Who this covers
This policy describes how Savorible handles information in three situations:
- you create a Savorible account and a food blog
- you visit Savorible’s own marketing site (the homepage, blog, Help, FAQ, these pages)
- you read a food blog hosted on Savorible
Using Savorible is also covered by the Terms of Service.
Information from an account
When you create an account or a food blog, we collect:
- your email address, and a hash of your password — never the password itself
- the blog’s name, address, description, author details, logo, brand colour, visibility and the recipes, posts, tags and photos you add
- billing state for the blog (subscription status, period dates, Stripe customer and subscription identifiers). Card numbers are handled by Stripe, not stored by Savorible
- first-touch acquisition (UTM parameters, referrer and landing path), copied once from an anonymous cookie when you sign up
- when you accepted the Terms of Service and acknowledged this policy, and which version of those documents was in force
- whether you asked to receive occasional product updates, tips, and offers — stored separately from that Terms acceptance
- support tickets and messages you send us
- security events we need in order to run the account, such as email-change and password-reset tokens
We use this to provide the Service: to sign you in, host the blog, send account email (verification, password reset, address change, a welcome note), take payment, answer support requests, and keep the product working.
The marketing site
On Savorible’s own site we may set a first-party cookie, savorible_attribution_v1, so we remember how you first arrived (UTM parameters, referrer, landing path). It lasts 90 days, is not overwritten by later visits, and is copied into your account if you sign up. It does not store your name, email or IP address.
In production we may also load Google Analytics 4 on the marketing site, and the same Google tag may include Google Ads conversion measurement. Neither is loaded on Preview, staging or local development, and neither is used on hosted customer blogs. Google’s own cookies and privacy policy then apply to that measurement.
On production we may also load an OpenAI measurement pixel on Savorible’s own pages — the marketing site, account creation, and the signed-in app — so advertising in ChatGPT can be tied to what happens afterwards. Hosted food blogs leave that pixel out. When it loads, it stores an ad click reference in __oppref for 30 days and a random browser reference in __obref for up to 365 days. OpenAI’s privacy policy applies to that measurement. Preview and local development leave it unloaded. Staging loads it only when that environment is given its own pixel.
Readers of a hosted food blog
A public or unlisted Savorible food blog records first-party page views so the owner can see traffic on their dashboard: page views, roughly how many visitors, top recipes, landing pages, referrers and UTM campaigns.
Those records do not include names, email addresses or IP addresses. Savorible’s Google Analytics property is never sent this traffic. Raw page-view events are deleted after 90 days; daily totals are kept so the owner’s report still works.
Drafts, private blogs, and visits we can tell are bots or staff impersonation are not recorded.
Cookies
Savorible sets these first-party cookies:
savorible_session— set when you sign in, httpOnly, so the browser can keep you signed in. It is cleared when you sign out.savorible_attribution_v1— first-touch marketing attribution, 90 days, as described above. Set on the marketing site.savorible_blog_visitor_v1— a random visitor identifier on hosted food blogs, 90 days, so the owner can see roughly how many people visited. It does not identify you by name or email, and it is not used to profile people across blogs.savorible_blog_session_v1— a short-lived visit cookie on hosted food blogs (30 minutes of idle time), so the first page of a visit can be reported as a landing page.
You can block or delete cookies in your browser. Blocking the session cookie will sign you out. Blocking the hosted-blog analytics cookies means that owner will under-count visits; the blog still works.
Who else sees it
We do not sell personal information. We share it with the processors we need in order to run Savorible:
- Stripe — checkout, subscriptions, invoices and the customer billing portal
- Resend — sending account email
- Vercel — hosting the application and storing uploaded photos
- Google — Analytics on the production marketing site only, when that tag is loaded
- OpenAI — ads measurement on Savorible’s own pages, when that pixel is loaded
We may also disclose information if the law requires it, or if we need to protect Savorible, our customers, or the public. If the business is sold or merged, information would transfer with it under this policy.
A published food blog is public (or unlisted, if the owner chose that). Recipes, photos and the author’s name on those pages are visible to readers and to search engines on a public blog. That is the owner’s publishing choice, not a disclosure we make on the side.
How long we keep it
Account and blog data stay for as long as the account exists. Cancelling a subscription does not delete the blog: it goes offline and the dashboard becomes read-only, and the work is still there if you subscribe again.
There is no self-service deletion yet. To have an account and its data removed, contact support. We will delete or anonymise what we hold unless we are required to keep a record (for example a billing identifier Stripe still needs, or a closed support thread we must retain for a short period).
Raw hosted-blog analytics events are deleted after 90 days. Password-reset and email-verification tokens expire and are spent; they are not kept as a working login.
Your choices
You can correct the email address, password, blog profile and content from the dashboard. You can cancel a subscription from Billing.
You can ask us for a copy of the personal information we hold, to correct it, or to delete the account, by contacting support. We may need to confirm it is you before we act. If you are in a place that grants further rights (for example access, deletion, or restriction under GDPR, or similar rights under UK or California law), this is how to exercise them.
Account email is transactional — verification, security, billing-related notices — and is sent whether or not you opted in to product updates. When you create your food blog we also ask whether to send occasional product updates, tips, and offers. That preference is stored separately from your Terms acceptance. We do not currently send a Savorible newsletter; when we do, we will use this preference, and you can ask us to change it by contacting support.
Children
Savorible is for adults. You must be 18 or older to create an account. We do not knowingly collect personal information from children. If you think we have, contact support and we will delete it.
Where it is processed
Savorible is operated using processors that may handle data in the United States. If you use the Service from elsewhere, you understand that your information may be processed in the United States and in other countries where those processors run.
Changes to this policy
We may update this policy. The date at the top of this page is when it last changed. If a change is material, we will say so in the product or by email to the address on the account.
Contact
Privacy questions and requests: contact support. That is the same inbox as the rest of Savorible support.
