法律文件
隐私政策
最后更新:2026年6月 · 生效日期:2026年6月1日
我们重视您的隐私。本政策说明 FridgeChef 收集哪些数据、如何使用以及您拥有哪些权利。我们不出售您的个人信息。
1. 数据控制者信息
本隐私政策适用于 FridgeChef(www.fridgechef.tech),由个人开发者运营,注册地:澳大利亚新南威尔士州。
联系方式:support@fridgechef.app
2. 我们收集哪些信息
| 数据类型 |
具体内容 |
收集方式 |
| 账号信息 |
邮箱地址、用户名、头像(Google 登录时获取姓名和头像) |
注册/登录时 |
| 认证数据 |
加密存储的密码哈希(邮箱注册)或 OAuth token(Google 登录) |
注册时,由 Supabase 处理 |
| 支付信息 |
支付记录、积分余额、订单 ID(不含信用卡号,由 Stripe 处理) |
购买积分时 |
| 使用数据 |
AI 查询时提交的食材列表(用于生成菜谱,不与身份绑定存储) |
使用 AI 功能时 |
| 本地数据 |
收藏菜谱、购物清单(存储在您设备的 localStorage,服务器不保存) |
使用功能时,仅本地 |
| 日志数据 |
IP 地址、浏览器类型、访问时间、页面访问记录 |
自动收集,由 Vercel 托管服务记录 |
3. 我们如何使用您的信息
- 提供服务:验证身份、管理积分余额、处理 AI 食材匹配请求。
- 支付处理:通过 Stripe 完成积分购买及退款流程。
- 服务改进:分析使用模式(匿名化),优化产品功能。
- 安全保障:检测异常访问,防止账号被盗和服务滥用。
- 服务通知:发送重要的账号或政策变更通知(不发送营销邮件,除非您主动订阅)。
我们不会将您的个人信息用于广告定向投放,也不会出售给第三方。
4. 第三方服务商
我们使用以下第三方服务处理数据,它们均有各自的隐私政策:
| 服务商 |
用途 |
处理的数据 |
| Supabase |
用户认证与数据库 |
邮箱、密码哈希、账号数据 |
| Stripe |
支付处理 |
支付卡信息、账单地址(Stripe PCI DSS 认证,FridgeChef 不接触卡号) |
| AI 引擎服务商 |
AI 菜谱生成 |
仅传输食材列表文本,不含任何个人身份信息 |
| Vercel |
服务器托管与 CDN |
访问日志(IP、请求时间),保留 30 天 |
| Google |
OAuth 登录(可选) |
姓名、邮箱、头像(仅您选择 Google 登录时) |
5. 数据存储与保留期限
- 账号数据:在您主动注销账号前长期保留。
- 支付记录:依据澳大利亚税务法规要求保留 7 年。
- AI 查询食材列表:不存储,查询完成后立即丢弃。
- 访问日志:由 Vercel 自动保留约 30 天后删除。
- 注销账号后:账号信息在 30 天内从我们的数据库中删除(支付记录依法保留)。
所有数据存储在 Supabase 的澳大利亚区域(ap-southeast-2,悉尼)服务器上。
6. Cookie 与本地存储
- 会话 Cookie:用于维持登录状态,关闭浏览器后自动清除(功能性 Cookie)。
- localStorage:在您设备上本地存储收藏菜谱、购物清单、语言偏好和积分余额。
- 我们不使用:广告追踪 Cookie、第三方分析 Cookie(如 Google Analytics)。
7. 数据安全
- 全站使用 HTTPS/TLS 加密传输。
- 密码通过 bcrypt 加密存储,我们无法获取您的明文密码。
- 依赖 Supabase 的企业级安全基础设施(SOC 2 认证)。
- 支付数据由 Stripe 处理(PCI DSS Level 1 认证),FridgeChef 不存储任何信用卡信息。
尽管我们采取了合理的安全措施,互联网传输无法保证 100% 安全。如发生数据泄露,我们将在 72 小时内通知受影响用户。
8. 您的权利(澳大利亚隐私法)
依据《澳大利亚隐私法 1988》(Privacy Act 1988)及澳大利亚隐私原则(APPs),您有权:
- 访问权:要求查看我们持有的您的个人信息。
- 更正权:要求更正不准确或过时的个人信息。
- 删除权:要求删除您的账号及个人数据(法律要求保留的除外)。
- 投诉权:如您认为我们违反了隐私法,可向澳大利亚信息专员办公室(OAIC)投诉:www.oaic.gov.au
行使上述权利,请发邮件至 support@fridgechef.app,我们将在 30 天内响应。
9. 欧盟用户(GDPR)
如您位于欧盟或欧洲经济区,您还享有 GDPR 赋予的额外权利,包括数据可携带权和限制处理权。我们处理您数据的法律依据为:履行服务合同(账号管理、支付)及合法利益(安全防护)。如需行使 GDPR 权利,请联系 support@fridgechef.app。
10. 未成年人
本服务不面向 13 岁以下儿童,我们不会故意收集未成年人的个人信息。如果您认为您的孩子在未经同意的情况下提交了个人信息,请立即联系我们,我们将及时删除相关数据。
11. 政策更新
我们可能不定期更新本隐私政策。更新后我们会修改页面顶部的"最后更新"日期。如涉及您权利的重大变更,我们将通过邮件提前 30 天通知注册用户。
12. 联系我们
如有任何隐私相关问题或数据请求,请联系:
Legal
Privacy Policy
Last updated: June 2026 · Effective: 1 June 2026
We value your privacy. This policy explains what data FridgeChef collects, how we use it, and your rights. We do not sell your personal information.
