Privacy policy
What Reduce collects when you convert and save recipes, who processes it, how long it is kept, and how to get it deleted.
Last updated
Who we are
Reduce is operated by Atlas Row LLC, a United States limited liability company, which is the data controller for the personal information described on this page. Write to [email protected] about anything on this page.
What this policy covers
This policy covers the Reduce website and app: the recipe converter, your cookbook, share links, and the Pro subscription. It does not cover the recipe sites you paste links from. Those are other people's websites with privacy policies of their own, and opening one is between you and them. Some of them are reached by your browser without you opening anything, which the section on what your browser loads from other services explains.
Information you give us
- Your account. If you sign up with an email address and a password, we store the email address. The password is handled by Supabase, which hosts our database and our authentication, and is stored as a hash that we cannot read.
- Google sign in. If you continue with Google, we ask Google for nothing beyond your basic profile and email, and we never receive your Google password. Three of those fields are the ones Reduce itself shows you: your email address, your name as Google has it, and the web address of your Google profile picture. The sign-in record Supabase keeps for the connection holds more than the app displays. It stores the account identifier Google issues for you, the profile details Google returns alongside it, and the times that connection was created, last updated and last used. That record is what lets you sign in with Google again, and it is deleted with your account.
- Your cookbook. Recipes you save, notes you write on them, ratings, favorites, collection names, and how many times you have marked a recipe cooked are stored against your account.
- Recipes you share. Publishing a share link copies that recipe to a page anyone with the link can read, and it stays readable for as long as the link exists. Reduce has no in-app control for taking a single share link down yet. Write to us and we will remove one for you, and deleting your account removes every link you have published.
- What you submit for conversion. The recipe address you paste, or the recipe text you paste, is sent to our server so it can be read. See how conversion works, below.
Information we collect automatically
- A device identifier. The first time you convert a recipe, your browser stores a random identifier. It exists to count free conversions against this browser as well as against your account, so that signing out is not a way to start the month again. It is a random value and it says nothing about you. It is also recorded on our server against each conversion it counts, which is what makes the allowance hold when you are signed out. Clearing your browser storage for this site removes the copy on your device; it does not remove the conversion records already stored against it.
- Your network address, when you convert without signing in. A conversion started while you are signed out is checked against a limit on how many conversions one network may run in an hour, which is what stops an automated caller spending our budget by pretending to be a new guest on every request. To count it we read the network address our host observed for the request and store the network it belongs to, together with the time. For an IPv4 address that network is the address itself. For an IPv6 address we keep only the first half, which identifies your connection and not your device. When no address can be read, the attempt is counted in a single shared bucket instead. We do not store it against your account, we do not use it to identify you, and conversions you run while signed in are not counted this way at all.
- Analytics. We use Google Analytics 4, measurement ID G-YW5N714EH1, to count how the product is used: which screens are opened, conversions started, finished and failed, saves, ratings, share links created and opened, Cook Mode sessions, and checkouts started and completed. Google Analytics sets cookies in your browser and gives your browser an analytics identifier, which it stores in a cookie named _ga.
- What Google Analytics collects on its own. Beyond the events we ask it to count, a standard Google Analytics installation collects information about your browser and device, such as the browser and its version, the operating system and its version, the device type, the screen size and the language you browse in. It also works out an approximate location from the network address the request arrives on. That location is coarse, no finer than a city, and Google derives it rather than passing us the address. We do not ask for it, we cannot turn it off from inside the page, and it is not tied to your account.
- Share link views. When someone opens one of your share links, we record the time, the site they came from, and their browser's user agent string, so we can show you how many times the link has been opened.
What we do not send to Google Analytics: recipe titles, recipe addresses, text you pasted, email addresses, account identifiers, or the query string of any page you visit. Reduce replaces the page address, page title and referrer that Google Analytics would otherwise collect by itself with the bare route you are on, such as /recipe, and with the referring site's host without its path.
Reduce has no in-app switch for analytics, and refusing cookies is not one either. Blocking the _ga cookie removes the identifier that ties your visits to each other, but Google Analytics can still report a visit without a cookie, so the measurement does not stop. What stops it is preventing the Google Analytics script from loading or running, which is what Google's Analytics opt-out browser add-on and script-blocking browser extensions do. Reduce works exactly the same either way.
What your browser loads from other services
Some of what a Reduce page is made of is fetched by your browser from somewhere other than Reduce. That happens as the page draws, without you clicking anything, and the service on the other end necessarily sees your network address and the ordinary details any browser sends with a request, such as the kind of browser you are using.
- Typefaces. The site is set in typefaces served by Google Fonts, and the stylesheet that loads them belongs to the whole site rather than to one screen. Google sees a request from your browser whenever that stylesheet or one of the font files behind it is actually fetched, which is on a first visit and again whenever your browser's stored copy has expired. Moving between screens inside Reduce does not fetch them again. This happens whether or not you have an account. It is there so the page reads the way it is meant to, it is a different service from Google Analytics, and we do not join it to your account or to the analytics identifier.
