LEGAL
Privacy Policy for Heirloom
Effective Date: December 23, 2025
Last Updated: December 23, 2025
Introduction
Welcome to Heirloom. We respect your privacy and are committed to protecting your personal information. This Privacy Policy explains how we collect, use, store, and protect your information when you use the Heirloom app ("App," "we," "us," or "our").
By using Heirloom, you agree to the collection and use of information in accordance with this policy.
Information We Collect
1. Recipe Data You Create
When you use Heirloom, you create and store:
- Recipe titles, instructions, and ingredient lists
- Photos you add to recipes
- Personal notes, comments, and modifications
- Collections, tags, and organizational data
- Cooking history and favorites
- Dinner party planning information
Storage: This data is stored locally on your device and, if you enable iCloud sync, in your private iCloud account.
2. Usage Information
We may collect limited, anonymized usage data to improve the App:
- Feature usage statistics (which features are used most)
- Error logs and crash reports
- App performance metrics
Important: This data is anonymous and cannot be used to identify you personally.
3. Photos and Camera Access
If you grant camera permissions:
- We access your camera to scan cookbook pages or photograph food
- Photos are processed locally on your device
- We do not upload photos to our servers unless you explicitly share recipes with others
4. AI-Powered Features
When you use AI features (ingredient parsing, recipe enhancement):
- Recipe text is sent to Anthropic (Claude AI) for processing
- This data is processed according to Anthropic's privacy policy
- Anthropic does not train AI models on your data
- We do not store AI requests beyond your device
Your Control: You can disable AI features at any time in Settings → AI Features.
How We Use Your Information
We use your information solely to:
- Provide core app functionality (store and display your recipes)
- Sync your recipes across your Apple devices via iCloud
- Enable AI-powered recipe parsing and enhancement (if enabled)
- Improve app performance and fix bugs
- Respond to your support requests
We do NOT:
- Sell your personal information to third parties
- Use your data for advertising
- Track your behavior across other apps or websites
- Share your recipes without your explicit consent
Data Storage and Security
Local Storage
- All recipe data is stored locally on your device using Apple's secure SwiftData framework
- Your device's operating system protects this data with encryption
- We cannot access your locally stored data
iCloud Sync (Optional)
- If you enable iCloud sync, your recipes are stored in your private iCloud account
- iCloud data is encrypted in transit and at rest
- Apple controls iCloud security; we do not have access to your iCloud data
- You can disable iCloud sync at any time in Settings
Photos
- Recipe photos are stored locally on your device to save iCloud storage
- Photos are NOT uploaded to our servers
- Photos are only shared when you explicitly share a recipe
API Keys (Advanced Users)
- If you add your personal Anthropic API key, it is stored securely in your device's iOS Keychain
- API keys are never transmitted to our servers
- We cannot access your API key
Recipe Sharing
iCloud Sharing
When you share a recipe via iCloud:
- The recipe is shared through Apple's CloudKit infrastructure
- Recipients with the link can view and save the recipe
- You control who has access by managing the share link
- You can revoke sharing access at any time
Pass Down Feature
When you "Pass Down" a recipe:
- The recipe is shared with attribution (recipe provenance)
- Recipients can see the recipe's lineage (who passed it down)
- This feature uses CloudKit and follows the same security as iCloud sharing
Export (Text/PDF)
When you export a recipe:
- The recipe is converted to text or PDF on your device
- You control where the exported file is sent (Messages, Email, etc.)
- We do not track or store exported recipes
Third-Party Services
Anthropic (Claude AI)
- Used for AI-powered ingredient parsing and recipe enhancement
- Data sent: Recipe text only (when you use AI features)
- Anthropic Privacy Policy: https://www.anthropic.com/privacy
- Anthropic does not use your data to train AI models
Apple iCloud
- Used for optional recipe syncing across your devices
- Apple Privacy Policy: https://www.apple.com/legal/privacy/
- We do not control Apple's data practices
Recipe Import Sources
When you import recipes from websites:
- The App fetches recipe data directly from the source website
- We do not track which websites you visit
- Imported recipes are stored locally on your device
Your Rights and Choices
Access Your Data
All your recipe data is accessible within the App at any time.
