Homelore

Privacy Policy

Last updated: July 10, 2026

Effective date: [your date]

This Privacy Policy explains how [your entity], doing business as Homelore (“Homelore,” “we,” “us,” or “our”), collects, uses, discloses, and retains information when you use the Homelore website, application, recipe-card tools, and physical-product services (collectively, the “Service”). Homelore is operated from California, United States.

1. Information We Collect

1.1 Account and Profile Information

We may collect:

  • email address;
  • name;
  • authentication identifiers and account status;
  • basic profile information received through Google sign-in or another authentication provider; and
  • preferences and settings associated with your account.

We do not receive your Google or other third-party account password.

1.2 Recipe and Creative Content

We collect content you choose to submit, including:

  • recipe text you paste into the Service;
  • an optional source, story, attribution, or provenance note;
  • AI-generated recipe titles, ingredients, instructions, notes, and other structured content;
  • edits and corrections you make;
  • section names, category choices, and recipe organization;
  • engraving text, gift messages, and personalization instructions; and
  • generated PDFs, card layouts, print files, and shipment selections.

The source field is optional. Please do not include sensitive, confidential, or unnecessary personal information in recipe text or source notes.

If Homelore later introduces image upload or handwritten-recipe processing, we will update this Policy before or when that feature begins collecting images and will explain whether original images are stored, where they are sent, and when they may be deleted.

1.3 Purchase, Recipient, and Shipping Information

We may collect:

  • purchaser and recipient names;
  • billing contact information made available by our payment processor;
  • shipping address;
  • email address and, if provided or required for delivery, telephone number;
  • box material, engraving, card, divider, and other product selections;
  • order, shipment, delivery, refund, and support history; and
  • gift-recipient information, gift messages, or personalization supplied by a purchaser.

If you provide information about another person, such as a gift recipient, you are responsible for providing it lawfully and only as reasonably necessary for the order. We will use gift-recipient information only to fulfill, deliver, and support the order unless the recipient separately engages with the Service.

Payment-card information is collected directly by Stripe or another payment processor. Homelore does not receive or store complete card numbers, expiration dates, or security codes.

1.4 Communications

We collect information you provide when you contact us, including emails, support requests, photographs of product issues, survey responses, and records of our correspondence.

1.5 Information Collected Automatically

When you use the Service, we and our infrastructure providers may automatically collect:

  • IP address;
  • browser and device type;
  • operating system;
  • referring page and pages or features accessed;
  • dates, times, and approximate request location derived from IP address;
  • error, security, and server logs;
  • recipe-generation counts and other feature-usage records;
  • order and shipment submission events; and
  • authentication-cookie and session information.

We may generate or store a random browser or device token in local storage. It is used to enforce limited free use and, where applicable, connect recipes created before account registration to the account later created by that browser. It is not used by Homelore for behavioral advertising.

1.6 Information from Other Companies

We may receive information from:

  • Authentication providers, such as Google or Supabase, including email address, basic profile information, authentication status, and account identifiers;
  • Payment processors, such as Stripe, including payment confirmation, amount, currency, customer contact information, fraud signals, refund status, and transaction identifiers;
  • Box makers, printers, packers, and carriers, including production, shipment, tracking, delivery, damage, and return information; and
  • Security and infrastructure providers, including logs, alerts, and technical information used to operate and protect the Service.

2. How We Use Information

We use information to:

  • provide, maintain, and improve the Service;
  • authenticate users and manage accounts;
  • process recipe text with artificial intelligence;
  • generate, store, display, edit, and download recipe cards;
  • create production files and fulfill print orders;
  • process payments, refunds, replacements, and customer support;
  • communicate transactional information, such as sign-in links, order confirmations, production updates, shipment notices, and changes to the Service;
  • enforce free-use and account limits;
  • detect, prevent, and investigate fraud, abuse, security incidents, and violations of our Terms;
  • debug errors and understand basic Service performance and use;
  • comply with law, respond to legal process, and establish, exercise, or defend legal claims; and
  • carry out another purpose disclosed when you provide the information or with your consent.

We do not use your private recipe content for third-party advertising. We do not sell personal information, and we do not share personal information for cross-context behavioral advertising.

We do not use recipe text submitted through the Service to train our own general-purpose artificial-intelligence model. If that practice changes, we will update and provide any notice or choice required by law before the new practice begins.

3. How We Disclose Information

We disclose information only as reasonably necessary for the purposes described below.

