Privacy
Last updated 8 October 2026
The short version
We collect what the product needs to work: your email, your first name, and what you tell us is in your kitchen. That is close to all of it.
We never sell or rent your information or your email address. Not to anyone, not for any price, not ever. Nobody gets it for their own marketing. That is the promise that matters, and it is the one thing on this page that will never get looser.
We do measure how the site is used, because we would be running it blind otherwise. This changed on 29 September 2026. Until then we only counted page views from our own server's logs. We now also use an analytics service, HeyCatch, which sees the pages you open and the things you click, and, if you have an account, your name and email address so that we can tell one cook's visit from another's. We use it to understand how the site is used and to measure our own marketing and advertising: which of our links, posts and ads bring people here, and what they do when they arrive. It works for us and for nobody else. We do not show advertising on this site, and we do not ask your browser where you are.
Three things leave our server: your ingredient list goes to the recipe search and to the AI models that write and adapt recipes, and how you use the site goes to the analytics service. If you choose a paid plan, our payment processor, Stripe, takes your card details directly; they never reach us. Section 5 says exactly who, and exactly what they get.
This changed on 8 October 2026. Paid plans start on 1 December 2026, so this page now says what happens when you pay. You can also now write your own recipes and add a photo of the finished dish; both are kept with your account.
Who we are
FridgeToForks is run by Scott Rosano through his company, Gigbuilder, based in Murphy, North Carolina, USA. The site and its database run on our own server. He is the person responsible for your information, and you can reach him at support@gigbuilder.com. There is more about who he is on the about page.
What we collect
Your account
- Your email address and your first name.
- If you use a password: a scrambled version of it (argon2id), never the password itself. We cannot read it, and we cannot tell you what it is.
- If you sign in with Google: an identifier Google gives us for your account, plus your email address and first name. See section 6.
- Whether you have confirmed your email address.
What you tell us about your kitchen
- The ingredients you add, and whether each is a staple or something you have right now.
- The appliances and equipment you own.
- Any preferences or dietary restrictions you set.
What you do here
- Recipes you save, cook, or make notes on.
- Recipes you write yourself, and a photo of the finished dish if you add one. A recipe you mark as shared can be seen by other cooks once we have checked it; one you keep to yourself is seen only by you.
- Your shopping list.
- Questions you ask the chef, and its answers, so the conversation makes sense next time you open it.
- A count of how many searches you have run, which is how we keep one account from running up a bill for everyone else.
If you pay for a plan
FridgeToForks is free, with no card, until 1 December 2026 for accounts opened by 15 November 2026; accounts opened after that get seven days free. After that, full access is $5 a month or $50 a year (see the pricing page). If you choose a plan, you pay through Stripe, and we keep:
- Stripe's reference numbers for you and your subscription.
- Which plan you are on (monthly or yearly), whether it is active, and the date it is paid up to.
- The billing notices Stripe sends us when something changes, such as a payment going through or failing. These can include your name, email address, the amount, and the brand and last four digits of your card.
Technical
- One session cookie of our own, and a visitor identifier kept by our analytics service. See section 4.
- Which pages you open and what you click, recorded by our analytics service. See section 5.
- Your browser's user agent string, stored with your session so you can tell your own sessions apart.
- Ordinary web server logs, which include IP addresses and the pages requested. We do not put these into any profile of you.
What we do not collect
- No card numbers. You type your card details into Stripe's own payment page, and they go straight to Stripe. We never see or store your full card number or its security code. Until your free time ends we do not ask for a card at all.
- No advertising on this site. We show no ads here, and nothing you do here is sold to an advertiser or an ad network. We do advertise FridgeToForks elsewhere, and we measure whether that works; see section 5.
- Nothing for sale. What we measure is how the site is used and how people found it, so we can fix what is confusing, see what is worth building, and tell which of our own marketing is working. It is never sold, and no other company gets it to use for itself.
- No location. We never ask your browser for it.
- No contacts or files from your device, and no photos except a picture of a dish you choose to add to your own recipe. We store that picture re-saved without its hidden details (such as where it was taken). Photos of a recipe card, a shelf or a receipt are read once to fill in the form and are not kept.
Cookies
One cookie, called ftf_session. It is what keeps you signed in.
It holds a random value, not your name or email, and it cannot be read by
JavaScript on the page. It lasts thirty days, and signing out deletes it.
That is the only cookie of our own that we set for cooks. Our analytics and marketing measurement service, HeyCatch, also keeps a random visitor identifier in your browser (in its storage, and in a cookie on this site), so that two pages opened by the same browser count as one visit. It is only ever read on this site. There are no cookies from ad networks and no cookies that follow you to other websites. Staff signing in to our own back office get a second cookie, which never touches a cook's browser.
