Sprig Privacy Policy
Effective date: July 27, 2026
Sprig (“the app”) is a recipe manager built around a simple idea: your data belongs on your device. This policy explains what little data leaves it, why, and what happens to it. Sprig is operated by Muhammad Haris Siddiqui (“we”, “us”).
The short version
- If you are signed out, your recipes, cookbooks, meal plans, grocery lists, pantry, and settings are stored on your device only. Nothing is uploaded in the background — content reaches us only for the moment an AI request you started is in flight.
- If you sign in, your recipes, cookbooks, meal plans, grocery lists and pantry are also copied to our server so they appear on your other devices. Your settings and attached photos are not. See “Cloud sync” below.
- Creating an account is optional. The app is fully usable without one, and without one nothing of yours is stored on our server at all.
- The AI features send content to OpenAI to work — recipe text, and, for the two photo features, the photo itself. Nothing goes to OpenAI until you ask for it, and we ask for your consent before the first time. Those requests pass through a relay we run, which stores none of the content; see “AI features” below.
- Photos you attach to your own recipes are a separate thing: those stay on your device and are never uploaded.
- The free plan shows ads, provided by Google AdMob. Ads need an advertising identifier for your device, and on iOS we ask your permission before using it for personalized ads — decline and you still get the same app with the same features, just generic ads. Premium removes ads entirely, and premium users are never asked. See “Advertising” below.
- We sell no data and use no third-party analytics SDKs. None of your recipes, photos, meal plans, grocery lists or pantry contents are ever shared with an advertiser.
Data stored on your device
Everything you create in Sprig — recipes, cookbooks, photos, meal plans, grocery lists, pantry items, ratings, notes, and preferences — is stored locally on your device. While you are signed out, that is the only copy: we cannot see, access, or recover it. Signing in adds a server-side copy of some of it, described under “Cloud sync” below; your device always remains the working copy.
Deleting the app removes this data from the device. One caveat worth knowing: on Android, the system’s own automatic backup can copy app data to your Google account and restore it when you reinstall, so a reinstall may bring your library back. That backup belongs to Google and your device, not to us — you can turn it off in Android Settings → Google → Backup, or clear it from your Google account.
Data that leaves your device
AI features (OpenAI)
Sprig has nine features that use OpenAI’s API. Each one sends only what that feature needs, and only when you start it:
| Feature | What is sent |
|---|---|
| Healthier ingredient swaps | The recipe title and ingredient list |
| Allergen and ingredient swaps | The recipe title, ingredient list, and the ingredient you asked to avoid |
| Spice level: reading a recipe’s current heat | The recipe title and ingredient list |
| Spice level: adjusting a recipe | The recipe title, ingredients, and steps |
| “What can I cook?” suggestions | Your pantry item names and your diet/time filters |
| Turning a suggestion into a full recipe | The dish name, your pantry, and your filters |
| Scan your fridge or pantry | The photo you take or choose |
| Import a recipe from photos | The photos you take or choose (up to four) |
| Import from a link, a YouTube description, or a TikTok caption | The page text, video description, or caption — see “Recipe import” below |
These requests carry no user ID, no device identifier, and no account
information — the request body is the recipe content and nothing else. We send
store: false, and OpenAI does not use API data to train its models, per
OpenAI’s API data
usage policy.
They pass through a relay we run. Your device sends the request to a
small service of ours, which attaches our OpenAI key and forwards it to
api.openai.com. It exists so that key is not shipped inside the app,
where anyone could extract it and spend our account. What this means for you, plainly:
- The relay handles the same content the table above describes — including your photos — for as long as the request takes. It stores none of it, and neither logs nor keeps request or response bodies.
- The relay sees your device’s IP address, because every network request reveals one. It does not store it. What it does store is a salted one-way hash of your IP with a request count, purely to stop one caller from draining our OpenAI budget. Those counters are deleted after 7 days and cannot be turned back into an IP address.
- OpenAI now sees the relay’s IP address instead of yours.
- The relay runs on Supabase
infrastructure. Its rate-limit counters are stored in our database in
Canada (region
ca-central-1), and the relay code itself runs on Supabase’s edge network, which may execute it in a region closer to you. Either way the request is then forwarded to OpenAI in the United States, so your content is processed there regardless of where you are.
The two photo features deserve a plainer statement than the text ones: a photo of your fridge or of a cookbook page can incidentally contain faces, mail, documents, or anything else in frame. Those pixels are uploaded as-is. Have a look at what’s in the shot before you send it.
