隱私權政策
手把手廚房 · 更新於 2026-10-10
做菜用不到帳號,也沒有追蹤、沒有廣告。只有你想把自己的菜譜公開到社群時,才需要建立一個帳號(見下面「社群帳號」);不建帳號的話,我們不收集任何能識別你身分的資料。
你的菜譜存在哪裡
- 你導入和編輯的菜譜、做好的菜的照片、下廚紀錄,都只存在這台裝置上。我們的伺服器沒有你的菜譜清單,也沒有你的照片。
- 菜譜照片的去背在手機上完成,不會上傳。
- 我們不提供雲端同步。這些資料會跟著 iPhone 本身的備份(例如 iCloud 備份)一起備份;沒有備份就刪掉 App 的話,會一起消失。
- 用 Apple Watch 時,做菜的步驟和計時是從手機直接傳到你自己的手錶上,不經過我們的伺服器。
截圖怎麼處理
- 你選的截圖會傳到我們的伺服器,立刻轉發給 AI 服務 DeepSeek 做辨識,拿到步驟後就丟棄。第一次使用前,App 會先問你同不同意。
- DeepSeek 的伺服器在中國。圖片裡如果有人或個人資訊,也會一起傳過去,請只選菜譜的圖。
- 我們的伺服器不保存任何圖片,不做備份,也不拿來訓練模型。
- DeepSeek 怎麼處理這次請求,適用他們自己的條款與隱私權政策。
貼網址導入
- 你貼上一個菜譜網頁的網址時,我們的伺服器會去讀那一頁公開的內容,把裡面的菜譜文字交給上面同一個 AI 服務整理成步驟。
- 伺服器不保存那個網頁,也不保存你貼過哪些網址;整理完就丟棄。導入的菜譜和截圖導入的一樣,只存在你的手機上,並記下來源網站。
分享出去的菜譜
- 只有你主動點「分享」,那一份菜譜才會存到伺服器並產生一條公開連結。
- 連結本身就是憑證 —— 分享過的菜譜不會自動出現在社群列表上;分享頁也標明了不讓搜尋引擎收錄。
- 你可以隨時在 App 裡撤回分享,撤回等於從伺服器刪除,連結立刻失效。
- 分享出去的是菜譜的做法和材料,不含任何裝置資訊。你的心得、做過幾次、署名和留言預設不帶 —— 心得和次數要你勾選、署名和留言要你自己填,才會一起公開(心得會顯示在網頁上,也會出現在連結的預覽卡片裡)。
社群帳號(選用)
- 可以用 Apple、Google 或電子郵件驗證碼登入。我們存:你的暱稱、登入方式的識別碼(Apple / Google 給的一串 ID)、你用來登入的電子郵件(用 Apple 或 Google 登入時,只存它們確認過的地址;選了 Apple「隱藏我的電子郵件」的,存的就是那個轉寄地址),以及帳號建立的時間。
- 電子郵件只用來寄登入驗證碼,以及在帳號頁顯示給你自己看。不寄廣告、不公開、不提供給任何人,也不會拿來把不同的登入方式自動合併成一個帳號。
- 驗證碼由發信服務 Resend 寄出;伺服器只存驗證碼的雜湊值,10 分鐘後失效。為了防止有人大量寄信,也會暫時記一個由網路位址算出、無法還原的雜湊值來限制次數(不存 IP 位址本身)。
- 登入後,手機上存一個登入憑證(在系統鑰匙圈裡),伺服器只存它的雜湊值;半年沒用會自動失效。你也可以在 App 裡登出所有裝置。
- 帳號不會同步你的菜譜、照片或下廚紀錄,那些一直只在你的手機上。
- 刪除帳號:App 裡「帳號 → 刪除帳號」。會刪掉帳號、暱稱、所有登入方式與登入紀錄(包括網頁版的)、你公開到社群的每一道菜(包括它們的分享連結)、你送出的檢舉、記在帳號上的訂閱紀錄。用 Apple 登入的,也會通知 Apple 撤銷授權。刪除帳號不會取消訂閱,取消要到 iPhone 的「設定 → Apple 帳號 → 訂閱項目」。
會員訂閱
- 會員是透過 Apple 的 App 內購買訂閱的,付款、續訂、退款都由 Apple 處理,我們拿不到你的付款資料。
- 你登入社群帳號時,App 會把這筆訂閱的交易編號傳給我們的伺服器;伺服器拿它向 Apple 查詢訂閱狀態和到期日,記在你的帳號底下,好讓網頁版認得你是會員。之後會定期再向 Apple 確認。
- 我們存的只有:交易編號、方案、狀態、到期日。刪除帳號時一併刪除。
網頁版
- 網頁版(cookcoach.rokajun.com)顯示社群上公開的菜譜:標題、作者暱稱、用料任何人都看得到,做法只給會員看。
- 網頁版用 App 登入:網頁上顯示一組 6 位數的碼,在 App 的帳號頁輸入即可。伺服器只存這組碼的雜湊值,5 分鐘後失效。
- 登入後,瀏覽器會存一個 Cookie,只用來保持登入(網頁裡的程式讀不到它);伺服器只存它的雜湊值。按「登出」或半年沒用就失效。
- 網頁版沒有其他 Cookie,沒有分析或廣告工具。網頁的字型從 jsDelivr 載入,和一般網站一樣,它會收到你的連線資訊。
公開到社群的菜譜
- 只有你登入、並對某一道菜再確認一次,它才會出現在公開列表上(App 裡和網頁版)。公開的是你確認那一刻的菜譜文字和你的暱稱。
- 公開前要先同意社群使用條款:對不當內容和騷擾他人零容忍,違反的內容會被移除、帳號會被停用。
- 之後你改了菜譜,公開的那一版不會自動跟著變;要你再確認一次才更新。
- 公開和更新時,系統會自動檢查有沒有廣告、聯絡方式或不當字詞;被別人檢舉的菜譜可能先暫時隱藏,由人工審核。
- 你可以隨時撤下,撤下之後就不在列表上了。撤下的菜譜仍然算在你的帳號底下,刪除帳號時會一起刪掉。
- 被檢舉而暫時隱藏、或被管理員移除的菜譜,即使你撤回分享,我們也會保留它的標題和審核紀錄(正文會刪掉),用來處理濫用;這些紀錄在你刪除帳號時一併刪除。
檢舉
任何人都可以檢舉公開的菜譜。沒登入的檢舉,我們只存一個由網路位址算出、無法還原的雜湊值,用來避免同一處重複計算;不存 IP 位址本身。
相機與相簿
只在你主動選圖或拍照的當下讀取那一張,不會掃描或上傳相簿裡的其他照片。