3.1 Service Providers

We use providers that perform services on our behalf, which may include:

Provider or categoryInformation involvedPurpose
Supabase or other database / authentication providersAccount information, recipe content, preferences, usage records, technical dataAuthentication, database hosting, storage, and account management
OpenAI or another AI processorRecipe text and optional source information submitted for processing; generated outputRecipe extraction, organization, translation where requested, and formatting
Stripe or another payment processorPurchaser contact, payment information collected directly by the processor, order amount, transaction and fraud informationPayments, refunds, fraud prevention, and transaction records
Vercel and Railway or other hosting / rendering providersWeb request data, account or recipe data as technically necessary, card content, temporary files, PDFsHosting, application operation, and PDF or print-file generation
Resend or another communications providerEmail address, name, order status, and message contentAuthentication and transactional email
Card printers and print-fulfillment providersRecipient details, recipe-card files and content, card specifications, order identifiersPrinting, quality control, and shipment preparation
Box makers, engravers, and final packersRecipient details, shipping address, box selection, engraving details, order instructions, and recipe cards or card content as needed for final packagingProducing the box, engraving, assembling the order, and shipping it to the recipient
Shipping carriersName, delivery address, telephone number where required, package information, and order identifiersDelivery, tracking, address correction, and claims
Security, support, and professional advisersInformation reasonably necessary for the engagementSecurity, customer support, legal, accounting, insurance, and business operations

Service providers are contractually required to process information only for the purposes of providing services to us and as otherwise permitted by their contracts and applicable law.

3.2 Legal, Safety, and Rights Protection

We may disclose information when we reasonably believe doing so is necessary to:

  • comply with law, regulation, subpoena, court order, or lawful government request;
  • protect the rights, property, security, or safety of Homelore, users, service providers, or others;
  • investigate fraud, abuse, infringement, or violations of our Terms; or
  • establish, exercise, or defend legal claims.

3.3 Business Transfers

We may disclose or transfer information in connection with a proposed or completed merger, financing, acquisition, reorganization, bankruptcy, sale of assets, or transfer of all or part of the business. A recipient will be subject to this Policy or will provide notice of materially different privacy practices as required by law.

3.4 With Your Direction or Consent

We may disclose information when you direct us to do so, when necessary to fulfill a purpose you request, or with your consent.

3.5 Aggregated or De-Identified Information

We may use and disclose information that has been aggregated or de-identified so that it cannot reasonably be linked to you. We will not attempt to re-identify information that applicable law requires us to maintain as de-identified.

4. Artificial Intelligence Processing

When you ask Homelore to create or revise a recipe card, we send the recipe text you submit and minimal related information—such as an optional source name—to OpenAI’s API or another AI processor.

We do not intentionally include your account email, shipping address, payment information, or order history in the AI request. However, any personal information you place inside the recipe text or source field will be transmitted as part of that content.

As of the date of this Policy, OpenAI states that data submitted through its API is not used to train or improve its models by default unless the API customer opts in. OpenAI also states that API prompts and responses may be included in abuse-monitoring logs retained for a limited period, unless a different approved retention arrangement applies. Depending on the endpoint and configuration, OpenAI may also retain application state.

OpenAI’s practices may change. Current information is available in OpenAI’s API data-control and privacy materials.

5. Data Retention

We retain information for only as long as reasonably necessary for the purposes described in this Policy, including providing the Service, fulfilling orders, preventing abuse, complying with legal and accounting obligations, resolving disputes, and enforcing agreements.

Our intended retention practices are:

  • Account and recipe library: Retained while your account is active until you delete the recipe or request account deletion, subject to the exceptions below.
  • Original pasted recipe text: Retained with the associated recipe so you can review or regenerate the card, unless you delete the recipe or account.
  • Generated cards, PDFs, and production records: Retained while needed for your library, printing, customer support, reprints, and order records. Temporary rendering files are deleted after they are no longer needed for generation or fulfillment.
  • Anonymous free-use and abuse-prevention records: Raw IP addresses will not be retained in Homelore’s application database longer than operationally necessary. Pseudonymous IP-derived identifiers and browser/device tokens may be retained for up to 12 months to enforce limits and prevent abuse, and may be deleted earlier when no longer needed or after account linkage.
  • Order, payment, shipping, refund, and tax records: Retained for the periods reasonably necessary to fulfill orders and meet legal, tax, accounting, warranty, fraud-prevention, and dispute-resolution requirements. Tax and financial transaction records are generally retained for at least seven (7) years following the transaction to meet applicable tax and accounting obligations.
  • Support communications: Retained while reasonably necessary to resolve the request and maintain appropriate business records.
  • Security and server logs: Retained according to operational need and the schedules of our infrastructure providers.
  • Backups: Deleted or overwritten on rolling schedules. Information removed from active systems may remain in backups for a limited period until those backups expire, unless longer retention is legally required.

