Privacy Policy
Last updated: September 5, 2026
This policy explains what "Piqi" (the "App") collects, how it is used, who it is shared with, how long it is kept, and how you can delete it.
Operator: Zhipeng Hui Contact: support@pi-qi.com
The short version
The App requires you to sign in with Apple or Google, but we do not collect your name or phone number — all we receive is an anonymous identifier that is specific to this App.
The videos, images and text you choose to analyze are uploaded to our server and passed to OpenAI for recognition; the original material is deleted once processing finishes.
The recipes that come out of it are stored on our servers under your account, so that you can get them back after changing phones or reinstalling. We do not interpret their contents, and we do not use them for analytics or recommendations.
You can erase everything on our server — including that recipe library — at any time from Settings › Delete Account inside the App.
1. What we collect
1.1 Your account
Using the App requires signing in with Apple or Google. When you do, Apple or Google hands us a signed identity token, from which we take exactly one thing: a user identifier that is specific to this App (Apple calls it sub). From that, our server creates an anonymous account number (something like u_1a2b3c4d).
- We never see your Apple or Google password; the whole sign-in happens inside
the system or your browser.
- That identifier is scoped to this App: the same Apple account produces a
different value for every other app, so nobody can use it to link you across apps.
- If an email address comes with the sign-in, we use it only to recognise your
account when you write to us. With Apple's Hide My Email we receive the relay address and make no attempt to resolve it.
- The account number is not linked to your name, phone number, the Apple ID
itself, or any advertising identifier.
- It does three things: remember how much of your monthly analysis quota you
have used, remember whether you have an active subscription, and associate your recipe library with you (see "Your recipe library is stored on our servers" under section 3).
1.2 What you submit
The videos and images you pick on the import screen, and any text you add yourself. These are uploaded to our server so we can generate a recipe.
1.3 What we derive from it
- Frames extracted from the video, and text transcribed from its audio
- The generated recipe itself (title, ingredients, steps, nutrition estimate)
1.4 Purchase information
When you subscribe, Apple gives us a signed transaction receipt. We use it to confirm the purchase is genuine and to record when the subscription expires. We never see or receive your payment method, card details, or Apple ID.
1.5 Technical information
- A push notification token (only if you allow notifications), used to tell you
when an analysis finishes
- Server access logs containing IP address, timestamp and request path, used for
troubleshooting and abuse prevention
1.6 What we do not collect
Location, contacts, calendar, your photo library beyond the items you explicitly pick, the advertising identifier (IDFA), and any third-party analytics or advertising SDK — the App contains none.
We do not sell or share personal information, and we do not use it for cross-context behavioral advertising.
2. Who it goes to
| Recipient | What | Why |
|---|---|---|
| OpenAI | Audio transcription, video frames, your text | Recognize the content and generate a recipe |
| Apple | Sign-in token verification, receipt verification requests, push notifications | Confirm it is you, confirm purchases, deliver notifications |
| Sign-in token verification | Confirm it is you | |
| Cloudflare | Generated recipe images | Image storage and delivery |
We do not sell, rent or otherwise share your information with anyone beyond these processors.
Our servers are located in the United States, and OpenAI processes data in the United States. If you use the App from outside the United States, your content is transferred there for processing.
3. How long we keep it
| Data | Retention |
|---|---|
| Uploaded videos and images | Deleted once analysis completes; material uploaded but never analyzed is deleted after 6 hours |
| Generated recipe images | Until you delete the recipe or your account — see below |
| Generated recipes (server cache) | Up to 30 days, and cleared whenever the service restarts — see below |
| Account number and subscription status | Until you delete your account |
| Your recipe library on our servers | Until you delete that recipe or your account — see below |
| "Deleted" markers (identifier and timestamp only) | Up to 90 days |
| Share codes | Expire automatically after 30 minutes |
| Server access logs | At most 30 days |
Why recipe images are kept
The step images in a recipe live on our server, and the copy of the recipe on your phone points at them — it does not hold its own copy. Deleting those images would mean a recipe you saved months ago silently loses its pictures.
So these images follow your account: they are deleted when you delete that recipe, or delete your account. We do not clear them to save storage.
About that server-side cache
When the same content is analyzed again, we reuse the previous result instead of processing it a second time. To do this, the generated recipe is held in server memory for up to 30 days. It:
- lives only in memory, is gone when the service restarts, and is never
written to disk or backed up
- is not associated with your account number — the cache key is a fingerprint
of the content itself, so it cannot tell us who submitted it
- does not contain your original video or images
Your recipe library is stored on our servers
This is separate from the cache described above; please read them apart.
Once you sign in, your recipe library (dish names, ingredients, steps, cooking notes, folder membership and so on) is stored on our servers under your account. This exists for one reason: so that when you change phones, reinstall the App or lose your device, you can sign in and get everything back.
Specifically:
- it is stored per account, and readable only with your sign-in credentials
- we do not interpret its contents — the server only knows which entry it is,
when it changed, and whether it was deleted; the recipe itself is opaque to us
- we **do not use it for analytics, model training, or content recommendations of
any kind**
- it is deleted together with your account: the moment you tap Delete Account,
this copy is gone too
- when you delete a single recipe, that entry is deleted on the server as well
(a "deleted" marker holding only an identifier and a timestamp is kept for up to 90 days — without it, a recipe you deleted would come back on your other devices)
⚠️ Until your first successful sync, your recipes exist only on that phone. The App's settings screen states the current status honestly ("not synced yet" / "synced"); it will never claim your recipes are backed up when they are not.
4. Your rights
Delete your account
Settings › Delete Account inside the App. This permanently deletes the account on our server, your quota record, your push notification tokens and any share codes you still have open, the copy of your recipe library on our servers, along with all recipe data on your device. This cannot be undone.
⚠️ Deleting your account does not cancel your subscription — that is a contract between you and Apple. Cancel it under Settings › Apple ID › Subscriptions on your device.
California residents (CCPA/CPRA)
If you are a California resident you have the right to know what personal information we collect, to request its deletion, to request correction, and not to be discriminated against for exercising these rights.
In practice: the only personal information we hold is the anonymous account number described in section 1.1, and Settings › Delete Account deletes it immediately without contacting us. You may also write to the email address above.
We do not sell your personal information and we do not share it for cross-context behavioral advertising, so there is no "Do Not Sell or Share" opt out to offer.
Access and correction
The App does not collect personally identifying information, so there is no profile to review or correct. If you have questions about what we hold, write to the email address above.
Withdrawing permission
Turn off photo library or notification access in your system Settings › Privacy. Everything else in the App keeps working.
5. Children
The App is not directed to children under 13, and we do not knowingly collect personal information from them (COPPA). If you believe a child under 13 has provided us with information, write to the email address above and we will delete it.
6. Security
- All network traffic uses HTTPS.
- Device keys are stored only as hashes on the server.
- Secret configuration files on the server are readable only by root.
No system can be guaranteed absolutely secure; we can only commit to taking reasonable measures.
7. Changes
If this policy changes we will update the date at the top of this page. Significant changes will also be surfaced inside the App.
8. Contact
support@pi-qi.com