- Recipe photographs. A recipe saved from a website keeps pointing at the picture on that website, so opening a recipe, your cookbook, or a share link can make your browser fetch that picture from the site it came from, or from whatever network delivers pictures for them. That request goes to them rather than through us, and it happens because the picture is on the page, not because you followed a link to their site.
How converting a recipe works
When you convert a recipe from a link, our server fetches that page. It first tries to read the recipe out of the structured data the page publishes about itself, which costs nothing and involves nobody else. When a page cannot be read that way, the fetch falls back to Firecrawl, a third party scraping service, which fetches the page on our behalf and therefore receives the address you submitted.
The page text, or the text you pasted, is then sent to Anthropic's API, which returns the recipe as structured data. Anthropic states that data submitted through its API is not used to train its models by default. Not training on it is not the same as not holding it. Under Anthropic's standard commercial API terms the inputs and outputs of a call are deleted within 30 days, and may be held longer where enforcing its usage policy or the law requires. Treat that as the longest we can promise on Anthropic's behalf: what Reduce controls is that we do not store the text ourselves, and anything shorter would depend on terms between Anthropic and us rather than on this page. Please do not paste anything into the converter that you would not want processed this way.
We keep a record of each conversion: the address you submitted, the title of the recipe it produced, and which of the methods above read the page. That record is also the ledger for your free monthly allowance, which is three conversions per calendar month for accounts without a Pro subscription. The allowance is counted against your account identifier and against the device identifier described above, whichever is present, so one browser and one account cannot each claim a separate allowance.
Ingredient swaps and Cook Mode tips
Two features ask Anthropic about a recipe you already have, and both work only while you are signed in. Asking for an alternative to an ingredient sends that ingredient, the name of the recipe it belongs to, and the recipe's one line description where it has one. Opening Cook Mode sends the recipe title and its steps, which means each step's text, the timing shown on it where there is one, and any tip already saved against it. Neither one sends your email address or your name.
We count these requests so that no single account can spend the budget for everyone. Each request records your account identifier, which of the two features asked, and the time. That count is the whole of what Reduce stores: none of the recipe text that was sent is stored with it. Reduce not storing it is not the same as it being gone. These requests go to the same Anthropic API under the same terms as a conversion, so the retention described above applies to them too. The limit is 30 requests per feature per account per day, measured against UTC, and the count is deleted with your account.
Payments
Pro subscriptions are billed by Stripe. Card details are entered on Stripe's own checkout page and never reach Reduce. We do not see them, we do not store them, and we could not produce them if asked. What the app shows against your account is your Stripe customer identifier, whether the subscription is active, and the date the current billing period ends. The usual route for changing or cancelling a subscription is Stripe's customer portal, which you reach from inside the app; if it does not open, or does not offer what you need, write to us and we will make the billing change for you, cancelling included. The terms of service describe how that works.
Reduce keeps more of the billing record than that summary shows. Stripe notifies our server when something happens, and we store three kinds of notice: the completed checkout that starts a subscription, and the two that follow when a subscription changes or ends. Three kinds is not three records. We keep one record for every notice of those kinds that Stripe sends, so a subscription that changes many times leaves one stored notice behind per change, and the number we hold is not fixed. Each is stored whole, as Stripe sends it, carrying the checkout, customer and subscription details for the event it describes. Anything else Stripe sends is acknowledged and not stored. The completed checkout is the one that carries your account identifier, because it is the notice that tells us whose subscription this is; the other two are matched by the Stripe customer and subscription identifiers instead. We also keep a running record of the subscription and of the customer behind it: those identifiers, the tier, the status, the end of the current period, and when each was last changed. None of it contains a card number.
Email we send you
Account email, such as a password reset or a confirmation of an address change, is delivered through Resend and sent from [email protected]. We do not send marketing email and there is no mailing list to be added to.
Why we use this information
- To run the product: converting recipes, keeping your cookbook, serving your share links.
- To count the free monthly allowance and to keep the converter from being abused.
- To take payment for Pro and to know whether a subscription is active.
- To answer you when you write to us.
- To understand, in aggregate, which parts of the product are used and which are not.
- To keep the service secure and to meet our legal obligations.
Who else processes it
These companies process personal information on our behalf, each for the one job named:
- Supabase: database, accounts and authentication, and the server functions.
- Cloudflare: hosting and delivery of the site.
- Google Analytics: usage analytics.
- Google Fonts: serving the typefaces every page is set in.
- Anthropic: reading a recipe out of page text, and answering the ingredient swap and Cook Mode tip requests described above.
- Firecrawl: fetching a page when it cannot be read directly.
- Stripe: payments and subscription management.
- Resend: delivery of account email.
We do not sell personal information, and we do not share it for cross context behavioral advertising. We may disclose information if the law requires it, or to protect the service and its users from abuse.
How long we keep it
- Saved recipes and notes: until you delete them in the app, or until your account is deleted.
- Your account: until it is deleted. There is no in-app account deletion yet, so the route that works today is the one under Your choices, below.
