Koste logoKoste
HomePrivacy PolicyEffective April 1, 2026

Privacy Policy

How Koste handles website and app data

Koste is built around a simpler privacy posture than many consumer apps: the current iPhone app does not require a dedicated Koste account, the landing page does not run ad-tech or analytics trackers, and most recipe content stays under your control on your device or in Apple's sync environment.

This policy still matters because Koste does process some personal information, especially when you send us a message, enable iCloud sync, import content from external links, or use Apple-provided intelligence features.

No Koste Login

The app is designed to work without creating a separate Koste account.

Local-First App Data

Recipe content is stored on device and can sync through Apple iCloud/CloudKit if you use that service.

Current Website Posture

The landing page currently uses a contact form, but not advertising cookies or third-party analytics trackers.

Privacy Policy

What This Policy Covers

This Privacy Policy covers the Koste website, the landing-page contact form, and the current Koste iPhone app. Koste is designed around a no-login model for core app use, so the amount of personal information we actively collect is limited compared with account-based services.

This policy is meant to reflect the current product as implemented in this repository: a local-first recipe manager with optional iCloud sync, import flows for photos, links, pasted text, and supported archive formats, plus a contact API used by the landing page.

Privacy Policy

Information We Process

Depending on how you use Koste, we may process the following categories of information:

  • contact information and message content you submit through the landing-page form
  • technical request data used to operate and protect the contact endpoint, including source labels, IP address, user-agent, request identifiers, and anti-spam honeypot values
  • recipe content you choose to add in the app, such as photos, imported images, OCR text, pasted text, recipe body text, tags, notes, favorites, and cook history
  • source information for imported links, including URLs, source domains, provider labels, preview images, and metadata fetched from the pages you ask Koste to inspect
  • app preferences and state such as appearance, haptics, spin settings, keep-screen-awake preference, and whether timer notifications are allowed
  • export archives and imported archive contents when you use Koste export or import features

Privacy Policy

How We Use Information

We use information only for product and support purposes connected to Koste, including to:

  • store, organize, search, sync, export, and display the recipes and notes you choose to keep in the app
  • generate title or tag suggestions from recipe photos, text, or imported link metadata
  • fetch previews for links you explicitly ask the app to import
  • schedule and manage local cooking timer notifications
  • respond to feedback, partnership inquiries, and support requests sent through the website
  • detect spam, rate-limit misuse, secure the API, and maintain the service
  • comply with legal obligations and resolve disputes if necessary

When you use the camera, photo library, or document-scanning flows to import a recipe, the images are processed for import, OCR, thumbnailing, and optional suggestion features within the app and related Apple services you choose to use. Koste does not currently transmit or store your personal photo library on Koste-operated servers.

Privacy Policy

Where Data Lives And Who May Receive It

Koste does not currently run a dedicated user-account backend for app content. Recipe data is stored on your device and, if you use Apple's iCloud services for sync, through Apple's CloudKit infrastructure tied to your Apple environment.

Landing-page contact submissions are sent to the Koste contact API and stored in PostgreSQL so we can review and respond to them. Contact submissions also include anti-abuse data such as IP address and user-agent because the API enforces CORS and rate limiting.

When you import a link, your device may contact the website you entered, Apple's link-preview services, and in some cases TikTok's oEmbed endpoint to retrieve title, image, and metadata needed for the preview flow. Those providers may receive standard request information from your device as part of the connection.

When Apple-provided system intelligence features are available, Koste may use them to help infer recipe titles and tags from content you choose to import. Apple states that some Apple Intelligence requests may be handled on device and some through Private Cloud Compute, depending on the task.

We do not currently run third-party website analytics, targeted advertising cookies, or cross-context behavioral advertising on the landing page, and we do not sell personal information.

Privacy Policy

Retention

App content generally remains available until you delete it, remove the app, or stop using the Apple services that sync it. Exported files remain wherever you save or share them until you delete those copies.

Contact submissions are retained only as long as reasonably necessary to handle the inquiry, maintain basic business records, enforce rate limiting and abuse protections, and meet legal obligations. We may retain limited information longer if needed to resolve disputes, investigate misuse, or defend legal claims.

You can ask us to delete a contact-form submission at any time. We may keep limited information where necessary to comply with law, document the request, prevent abuse, or defend legal claims.

Privacy Policy

Your Rights And Choices

Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or receive a portable copy of personal information we control. California residents may also have specific rights under the CCPA, and people in the EEA may have GDPR rights.

Because Koste does not currently maintain a dedicated user account for app content, the practical way to exercise rights relating to information we directly control is to contact us through the website and describe your request clearly. We may need to verify identity before acting on a request, and some rights are subject to legal exceptions.

You can also control much of your data directly by deleting recipes in the app, removing exported files, disabling notifications in iOS settings, or changing your Apple iCloud/CloudKit settings for synced data.

Privacy Policy

Children And Sensitive Situations

Koste is not directed to children under 13, and we do not knowingly collect personal information from children through the website. If you believe a child submitted personal information to us through the contact form, contact us so we can review and delete it where appropriate.

Please do not send sensitive personal information through the contact form unless it is genuinely necessary for your request. The current form is meant for product feedback and support, not for highly sensitive disclosures.

Privacy Policy

Changes To This Policy

We may update this policy as Koste changes. When we do, we will revise the effective date on this page and post the updated version here.

If a change materially affects how we handle information, including if Koste later introduces paid features or different commercial flows that require additional billing or account-related processing, we will try to describe the change clearly rather than burying it in silent edits.

Questions

Contact About Privacy

Privacy requests, support questions, and policy questions can be sent through the contact form on the Koste home page.

If you are making a privacy request, say what right you want to exercise and provide enough detail for us to find the relevant record. If you are in the EEA, the European Commission notes that organisations generally must respond without undue delay and at the latest within one month.