If your browser blocks trackers or you use a content blocker, the analytics simply do not run, and nothing on the site stops working.
Who else sees your information
We do not sell or rent your information or your email address, to anybody, at any price. We do not share it for anyone else's marketing, and we never will. These are the only companies that receive any of it, and only for the job listed.
| Who | What they get | Why |
|---|---|---|
| OpenRouter, and through it the AI model providers | Your ingredient list, recipe text, and anything you type into Ask the Chef. | To work out what you can cook, rewrite a method for your appliances, and answer your questions. |
| Spoonacular | The names of ingredients you have. | To search a recipe database for matches. Your name and email are not sent. |
| Stripe (payments) | Only if you choose a paid plan: your email address, your card details (entered on Stripe's own page, never sent through us), and your billing address if Stripe asks for it. | To take payment for your plan, send your receipts, and handle renewals, cancellations and refunds. Stripe also uses payment information to prevent fraud, under its own privacy policy. |
| Only if you choose Sign in with Google. See section 6. | To confirm you are who you say you are. | |
| HeyCatch (analytics), which runs on PostHog | The pages you open, what you click, the site you arrived from, your browser and device type, and your IP address as the request arrives. If you have an account: your account identifier, first name, email address and plan, and the fact that you signed up or confirmed your email. It does not receive your password, and we do not send it your kitchen contents, though the text of a button or link you click is recorded. | To see how the site is used, where people get stuck, and which changes help; and to measure our own marketing and advertising, meaning which link, post or ad brought a visitor and whether they signed up. It works on our instructions only. |
| Google Fonts | Your IP address and browser, when the page loads a font. | The site's typefaces are served from Google Fonts. This happens on every page, whether or not you have an account. |
We may also share information if the law requires it, or to protect someone's safety. If we are ever asked for your data by a legal process, we will tell you unless we are forbidden from doing so.
Sign in with Google
This is optional. There is a password option and it works just as well.
If you use it, Google tells us a permanent identifier for your account, your email address, whether Google has confirmed that address, and your name. We store the identifier, your email, and your first name. We never see your Google password, and we get no access to your Gmail, Drive, contacts, calendar, or anything else. We cannot post anything as you.
We use the identifier rather than your email address to recognise you, so that changing your Google email does not lock you out, and so an email address that later belongs to somebody else does not open your account.
If a FridgeToForks account already exists with the same email address, we connect the two so that either method signs you in, but only when Google has confirmed that the address is really yours.
How long we keep it
- Your account and kitchen: until you ask us to delete it.
- Billing records: for as long as the law requires us to keep records of payments, even after you cancel or delete your account. Stripe keeps its own records under its own policy.
- Sessions: thirty days in a browser, and they are deleted when you sign out or change your password.
- Email confirmation and password reset links: forty eight hours and two hours respectively, then they stop working.
- Server logs: a short rolling window, two weeks, for diagnosing faults. The anonymous daily counts derived from them are kept longer, because a year-on-year comparison is the only thing they are for.
Your choices
You can see and change your kitchen, saved recipes and shopping list at any time while signed in, and remove any item yourself.
For anything else, email support@gigbuilder.com and we will:
- tell you what we hold about you,
- correct anything that is wrong,
- send you a copy of your data,
- or delete your account and everything attached to it.
We will not make you jump through hoops, and we will not charge you. Ask from the email address on the account, or we cannot safely tell it is you. Depending on where you live you may have further rights, including under the GDPR or California law; we will honour those requests the same way.
Security
The whole site is served over HTTPS. Passwords are stored using argon2id, a deliberately slow algorithm chosen so that stolen data is not usable. Session tokens are stored only as a hash, so a copy of our database does not hand anyone a working session. Access to the server is limited to the people who run it.
No system is perfect. If you find a security problem, please tell us at support@gigbuilder.com and we will take it seriously.
Children
FridgeToForks is not intended for children under 13, and we do not knowingly collect information from them. If you believe a child has given us information, email us and we will remove it.
Where your data is held
Our server is in the United States. The companies in section 5 process data in the United States and possibly elsewhere. If you are using the site from outside the United States, your information will be handled there.
Changes to this policy
If we change it, we will update the date at the top. If a change matters to you, for example if we ever start collecting something new, we will say so plainly rather than quietly editing this page.
Contact
Questions, requests, or complaints: support@gigbuilder.com.
See also the Terms of Service.