Privacy Policy

Ruchy · Effective 19 July 2026 · Operated by Raj Bharath, India.

This policy explains what personal data Ruchy ("we", "us") collects, why, who we share it with, and the rights you have under India's Digital Personal Data Protection Act, 2023 (DPDP). By using the app you agree to this policy.

1. Who we are

Ruchy is a recipe app that lets you save recipes from links, photos, and text, organise them, and cook them. The data controller ("Data Fiduciary" under DPDP) is Raj Bharath, contactable at hello@ruchy.app.

2. You do not create an account with personal details

Ruchy does not require your name, email, or phone number to work. On first launch the app creates an anonymous device identity (a random ID) so your recipes can back up to the cloud and sync across your own devices. We do not know who you are from this ID.

3. What we collect and why

DataWhyWhere it lives
Anonymous device IDSync and back up your own dataDevice + our cloud (Supabase)
Display name (optional, if you enter one)To greet you in the appDevice + cloud
Diet & allergy preferences (e.g. vegetarian, nut allergy)To suggest recipes you can safely eat and flag imports that clashDevice + cloud, and sent to our AI provider (see §4)
Recipes you save; meal plans; grocery & pantry lists; your food/nutrition logThe core features of the appDevice + cloud
Links, text, and photos you import to create a recipeTo read them into a structured recipeSent to our AI provider (see §4); the resulting recipe is stored
The web address a recipe came fromTo credit the original creator and let you reopen the source (see Terms §4)Device + cloud, saved with the recipe
Photos you take of your own cooked dishesTo illustrate your saved recipeDevice only — these are not uploaded

Sensitive data. Diet and allergy information can reveal health details. We collect it only to make recipe suggestions safe for you, we ask for it optionally, and you can clear it at any time in Settings.

4. AI processing and cross-border transfer

To turn a link, photo, or text into a recipe — and to filter recipe searches by your diet — the relevant content is sent to providers that process it on servers outside India (in the United States). Google (Gemini) reads recipes from links, photos and text. For Discover, Serper runs the web search and Google (Gemini) selects and formats the results; Anthropic (Claude) is used for that search only on an alternative configuration, and is not used when Serper is enabled.

What the search provider receives. When you use Discover, your search words are sent to Serper together with your country and language — and, if you have set a diet, that diet is added to the search text (for example a search becomes “vegan <your words> recipe”). Diet can reveal health information, and some values can imply religious practice, so we are naming this explicitly rather than describing it as ordinary search. Your name, device ID and allergy list are never sent to the search provider. If you would rather not send this, leave the diet setting unset or avoid Discover; every other part of the app works without it.

Before any content is sent for AI processing for the first time, the app shows you a consent screen describing exactly what is shared, and you must agree. We do not send your name or device ID to the AI provider with this content.

5. What we do NOT do

6. How long we keep it

We keep your data until you delete it. Deleting a recipe removes it (a short recovery window applies via the in-app bin). Deleting your account (see §8) removes your synced data from our cloud.

7. Who we share with (processors)

These providers process data on our behalf under their own security terms. We do not share your data with anyone for their own marketing.

8. Your rights under DPDP, and deleting your data

You have the right to access, correct, and erase your personal data, to withdraw consent, and to grievance redressal.

9. Grievance Officer (required by DPDP)

If you have a complaint about how your data is handled, contact our Grievance Officer:

10. Children

Ruchy is intended for users aged 18 and over. Under DPDP, processing a child's data requires verifiable parental consent; we do not knowingly collect data from children. If you believe a child has used the app, contact us and we will delete the data.

11. Security

We protect data in transit with HTTPS and restrict who can read your cloud data to your own account. No system is perfectly secure, but we design to keep your data private by default.

12. Changes

We may update this policy; we will change the effective date above and, for material changes, notify you in the app.