Back to home

Privacy Policy — BakeCost

Effective date: August 24, 2026 · Version 2.2

This policy describes how BakeCost ("the app", "we", "our", "us") collects, uses, stores, and protects your information when you use the mobile application, the web platform (bakecost.app), and related services (collectively, the "Service").

BakeCost is operated by Xavier Llano, an individual operating under the trade name "XlStudio", based in Pennsylvania, United States, who acts as the data controller for your account data.

Quick summary

  • Offline mode (no account): your business information stays only on your device. We have no access to it.
  • Account mode (optional): if you create an account, your information syncs encrypted to secure servers for backup and multi-device access. Only you can access your data.
  • Storefront (public store): if you activate your store, your customers' order data is stored on our servers and accessible to you as the store owner.
  • Import a recipe from a photo (AI, optional): only if you use this feature, the photo you choose leaves your phone so an AI provider can read it, and is discarded when it finishes. We do not store it and it is not used to train models. See section 1.6.
  • We never sell your information.
  • We don't use advertising or behavioral trackers.
  • We comply with applicable privacy laws, including the Children's Online Privacy Protection Act (COPPA) and Federal Trade Commission (FTC) regulations of the United States.

1. Information we collect

1.1 Offline mode (no account)

All information is stored locally on your device using the app's private storage. This includes:

  • Products, recipes (including your recipe book), and ingredients
  • Customers (name, phone, email, address, and birthday if you add them)
  • Orders, quotes, and payments
  • Inventory and stock movements
  • Price history
  • Expenses
  • Notes and photos of products and orders
  • Business settings (name, contact, currency)

In offline mode, we have no access to this information. Nothing leaves your phone unless you actively share it.

1.2 Account mode (optional)

If you choose to create an account for cloud sync, we collect:

Account information:

  • Email address
  • Full name
  • Business name
  • Business phone (optional)
  • Preferred currency
  • Timezone

Authentication information:

  • Password (stored with cryptographic hash; never in plain text)
  • Session tokens
  • Authentication provider (email, Apple Sign In, Google Sign-In)

Sync information:

  • All business data listed in section 1.1 syncs to our servers when internet is available
  • The product photos you sync are stored on our server and served via public, non-guessable URLs (anyone who has a photo's exact URL can view it). Order photos are not uploaded; they stay on your device
  • Sync timestamps
  • Device identifiers for multi-device management

Push notification tokens:

  • If you enable notifications, we store your device's push token (Expo Push Token) to send you order reminders from the server (as a backup to the local reminders, e.g. on a second device)

BakeCost Pro subscription (only if you subscribe):

  • Your subscription status, plan, and entitlement (if you have active Pro)
  • Purchase/receipt identifiers to validate your subscription
  • For purchases made on the web, a Stripe customer identifier

Payments are processed by Apple (App Store), Google (Google Play), or, when available, Stripe (web). We do not store your card number or full payment details.

1.3 Storefront (public store)

If you activate your public storefront on BakeCost, we additionally store:

Your store's public profile information:

  • Store name, description, logo
  • Store slug / URL
  • Delivery and pickup configuration
  • Published products with photos and prices
  • Accepted payment methods
  • Hours and minimum advance notice time
  • Business phone / WhatsApp (shared with customers who place an order so they can contact you)

Public photos: the product photos and the logo you upload for your storefront are hosted on our server (Supabase Storage) and are publicly accessible via their URL: anyone with your store link can view them. Order (reference) photos are not published; they stay on your device.

Information from customers who place orders in your store:

  • Customer name
  • Phone number / WhatsApp
  • Email address (if provided)
  • Delivery address (if they choose delivery)
  • Order details (products, quantities, notes)
  • Requested delivery date and time
  • Selected payment method

Abuse prevention: to prevent spam, the site may temporarily use the IP address of whoever submits the form; it is not stored with the order and is not used to track anyone.

Important: BakeCost acts as a data processor on behalf of the store owner (bakery). The store owner is the data controller for their customers' data. BakeCost does not use store customers' data for any purpose of its own.

1.4 Automatically collected information

Crash reports (Sentry): When the app crashes unexpectedly, a technical report is automatically sent to Sentry that includes:

  • Error stack trace
  • Device model
  • Operating system version
  • App version
  • Timezone and locale

It does NOT include: your name, orders, customers, recipes, photos, amounts, or any data from your business.