AI consent, and what AI output is worth
Before Sprig sends anything to OpenAI for the first time, it shows you a consent prompt explaining what leaves your device. If you decline, no AI request is made and the rest of the app — saving, editing, planning, cooking, grocery lists, and importing from any site that publishes structured recipe data — keeps working normally.
AI output is generated text. It can be wrong: a swap may not taste right, a heat level may be misjudged, a scanned ingredient may be misread, an imported recipe may have a quantity the source never said. Check it against the original before you cook, and treat generated nutrition, portion, or ingredient advice as a starting point, not a fact. Sprig’s AI features are not dietary, nutritional, or medical advice. If you have an allergy, an intolerance, or a medical condition, verify every ingredient yourself and talk to a qualified professional.
Recipe import
When you import a recipe from a link, the app fetches that page directly from your device, exactly as a browser would. Fetching the page involves no server of ours at all: the site sees a normal page request from your IP address, and we see nothing. The same is true of the YouTube and TikTok pages Sprig reads when you paste one of those links. (Our AI relay is only involved if the page needs the AI fallback described below.)
What happens next depends on the page. Most recipe sites publish structured recipe data, and Sprig reads it on-device with no AI and no network calls beyond fetching the page. When a page has no structured data, Sprig falls back to sending the page’s text to OpenAI to read the recipe out of it — the same fallback applies to a YouTube video description and a TikTok caption. That fallback is an AI request and is covered by the consent above.
Instagram is never fetched at all; Sprig asks you to paste the caption instead.
Optional sign-in (Google or Apple)
If you choose to sign in, authentication is handled by Supabase Auth. We receive and store your name, email address, and a unique user ID as provided by Google or Apple. Signing in with Google or Apple does not give us access to your Google or Apple account, your contacts, or your mail — only the name, email and ID in the sign-in token. Supabase’s handling of this data is described in Supabase’s privacy policy.
Your password is never involved: Sprig never sees, asks for, or stores one.
Cloud sync (signed-in users only)
Signing in turns on sync, so the same library appears on every device you use. This is the one place where your own content is stored on a server we run.
What is uploaded: your recipes (title, description, ingredients, steps, tags, notes, ratings, servings, times, nutrition estimates and source links), your cookbooks, your meal-plan entries, your grocery list, and your pantry — each pantry item’s name, when you added it, and any use-by date you set on it.
What is not uploaded: photos you attached to recipes — they stay on the device, and a recipe synced to your second device shows its emoji placeholder instead. Also not uploaded: your kitchen filters, your app settings, and your AI consent record. Those remain per-device.
Where it lives: in a Supabase
Postgres database in Canada (region ca-central-1), protected by row-level
security rules that allow each account to read and write only its own rows. We do not
sell it, mine it, or use it to train anything.
Deleting syncs too. Delete a recipe on one device and it is removed from the server and from your other devices. Because deletions have to propagate, a deleted record leaves behind a marker row — its identifier and the time it was deleted, with the recipe content removed — so that your other devices know not to restore it. Deleting your account removes those markers along with everything else.
Signing out does not delete anything, on the device or on the server. It stops syncing and leaves your library on the device. To remove the server-side copy, delete your account (see below).
Purchases (RevenueCat)
Premium subscriptions and purchases are processed by Apple’s App Store or Google Play — we never see your payment details. Our billing partner RevenueCat receives purchase receipts, basic device information, and a user ID, so purchases can be validated and restored. If you are signed out, that user ID is an anonymous one RevenueCat generates. If you are signed in, Sprig passes your account’s user ID to RevenueCat, which links your purchase record to your Sprig account so entitlements follow you across devices. See RevenueCat’s privacy policy.
Advertising (Google AdMob)
The free plan is supported by ads served by Google AdMob. Premium removes every ad in the app, and a premium user’s device never contacts AdMob at all — not for an ad, not for a consent form, not for a tracking prompt.
What AdMob receives. When an ad is requested, Google receives your device’s advertising identifier (the IDFA on iOS, the Advertising ID on Android), your approximate location derived from your IP address, and technical information about your device and the ad itself — which ad was shown, whether it loaded, whether you tapped it. Google uses this to select ads, to measure them, and to detect fraud.
What AdMob never receives. Your recipes, photos, ingredients, meal plans, grocery lists, pantry contents, email address and Sprig account ID are never sent to Google or any advertiser. Ads are not targeted using anything you have stored in Sprig.
Your choices.