Delete Your Data
- Delete individual recipes: Swipe left on any recipe
- Delete all data: Settings → Data Management → Clear All Data
- Uninstalling the app removes all local data from your device
Disable iCloud Sync
Settings → Cloud Storage → iCloud Sync → Toggle Off
This removes your recipes from iCloud but keeps them on your device.
Disable AI Features
Settings → AI Features → Toggle off individual features
This prevents any data from being sent to AI services.
Export Your Data
You can export individual recipes as text or PDF files at any time.
Children's Privacy
Heirloom is intended for general audiences. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, please contact us, and we will delete it promptly.
Data Retention
- Local Data: Retained until you delete it or uninstall the app
- iCloud Data: Retained until you delete it or disable iCloud sync
- AI Processing: Data is not retained after processing (processed in real-time)
- Usage Analytics: Anonymous data retained for 90 days for app improvement
International Users
Heirloom is designed for use worldwide. Your data may be processed in:
- Your local device (all countries)
- Apple's iCloud infrastructure (data centers globally)
- Anthropic's AI infrastructure (United States)
If you are in the European Union, you have additional rights under GDPR (see "Your Rights" section).
Changes to This Privacy Policy
We may update this Privacy Policy from time to time. Changes will be posted:
- Within the App (Settings → Privacy Policy)
- On our website: https://rationale.work
Significant changes will be accompanied by a prominent notice in the App.
Your Privacy Rights (GDPR & CCPA)
For EU Users (GDPR)
You have the right to:
- Access your personal data
- Rectify inaccurate data
- Erase your data ("right to be forgotten")
- Restrict or object to data processing
- Data portability (export your data)
For California Users (CCPA)
You have the right to:
- Know what personal information is collected
- Know if personal information is sold (we do not sell data)
- Opt-out of data sales (not applicable)
- Delete your personal information
- Non-discrimination for exercising your rights
To exercise these rights, contact us at privacy@rationale.work.
Contact Us
If you have questions about this Privacy Policy or your data:
- Email: privacy@rationale.work
- App Support: Settings → Support → Contact Support
- Website: https://rationale.work
We will respond to privacy inquiries within 30 days.
Legal Basis for Processing (GDPR)
We process your data based on:
- Consent: You choose to use the App and enable features
- Contract Performance: Providing the App services you requested
- Legitimate Interests: Improving the App and fixing bugs (anonymized data)
Data Security Measures
We implement industry-standard security practices:
- Local data encrypted by iOS
- iCloud data encrypted in transit (TLS) and at rest
- API keys stored in iOS Keychain (hardware-backed encryption)
- No servers means no server breaches
- Regular security reviews and updates
Analytics and Tracking
We do NOT use:
- Advertising trackers
- Third-party analytics (e.g., Google Analytics, Facebook Pixel)
- Cross-site tracking
- Behavioral profiling
We may collect (optional, anonymized):
- Crash reports to fix bugs
- Feature usage counts to prioritize development
- This data cannot identify you personally
Cookies and Similar Technologies
Heirloom is a native iOS app and does not use cookies. If you access our website (if applicable), we may use cookies as described in our separate Website Privacy Policy.
Your Consent
By using Heirloom, you consent to this Privacy Policy. If you do not agree, please do not use the App.
Summary (Plain English)
- Your recipes stay on your device (and your iCloud if you enable it)
- We don't sell your data or show you ads
- AI features send recipe text to Anthropic (you can disable this)
- You can delete your data anytime
- We can't access your recipes—they're yours
- Recipe sharing is optional and controlled by you
Questions? Contact us at privacy@rationale.work.
This Privacy Policy was last updated on December 23, 2025.