Information we do NOT collect:

  • We do not use tracking cookies
  • We do not use Google Analytics, Firebase Analytics, Mixpanel, or any third-party analytics service
  • We do not collect GPS location data
  • We do not access your contact list
  • We do not collect financial or credit card information (payments are coordinated directly between the bakery and the customer)

1.6 Import a recipe from a photo (AI) — optional

BakeCost includes an optional feature that reads a photo of a recipe and turns it into a draft ingredient list. It only happens when you use it: you tap "Import recipe from photo", choose to take a picture or pick one from your gallery, and that image is sent to be read. If you never use this feature, no image is ever sent.

What is sent: only the photo you chose (compressed as JPEG) and the app language. Nothing else from your business is sent: not your recipes, not your prices, not your customers, not your orders.

Where it goes: your device → our server → Google LLC (Gemini API), the provider that reads the image. Both hops are encrypted with HTTPS. The feature requires being signed in, because it is our server — never your phone directly — that sends the image to the provider.

What does NOT happen to that photo:

  • We do not store it. It is processed in memory and discarded when the request ends: it is not written to our database, nor to our file storage, nor attached to your account.
  • We do not log it. Our technical logs record content-free data only: model used, response code, duration, and payload size.
  • It is not used to train artificial intelligence models, not by us and not by Google. We use the Gemini API on its paid tier, whose terms exclude that use. Google may retain the request temporarily to process it and for its own abuse monitoring, per the Gemini API terms.
  • On your device: the temporary copies created by the camera or the photo picker are deleted as soon as the image is sent. The photo already in your gallery is not modified and is not uploaded anywhere else.

What you get back: a text draft —name, servings, ingredient lines, and the preparation method, transcribed as it appears in the photo— that the app shows you so you can review and correct it. Nothing is saved in your app until you confirm it, and what you confirm is saved to your recipe book: turning a recipe into a product is a separate decision, yours.

The AI does not calculate prices or costs. Every amount you see is computed by BakeCost's deterministic engine from the data you confirmed. The model only reads the photo.

Usage limits: to prevent abuse we may limit how many imports can be made per day. To keep that count we store a counter tied to your account identifier (see section 3); that counter contains no images and no recipe text.

AI gets things wrong. What it returns is an indicative draft: always review it before using it —especially ingredients, quantities, and units— and all the more so when allergens or food safety depend on it. See the Terms of Service.

2. How we use your information

We use the information we collect exclusively to:

  • Provide the Service: enable app functionality, data sync, and order management
  • Authentication: verify your identity and maintain account security
  • Notifications: send order reminders that you configure
  • Technical support: diagnose and fix technical errors
  • Communication: respond to your support inquiries

We do NOT use your information for:

  • Third-party advertising or marketing
  • Behavioral profiling
  • Sale or rental to third parties
  • Training artificial intelligence models — including the photos you send to the AI recipe importer, neither by us nor by our provider (section 1.6)
  • Any purpose not described in this policy

3. How we share your information

We do not sell, rent, or share your personal information with third parties for marketing purposes.

We share information only in the following cases:

Service providers (sub-processors):

  • Supabase, Inc. — Database and authentication. Data is stored on Amazon Web Services (AWS) servers in the United States. Supabase Privacy Policy
  • Vercel, Inc. — Web application and API hosting. Vercel Privacy Policy
  • Sentry (Functional Software, Inc.) — Technical crash reports only. Sentry Privacy Policy
  • Expo (650 Industries, Inc.) — Push notifications. Expo Privacy Policy
  • RevenueCat (RevenueCat, Inc.) — In-app subscription management and purchase-receipt validation (iOS/Android). RevenueCat Privacy Policy
  • Stripe (Stripe, Inc.) — Payment processing for subscriptions purchased on the web. Stripe Privacy Policy
  • Google LLC (Gemini API) — Reads the photo in the optional "Import recipe from photo" feature (section 1.6). It receives only that image and the app language; never your recipes, prices, customers, or orders. We use the paid tier, whose terms exclude Google using those submissions to improve or train its models; it logs them for a limited period solely to detect prohibited use. Gemini API terms · Google Privacy Policy
  • Upstash, Inc. — Temporary counters for usage limits and abuse prevention (account identifier or IP address). They contain no business data. Upstash Privacy Policy

Storefront: when a customer places an order in your store, their contact and order information is visible to you as the store owner.

