Privacy Policy
Last updated 14 September 2026
This policy explains what personal data Guston collects, why we collect it, who we share it with, and the rights you have over it. It covers the Guston apps for iOS and Android, guston.app and creator.guston.app.
1. Who is responsible
The controller of your personal data is Nikita Belopotapov. For anything in this policy, including requests about your data, write to welcome@guston-app.com.
2. What we collect
Account
You sign in with Apple or Google. From that sign-in we receive an account identifier, your email address and, if you allow it, your name and profile picture. If you use Sign in with Apple and choose to hide your email, we only ever see Apple’s relay address. We never receive your Apple or Google password.
Your profile and preferences
Your username, avatar and bio, the cooking preferences, diets and allergens you select during onboarding or in Settings, notification preferences, your app language and the country we derive from your device settings, and small interface state such as which tips you have already seen.
Allergen and diet selections say something about your health or beliefs. We store them only to filter and label recipes for you, we never use them for advertising, and you can clear them in Settings at any time.
What you create
Recipes, collections, shopping lists, photos you upload, and the recipes you save from other users. For imported recipes we also store the link to the original post, the platform it came from, and the author’s handle or name.
How you use the app
Which recipes you open, what you import and when, your position in usage quotas, saves and follows, referral and invite events, and reports or blocks you submit. We use this to make the app work — the feed, your history, limits, abuse handling — and to understand which features are worth keeping.
Device and diagnostics
A push notification token with the device platform, app version and language, so notifications can reach the right device. Crash reports and analytics events collected through Google Firebase (Crashlytics and Google Analytics for Firebase), which include a device identifier generated by Firebase, device model, operating-system version and app version. On iOS we also read Apple’s Search Ads attribution token once after install, which tells us which ad campaign an install came from. We do not use the advertising identifier (IDFA), we do not ask for tracking permission, and we do not track you across other apps or websites.
Feedback you send
Your message, the email address you give us, and — only if you tick the box — diagnostic details such as app version, device model and the most recent error code.
Voice
If you dictate a recipe or use voice control while cooking, speech is turned into text by your device’s own speech recognition. Where your device and language support on-device recognition, the audio never leaves your phone. Where they do not, the operating system streams the audio to Apple’s or Google’s speech service under their own privacy terms. Either way, Guston receives the resulting text, never the audio, and we do not store recordings.
Website
On guston.app we use Vercel Analytics and Speed Insights, which measure page views and loading performance without cookies and without building a profile of you. We set no advertising or tracking cookies. On creator.guston.app, signing in sets a session cookie that keeps you signed in; it is limited to that subdomain, which is why the main site works fully signed-out.
For a published creator page we keep daily counters — page views, recipe views, clicks on the page’s links — so the creator can see how their page performs. These are counts only: no IP addresses, no identifiers, nothing that ties a view to a person.
3. Why we use it, and on what legal basis
- To provide the Service — your account, your recipes, imports, translations, notifications you asked for, the creator claim and creator pages. Legal basis: performance of our contract with you.
- To keep it working and safe — quotas, abuse and fraud prevention, crash and error diagnostics, security. Legal basis: our legitimate interest in a working, non-abused service.
- To understand and improve the product — aggregate usage analytics and install attribution. Legal basis: our legitimate interest in developing the Service; where your local law requires consent for analytics, we ask for it.
- To communicate with you — answering feedback, service notices, and messages about features you asked to hear about, such as the Creator Pro wait-list. Legal basis: our contract with you and your consent.
- To comply with the law — for example, responding to valid legal requests. Legal basis: legal obligation.
We do not sell personal data, and we do not use it for advertising profiles.
4. Who we share it with
We use a small number of providers to run Guston. They process data on our instructions, under contract:
- Supabase — our database, file storage, authentication and server functions. Your account and content are stored in the European Union (Frankfurt).
- Vercel — hosting for the website, served from the EU.
- Anthropic — the AI models that read a post and produce a structured recipe, and that translate recipes. The post content and recipe text are sent for processing; the provider does not use them to train models.
- Apify — retrieval of the public posts you ask us to import.
- Google — Sign in with Google, Firebase Analytics and Crashlytics, and Firebase Cloud Messaging for Android notifications.
- Apple — Sign in with Apple, push notifications, and Search Ads attribution.
- Stripe — the Creator Pro wait-list. If you save a card, Stripe holds the card details; we receive only a customer reference and the fact that a card was saved. No card data ever reaches our systems.
- Resend — delivery of the emails our systems send, such as forwarding your feedback to us.
We may also disclose data where the law requires it, to protect rights and safety, or as part of a transfer of the Service to a company that takes it over — in which case this policy continues to apply until we publish a replacement.
What is public
Some data is public by design: recipes and collections you mark public, your public profile, and a claimed creator page. These are served on the web and can be indexed by search engines and cached by them. Private recipes, your shopping list, your preferences and your email address are not public.
International transfers
Anthropic, Apify, Google, Apple, Stripe and Resend may process data outside the European Economic Area, including in the United States. Those transfers rely on the European Commission’s Standard Contractual Clauses or an adequacy decision such as the EU–US Data Privacy Framework.
5. How long we keep it
- Account and content — until you delete your account, or until you delete the content.
- Analytics — Google Analytics event data is retained for two months; aggregate reports derived from it may be kept longer.
- Operational logs — import, error and quota records are kept while they are useful for running and debugging the Service, and are deleted or anonymised afterwards.
- Backups — deleted data can persist in encrypted backups for a short period before those backups roll over.
When you delete your account (Settings → Delete account) we delete your account record, your profile and the recipes you created that nobody else has saved. Recipes other users have saved to their kitchen remain in the Service with your identifier removed, because we cannot take content out of other people’s collections. If you claimed a creator page, media we already copied to our storage under the Terms may stay on recipes that other users saved. Deletion is immediate and cannot be undone.
6. Your rights
If you are in the European Economic Area or the United Kingdom, you have the right to access your data, to correct it, to have it deleted, to restrict or object to how we use it, to receive a copy in a portable format, and to withdraw consent where we rely on it — withdrawing consent does not affect what we did before. People outside the EEA have similar rights under their own law, and we apply this policy to everyone.
Most of it you can do yourself: edit your profile and preferences in Settings, delete individual recipes, turn notifications off, and delete your account. For anything else, write to welcome@guston-app.com and we will answer within one month.
You also have the right to complain to your data-protection supervisory authority. We would rather you told us first, so we can fix it.
7. Children
Guston is not directed at children under 13, and we do not knowingly collect their data. If you believe a child has given us personal data, write to us and we will delete it.
8. Security
Data is encrypted in transit, access to production systems is limited to the people who operate the Service, and content is protected by row-level rules in the database so one account cannot read another’s private data. No service can promise perfect security; if a breach affects your data and the law requires it, we will tell you.
9. Changes
When this policy changes we update the date at the top of the page, and we tell you in the app or by email if the change is material.
10. Contact
Nikita Belopotapov — welcome@guston-app.com.