Public beta data & privacy

How CooksIntelligence handles your data

The landing page is public. Planning, pantry, favorites, saved plans, and account controls require sign-in and are scoped to the account's household. This page explains what the public beta sends, stores, and does not collect.

01

Graph exploration is not saved

Using the ingredient graph creates no CooksIntelligence account record. The hosting service may still create ordinary security and request logs.

02

AI runs during actions you start

Text or microphone input goes to OpenAI after you ask a question or tap the voice control. Loading a Whole Foods flyer can also send the bounded product names and brands to OpenAI to identify likely dinner ingredients. Fixed rules are used when AI is unavailable.

03

No ad trackers or advertising

The public beta has no advertising or behavioral tracking. It does not connect to retailer or recipe-site accounts.

Sign-in & storage

Account data the app stores

The Sites hosting service gives CooksIntelligence a stable authenticated user ID and account details. Every query uses that ID, so one account cannot request another account's records.

Saved meals, scheduled meal slots, grocery preferences, and versioned weekly planning criteria can include dates, servings, adults and kids, timing, dietary preferences, nutrition-ranking targets, your ZIP, preferred stores, selected retailer location IDs, preferred retailer organization IDs, preferred recipe-source IDs, and timestamps. A retailer preference does not mean a retailer account, price feed, cart, or inventory connection exists.

A guided shopping plan can store the Whole Foods store name, store ID, flyer URL, and offer details you select or enter: ingredient, product name, optional price, Prime status, valid-through date, capture time, and source URL. It can also store the ATK recipe title and URL, grocery items you enter, shopping checkoffs, and the items you mark as already in the pantry for that plan.

A shopping run stores plan and list revisions and the item keys you mark in cart or unavailable. A supported cooking run can store the exact serving schedule, meal and cooking-plan revisions, task and timer state, schedule changes, ingredient confirmation, lifecycle times, and acknowledged actions. Serving schedules and acknowledgments can reveal household routines. Revision records prevent stale tabs from silently overwriting a plan or cooking run.

The pantry stores supported ingredients marked in stock, low, or out of stock, plus an optional exact amount. It retains the newest 1,024 change events. Stop tracking removes the active item without changing a saved week and leaves a quantity-free marker, exported separately, so a stale tab cannot restore it. Changes are limited to 120 per 15 minutes and 500 per day per account. Pantry data is a household note, not inventory, purchase proof, or consumption. It changes a grocery list only when you apply an exact compatible amount; shopping and cooking do not reduce pantry amounts automatically.

Each account can keep 26 plan weeks and plan eight weeks ahead. At the limit, a new week removes only the oldest past week and its meals, shopping and cooking runs, meal reviews, and update history. Current and future weeks are not removed. Account export includes all retained plans, runs, meal reviews, pantry items, and related updates.

A meal review can store whether you made or skipped a meal, rating, repeat choice, adult and kid reactions, effort, cooking time, servings, leftovers, and a note. It copies the planned meal and displayed nutrition. That nutrition is still a planned estimate; notes, substitutions, and serving changes do not recalculate it. Only preference changes you approve can guide later meal suggestions.

Meal-photo storage is not connected to meal reviews in this beta. Meal review cannot upload or save a photo, and a photo would not prove nutrition, doneness, or food safety.

The planner requires sign-in. An unfinished weekly draft and typed market choices can remain in that browser tab's session storage. They are bounded before reuse, are not account records, and clear after save, discard, or when the browser ends the tab session.

Saved meals can be removed individually. A signed-in account can download its guided shopping plan, saved and scheduled meals, grocery preferences, exact weekly criteria snapshots, active and untracked pantry items and change history, shopping checkoffs, cooking schedules, task and timer state, cooking acknowledgments, meal reviews, and revision metadata as JSON, or erase those records in one confirmed action. This includes each meal review's planned-nutrition estimate and approved, pending, or declined preference choices. The export omits account ID, email address, mutation tokens, and payload digests.

Export and deletion do not cover hosting security logs, short-lived pseudonymous cost counters, or information already processed by outside providers. Do not put sensitive information in meal titles, meal-review notes, or store preferences.

Text AI & history

Data sent with a written AI request

A model-backed request sends the question, bounded recipe material, selected graph context, and server-derived food facts to OpenAI. For weekly ranking, code first applies meal-slot, dietary, and time rules. OpenAI receives only the eligible plan candidates and their planning facts. If AI is unavailable, those candidates keep a deterministic order.

After you load a Whole Foods flyer, the app may send each bounded product name, brand, and existing app ingredient ID to OpenAI for dinner-category classification. It does not send your location, store name, flyer URL, price, Amazon account data, or Whole Foods account data. The result only checks suggested items; you review the list before searching recipes. If AI is unavailable, fixed rules produce the clearly labeled automatic review.