1. Data Controller
This Privacy Policy applies to FridgeChef (www.fridgechef.tech), operated by an individual developer registered in New South Wales, Australia.
Contact: support@fridgechef.app
2. What We Collect
| Data Type |
Details |
When Collected |
| Account Info |
Email address, username, avatar (name and avatar from Google if signing in via Google) |
On registration / sign-in |
| Auth Data |
Encrypted password hash (email sign-up) or OAuth token (Google sign-in) |
On registration, handled by Supabase |
| Payment Info |
Payment records, credit balance, order ID (no card numbers — handled by Stripe) |
On credit purchase |
| Usage Data |
Ingredient lists submitted for AI matching (used to generate recipes, not stored linked to identity) |
When using AI features |
| Local Data |
Saved recipes and shopping lists (stored in your device's localStorage; not on our servers) |
When using features, local only |
| Log Data |
IP address, browser type, access time, page visit records |
Automatically, recorded by Vercel hosting |
3. How We Use Your Information
- Service delivery: Verifying identity, managing credit balance, processing AI ingredient-match requests.
- Payment processing: Completing credit purchases and refunds via Stripe.
- Service improvement: Analysing usage patterns (anonymised) to optimise product features.
- Security: Detecting abnormal access, preventing account hijacking and abuse.
- Service notices: Sending important account or policy-change notifications (no marketing emails unless you opt in).
We do not use your personal information for targeted advertising and we do not sell it to third parties.
4. Third-Party Service Providers
We use the following third-party services, each with their own privacy policies:
| Provider |
Purpose |
Data Processed |
| Supabase |
Authentication & database |
Email, password hash, account data |
| Stripe |
Payment processing |
Card details, billing address (Stripe PCI DSS certified — FridgeChef never touches card numbers) |
| AI Engine Provider |
AI recipe generation |
Ingredient list text only — no personally identifiable information |
| Vercel |
Server hosting & CDN |
Access logs (IP, request time), retained 30 days |
| Google |
OAuth sign-in (optional) |
Name, email, avatar (only if you choose Google sign-in) |
5. Data Storage & Retention
- Account data: Retained until you voluntarily delete your account.
- Payment records: Retained 7 years as required by Australian tax law.
- AI query ingredient lists: Not stored — discarded immediately after the query completes.
- Access logs: Automatically deleted by Vercel after approximately 30 days.
- After account deletion: Account data is removed from our database within 30 days (payment records retained as legally required).
All data is stored on Supabase servers in the Australia region (ap-southeast-2, Sydney).
6. Cookies & Local Storage
- Session cookie: Maintains your signed-in state; cleared automatically when you close the browser (functional cookie).
- localStorage: Stores saved recipes, shopping list, language preference, and credit balance locally on your device.
- We do not use: Advertising-tracking cookies or third-party analytics cookies (e.g., Google Analytics).
7. Data Security
- All traffic is encrypted via HTTPS/TLS.
- Passwords are stored hashed with bcrypt — we cannot access your plaintext password.
- We rely on Supabase's enterprise-grade security infrastructure (SOC 2 certified).
- Payment data is handled by Stripe (PCI DSS Level 1 certified) — FridgeChef stores no card information.
Although we take reasonable security measures, no internet transmission can be guaranteed 100% secure. In the event of a data breach we will notify affected users within 72 hours.
8. Your Rights (Australian Privacy Law)
Under the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs) you have the right to:
- Access: Request a copy of the personal information we hold about you.
- Correction: Request correction of inaccurate or outdated information.
- Deletion: Request deletion of your account and personal data (subject to legal retention requirements).
- Complaint: If you believe we have breached the Privacy Act, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC): www.oaic.gov.au
To exercise any of the above rights, email support@fridgechef.app. We will respond within 30 days.
9. EU Users (GDPR)
If you are located in the EU or EEA, you have additional rights under the GDPR including data portability and the right to restrict processing. The legal bases for our processing are: performance of a contract (account management, payments) and legitimate interests (security). To exercise GDPR rights, contact support@fridgechef.app.
10. Children
The Service is not directed at children under 13. We do not knowingly collect personal information from minors. If you believe your child has submitted personal information without consent, please contact us immediately and we will delete the relevant data promptly.
11. Policy Updates
We may update this Privacy Policy from time to time. We will update the "Last updated" date at the top of this page. For material changes affecting your rights, we will notify registered users by email at least 30 days in advance.
12. Contact Us
For any privacy-related questions or data requests: