Skip to main content
Rationale:The Design Practice of Matt Hanson

LEGAL

Privacy Policy for Heirloom

Effective Date: December 23, 2025
Last Updated: December 23, 2025

Introduction

Welcome to Heirloom. We respect your privacy and are committed to protecting your personal information. This Privacy Policy explains how we collect, use, store, and protect your information when you use the Heirloom app ("App," "we," "us," or "our").

By using Heirloom, you agree to the collection and use of information in accordance with this policy.

Information We Collect

1. Recipe Data You Create

When you use Heirloom, you create and store:

  • Recipe titles, instructions, and ingredient lists
  • Photos you add to recipes
  • Personal notes, comments, and modifications
  • Collections, tags, and organizational data
  • Cooking history and favorites
  • Dinner party planning information

Storage: This data is stored locally on your device and, if you enable iCloud sync, in your private iCloud account.

2. Usage Information

We may collect limited, anonymized usage data to improve the App:

  • Feature usage statistics (which features are used most)
  • Error logs and crash reports
  • App performance metrics

Important: This data is anonymous and cannot be used to identify you personally.

3. Photos and Camera Access

If you grant camera permissions:

  • We access your camera to scan cookbook pages or photograph food
  • Photos are processed locally on your device
  • We do not upload photos to our servers unless you explicitly share recipes with others

4. AI-Powered Features

When you use AI features (ingredient parsing, recipe enhancement):

  • Recipe text is sent to Anthropic (Claude AI) for processing
  • This data is processed according to Anthropic's privacy policy
  • Anthropic does not train AI models on your data
  • We do not store AI requests beyond your device

Your Control: You can disable AI features at any time in Settings → AI Features.

How We Use Your Information

We use your information solely to:

  • Provide core app functionality (store and display your recipes)
  • Sync your recipes across your Apple devices via iCloud
  • Enable AI-powered recipe parsing and enhancement (if enabled)
  • Improve app performance and fix bugs
  • Respond to your support requests

We do NOT:

  • Sell your personal information to third parties
  • Use your data for advertising
  • Track your behavior across other apps or websites
  • Share your recipes without your explicit consent

Data Storage and Security

Local Storage

  • All recipe data is stored locally on your device using Apple's secure SwiftData framework
  • Your device's operating system protects this data with encryption
  • We cannot access your locally stored data

iCloud Sync (Optional)

  • If you enable iCloud sync, your recipes are stored in your private iCloud account
  • iCloud data is encrypted in transit and at rest
  • Apple controls iCloud security; we do not have access to your iCloud data
  • You can disable iCloud sync at any time in Settings

Photos

  • Recipe photos are stored locally on your device to save iCloud storage
  • Photos are NOT uploaded to our servers
  • Photos are only shared when you explicitly share a recipe

API Keys (Advanced Users)

  • If you add your personal Anthropic API key, it is stored securely in your device's iOS Keychain
  • API keys are never transmitted to our servers
  • We cannot access your API key

Recipe Sharing

iCloud Sharing

When you share a recipe via iCloud:

  • The recipe is shared through Apple's CloudKit infrastructure
  • Recipients with the link can view and save the recipe
  • You control who has access by managing the share link
  • You can revoke sharing access at any time

Pass Down Feature

When you "Pass Down" a recipe:

  • The recipe is shared with attribution (recipe provenance)
  • Recipients can see the recipe's lineage (who passed it down)
  • This feature uses CloudKit and follows the same security as iCloud sharing

Export (Text/PDF)

When you export a recipe:

  • The recipe is converted to text or PDF on your device
  • You control where the exported file is sent (Messages, Email, etc.)
  • We do not track or store exported recipes

Third-Party Services

Anthropic (Claude AI)

  • Used for AI-powered ingredient parsing and recipe enhancement
  • Data sent: Recipe text only (when you use AI features)
  • Anthropic Privacy Policy: https://www.anthropic.com/privacy
  • Anthropic does not use your data to train AI models

Apple iCloud

Recipe Import Sources

When you import recipes from websites:

  • The App fetches recipe data directly from the source website
  • We do not track which websites you visit
  • Imported recipes are stored locally on your device

Your Rights and Choices

Access Your Data

All your recipe data is accessible within the App at any time.