Recipe ranking normally sends opaque candidate IDs and bounded planning facts. A custom exclusion review may also send the bounded candidate title and ingredient names. After dinners are selected, ingredient consolidation sends only the selected ingredient names and saved pantry display names under temporary surrogate IDs so AI can identify equivalent shopping items. It does not send recipe URLs, quantities, prices, directions, raw account or household IDs, or store data. A stable SHA-256-derived pseudonymous safety identifier accompanies the OpenAI request. CooksIntelligence setsstore: false, validates that every supplied ingredient is returned exactly once, and does not save the provider prompt or response in account data.

For a planning-assistant question, the server reloads the relevant account-owned planning records and prepares possible answers. OpenAI receives your question, the current stage, opaque candidate IDs, and short non-sensitive ranking summaries. That route does not attach your ZIP, store labels, meal titles, recipe directions, notes, photos, dates, or saved outcome text. Anything you type in the question is sent. The selected answer is server-written, and asking a question does not change your plan. If AI is unavailable, the app labels and returns a deterministic suggestion.

Food-history requests may use OpenAI web search and return clickable sources. CooksIntelligence sets store: false on Responses API calls and does not save the question or answer in its meal database. OpenAI may still retain abuse-monitoring logs for up to 30 days by default, subject to your account's applicable data controls; store: false does not promise zero provider retention.

For cost control, the app retains aggregate token counts and a one-way user digest for roughly 14 days. Expired rows are removed during the next budget check. Those rows contain no question, prompt, answer, email address, or raw account ID.

Voice

Data sent during a voice session

The browser checks whether the signed-in voice service is available before asking for microphone permission. It then streams live session audio to OpenAI over WebRTC. CooksIntelligence's server negotiates the session and supplies verified graph facts. The app does not write microphone or response audio to its D1 database or object storage. OpenAI processes the live audio under its applicable terms and policies.

The page may show OpenAI's transcript of spoken replies while the session is open. Those captions remain in page memory and clear when voice stops. Stopping voice, changing the graph, or leaving the page closes the local connection and microphone tracks. The interface stops each session after 10 minutes, and the server allows at most three new voice sessions per account per UTC day.

CooksIntelligence's browser interface enforces the voice instructions, tools, and time limits. The server negotiates the direct connection but cannot monitor or end a modified client's live session. Voice remains limited to household owners until trusted server-side controls and cost and safety tests are complete.

In Guided Cook, voice can move or repeat the current step, start or cancel one kitchen timer, or read the current step and remaining time. Those steps and timers stay in the open page and clear when it reloads. For a supported saved-week meal, the saved cooking plan stores task progress, schedule changes, timer state, and acknowledgments after you explicitly start it, so the cooking run can recover after a reload.

Keep the cooking page open for in-app timing guidance. Basic Guided Cook may attempt a local chime or vibration; the saved cooking plan updates visual timer status only. The beta does not promise a push, text, background, or lock-screen notification. A timer ending, a task checkoff, or a served acknowledgment never proves doneness or food safety; check the food and follow a verified safety source yourself.

Other providers

Retailer, recipe, nutrition, and location data

Selecting Use my location asks the browser for a one-time location. The browser sends those coordinates to CooksIntelligence's first-party store-search route. The server coarsens them before sending them to OpenStreetMap Nominatim. It then checks each candidate against an official Whole Foods store page and returns only stores with a verified official store ID.

Coordinates and distance are not written to the household profile or account export. A store name, official store ID, and flyer URL can be saved only when you select a store and save the guided plan. If location permission is denied or unavailable, you can enter an official store or flyer URL manually.

When you load weekly offers, the server retrieves the selected store's official public Whole Foods flyer without forwarding account credentials or cookies. The flyer provides advertised offers, not delivery inventory. Amazon or Whole Foods delivery prices and stock may differ.

CooksIntelligence does not ask for or use Amazon, Whole Foods, or ATK credentials. It does not access those accounts, carts, Buy Again, delivery inventory, or saved recipes. When you start a recipe search, it reads allowlisted public ATK metadata: title, canonical link, time, yield, ingredient list, diet, and category. It does not extract directions, editorial commentary, or images. The app can copy the remaining buy list and open Whole Foods ordering, but it does not add products to an Amazon cart.

The current public Nominatim service is for test-scale, user-triggered searches. Public release requires a production location provider or a hosted Nominatim service. Results include the required OpenStreetMap attribution.

Live nutrition search, when configured, sends a food-search phrase to USDA FoodData Central. Any sample grocery offers elsewhere in the beta are labeled demonstration data.

Shopping checkoffs and guided-plan pantry marks are CooksIntelligence account notes only. They do not prove a retailer purchase, package size, paid price, pantry quantity, shelf stock, substitution, or consumption.

Safety

Keep health details out of the service

Nutrition is an estimate and the AI assistant is not medical advice. Do not submit diagnoses, medical records, or other sensitive health information. Use verified allergen labels and food-safety guidance for real decisions.