Privacy
This page says what Tuckabox does with what you put into it. It describes how the app works today, not what it might do one day.
What stays on your device
Your recipe box, your pantry, your shopping list, what you have ticked off while cooking and your settings are stored by your browser, on the device you are using. If you never sign in, none of it leaves that device and Tuckabox cannot see any of it. Clearing this site's data in your browser deletes it, and nobody can get it back for you — which is why Settings can export your recipes to a file.
You do not need an account for any of that. The recipe box, the pantry, the shopping list, cook mode and importing a recipe from a link all work signed out.
What goes to our server when you sign in
Signing in keeps a copy of your recipes, your pantry and your shopping list on our server, so your other devices can read them. That copy is held against your account. No other cook can reach it.
We use that copy for one more thing. Now and then we read how pantry items are worded — never recipes, and never your shopping list — to check that Tuckabox understands the way people write down food. "Half an onion" has to match recipes that need onion. What comes out of that check is counts and words we did not recognise, never anyone's list.
The server is in Virginia, in the United States. So is the database.
What we send to Anthropic
Five things in Tuckabox use Anthropic's AI: reading a recipe out of text or photographs, inventing a dinner from your pantry, suggesting starter recipes, suggesting a substitution, and filling your pantry from photographs of your kitchen or from what you say is in it. All five need an account. A sixth, making a recipe plant-based, uses a different company and is described below.
When you use one, we send what that action needs to Anthropic, a company in the United States, and the answer comes straight back. Depending on the action, that is the text you pasted, the photographs you chose, the recipe you are looking at, or what is in your pantry. Tuckabox keeps no copy of the photographs — of a recipe or of your kitchen — they are sent, read, and never stored here. What Anthropic keeps, and for how long, is Anthropic's to say.
Anthropic's commercial terms for the service we use say that “Anthropic may not train models on Customer Content from Services”. That is Anthropic's promise rather than ours. You can read it at anthropic.com/legal/commercial-terms.
What we send to TypeSafe
A sixth thing uses AI: making a recipe plant-based. It needs an account too, and it costs nothing and spends none of your AI actions. It uses a different company, TypeSafe, in the United States, whose small model picks swaps from a list Tuckabox keeps. We send it the recipe you are converting, its title, its ingredient lines and its method, and the answer comes straight back. Tuckabox stores the swaps you accept as part of your recipe, and counts of how many recipes your account converted and asked to convert each day, listed below with the other things we record. It stores nothing else about the conversion.
TypeSafe's privacy policy says it will “not train or fine tune any artificial intelligence or machine learning models on your prompts or other Input”, and that it keeps data “for as long as reasonably necessary to provide you with the Services, or otherwise in support of our business or commercial purposes”. It names no period, so we cannot tell you one. That is TypeSafe's policy rather than our promise. You can read it at typesafe.ai/privacy.
Your account and your payment
Clerk holds your account: your email address, how you sign in, and your plan. Clerk is outside Australia. If you buy the plan, you pay inside Clerk's own checkout — your card details never reach Tuckabox's code at all.
What we record about using the app
Eight things, and no more than these:
- Which days your account opened the app. Not what you did on them.
- For each recipe imported from a link, the site it came from — say bbcgoodfood.com — and whether the import worked. Never the full address, and never the recipe.
- How many AI actions your account has used and what each one cost us to run. This is the billing record.
- How many recipes your account made plant-based on each day, and how many times it asked to. Two numbers per day, never which recipes, so that nobody can run that feature without limit. They are deleted when you close your account.
- When you fill your pantry from a photograph or a spoken list, which of those two you used, and three numbers: how many things came back, how many you kept, and how many we could see but could not name. Plus whether you replaced your pantry or added to it. Never the photograph, never what you said, and never any of the names. We are measuring how well that feature reads a real kitchen, and we will stop recording it once we know.
- If Tuckabox breaks in your browser and you press Send report, what broke: the browser's own name for the error, where it happened in the code Tuckabox runs — ours, and the shared libraries we build it from — and which version of your saved recipes was being opened. Never the error's message, because that is the part that can quote your own recipe back at us. Nothing is sent unless you press the button.
- With that report, the line your browser sends every website to identify itself. It names the browser and its version, and usually the operating system and the kind of device you are on. We keep it because most faults of this kind only happen on one browser or one version.
- If you are signed in when you press Send report, the report can carry your account with it. It does not always: we keep one record per distinct fault, so a report that matches one somebody already sent is counted against theirs. When a report cannot get through at the time, your browser keeps it and tries again later, and that later try never carries your account — though the first try may already have reached us with it. If you are signed out, nothing about who you are is sent at all, on either try.
None of those records what you were cooking. There is no record anywhere of which recipes you open.
We delete a crash report once it is 90 days old. The clearing out happens whenever the next report arrives, so if nobody sends one for a while, the last few sit there until somebody does.
Visitor numbers
We use Vercel Web Analytics to count visits. It is told which screen was opened — /recipe, /shopping — along with the things any web server sees anyway: where you came from, your country, your browser and whether you are on a phone. Everything after the screen's name is cut off before it leaves your browser, so which recipe you opened is never sent.
It sets no cookies and it cannot follow you to another site. Vercel says it recognises a visitor by a hash of the request and discards that after 24 hours. Nothing ties a visit to your account.
Cookies
Clerk sets cookies to keep you signed in. Tuckabox sets none of its own, and nothing here advertises to you or follows you around.
When you close your account
Close your account from the account panel in Settings. Clerk tells us it has closed, and your recipes, pantry, shopping list and daily counts of plant-based conversions are deleted from our server when that message arrives — normally within moments. If the deletion fails, the message is sent again until it works. The copy on your own device stays there until you clear it.
Three things stay behind:
- The record of the AI actions your account used, because that is what you were billed for.
- The note of which days the app was opened, and which sites links came from. That is how we understand whether Tuckabox is worth running.
- Any crash report you sent. What broke is about our code, not about you, and it may still need fixing, so we keep the fault itself. We take your account off those reports when you close your account. A report that was still on its way to us at that exact moment can keep your account on it — if that matters to you, email us and we will clear it. The whole report goes at 90 days, in the way described higher up the page: the clearing out happens when the next report arrives, so the last few can sit a while longer.
None of the three holds a recipe. The first two have no date on which they are deleted. If you want any of them gone sooner, email us and we will remove them.
Getting in touch
Questions about any of this, or about what we hold on you: hello@tuckabox.app.
Tuckabox is run by Roan Bradley in Australia. Last updated 23 September 2026 — when this page changes, that date changes with it.