FoodRef Privacy Policy
Last updated: July 11, 2026
FoodRef ("we," "us") operates the website foodref.ai, the FoodRef browser extension, and the FoodRef iOS app. This page explains what data we collect, how we use it, and the choices you have. The iOS app shows the foodref.ai website inside a native shell, so everything this policy says about the website applies equally in the app.
We've tried to write this in plain language. If anything is unclear, email us at cheferee@foodref.ai.
What we collect from the website
When you visit foodref.ai, our hosting provider (Vercel) and our database provider (Supabase) automatically receive standard web request information: your IP address, browser type, the page you requested, and the time of the request. This is the same information any website receives. We use it to operate the site, debug problems, and prevent abuse.
When you use the recipe scanner at foodref.ai/scan, we send the recipe text you paste to Anthropic's API to generate a diet scorecard. We also store the recipe text and the resulting scorecard in our database so the recipe has a permanent shareable URL. We store a hashed version of your IP address (not the IP itself) for the sole purpose of rate-limiting the scanner to prevent abuse. The hashed IP cannot be reversed to identify you. If you're signed in when you scan, the recipe is also linked to your account so you can find it in your saved recipes.
We use Vercel Web Analytics to count page views. It is cookieless: it sets no cookies, doesn't follow you across other sites, and gives us only aggregate numbers such as which pages are popular. We do not use advertising trackers or social media pixels on foodref.ai.
Accounts and saved preferences
You can use FoodRef without an account. If you create one, you sign in with a magic link sent to your email — we store your email address and never a password, because there isn't one. Signing in sets session cookies so you stay signed in; these are the only cookies FoodRef itself sets.
If you save a dietary profile, we store the diets you selected, the ingredients you avoid, your minimum-score threshold, and your preferred cuisines, linked to your account. Recipes you scan while signed in and recipes you upvote are also linked to your account.
Deleting your account (from your account page) immediately deletes your email address, dietary profile, and upvotes. Recipes you scanned stay public — they're shared pages other people may have bookmarked — but they are unlinked from you and no longer connected to any account.
Menu scanner (photos)
When you use the menu scanner at foodref.ai/menu, your photo is resized on your device, sent to our server, and passed to Anthropic's API to read the menu items. We do not store the photo — it is processed and discarded. We don't store the menu's text either. In the iOS app the scanner can use your camera or photo library, with your permission; photos taken there are handled exactly the same way.
What we do keep is a record of each scan: how many menu lines were read, how many dishes we matched and which ones, which diets you had active, a hashed version of your IP address (for rate limiting, as with the recipe scanner), and — if you're signed in — a link to your account. These records contain no photo and no menu text. Deleting your account unlinks them from you but doesn't delete them; once unlinked, nothing in them identifies you.
What we collect from the browser extension
The FoodRef browser extension sends the text you select on a webpage to foodref.ai's lookup API so we can return a diet scorecard. This is the only information sent. We do not read other content on the pages you visit, the URLs of those pages, your browsing history, or any personal information from the page.
The extension stores recently looked-up text and its scorecard locally on your device (in Chrome's local extension storage) for 24 hours so repeat lookups are instant and don't require another API call. This data never leaves your computer. You can clear it at any time by removing the extension or by clearing your browser's extension storage.
If the text you select is short, we look it up against our food database and nothing is stored. If you select a longer passage (roughly a full recipe) and it doesn't match a food, we score it as a recipe scan — and, just like the website scanner, the text and its scorecard are saved so the result has a permanent shareable URL. If you're signed in to foodref.ai in the same browser, that saved recipe is linked to your account. We do not use analytics or telemetry in the extension.
How we use what we collect
We use the data described above to:
- Operate and improve the FoodRef website, extension, and app
- Generate diet scorecards and menu matches in response to your requests
- Remember your dietary profile and tailor scores and results to it
- Prevent abuse of our APIs (via hashed-IP rate limiting on the recipe and menu scanners)
- Debug technical problems
We do not sell your data. We do not share your data with advertisers or marketing partners.
Third parties that process data on our behalf
To run FoodRef, we use the following service providers:
- Vercel hosts the website, runs our serverless API routes, and provides our cookieless web analytics.
- Supabase stores recipes, scorecards, accounts and dietary profiles, menu-scan records, and the hashed IPs used for rate limiting.
- Anthropic processes recipe text, selection text, and menu photos to generate diet scorecards and read menus.
These providers process data only as needed to provide their services to us and are bound by their own privacy practices. We don't grant them rights to use your data for their own purposes.
Affiliate links
Some pages on foodref.ai contain affiliate links to retailers such as Amazon. If you click an affiliate link and make a purchase, the retailer may pay us a commission. The retailer, not us, sees your purchase information. Affiliate links are clearly placed and do not require you to click them to use FoodRef.
Data retention
Recipes scanned via foodref.ai/scan are retained indefinitely so their shareable URLs continue to work. If you want a recipe you scanned removed, email us with the URL and we'll delete it.
Menu-scan records (the counts and matches described above — never photos or menu text) are retained indefinitely as anonymous usage data.
Hashed IPs used for rate limiting are stored on the recipe or menu-scan record they belong to and are retained with that record. They are salted hashes and cannot be reversed to identify you.
Your email address and dietary profile are retained until you delete your account.
Locally cached lookups in the browser extension are retained for 24 hours on your device, then automatically discarded.
Your rights
You can stop using the website or uninstall the extension at any time. Uninstalling the extension immediately deletes all locally cached data on your device.
If you have an account, you can download a copy of your data and delete your account yourself from your account page — no email required. Deletion is immediate: your email address, dietary profile, and upvotes are erased, and your scanned recipes and menu-scan records are unlinked from you as described above.
If you live in a jurisdiction that grants you specific data rights (such as the EU under GDPR, the UK under UK GDPR, or California under CCPA), you may have the right to request access to, correction of, or deletion of personal data we hold about you. To make a request, or for anything the account page doesn't cover, email cheferee@foodref.ai.
Children's privacy
FoodRef is not directed to children under 13 (or under 16 in the EU/UK). We don't knowingly collect data from children. If you believe a child has used FoodRef, please contact us and we'll delete any data associated with the request.
Changes to this policy
If we change this policy, we'll update the "Last updated" date at the top and, if the change is material, post a notice on the homepage for at least 30 days. Continued use of FoodRef after a change means you accept the updated policy.
Contact
Questions about this policy or about your data: cheferee@foodref.ai.