Tastease
Simple, delicious.
← Back to Tastease

Privacy Policy

Effective date: June 14, 2026
Operator: Develemit LLC
Contact: [email protected]

This Privacy Policy explains how Tastease (tastease.app) collects, uses, and protects your personal data. By using the service you agree to this policy.

1. Who We Are

Tastease is operated by Develemit LLC. For privacy inquiries, contact us at [email protected].

2. Data We Collect

We collect only what we need to operate the service:

CategoryDataSource
IdentityName, email address, profile picture (Google only)Google OAuth, Apple OAuth, or email magic link at sign-in
AccountHousehold name, member namesUser-entered
Meal dataMeals, recipes, cooking notes, ratingsUser-created
Planning dataWeekly plans, shopping listsUser-created
PreferencesDietary notes, cook time preferences, Kroger store locationUser-entered
BillingStripe Customer ID, subscription status and datesStripe webhook
Kroger tokensOAuth access token and refresh tokenKroger OAuth (only if you connect Kroger)
ObservabilityPage views, API errors, billing eventsemit-vision (internal monitoring)
InfrastructureServer logs, request IP addressesnginx / Docker

We do not collect: payment card numbers (handled by Stripe), passwords (sign-in is via Google OAuth, Apple OAuth, or email magic link — we never set or store one), health data, precise location, device fingerprints, or advertising identifiers.

3. How We Use Your Data and Our Lawful Basis (GDPR)

Data categoryPurposeGDPR basis
Identity, account, meal, planning, preferencesOperate the service you signed up forContract performance (Art. 6(1)(b))
BillingProcess payments and comply with tax obligationsContract + legal obligation (Art. 6(1)(b)/(c))
Kroger OAuth tokensAdd items to your Kroger cart at your directionConsent (Art. 6(1)(a)) — you explicitly connect Kroger
Observability and infrastructure logsMonitor uptime, debug errors, prevent abuseLegitimate interests (Art. 6(1)(f)) — internal only, never shared

4. Kroger Token Storage — Important Disclosure

When you connect your Kroger account, we store your OAuth access token and refresh token in our database in plaintext. This is appropriate for a single-household personal application where the token is stored server-side and never sent to your browser. If you are concerned, you can disconnect your Kroger account at any time in Settings, which immediately deletes the stored tokens.

5. Cookies and Session Storage

We use only strictly necessary cookies:

  • Session cookie (authjs.session-token or __Secure-authjs.session-token): keeps you signed in. Set by NextAuth v5. Deleted when you sign out.
  • CSRF token: prevents cross-site request forgery. Session-scoped.
  • Callback URL: temporary, used only during sign-in to redirect you back to where you were.

We do not use advertising cookies, third-party tracking pixels, or persistent analytics identifiers. No consent banner is shown because no non-essential cookies are set. See our Cookie Notice for full details.

6. Subprocessors

We share your data only with the following processors, under appropriate data processing agreements:

  • Stripe, Inc. — payment processing. stripe.com/privacy
  • Google LLC — OAuth authentication. policies.google.com/privacy
  • Apple Inc. — OAuth authentication. apple.com/legal/privacy
  • develemail (Develemit LLC) — email magic-link delivery, operated by the same entity. No third-party transfer.
  • The Kroger Co. — grocery cart integration (only if you connect Kroger). kroger.com/i/privacy-policy
  • GitHub, Inc. — container image hosting (GHCR). No personal data in images. github.com privacy policies
  • emit-vision (Develemit LLC) — internal observability and uptime monitoring, operated by the same entity. No third-party transfer.

We do not sell your personal data and do not share it with advertising networks.

7. Data Retention

  • Active accounts: retained until you request deletion.
  • Deleted accounts: purged from our systems within 30 days of deletion.
  • Stripe billing records: retained for 7 years to comply with tax and accounting obligations.
  • Observability logs: retained for 90 days then automatically deleted.
  • Kroger tokens: deleted immediately when you disconnect Kroger or delete your account.

8. Data Security

We use TLS encryption for all data in transit. Our PostgreSQL database is hosted on encrypted storage. We perform daily automated backups with 7-day retention. Kroger tokens are stored server-side only and are never sent to your browser. Access to production infrastructure is restricted to the operator.

9. Your Rights (GDPR — EU/EEA Users)

If you are in the EU or EEA, you have the following rights:

  • Access: request a copy of the personal data we hold about you.
  • Rectification: correct inaccurate data.
  • Erasure: delete your account via Settings > Delete Account, or email us.
  • Portability: request your data in a machine-readable format by emailing [email protected].
  • Restriction and objection: limit or object to processing in certain circumstances.
  • Withdraw consent: disconnect your Kroger account at any time to withdraw consent for token storage and Kroger-related processing.
  • Lodge a complaint: you may complain to your local data protection authority.

To exercise any right, email [email protected]. We will respond within 30 days.

10. Your Rights (CCPA/CPRA — California Residents)

  • Right to know: what personal data we collect and how we use it (see Section 2 above).
  • Right to delete: request deletion via Settings > Delete Account or email.
  • Right to correct: update inaccurate information.
  • Right to opt out of sale: we do not sell your personal data. There is nothing to opt out of.
  • Non-discrimination: we will not discriminate against you for exercising these rights.

11. Children's Privacy

Tastease is not directed to users under 13 (under 16 in the EU/EEA). We do not knowingly collect personal data from minors. For sign-in via Google or Apple OAuth, those providers' own age verification adds a layer of enforcement; email magic-link sign-in relies on the age representation you make under our Terms of Service. If we learn we have inadvertently collected data from a minor, we will delete it promptly.

12. International Data Transfers

Your data is hosted on servers in the United States. If you are in the EU/EEA, your data is transferred to the US under appropriate safeguards. Stripe, Google, and Apple publish Standard Contractual Clauses (SCCs) for their international transfers. For transfers via our own infrastructure, we rely on the EU-US Data Privacy Framework where applicable.

13. Changes to This Policy

We may update this policy. For material changes, we will notify you by email at least 30 days before the change takes effect. The effective date at the top of this page will always reflect the current version.

14. Contact

Develemit LLC
Email: [email protected]

This document was prepared with AI assistance. It is not a substitute for legal advice. Last reviewed: June 2026.

Terms of ServicePrivacy PolicyCookie NoticeAcceptable Use Policy