Privacy Policy
Last updated: August 24, 2026
Saffra ("the app", "we", "us") is an AI cooking companion built by HyperSage AI Labs LLC. This policy explains what data we collect, how we use it, and the choices you have. It's written in plain English — no dark patterns.
The short version
- We collect only what the app needs to work: your identity (via Sign in with Apple or Google), your cooking profile (equipment, allergies, preferences), your pantry, your conversation history with the chef, and recipes you import.
- We use this data solely to operate the app — personalize the chef, remember your pantry, adapt recipes for you. We do not sell it, we do not use it to train models, we do not share it with advertisers.
- Voice commands are transcribed by Apple's speech recognition service, which processes audio on Apple's servers.
- Your conversations with the chef do leave your device: each message, along with a summary of your profile and pantry, goes to our server and on to OpenAI to generate the reply. Two more things can leave to be read by an AI model — a photo of a shelf when you ask Saffra to identify what's on it, and the audio clip of any question you ask in Cooking Mode, which is re-transcribed by OpenAI's Whisper; those two are read, then discarded. All of it is detailed below.
- You can delete your account and all associated data at any time.
What we collect
Early-access waitlist (this website)
- Email address — only the email you type into the signup form on this site, plus a timestamp and the source label
saffra-website. We use it for one thing: to send you a single message when TestFlight opens. We never sell it, we never share it with advertisers, and we never send marketing email beyond the launch notification. You can ask for removal at any time by emailing support@hypersage.ai.
Account (in the app, post-launch)
- Apple or Google user ID (opaque identifier from Sign in with Apple or Sign in with Google) — to log you in.
- Email address — only if Apple or Google passes it to us, and only to contact you about your account. We never send marketing email.
Profile
- Kitchen equipment, dietary restrictions, allergies, likes, dislikes, skill level, cuisine preferences, household size, budget, time constraints, cooking style notes, preferred voice, unit system — collected during onboarding so the chef can tailor its suggestions. You can edit or clear any of these in Profile / Me.
Pantry
- Items you add manually, via barcode scan, via receipt scan, or by photographing a shelf — including names, quantities, expirations, brand, and allergens.
- Receipt and cookbook photos: OCR runs on your iPhone via Apple's Vision framework. The image never leaves your device. Only the extracted text is sent to us for parsing.
- Ingredient photos (fridge, counter, or shelf): this one is different. When you photograph a shelf so Saffra can identify what's on it, the image is uploaded to our server and passed to OpenAI's vision model, which returns a list of the foods it thinks it can see. We show you that list to confirm before anything is added to your pantry. We do not store the image — it is held in memory for the request, and neither we nor OpenAI use it to train models. Receipt and cookbook pages are not sent this way; only the shelf photo is.
Conversations
- Messages you send to the chef and the chef's replies, so the chef has memory across sessions. Older conversations are periodically summarized and the raw messages are deleted.
Recipes
- Recipes you import via URL or cookbook photo, and adapted versions created for you.
Community content (opt-in)
Community sharing is not available in the current version of Saffra, so none of the following is collected today. It describes what would be collected if community sharing becomes available and you opt in.
- Public handle & display name — only if you opt into the Community and pick a handle.
- Cook posts you explicitly share to the community, including the photo you uploaded, the caption you wrote, and which recipe the photo is for. Anyone using the app can see posts whose moderation state is
live; your private cook photos (the default) stay on your device and are never uploaded. - Likes, comments, follows, blocks, reports you create on community content.
- Moderation metadata — for every community post we keep a short record of our automated vision classifier's "food / not food" and "safe / unsafe" decisions, plus the removal reason if a post is taken down. This is used to enforce the rules, not to build a profile of you.
- Notifications — an in-app inbox of likes, comments, and follows you have received. Not sent to you via push in the current version.
Voice
- When you use voice mode, audio is transcribed by Apple's Speech framework. The app does not request on-device recognition, so Apple's server-backed service is what runs and the audio reaches Apple; it does not reach us.
- In Cooking Mode the recorded clip is also sent to our server and forwarded to OpenAI's Whisper for a second transcription. This is not a rare backstop: it runs for every spoken question, because Whisper reads question-length kitchen speech more accurately than Apple's transcript, and it also runs whenever Apple returns nothing or returns something the app cannot parse. A navigation command Apple recognizes cleanly (“next”, “back”) is not sent, and dictation in the chat composer is never sent. We do not retain the audio; it is processed and discarded.
