Privacy Policy
Effective date: June 14, 2026
Operator: Develemit LLC
Contact: [email protected]
This Privacy Policy explains how Tastease (tastease.app) collects, uses, and protects your personal data. By using the service you agree to this policy.
1. Who We Are
Tastease is operated by Develemit LLC. For privacy inquiries, contact us at [email protected].
2. Data We Collect
We collect only what we need to operate the service:
| Category | Data | Source |
|---|---|---|
| Identity | Name, email address, profile picture | Google OAuth at sign-in |
| Account | Household name, member names | User-entered |
| Meal data | Meals, recipes, cooking notes, ratings | User-created |
| Planning data | Weekly plans, shopping lists | User-created |
| Preferences | Dietary notes, cook time preferences, Kroger store location | User-entered |
| Billing | Stripe Customer ID, subscription status and dates | Stripe webhook |
| Kroger tokens | OAuth access token and refresh token | Kroger OAuth (only if you connect Kroger) |
| Observability | Page views, API errors, billing events | emit-vision (internal monitoring) |
| Infrastructure | Server logs, request IP addresses | nginx / Docker |
We do not collect: payment card numbers (handled by Stripe), passwords (Google OAuth only), health data, precise location, device fingerprints, or advertising identifiers.
3. How We Use Your Data and Our Lawful Basis (GDPR)
| Data category | Purpose | GDPR basis |
|---|---|---|
| Identity, account, meal, planning, preferences | Operate the service you signed up for | Contract performance (Art. 6(1)(b)) |
| Billing | Process payments and comply with tax obligations | Contract + legal obligation (Art. 6(1)(b)/(c)) |
| Kroger OAuth tokens | Add items to your Kroger cart at your direction | Consent (Art. 6(1)(a)) — you explicitly connect Kroger |
| Observability and infrastructure logs | Monitor uptime, debug errors, prevent abuse | Legitimate interests (Art. 6(1)(f)) — internal only, never shared |
4. Kroger Token Storage — Important Disclosure
When you connect your Kroger account, we store your OAuth access token and refresh token in our database in plaintext. This is appropriate for a single-household personal application where the token is stored server-side and never sent to your browser. If you are concerned, you can disconnect your Kroger account at any time in Settings, which immediately deletes the stored tokens.
5. Cookies and Session Storage
We use only strictly necessary cookies:
- Session cookie (
authjs.session-tokenor__Secure-authjs.session-token): keeps you signed in. Set by NextAuth v5. Deleted when you sign out. - CSRF token: prevents cross-site request forgery. Session-scoped.
- Callback URL: temporary, used only during sign-in to redirect you back to where you were.
We do not use advertising cookies, third-party tracking pixels, or persistent analytics identifiers. No consent banner is shown because no non-essential cookies are set. See our Cookie Notice for full details.
6. Subprocessors
We share your data only with the following processors, under appropriate data processing agreements:
- Stripe, Inc. — payment processing. stripe.com/privacy
- Google LLC — OAuth authentication. policies.google.com/privacy
- The Kroger Co. — grocery cart integration (only if you connect Kroger). kroger.com/i/privacy-policy
- GitHub, Inc. — container image hosting (GHCR). No personal data in images. github.com privacy policies
- healthchecks.io — uptime monitoring. No user data is sent. healthchecks.io/privacy
- emit-vision (Develemit LLC) — internal observability service operated by the same entity. No third-party transfer.
We do not sell your personal data and do not share it with advertising networks.
7. Data Retention
- Active accounts: retained until you request deletion.
- Deleted accounts: purged from our systems within 30 days of deletion.
- Stripe billing records: retained for 7 years to comply with tax and accounting obligations.
- Observability logs: retained for 90 days then automatically deleted.
- Kroger tokens: deleted immediately when you disconnect Kroger or delete your account.
8. Data Security
We use TLS encryption for all data in transit. Our PostgreSQL database is hosted on encrypted storage. We perform daily automated backups with 7-day retention. Kroger tokens are stored server-side only and are never sent to your browser. Access to production infrastructure is restricted to the operator.
9. Your Rights (GDPR — EU/EEA Users)
If you are in the EU or EEA, you have the following rights:
- Access: request a copy of the personal data we hold about you.
- Rectification: correct inaccurate data.
- Erasure: delete your account via Settings > Delete Account, or email us.
- Portability: request your data in a machine-readable format by emailing [email protected].
- Restriction and objection: limit or object to processing in certain circumstances.
- Withdraw consent: disconnect your Kroger account at any time to withdraw consent for token storage and Kroger-related processing.
- Lodge a complaint: you may complain to your local data protection authority.
To exercise any right, email [email protected]. We will respond within 30 days.
10. Your Rights (CCPA/CPRA — California Residents)
- Right to know: what personal data we collect and how we use it (see Section 2 above).
- Right to delete: request deletion via Settings > Delete Account or email.
- Right to correct: update inaccurate information.
- Right to opt out of sale: we do not sell your personal data. There is nothing to opt out of.
- Non-discrimination: we will not discriminate against you for exercising these rights.
11. Children's Privacy
Tastease is not directed to users under 13 (under 16 in the EU/EEA). We do not knowingly collect personal data from minors. Google OAuth's own age verification enforces this at sign-in. If we learn we have inadvertently collected data from a minor, we will delete it promptly.
12. International Data Transfers
Your data is hosted on servers in the United States. If you are in the EU/EEA, your data is transferred to the US under appropriate safeguards. Stripe and Google publish Standard Contractual Clauses (SCCs) for their international transfers. For transfers via our own infrastructure, we rely on the EU-US Data Privacy Framework where applicable.
13. Changes to This Policy
We may update this policy. For material changes, we will notify you by email at least 30 days before the change takes effect. The effective date at the top of this page will always reflect the current version.
14. Contact
Develemit LLC
Email: [email protected]
This document was prepared with AI assistance. It is not a substitute for legal advice. Last reviewed: June 2026.