Gather Privacy Policy
Effective: 13 September 2026. Publisher and data controller: Rik Breukers. Privacy contact: twistmodzzz@gmail.com. This policy covers Gather for iPhone and Android and its browser preview.
Gather lets you keep recipes and groceries locally, share them with one household partner, add your own recipe photos or find optional online photos and open selected products in the Albert Heijn (AH) app. AH use is optional; the rest of Gather works without it.
Why data is used
Account, membership and shared recipe/list data are processed to provide the account and household service you request (GDPR Article 6(1)(b)). An email address and sign-in credentials are needed for account features; you can still use local recipes and lists without them. Photo-search queries rely on your optional consent (Article 6(1)(a)); disabling search stops future searches, while saved image-display requests are explained below.
Support correspondence and necessary technical security data are processed for the legitimate interests of answering requests, maintaining the service and preventing abuse (Article 6(1)(f)). Data needed to fulfil applicable legal duties, including privacy-rights requests, is processed under Article 6(1)(c). Information is not used for advertising or sold.
If you choose the AH feature, product searches, saved product choices and outgoing handoffs are processed to provide that requested function (Article 6(1)(b)). Searches and handoffs require your explicit action, as described below.
Local use and a shared household
You can use recipes and grocery lists without an account. Original recipes and selected personal photo copies, ingredients, quantities, cooking instructions, selected meals, manually added groceries, remembered product names, favorite products with their saved amounts and units, and checkmarks stay in that installation’s local storage. The browser preview keeps its local copy in that browser.
Creating a household copies your local recipes and list into a separate shared space. Joining an existing household opens its shared data. Neither action overwrites your original local recipe collection. Up to two verified members have equal rights to view, edit and remove shared recipes and list entries.
Shared data includes recipes and ingredients, people and quantities, cooking instructions, selected personal photo copies, saved online photo URLs and attribution, selected meals, manually added groceries and their amounts/units, remembered product names, favorite products with their saved amounts and units, grocery checkmarks and the default number of people. Household names, member user IDs and invitation records support membership. Revision numbers, shopping-context generations and mutation receipts prevent lost updates and duplicate changes; receipts contain a mutation ID, a fingerprint and a timestamp, not a separate recipe history.
Shared records are stored using Google Cloud Firestore in the EU multi-region eur3. Data sent to Firebase uses encrypted connections. Language and photo-search permission remain personal and are not shared between members.
Accounts and Firebase
Google Firebase Authentication handles your email address, password sign-in, verification and password resets. It assigns an account user ID. Gather does not store passwords in its recipe database. On phones, Firebase session information is saved in secure device storage; the browser uses its own local authentication storage. Signing out removes the active sign-in session.
Firebase receives technical connection information, including IP addresses and user-agent information, for service operation and abuse prevention. Firebase Authentication processes sign-in data in the United States. Firestore uses the selected EU region; Hosting and other operational processing use global infrastructure. See Firebase privacy and security and its data-processing terms.
An invitation code gives its holder the opportunity to join your household with a verified account while a place remains available. Codes expire after 23 hours and can be used once. Share them only with your intended household member. Gather does not access your contacts or send invitation SMS messages.
Offline data and deletion
Accounts remain until deleted. Shared content remains while the household exists, unless its members remove it. A deleted recipe, meal or manual grocery leaves a minimal deletion marker so an older device cannot restore it accidentally; revision metadata and change receipts remain until the household is deleted. Invitation codes expire independently of their records; those records are cleaned up when the relevant membership/account is removed. Local data remains until it is edited, cleared or deleted as described below.
Gather remembers names of products you add manually so it can suggest them later. Manage these in Settings > Saved products. Deleting a saved name removes its suggestion without removing an item already on the current list; clearing the current list does not clear saved names. In a shared household this affects both members. A removed shared suggestion leaves a minimal synchronization marker, including its normalized name in the record identifier, until the household is deleted. Its saved display-name value is removed. Deliberately adding the name again can remember it again. These names are not sent to Wikimedia or AH merely because you type or save them; separate searches require the actions described below.
