Privacy Policy
This policy explains what personal information the Boha app and its server collect, why, where it goes, and how you control it. It also covers our website, boha.starb.ca. We wrote it to match what the app actually does.
1. Who we are
Boha is run by an individual in Quebec, Canada (“we”, “us”). We are responsible for the personal information described here.
Person in charge of the protection of personal information: the Privacy Officer (the operator of Boha). Contact: support@boha.starb.ca.
2. The short version
- No ads. No tracking. No analytics. We do not sell or rent your information.
- New recipes are private until you choose to share them.
- To read an import, our server sends it to AI services: OpenRouter, and through it GLM, DeepSeek and Google Gemini. The app asks you before your first import.
- Text, links, web pages and photos you send for import are not stored or logged on our server.
- You can delete your account in the app. This deletes your data from our systems (section 9).
- Some service providers are outside Quebec, mostly in the United States. Sections 6 and 7 explain.
3. What we collect
Account
You can browse and cook without an account. To create, import, save, like, comment, follow, share, report or block, you sign in. Sign-in is handled by Supabase, with Google or, on iOS, with Sign in with Apple. Supabase keeps your email address, your name, your profile picture and your sign-in sessions. Supabase can also see technical data such as your IP address and device type when you sign in.
Our own tables do not store your email address. They store your account ID, your handle, your display name, your profile picture address and your bio.
Your recipes and activity
- Recipes you create or import: title, ingredients, steps, notes, tags, times, and the source link of an imported recipe and the link to its website photo.
- Visibility of each recipe: private (only you), unlisted (anyone with the link) or public. New recipes start private.
- Likes, saves, comments, follows, and people you block.
- Recipes shared with you by link that you opened while signed in.
- Reports you file: what you reported, the reason, and an optional note.
Photos
Photos you add to a recipe are stored with Cloudflare R2, in a folder named with your account ID. Before upload, the app resizes the photo and saves it as a new JPEG, which removes metadata such as location.
Important: each photo is served from a web address that contains your account ID and a long random part. It is hard to guess, but it is not secret. Anyone who has that exact address can see the photo, even if the recipe is private. Do not put anything in a photo that you want to keep secret.
Imports
When you import a recipe from text, a link or a photo, the app sends it to our server. Our server sends the recipe text to OpenRouter, an AI service. OpenRouter sends the text to an AI model that turns it into a recipe: GLM, made by Z.ai, or DeepSeek if GLM fails. For a link, our server sends the text of the page, not the link. For a photo, OpenRouter first sends the photo to Google Gemini, which reads the text in the photo. Then that text goes to GLM or DeepSeek, like any other import. Section 6 names the companies that run these models.
We do not send your account ID, your name or your email address with an import. The app asks for your permission before your first import. Our server does not store or log the text, the link or the photo. We keep only a usage record for each import: your account ID, the time, how long it took, the AI model and provider, token counts, the cost of the photo read (for photo imports), and whether it worked. We use these records to count your free imports, to limit imports for everyone when the service has too much load, and to track cost.
For a link, our server fetches the page itself, so the website sees our server, not your device. For TikTok links, our server first asks TikTok’s public embed service for the post caption.
Some websites block our server. When a website blocks our server, the app downloads the page on your device, so the website sees your device, as it does when you open the page in a browser. The app, or on iOS the Boha share option in Safari, then sends the page content and its link to our server to read the recipe. If you were signed in to that website, the page content can include your name or other details that the page shows. We use the page content only to read the recipe. Our server does not store or log the page content or the link.
If you save the imported recipe, the recipe and its source link are stored like any recipe you create. For a recipe imported from a website, we also store the link to the website’s own photo of the recipe, but not the photo.
For a recipe imported from a website, the app, and the recipe’s share web page, show the website’s photo by loading it from that website, so that website can see the viewer’s device address (IP address), like any web page.
Subscription
Imports past the free allowance need Boha Pro: a subscription or a one-time lifetime purchase, bought through the Apple App Store or Google Play. We never see your payment card. Apple or Google handle the payment. RevenueCat tells our server whether you have Boha Pro, linked to your account ID. We store only that status and its end date, if it has one.
On your device
Your settings and your unsaved drafts stay on your device and in your own device backup. The import queue (text, links, web pages and photos waiting to be read) also stays on your device, but it is never backed up. It is deleted when each import ends or when you remove it. The app also keeps a list of the websites that blocked our server, so that it reads their pages on your device the next time. The list holds only the site names, such as example.com, never the pages or links. Each name is kept for 30 days. The list stays on your device and in your own device backup, and the app removes it when you delete your account. The app asks for camera access only when you take a photo to import.
Server logs
Our server logs each request’s method, path without its query string, status code and duration, and it logs errors. The logs never contain query strings, request bodies, sign-in tokens, recipe text, import text, links, web page content, photos or report notes. The company that hosts our server may keep standard network logs, such as IP addresses, for security.
Website
Our website, boha.starb.ca, is hosted on Cloudflare Pages. It uses no cookies, no tracking and no analytics. It loads its fonts from its own server, not from another company. Like any web host, Cloudflare handles your IP address and the pages you ask for, to deliver them and to protect the site.
What we do not collect
We do not collect your location, contacts, advertising ID or browsing history. We do not use cookies or trackers in the app. The app contains no advertising or analytics code.
4. Why we use it
- To run your account and show your recipes, profile and activity to you and, when you choose, to others.
- To import recipes when you ask.
- To count free imports, apply limits and manage your subscription.
