Privacy information
Privacy
Optional community · Beta
The community is optional. Reading and downloading published recipes does not require an account. Submitting and rating recipes requires a community profile. Signing in, signing out or deleting the account does not change local baking data, in-app purchases or AI credits.
We process your email address or Apple provider identifier, chosen public display name, acceptance of the rules and revocable sessions to provide your community account. Email and Apple names do not automatically become public. Only approved recipe versions, an explicitly selected cover image and the author’s display name are public. Ratings are linked to an account but displayed only as totals. Reports and blocks support moderation and safety.
Community data is processed in a separate Cloudflare D1 database and private R2 file store; Vercel hosts the website and API gateway. Cloudflare Email Service delivers requested login emails, and Apple handles Sign in with Apple. Private notes, baking logs, AI prompts, galleries and step media are not automatically published. Uploaded cover images are re-encoded and metadata is removed.
Login codes expire after ten minutes, work once and are stored only as hashes by Crusted. Sessions last 30 days and renew with use, using essential HttpOnly browser cookies or the native Keychain. A single-use embedded-browser handoff lasts one minute. IP and email rate-limit keys are short-lived keyed hashes. Session records do not store IP addresses or device identifiers. Community pages and actions are not connected to voluntary usage analytics.
Profiles, publications and related files are retained until deletion. Pending versions are visible only to the author and moderation. Account deletion revokes sessions and hides publications immediately. A retryable background process deletes account data, ratings and files and revokes Apple access. Service failures delay cleanup but do not make hidden content public. Other users’ downloaded local copies cannot be recalled. Technical moderation records are kept for at most 30 days. Providers’ documented retention policies apply to their delivery and security records.
Processing supports the community service you request (Article 6(1)(b) GDPR); security, abuse prevention and moderation serve legitimate interests (Article 6(1)(f) GDPR). You may withdraw publications, remove ratings, block authors and delete your community account in the app or website. This does not cancel an Apple subscription.
Summary
Crusted stores recipes, projects, baking history, images, and personal statistics locally on your device by default. External services process data only where required for features you use, particularly Live Activity phase changes, Pro AI, website import, in-app purchases, support, and—after your consent—optional usage analytics.
Crusted does not use your data for personalized advertising and does not track you across apps or websites.
Controller
Justin Voitel
Zanderstraße 24, 12621 Berlin, Germany
Email: support@crusted.app
Website: crusted.app
Data involved
- local recipe data, ingredients, steps, notes, images, baking projects, timer status, bake logs, and personal statistics
- when using Pro AI: your input, recipe and baking data required for the request, AI settings, and the generated response
- for website imports: the URL you provide and relevant recipe content extracted from it
- random installation and purchase identifiers as well as Apple product, transaction, subscription, entitlement, and credit information
- for an active bake-program Live Activity: a random ActivityKit identifier and push token, phase titles and times, temperature, steam status, and the minimal display state; recipe instructions and notes are not transmitted
- after consent: aggregated usage counters; also technical status, duration, token, credit, and error data from server requests
- when using the website: page path, referrer, browser and device class, and an approximate region derived from network data
- optional support details such as name, email address, subject, message, device model, operating system, and app version
Purposes of processing
Processing is used to provide app features, support, website recipes, analyze issues, and improve Crusted.
- Providing recipe management, bake mode, history, and bake logs
- Updating the phase title, temperature, and phase counter of an active Live Activity while the app is suspended
- Creating, optimizing, and coaching recipes through Pro AI and importing recipe websites
- Processing and restoring Pro purchases, subscriptions, and AI credits, including fraud and duplicate-charge protection
- Providing support, website recipes, and embedded web views
- Processing support requests
- Security, abuse prevention, issue analysis, stability, and product improvement
Optional anonymous usage analytics
After your explicit consent, Crusted transmits only daily aggregated counters. These include app opens, recipe additions by origin, started and completed bake runs, accompanied project time, broad recipe categories, and the estimated number of baked loaves.
Recipe names, ingredients, steps, images, notes, ratings, prompts, recipe or project IDs, and persistent user or device identifiers are not transmitted. You can withdraw consent in Settings at any time for future collection. Pending counters are then deleted.
Pro AI and website import
When you actively start a Pro AI feature, Crusted sends your input and the recipe or baking data required for the task to the Crusted AI Worker on Cloudflare and then through the API to OpenAI. This applies to recipe generation, recipe optimization, the bake coach, and website import. The data is used solely to process your specific request, deliver the result, and technically safeguard credit usage.
For website import, the Crusted AI Worker additionally processes the URL you provide. Known marketing and tracking parameters and URL fragments are removed before fetching the page. Neither the URL, domain, nor source identifier is sent to OpenAI; only structured data reduced to necessary recipe fields or limited, cleaned visible page text is submitted. URLs, images, author, and publisher details are specifically removed from structured data. The source URL is then attached to the recipe draft locally in the app only.
To recover a successful response lost because of a connection failure, the Crusted AI Worker may cache the result until the app acknowledges receipt, for no more than 15 minutes and only up to 96 KB. This wallet-bound cache contains no source URL, domain, page title, or other source attribution. A content-free marker may then remain for up to 24 hours to prevent duplicate computation and charging.