We may retain limited information after deletion when necessary to complete an active order, provide a replacement, comply with law, prevent fraud or abuse, resolve disputes, enforce agreements, or protect legal rights. We may also retain aggregated or de-identified information indefinitely.

6. Security

We use commercially reasonable administrative, technical, and organizational measures designed to protect information, which may include:

  • encrypted connections using HTTPS/TLS;
  • authentication and access controls;
  • restricted database permissions;
  • separation of client-side and server-side secrets;
  • service-to-service authentication;
  • logging and security monitoring; and
  • vendor-management and deletion procedures appropriate to the Service.

No transmission or storage system is completely secure. We cannot guarantee absolute security.

You are responsible for protecting access to your email account and devices because Homelore may use email-based magic links for authentication.

If a breach of the security of the system compromises personal information, we will notify affected individuals and, where applicable, regulators in accordance with California Civil Code §§ 1798.29 and 1798.82 and other applicable law. Notification will be made in the most expedient time possible and without unreasonable delay, consistent with the legitimate needs of law enforcement and any measures necessary to determine the scope of the incident and restore the integrity of the system.

7. Your Choices and Requests

7.1 Access and Portability

You can access recipe content through your account and may download card PDFs where that feature is available. You may request a copy of personal information we maintain about you by contacting [your email].

7.2 Correction

You can edit much of your recipe and profile information through the Service. You may ask us to correct inaccurate personal information that you cannot edit directly.

7.3 Deletion

You may delete individual recipes through available account controls or request deletion of your account by contacting [your email].

After verifying the request, we will delete or de-identify covered information from active systems within a reasonable period, generally within 45 days (which may be extended by an additional 45 days where reasonably necessary, with notice to you), except where retention is reasonably necessary for an active or completed order, legal compliance, fraud prevention, security, disputes, backups, or another lawful purpose.

Deleting an account cannot recall or “unprint” physical products already produced or delivered. If an active paid order is associated with the account, we may retain and use information needed to fulfill, support, cancel, or refund that order.

7.4 Email Choices

Transactional messages, such as authentication, order, production, and shipment communications, are necessary to provide the Service.

Homelore does not currently send marketing email. If we introduce marketing email, we will provide an unsubscribe mechanism and update this Policy as appropriate.

7.5 Browser and Local-Storage Controls

You can configure your browser to block or delete cookies and local storage. Doing so may prevent authentication, recipe recovery, free-use tracking, or other Service features from functioning properly.

8. California Privacy Information

8.1 Voluntary Privacy Choices and CCPA Applicability

Homelore voluntarily provides the access, correction, deletion, and portability choices described above to its users.

The California Consumer Privacy Act, as amended (“CCPA”), applies only to businesses meeting statutory thresholds and other requirements. If and when the CCPA applies to Homelore, California residents may exercise all rights provided by that law, including the rights to know, delete, correct, opt out of sale or sharing, limit certain uses of sensitive personal information where applicable, and receive nondiscriminatory treatment.

To submit a privacy request, contact [your email]. We may need to verify your identity. Where applicable, an authorized agent may submit a request on your behalf, subject to legally permitted verification.

Where the CCPA applies, we will acknowledge receipt of a verifiable consumer request within ten (10) business days and respond within forty-five (45) calendar days, which may be extended by an additional forty-five (45) days where reasonably necessary, with notice to you. You may make a verifiable request twice within a twelve-month period free of charge.

8.2 Categories of Personal Information

Depending on how you use the Service, we may collect and disclose for business purposes the following categories of personal information:

  • Identifiers: name, email address, postal address, IP address, account identifiers, device token, and order identifiers;
  • Customer-record and commercial information: product selections, purchases, payments, refunds, shipment history, and customer-service records;
  • Internet or electronic-network activity: browser, device, pages or features used, logs, and interactions with the Service;
  • Geolocation information: approximate location inferred from IP address and delivery location provided for shipping;
  • User-provided content: recipe text, optional source information, notes, personalization, gift messages, and communications;
  • Inferences: limited inferences necessary for fraud prevention, account security, or understanding Service use; and
  • Sensitive personal information, in limited circumstances: account login credentials managed by authentication providers and payment information managed by payment processors. Homelore does not use sensitive personal information to infer characteristics about users.

