Overeasy privacy policy
Effective: August 23, 2026
Overeasy turns public recipe links and text you provide into recipes and syncs them across your devices. This policy describes the data needed to do that. Overeasy does not sell personal data, serve ads, or track activity across other apps or websites.
Data we collect and why
- Account and device identifiers, authentication sessions, and App Attest security records provide sign-in, sync, fraud prevention, and replay defense. Apple or Google supplies its stable account identifier only when you choose that sign-in method.
- A display name and a profile picture identify your account to you inside the app. Both may be supplied by the sign-in provider, and the display name is editable and is never overwritten by a later sign-in. A provider's picture is a link to their own copy, which Overeasy does not host.
- A profile photo you choose yourself is stored by Overeasy, in the same private object storage as your recipe images. It is shown only to you, in your own app: it is never attached to anything you share, never shown in Discover, and never served to another account. It is reachable only through a signed link that expires within hours, it replaces the provider's picture without deleting it, and you can remove it at any time from the avatar in Profile. Removing it, replacing it, or deleting your account deletes the stored photo. Overeasy uses the camera and reads from your photo library only when you choose a picture, and only the picture you choose.
- Imported URLs, public-source metadata, recipe content, thumbnails, and edit history provide imports and device sync.
- Discover ranks public recipe-video sources by aggregate saves. It shows the public creator account, source metadata, thumbnail, and total save count. It does not expose who saved a recipe, private edits, ingredients, or personal correction notes from another account.
- A record of which Discover sources were shown to your account, and when, keeps the feed from repeating itself: a source you were shown in the last day sorts below ones you have not seen. Only the source identifier and the time it was last served are stored — never how long you looked, whether you opened it, or anything you did next. Nothing is suppressed permanently, the record is not used for advertising or profiling, and it is deleted with your account.
- Pasted recipe text and correction notes are encrypted at rest and used only to complete or retry the requested import.
- Request IDs, pseudonymous user identifiers, import job IDs, provider stage, duration, result, rate-limit decisions, and error class support security, reliability, and cost control. Logs exclude recipe/private text, authorization tokens, provider credentials, and raw identity tokens.
- Apple Health receives nutrition only after you explicitly export it from the device. The permission Overeasy asks for is write-only: it can add the serving you export and cannot read anything from Health, including data written by other apps. Health data is never used for advertising or marketing, never sold, never shared with a third party, and never leaves the device through Overeasy — the export is a local write from your phone to your own Health store. Timers and local notifications remain on the device.
Service providers
Overeasy shares only data necessary to operate the selected feature:
- Hosting, managed PostgreSQL, Redis, and private object-storage providers process service data and backups.
- Depending on the successful import path, public URLs, captions, media evidence, pasted text, or correction notes may be processed by configured acquisition, transcription, vision, and extraction providers such as Supadata, SoScripted, OpenRouter, Anthropic, or their hosted model provider.
- Apple and Google process authentication when their respective sign-in option is used.
These processors act to provide Overeasy's service. Overeasy does not disclose data to advertising or data-broker services.
Retention
- Pasted text and correction notes: erased within 24 hours after an import reaches a terminal state.
- Completed or failed import jobs: 30 days.
- Provider-attempt and cost records: 90 days.
- Expired or revoked session and refresh-token hashes: seven days.
- Negative extraction caches: until their short expiry; invalid caches and orphaned thumbnails: 30 days before cleanup.
- Recipe sync changes and deletion tombstones: 365 days. A device returning after that window receives a fresh authoritative snapshot.
- Discover impression records: 30 days. They stop affecting what you are shown after 24 hours, well before they are erased.
- Pseudonymous account-deletion audit records: 365 days.
- Recipes and account data: while the account exists, unless removed earlier at the user's request.
- Temporary object uploads: one day; noncurrent object versions: 30 days.
Encrypted automated backups are retained for 35 days; continuous point-in-time recovery covers at least the latest seven days. Expired backups are destroyed by the infrastructure provider's lifecycle.
Account deletion
Every guest, Apple, and Google account can be permanently deleted in Account → Delete account. The operation verifies the current session, revokes Sign in with Apple credentials when applicable, and removes or anonymizes recipes, imports, sessions, devices, identity links, the display name, the provider's profile picture link, any profile photo you uploaded, provider usage, private text, sync history, Discover impression records, and unreferenced objects. It is idempotent so a network retry cannot recreate or partially delete the account.
Deletion cannot be undone. Backups are not used to restore an individual deleted account; any residual encrypted copy ages out within the 35-day backup schedule.
Security and changes
Private text uses authenticated, versioned encryption keys stored separately by environment in managed secret storage. Traffic uses TLS, production access is attested and rate limited, and workers are restricted from private-network and cloud-metadata egress.
Material policy changes will update the effective date and the in-app disclosure.
Contact
Questions about this policy, a privacy request, or anything that went wrong: hello@chetangoel.me. A person reads it. Overeasy is made by Chetan Goel.