- Share links: until your account is deleted, or until you ask us to take one down. A published link keeps resolving until then, because there is no in-app control for removing a single link yet.
- Conversion records: kept as your allowance ledger. A conversion you made while signed in belongs to your account and is deleted with it. A conversion you made while signed out is attached to the device identifier and to no account, so there is no account deletion for it to follow, and we keep it until you ask us to remove it. Neither kind is on an automatic deletion schedule today.
- Share view records: kept until the share link they belong to is deleted.
- Signed-out conversion attempt records, meaning the network and the time described above: one hour. The limit only ever counts the last hour, so anything older is deleted the next time the check runs. This is the one thing on this list that does delete itself.
- Analytics records: held by Google for the retention period configured on our Google Analytics property.
- The device identifier: in your browser until you clear this site's storage, and on our server for as long as the conversion records that carry it.
- Assistant request counts, meaning the record that an ingredient swap or a Cook Mode tip was asked for: kept as the ledger for the daily limit and deleted with your account. The recipe text those requests carried is not stored by Reduce at all, though Anthropic holds it under the API retention described above.
- Billing records, meaning every stored notice of the kinds described above and the subscription and customer state we keep from them: kept as our record of what was billed, including after a subscription ends, which is what a payment record is for. They sit in their own tables, which are keyed by Stripe identifiers and carry no foreign key to your account row, so deleting your account cascades nothing into them, and nothing sweeps them, so they are on no deletion schedule and deleting your account does not reach them. That is a fact about the schema and not a claim that the records are anonymous: the stored checkout notice still contains the account identifier it was sent with, which keeps it traceable to you.
Deleting your account removes your profile, your saved recipes, your notes, your share links, the view records attached to them, the conversion records made while you were signed in, and your assistant request counts. It is a deletion, not a flag. Two things are not part of that removal. Conversions you made before you had an account, or while signed out, are attached to a device identifier rather than to the account, so there is no account deletion for them to follow. Write to us and we will delete those too. Billing records sit in their own tables, which carry no foreign key to your account row and which nothing sweeps, so the deletion does not reach them, and the stored checkout notice still contains the account identifier it was sent with, which keeps it traceable to you. A record of what was billed is one we keep, so write to us and we will remove whatever we are not required to keep.
Your choices
Most of what we hold is already in front of you: your cookbook, your notes and your ratings are all editable and deletable in the app. Share links are the exception. Once you publish one it keeps resolving for anyone who has it, and there is no in-app control for taking it down yet. Write to [email protected] to have a share link removed, and deleting your account removes every link you have published.
You can delete your account and all associated data at any time. Email [email protected] from the address on the account to request deletion; an in-app delete control is being added to your account settings.
For a copy of everything we hold about you, or a correction, write to the same address from the address on the account. The support page says what to expect.
California privacy rights
If you live in California, the California Consumer Privacy Act, as amended by the California Privacy Rights Act, gives you the rights below. Reduce works the same whether or not you use them, and we will never charge you a different price or give you a worse service for asking.
- To know what personal information we collect, why, and who we share it with. That is this page.
- To get a copy of the personal information we hold about you.
- To have inaccurate personal information corrected.
- To have your personal information deleted.
- To limit the use of sensitive personal information. The credentials that sign you in, meaning your account login together with your password, are sensitive personal information as the CPRA defines that term. They are the only sensitive personal information we hold. We use them to authenticate you and to keep your account secure, and for nothing else: we do not use them to infer anything about you, and we do not disclose them. That is already the limit this right lets you ask for, so there is nothing further to restrict.
- Not to be discriminated against for exercising any of these rights.
In the categories that Act uses, we collect identifiers (your email address, your account identifier, the device identifier, the analytics identifier Google Analytics stores in your browser, and the network an unsigned-in conversion came from), commercial information (whether you hold a subscription, the purchase history Stripe keeps for it, and the billing records we keep from Stripe's notices), internet activity (which screens you open in Reduce, which recipes you convert, the ingredient swap and Cook Mode tip requests you make, together with the browser and device information Google Analytics collects by default and the requests your browser makes to Google Fonts and to the sites recipe pictures come from), geolocation data in the coarse form described above (the approximate location, no finer than a city, that Google Analytics derives from a network address), and sensitive personal information in the single form described above, the credentials that sign you in. We draw no inferences and build no profiles.
We do not sell personal information and we do not share it for cross context behavioral advertising, so there is no Do Not Sell Or Share link for us to offer you. To make a request, write to [email protected] from the address on your account and we will answer within 45 days. You may use an authorized agent, in which case we will ask for proof that you authorized them.
Children
Reduce is not directed at children under 13, and we do not knowingly collect personal information from them. If you believe a child has given us personal information, write to [email protected] and we will delete it.
Changes to this policy
When the product changes what it collects, this page changes with it, and the date at the top is when the current wording took effect. If a change materially affects how we use information you have already given us, we will say so here rather than quietly reword the paragraph.