- Text-to-speech uses OpenAI's text-to-speech. Audio is generated on our server and streamed to your device. Audio for publicly available curated recipes is cached (content-addressed) so we don't re-generate the same clip for every user.
Usage
- Per-user counters of chat messages, recipe adaptations, photo scans, voice characters, and Whisper seconds, used to enforce lifetime, monthly and daily limits and for aggregate cost monitoring. Not shared externally.
We do NOT collect
- Location, contacts, calendar, browsing history, financial data, health data outside your self-declared dietary/allergy profile.
- Any analytics that track you across apps or websites.
How we use it
- Operate the app — personalize recommendations, remember your pantry, stream chef responses.
- Safety — enforce rate limits and guard against abuse.
- Community safety — if community sharing becomes available: run an automated vision check ("is this food?" / "is this safe?") on every community photo before it's visible to others, and review user reports so we can remove rule-breaking content quickly.
- Product improvement — only via aggregate metrics (e.g., "how often does the chef call
lookup_recipe?"), never with identifiable data.
Third-party services
We share data with these service providers only to the extent needed to run the app:
- Apple — Sign in with Apple, and speech recognition: the audio you speak in voice mode is transcribed by Apple's Speech framework. The app does not request on-device recognition, so the service runs server-backed and the audio reaches Apple. It does not reach us.
- Google — Sign in with Google, only if you use it. Governed by Google's privacy policy.
- OpenAI — six paths. (1) Chef chat: your messages, along with a summary of your profile and pantry, are sent to OpenAI to generate and adapt the chef's replies. (2) Vision: when you photograph a shelf to add ingredients, that image is sent to OpenAI's vision model to identify the foods in it. (3) Whisper: the audio of every question you ask in Cooking Mode, re-transcribed for accuracy — see Voice above for exactly when a clip is sent. (4) Text-to-speech: text you want spoken aloud. (5) Search: your recipe searches and imported recipe text are converted to embeddings to power search over Saffra's own recipe catalog — there is no external web-search provider. (6) Community photo review: if community sharing becomes available and you share a cook photo to it, that photo would be sent to OpenAI's vision model for the "is this food / is this safe" check before it goes live. This path does not run today — community sharing is not available in the current version. Governed by OpenAI's privacy policy. Neither the shelf image nor the audio is retained by us, and none of your content is used to train models.
- USDA FoodData Central — ingredient names are sent to look up nutrition information. No personal data.
- Open Food Facts — barcode lookups send just the barcode number. No personal data.
- Google Firebase — for the early-access waitlist on this website only. Stores your email address until launch notification is sent.
- Fly.io, Cloudflare R2, Upstash Redis — hosting infrastructure.
None of these providers are authorized to use your data for their own purposes.
How long we keep it
- Account + profile + pantry — until you delete your account.
- Conversations — individual messages may be auto-summarized and deleted after ~20 turns; summaries persist until you delete the conversation.
- TTS audio cache — until you delete your account.
- Voice audio sent to Whisper — not stored; discarded after transcription.
- Ingredient/shelf photos — not stored; held only for the length of the request that identifies the foods in them, then discarded.
- Community posts, photos, comments, likes, follows, blocks, notifications (only if community sharing becomes available; none exist today) — until you delete them individually or delete your account. When you delete your account we hard-delete the photos from object storage and remove the associated rows. Reports you've filed are retained in an anonymized form so we can keep acting on repeat abuse.
- Waitlist email — until launch notification is sent or you ask for removal, whichever is sooner.
Your choices
- Edit or delete any profile field in Profile / Me.
- Delete a pantry item, recipe, or conversation any time.
- Sign out via Profile / Me.
- Delete your account → from Profile / Me, or by emailing support@hypersage.ai. In-app deletion runs the cascade immediately (photos, posts, comments, likes, follows, blocks, notifications); email requests are processed within 30 days.
- Block another community member, and report a post or comment, from their public profile or the post itself — available if community sharing becomes available. Every report is reviewed, and we always respond to abusive content within 24 hours.
- Turn off premium voice in Settings to use on-device iOS voices only — no text leaves your device to be spoken.
Kids
The app is not directed at children under 13. We don't knowingly collect data from children.
International transfers
Our servers are in the United States. If you're in another country, your data is transferred to the US for processing. We rely on standard contractual clauses where required.
Changes
If we update this policy, we'll note the new date above and flag material changes in-app.
Contact
- Email: support@hypersage.ai
- For early-access list questions: support@hypersage.ai