1. Who this policy covers
Cookestra is operated by the seller identified on its App Store listing (“Cookestra,” “we,” or “us”). This policy applies to the Cookestra iOS and watchOS apps, Cookestra widgets and Live Activities, cookestra.app, and—when enabled—the Chef+ content service.
Cookestra does not create a separate username-and-password account. App Store purchases and optional iCloud sync use the Apple accounts already managed by you and Apple.
2. Data kept on your devices
Cookestra stores the information needed to personalize and operate the app, including dietary preferences, allergens and avoidances, household tastes, serving and spice preferences, favorites, cooking history, My Kitchen notes, substitutions, Mastery progress, plans, timers and the current cooking step.
Sensitive profile and kitchen-memory files are encrypted on device using AES-256-GCM. Their encryption key is held in the Apple Keychain with this-device-only protection, and protected files are unavailable while the device is locked. Some short-lived operational state uses the app sandbox or App Group storage so widgets, Live Activities and Apple Watch can remain in step.
3. Optional Cookestra Cloud sync
If you enable Cookestra Cloud, favorites and cooking history, My Kitchen memory, Mastery progress and The Week plan are sent to your private CloudKit database. Apple operates CloudKit and controls the security of your iCloud account. Dietary and allergen profile boundaries are not part of Cookestra's CloudKit sync payload.
You can pause sync or delete Cookestra's private CloudKit records from Settings. Cloud deletion is verified and leaves sync paused. Local data remains on the device unless you separately reset it or remove the app.
4. Chef+ authorization data
When the production Chef+ service is enabled and you request premium content, Cookestra sends a StoreKit signed transaction, an Apple App Attest key and assertion, the app identity and version, and a request-specific public encryption key. This is used only to verify an active subscription, detect tampering or replay, rate-limit abuse, and deliver short-lived encrypted content packages.
The service stores pseudonymous security records such as the App Attest public key and counter, hashed transaction identifiers, product and entitlement status, challenge and delivery-token metadata, and security audit events. The common Chef+ recipe and artwork packages themselves do not contain your profile or kitchen notes.
5. Service providers and network information
- Apple provides the App Store, StoreKit, App Attest, iCloud/CloudKit, notifications and operating-system services.
- Cloudflare is intended to host the Chef+ Worker, private package storage, security database and rate limiting.
For abuse prevention, the Chef+ Worker hashes the network address supplied by Cloudflare and does not write the raw address to its application database. Cloudflare may process standard network and operational logs under its own infrastructure policies. Cookestra does not include third-party advertising, cross-app tracking or third-party behavioral analytics SDKs.
6. Retention
- Device data remains until you change, reset or remove it, or uninstall Cookestra.
- CloudKit data remains in your private database until you delete it, disable the relevant Apple service, or Apple applies its account retention rules.
- Chef+ challenges normally expire after five minutes; manifest access after two minutes; package access after fifteen minutes.
- Chef+ entitlement security-audit events are scheduled for deletion after 400 days. App Attest key records are retained while needed to prevent replay and protect premium access, or until a verified deletion request can be completed, subject to legal and security obligations.
7. Your choices
- Change personalization and safety preferences in Settings.
- Pause iCloud sync or delete private iCloud data in Settings.
- Export My Kitchen data from Settings.
- Remove local data using Cookestra's reset controls or by deleting the app.
- Manage or cancel Chef+ in your Apple subscription settings.
- Request help with access or deletion through the address below.
See the step-by-step data choices guide.
8. Children and sensitive use
Cookestra is a general-audience cooking product and is not directed to children under 13 or the minimum digital-consent age where you live. Recipe suggestions and allergen notices are informational; they are not medical advice and do not replace labels, professional advice or safe food-handling judgment.
9. Changes and contact
We may update this policy as Cookestra changes. We will revise the effective date and provide additional notice when required.
Questions or requests: support@cookestra.app