- On iOS, Sprig asks for permission before using the advertising identifier to track you across apps (Apple’s App Tracking Transparency prompt). If you decline — or never answer — Sprig requests non-personalized ads only, which are chosen from context rather than a profile. You can change this any time in iOS Settings → Privacy & Security → Tracking.
- In the EEA, the UK, and US states with privacy laws, you are shown Google’s consent form before any ad loads, and Sprig will not start the ad SDK if you do not consent to ads. You can reopen that form later at Settings → Ad privacy and change your mind.
- On Android, you can reset or delete your Advertising ID in the system settings.
- Anywhere, buying Premium removes ads outright.
Ad content is limited to Google’s “G” (general audiences) rating to suit the app’s age rating. Google’s handling of this data is governed by its own policies — see how Google uses information from sites or apps that use its services and the Google Privacy Policy.
Grocery checkout (“Buy ingredients”)
This feature is optional and works two ways, depending on the retailer you pick.
- Instacart builds a checkout-ready page for you. To do that, Sprig sends the recipe to Instacart’s Developer Platform API: the title, the ingredient lines with quantities, the cooking steps, the serving count, and — only when the recipe’s image is a public web URL from an import — that image URL and the original source link. Photos you attached yourself are local files and are never sent. The request travels through a small relay of ours — the same arrangement as the AI relay above, running on the same Supabase infrastructure — which exists solely to keep our Instacart credential off your device; it forwards the request and the resulting link without storing either. Instacart returns that link, which Sprig caches on your device for up to a month so repeat taps don’t re-send anything.
- Whole Foods, Amazon Fresh, and Walmart have no cart API, so Sprig simply opens that retailer’s normal search page with an ingredient name in the URL. Nothing is posted anywhere.
Those retailers’ own privacy policies govern what happens on their side. No purchase or browsing information comes back to us.
Photos and camera
There are two different things going on here, and they deserve to be told apart.
- Photos you attach to a recipe stay on your device. They are copied into Sprig’s own storage, referenced by the recipe, and deleted when the recipe is. They are never uploaded — not to us, not to OpenAI, not to a retailer.
- Photos you feed to an AI feature are uploaded. That is “Scan your fridge or pantry” and “Import a recipe from photos”, and only those. Each is something you start deliberately, and the photo goes to OpenAI as described above.
Camera and photo-library access is requested only when you use a feature that needs it, and is used for nothing else.
Children
Sprig is not directed at children under 13, and we do not knowingly collect personal information from them. Because the app is not child-directed, it is not registered as such with the ad network; ads are nonetheless capped at Google’s general-audiences (“G”) content rating.
Data retention and deletion
Step-by-step instructions, including how to delete without the app, are on the account deletion page.
Local data is under your control. Delete recipes individually, or use Settings → Account → Delete account to erase the whole library at once.
Your account. You can delete it from inside the app at any time: Settings → Account → Delete account. Sprig re-authenticates you, then deletes your Supabase authentication record — which also erases every synced recipe, cookbook, meal-plan entry, grocery item, pantry item, deletion marker and profile row on our server — and wipes every recipe, cookbook, meal plan, grocery list, pantry item, saved photo, and cached checkout link on the device. Nothing of yours is retained on either side. For Sign in with Apple accounts, Sprig does not currently revoke the Apple grant itself — deleting your account removes the account and its data, and the grant is revoked from iOS Settings → your name → Sign in with Apple → Sprig. Revoking the grant does not by itself delete anything, and deleting your account does not depend on it. If you want to be certain the Apple grant is gone, revoke it yourself in iOS Settings → your name → Sign in with Apple; that is the authoritative place, and it takes a moment.
If you can’t use the in-app flow — you deleted the app, lost the device, or it won’t open — email haris.sidd786@gmail.com from the address you signed in with, with the subject “Delete my account”. We will delete the authentication record and confirm by reply, normally within 30 days. Local data on a device we have no access to can only be removed by deleting the app on that device.
What we keep after deletion: nothing of yours. Deleting the account removes your synced library and your authentication record together, and the AI relay’s rate-limit counters hold only a salted hash that cannot be traced back to you. Purchase records are retained by Apple, Google, and RevenueCat as those companies require for restoring purchases and for financial compliance; they are outside our control. Requests to Apple or Google about purchase data have to go to them directly.
Changes
If this policy changes materially, the effective date above will change and the update will ship with an app release. Continued use after an update means you accept the revised policy.
Contact
Questions, privacy requests, or account deletion: haris.sidd786@gmail.com