We collect these categories from you, your browser or device, authentication and payment providers, fulfillment and shipping partners, and other service providers. We use and disclose them for the purposes described in Sections 2 and 3.

8.2.1 Right to Limit Use of Sensitive Personal Information

Homelore uses sensitive personal information only for purposes that are exempt from the right to limit under the CCPA, such as authenticating users, processing payments, providing the Service you request, preventing fraud, and ensuring security. We do not use or disclose sensitive personal information to infer characteristics about you or for any purpose that would trigger the right to limit. For this reason, we do not currently provide a separate “Limit the Use of My Sensitive Personal Information” mechanism. If our practices change, we will update this Policy and provide the required choice before beginning the new practice.

8.3 No Sale or Sharing for Targeted Advertising

Homelore does not sell personal information and does not share personal information for cross-context behavioral advertising.

Because we do not engage in those practices, we do not currently provide a “Do Not Sell or Share My Personal Information” link. If our practices change, we will update this Policy and implement legally required choices before beginning the new practice.

8.4 Do Not Track and Global Privacy Control

Homelore does not currently track users over time across unaffiliated websites for targeted advertising and does not permit advertising networks to collect information through the Service for that purpose.

Because we do not sell or share personal information for cross-context behavioral advertising, browser “Do Not Track” and Global Privacy Control signals do not change our current practices. If we later engage in a practice for which applicable law requires us to honor such a signal, we will do so.

8.5 California “Shine the Light”

California residents may request information about certain disclosures of personal information to third parties for those third parties’ own direct-marketing purposes. Homelore does not currently make such disclosures.

8.6 Notice at Collection

At or before the point at which we collect personal information, we provide notice of the categories of personal information we collect, the purposes for which we use it, whether it is sold or shared (it is not), and the applicable retention periods or criteria. This Policy, together with any notice presented at the point of collection (for example, at account sign-up or checkout), serves as our Notice at Collection. The categories and purposes are described in Sections 1, 2, and 8.2, and our retention practices are described in Section 5.

9. Cookies and Local Storage

Homelore currently uses only storage and similar technologies reasonably necessary to operate the Service, such as:

  • Authentication cookies or tokens: Maintain your sign-in session and account security.
  • Local-storage device token: Enforces limited free use and may connect pre-account recipes to a later-created account.
  • Checkout and security technologies: Support payments, fraud detection, and essential transaction functions.

We do not currently use advertising cookies, third-party retargeting pixels, or cross-site behavioral-advertising trackers.

If we add analytics or advertising technologies, we will update this Policy and provide any notice or choice required by law.

10. Children’s Privacy

The Service is not directed to children under 18, and children under 18 may not create an account or purchase products.

We do not knowingly collect personal information from children under 13, consistent with the Children’s Online Privacy Protection Act (COPPA). Because the Service is not directed to and may not be used by anyone under 18, we also do not knowingly collect personal information from children under 18. If we learn that we have collected personal information from a child under 18 without appropriate authorization, we will delete it as required by law. If you believe a child has provided personal information, contact [your email] so we can investigate and delete it where required.

California residents under 18 who are registered users may request removal of content they have publicly posted through the Service by contacting [your email], consistent with California Business and Professions Code 22581; removal may not be complete or comprehensive where the law provides exceptions.

11. International Users

The Service is operated from the United States. If you use it from another country, information may be transferred to and processed in the United States and other countries where our service providers operate.

This Policy is not intended to serve as a comprehensive privacy notice under European Union, United Kingdom, Canadian, Australian, or other non-U.S. laws. If Homelore expands to additional jurisdictions, we will update this Policy to address applicable local requirements.

12. Third-Party Websites

The Service or transactional messages may link to third-party websites. Their privacy practices are governed by their own policies, not this Policy. Homelore is not responsible for the independent privacy or security practices of third parties.

13. Changes to This Policy

We may update this Policy from time to time. We will post the updated version, revise the “Last updated” date, and describe the process by which material changes will be communicated.

For material changes, we will provide reasonable additional notice before the change takes effect, such as an email or in-Service notice, where required or appropriate. We will not use previously collected personal information for a materially different purpose without any notice or consent required by law.

14. Contact Us

Questions, requests, or complaints about privacy may be sent to:

[your entity]

Doing business as Homelore

[your address]

Privacy email: [your email]

Support email: [your email]