-force lockout). Contractor access limited to dev environments only. No method of storage is 100% secure.

12. Changes

Material changes notified via in-app notification 30 days in advance. Continued use constitutes acceptance.

13. Contact

QUARTER KITCHEN LLC

522 W Riverside Ave #5608

Spokane, WA 99201

United States

t.gardnertree@gmail.com

All privacy requests answered within 30 days.

© 2026 Quarter Kitchen LLC