I'm Ben Slater, the developer behind KitchenFox. KitchenFox is a one-person project operated by Slater Tech Ltd in the United Kingdom. This page explains, in plain English, what personal data the app collects, why, how it's stored, and what you can do about it.
If anything here is unclear or you'd like to exercise any of your rights, email support@kitchenfox.co.uk and I'll respond personally.
1. Who is the data controller?
The data controller for the personal data described below is:
- Slater Tech Ltd (trading as KitchenFox)
- Company number 17187576, registered in England and Wales
- Registered office: 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom
- Contact: support@kitchenfox.co.uk
KitchenFox is operated from the United Kingdom by Slater Tech Ltd, but the service is available to people in most countries. Wherever you use it, KitchenFox aims to handle your personal data to the standard set by the UK GDPR and — for users in the European Economic Area (EEA) — the EU GDPR. Where your local data-protection law gives you stronger rights, those rights still apply.
2. What data does KitchenFox collect?
Account information
- Your email address, used to sign in and to send essential account emails.
- A display name if you choose to set one.
- A securely hashed password (the plain password is never stored).
Content you create
- Recipes you save, including ingredients, steps, photos and tags.
- Planner entries: which recipes you've scheduled, when, and for how many people.
- Shopping lists you generate.
- Settings such as your preferred supermarket and household size.
Billing information
KitchenFox uses Stripe as its merchant of
record for paid subscriptions, through Stripe's "Onelink" service.
When you pay, your purchase is "Sold through Onelink" and your card or bank
statement shows a descriptor such as Onelink.com* KitchenFox
(or similar). Stripe — not KitchenFox — is the seller of record for the
payment and the party that handles your card details, billing, tax and
fraud checks.
- Stripe collects and processes your payment details directly. KitchenFox never sees or stores your full card number.
- KitchenFox stores only a customer reference, your subscription status, and the last four digits of the card on file so you can recognise it.
- For payment, billing and tax data, Stripe acts as an independent data controller under its own privacy policy, not simply as KitchenFox's processor. Stripe is responsible for calculating, collecting and remitting any sales tax, VAT or GST due on your subscription.
Waitlist data (closed beta)
KitchenFox is currently in a closed beta. If you try to sign up while sign-ups are restricted, we offer you the option to join a waitlist. If you give explicit consent, we store:
- Your email address (so we can contact you).
- The name you entered on the sign-up form, if any.
- The date you joined.
This data is processed on the lawful basis of consent (UK GDPR Article 6(1)(a)) and is used only to send you a single email when public sign-ups open. After that one notification, the record is kept for up to 30 days and then deleted. You can withdraw consent and have your entry removed at any time by replying to the confirmation email or contacting support@kitchenfox.co.uk.
Technical data
- Anonymous usage analytics via Vercel Analytics. This includes page views and approximate country, but no cookies and no personally identifying information.
- Error reports via Sentry when something goes wrong in the app, so I can fix it. These include the error message, a stack trace, and your user ID so I can match the error to your account if you ask for help.
- Standard server logs (IP address, user agent, request path), kept for up to 30 days for security and debugging.
3. Why does KitchenFox use this data?
- To run the service: save your recipes, show your planner, generate shopping lists, and keep you signed in.
- To handle billing: manage your subscription and send receipts.
- To improve and debug: diagnose errors and understand which features are used.
- To contact you when needed: account-related emails such as password resets, security alerts, and important changes to the service.
The legal bases under UK GDPR are: contract (to deliver the service you've signed up for), legitimate interests (security, fraud prevention, product improvement) and consent where it applies (such as the closed-beta waitlist, and any future optional marketing emails).
4. AI-powered recipe import
When you import a recipe from a URL, photo or pasted text, KitchenFox sends the relevant content to a third-party AI provider to extract the structured recipe. KitchenFox currently uses both Anthropic and OpenAI for this, and routes each request automatically to whichever model is most suitable for the type of input (a URL, an image, or pasted text). Both providers process this data on KitchenFox's behalf under a data processing agreement, and inputs are not used to train any provider's models. Imported content is stored against your account and treated like the rest of your recipe data.
5. Sub-processors
KitchenFox uses these sub-processors to deliver the service. Each is bound by a data processing agreement.
- Vercel Inc. — application hosting and analytics.
- Neon Inc. — managed Postgres database hosting in EU regions.
- Stripe — payments and subscription billing. Stripe acts as merchant of record (through its Onelink service) and as an independent controller for payment, billing and tax data, rather than purely as a sub-processor — see "Billing information" above.
- Anthropic, PBC — AI recipe extraction (one of two providers used; requests are routed automatically).
- OpenAI Ireland Limited — AI recipe extraction (one of two providers used; requests are routed automatically).
- Sentry (Functional Software, Inc.) — error reporting.
- Resend Inc. — transactional email delivery.
Some of these processors are based outside the UK and the EEA. Where personal data is transferred internationally, it is protected by an appropriate safeguard — such as the UK International Data Transfer Agreement, the EU Standard Contractual Clauses, or an adequacy decision.
6. How long is data kept?
- Active accounts: for as long as your account is open.
- Deleted accounts: personal data is fully deleted within 30 days of you deleting your account, except where retention is required by law (for example, financial records that Slater Tech Ltd must keep for 6 years under UK tax law). Payment and tax records for your purchases are held by Stripe, as merchant of record, under its own retention rules.
- Server logs: up to 30 days.
- Error reports: up to 90 days.
7. Your rights
Under the UK GDPR — and, for users in the EEA, the EU GDPR — you have the right to:
- Access the personal data KitchenFox holds about you.
- Have inaccurate data corrected.
- Have your data deleted (you can also do this from in-app settings).
- Restrict or object to processing.
- Receive your data in a portable format.
- Withdraw consent where processing is based on consent.
To exercise any of these, email support@kitchenfox.co.uk. If you're in the UK and you're not happy with how I've handled your request, you can complain to the Information Commissioner's Office at ico.org.uk. If you're in the EEA, you can complain to your local data-protection authority. Residents of some other regions (for example California) have similar rights under their own laws, and the same contact address applies.
8. Cookies
KitchenFox uses a small number of cookies that are strictly necessary to keep you signed in and to remember basic preferences (such as theme). It does not use advertising or cross-site tracking cookies.
9. Children
KitchenFox is not intended for use by children under 16 (or the minimum age for online consent in your country, if that is higher). If you believe a child has signed up, please contact me and I'll delete the account.
10. Changes to this policy
If this policy changes in a meaningful way, I'll email registered users before the change takes effect. Smaller clarifications will be reflected in the "last updated" date at the top of the page.