麥克風與語音指令
- 裝置支援時,語音辨識在手機上完成;不支援時,系統會交給 Apple 的語音辨識服務處理(需要連網,適用 Apple 的隱私權政策)。
- 本 App 不保存錄音,也不傳到我們的伺服器。
- 暫時用不了(例如沒有網路)時,語音會自動關掉並提示你,點螢幕照常可以操作。
- 這個功能預設關閉,你自己在設定裡打開才會用到麥克風。
通知
只用來在計時結束時提醒你。不會用來推播行銷訊息。
伺服器與運行紀錄
- 我們的伺服器和資料庫架在 Cloudflare 上。和一般網站一樣,連線會經過 Cloudflare,它會為了傳送和安全處理 IP 位址等連線資訊。
- 伺服器會留下運行紀錄來排查錯誤,可能包含連線資訊;AI 辨識出錯時,也可能有一小段辨識出來的菜譜文字(不含圖片)。這些紀錄最長保留 7 天,之後自動刪除。
我們不做的事
- 沒有第三方分析、廣告或追蹤 SDK。
- 不收集裝置識別碼、位置、通訊錄。
- 不販售、不交換任何資料。
兒童
這個 App 不針對 13 歲以下兒童,也不會刻意收集他們的資料。
變更
政策有變動會更新本頁的日期。重大變動會在 App 內告知。
聯絡
rokajun11@gmail.com
Privacy Policy
Cook Coach · Updated 2026-10-10
Cooking needs no account, and there is no tracking and no ads. You only need an account if you want to publish your own recipes to the community (see "Community account" below); without one, we collect nothing that identifies you.
Where your recipes live
- Recipes you import and edit, photos of dishes you made, and your cooking history are stored only on this device. Our server holds no list of your recipes and none of your photos.
- Background removal on recipe photos happens on the phone and is never uploaded.
- We don't offer cloud sync. This data is included in your iPhone's own backups (such as iCloud Backup); if you delete the app without a backup, it's gone.
- With Apple Watch, steps and timers go straight from your phone to your own watch, not through our server.
What happens to your screenshots
- A screenshot you pick is sent to our server and immediately forwarded to the AI service DeepSeek for recognition, then discarded. The app asks for your consent before the first time.
- DeepSeek's servers are in China. Anything visible in the image, including people or personal details, is sent too — please pick recipe images only.
- Our server stores no images, keeps no backups, and does not use them for training.
- How DeepSeek handles that request is governed by their own terms and privacy policy.
Importing from a link
- When you paste the address of a recipe page, our server reads that page's public content and passes the recipe text to the same AI service above to turn it into steps.
- The server keeps neither the page nor the addresses you paste; they are discarded once the steps are ready. Like a screenshot import, the recipe is stored only on your phone, with the source site noted.
Recipes you share
- A recipe is stored on the server and given a public link only when you tap Share.