- To keep the service safe: blocks, reports, removing content that breaks our Terms.
- To answer your messages.
We use your information only for these purposes. When you use a feature, you consent to the processing it needs. You can withdraw consent by stopping use of the feature or deleting your account.
5. What other people can see
- Your handle, display name, profile picture, bio and counts (followers, following, public recipes) are public.
- Public recipes, their like counts, and the comments on them (with the commenter’s name) are public. Anyone can see them without an account. Who liked a recipe is not shown.
- Unlisted recipes are visible to anyone with the link. You can reset the link.
- Private recipes are visible only to you (see the photo note in section 3).
6. Service providers
We use these providers to run the app. Each one gets only what it needs for its task.
| Provider | What it does | Data | Location |
|---|---|---|---|
| Supabase | Sign-in and accounts, and hosts our database | Email, name, profile picture, sessions, IP address, device data; profile, recipes, activity, reports, import usage records, subscription status | Canada (region to be confirmed); company in the United States |
| Server host (not yet chosen) | Runs our server | Everything the server handles, while it handles it | To be confirmed; this policy will be updated |
| Cloudflare (R2, Pages) | Stores and serves photos, and hosts our website | Recipe photos; for website visits, your IP address and the pages you ask for | Global network, company in the United States |
| OpenRouter | Sends import requests to AI models | Import text, page text or photo, for the time of the request | United States |
| AI models reached through OpenRouter: GLM (made by Z.ai, usually run by DeepInfra or NextBit), DeepSeek (run by a host that OpenRouter chooses) and Gemini (made and run by Google) | GLM and DeepSeek turn the import text into a recipe. Gemini reads the text in an import photo. | Import text or page text (GLM, DeepSeek); import photo (Gemini); for the time of the request | Mostly United States; may vary |
| RevenueCat | Subscription status | Account ID, purchase and renewal events | United States |
| Apple, Google | App stores and payments | Under their own privacy policies | United States |
| Email: Cloudflare (Email Routing) and Google (Gmail) | Cloudflare receives email sent to our support address and forwards it to Gmail. Gmail keeps our email and sends our replies, and the report alerts that our server sends to us. | Your email address and the content of the emails you send us or we send you; in a report alert, the report ID, what was reported (type and ID) and the reason (never your note) | United States (Cloudflare: global network) |
AI and your imports: OpenRouter prompt logging is turned off in our account, so OpenRouter does not keep the content of your imports. Every import request we send also asks OpenRouter to use only hosts that do not keep or train on the data. The hosts’ own terms also apply.
7. Information stored outside Quebec
Most of the providers above are outside Quebec, mainly in the United States. Before we send personal information outside Quebec, we assess whether it will be properly protected, as Quebec law requires. We use providers with written terms that limit their use of the data, we send the least data we can, and we encrypt data in transit. Information held outside Canada may be accessible to courts and authorities in that country.
8. How long we keep it
- Your account data, recipes and activity: until you delete them or your account.
- Import text, links, web page content and photos: not kept on our server. They pass through during the request.
- Import usage records and subscription status: until you delete your account.
- The list of websites that blocked our server, on your device: 30 days for each site name, and removed when you delete your account.
- Reports: until you delete your account, or until we close them if we no longer need them.
- Backups made by our database host may keep deleted data until they expire, within 30 days.
9. Deleting your account
In the app, tap the profile button at the top of the Home screen to open You. Under Account, choose Delete Account. This deletes, from our database: your profile, your recipes and their photo records, your comments, likes, saves, follows, blocks, the reports you filed, your import usage records and your shared-with-me list. It also deletes your sign-in account at Supabase, your subscription status, and your RevenueCat customer record. Your photo files are then deleted from storage. Counts on other people’s profiles and recipes are corrected.
Copies in our database host’s backups roll off within 30 days. Purchase records held by Apple or Google are governed by their own privacy policies.
Deleting your account does not cancel a subscription. Cancel it in your App Store or Google Play settings.
You can also ask us to delete your account by email.
10. Your rights
Under Quebec law (Law 25) and Canadian federal law (PIPEDA), you can:
- ask what personal information we hold about you and get a copy, including in a structured, commonly used technology format;
- ask us to correct information that is wrong or incomplete;
- ask us to delete your information, or withdraw your consent;
- ask how we got the information and who we shared it with;
- ask us to stop spreading your information, or to de-index a link to it, when spreading it breaks the law or a court order, or seriously harms your reputation or privacy (Law 25, s. 28.1).
You can edit or delete most of your information yourself in the app. For anything else, email the Privacy Officer at support@boha.starb.ca. We answer within 30 days. We may need to confirm who you are first.
If you are not satisfied with our answer, you can complain to the Commission d’accès à l’information du Québec, or to the Office of the Privacy Commissioner of Canada.
11. Security
Data travels over encrypted connections. Access to the database and storage is limited to the operator and protected by keys that are never in the app. If a confidentiality incident creates a risk of serious injury, we will notify the Commission d’accès à l’information and the people affected, and keep a record of the incident, as the law requires.
12. Children
Boha is not intended for children under 16. You must be 16 or older to create an account. If you believe a child under 16 has an account, contact us and we will delete it.
13. Changes to this policy
We will update this page when the app changes what it does with your information, and change the date at the top. If a change is important, we will tell you in the app before it applies.
14. Contact
Privacy Officer, Boha: support@boha.starb.ca
See also our Terms of Use. Version française : Politique de confidentialité.