A private local cache holds shared data and saved pending changes for offline use. Changes sync when connected; conflicting edits need review. Signing out or leaving a household stops access to that shared space but keeps its local cache on the device. It does not replace the original local recipes.
Open Settings > Shop together to reach Your household and delete your account. The app rechecks your password, removes your account and profile, cleans up invitation records associated with your account and removes its tracked household caches for that account on this device. If another member remains, the shared recipes and list stay available to that member. When the last member leaves, the household is locked against new changes while its records and receipts are deleted, then the household is removed. Failed cleanup can be retried; the app does not report deletion as successful before completion.
Original local recipes, manually added groceries, saved product names, personal settings and operating-system backups are separate from account deletion. Edit or remove local recipes in the app, or clear the app’s data or browser storage. Removing an iOS app’s installation data differs from offloading it, which may retain data. Manage device backups separately. Authentication and provider operational records may take longer to be removed from provider backups; Firebase documents its retention practices at the link above.
If you cannot use the app, request account and associated-data deletion by emailing twistmodzzz@gmail.com from your account email address, with “Gather account deletion” in the subject. Include the account email address; do not send your password. The shared-data and backup limits described in this section also apply to these requests.
Optional recipe photos
You can choose a photo for a recipe using the system image picker. Gather receives the image you select, not access to your whole gallery. This feature selects images only and does not request camera, microphone or broad photo-library access. Choosing your own photo does not send it to Wikimedia or AH and does not enable online photo search.
Gather makes a small JPEG copy from the image’s pixels before saving it with the recipe; the original file and its EXIF/GPS metadata are not retained in that recipe. Local recipe photos remain on the device and work offline. A photo saved in a shared household is included in the same private Firestore recipe record, accessible to the household’s members under its existing access rules and cached locally for offline use. No public image link or separate photo-hosting service is created. Your original photo stays in your device’s library.
You can replace or remove the attached photo in the recipe editor. This changes the saved local or shared recipe copy, not the original image in your library. Existing offline caches, pending changes and backups follow the retention and deletion limits above. The selected-photo processing provides the recipe feature you request (Article 6(1)(b)).
Online photo search is off by default. After you allow it, Gather can send a normalized recipe name to Wikimedia Commons when you leave the recipe-name field, request a photo or save a recipe. Ingredient lists, descriptions and instructions are not included in the photo-search query. Permission stays personal, including in a shared household.
Wikimedia receives the query, IP address and normal connection information. Displaying a saved online photo also requests its image from Wikimedia, even after search is switched off. Remove the saved photo to stop its future display requests. Selected photo links and credits are saved with the recipe and therefore shared when that recipe belongs to a household. Bundled recipe-library photos, when selected, work offline. Photo attribution is available with the recipe.
Wikimedia handles its service logs and international processing under its own privacy policy. Switching search off or deleting a Gather account does not erase information already received by Wikimedia.
Opening products in the AH app
This is an unofficial feature, not endorsed or supported by Albert Heijn. Gather does not ask for, receive or store your AH account credentials or your signed-in AH session. A Gather account does not sign you into AH.
Pressing Search sends the product-name query you entered to AH's catalog service. Typing a name alone does not send it. AH receives your IP address and connection information. Catalog access uses an anonymous technical token held temporarily in memory, without your AH account or its login cookies; Gather clears this token when the AH screen closes. Product photos load from AH when shown, including saved products or products selected by your household partner. Showing these photos therefore makes requests to AH even without a new search. Gather does not send your full recipes, cooking instructions or Gather email address in catalog queries.
When you select a product, Gather saves its ingredient match, product name, exact AH product number, image link and available package information. In local use these preferences stay on the device. In a shared household they are stored in Firestore and shared with the other member so both can reuse or change the selection. Chosen package counts remain local to this device and its Gather account/household, or its separate local-use profile.