OpenAI requests are sent with persistent response storage disabled. OpenAI does not use content submitted through its API to train its models by default. Depending on the data controls available for the Crusted API project, OpenAI may still retain content and technical metadata for security and abuse prevention for up to 30 days. No Pro AI processing starts without your active request.
Live Activities and APNs
When a bake program starts, Crusted requests a random ActivityKit push token from Apple. The app sends this token, the phase boundaries, and the minimal display state to the Crusted Worker on Cloudflare. Recipe instructions and notes are removed before transmission.
Cloudflare temporarily holds the schedule and, at a phase boundary, sends the new title, temperature, steam status, and phase counter through Apple Push Notification service (APNs) to that specific Live Activity. Countdown and continuous progress remain local iOS displays. The schedule is deleted when the activity stops, after the final successful phase change, or when a push token becomes invalid. Operational logs contain only delivery status, retry count, and phase index, never push tokens, recipe names, phase titles, or notes.
Purchases, entitlements, and AI wallet
In-app purchases are processed by Apple. Crusted does not receive payment details such as card or bank information. To verify and restore Pro and Pro AI access and manage AI credits, Crusted processes product identifiers, Apple transaction and original transaction identifiers, subscription status, and expiration dates.
The app also uses a randomly generated App Account identifier stored in the Keychain and a random installation identifier. They are used only to associate purchases and AI wallets, account for credits, recover lost responses, and protect against fraud, duplicate charges, and abuse. They are not advertising identifiers; Crusted does not create a user account from them or use them for tracking.
Website and Vercel Web Analytics
The Crusted website and certain support and recipe pages opened inside the app are hosted by Vercel and use Vercel Web Analytics. This may process the time, page path, referrer, filtered URL parameters, browser, operating system, device class, and an approximate region such as country, region, or city derived from the network connection.
Vercel Web Analytics does not use advertising cookies for this purpose. A visitor hash derived from the request is reset within 24 hours and is used only for aggregated audience measurement. Crusted does not use this data for personalized advertising or tracking across apps or third-party websites.
Legal bases
- Art. 6(1)(b) GDPR for functions required to provide the app or fulfill contractual services.
- Art. 6(1)(f) GDPR for legitimate interests in security, stability, abuse prevention, and product improvement.
- Art. 6(1)(a) GDPR for optional anonymous usage analytics and other consent-based features.
Recipients and service providers
Data is only shared to the extent necessary for the respective functions.
- Apple for App Store, in-app purchases, ActivityKit, and delivery of targeted Live Activity updates through APNs. Website and support services are only used when you actively open or submit them.
- Notion for support tickets when you use the website support form.
- Cloudflare for operating AI, Live Activity, and analytics workers, short-term recovery of AI responses, temporary scheduling of bake-program phase changes, managing entitlements and credits, and storing aggregated daily counters in D1. Cloudflare technically processes network data such as IP addresses for delivery, security, rate limiting, and abuse prevention; Crusted does not store the IP address as part of its aggregated app analytics database.
- OpenAI as the provider of the AI models used by Pro AI. Only the content and technical metadata required for the task you actively start are submitted through the API.
- Vercel for hosting, delivery, and aggregated audience analytics for the website and Crusted web pages loaded in the app.
- Apple handles payment processing for in-app purchases; payment data itself is not processed directly by Crusted.
Retention period
- Local recipe, image, project, timer, statistics, and history data remains on your device until you delete it or remove the app.
- Temporary Live Activity schedules are deleted when the activity stops, after the final successful phase change, when a push token becomes invalid, or no later than the end of the permitted time window.
- Successful AI responses are cached by the Crusted AI Worker for no more than 15 minutes or until receipt is acknowledged; for website imports, this cache contains no source attribution. A content-free idempotency marker then remains for no more than 24 hours.
- OpenAI receives requests with persistent response storage disabled, but depending on enabled data controls may generally retain API content and related security logs for abuse prevention for up to 30 days unless a longer legal obligation applies.
- Purchase, entitlement, and credit data is kept as long as necessary to provide and restore the purchased service, prevent abuse, account for usage, and meet legal record-keeping duties.
- Support requests are kept as long as necessary for processing and documentation.
- Structured AI and worker metrics may include task type, model, status, duration, token and credit usage, and technical errors, but not the prompt or generated result. They are retained only as long as needed for operations, accounting, stability, and abuse prevention.
- Aggregated analytics counters are stored without a user reference. Random batch IDs used to prevent duplicate uploads are removed after 15 days.
- Vercel's documented retention and aggregation periods apply to website analytics.
Transfers to third countries
If service providers process data outside the European Union or EEA, this is done only on the basis of appropriate safeguards under the GDPR, such as standard contractual clauses or an adequacy decision.
Your rights
- Access to your processed personal data
- Correction of inaccurate or incomplete data
- Deletion where legal requirements are met
- Restriction of processing
- Data portability
- Objection to processing based on legitimate interests
- Withdrawal of consent with effect for the future
- Complaint to a competent data protection authority
Contact and privacy requests
For privacy questions, access requests, or other concerns, contact support@crusted.app.
Last updated
August 13, 2026