- The link is the credential — shared recipes don't appear in the community list on their own, and share pages tell search engines not to index them.
- You can unshare at any time from the app; that deletes it from the server and the link stops working immediately.
- What's shared is the method and ingredients, with no device information. Your notes, how often you cooked it, a byline and a message are left out by default — notes and the count only if you tick them, a byline and message only if you write them (notes appear on the web page and in the link preview card).
Community account (optional)
- You can sign in with Apple, Google, or an email code. We store your display name, the identifier of each sign-in method (an ID from Apple / Google), the email you sign in with (for Apple or Google, only an address they have verified — if you chose Apple's "Hide My Email", that relay address), and when the account was created.
- Your email is used only to send sign-in codes and to show you which address you signed in with. No marketing, never shown publicly, never given to anyone, and never used to merge different sign-in methods into one account automatically.
- Codes are sent through the email service Resend; the server keeps only a hash of the code, which expires after 10 minutes. To stop bulk sending, we also briefly keep a one-way hash derived from the network address to limit how many codes can be sent (never the IP address itself).
- After you sign in, a sign-in token is kept on your phone (in the system keychain) and only its hash on the server; it expires after six months without use. You can also sign out of all devices in the app.
- An account does not sync your recipes, photos or cooking history — those stay on your phone.
- Deleting your account: in the app, Account → Delete account. This deletes the account, your name, every sign-in method and session (web ones included), every recipe you published to the community (including their share links), the reports you sent, and the subscription record on the account. If you used Sign in with Apple, we also ask Apple to revoke the authorization. Deleting your account doesn't cancel a subscription — do that in iPhone Settings → Apple Account → Subscriptions.
Premium subscription
- Premium is bought through Apple's In-App Purchase. Apple handles payment, renewals and refunds; we never see your payment details.
- When you're signed in to a community account, the app sends the subscription's transaction ID to our server, which asks Apple for its status and expiry date and records them on your account so the web version knows you're a member. It checks with Apple again from time to time.
- We keep only the transaction ID, plan, status and expiry date. They are deleted with your account.
Web version
- The web version (cookcoach.rokajun.com) shows recipes published to the community: anyone can see the title, the author's display name and the ingredients; the method is for members only.
- You sign in to the web with the app: the page shows a 6-digit code that you enter on the app's Account page. The server keeps only a hash of the code, which expires after 5 minutes.
- Once signed in, your browser keeps a cookie used only to keep you signed in (scripts on the page can't read it); the server keeps only its hash. It ends when you sign out or after six months without use.
- The web version sets no other cookies and uses no analytics or advertising tools. Its font is loaded from jsDelivr, which, like any website, receives your connection data.
Recipes you publish to the community
- A recipe appears in the public list (in the app and on the web) only after you sign in and confirm it once more. What's published is the recipe text at that moment, plus your display name.
- Before publishing you agree to the Community Terms: zero tolerance for objectionable content or abuse; violations are removed and the account is suspended.
- If you edit the recipe later, the published version doesn't change until you confirm again.
- Recipes are checked automatically for ads, contact details and abusive words when published or updated; recipes reported by others may be hidden while a person reviews them.
- You can take a recipe down at any time. A recipe you took down still belongs to your account and is deleted with it.
- If a recipe was hidden after reports or removed by a moderator, we keep its title and moderation record (not its text) even after you withdraw the share link, to handle abuse. These records are deleted when you delete your account.
Reports
Anyone can report a published recipe. For reports from people who aren't signed in, we keep only a one-way hash derived from the network address, to avoid counting the same place twice — never the IP address itself.
Camera and photo library
Read only at the moment you pick or take a photo. Nothing else in your library is scanned or uploaded.
Microphone and voice commands
- When your device supports it, speech recognition runs on the phone. Otherwise the system hands it to Apple's speech recognition service (needs internet; Apple's privacy policy applies).
- This app keeps no recordings and sends none to our server.
- If voice isn't available (for example, no connection), it turns itself off and tells you; tapping the screen always works.
- The feature is off by default and uses the microphone only after you turn it on.
Notifications
Used only to alert you when a cooking timer finishes. Never for marketing.
Servers and logs
- Our server and database run on Cloudflare. As with any website, connections pass through Cloudflare, which processes connection data such as IP addresses to deliver and secure them.
- The server keeps operational logs to fix errors; they may include connection data and, when AI recognition fails, a short piece of the recognised recipe text (never images). Logs are kept for at most 7 days, then deleted automatically.
What we don't do
- No third-party analytics, advertising, or tracking SDKs.
- No device identifiers, location, or contacts.
- Nothing is sold or traded.
Children
This app is not directed at children under 13 and does not knowingly collect their data.
Changes
The date at the top changes when this policy does. Significant changes will be noted in the app.
Contact
rokajun11@gmail.com