Delete Your Data

  • Delete individual recipes: Swipe left on any recipe
  • Delete all data: Settings → Data Management → Clear All Data
  • Uninstalling the app removes all local data from your device

Disable iCloud Sync

Settings → Cloud Storage → iCloud Sync → Toggle Off

This removes your recipes from iCloud but keeps them on your device.

Disable AI Features

Settings → AI Features → Toggle off individual features

This prevents any data from being sent to AI services.

Export Your Data

You can export individual recipes as text or PDF files at any time.

Children's Privacy

Heirloom is intended for general audiences. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, please contact us, and we will delete it promptly.

Data Retention

  • Local Data: Retained until you delete it or uninstall the app
  • iCloud Data: Retained until you delete it or disable iCloud sync
  • AI Processing: Data is not retained after processing (processed in real-time)
  • Usage Analytics: Anonymous data retained for 90 days for app improvement

International Users

Heirloom is designed for use worldwide. Your data may be processed in:

  • Your local device (all countries)
  • Apple's iCloud infrastructure (data centers globally)
  • Anthropic's AI infrastructure (United States)

If you are in the European Union, you have additional rights under GDPR (see "Your Rights" section).

Changes to This Privacy Policy

We may update this Privacy Policy from time to time. Changes will be posted:

Significant changes will be accompanied by a prominent notice in the App.

Your Privacy Rights (GDPR & CCPA)

For EU Users (GDPR)

You have the right to:

  • Access your personal data
  • Rectify inaccurate data
  • Erase your data ("right to be forgotten")
  • Restrict or object to data processing
  • Data portability (export your data)

For California Users (CCPA)

You have the right to:

  • Know what personal information is collected
  • Know if personal information is sold (we do not sell data)
  • Opt-out of data sales (not applicable)
  • Delete your personal information
  • Non-discrimination for exercising your rights

To exercise these rights, contact us at privacy@rationale.work.

Contact Us

If you have questions about this Privacy Policy or your data:

We will respond to privacy inquiries within 30 days.

Legal Basis for Processing (GDPR)

We process your data based on:

  • Consent: You choose to use the App and enable features
  • Contract Performance: Providing the App services you requested
  • Legitimate Interests: Improving the App and fixing bugs (anonymized data)

Data Security Measures

We implement industry-standard security practices:

  • Local data encrypted by iOS
  • iCloud data encrypted in transit (TLS) and at rest
  • API keys stored in iOS Keychain (hardware-backed encryption)
  • No servers means no server breaches
  • Regular security reviews and updates

Analytics and Tracking

We do NOT use:

  • Advertising trackers
  • Third-party analytics (e.g., Google Analytics, Facebook Pixel)
  • Cross-site tracking
  • Behavioral profiling

We may collect (optional, anonymized):

  • Crash reports to fix bugs
  • Feature usage counts to prioritize development
  • This data cannot identify you personally

Cookies and Similar Technologies

Heirloom is a native iOS app and does not use cookies. If you access our website (if applicable), we may use cookies as described in our separate Website Privacy Policy.

Your Consent

By using Heirloom, you consent to this Privacy Policy. If you do not agree, please do not use the App.

Summary (Plain English)

  • Your recipes stay on your device (and your iCloud if you enable it)
  • We don't sell your data or show you ads
  • AI features send recipe text to Anthropic (you can disable this)
  • You can delete your data anytime
  • We can't access your recipes—they're yours
  • Recipe sharing is optional and controlled by you

Questions? Contact us at privacy@rationale.work.

This Privacy Policy was last updated on December 23, 2025.