Legal obligation: we may disclose information if required by law, court order, or legal process.

4. Actions you control

  • Quote via WhatsApp: opens your WhatsApp app with the message ready. You choose who to send it to. We see nothing.
  • Quote PDF: generated on your device; you choose how to share it.
  • Manual backup: you generate a JSON file and share it however you choose.
  • Call / WhatsApp a customer: opens your system app with the number prefilled.

5. System permissions

The app may request these permissions. You can deny them without losing core functionality:

  • Camera: to take photos of your products and orders —stored on your device, and in the cloud if you have an account— and, if you use "Import recipe from photo", to photograph a recipe so the AI can read it (section 1.6). That recipe photo is not stored anywhere.
  • Photos / Library: to pick images you already have —a product, your store logo, or the recipe you want to import— and, if you request it, save your store's QR code to your photos.
  • Notifications: only if you enable order reminders.
  • Internet connection (not a permission the system asks for, nor one you can revoke): used for sync, the storefront, and push notifications. The app works without a connection in offline mode.

6. Your rights over your information

You have the following rights over your information, regardless of where you reside:

  • Access: you can view all your information from the app at any time.
  • Edit: you can modify any data in your account, business, products, customers, and orders.
  • Export: you can export all your information in JSON format from More → Backup → Create backup.
  • Delete specific data: you can delete products, orders, customers, and other data individually.
  • Delete everything (offline mode): from More → Backup → Delete all, you erase all local information. This action is immediate and irreversible.
  • Delete account (account mode): you can delete your account and all associated data from More → Account → Delete account (open Account by tapping your account card at the top of the More tab; or by writing to us at [email protected]; also at bakecost.app/en/eliminar-cuenta). Deletion is immediate and permanent:
    • We immediately erase your business data from the server, your storefront's public photos, and your sign-in identity
    • In the rare case that one of those pieces can't be erased at that moment (for example, your storefront's public photos or your sign-in identity), the app tells you right then and states exactly what is still pending. Write to us at [email protected] and we complete it (we reply within 30 days at most). We never report as deleted something that still exists
    • Your public storefront is deactivated immediately
    • This action cannot be undone; export a backup first if you want to keep your information
    • Deleting your cloud account is independent of the data stored locally on your device
  • Portability: you can export your data in JSON format at any time before deleting your account.

You don't need our permission or to wait for a response to exercise most of these rights — control is built directly into the app.

For any additional requests, write to us at [email protected] and we will respond within 30 days.

7. Data retention

Offline mode: information remains on your device until you delete it or uninstall the app.

Account mode: information remains on our servers while your account is active. If you delete your account, data is erased immediately and permanently.

Storefront — customer data: order data is retained while the bakery's account is active. If the bakery deletes their account, those orders — and the customer contact data they contain — are deleted along with the rest of their information.

Crash reports: Sentry retains crash reports for a limited period and then deletes them automatically. The period is set by the plan we have with Sentry; you can consult it in their data retention policy.

Import a recipe from a photo (AI): the photo is not retained. It is processed in memory and discarded when the request ends; we keep no copy, neither in the database nor in file storage. Google logs it for a limited period solely to detect prohibited use, per its terms (section 1.6). The text draft it returns lives only on your screen until you decide to use it or discard it.

Manual backups: if you export a backup and upload it to iCloud, Google Drive, or another service, that copy is outside our control and governed by that service's policies.

8. Security

We implement the following security measures:

  • Encryption in transit: all communication between the app and our servers uses TLS 1.2 or higher (HTTPS).
  • Encryption at rest: data stored in Supabase is encrypted with AES-256.
  • Passwords: stored with bcrypt cryptographic hash. We never store passwords in plain text.
  • Authentication: we use JSON Web Tokens (JWT) with expiration.
  • Protected email change: changing your sign-in email requires confirmation from both addresses, the new one and the previous one. This is a deliberate account-takeover defense: someone who took over your session cannot quietly move your sign-in to another address without you confirming it too.
  • Per-account isolation: every database query is restricted on the server to the account making it, and an automated test blocks any change that bypasses that restriction. Row Level Security is additionally enabled as an extra layer over direct public access to the database.
  • Rate limiting: sign-in is protected against brute-force attacks by our authentication provider (Supabase Auth), and the public storefront form is rate-limited per IP to prevent spam.
  • Offline mode: information on your device is protected by your operating system's security measures (device encryption, lock code).

