GestureCook Logo

GestureCook

  • Home
  • App
  • About
  • Account

Privacy Policy

Last updated: 20 September 2026

1. Who is responsible

Gesture Cook is operated by:

Silvan Metzker PickPost PT844713 Pumpwerkstrasse 56 8105 Regensdorf Switzerland

Email: [email protected]

Gesture Cook is offered to people in the European Union from outside it, so the GDPR applies alongside the Swiss Federal Act on Data Protection.

2. What we collect, and why

Account data — email address, display name, profile photo, username, and the identifier from Apple or Google if you sign in that way. Used to give you an account, keep your recipes attached to it, and show who wrote a public recipe. Legal basis: performance of our contract with you (Art. 6(1)(b) GDPR).

Recipes and content you create — recipe text, images, comments, ratings, favourites, lists, and whether a recipe is public or private. Legal basis: performance of our contract with you (Art. 6(1)(b)).

What you give to Miso, our AI assistant — text you type, photos you take of recipe cards or cookbook pages, and voice recordings you make when dictating. Legal basis: your consent (Art. 6(1)(a)), asked for in the app before anything is sent and withdrawable at any time. See section 3.

Device and usage data — device type, operating system, app version, a device identifier, IP address, the approximate region derived from it, and analytics events about which features are used. Legal basis: our legitimate interest (Art. 6(1)(f)) in operating, securing and improving the app.

Subscription data — your subscription status and history, through RevenueCat and the app stores. We never see your card details. Legal basis: performance of our contract with you (Art. 6(1)(b)).

What we do not collect

The camera feed used for gesture control never leaves your device. Hand-gesture recognition runs entirely on your phone, offline. No frame, image or video from it is transmitted or stored anywhere.

This is a different feature from scan a recipe, which does upload the photos you take — see the next section.

3. AI features (Miso)

Miso uses generative AI operated by OpenAI, acting as our processor. When you use Miso, this is sent to OpenAI so it can produce a recipe and return it to us:

  • text you type or dictate for Miso;
  • photographs you take of a recipe card, cookbook page or handwritten note;
  • audio recordings you make in the dictate flow.

We ask before the first time. The app asks for your permission, names OpenAI, and lists what is sent. Nothing is sent until you agree.

You can take it back. Turn it off under More → AI features. Miso then stops working; everything else — gesture control, your saved recipes, offline access, search, lists — keeps working normally.

Training. Your input is not used to train OpenAI's models or ours. OpenAI does not train on data submitted through its API by default, and we have not opted in.

Retention at OpenAI. OpenAI may keep inputs and outputs for up to 30 days for abuse monitoring, after which they are deleted, unless it is legally required to keep them longer.

Where it is processed. Under OpenAI's data processing addendum, OpenAI Ireland Limited processes data from the EEA and Switzerland. Any onward transfer to the United States is covered by the EU Standard Contractual Clauses.

Labelling. Recipes Miso wrote are labelled in the app and carry a machine-readable marker recording that they were AI-generated. That marker stays with the recipe after you edit it, because editing does not change where the text originally came from.

A word about photos. A photograph can capture more than you mean it to — the surface the card is lying on, other handwriting, people in the background. Please photograph only what you intend to send.

4. Who else receives data

WhoWhat for
Google (Firebase)Sign-in, database, file storage, cloud functions, analytics — our backend
OpenAIThe AI features in section 3, only with your consent
RevenueCatSubscription management
Apple / Google PlayApp distribution and payment; independent controllers for the purchase itself

We do not sell personal data, and we do not share it for advertising.

International transfers. These providers process data in the United States and elsewhere. Google LLC is certified under the EU–US Data Privacy Framework and also relies on the Standard Contractual Clauses. Transfers to OpenAI rely on the Standard Contractual Clauses in its data processing addendum, as described in section 3.

5. How long we keep it

  • Account data, recipes, lists and comments: while your account exists.
  • When you delete your account: everything goes — your profile, your public

recipes, your private recipes, your lists, your comments, your username and all your uploaded images, along with your sign-in record. This is immediate and it cannot be undone. Public recipes you published are deleted too; they are not kept or anonymised.

  • Miso inputs: kept by OpenAI for up to 30 days for abuse monitoring, then

deleted. We do not store your raw Miso input separately after the recipe is made.

  • Device and usage data: up to 24 months, then aggregated.
  • Reports and moderation records: up to 24 months, so we can recognise repeat

problems and answer complaints.

6. Your rights

You can ask us to give you a copy of your data, correct it, delete it, restrict or object to how we use it, or send it to another service.

Where we rely on consent — which is the case for the AI features — you can withdraw it at any time, without affecting anything done before you did.

You can do two of these yourself, immediately: delete your account and all your data from inside the app, and turn off the AI features under More → AI features.

For anything else, email [email protected]. We answer within one month.

You can also complain to a supervisory authority: in Switzerland the Federal Data Protection and Information Commissioner (FDPIC), and in the EU the authority where you live.

7. Children

Gesture Cook is not directed at children and you must be at least 16 to use it. We do not knowingly collect data from anyone under 16. If you believe a child has given us data, email us and we will delete it.

8. Security

Data travels over encrypted connections and is stored with the providers listed in section 4. No service can promise perfect security, but we take reasonable technical and organisational measures to protect your data.

9. Changes

Changes are posted on this page with a new date at the top. If a change materially affects how we use your data, we will tell you in the app before it takes effect.

10. Contact

[email protected] Silvan Metzker PickPost PT844713 Pumpwerkstrasse 56 8105 Regensdorf Switzerland

SupportPrivacy PolicyTerms of Service
© 2026 All rights reserved