Pressing Open in the AH app passes the selected product numbers and package counts to the installed AH app through an AH link. Gather opens AH directly and does not automatically fall back to an external browser on a phone. The browser preview opens AH in a new tab. AH uses its own signed-in account or asks you to sign in there. The link does not include your Gather account, recipe instructions, ingredient names or recipe photos. Gather cannot read the resulting AH list or basket and receives no confirmation of additions. Gather never places or pays for an order and does not check off groceries after opening AH.
Once AH opens, Gather closes the handoff screen without asking you to confirm a basket check. A later deliberate press offers the full selected list to AH again and may increase quantities there. Only simultaneous taps during an opening operation are blocked; there is no persistent confirmation gate or automatic retry.
Local preferences and package choices remain until their local app/browser data is cleared or the relevant tracked account cache is removed through account deletion. Older Gather versions may have left local attempt journals containing ingredient references, product IDs/counts and attempt times. The current handoff neither reads nor updates these journals and does not use them to block another press; they remain subject to the same local-data cleanup. They are not addition receipts or new user confirmations.
You can replace product preferences in Gather. Shared preferences remain with the household, including for a remaining partner, under the deletion rules above. Stopping this feature or deleting Gather data does not delete information already received by AH. Manage AH lists, account information and privacy requests directly with AH.
AH independently controls its service and account data, including retention and its own settings. Its privacy policy for online services explains website/app connection data, searches and account-held shopping lists; its privacy-request page explains how to contact AH. Gather does not promise a separate deletion deadline for AH's records.
Sharing, support and external services
The Share action sends list text to the app or destination you select. That destination controls its copy. External links open when tapped and follow the destination’s privacy practices. Gather includes no advertising, analytics or tracking SDKs and requests no contact, camera, microphone or precise-location access.
If you email support, the publisher receives your email address and the information you choose to send through Gmail to respond to your request. Messages are kept while the request is being handled and for necessary follow-up, or where an applicable legal obligation requires retention. They are manually reviewed and deleted when those purposes no longer apply. You can request deletion using the contact above. Gather does not promise automatic mailbox deletion on a fixed schedule. Gmail is provided by Google under its privacy policy.
These privacy and support pages are served by Google Firebase Hosting over HTTPS. They contain no advertising, analytics scripts, cookies set by Gather, forms or embedded third-party content. Hosting receives visitors’ IP addresses and request information to deliver the pages, detect abuse and provide service-usage information. Google describes Hosting IP retention as a few months in its Firebase privacy information. Hosting uses global infrastructure; the Firestore EU location does not restrict website requests to the EU.
International processing
Google’s Firebase data-processing terms describe its role, security commitments, subprocessors and international-transfer safeguards. They provide for the EU–US Data Privacy Framework for applicable transfers to certified Google entities, and standard contractual clauses where applicable. The current subprocessor list identifies providers, locations and activities. Gmail and independently operated Wikimedia services also follow their own linked privacy policies; selecting EU recipe storage does not make every service an EU-only service.
Privacy requests and changes
Contact twistmodzzz@gmail.com to request access, correction, deletion, restriction or a portable copy of your personal data, or to object to processing based on legitimate interests. You can withdraw optional photo-search consent in Settings without affecting earlier processing. The publisher may ask for the information needed to verify that a request concerns your account; do not send a password. Requests are handled within the applicable legal period, normally one month under the GDPR. If an extension or refusal applies, you will receive an explanation.
You can complain to the Dutch Data Protection Authority or your local data-protection authority. Requests about data independently retained by Wikimedia, Google or AH follow their privacy contact routes as well. Gather does not use profiling or automated decisions that produce legal or similarly significant effects.
We update this policy when the app’s data practices change. The effective date above identifies this version. Any new optional processing will be explained before you choose it.