If you discover a security vulnerability, please report it responsibly to [email protected].

9. International data transfers

If you are located outside the United States, your information will be transferred to and stored on servers located in the United States (AWS, through Supabase). By using the Service with an account, you consent to this transfer.

If you use AI recipe import (section 1.6), the photo you send is additionally processed on Google LLC infrastructure, also in the United States, and is not stored. The usage-limit counters (Upstash) are likewise held in the United States.

We take reasonable steps to protect your information in accordance with this policy, regardless of where it is processed.

10. Third-party services and libraries

  • Expo / React Native: development framework. Does not collect user data in production.
  • Expo Notifications: handles push notifications through Expo's service.
  • Expo Image Picker: lets you pick images. Product photos, order photos, and your logo are saved in the app's storage; the recipe photo in section 1.6 is not — its temporary copy is deleted as soon as it is sent.
  • Supabase: cloud database, authentication, and storage.
  • Vercel: web application and API hosting.
  • Sentry: technical crash reports exclusively.
  • RevenueCat: manages BakeCost Pro subscriptions and validates in-app purchase receipts (iOS/Android).
  • Stripe: processes payments for subscriptions purchased on the web. We do not store your card details.
  • Google Play Services / Apple App Store: handle installation, updates, and in-app purchases (BakeCost Pro).
  • Google Gemini API: reads the photo in the optional "Import recipe from photo" feature. It receives only that image and the app language.
  • Upstash Redis: usage counters for limits and abuse prevention.

We do not use third-party analytics (Google Analytics, Firebase, Mixpanel, etc.), advertising, or behavioral trackers.

11. Children

The app is intended for adults who manage a bakery business. The Service is not directed at children under 13.

  • We do not knowingly solicit, collect, or store personal information from children under 13, in compliance with the Children's Online Privacy Protection Act (COPPA).
  • We do not allow children under 13 to create accounts.
  • If we discover that we have collected information from a child under 13, we will delete it immediately.
  • If you are a parent or guardian and believe your child under 13 has provided us with personal information, contact us at [email protected] and we will delete such information without delay.

12. California residents (CCPA)

If you reside in California, you have additional rights under the California Consumer Privacy Act (CCPA):

  • Right to know: you can request that we inform you what personal information we have collected about you.
  • Right to delete: you can request the deletion of your personal information.
  • Right to non-discrimination: we will not discriminate against you for exercising your privacy rights.
  • We do not sell your personal information. We have never sold and will never sell our users' personal information.

To exercise these rights, write to us at [email protected].

13. Changes to this policy

If we make material changes to this policy:

  • We will update the date and version at the top of this document
  • We will notify you through the app or by email (if you have an account)
  • Changes will take effect 30 days after notification, unless the law requires a different timeframe

Continued use of the Service after the changes take effect constitutes your acceptance of the updated policy.

Changes in version 2.2 (August 24, 2026): describes importing recipes from a photo (section 1.6) and adds Google LLC (Gemini API) and Upstash, Inc. as sub-processors (sections 3 and 10). There is no published version 2.1: that number was used by an internal draft from July 2026 that was never published. Section 1.5 (waitlist) and Resend as a sub-processor are also removed: the form and its endpoint were taken down on August 17 and 21, 2026, no address remains stored, and this version no longer describes that collection. Numbering skips from 1.4 to 1.6 deliberately, so external references to section 1.6 keep working. And the description of per-account isolation in section 8 is corrected, as it named Row Level Security as the mechanism: the real isolation is enforced on the server, query by query.

About version 2.2 (August 24, 2026). This version describes a new, optional feature — importing recipes from a photo, section 1.6 — and does not change how we handle any information we were already collecting. You are not subject to it by continuing to use the rest of the Service: it applies only if you choose to use that feature, and the app explains on screen what is sent before you send anything. The 30-day period above applies to changes in the handling of data we are already collecting.

14. Contact

If you have questions about this policy, about how we handle your information, or wish to exercise any privacy right:

Email: [email protected] Suggested subject: "Privacy — [your inquiry]"

We commit to responding within 30 days.

This policy applies to the mobile version of BakeCost distributed on App Store and Google Play, the web platform at bakecost.app, and all related services.