Privacy Policy
Quickle Limited (“Quickle”, “we”) builds the Quickle app. This policy explains what we collect, why, and your rights under UK GDPR. The short version: we collect what the app needs to work, we don’t sell your data, and your supermarket login never touches our servers.
What we collect
- Account details — when you sign in with Apple or Google: your name and email address (Apple lets you hide your email; that works fine with us). If you sign in with an email address and password instead, we store your email address, and your password is stored only as a salted one-way hash by our database provider, Supabase — nobody at Quickle can read it or recover it for you, which is why a forgotten password is reset by emailed link rather than looked up.
- Your recipes and plans — recipes you save or import (including links you share and photos you take of recipes), your weekly meal plans, and shopping preferences such as your chosen supermarket, household size and dietary preferences.
- Imported content processing — when you import a recipe we process the link, caption, audio and video frames to extract the recipe. This uses trusted processors: Deepgram (audio transcription) and Anthropic (AI recipe extraction), plus a video-processing server we run ourselves on Fly.io in London, which downloads the video and takes the still frames the extraction reads. The content processed is the recipe you chose to import, not your wider account.
- Usage analytics — app events (e.g. “recipe imported”, “basket filled”) via PostHog, used to understand what’s working and fix what isn’t. Before you sign in these are tied to a pseudonymous device identifier; once you sign in they are tied to your account identifier, so a problem can be followed across your devices and after a reinstall. Your name and email address are never sent to PostHog.
- Crash reports — via Sentry, so we can fix bugs. These may include device model and OS version.
- Subscription status — processed by Apple and RevenueCat. We never see your payment details.
- Notifications — if you allow them, a device token held by Expo’s push service so we can tell you when someone in your household orders the shop or your picks match. Nothing else is sent with it.
- Household sharing — if you join a household, the name you choose, your weekly plan, your saved recipes and your meal picks are visible to the other members (up to five people). Your dietary preferences stay private to you.
- Advertising measurement — if you say yes to the tracking prompt, Apple’s advertising identifier is shared with RevenueCat and Meta (Facebook), the ad platforms we use to measure which ad brought you here, for one purpose: knowing which ad led to which subscription, so we can buy fewer and better ads. Say no and the app works identically — Meta then receives only a pseudonymous install identifier and basic app events (such as install and subscription), which do not follow you across other apps or websites. We never use any of it to build a profile of you, and we never sell it.
What we never collect
- Your Quickle password in readable form. It goes straight from the sign-in screen to our database provider, which hashes it. It is never written to your phone, our logs, our analytics or our crash reports.
- Your supermarket password. When Quickle fills your basket, you sign in to your supermarket inside the supermarket’s own secure webpage on your device. Your credentials go directly to the supermarket and are never sent to, stored by, or visible to Quickle.
- We don’t sell personal data, and nothing in Quickle tracks you around other apps or websites. The only advertising data we handle is the measurement described above, and the cross-app part of it only if you allow it.
Where your data lives
Account, recipe and plan data are stored with Supabase (our database provider). Analytics and crash data are held by PostHog and Sentry. Some processors may store data outside the UK; where they do, transfers are covered by standard contractual clauses.
How long we keep it
For as long as you have an account. Delete it from inside the app — Profile → Account → Delete account — or email us, and your account, recipes, plans and push token are deleted straight away. If you set up a household, it passes to whoever joined first so nobody else loses their plan; pseudonymous analytics may be retained in aggregate.
Your rights
Under UK GDPR you can request access to, correction of, or deletion of your personal data, and you can complain to the ICO (ico.org.uk). For any request, email contact@quickleapp.com — we respond within 30 days. The data controller is Quickle Limited, 124 City Road, London, EC1V 2NX, United Kingdom (company no. 17374653).
Changes
If this policy changes materially we’ll say so in the app. This page always holds the current version.
